Microsoft replaces OpenAI and eliminates the SMS login option.
Microsoft is redefining its technology stack for the AI era, focusing on both offensive and defensive strategies. This week, it made moves in two key areas. Firstly, it began replacing OpenAI’s models in its most popular applications to reduce expenses. Additionally, it announced a timeline for discontinuing the text-message login due to an increase in AI-enabled phishing attacks.
Although these announcements may seem unrelated, they are interconnected by a common motive.
Switching from OpenAI
According to Bloomberg, Microsoft is substituting OpenAI’s image-generation models with its proprietary technology in applications like PowerPoint and Bing. “It’s faster, it’s cheaper, it’s higher quality, and it improves retention,” stated Mustafa Suleyman, Microsoft’s AI chief.
The crucial factor here is cost. Suleyman noted that the company’s own MAI models are approximately 85% less expensive than OpenAI’s when used in PowerPoint.
Despite having access to OpenAI’s models for free through their partnership, Microsoft incurs significant expenses for running them, which adds up. Earlier this month, it started to replace OpenAI and Anthropic's text models in its office applications, achieving comparable performance to GPT-5.6 on common tasks in Excel at a lower cost.
Image generation is next on the agenda. MAI models are already functioning in over half of Microsoft’s products, with testing underway across all of them. Organizations like T-Mobile and EasyJet in the UK have begun implementing its voice models in their customer service operations.
The underlying message is one of gaining independence. Suleyman, a DeepMind co-founder brought on last year to advance Microsoft’s AI initiatives, aims to reduce reliance on OpenAI. Having invested over $100 billion in this partnership, every application that shifts to in-house models diminishes OpenAI's role from a collaborator to a vendor.
Phasing out the SMS login
The second development is a defensive tactic. Starting September 1, passkeys will become the default sign-in method for Entra ID, Microsoft’s identity service. By February 1, 2027, the company will cease sending SMS and voice-call codes altogether, though it will continue to support Windows Hello and FIDO2 security keys.
The familiar SMS code is being phased out, primarily due to AI. “The AI era demands stronger, phishing-resistant authentication,” Microsoft explained. Their data highlights the issue: AI-enhanced phishing emails achieve a 54% click-through rate, compared to just 12% for traditional phishing attempts.
With AI making scams significantly more persuasive, the least secure login method must be eliminated. Passkeys are beneficial because an attacker would need the victim's actual device rather than merely a compromised code.
However, neither initiative is as straightforward as it appears. Microsoft positions its models as competitive with OpenAI only for “common” tasks, and much of the implementation remains in the testing phase. Passkeys are not a comprehensive solution either, which is why biometrics and hardware keys continue to be utilized.
Nonetheless, the connection is clear: AI is both what Microsoft seeks to operate more cost-effectively and the reason it is adjusting its security measures. Even Google now allows signing in with a selfie. The decline of the password is accelerating.
Other articles
Microsoft replaces OpenAI and eliminates the SMS login option.
Microsoft is substituting OpenAI's image models in PowerPoint and Bing to reduce expenses by 85%, and is discontinuing SMS logins due to the increased effectiveness of phishing facilitated by AI.
