Aug 11, 2026·7 min read

Microsoft built the context layer. It still runs inside Microsoft's cloud.

Work IQ, Fabric IQ, Foundry IQ, and Web IQ make Microsoft the largest vendor yet to build the context-layer argument this site has made since June. The boundary the layer runs inside has not changed.

Microsoft built the context layer. It still runs inside Microsoft's cloud.

Microsoft, the largest enterprise software vendor there is, spent Build 2026 making the context-layer argument this site has made since June. It announced four products that ground enterprise AI agents in the data those agents need to be useful, under one name: the Microsoft IQ context layer, described in its own materials as a new context layer that grounds agents in both world knowledge and enterprise knowledge. Whether that argument is correct is no longer the interesting question. Microsoft agreeing that it is settles that one. The interesting question is where the layer runs.

What Microsoft announced

Work IQ is the piece aimed at organizational memory: people, documents, meetings, and how they connect, surfaced through APIs so an agent can reason about who did what and with whom, rather than guessing from a single app's slice of it. Fabric IQ does the equivalent job for structured data, building a shared semantic layer over the tables and metrics an enterprise already runs in Fabric, so an agent and a human analyst start from the same definition of a customer or a deal instead of five departmental ones. Web IQ grounds an agent in fresh material from outside the company, pages, news, and search results returned as evidence rather than raw pages, with Microsoft citing zero retention of what it pulls back. Foundry IQ is the seam connecting all three, plus a company's own files and databases, deciding for a given question which sources to consult and how to blend the answers into one grounded response instead of three contradictory ones. An enterprise that has spent two years bolting a chat interface onto a search index will read that division of labor and recognize the mess it fixes.

None of that is a small announcement. It is the same three-part job this site has described the context layer doing since June: connect data across systems, govern who and what can reach it, and give the model something structured and traceable to reason over instead of a raw document dump. Microsoft built its version at the scale only Microsoft can build at, across every Microsoft 365 tenant in the world at once. Context layer is the moat argued the category would be won by whoever turns proprietary data into a connected, governed, traceable graph. Microsoft just agreed, in public, at its own developer conference, with a product family instead of a slide.

The boundary question

Agreeing on the category is not the same as agreeing on where it runs. Work IQ's data stays inside the customer's own Microsoft 365 tenant, which is a genuine boundary and a real answer to a real question. It is a different question, though, from the one that decides whether an insurer or a bank can put a given vendor in front of its data at all. That question is narrower and harder: does the workload, the retrieval, the reasoning, the model call, run inside infrastructure the customer's own security team provisions and controls from first line of code to teardown, or does it run as a managed service inside the vendor's cloud, under the vendor's own retention terms and the vendor's own service agreement. Microsoft IQ answers that question the way almost every enterprise AI product answers it. The service runs where Microsoft built it, and the customer's systems call out to reach it.

Nodes answers the same question with the entire architecture rather than a feature flag. None of this is a claim that Microsoft's engineering is weaker. Foundry IQ's retrieval planning across enterprise and web sources is a serious piece of infrastructure, built by people who understand the problem. The claim is narrower: the two architectures put the serious infrastructure in different places, and for one population of buyers, the place decides the outcome before the capability gets evaluated.

The practical difference shows up first in what a security team gets to inspect. A workload running inside a vendor's own cloud is a black box from the customer's side of the line: the customer can read the vendor's documentation and audit reports, but cannot walk into the environment and see what happened to a given record. A workload running inside the customer's own cloud account is not a black box, because the customer already owns the logging, the network boundary, and the access controls the workload runs behind. The inspection is not something the vendor grants. It is something the customer already had, extended to cover one more workload instead of a new one it has to trust from outside.

Where the thesis breaks

The fair version of this argument has to concede what Microsoft actually has, which is distribution nothing else in the market can match. An enterprise already running Microsoft 365, Fabric, and Foundry gets Work IQ, Fabric IQ, and Foundry IQ with no new integration project and no new vendor relationship. For the large majority of companies buying enterprise AI right now, that is the correct default, and no honest architecture argument changes it. The context-layer thesis was never a claim that every enterprise needs a boundary Microsoft cannot offer. It was a claim about what determines whether the category's advantage compounds, and distribution inside an existing platform is a real form of that compounding, earned rather than assumed.

Insurance, banking, and the small set of industries whose own data-handling terms forbid a given record from ever leaving a controlled perimeter are where the fair version runs out. The gap in the System of Intelligence thesis named this boundary in the broader a16z framing, and the same gap sits inside Microsoft's version of it. A data-sensitive enterprise's own data-handling terms answer the threshold question, can this system touch our data without that data ever traveling to infrastructure we do not control, before a product evaluation ever starts, not after. A managed context layer running inside a vendor's own cloud, however well built, sits on the wrong side of that threshold by construction. Microsoft IQ inherits the same threshold every prior enterprise AI product has run into, because the threshold was never about whose retrieval performed better. It was about whose infrastructure the data was allowed to reach in the first place. This threshold question, and what it looks like in practice at one carrier, is examined in more depth elsewhere on this site.

This is not a gap Microsoft is likely to close by adding a setting. A VPC-resident deployment is not a configuration of a multi-tenant service; it is a different manufacturing process for the same product, decided at the first line of the architecture rather than added on request. Building it changes what has to be true about every layer underneath the product, from how the model is packaged to who holds the keys to the data store. That is precisely why so few vendors have built it, and why the ones that have tend to be smaller companies for whom the constraint was the starting brief rather than a feature added to an existing platform years into its life.

The proof, such as it is

Nodes runs single-tenant and VPC-resident inside the customer's own cloud, with customer-owned weights and no data egress. Every workflow it proposes pauses for a human to approve, edit, or decline before anything executes, and the decision carries a record of what was read, what was proposed, and what a human did with it. The evidence for what a connected context layer produces once it clears that threshold sits at a Fortune 500 insurance carrier: four years of production data, 10,765 agents hired. The methodology behind those figures is published in Decision Traces.

What Build 2026 proves

Nothing in Microsoft's Build 2026 materials claims Work IQ, Fabric IQ, or Foundry IQ runs inside a customer-controlled VPC. The announcement is exactly what it appears to be: a managed context layer, built well, distributed at a scale no challenger can match, running where Microsoft's own cloud runs.

That is the whole point. Microsoft did not need to build a VPC-resident context layer to prove the category was real. It needed to build any context layer, at platform scale, in public, and let the market watch the largest enterprise software vendor alive spend its flagship conference making an architecture argument this site made in June. The boundary question does not disappear because the vendor asking a data-sensitive enterprise to trust it got bigger. It gets asked again, this time of a company most buyers have never had a reason to doubt on any other dimension, and the size of the vendor asking is not an answer to it.

Sources

Saad Bin Shafiq is the founder of Nodes, serving data-sensitive enterprises. Methodology: Decision Traces.