Skip to content

ReportsMSFT10-K FY2026

SEC filings, compared

What changed in Microsoft's 10-K for the fiscal year ended June 30, 2026

Compared with the 10-K for the fiscal year ended June 30, 2025. Items 1A and 7 analysed; every summary checked against the quoted filing text.

Registrant
MICROSOFT CORP · MSFT
This filing
0001193125-26-323660 · filed Jul 29, 2026
Compared with
0000950170-25-100235 · filed Jul 30, 2025
Processed
Sep 14, 2026 UTC · parser-v4 · classify-v4 · select-v1

Research tool. Describes what filings say. Not investment advice. Verify independently. Read the cited paragraph before relying on it.

How a report is made

120 material changes among 176 changed paragraphs

18 shown by default across the three sections below; each section's "Show all" reaches the rest, in filing order.

Numbers from XBRL

Each figure is the one the filing itself tagged, taken from the filing that reported it. Not written by a model.

ConceptFY2026FY2025Change (our arithmetic)
Revenueus-gaap:RevenueFromContractWithCustomerExcludingAssessedTax331,839,000,000USD · Jul 1, 2025 to Jun 30, 2026281,724,000,000USD · Jul 1, 2024 to Jun 30, 2025+50,115,000,000+17.8%
Net income or lossus-gaap:NetIncomeLoss133,749,000,000USD · Jul 1, 2025 to Jun 30, 2026101,832,000,000USD · Jul 1, 2024 to Jun 30, 2025+31,917,000,000+31.3%
Cash and cash equivalentsus-gaap:CashAndCashEquivalentsAtCarryingValue20,935,000,000USD · at Jun 30, 202630,242,000,000USD · at Jun 30, 2025−9,307,000,000−30.8%
Net cash from operating activitiesus-gaap:NetCashProvidedByUsedInOperatingActivities182,935,000,000USD · Jul 1, 2025 to Jun 30, 2026136,162,000,000USD · Jul 1, 2024 to Jun 30, 2025+46,773,000,000+34.4%

Values as tagged in the filing's inline XBRL, resolved by accession rather than by period matching. When a value is not tagged, we show that instead of estimating it. FY2026: 0001193125-26-323660 · FY2025: 0000950170-25-100235

What the company says for the first time

Paragraphs with no counterpart in the prior filing.

27 material additions

Item 1A · Risk Factors

5 of 16 shown · Ordered by the model, quote-checked

01AddedItem 1A › STRATEGIC AND COMPETITIVE RISKS › We face intense competition across all markets for our products and services, which could adversely affect our results of operations.

Summary · quote-checked

Added a risk disclosure addressing uncertain cloud and AI demand, capacity misalignment, asset impairment, and inability to meet customer needs.

The paragraph introduces substantive risks involving demand forecasting, infrastructure underutilization, asset impairments, capacity constraints, and customer service limitations.

Why the model ranked it here

Client should read this because demand misjudgments could leave infrastructure underused, impair assets, or prevent the company from meeting customer needs.

Filing text · FY2025 10-K · filed Jul 30, 2025

No corresponding language in the FY2025 10-K.

Filing text · FY2026 10-K · filed Jul 29, 2026

[added] Demand for cloud-based and AI products and services is evolving and difficult to forecast. Overestimation of demand or misalignment of capacity investments may result in underutilization of infrastructure and may lead to impairment of assets on our balance sheet. Conversely, demand exceeding available capacity limits our ability to meet customer needs in a timely manner.

Cite this change

"Demand for cloud-based and AI products and services is evolving and difficult to forecast. Overestimation of demand or misalignment of capacity investments may result in underutilization of infrastructure and may lead to impairment of assets on our balance sheet. Conversely, demand exceeding available capacity limits our ability to meet customer needs in a timely manner."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

02AddedItem 1A › OPERATIONAL RISKS

Summary · quote-checked

Added a risk concerning electrical power availability, infrastructure constraints, costs, and their potential effects on datacenter expansion and growth.

The new paragraph identifies power dependencies, potential constraints and outages, utility or regulatory requirements, and consequences for datacenter capacity and customer demand.

Why the model ranked it here

Client should read this because limited or costly electrical power could restrict datacenter expansion and the company’s ability to support demand.

Filing text · FY2025 10-K · filed Jul 30, 2025

No corresponding language in the FY2025 10-K.

Filing text · FY2026 10-K · filed Jul 29, 2026

[added] The availability, reliability, and cost of electrical power are critical to the operation and expansion of our datacenters. In many regions, electricity generation, transmission, and distribution infrastructure is experiencing increasing demand and capacity constraints. Limitations in power availability, delays in obtaining power connections, outages, shortages, increased energy costs, or requirements imposed by utilities, regulators, or other market participants could restrict our ability to develop or expand datacenter capacity. In addition, alternative energy sources and other emerging solutions may not be available in sufficient quantities, may not timely scale to meet our requirements, or may be available only at higher costs. If we are unable to secure adequate power resources on commercially reasonable terms, our ability to support customer demand and execute our growth strategy could be adversely affected.

Cite this change

"The availability, reliability, and cost of electrical power are critical to the operation and expansion of our datacenters. In many regions, electricity generation, transmission, and distribution infrastructure is experiencing increasing demand and capacity constraints. Limitations in power availability, delays in obtaining power connections, outages, shortages, increased energy costs, or requirements imposed by utilities, regulators, or other market participants could restrict our ability to develop or expand datacenter capacity. In addition, alternative energy sources and other emerging solutions may not be available in sufficient quantities, may not timely scale to meet our requirements, or may be available only at higher costs. If we are unable to secure adequate power resources on commercially reasonable terms, our ability to support customer demand and execute our growth strategy could be adversely affected."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

03AddedItem 1A › STRATEGIC AND COMPETITIVE RISKS › We face intense competition across all markets for our products and services, which could adversely affect our results of operations.

Summary · quote-checked

Added a risk describing dependence on strategic AI partners, third-party technologies, cloud consumption, infrastructure capacity, and evolving customer demand.

The paragraph introduces substantive dependencies and potential adverse events involving partners, access to technology, capacity allocations, commercial arrangements, and demand for AI products and services.

Why the model ranked it here

Client should read this because the AI strategy depends on partners that may compete with the company, change arrangements, or reduce expected technology access and cloud consumption.

Filing text · FY2025 10-K · filed Jul 30, 2025

No corresponding language in the FY2025 10-K.

Filing text · FY2026 10-K · filed Jul 29, 2026

[added] Our AI strategy also depends in part on strategic relationships with third parties that provide technologies, models, products, and services that enhance our offerings. These relationships may change over time, and many of these partners compete with us with respect to certain products and services. Changes in strategic priorities, contractual arrangements, our access to third-party technologies, or key commercial relationships could adversely affect the competitiveness of our AI products and services. In some cases, these parties are significant customers of Azure and other cloud services. The economic benefits we expect to derive from these relationships, including through commercial arrangements, technology access, and Azure consumption, may not be realized or sustained. As we manage infrastructure capacity constraints and evolving customer demand, we may modify capacity allocations, deployment priorities, pricing, or other commercial arrangements. Strategic partners and other customers may likewise adjust their purchasing decisions, deployment strategies, workloads, or anticipated use of our products and services. As a result, expected consumption or anticipated demand may not materialize, may be delayed or reduced, or may decline over time. Any such developments could adversely affect our business, financial condition, and results of operations.

Cite this change

"Our AI strategy also depends in part on strategic relationships with third parties that provide technologies, models, products, and services that enhance our offerings. These relationships may change over time, and many of these partners compete with us with respect to certain products and services. Changes in strategic priorities, contractual arrangements, our access to third-party technologies, or key commercial relationships could adversely affect the competitiveness of our AI products and services. In some cases, these parties are significant customers of Azure and other cloud services. The economic benefits we expect to derive from these relationships, including through commercial arrangements, technology access, and Azure consumption, may not be realized or sustained. As we manage infrastructure capacity constraints and evolving customer demand, we may modify capacity allocations, deployment priorities, pricing, or other commercial arrangements. Strategic partners and other customers may likewise adjust their purchasing decisions, deployment strategies, workloads, or anticipated use of our products and services. As a result, expected consumption or anticipated demand may not materialize, may be delayed or reduced, or may decline over time. Any such developments could adversely affect our business, financial condition, and results of operations."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

04AddedItem 1A › OPERATIONAL RISKS

Summary · quote-checked

Adds a risk concerning reliance on third-party datacenter and cloud infrastructure providers and potential disruptions to service delivery and system performance.

The new paragraph discloses a previously absent operational dependency and identifies provider failures, capacity constraints, cybersecurity incidents, and other disruptions as risks.

Why the model ranked it here

Client should read this because failures or disruptions at third-party infrastructure providers could impair service delivery, system performance, and customer expectations.

Filing text · FY2025 10-K · filed Jul 30, 2025

No corresponding language in the FY2025 10-K.

Filing text · FY2026 10-K · filed Jul 29, 2026

[added] In addition to datacenters we own or operate, we rely on third-party providers, including colocation facilities, leased datacenters, and cloud infrastructure providers, to support portions of our operations. If any of these providers fail to meet our requirements, or experience service interruptions, operational failures, capacity constraints, physical damage, cybersecurity incidents, or other disruptions, our ability to provide services, maintain system performance, or meet customer expectations could be negatively impacted.

Cite this change

"In addition to datacenters we own or operate, we rely on third-party providers, including colocation facilities, leased datacenters, and cloud infrastructure providers, to support portions of our operations. If any of these providers fail to meet our requirements, or experience service interruptions, operational failures, capacity constraints, physical damage, cybersecurity incidents, or other disruptions, our ability to provide services, maintain system performance, or meet customer expectations could be negatively impacted."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

05AddedItem 1A › OPERATIONAL RISKS

Summary · quote-checked

Adds a risk concerning delays or inability to obtain necessary equipment, hardware, or components on acceptable terms and timelines.

The new paragraph discloses a supply and infrastructure dependency, including potential effects on deployments, sales, and costs.

Why the model ranked it here

Client should read this because delays or unfavorable terms for essential equipment and components could delay deployments, reduce sales, and increase costs.

Filing text · FY2025 10-K · filed Jul 30, 2025

No corresponding language in the FY2025 10-K.

Filing text · FY2026 10-K · filed Jul 29, 2026

We may experience supply problems. There are limited suppliers for certain critical device and datacenter components, and those items are in short supply. We continue to identify and evaluate opportunities to expand our datacenter locations and increase our server capacity to meet the evolving needs of our customers, particularly given the growing demand for AI products and services. Our competitors are also scaling their infrastructure and use some of the same suppliers and materials for hardware components as we do, which impacts price and availability. We depend on the timely availability of critical hardware, equipment, and components used to construct and operate datacenters and related infrastructure. We have experienced and may continue to experience supply constraints, including shortages of semiconductors, networking equipment, power systems, cooling equipment, and other key components. Expanding manufacturing or supply capacity for certain components may require significant investments and multi-year lead times. As components are delayed or become unavailable or more expensive, whether because of supplier capacity constraint, industry shortages, legal or regulatory changes that restrict supply sources, geopolitical tensions, trade restrictions, tariffs, transportation disruptions, supplier financial distress, natural disasters, public health events, instability in regions important to our or our suppliers' supply chains, or other reasons, we may not obtain timely replacement supplies, or may be able to obtain supplies only by entering into long-term purchase commitments, price commitments, paying prices above prevailing market rates, or other arrangements on terms that are less favorable than prevailing market terms. [added] Any delay or inability to obtain necessary equipment, hardware, or components on acceptable terms and timelines could delay infrastructure deployments, result in reduced sales, higher costs, or

Cite this change

"Any delay or inability to obtain necessary equipment, hardware, or components on acceptable terms and timelines could delay infrastructure deployments, result in reduced sales, higher costs, or"

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

Show all 16 in Item 1A (11 more, in filing order)

Item 7 · MD&A

3 of 11 shown · Ordered by the model, quote-checked

01AddedItem 7 › OVERVIEW

Summary · quote-checked

Added disclosure that commercial remaining performance obligation increased 84% to $678 billion.

The new paragraph introduces a quantified performance-obligation disclosure and states a substantial increase, adding information about the company’s commitments.

Why the model ranked it here

The sharp expansion in commercial remaining performance obligations materially changes the scale of commitments and future revenue visibility disclosed to clients.

Filing text · FY2025 10-K · filed Jul 30, 2025

No corresponding language in the FY2025 10-K.

Filing text · FY2026 10-K · filed Jul 29, 2026

[added] Commercial remaining performance obligation increased 84% to $678 billion.

Cite this change

"Commercial remaining performance obligation increased 84% to $678 billion."

Microsoft, Form 10-K for FY2026, Item 7, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

02AddedItem 7 › OTHER INCOME (EXPENSE), NET

Summary · quote-checked

Added disclosure of net gains and losses from OpenAI investments, including a fiscal year 2026 dilution gain from the OpenAI Recapitalization.

The paragraph introduces a new investment-related result and identifies a specific recapitalization event underlying the gain, changing the disclosed substance of MD&A.

Why the model ranked it here

The newly disclosed investment gains and losses, including a recapitalization-related dilution gain, materially change the explanation of other income.

Filing text · FY2025 10-K · filed Jul 30, 2025

No corresponding language in the FY2025 10-K.

Filing text · FY2026 10-K · filed Jul 29, 2026

[added] Other income (expense), net included $6.5 billion of net gains and $4.8 billion of net losses for fiscal years 2026 and 2025, respectively, from investments in OpenAI, primarily net recognized gains (losses) on our equity method investment reflected in Other, net. The net gains recorded for fiscal year 2026 primarily relate to the dilution gain from the OpenAI Recapitalization.

Cite this change

"Other income (expense), net included $6.5 billion of net gains and $4.8 billion of net losses for fiscal years 2026 and 2025, respectively, from investments in OpenAI, primarily net recognized gains (losses) on our equity method investment reflected in Other, net. The net gains recorded for fiscal year 2026 primarily relate to the dilution gain from the OpenAI Recapitalization."

Microsoft, Form 10-K for FY2026, Item 7, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

03AddedItem 7 › SUMMARY RESULTS OF OPERATIONS

Summary · quote-checked

Added disclosure that OpenAI investment gains increased current-year net income and diluted EPS, while prior-year losses decreased both metrics.

The new paragraph introduces an investment-related source of earnings volatility and quantifies its effects on net income and diluted EPS, changing the disclosed results narrative.

Why the model ranked it here

The investment gains materially affected reported net income and diluted earnings per share, making underlying performance more difficult to assess without this context.

Filing text · FY2025 10-K · filed Jul 30, 2025

No corresponding language in the FY2025 10-K.

Filing text · FY2026 10-K · filed Jul 29, 2026

[added] Current year net income and diluted EPS were positively impacted by net gains from investments in OpenAI, which resulted in an increase in net income and diluted EPS of $5.0 billion and $0.67, respectively. Prior year net income and diluted EPS were negatively impacted by net losses from investments in OpenAI, which resulted in a decrease in net income and diluted EPS of $3.6 billion and $0.49, respectively.

Cite this change

"Current year net income and diluted EPS were positively impacted by net gains from investments in OpenAI, which resulted in an increase in net income and diluted EPS of $5.0 billion and $0.67, respectively."

Microsoft, Form 10-K for FY2026, Item 7, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

Show all 11 in Item 7 (8 more, in filing order)

What the company no longer says

Paragraphs of the prior filing that this filing dropped. Only last year's text can show these.

5 material removals

Item 1A · Risk Factors

1 of 1 shown · In filing order, too few to rank

01RemovedItem 1A › INTELLECTUAL PROPERTY RISKS

Summary · quote-checked

A risk disclosure about weakened patent protection, broad open-source licensing, and resulting operational effects was removed.

The removed paragraph described intellectual-property risks and a potential adverse effect on results of operations, so its deletion changes disclosed risk substance.

Filing text · FY2025 10-K · filed Jul 30, 2025

[removed] Changes in the law may continue to weaken our ability to prevent the use of patented technology. Our increasing engagement with open source software will also cause us to license our intellectual property rights broadly in certain situations. If we are unable to protect our intellectual property, our results of operations could be adversely affected.

Filing text · FY2026 10-K · filed Jul 29, 2026

No corresponding language in the FY2026 10-K.

Cite this change

"Changes in the law may continue to weaken our ability to prevent the use of patented technology."

Microsoft, Form 10-K for FY2025, Item 1A, accession 0000950170-25-100235, filed 30 July 2025.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000095017025100235/msft-20250630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

Item 7 · MD&A

4 of 4 shown · In filing order, too few to rank

01RemovedItem 7 › Reportable Segments

Summary · quote-checked

Removed disclosure describing segment composition changes, related management reporting, and recasting of prior-period segment information.

The deleted paragraph disclosed a substantive change in reportable segments and how management allocates resources and assesses performance, not merely a presentation or date update.

Filing text · FY2025 10-K · filed Jul 30, 2025

[removed] In August 2024, we announced changes to the composition of our segments. These changes align our segments with how we currently manage our business, most notably bringing the commercial components of Microsoft 365 together in the Productivity and Business Processes segment. Beginning in fiscal year 2025, the information that our chief operating decision maker is regularly provided and reviews for purposes of allocating resources and assessing performance reflects these segment changes. Prior period segment information has been recast to conform to the way we internally manage and monitor our business during fiscal year 2025.

Filing text · FY2026 10-K · filed Jul 29, 2026

No corresponding language in the FY2026 10-K.

Cite this change

"In August 2024, we announced changes to the composition of our segments. These changes align our segments with how we currently manage our business, most notably bringing the commercial components of Microsoft 365 together in the Productivity and Business Processes segment. Beginning in fiscal year 2025, the information that our chief operating decision maker is regularly provided and reviews for purposes of allocating resources and assessing performance reflects these segment changes. Prior period segment information has been recast to conform to the way we internally manage and monitor our business during fiscal year 2025."

Microsoft, Form 10-K for FY2025, Item 7, accession 0000950170-25-100235, filed 30 July 2025.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000095017025100235/msft-20250630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

02RemovedItem 7 › Effective Tax Rate

Summary · quote-checked

The MD&A removed disclosure about Pillar Two’s 15% global minimum tax and its potential impact beginning in fiscal year 2025.

The removed paragraph disclosed a newly applicable tax regime, implementation across countries, monitoring, and expected financial-statement impact, representing substantive information about an obligation.

Filing text · FY2025 10-K · filed Jul 30, 2025

[removed] The Organisation for Economic Co-operation and Development ("OECD") published its model rules "Tax Challenges Arising From the Digitalisation of the Economy - Global Anti-Base Erosion Model Rules (Pillar Two)" which established a global minimum corporate tax rate of 15% for certain multinational enterprises. Many countries have implemented or are in the process of implementing the Pillar Two legislation, which applies to Microsoft beginning in fiscal year 2025. While we do not currently estimate a material impact to our consolidated financial statements, we continue to monitor the impact as countries implement legislation and the OECD provides additional guidance.

Filing text · FY2026 10-K · filed Jul 29, 2026

No corresponding language in the FY2026 10-K.

Cite this change

"The Organisation for Economic Co-operation and Development ("OECD") published its model rules "Tax Challenges Arising From the Digitalisation of the Economy - Global Anti-Base Erosion Model Rules (Pillar Two)" which established a global minimum corporate tax rate of 15% for certain multinational enterprises. Many countries have implemented or are in the process of implementing the Pillar Two legislation, which applies to Microsoft beginning in fiscal year 2025. While we do not currently estimate a material impact to our consolidated financial statements, we continue to monitor the impact as countries implement legislation and the OECD provides additional guidance."

Microsoft, Form 10-K for FY2025, Item 7, accession 0000950170-25-100235, filed 30 July 2025.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000095017025100235/msft-20250630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

03RemovedItem 7 › Effective Tax Rate

Summary · quote-checked

The current filing removes disclosure that Microsoft was assessing the OBBBA and describes its tax-rate, depreciation, and research-expensing provisions.

The removed paragraph disclosed a newly enacted law and specific tax provisions affecting Microsoft, constituting a substantive tax obligation and policy disclosure rather than a wording or date update.

Filing text · FY2025 10-K · filed Jul 30, 2025

[removed] We are currently assessing the One Big Beautiful Bill Act ("OBBBA") which was enacted on July 4, 2025. The OBBBA provides a U.S. global intangible low-taxed income effective tax rate of 14% effective fiscal year 2027 for Microsoft. It also provides bonus depreciation for certain assets placed into service after January 19, 2025 and an election to expense U.S. incurred research or experimental expenditures.

Filing text · FY2026 10-K · filed Jul 29, 2026

No corresponding language in the FY2026 10-K.

Cite this change

"We are currently assessing the One Big Beautiful Bill Act ("OBBBA") which was enacted on July 4, 2025. The OBBBA provides a U.S. global intangible low-taxed income effective tax rate of 14% effective fiscal year 2027 for Microsoft. It also provides bonus depreciation for certain assets placed into service after January 19, 2025 and an election to expense U.S. incurred research or experimental expenditures."

Microsoft, Form 10-K for FY2025, Item 7, accession 0000950170-25-100235, filed 30 July 2025.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000095017025100235/msft-20250630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

04RemovedItem 7 › Income Taxes

Summary · quote-checked

Removed disclosure of the TCJA transition tax installments, including the $4.4 billion eighth installment payable in fiscal year 2026.

The removed paragraph disclosed a specific remaining tax obligation, payment timing, and installment amount, changing the filing’s statement about commitments and liquidity.

Filing text · FY2025 10-K · filed Jul 30, 2025

[removed] As a result of the TCJA, we are required to pay a one-time transition tax on deferred foreign income not previously subject to U.S. income tax. Under the TCJA, the transition tax is payable in interest-free installments over eight years, with 8% due in each of the first five years, 15% in year six, 20% in year seven, and 25% in year eight. As of June 30, 2025, our eighth transition tax installment of $4.4 billion is short-term and payable in the first quarter of fiscal year 2026.

Filing text · FY2026 10-K · filed Jul 29, 2026

No corresponding language in the FY2026 10-K.

Cite this change

"As of June 30, 2025, our eighth transition tax installment of $4.4 billion is short-term and payable in the first quarter of fiscal year 2026."

Microsoft, Form 10-K for FY2025, Item 7, accession 0000950170-25-100235, filed 30 July 2025.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000095017025100235/msft-20250630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

What the company says differently

Paragraphs that changed between the two filings, shown as a word diff.

88 material changes

Item 1A · Risk Factors

2 of 42 shown · Ordered by the model, quote-checked

01ChangedItem 1A › CYBERSECURITY, DATA PRIVACY, AND PLATFORM ABUSE RISKS › Cyberattacks and security vulnerabilities could lead to reduced revenue, increased costs, liability claims, or harm to our reputation or competitive position.

Summary · quote-checked

Added details of a nation-state attack and unauthorized access, expanded affected parties to suppliers, and clarified patching failures.

The paragraph now discloses a specific cyber incident, unauthorized access to repositories and systems, and potential continuing effects, substantively changing the disclosed cybersecurity risk.

Why the model ranked it here

The disclosure moves cybersecurity exposure from a general threat to a specific nation-state intrusion involving unauthorized access to company repositories and systems.

Filing text · FY2025 10-K · filed Jul 30, 2025

Threats to security can take a variety of forms. Threat actors, including individual and groups of hackers and sophisticated organizations, including nation-states, state-sponsored organizations, or cybercriminal groups, continuously undertake attacks that pose threats to our customers and our internal infrastructure, and we have experienced cybersecurity incidents in which such actors have gained unauthorized access to our systems and data, including customer systems and data. These actors use a wide variety of methods, which include developing and deploying malicious software; exploiting known and potential vulnerabilities or intentionally designed processes in our or third-party hardware, software, or other infrastructure to attack our products and services or gain access to our networks and datacenters; using social engineering techniques to induce our employees, users, partners, or customers to disclose sensitive information, such as passwords, or take other actions to gain access to our data or our users' or customers' data; or acting in a coordinated manner or conducting coordinated attacks. For example, as previously disclosed in our Form 8-K filed with the Securities and Exchange Commission on January 19, 2024 and amended on March 8, 2024, beginning in late November 2023, a nation-state associated threat actor used a password spray attack to compromise a legacy test account and, in turn, gain access to Microsoft email accounts. The threat actor used information it obtained to gain unauthorized access to some of our source code repositories and internal systems, and the threat actor could continue to utilize this and other information to attempt to gain access to our systems or otherwise adversely affect our business and results of operations. This incident has and may continue to result in harm to our reputation and customer relationships. Nation-state and state-sponsored actors can sustain malicious activities for extended periods and deploy significant resources to plan and carry out attacks. Nation-state attacks against us, our customers, [removed] or our partners have and may continue to intensify due to our transparency to our customers, other stakeholders, and the public about cyberattacks, and during elections or periods of intense diplomatic or armed conflict. Challenges or failures [removed] in applying security patches to all hardware and devices connected to our systems, including end-of-life and end-of-support equipment, have and may continue to result in unauthorized access to our systems and data in the future. Cyber incidents and attacks, individually or in the aggregate, could adversely affect our financial condition, results of operations, competitive position, and reputation, or expose us to legal or regulatory risk.

Filing text · FY2026 10-K · filed Jul 29, 2026

Threats to security can take a variety of forms. Threat actors, including individual and groups of hackers and sophisticated organizations, including nation-states, state-sponsored organizations, or cybercriminal groups, continuously undertake attacks that pose threats to our customers and our internal infrastructure, and we have experienced cybersecurity incidents in which such actors have gained unauthorized access to our systems and data, as well as customer, partner, and supplier systems and data. These actors use a wide variety of methods, which include developing and deploying malicious software; exploiting known, latent, or potential vulnerabilities or intentionally designed processes in our or third-party hardware, software, or other infrastructure to attack our products and services or gain access to our networks and datacenters; using social engineering and AI-assisted techniques to induce our employees, users, partners, suppliers, or customers to disclose sensitive information, such as passwords, or take other actions to gain access to our data or our users' or customers' data; or acting in a coordinated manner or conducting coordinated attacks. For example, as previously disclosed in our Form 8-K filed with the Securities and Exchange [added] Commission on January 19, 2024 and amended on March 8, 2024, beginning in late November 2023, a nation-state associated threat actor used a password spray attack to compromise a legacy test account and, in turn, gain access to Microsoft email accounts. The threat actor used information it obtained to gain unauthorized access to some of our source code repositories and internal systems, and the threat actor could continue to utilize this and other information to attempt to gain access to our systems or otherwise adversely affect our business and results of operations. This incident has and may continue to result in harm to our reputation and customer relationships. Nation-state and state-sponsored actors can sustain malicious activities for extended periods and deploy significant resources to plan and carry out attacks. Nation-state attacks against us, our customers, [added] suppliers, or partners have and may continue to intensify due to our transparency to our customers, other stakeholders, and the public about cyberattacks, and during elections or periods of intense diplomatic or armed conflict. Challenges or failures [added] to update or apply security patches to all hardware and devices connected to our systems, including end-of-life and end-of-support equipment, have and may continue to result in unauthorized access to our systems and data in the future. Cyber incidents and attacks, individually or in the aggregate, could adversely affect our financial condition, results of operations, competitive position, and reputation, or expose us to legal or regulatory risk.

Cite this change

"Commission on January 19, 2024 and amended on March 8, 2024, beginning in late November 2023, a nation-state associated threat actor used a password spray attack to compromise a legacy test account and, in turn, gain access to Microsoft email accounts. The threat actor used information it obtained to gain unauthorized access to some of our source code repositories and internal systems, and the threat actor could continue to utilize this and other information to attempt to gain access to our systems or otherwise adversely affect our business and results of operations."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

02ChangedItem 1A › OPERATIONAL RISKS

Summary · quote-checked

Expanded supply-chain risk disclosure to state experienced and ongoing shortages, infrastructure dependencies, capacity investments, and potentially unfavorable procurement arrangements.

The current paragraph adds substantive supply constraints, named affected components, investment lead times, and obligations to accept costly or unfavorable supply arrangements.

Why the model ranked it here

The disclosure states that supply constraints have already occurred and identifies critical components, infrastructure dependencies, and potentially costly procurement obligations.

Filing text · FY2025 10-K · filed Jul 30, 2025

We may experience supply [removed] or quality problems. There are limited suppliers for certain device and datacenter [removed] components. We continue to identify and evaluate opportunities to expand our datacenter locations and increase our server capacity to meet the evolving needs of our customers, particularly given the growing demand for AI [removed] services. Capacity available to us may be affected as competitors use some of the same suppliers and materials for hardware [removed] components. If components are delayed or become unavailable, whether because of supplier capacity constraint, industry shortages, legal or regulatory changes that restrict supply sources, or other reasons, we may not obtain timely replacement supplies, resulting in reduced sales or inadequate datacenter capacity to support the delivery and continued development of our products and services. Component shortages, excess or obsolete inventory, or price reductions resulting in inventory adjustments may increase our cost of revenue. Datacenter servers, Xbox consoles, Surface devices, and other hardware are assembled in Asia and other geographies that may be subject to disruptions in the supply chain, resulting in shortages which could adversely affect our business, operations, financial condition, and results of operations.

Filing text · FY2026 10-K · filed Jul 29, 2026

We may experience supply problems. There are limited suppliers for certain [added] critical device and datacenter [added] components, and those items are in short supply. We continue to identify and evaluate opportunities to expand our datacenter locations and increase our server capacity to meet the evolving needs of our customers, particularly given the growing demand for AI [added] products and services. Our competitors are also scaling their infrastructure and use some of the same suppliers and materials for hardware [added] components as we do, which impacts price and availability. We depend on the timely availability of critical hardware, equipment, and components used to construct and operate datacenters and related infrastructure. We have experienced and may continue to experience supply constraints, including shortages of semiconductors, networking equipment, power systems, cooling equipment, and other key components. Expanding manufacturing or supply capacity for certain components may require significant investments and multi-year lead times. As components are delayed or become unavailable or more expensive, whether because of supplier capacity constraint, industry shortages, legal or regulatory changes that restrict supply sources, geopolitical tensions, trade restrictions, tariffs, transportation disruptions, supplier financial distress, natural disasters, public health events, instability in regions important to our or our suppliers' supply chains, or other reasons, we may not obtain timely replacement supplies, or may be able to obtain supplies only by entering into long-term purchase commitments, price commitments, paying prices above prevailing market rates, or other arrangements on terms that are less favorable than prevailing market terms. Any delay or inability to obtain necessary equipment, hardware, or components on acceptable terms and timelines could delay infrastructure deployments, result in reduced sales, higher costs, or

Cite this change

"We have experienced and may continue to experience supply constraints, including shortages of semiconductors, networking equipment, power systems, cooling equipment, and other key components."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

03ChangedItem 1A › CYBERSECURITY, DATA PRIVACY, AND PLATFORM ABUSE RISKS › Cyberattacks and security vulnerabilities could lead to reduced revenue, increased costs, liability claims, or harm to our reputation or competitive position.

Summary · quote-checked

The cybersecurity risk disclosure now describes active use of AI to accelerate and scale attacks, adds prevention concerns, and includes suppliers among affected stakeholders.

The change shifts AI use from a possibility to an asserted activity and adds specific attack capabilities and impacts, substantively expanding the stated cybersecurity risk.

Why the model ranked it here

The disclosure states that attackers are actively using AI to accelerate, scale, and refine attacks, reducing the time available for detection and mitigation.

Filing text · FY2025 10-K · filed Jul 30, 2025

Cyberthreats are constantly evolving and becoming increasingly sophisticated and complex, increasing the difficulty of detecting and successfully defending against them. Threat actors [removed] may also utilize emerging [removed] technologies, such as AI and machine [removed] learning. Our current capabilities may not detect certain vulnerabilities or new attack methods, which may allow them to persist in the environment over long periods of time. It may be difficult to determine the best way to investigate, mitigate, contain, and remediate the harm caused by a cyber incident. Such efforts may not be successful, and we may make errors or fail to take necessary actions. It is possible that threat actors may gain undetected access to other networks and systems after establishing a foothold on an internal system. Cyber incidents and attacks can have cascading impacts that unfold with increasing speed across our internal networks and systems, as well as those of our partners and customers. In addition, it may take considerable time for us to investigate and evaluate the full impact of incidents, particularly for sophisticated attacks. As a result of these and other factors, we may not be able to provide prompt, full, and reliable information about the incident to our customers, partners, regulators, and the public. Breaches of our facilities, network, or data security can disrupt the security of our systems and business applications, impair our ability to provide services to our customers and protect the privacy of their data, result in product development delays, compromise confidential or technical business information, result in theft or misuse of our intellectual property or other assets, subject us to ransomware attacks, require us to allocate more resources to improve technologies or remediate the impacts of attacks, or otherwise adversely affect our business. In addition, actions taken to remediate an incident could result in outages, data losses, and disruptions of our services.

Filing text · FY2026 10-K · filed Jul 29, 2026

Cyberthreats are constantly evolving and becoming increasingly sophisticated and complex, increasing the difficulty of [added] preventing, detecting and successfully defending against them. Threat actors also utilize emerging [added] technologies such as AI and machine [added] learning to, among other things, increase the speed and scale of attacks by generating and refining malicious content and code, automate reconnaissance and targeting, accelerate their ability to detect or exploit vulnerabilities, and rapidly iterate on attack techniques, which can broaden the scope, intensity, and sophistication of campaigns and reduce the time we have to identify and mitigate emerging threats. Our current capabilities may not detect certain vulnerabilities or new attack methods, which may allow them to persist in the environment over long periods of time. It may be difficult to determine the best way to investigate, mitigate, contain, and remediate the harm caused by a cyber incident. Such efforts may not be successful, and we may make errors or fail to take necessary actions. It is possible that threat actors may gain undetected access to other networks and systems after establishing a foothold on an internal system. Cyber incidents and attacks can have cascading impacts that unfold with increasing speed across our internal networks and systems, as well as those of our partners and customers. In addition, it may take considerable time for us to investigate and evaluate the full impact of incidents, particularly for sophisticated attacks. As a result of these and other factors, we may not be able to provide prompt, full, and reliable information about the incident to our customers, partners, [added] suppliers, regulators, and the public. Breaches of our facilities, network, or data security can disrupt the security of our systems and business applications, impair our ability to provide services to our customers and protect the privacy of their data, result in product development delays, compromise confidential or technical business information, result in theft or misuse of our intellectual property or other assets, subject us to ransomware attacks, require us to allocate more resources to improve technologies or remediate the impacts of attacks, or otherwise adversely affect our business. In addition, actions taken to remediate an incident could result in outages, data losses, and disruptions of our services.

Cite this change

"Threat actors also utilize emerging technologies such as AI and machine learning to, among other things, increase the speed and scale of attacks by generating and refining malicious content and code, automate reconnaissance and targeting, accelerate their ability to detect or exploit vulnerabilities, and rapidly iterate on attack techniques, which can broaden the scope, intensity, and sophistication of campaigns and reduce the time we have to identify and mitigate emerging threats."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

04ChangedItem 1A › CYBERSECURITY, DATA PRIVACY, AND PLATFORM ABUSE RISKS › Cyberattacks and security vulnerabilities could lead to reduced revenue, increased costs, liability claims, or harm to our reputation or competitive position.

Summary · quote-checked

The disclosure adds AI-related third-party cybersecurity risk, describes supply-chain exploitation as occurring, and expands affected parties and potential impacts.

The paragraph changes hypothetical supply-chain language to realized exploitation, adds an AI-related risk, and identifies broader third-party and customer-environment consequences.

Why the model ranked it here

The disclosure changes supply-chain exploitation from a hypothetical technique to an experienced risk and adds AI-related exposure involving third parties and customer environments.

Filing text · FY2025 10-K · filed Jul 30, 2025

Inadequate account security or organizational security practices, including those of companies we have acquired or those of the third parties we utilize, have resulted and may result in unauthorized access to our systems and data, including customer systems and data. For example, passwords may not be rotated and employee access may not be updated or removed on a timely basis. Employees or third parties may intentionally compromise our or our users' security or systems or reveal confidential information, and laws in [removed] foreign jurisdictions may compel actions by such parties against our interests and could limit our recourse. Malicious actors [removed] may employ the supply chain to [removed] introduce malware through software updates or compromised supplier [removed] accounts or hardware.

Filing text · FY2026 10-K · filed Jul 29, 2026

Inadequate account security or organizational security practices, including those of companies we have acquired or those of the third parties we utilize, have resulted and may result in unauthorized access to our systems and data, including customer systems and data. For example, passwords may not be rotated and employee access may not be updated or removed on a timely basis. [added] Further, third parties that we utilize may also face the AI-based enhanced cybersecurity risk as described elsewhere in these risk factors. Employees or third parties may intentionally compromise our or our users' security or systems or reveal confidential information, and laws in [added] certain jurisdictions may compel actions by such parties against our interests and could limit our recourse. Malicious actors [added] have and may continue to exploit the supply chain to [added] compromise our systems by, for example, injecting malware, including through software updates or compromised supplier [added] or open-source software code, accounts, or hardware.[added] Incidents involving the supply chain, including third-party vendors, suppliers, service providers, open-source software, or customer environments, may adversely affect our systems and our products and services, even where our own systems are not directly compromised.

Cite this change

"Further, third parties that we utilize may also face the AI-based enhanced cybersecurity risk as described elsewhere in these risk factors."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

05ChangedItem 1A › CYBERSECURITY, DATA PRIVACY, AND PLATFORM ABUSE RISKS › Cyberattacks and security vulnerabilities could lead to reduced revenue, increased costs, liability claims, or harm to our reputation or competitive position.

Summary · quote-checked

The disclosure adds risks from AI-generated code and states that products have contained, and may continue to contain, vulnerabilities or undetected errors.

The change adds a specific AI-generated-code risk and shifts from potential vulnerabilities to an assertion that vulnerabilities have occurred, substantively changing the cybersecurity disclosure.

Why the model ranked it here

The disclosure adds AI-generated code as a source of vulnerabilities and indicates that products have contained or may continue to contain undetected errors.

Filing text · FY2025 10-K · filed Jul 30, 2025

The security of our products and services is important in our customers' decisions to purchase or use our products or services across cloud and on-premises environments. Security threats are a significant challenge to companies like us, whose business is providing technology products and services to others. Threats to or attacks on our own infrastructure, such as the nation-state attack described in the prior risk factor, have also affected our customers and may do so in the future. The reliability of our cloud-based services and the protection of customer data depend on the security of our infrastructure, which includes hardware and other elements provided by third parties. Adversaries tend to focus their efforts on the most popular operating systems, programs, and services, including many of ours, as well as customers with sensitive data, and we expect that to continue. In addition, adversaries can attack our customers' on-premises or cloud environments, sometimes exploiting previously unknown ("zero-day") vulnerabilities. Product vulnerabilities can persist even after we have issued security patches if customers have not installed the most recent updates, or if the attackers exploited the vulnerabilities before patching to install additional malware to further compromise customers' systems. Adversaries will continue to attack customers using our cloud services as customers embrace digital transformation. Adversaries that acquire user account information can use that information to compromise our users' accounts, including where accounts share the same attributes such as passwords. Inadequate account security practices may also result in unauthorized access, and user activity may result in ransomware or other malicious software impacting a customer's use of our products or services. [removed] Weaknesses in our development [removed] processes can result in vulnerabilities in our products. Open source software can also contain vulnerabilities that may make our products susceptible to cyberattacks as we increasingly incorporate [removed] open source software into our products. [removed] Additionally, features that rely on generative AI can be susceptible to security threats.

Filing text · FY2026 10-K · filed Jul 29, 2026

The security of our products and services is important in our customers' decisions to purchase or use our products or services across cloud and on-premises environments. Security threats are a significant challenge to companies like us, whose business is providing technology products and services to others. Threats to, or attacks on, our own infrastructure, such as the nation-state attack described in the prior risk factor, have also affected our customers and may do so in the future. The reliability of our cloud-based services and the protection of customer data depend on the security of our infrastructure and the security of third-party infrastructure upon which we rely, which includes hardware, software, and other elements provided by third parties. Adversaries tend to focus their efforts on the most popular operating systems, programs, and services, including many of ours, as well as customers with sensitive data, and we expect that to continue. In addition, adversaries can attack our customers' on-premises or cloud environments, sometimes exploiting previously unknown ("zero-day") vulnerabilities. Product vulnerabilities can persist even after we have issued security patches if customers have not installed the most recent updates, or if attackers, potentially with the assistance of artificial intelligence, reconstruct and exploit the vulnerabilities before patching. Attackers may utilize vulnerabilities to install malware to further compromise customers' systems. Adversaries will continue to attack customers as they embrace digital transformation. Adversaries that acquire user account information can use that information to compromise our users' accounts, including where accounts share the same attributes such as passwords. Inadequate account security practices may also result in unauthorized access, and user activity may result in ransomware or other malicious software impacting a customer's use of our products or services. [added] Our products are highly complex and weaknesses may exist in our development [added] processes. For example, code generated by AI could include errors, deficiencies, or vulnerabilities that increase our exposure to cyberattacks. Additionally, open-source software can also contain vulnerabilities that may make our products susceptible to cyberattacks as we increasingly incorporate [added] open-source software into our products. [added] Accordingly, our products have and may continue to contain vulnerabilities or undetected errors.

Cite this change

"For example, code generated by AI could include errors, deficiencies, or vulnerabilities that increase our exposure to cyberattacks."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

06ChangedItem 1A › CYBERSECURITY, DATA PRIVACY, AND PLATFORM ABUSE RISKS › Abuse of our platforms may harm our reputation or user engagement.

Summary · quote-checked

The disclosure adds evolving regulation and scrutiny, expands affected groups, and states that unintended AI consequences have occurred and are expected to continue.

The paragraph changes from hypothetical consequences to experienced and expected incidents, while adding regulatory scrutiny and vulnerable groups, substantively changing the disclosed AI risks.

Why the model ranked it here

The disclosure shifts AI harms from hypothetical concerns to unintended consequences that have occurred and are expected to continue amid increasing regulatory scrutiny.

Filing text · FY2025 10-K · filed Jul 30, 2025

Issues in the development, deployment, and use of AI may result in reputational or competitive harm or liability. We are building AI into many of our offerings, including our productivity services, and we are also making AI available for our customers to use in solutions that they build. This AI may be developed by Microsoft or others, including our strategic partner, OpenAI. We expect these elements of our business to grow. We envision a future in which AI operating in devices, applications, and the cloud helps our customers be more productive in their work and personal lives. As with many innovations, AI presents risks and challenges that could affect its adoption, and therefore our business. AI algorithms or training methodologies may be flawed. Datasets may be overbroad, insufficient, or contain biased or inaccurate information. Content generated by AI systems may be offensive, illegal, inaccurate, or otherwise harmful. Ineffective or inadequate AI development or deployment practices by Microsoft or others could result in incidents that impair the acceptance of AI solutions, cause harm to individuals, customers, or society, or result in our products and services not working as intended. Human review of certain inputs and outputs may be required, including for agentic AI systems that can take actions autonomously. Our implementation of AI systems could result in legal liability, regulatory action, brand, reputational, or competitive harm, or other adverse impacts. These risks may stem from issues related to intellectual property, data privacy, and other claims associated with AI training and outputs. They are further compounded by the evolving regulatory landscape, with new laws emerging globally, including the European Union ("EU"). [removed] Some AI scenarios present ethical issues or may have broad impacts on society. There is also rising divergence globally in how to address these issues and impacts, with the result that we will need to navigate a web of different tensions across geographies. [removed] Finally, if we enable or offer AI solutions that have unintended consequences, unintended usage or customization by our customers and partners, are contrary to our responsible AI policies and practices, or are otherwise controversial because of the impact on human rights, privacy, employment, or other social, economic, or political issues, our reputation, competitive position, business, financial condition, and results of operations could be adversely affected.

Filing text · FY2026 10-K · filed Jul 29, 2026

Issues in the development, deployment, and use of AI may result in reputational or competitive harm or liability. We are providing access to AI across our offerings and enabling customers and partners to build AI-based solutions using our platforms. These capabilities may be developed by Microsoft or third parties and are becoming an increasing part of our business. The increasing scale and adoption of AI amplifies challenges that may affect its development, deployment, and use, which could give rise to reputational, competitive, or legal harm. Our AI models and the methodologies used to train them may be flawed. Datasets may be overbroad, insufficient, or contain biased or inaccurate information. Content generated by AI systems may be offensive, illegal, inaccurate, or otherwise harmful. Ineffective or inadequate AI development or deployment practices by Microsoft or others could result in incidents that impair the acceptance of AI solutions, cause harm to individuals, customers, or society, or result in our products and services not working as intended. Human review of certain inputs and outputs or other forms of human oversight may be required, including for agentic AI systems that can take actions autonomously. Companion or highly-personalized AI systems may result in over-reliance or dependence by users that is harmful. Our implementation of AI systems could result in legal liability, regulatory action, litigation, brand, reputational, or competitive harm, or other adverse impacts. These risks may stem from issues related to AI model and system capabilities, intellectual property, data privacy, product liability, and other claims associated with AI training, outputs, and system behavior. [added] They are further compounded by the evolving regulatory landscape, with new laws emerging globally and increased scrutiny from regulators and lawmakers. Certain AI technologies and use cases present ethical issues or may have broad [added] or uneven impacts on [added] society or vulnerable groups within society. There is also rising divergence globally in how to address these issues and impacts, with the result that we will need to navigate a web of different tensions across geographies. [added] We have experienced, and expect to continue to experience, instances in which the AI solutions we enable or offer produce unintended consequences, are used or customized in unforeseen ways by customers or partners, or operate in a manner inconsistent with our responsible AI policies and practices. These outcomes may give rise to public controversy, societal concerns, or regulatory actions relating to human rights, privacy, employment, or other social, economic, or political issues, and could adversely affect our reputation, competitive position, business, financial condition, and results of operations.

Cite this change

"They are further compounded by the evolving regulatory landscape, with new laws emerging globally and increased scrutiny from regulators and lawmakers."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

07ChangedItem 1A › STRATEGIC AND COMPETITIVE RISKS › We face intense competition across all markets for our products and services, which could adversely affect our results of operations.

Summary · quote-checked

The disclosure expands from execution costs and competition to substantial AI and cloud investment, funding dependence, regulatory exposure, and risks to expected revenue realization.

The paragraph adds substantive risks involving capital access, financing costs, regulatory and political challenges, accelerated infrastructure investment, and potentially delayed or lower revenue realization.

Why the model ranked it here

The disclosure makes the cloud and AI strategy dependent on substantial investment, financing access, regulatory conditions, and successful revenue realization.

Filing text · FY2025 10-K · filed Jul 30, 2025

Our [removed] focus on cloud-based and AI services presents execution and competitive risks. We are incurring significant costs to build and maintain infrastructure to support cloud-based and AI services, reducing operating margins. Whether we succeed in cloud-based and AI services depends on our [removed] execution in several areas, including:

Filing text · FY2026 10-K · filed Jul 29, 2026

Our [added] cloud and AI strategy requires substantial investments and depends on evolving customer demand, technological developments, competitive dynamics, and regulatory conditions, any of which could adversely affect our business, financial condition, and results of operations. We have made and are continuing to make significant capital and operational investments to develop, train, deploy, and support AI models and related cloud-based services, including building and expanding datacenters, acquiring necessary components, and securing energy resources. These investments are being made at significant scale and on an accelerated timeline, require substantial and increasing capital expenditures and continued access to capital, and are in advance of fully developed revenue streams. The associated revenue may not be realized in the expected timeframes or at expected levels. Our capital and operational investments are complex and involve projects in multiple locations around the world that expose us to increased compliance risks and political challenges, among others. Our ability to fund these investments depends on our [added] ability to generate sufficient cash flows and obtain financing on acceptable terms. Adverse changes in interest rates, credit markets, investor sentiment, our credit ratings, or other factors affecting capital availability could increase our cost of capital or limit our ability to execute our infrastructure strategy. The financial success of these investments depends on a number of uncertain factors, including customer demand for cloud-based and AI products and services and continued customer use of Azure to build, train, deploy, and run AI workloads, our ability to price and monetize those services at levels sufficient to recover our costs, competitive dynamics affecting pricing, and the pace of adoption of AI. Customers may reduce, delay, or shift AI workloads to competing platforms, on-premises or local deployments, or other alternatives. If adoption of our AI services develops more slowly than expected, or if customers do not continue to utilize Azure for AI workloads at anticipated levels, we may not realize the expected returns on our investments.

Cite this change

"Our cloud and AI strategy requires substantial investments and depends on evolving customer demand, technological developments, competitive dynamics, and regulatory conditions, any of which could adversely affect our business, financial condition, and results of operations."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

08ChangedItem 1A › CYBERSECURITY, DATA PRIVACY, AND PLATFORM ABUSE RISKS › Abuse of our platforms may harm our reputation or user engagement.

Summary · quote-checked

The paragraph adds specific child-safety, age-assurance, platform-design, and AI-related risks while removing broader regulatory uncertainty and freedom-of-expression discussion.

The disclosure changes the identified regulatory risks and obligations, adding potentially distinct risks for children and adolescents and fines and penalties; this is substantive, not a rephrasing.

Why the model ranked it here

The disclosure adds concrete obligations for age assurance, age-appropriate design, and parental controls that may create compliance exposure and penalties.

Filing text · FY2025 10-K · filed Jul 30, 2025

Our [removed] consumer services as well as our enterprise services may be used to find, generate, store, or disseminate harmful or illegal content in violation of our terms or applicable law. We may not proactively discover such content due to scale, the limitations of existing technologies, and conflicting legal frameworks. [removed] When discovered by users and others, such content may negatively affect our reputation, our brands, [removed] and user engagement. Regulations and other initiatives have been enacted to make platforms responsible for preventing or eliminating harmful content online, and we expect this to continue with focused attention on child safety. At the same time, [removed] regulations and other initiatives regarding freedom of expression may conflict with such content moderation regulations. The legal and regulatory environment in this area is complex and continues to evolve across multiple jurisdictions. As a result, there is considerable uncertainty regarding both current and future compliance obligations. Failure to comply with [removed] content requirements may subject us to enhanced regulatory oversight, civil or criminal liability, [removed] or reputational damage, which could adversely affect our business, financial condition, and results of operations.

Filing text · FY2026 10-K · filed Jul 29, 2026

Our services may be used to find, generate, store, or disseminate harmful or illegal content in violation of our terms or applicable law. We may not proactively discover such content due to scale, the limitations of existing technologies, and conflicting legal frameworks. [added] This content may negatively affect [added] users, our reputation, our brands, [added] or could impact our business in certain markets. Regulatory enforcement is increasingly focused on product design, safety-by-design, and the responsibility of platform providers. At the same time, [added] laws designed to reduce risks to children are driving new obligations for age-assurance systems, age-appropriate design, and parental controls across the online ecosystem, including within app stores and operating systems. In addition, certain AI technologies, including conversational or emotionally engaging AI systems, may present distinct risks for children and adolescents. Failure to comply with [added] these requirements may subject us to enhanced regulatory oversight, civil or criminal liability, [added] fines and penalties, or other reputational damage, which could adversely affect our business, financial condition, and results of operations.

Cite this change

"At the same time, laws designed to reduce risks to children are driving new obligations for age-assurance systems, age-appropriate design, and parental controls across the online ecosystem, including within app stores and operating systems."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

09ChangedItem 1A › RISKS RELATING TO THE EVOLUTION OF OUR BUSINESS

Summary · quote-checked

The disclosure broadens potential challenges from completed acquisitions to transactions and arrangements generally, including legal and regulatory challenges, and states challenges have occurred.

The change expands the affected transactions, adds legal and regulatory proceedings, and shifts from a hypothetical possibility to an assertion that challenges have occurred.

Why the model ranked it here

The disclosure broadens transaction risk beyond completed acquisitions and states that legal and regulatory challenges have occurred.

Filing text · FY2025 10-K · filed Jul 30, 2025

Acquisitions, joint ventures, and strategic alliances could have an adverse effect on our business. We expect to continue making acquisitions and entering into joint ventures and strategic alliances as part of our long-term business strategy. For example, in October 2023 we completed our acquisition of Activision Blizzard, Inc. ("Activision Blizzard"). In January 2023 we announced the third phase of our OpenAI strategic partnership. Acquisitions and other transactions and arrangements involve significant challenges and risks, including that they do not advance our business strategy, that we get an unsatisfactory return on our investment, that they raise new compliance-related obligations and challenges, that we have difficulty integrating and retaining new employees, business systems, and technology, that they distract management from our other businesses, or that announced transactions may not be completed. If an arrangement fails to adequately anticipate changing circumstances and interests of a party, it may result in early termination or renegotiation of the arrangement. We also have limited ability to control or influence third parties with whom we have arrangements, which may impact our ability to realize the anticipated benefits. The success of these transactions and arrangements depend in part on our ability to leverage them to enhance our existing products and services or develop compelling new ones, as well as the acquired companies' ability to meet our policies and processes in areas such as data governance, privacy, digital safety, responsible AI, and cybersecurity. It may take longer than expected to realize the full economic benefits from these transactions and arrangements, such as increased revenue or enhanced efficiencies, or the benefits may ultimately be smaller than we expected, which could cause an impairment of goodwill or intangibles. We have recorded, and may in the future be required to record, a significant charge in our consolidated financial statements during the period in which any impairment of our goodwill or amortizable intangible assets is determined, negatively affecting our results of operations. In addition, [removed] an acquisition may be subject to [removed] challenge even after it has been completed. These events could adversely affect our business, operations, financial condition, and results of operations.

Filing text · FY2026 10-K · filed Jul 29, 2026

Acquisitions, joint ventures, and strategic alliances could have an adverse effect on our business. We expect to continue making acquisitions and entering into joint ventures and strategic alliances as part of our long-term business strategy. For example, in October 2023 we completed our acquisition of Activision Blizzard, Inc. Additionally, we have a long-term strategic partnership with OpenAI. Acquisitions and other transactions and arrangements involve significant challenges and risks, including that they do not advance our business strategy, that we get an unsatisfactory return on our investment, that they raise new compliance-related obligations and challenges, that we have difficulty integrating and retaining new employees, business systems, and technology, that they distract management from our other businesses, or that announced transactions may not be completed. If an arrangement fails to adequately anticipate changing circumstances and interests of a party, it may result in early termination or renegotiation of the arrangement. We also have limited ability to control or influence third parties with whom we have arrangements, which may impact our ability to realize the anticipated benefits. The success of these transactions and arrangements depend in part on our ability to leverage them to enhance our existing products and services or develop compelling new ones, as well as the acquired companies' ability to meet our policies and processes in areas such as data governance, privacy, digital safety, responsible AI, and cybersecurity. It may take longer than expected to realize the full economic benefits from these transactions and arrangements, such as increased revenue or enhanced efficiencies, or the benefits may ultimately be smaller than we expected, which could cause an impairment of goodwill or intangibles. We have recorded, and may in the future be required to record, a significant charge in our consolidated financial statements during the period in which any impairment of our goodwill or amortizable intangible assets is determined, negatively affecting our results of operations. In addition, [added] these transactions and arrangements have been and may be subject to [added] legal and regulatory challenge. These events could adversely affect our business, operations, financial condition, and results of operations.

Cite this change

"In addition, these transactions and arrangements have been and may be subject to legal and regulatory challenge."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

10ChangedItem 1A › CYBERSECURITY, DATA PRIVACY, AND PLATFORM ABUSE RISKS › Abuse of our platforms may harm our reputation or user engagement.

Summary · quote-checked

AI risk disclosure was substantively revised, adding risks involving user dependence, litigation, product liability, and system behavior while removing certain prior descriptions.

The paragraph adds new harm mechanisms and legal exposure, including user over-reliance, litigation, product liability, and system behavior, while changing the scope and framing of AI risks.

Why the model ranked it here

The disclosure adds risks that personalized AI systems may cause harmful user dependence and create litigation, product liability, and system-behavior exposure.

Filing text · FY2025 10-K · filed Jul 30, 2025

Issues in the development, deployment, and use of AI may result in reputational or competitive harm or liability. We are [removed] building AI into many of our offerings, including our productivity services, and we are also making AI available for our customers to use in solutions that they build. This AI may be developed by Microsoft or [removed] others, including our strategic partner, OpenAI. We expect these elements of our [removed] business to grow. We envision a future in which AI operating in devices, applications, and the cloud helps our customers be more productive in their work and personal lives. As with many innovations, AI presents risks and challenges that could affect its adoption, and therefore our business. AI algorithms or training methodologies may be flawed. Datasets may be overbroad, insufficient, or contain biased or inaccurate information. Content generated by AI systems may be offensive, illegal, inaccurate, or otherwise harmful. Ineffective or inadequate AI development or deployment practices by Microsoft or others could result in incidents that impair the acceptance of AI solutions, cause harm to individuals, customers, or society, or result in our products and services not working as intended. Human review of certain inputs and outputs may be required, including for agentic AI systems that can take actions autonomously. Our implementation of AI systems could result in legal liability, regulatory action, brand, reputational, or competitive harm, or other adverse impacts. These risks may stem from issues related to intellectual property, data privacy, and other claims associated with AI [removed] training and outputs. They are further compounded by the evolving regulatory landscape, with new laws emerging globally, including the European Union ("EU"). Some AI scenarios present ethical issues or may have broad impacts on society. There is also rising divergence globally in how to address these issues and impacts, with the result that we will need to navigate a web of different tensions across geographies. Finally, if we enable or offer AI solutions that have unintended consequences, unintended usage or customization by our customers and partners, are contrary to our responsible AI policies and practices, or are otherwise controversial because of the impact on human rights, privacy, employment, or other social, economic, or political issues, our reputation, competitive position, business, financial condition, and results of operations could be adversely affected.

Filing text · FY2026 10-K · filed Jul 29, 2026

Issues in the development, deployment, and use of AI may result in reputational or competitive harm or liability. We are [added] providing access to AI across our offerings and enabling customers and partners to build AI-based solutions using our platforms. These capabilities may be developed by Microsoft or [added] third parties and are becoming an increasing part of our [added] business. The increasing scale and adoption of AI amplifies challenges that may affect its development, deployment, and use, which could give rise to reputational, competitive, or legal harm. Our AI models and the methodologies used to train them may be flawed. Datasets may be overbroad, insufficient, or contain biased or inaccurate information. Content generated by AI systems may be offensive, illegal, inaccurate, or otherwise harmful. Ineffective or inadequate AI development or deployment practices by Microsoft or others could result in incidents that impair the acceptance of AI solutions, cause harm to individuals, customers, or society, or result in our products and services not working as intended. Human review of certain inputs and outputs [added] or other forms of human oversight may be required, including for agentic AI systems that can take actions autonomously. [added] Companion or highly-personalized AI systems may result in over-reliance or dependence by users that is harmful. Our implementation of AI systems could result in legal liability, regulatory action, [added] litigation, brand, reputational, or competitive harm, or other adverse impacts. These risks may stem from issues related to [added] AI model and system capabilities, intellectual property, data privacy, [added] product liability, and other claims associated with AI [added] training, outputs, and system behavior. They are further compounded by the evolving regulatory landscape, with new laws emerging globally and increased scrutiny from regulators and lawmakers. Certain AI technologies and use cases present ethical issues or may have broad or uneven impacts on society or vulnerable groups within society. There is also rising divergence globally in how to address these issues and impacts, with the result that we will need to navigate a web of different tensions across geographies. We have experienced, and expect to continue to experience, instances in which the AI solutions we enable or offer produce unintended consequences, are used or customized in unforeseen ways by customers or partners, or operate in a manner inconsistent with our responsible AI policies and practices. These outcomes may give rise to public controversy, societal concerns, or regulatory actions relating to human rights, privacy, employment, or other social, economic, or political issues, and could adversely affect our reputation, competitive position, business, financial condition, and results of operations.

Cite this change

"Companion or highly-personalized AI systems may result in over-reliance or dependence by users that is harmful."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

11ChangedItem 1A › LEGAL, REGULATORY, AND LITIGATION RISKS

Summary · quote-checked

Added disclosure that potential AI-related rulemakings and expanded export license conditions could adversely affect Microsoft's business, strategy, and operations.

The paragraph adds a new regulatory risk concerning replacement of the rescinded AI Diffusion Rule, expanded export license conditions, and other AI-related rulemakings; conflict wording changes are secondary.

Filing text · FY2025 10-K · filed Jul 30, 2025

Trade: Increasing trade laws, policies, sanctions, and other regulatory requirements also affect our operations in and outside the U.S. relating to trade and investment. Economic sanctions in the U.S., the EU, and other countries prohibit most business with restricted entities or countries. U.S. export controls restrict Microsoft from offering many of its products and services to, or making investments in, certain entities in specified countries. U.S. import controls restrict us from integrating certain information and communication technologies into our supply chain and allow for government review of transactions involving information and communications technology from countries determined to be foreign adversaries. Supply chain regulations may impact the availability of goods or result in additional regulatory scrutiny. Restrictions on data flows and outbound investment and customer sensitivities may limit our ability to leverage parts of our global engineering footprint to provide services in certain jurisdictions. Increased geopolitical instabilities and changing U.S. Administration priorities create an unpredictable trade landscape. U.S. tariff and shifting AI export controls policies, like the AI Diffusion Rule, could increase operational costs, create uncertainty in the continuity of our products, and accelerate sovereignty initiatives among international partners and customers. The volatility of U.S. tariffs has triggered economic uncertainty and could impact cloud and devices supply chain cost competitiveness. The potential replacement of the recently rescinded AI Diffusion Rule and other potential AI-related rulemakings could adversely affect Microsoft's business, strategy, and operations. Periods of intense diplomatic or armed [removed] conflict like the ongoing conflict in Ukraine and the [removed] Israel-Hamas conflict could result in (1) new and rapidly evolving sanctions and trade restrictions, which may impair trade with sanctioned individuals and countries, and (2) negative impacts to regional trade ecosystems among our customers, partners, and us.

Filing text · FY2026 10-K · filed Jul 29, 2026

Trade: Increasing trade laws, policies, sanctions, and other regulatory requirements also affect our operations in and outside the U.S. relating to trade and investment. Economic sanctions in the U.S., the EU, and other countries could prohibit business with restricted entities or countries. U.S. export controls restrict Microsoft from offering many of its products and services to, or making investments in, certain entities in specified countries. U.S. import controls restrict us from integrating certain information and communication technologies into our supply chain and allow for government review of transactions involving information and communications technology from countries determined to be foreign adversaries. Supply chain regulations may impact the availability of goods or result in additional regulatory scrutiny. Restrictions on data flows and outbound investment and customer sensitivities may limit our ability to leverage parts of our global engineering footprint to provide services in certain jurisdictions. Increased geopolitical instabilities and changing U.S. Administration priorities create an unpredictable trade landscape. U.S. tariffs, shifting AI export controls policies, and disagreements among governments on sanctions policies toward third countries, has and may continue to increase operational costs, create uncertainty in the continuity of our products, and accelerate sovereignty initiatives among international partners and customers. The volatility of U.S. tariffs has triggered economic uncertainty and could impact cloud and devices supply chain cost competitiveness. [added] The potential replacement of the rescinded AI Diffusion Rule, expanded export license conditions, and other potential AI-related rulemakings could adversely affect Microsoft's business, strategy, and operations. Periods of intense diplomatic or armed [added] conflict, such as the conflicts in Ukraine and the [added] Middle East could continue to result in (1) new and rapidly evolving sanctions and trade restrictions, which may impair trade with sanctioned individuals and countries, and (2) negative impacts to regional trade ecosystems among our customers, partners, and us.

Cite this change

"The potential replacement of the rescinded AI Diffusion Rule, expanded export license conditions, and other potential AI-related rulemakings could adversely affect Microsoft's business, strategy, and operations."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

12ChangedItem 1A › STRATEGIC AND COMPETITIVE RISKS › We face intense competition across all markets for our products and services, which could adversely affect our results of operations.

Summary · quote-checked

The risk shifts from uncertain user attraction and revenue generation to execution across product, market, acquisition, and retention initiatives, with consequences for adoption, market share, and revenue growth.

The revised paragraph introduces specific execution dependencies and new stated effects on adoption and market share, while replacing the prior reference to infrastructure and development investments.

Filing text · FY2025 10-K · filed Jul 30, 2025

[removed] It is uncertain whether our strategies will continue to attract users or generate the revenue required to succeed. If we are not effective in executing organizational and technical changes to increase efficiency and accelerate innovation, or if we fail to generate sufficient usage of our new products and services, [removed] we may not grow revenue in line with the infrastructure and development investments described above. This could adversely affect our operations, financial condition, and results of operations.

Filing text · FY2026 10-K · filed Jul 29, 2026

[added] Our success depends on our ability to execute effectively across product development, go-to-market, customer acquisition, and customer retention initiatives. Failure to do so could reduce adoption, market share, and revenue growth. If we are not effective in executing organizational and technical changes to increase efficiency and accelerate innovation, or if we fail to generate sufficient usage of our new products and services, [added] the timing or magnitude of any revenue growth may not be in line with these costs. This could adversely affect our operations, financial condition, and results of operations.

Cite this change

"Our success depends on our ability to execute effectively across product development, go-to-market, customer acquisition, and customer retention initiatives. Failure to do so could reduce adoption, market share, and revenue growth."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

13ChangedItem 1A › STRATEGIC AND COMPETITIVE RISKS › We face intense competition across all markets for our products and services, which could adversely affect our results of operations.

Summary · quote-checked

The misuse risk was reframed to cover malicious actors and unlawful purposes, with potential regulatory scrutiny, service disruptions, and financial-condition effects.

The disclosure broadens the affected actors and misuse scope and adds distinct consequences, including regulatory scrutiny and service disruptions, changing the substance of the risk.

Filing text · FY2025 10-K · filed Jul 30, 2025

Our [removed] AI systems offer users powerful tools and capabilities. However, there may be [removed] instances where these systems are used in ways that are unintended or inappropriate. In addition, some users may also engage in fraudulent or abusive activities through our cloud-based and AI services, such as unauthorized account access, payment fraud, or terms of service violations including cryptocurrency mining or launching cyberattacks. While we are committed to detecting and controlling such misuse [removed] of our cloud-based and AI services, our efforts may not be [removed] effective, and we may incur reputational damage or experience adverse impacts [removed] to our business and results of operations.

Filing text · FY2026 10-K · filed Jul 29, 2026

Our [added] cloud-based and AI products and services may be [added] misused by customers, users, or malicious actors for unintended, fraudulent, abusive, or unlawful purposes. Our efforts to detect, prevent, and mitigate such misuse may not be [added] successful, which could result in reputational harm, regulatory scrutiny, service disruptions, or adverse impacts [added] on our business, financial condition, and results of operations.

Cite this change

"Our cloud-based and AI products and services may be misused by customers, users, or malicious actors for unintended, fraudulent, abusive, or unlawful purposes."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

14ChangedItem 1A › STRATEGIC AND COMPETITIVE RISKS › We face intense competition across all markets for our products and services, which could adversely affect our results of operations.

Summary · quote-checked

The disclosure adds making cloud-based and AI products and services platform-agnostic as a stated competitive requirement, and expands the scope from services to products and services.

This adds a substantive strategic requirement beyond maintaining performance and compatibility, changing what the company identifies as necessary to address competitive risk.

Filing text · FY2025 10-K · filed Jul 30, 2025

[removed] Maintaining the utility, compatibility, and performance of our cloud-based and AI services on the growing array of computing devices, including PCs, smartphones, tablets, gaming consoles, and other devices.

Filing text · FY2026 10-K · filed Jul 29, 2026

[added] Making our suite of cloud-based and AI products and services platform-agnostic and maintaining the utility, compatibility, and performance of our cloud-based and AI [added] products and services on the growing array of computing devices, including PCs, smartphones, tablets, gaming consoles, and other devices.

Cite this change

"Making our suite of cloud-based and AI products and services platform-agnostic and maintaining the utility, compatibility, and performance of our cloud-based and AI products and services on the growing array of computing devices, including PCs, smartphones, tablets, gaming consoles, and other devices."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

15ChangedItem 1A › STRATEGIC AND COMPETITIVE RISKS › We face intense competition across all markets for our products and services, which could adversely affect our results of operations.

Summary · quote-checked

The AI disclosure removes significant development-cost obligations and adds competition from hyperscalers, open-source offerings, frontier providers, and potential partners.

The paragraph changes the disclosed AI risk by removing a cost obligation and adding named competitive sources and partner dependencies, altering the substance of the risk.

Filing text · FY2025 10-K · filed Jul 30, 2025

We are investing in [removed] artificial intelligence ("AI") across the entire company and infusing [removed] generative AI capabilities into our [removed] consumer and commercial offerings. AI technology and services are a highly competitive and rapidly evolving market, and new competitors continue to enter the market. [removed] We will bear significant development and operational costs to build and support the AI models, services, platforms, and infrastructure necessary to meet the needs of our customers. To compete effectively we must also be responsive to technological change, new and potential regulatory developments, and public scrutiny.

Filing text · FY2026 10-K · filed Jul 29, 2026

We are investing in [added] AI across the entire company and infusing AI capabilities into our offerings. AI technology and services are a highly competitive and rapidly evolving market, and new competitors continue to enter the market. [added] Our AI offerings compete with AI products from hyperscalers, open-source offerings, and frontier model providers, some of which are also current or potential partners. To compete effectively we must also be responsive to technological change, new and potential regulatory developments, and public scrutiny.

Cite this change

"Our AI offerings compete with AI products from hyperscalers, open-source offerings, and frontier model providers, some of which are also current or potential partners."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

16ChangedItem 1A › LEGAL, REGULATORY, AND LITIGATION RISKS

Summary · quote-checked

The ESG risk disclosure adds permitting and operational requirements, potential investment and cost impacts, and AI-related energy and emissions challenges to sustainability goals.

The paragraph adds new regulatory obligations, possible significant investments and unexpected costs, and a changed risk mechanism linking AI development to sustainability goals.

Filing text · FY2025 10-K · filed Jul 30, 2025

Environmental, Social, and Governance: Laws, regulations, and policies relating to environmental, social, and governance matters are being developed and formalized in Europe, the U.S., and elsewhere, which may include greenhouse gas emissions and energy usage caps, as well as specific, target-driven environmental, social, and governance frameworks and disclosure requirements. In addition, in 2020 we announced goals to become carbon negative, water positive, and zero waste by 2030. Any failure or perceived failure to meet our sustainability goals, or to meet various sustainability regulatory requirements, could result in claims and lawsuits, regulatory actions, penalties, or damage to our reputation, each of which could adversely affect our business, operations, financial condition, and results of operations.

Filing text · FY2026 10-K · filed Jul 29, 2026

Environmental, Social, and Governance: Laws, regulations, and policies relating to environmental, social, and governance matters are being developed and formalized in Europe, the U.S., and elsewhere, which may include greenhouse gas emissions and energy usage caps, [added] permitting, reporting, procurement, operational, and infrastructure-siting requirements as well as specific, target-driven environmental, social, and governance frameworks and disclosure requirements. [added] These laws, regulations, and policies may require significant investments or operational changes and may result in new or unexpected costs. In addition, in 2020 we announced goals to become carbon negative, water positive, and zero waste by 2030. [added] AI development and deployment has and will likely continue to raise energy use and emissions, making it harder to meet these goals. Any failure or perceived failure to meet our sustainability goals, or to meet various sustainability regulatory requirements, could result in claims and lawsuits, regulatory actions, penalties, or damage to our reputation, each of which could adversely affect our business, operations, financial condition, and results of operations.

Cite this change

"AI development and deployment has and will likely continue to raise energy use and emissions, making it harder to meet these goals."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

17ChangedItem 1A › OPERATIONAL RISKS

Summary · quote-checked

The risk expands to datacenters, changes Xbox capitalization, and removes specific recall, safety-alert, and product-liability consequences.

Adding datacenters broadens the affected assets, while removing specific consequences changes the disclosed risk and its potential outcomes.

Filing text · FY2025 10-K · filed Jul 30, 2025

Our hardware products such as [removed] Xbox consoles, Surface devices, and other devices we design and market are highly complex. Failure to prevent, detect, or address defects in design, manufacture, or associated software could [removed] result in recalls, safety alerts, or product liability claims, which could adversely affect our business and results of operations.

Filing text · FY2026 10-K · filed Jul 29, 2026

Our [added] datacenters and our hardware products such as [added] XBOX consoles, Surface devices, and other devices we design and market are highly complex. Failure to prevent, detect, or address defects in design, manufacture, or associated software could adversely affect our business and results of operations.

Cite this change

"Our datacenters and our hardware products such as XBOX consoles, Surface devices, and other devices we design and market are highly complex. Failure to prevent, detect, or address defects in design, manufacture, or associated software could adversely affect our business and results of operations."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

18ChangedItem 1A › OPERATIONAL RISKS

Summary · quote-checked

The risk disclosure shifts from outages and service disruptions to infrastructure expansion, while removing several dependency and regulatory-constraint details.

The paragraph changes the stated risk and removes substantive risks involving data loss, energy and infrastructure dependencies, environmental regulation, geopolitical disruption, and evolving regulatory constraints.

Filing text · FY2025 10-K · filed Jul 30, 2025

We may [removed] have excessive outages, data losses, and disruptions of our online services if we fail to maintain an adequate operations infrastructure. Our increasing user traffic, growth in services, and the complexity of our products and services demand more computing power. We spend substantial amounts to build, purchase, or lease datacenters and equipment and to upgrade our technology and network [removed] infrastructure to handle more traffic on our websites and in our datacenters. Our datacenters depend on the availability of permitted and buildable land, predictable energy, networking supplies, and servers, including graphics processing units and other components. [removed] The cost or availability of these dependencies could be adversely affected by a variety of factors, including the transition to a clean energy economy, local and regional environmental regulations, and geopolitical disruptions. These demands continue to increase as we introduce new products and services and support the growth and the augmentation of existing services, [removed] including through the incorporation of AI features and/or functionality. We are rapidly growing our business of providing a platform and back-end hosting for services provided by third parties to their end users. [removed] Maintaining, securing, and expanding this infrastructure is expensive and complex, and requires development of principles for datacenter builds in geographies with higher safety and reliability risks. [removed] It requires that we maintain an Internet connectivity infrastructure and storage and compute capacity that is robust and reliable within competitive and regulatory constraints that continue to evolve. Inefficiencies or operational failures, including temporary or permanent loss of customer data, outages, insufficient Internet connectivity, insufficient or unavailable power or water supply, or inadequate storage and compute capacity could diminish the quality of our products, services, and user experience, resulting in contractual liability, claims by customers and other third parties, regulatory actions, damage to our reputation, and loss of current and potential users, subscribers, and advertisers, each of which could adversely affect our business, operations, financial condition, and results of operations.

Filing text · FY2026 10-K · filed Jul 29, 2026

We may [added] be unable to develop and expand adequate infrastructure. Our increasing user traffic, [added] our growth in services, and the complexity of our products and services demand more [added] infrastructure capacity and computing power. We [added] have spent and will continue to spend substantial amounts to build, purchase, or lease datacenters and equipment and to upgrade our technology and network [added] infrastructure. Our infrastructure capacity depends on the availability of permitted and buildable land, predictable [added] and affordable energy, networking supplies, and servers, including graphics processing units and other components. These demands continue to increase as we introduce new products and services and support the growth and the augmentation of existing services, [added] and scale further the incorporation of AI features and/or functionality. We are rapidly growing our business of providing a platform and back-end hosting for services provided by third parties to their end users. [added] In addition, infrastructure in certain geographies carries higher safety and reliability risks. [added] Maintaining, securing, and expanding our infrastructure globally is expensive and complex.

Cite this change

"We may be unable to develop and expand adequate infrastructure."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

19ChangedItem 1A › STRATEGIC AND COMPETITIVE RISKS › We face intense competition across all markets for our products and services, which could adversely affect our results of operations.

Summary · quote-checked

The risk now expressly covers AI services in addition to cloud-based services.

A newly named service category is tied to reliability, security, and customer compliance requirements, expanding the scope of the disclosed risk.

Filing text · FY2025 10-K · filed Jul 30, 2025

Ensuring our cloud-based services meet the reliability expectations and specific requirements of our customers and maintain the security of their data as well as help them meet their own compliance needs.

Filing text · FY2026 10-K · filed Jul 29, 2026

Ensuring our cloud-based [added] and AI services meet the reliability expectations and specific requirements of our customers and maintain the security of their data as well as help them meet their own compliance needs.

Cite this change

"Ensuring our cloud-based and AI services meet the reliability expectations and specific requirements of our customers and maintain the security of their data as well as help them meet their own compliance needs."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

20ChangedItem 1A › CYBERSECURITY, DATA PRIVACY, AND PLATFORM ABUSE RISKS › Cyberattacks and security vulnerabilities could lead to reduced revenue, increased costs, liability claims, or harm to our reputation or competitive position.

Summary · quote-checked

Added a disclosure that rapidly evolving AI technologies may outpace security products, controls, and standards, increasing the risk of insufficient measures against emerging threats.

The paragraph adds a new AI-specific cybersecurity risk and states that security measures may be insufficient against newly emerging threats, substantively expanding the disclosed exposure.

Filing text · FY2025 10-K · filed Jul 30, 2025

Our customers operate complex systems with third-party hardware and software from multiple vendors that may include systems acquired over many years. They expect our products and services to support all these systems and products, including those that no longer incorporate the strongest current security advances or standards. As a result, we may not be able to discontinue support [removed] in our services for a product, service, standard, or feature solely because a more secure alternative is available. Failure to utilize the most current security advances and standards can increase our customers' vulnerability to attack. Further, [removed] customers of widely varied sizes and technical sophistication use our technology, and consequently may still have limited capabilities and resources to help them adopt and implement state-of-the-art cybersecurity practices and technologies. In addition, we must account for this wide variation of technical sophistication when defining default settings for our products and services, including security default settings, as these settings may limit or otherwise impact other aspects of operations and some customers may have limited capability to review and reset these defaults.

Filing text · FY2026 10-K · filed Jul 29, 2026

Our customers operate complex systems with third-party hardware and software from multiple vendors that may include systems acquired over many years. They expect our products and services to support all these systems and products, including those that no longer incorporate the strongest current security advances or standards. As a result, we may not be able to discontinue support [added] of our services for a product, service, standard, or feature solely because a more secure alternative is available. Failure to utilize the most current security advances and standards can increase our customers' vulnerability to attack. Further, [added] the rapid evolution of AI technologies and use cases may outpace the development, deployment, and effectiveness of security products, controls, and industry standards, particularly in complex customer environments, increasing the risk that security measures will be insufficient to address newly emerging threats. Customers of widely varied sizes and technical sophistication use our technology, and consequently may still have limited capabilities and resources to help them adopt and implement state-of-the-art cybersecurity practices and technologies. In addition, we must account for this wide variation of technical sophistication when defining default settings for our products and services, including security default settings, as these settings may limit or otherwise impact other aspects of operations and some customers may have limited capability to review and reset these defaults.

Cite this change

"Further, the rapid evolution of AI technologies and use cases may outpace the development, deployment, and effectiveness of security products, controls, and industry standards, particularly in complex customer environments, increasing the risk that security measures will be insufficient to address newly emerging threats."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

21ChangedItem 1A › CYBERSECURITY, DATA PRIVACY, AND PLATFORM ABUSE RISKS › Cyberattacks and security vulnerabilities could lead to reduced revenue, increased costs, liability claims, or harm to our reputation or competitive position.

Summary · quote-checked

The paragraph broadens affected systems and attack methods, adds suppliers and AI-assisted techniques, and removes the detailed nation-state incident example.

These changes alter the described cybersecurity exposure and remove a specific prior incident disclosure, going beyond wording or routine updates.

Filing text · FY2025 10-K · filed Jul 30, 2025

Threats to security can take a variety of forms. Threat actors, including individual and groups of hackers and sophisticated organizations, including nation-states, state-sponsored organizations, or cybercriminal groups, continuously undertake attacks that pose threats to our customers and our internal infrastructure, and we have experienced cybersecurity incidents in which such actors have gained unauthorized access to our systems and data, [removed] including customer systems and data. These actors use a wide variety of methods, which include developing and deploying malicious software; exploiting [removed] known and potential vulnerabilities or intentionally designed processes in our or third-party hardware, software, or other infrastructure to attack our products and services or gain access to our networks and datacenters; using social engineering techniques to induce our employees, users, partners, or customers to disclose sensitive information, such as passwords, or take other actions to gain access to our data or our users' or customers' data; or acting in a coordinated manner or conducting coordinated attacks. For example, as previously disclosed in our Form 8-K filed with the Securities and Exchange[removed] Commission on January 19, 2024 and amended on March 8, 2024, beginning in late November 2023, a nation-state associated threat actor used a password spray attack to compromise a legacy test account and, in turn, gain access to Microsoft email accounts. The threat actor used information it obtained to gain unauthorized access to some of our source code repositories and internal systems, and the threat actor could continue to utilize this and other information to attempt to gain access to our systems or otherwise adversely affect our business and results of operations. This incident has and may continue to result in harm to our reputation and customer relationships. Nation-state and state-sponsored actors can sustain malicious activities for extended periods and deploy significant resources to plan and carry out attacks. Nation-state attacks against us, our customers, or our partners have and may continue to intensify due to our transparency to our customers, other stakeholders, and the public about cyberattacks, and during elections or periods of intense diplomatic or armed conflict. Challenges or failures in applying security patches to all hardware and devices connected to our systems, including end-of-life and end-of-support equipment, have and may continue to result in unauthorized access to our systems and data in the future. Cyber incidents and attacks, individually or in the aggregate, could adversely affect our financial condition, results of operations, competitive position, and reputation, or expose us to legal or regulatory risk.

Filing text · FY2026 10-K · filed Jul 29, 2026

Threats to security can take a variety of forms. Threat actors, including individual and groups of hackers and sophisticated organizations, including nation-states, state-sponsored organizations, or cybercriminal groups, continuously undertake attacks that pose threats to our customers and our internal infrastructure, and we have experienced cybersecurity incidents in which such actors have gained unauthorized access to our systems and data, [added] as well as customer, partner, and supplier systems and data. These actors use a wide variety of methods, which include developing and deploying malicious software; exploiting [added] known, latent, or potential vulnerabilities or intentionally designed processes in our or third-party hardware, software, or other infrastructure to attack our products and services or gain access to our networks and datacenters; using social engineering [added] and AI-assisted techniques to induce our employees, users, partners, [added] suppliers, or customers to disclose sensitive information, such as passwords, or take other actions to gain access to our data or our users' or customers' data; or acting in a coordinated manner or conducting coordinated attacks. For example, as previously disclosed in our Form 8-K filed with the Securities and Exchange Commission on January 19, 2024 and amended on March 8, 2024, beginning in late November 2023, a nation-state associated threat actor used a password spray attack to compromise a legacy test account and, in turn, gain access to Microsoft email accounts. The threat actor used information it obtained to gain unauthorized access to some of our source code repositories and internal systems, and the threat actor could continue to utilize this and other information to attempt to gain access to our systems or otherwise adversely affect our business and results of operations. This incident has and may continue to result in harm to our reputation and customer relationships. Nation-state and state-sponsored actors can sustain malicious activities for extended periods and deploy significant resources to plan and carry out attacks. Nation-state attacks against us, our customers, suppliers, or partners have and may continue to intensify due to our transparency to our customers, other stakeholders, and the public about cyberattacks, and during elections or periods of intense diplomatic or armed conflict. Challenges or failures to update or apply security patches to all hardware and devices connected to our systems, including end-of-life and end-of-support equipment, have and may continue to result in unauthorized access to our systems and data in the future. Cyber incidents and attacks, individually or in the aggregate, could adversely affect our financial condition, results of operations, competitive position, and reputation, or expose us to legal or regulatory risk.

Cite this change

"Threat actors, including individual and groups of hackers and sophisticated organizations, including nation-states, state-sponsored organizations, or cybercriminal groups, continuously undertake attacks that pose threats to our customers and our internal infrastructure, and we have experienced cybersecurity incidents in which such actors have gained unauthorized access to our systems and data, as well as customer, partner, and supplier systems and data."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

22ChangedItem 1A › OPERATIONAL RISKS

Summary · quote-checked

The paragraph adds AI and other software to the quality-risk disclosure and removes the statement that customer reliance is increasing.

Naming AI products ties a specific product category to quality and reliability risks, while removing “increasingly” changes the stated customer-reliance trend.

Filing text · FY2025 10-K · filed Jul 30, 2025

[removed] Our software products and services also have and may in the future experience quality or reliability problems. The processes we use to develop our software are imperfect. Like all software, our software contains bugs and other defects that interfere with their intended operation. Our customers [removed] increasingly rely on us for critical business functions and multiple workloads. Many of our products and services are interdependent on one another. Our products and services may be impacted by interaction with third-party products and services. Our customers may also utilize their own or third-party products and services whose reliability is dependent on interaction with our products and services. Each of these circumstances potentially magnifies the impact of quality or reliability issues. Weaknesses in our processes could result in defects we do not detect and fix in pre-release testing, which could cause reduced sales, damage to our reputation, repair or remediation costs, delays in the release of new products or versions, or legal liability, [removed] and could adversely affect our business, financial condition, and results of operations. Although our license agreements typically contain provisions that eliminate or limit our exposure to liability, [removed] there is no assurance these provisions [removed] will withstand legal challenge.

Filing text · FY2026 10-K · filed Jul 29, 2026

[added] We may experience other quality problems. Our AI and other software products and services also have and may in the future experience quality or reliability problems. The processes we use to develop our software are imperfect. Like all software, our software contains bugs and other defects that interfere with their intended operation. Our customers rely on us for critical business functions and multiple workloads. Many of our products and services are interdependent on one another. Our products and services may be impacted by interaction with third-party products and services. Our customers may also utilize their own or third-party products and services whose reliability is dependent on interaction with our products and services. Each of these circumstances potentially magnifies the impact of quality or reliability issues. Weaknesses in our processes could result in defects we do not detect and fix in pre-release testing, which could cause reduced sales, damage to our reputation, repair or remediation costs, delays in the release of new products or versions, or legal liability, [added] any of which could adversely affect our business, financial condition, and results of operations. Although our license agreements typically contain provisions that eliminate or limit our exposure to liability, these provisions [added] may not withstand legal challenge.

Cite this change

"We may experience other quality problems. Our AI and other software products and services also have and may in the future experience quality or reliability problems."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

23ChangedItem 1A › LEGAL, REGULATORY, AND LITIGATION RISKS

Summary · quote-checked

The AI regulatory risk now includes potential government restrictions and additional regulatory areas, while rephrasing the description of evolving legislative action.

The added sentence introduces possible restrictions on advanced AI models and broader government intervention, substantively expanding the disclosed regulatory risks beyond wording changes.

Filing text · FY2025 10-K · filed Jul 30, 2025

AI: Legislative and regulatory action is [removed] emerging in AI, which could increase costs or restrict opportunity. For example, the EU's AI Act may increase costs or impact the provision or operation of our AI models and services in the European market. AI regulatory areas include model and system development and deployment, frontier model safety, transparency, [removed] and content provenance.

Filing text · FY2026 10-K · filed Jul 29, 2026

AI: Legislative and regulatory action is [added] evolving with respect to AI, which could increase costs or restrict opportunity. For example, the EU's AI Act may increase costs or impact the provision or operation of our AI models and services in the European market. [added] In addition, governments may impose restrictions on the development, deployment, availability, or cross-border access to advanced AI models based on safety, cybersecurity, or national security or may apply laws to AI models in ways we cannot anticipate. AI regulatory areas include model and system development and deployment, frontier model safety, transparency, [added] content provenance, digital replicas, and AI companions.

Cite this change

"In addition, governments may impose restrictions on the development, deployment, availability, or cross-border access to advanced AI models based on safety, cybersecurity, or national security or may apply laws to AI models in ways we cannot anticipate."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

24ChangedItem 1A › INTELLECTUAL PROPERTY RISKS

Summary · quote-checked

The disclosure broadens the trade-secret risk from source-code leaks to unauthorized access or disclosure of source code or other intellectual property.

The revised language changes the triggering event and extends the potential loss of future trade-secret protection beyond source code, altering the disclosed risk’s scope.

Filing text · FY2025 10-K · filed Jul 30, 2025

Source code, the detailed program commands for our [removed] operating systems and other software programs, is critical to our business. [removed] If our source code [removed] leaks, we might lose future trade secret protection for that [removed] code. It may then become easier for third parties to compete with our products by copying functionality, which could adversely affect our results of operations. Unauthorized access to or disclosure of source code or other intellectual property also increases the security risks described elsewhere in these risk factors.

Filing text · FY2026 10-K · filed Jul 29, 2026

Source code, the detailed program commands for our software programs, is critical to our business. [added] Unauthorized access to or disclosure of source code [added] or other intellectual property may negatively impact future trade secret protection for that [added] intellectual property. It may then become easier for third parties to compete with our products by copying functionality, which could adversely affect our results of operations. Unauthorized access to or disclosure of source code or other intellectual property also increases the security risks described elsewhere in these risk factors.

Cite this change

"Unauthorized access to or disclosure of source code or other intellectual property may negatively impact future trade secret protection for that intellectual property."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

25ChangedItem 1A › OPERATIONAL RISKS

Summary · quote-checked

The risk now specifically includes inefficient operation of cloud-based and AI products and services, and expands quality concerns to actual or perceived quality.

The added cloud-based and AI infrastructure failure scenario introduces a specifically named operational dependency; the quality wording is clarifying but the mixed change is material.

Filing text · FY2025 10-K · filed Jul 30, 2025

We may have excessive outages, data losses, and disruptions of our online services if we fail to maintain an adequate operations infrastructure. Our increasing user traffic, growth in services, and the complexity of our products and services demand more computing power. We spend substantial amounts to build, purchase, or lease datacenters and equipment and to upgrade our technology and network infrastructure to handle more traffic on our websites and in our datacenters. Our datacenters depend on the availability of permitted and buildable land, predictable energy, networking supplies, and servers, including graphics processing units and other components. The cost or availability of these dependencies could be adversely affected by a variety of factors, including the transition to a clean energy economy, local and regional environmental regulations, and geopolitical disruptions. These demands continue to increase as we introduce new products and services and support the growth and the augmentation of existing services, including through the incorporation of AI features and/or functionality. We are rapidly growing our business of providing a platform and back-end hosting for services provided by third parties to their end users. Maintaining, securing, and expanding this infrastructure is expensive and complex, and requires development of principles for datacenter builds in geographies with higher safety and reliability risks. It requires that we maintain an Internet connectivity infrastructure and storage and compute capacity that is robust and reliable within competitive and regulatory constraints that continue to evolve. Inefficiencies or operational failures, including temporary or permanent loss of customer data, outages, insufficient Internet connectivity, insufficient or unavailable power or water supply, or inadequate storage and compute capacity could diminish the quality of our products, services, and user experience, resulting in contractual liability, claims by customers and other third parties, regulatory actions, damage to our reputation, and loss of current and potential users, subscribers, and advertisers, each of which could adversely affect our business, operations, financial condition, and results of operations.

Filing text · FY2026 10-K · filed Jul 29, 2026

Inefficiencies or operational failures, including temporary or permanent loss of customer data, outages, insufficient Internet connectivity, insufficient or unavailable power or water supply, [added] inefficient operation of our of our cloud-based and AI products and services on our infrastructure, or inadequate storage and compute capacity could diminish the [added] actual or perceived quality of our products, services, and user experience, resulting in contractual liability, claims by customers and other third parties, regulatory actions, damage to our reputation, and loss of current and potential users, subscribers, and advertisers, each of which could adversely affect our business, operations, financial condition, and results of operations.

Cite this change

"Inefficiencies or operational failures, including temporary or permanent loss of customer data, outages, insufficient Internet connectivity, insufficient or unavailable power or water supply, inefficient operation of our of our cloud-based and AI products and services on our infrastructure, or inadequate storage and compute capacity could diminish the actual or perceived quality of our products, services, and user experience, resulting in contractual liability, claims by customers and other third parties, regulatory actions, damage to our reputation, and loss of current and potential users, subscribers, and advertisers, each of which could adversely affect our business, operations, financial condition, and results of operations."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

26ChangedItem 1A › CYBERSECURITY, DATA PRIVACY, AND PLATFORM ABUSE RISKS › Cyberattacks and security vulnerabilities could lead to reduced revenue, increased costs, liability claims, or harm to our reputation or competitive position.

Summary · quote-checked

The cybersecurity risk expands from generative AI models to broader AI technologies used in internal or third-party systems and adopts broader regulatory language.

The paragraph newly identifies algorithms, copilots, autonomous agents, and third-party systems as potential attack surfaces, substantively expanding the described exposure beyond wording changes.

Filing text · FY2025 10-K · filed Jul 30, 2025

Our internal environment continues to evolve. Often, we are early adopters of new devices and technologies. We embrace new ways of sharing data and communicating internally and with partners and customers using methods such as social networking and other consumer-oriented technologies. Increasing use of [removed] generative AI models in our internal systems may create new attack surfaces or methods for adversaries. Our business policies and internal security controls may not keep pace with [removed] these changes as new threats emerge or the [removed] emerging cybersecurity regulations in jurisdictions worldwide.

Filing text · FY2026 10-K · filed Jul 29, 2026

Our internal environment continues to evolve. Often, we are early adopters of new devices and technologies. We embrace new ways of sharing data and communicating internally and with partners and customers using methods such as social networking and other consumer-oriented technologies. Increasing use of [added] AI, including models, algorithms, copilots, and autonomous or semi-autonomous agents, in our internal [added] or third-party systems may create new attack surfaces or methods for adversaries. Our business policies and internal security controls may not keep pace with [added] emerging threats or the [added] evolving regulatory landscape.

Cite this change

"Increasing use of AI, including models, algorithms, copilots, and autonomous or semi-autonomous agents, in our internal or third-party systems may create new attack surfaces or methods for adversaries."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

27ChangedItem 1A › STRATEGIC AND COMPETITIVE RISKS › We face intense competition across all markets for our products and services, which could adversely affect our results of operations.

Summary · quote-checked

The competition disclosure shifts from stating significant platform competition to warning that competitors may hinder customer attraction and retention.

The revised sentence changes both the asserted competition description and its potential consequence, adding a specific customer acquisition and retention risk with changed modality.

Filing text · FY2025 10-K · filed Jul 30, 2025

An important element of our business model has been to create platform-based ecosystems on which many participants can build diverse solutions. A well-established ecosystem creates beneficial network effects among users, application developers, and the platform provider that can accelerate growth. Establishing significant scale in the marketplace is necessary to meet consumer demand and to achieve and maintain attractive margins. [removed] We face significant competition from firms that provide competing platforms.

Filing text · FY2026 10-K · filed Jul 29, 2026

An important element of our business model has been to create platform-based ecosystems on which many participants can build diverse solutions. A well-established ecosystem creates beneficial network effects among users, application developers, and the platform provider that can accelerate growth. Establishing significant scale in the marketplace is necessary to meet consumer demand and to achieve and maintain attractive margins. [added] Firms offering competing platforms may make it more difficult to attract and retain customers.

Cite this change

"Firms offering competing platforms may make it more difficult to attract and retain customers."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

28ChangedItem 1A › STRATEGIC AND COMPETITIVE RISKS › We face intense competition across all markets for our products and services, which could adversely affect our results of operations.

Summary · quote-checked

The paragraph no longer states that pricing and delivery models are evolving.

The deletion removes a substantive description of changing market conditions, rather than merely rephrasing or rolling forward boilerplate.

Filing text · FY2025 10-K · filed Jul 30, 2025

A material part of our business involves cloud-based services available across the spectrum of computing devices. We and our competitors continue to devote significant resources to developing and deploying cloud-based strategies and services for consumers and business [removed] customers, and pricing and delivery models are evolving.

Filing text · FY2026 10-K · filed Jul 29, 2026

A material part of our business involves cloud-based services available across the spectrum of computing devices. We and our competitors continue to devote significant resources to developing and deploying cloud-based strategies and services for consumers and business [added] customers.

Cite this change

"We and our competitors continue to devote significant resources to developing and deploying cloud-based strategies and services for consumers and business customers."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

29ChangedItem 1A › CYBERSECURITY, DATA PRIVACY, AND PLATFORM ABUSE RISKS › Cyberattacks and security vulnerabilities could lead to reduced revenue, increased costs, liability claims, or harm to our reputation or competitive position.

Summary · quote-checked

The risk disclosure adds increasing use of agentic AI as a source of limitations on preventing third-party scraping.

The paragraph changes the stated cause and removes the tentative “may weaken” formulation, tying the risk to a newly identified technology-related driver.

Filing text · FY2025 10-K · filed Jul 30, 2025

We may not be able to protect information in our products and services from use by others. LinkedIn and other Microsoft products and services contain valuable information and content protected by contractual restrictions or technical measures. In certain cases, we have made commitments to our members and users to limit access to or use of this information. [removed] Changes in the law or interpretations of the law may weaken our ability to prevent third parties from scraping or gathering information or content through use of bots or other measures and using it for their own benefit [removed] which could adversely affect our business, financial condition, and results of operations.

Filing text · FY2026 10-K · filed Jul 29, 2026

We may not be able to protect information in our products and services from use by others. LinkedIn and other Microsoft products and services contain valuable information and content protected by contractual restrictions or technical measures. In certain cases, we have made commitments to our members and users to limit access to or use of this information. [added] Limitations on our ability to prevent third parties from scraping or gathering information or content through use of bots or other measures and using it for their own benefit [added] due to, among other things, changes in the law, interpretations of law, or increasing use of agentic AI, could adversely affect our business, financial condition, and results of operations.

Cite this change

"Limitations on our ability to prevent third parties from scraping or gathering information or content through use of bots or other measures and using it for their own benefit due to, among other things, changes in the law, interpretations of law, or increasing use of agentic AI, could adversely affect our business, financial condition, and results of operations."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

30ChangedItem 1A › GENERAL RISKS

Summary · quote-checked

The risk disclosure adds economic and customer-spending factors and states that IT spending may be delayed, not merely reduced.

The paragraph expands the identified drivers of adverse conditions and changes the potential effect on IT spending, substantively broadening the disclosed risk.

Filing text · FY2025 10-K · filed Jul 30, 2025

Adverse economic or market conditions could harm our business. Worsening economic conditions, including inflation, recession, pandemic, or other changes in economic conditions, may cause lower IT spending and adversely affect our results of operations. If demand for computing power, PCs, servers, and other computing devices declines, or consumer or business spending for those products declines, our results of operations could be adversely affected.

Filing text · FY2026 10-K · filed Jul 29, 2026

Adverse economic or market conditions could harm our business. Worsening economic conditions, including inflation, recession, pandemic, or other changes in economic conditions, [added] periods of economic uncertainty, evolution of customer demand, technology investment cycles, interest rates, foreign exchange rates, or the timing and mix of customer spending, may cause lower [added] or delayed IT spending and adversely affect our results of operations. If demand for computing power, PCs, servers, and other computing devices declines, or consumer or business spending for those products declines, our results of operations could be adversely affected.

Cite this change

"Worsening economic conditions, including inflation, recession, pandemic, or other changes in economic conditions, periods of economic uncertainty, evolution of customer demand, technology investment cycles, interest rates, foreign exchange rates, or the timing and mix of customer spending, may cause lower or delayed IT spending and adversely affect our results of operations."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

31ChangedItem 1A › GENERAL RISKS

Summary · quote-checked

The risk now covers conflicts in the Middle East and general supply-chain disruptions rather than disruptions specifically affecting hardware manufacturers.

A newly named regional conflict is tied to the risk, and the stated supply-chain disruption exposure is broadened by removing the specific hardware-manufacturer reference.

Filing text · FY2025 10-K · filed Jul 30, 2025

Abrupt political change, terrorist activity, and armed conflict, such as the [removed] ongoing conflict in Ukraine, pose economic and other risks, which may negatively impact our ability to sell to and collect from customers, increase our operating costs, or otherwise disrupt our operations in markets both directly and indirectly impacted by such events. These conditions also may add uncertainty to the timing and budget for technology investment decisions by our customers and may cause supply chain [removed] disruptions for hardware manufacturers. Geopolitical change may result in changing regulatory systems and requirements and market interventions that could impact our operating strategies, access to national, regional, and global markets, hiring, and profitability. Geopolitical instability may lead to sanctions and impact our ability to do business in some markets or with some public-sector customers. Any of these changes could adversely affect our results of operations. Changes in geopolitical conditions also increase the security risks described elsewhere in these risk factors.

Filing text · FY2026 10-K · filed Jul 29, 2026

Abrupt political change, terrorist activity, and armed conflict, such as the [added] conflicts in Ukraine and the Middle East, pose economic and other risks, which may negatively impact our ability to sell to and collect from customers, increase our operating costs, or otherwise disrupt our operations in markets both directly and indirectly impacted by such events. These conditions also may add uncertainty to the timing and budget for technology investment decisions by our customers and may cause supply chain [added] disruptions. Geopolitical change may result in changing regulatory systems and requirements and market interventions that could impact our operating strategies, access to national, regional, and global markets, hiring, and profitability. Geopolitical instability may lead to sanctions and impact our ability to do business in some markets or with some public-sector customers. Any of these changes could adversely affect our results of operations. Changes in geopolitical conditions also increase the security risks described elsewhere in these risk factors.

Cite this change

"Abrupt political change, terrorist activity, and armed conflict, such as the conflicts in Ukraine and the Middle East, pose economic and other risks, which may negatively impact our ability to sell to and collect from customers, increase our operating costs, or otherwise disrupt our operations in markets both directly and indirectly impacted by such events."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

32ChangedItem 1A › STRATEGIC AND COMPETITIVE RISKS › We face intense competition across all markets for our products and services, which could adversely affect our results of operations.

Summary · quote-checked

The paragraph expands the vertically integrated model risk to include proprietary hardware, infrastructure, AI models, and operational risks.

The disclosure adds specific capabilities and a new operational-risk exposure, while changing the stated cost and margin consequences.

Filing text · FY2025 10-K · filed Jul 30, 2025

A competing vertically-integrated model, in which a single firm controls the hardware and software elements of a product and related services, has succeeded with some consumer products such as PCs, tablets, smartphones, gaming consoles, wearables, and other endpoint devices. Competitors pursuing this model also earn revenue from services integrated with the hardware and software platform, including applications and content sold through their integrated marketplaces. They may also be able to claim security and performance benefits from their vertically-integrated offer. We also offer some vertically-integrated hardware and software products and services. [removed] Shifting a portion of our [removed] business to a vertically-integrated model may increase our cost [removed] of revenue and reduce our operating margins.

Filing text · FY2026 10-K · filed Jul 29, 2026

A competing vertically-integrated model, in which a single firm controls the hardware and software elements of a product and related services, has succeeded with some consumer products such as PCs, tablets, smartphones, gaming consoles, wearables, and other endpoint devices. Competitors pursuing this model also earn revenue from services integrated with the hardware and software platform, including applications and content sold through their integrated marketplaces. They may also be able to claim security and performance benefits from their vertically-integrated offer. We also offer some vertically-integrated hardware and software products and services. [added] Expansion of our [added] vertically-integrated capabilities, including developing proprietary hardware, infrastructure, and artificial intelligence ("AI") models, could increase our cost [added] structure, reduce margins, and expose us to operational risks.

Cite this change

"Expansion of our vertically-integrated capabilities, including developing proprietary hardware, infrastructure, and artificial intelligence ("AI") models, could increase our cost structure, reduce margins, and expose us to operational risks."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

33ChangedItem 1A › LEGAL, REGULATORY, AND LITIGATION RISKS

Summary · quote-checked

Trade-risk disclosure changes sanction language, adds government disagreements as a cost driver, and removes a specific AI rulemaking risk.

The paragraph changes certainty about sanctions, adds a new sanctions-policy risk and associated effects, and removes a named AI regulatory risk, altering the disclosed exposure.

Filing text · FY2025 10-K · filed Jul 30, 2025

Trade: Increasing trade laws, policies, sanctions, and other regulatory requirements also affect our operations in and outside the U.S. relating to trade and investment. Economic sanctions in the U.S., the EU, and other countries [removed] prohibit most business with restricted entities or countries. U.S. export controls restrict Microsoft from offering many of its products and services to, or making investments in, certain entities in specified countries. U.S. import controls restrict us from integrating certain information and communication technologies into our supply chain and allow for government review of transactions involving information and communications technology from countries determined to be foreign adversaries. Supply chain regulations may impact the availability of goods or result in additional regulatory scrutiny. Restrictions on data flows and outbound investment and customer sensitivities may limit our ability to leverage parts of our global engineering footprint to provide services in certain jurisdictions. Increased geopolitical instabilities and changing U.S. Administration priorities create an unpredictable trade landscape. U.S. [removed] tariff and shifting AI export controls policies, [removed] like the AI Diffusion Rule, could increase operational costs, create uncertainty in the continuity of our products, and accelerate sovereignty initiatives among international partners and customers. The volatility of U.S. tariffs has triggered economic uncertainty and could impact cloud and devices supply chain cost competitiveness.[removed] The potential replacement of the recently rescinded AI Diffusion Rule and other potential AI-related rulemakings could adversely affect Microsoft's business, strategy, and operations. Periods of intense diplomatic or armed conflict like the ongoing conflict in Ukraine and the Israel-Hamas conflict could result in (1) new and rapidly evolving sanctions and trade restrictions, which may impair trade with sanctioned individuals and countries, and (2) negative impacts to regional trade ecosystems among our customers, partners, and us.

Filing text · FY2026 10-K · filed Jul 29, 2026

Trade: Increasing trade laws, policies, sanctions, and other regulatory requirements also affect our operations in and outside the U.S. relating to trade and investment. Economic sanctions in the U.S., the EU, and other countries [added] could prohibit business with restricted entities or countries. U.S. export controls restrict Microsoft from offering many of its products and services to, or making investments in, certain entities in specified countries. U.S. import controls restrict us from integrating certain information and communication technologies into our supply chain and allow for government review of transactions involving information and communications technology from countries determined to be foreign adversaries. Supply chain regulations may impact the availability of goods or result in additional regulatory scrutiny. Restrictions on data flows and outbound investment and customer sensitivities may limit our ability to leverage parts of our global engineering footprint to provide services in certain jurisdictions. Increased geopolitical instabilities and changing U.S. Administration priorities create an unpredictable trade landscape. U.S. [added] tariffs, shifting AI export controls policies, [added] and disagreements among governments on sanctions policies toward third countries, has and may continue to increase operational costs, create uncertainty in the continuity of our products, and accelerate sovereignty initiatives among international partners and customers. The volatility of U.S. tariffs has triggered economic uncertainty and could impact cloud and devices supply chain cost competitiveness. The potential replacement of the rescinded AI Diffusion Rule, expanded export license conditions, and other potential AI-related rulemakings could adversely affect Microsoft's business, strategy, and operations. Periods of intense diplomatic or armed conflict, such as the conflicts in Ukraine and the Middle East could continue to result in (1) new and rapidly evolving sanctions and trade restrictions, which may impair trade with sanctioned individuals and countries, and (2) negative impacts to regional trade ecosystems among our customers, partners, and us.

Cite this change

"Economic sanctions in the U.S., the EU, and other countries could prohibit business with restricted entities or countries."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

34ChangedItem 1A › CYBERSECURITY, DATA PRIVACY, AND PLATFORM ABUSE RISKS › Cyberattacks and security vulnerabilities could lead to reduced revenue, increased costs, liability claims, or harm to our reputation or competitive position.

Summary · quote-checked

The cybersecurity risk now expressly includes enhanced AI-based threats, while the liability disclaimer is rephrased with similar uncertainty.

Adding enhanced AI-based threats introduces a newly named threat tied to security practices. The liability-language revision appears substantively equivalent and does not independently change the disclosure.

Filing text · FY2025 10-K · filed Jul 30, 2025

The cost of these measures to protect products and customer-facing services could reduce our operating margins. If we fail to do these things well, actual or perceived security vulnerabilities in our processes, products, and services, data corruption issues, or reduced performance could harm our reputation and lead customers to exercise contractual or other remedies against us, reduce or delay future purchases of products or subscriptions to services, or to use competing products or services. Customers and third parties granted access to customer systems may fail to update their systems, continue to run software or operating systems we no longer support, may fail to timely install or enable security patches, or may otherwise fail to adopt adequate security [removed] practices. Customers may also spend more on protecting their existing computer systems from attack, which could delay adoption of additional products or services. Customers in certain industries such as financial services, health care, and government have enhanced or specialized expectations and requirements to which we must develop and engineer our products and services. Any of these could adversely affect our reputation and results of operations. Actual or perceived vulnerabilities may lead to claims against us. Our license agreements typically contain provisions that eliminate or limit our exposure to liability, but [removed] there is no assurance these provisions [removed] will withstand legal challenges. At times, to achieve commercial objectives, we may enter into agreements with larger liability exposure to customers.

Filing text · FY2026 10-K · filed Jul 29, 2026

The cost of these measures to protect products and customer-facing services could reduce our operating margins. If we fail to do these things well, actual or perceived security vulnerabilities in our processes, products, and services, data corruption issues, or reduced performance could harm our reputation and lead customers to exercise contractual or other remedies against us, reduce or delay future purchases of products or subscriptions to services, or to use competing products or services. Customers and third parties granted access to customer systems may fail to update their systems, continue to run software or operating systems we no longer support, may fail to timely install or enable security patches, or may otherwise fail to adopt adequate security [added] practices, including in response to enhanced AI-based threats. Customers may also spend more on protecting their existing computer systems from attack, which could delay adoption of additional products or services. Customers in certain industries such as financial services, health care, and government have enhanced or specialized expectations and requirements to which we must develop and engineer our products and services. Any of these could adversely affect our reputation and results of operations. Actual or perceived vulnerabilities may lead to claims against us. Our license agreements typically contain provisions that eliminate or limit our exposure to liability, but these provisions [added] may not withstand legal challenges. At times, to achieve commercial objectives, we may enter into agreements with larger liability exposure to customers.

Cite this change

"Customers and third parties granted access to customer systems may fail to update their systems, continue to run software or operating systems we no longer support, may fail to timely install or enable security patches, or may otherwise fail to adopt adequate security practices, including in response to enhanced AI-based threats."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

35ChangedItem 1A › LEGAL, REGULATORY, AND LITIGATION RISKS

Summary · quote-checked

Adds cybersecurity among applicable requirements and removes disclosure about expanding data-production demands and increasingly complex law-enforcement requests.

The paragraph changes the described regulatory exposure by adding cybersecurity obligations and removing a specific, increasing legal-demand and customer-data-production obligation.

Filing text · FY2025 10-K · filed Jul 30, 2025

We are subject to a variety of new, existing, and evolving legal and regulatory requirements that could adversely affect our results of operations. We are subject to a wide range of laws, regulations, and legal requirements in the U.S. and globally, including those that may apply to our products and online services offerings, and those that impose requirements related to user privacy, telecommunications, data storage and protection, digital accessibility, advertising, and online safety. Laws in several jurisdictions, including EU Member State laws under the European Electronic Communications Code, increasingly define certain of our services as regulated services. This trend may continue with our offerings becoming subject to additional data protection, security, digital safety, law enforcement surveillance, and other obligations. Regulators and private litigants may assert that our collection, use, and management of customer data and other information is inconsistent with their laws and regulations, including laws that apply to the tracking of users via technology such as cookies. In addition, laws requiring us to[removed] retrieve and produce customer data in response to compulsory legal demands from law enforcement and governmental authorities are expanding and the requests we are experiencing are increasing in volume and complexity.

Filing text · FY2026 10-K · filed Jul 29, 2026

We are subject to a variety of new, existing, and evolving legal and regulatory requirements that could adversely affect our results of operations. We are subject to a wide range of laws, regulations, and legal requirements in the U.S. and globally, including those that may apply to our products and online services offerings, and those that impose requirements related to user privacy, [added] cybersecurity, telecommunications, data storage and protection, digital accessibility, advertising, and online safety. Laws in several jurisdictions, including EU Member State laws under the European Electronic Communications Code, increasingly define certain of our services as regulated services. This trend may continue with our offerings becoming subject to additional data protection, security, digital safety, law enforcement surveillance, and other obligations. Regulators and private litigants may assert that our collection, use, and management of customer data and other information is inconsistent with their laws and regulations, including laws that apply to the tracking of users via technology such as cookies. In addition, laws requiring us to retrieve and produce customer data in response to compulsory legal demands from law enforcement and governmental authorities are evolving and the requests we are experiencing are increasing in volume and complexity.

Cite this change

"We are subject to a wide range of laws, regulations, and legal requirements in the U.S. and globally, including those that may apply to our products and online services offerings, and those that impose requirements related to user privacy, cybersecurity, telecommunications, data storage and protection, digital accessibility, advertising, and online safety."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

36ChangedItem 1A › GENERAL RISKS

Summary · quote-checked

Removed the specific reference to geopolitical tension between the U.S. and Europe from the disclosed global-business risks.

The change eliminates a geographic focus tied to the geopolitical-risk disclosure, altering the specificity of the stated exposure rather than merely rephrasing it.

Filing text · FY2025 10-K · filed Jul 30, 2025

Our global business exposes us to operational and economic risks. Our customers, employees, and infrastructure are located throughout the world and a significant part of our revenue comes from international sales. The global nature of our business creates operational, economic, and geopolitical risks. Global, regional, and local economic developments, monetary policy, geopolitical tension, [removed] particularly between the U.S. and Europe, restrictions on international trade, such as tariffs and other controls on imports or exports, inflation, and recession, as well as political and military disputes, could adversely affect our results of operations. Non-compliance with sanctions as well as general ecosystem disruptions could result in reputational harm, operational delays, monetary fines, loss of revenue, increased costs, loss of export privileges, or criminal sanctions, which could adversely affect our business, financial condition, and results of operations.

Filing text · FY2026 10-K · filed Jul 29, 2026

Our global business exposes us to operational and economic risks. Our customers, employees, and infrastructure are located throughout the world and a significant part of our revenue comes from international sales. The global nature of our business creates operational, economic, and geopolitical risks. Global, regional, and local economic developments, monetary policy, geopolitical tension, restrictions on international trade, such as tariffs and other controls on imports or exports, inflation, and recession, as well as political and military disputes, could adversely affect our results of operations. Non-compliance with sanctions as well as general ecosystem disruptions could result in reputational harm, operational delays, monetary fines, loss of revenue, increased costs, loss of export privileges, or criminal sanctions, which could adversely affect our business, financial condition, and results of operations.

Cite this change

"Global, regional, and local economic developments, monetary policy, geopolitical tension, restrictions on international trade, such as tariffs and other controls on imports or exports, inflation, and recession, as well as political and military disputes, could adversely affect our results of operations."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

37ChangedItem 1A › INTELLECTUAL PROPERTY RISKS

Summary · quote-checked

The intellectual-property risk expands claims arising from AI training and output to include inference.

Adding inference identifies an additional source of potential intellectual-property claims, substantively broadening the disclosed AI-related risk.

Filing text · FY2025 10-K · filed Jul 30, 2025

Third parties may claim that we infringe their intellectual property. From time to time, others claim we infringe their intellectual property rights, including current copyright infringement and other claims arising from AI [removed] training and output. To resolve these claims, we may enter into royalty-bearing data access or licensing agreements on terms that are less favorable than currently available, stop selling or redesign affected products or services, or pay damages to satisfy indemnification commitments with our customers. Adverse outcomes could also include monetary damages or injunctive relief that may limit or prevent importing, marketing, and selling our products or services that have infringing technologies. We have paid significant amounts to settle claims related to the use of technology and intellectual property rights and to procure intellectual property rights as part of our strategy to manage this risk, and may continue to do so, which could adversely affect our results of operations.

Filing text · FY2026 10-K · filed Jul 29, 2026

Third parties may claim that we infringe their intellectual property. From time to time, others claim we infringe their intellectual property rights, including current copyright infringement and other claims arising from AI [added] training, inference, and output. To resolve these claims, we may enter into royalty-bearing data access or licensing agreements on terms that are less favorable than currently available, stop selling or redesign affected products or services, or pay damages to satisfy indemnification commitments with our customers. Adverse outcomes could also include monetary damages or injunctive relief that may limit or prevent importing, marketing, and selling our products or services that have infringing technologies. We have paid significant amounts to settle claims related to the use of technology and intellectual property rights and to procure intellectual property rights as part of our strategy to manage this risk, and may continue to do so, which could adversely affect our results of operations.

Cite this change

"From time to time, others claim we infringe their intellectual property rights, including current copyright infringement and other claims arising from AI training, inference, and output."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

38ChangedItem 1A › CYBERSECURITY, DATA PRIVACY, AND PLATFORM ABUSE RISKS › Cyberattacks and security vulnerabilities could lead to reduced revenue, increased costs, liability claims, or harm to our reputation or competitive position.

Summary · quote-checked

The risk disclosure expands reliance on third-party infrastructure and adds potential artificial-intelligence-assisted vulnerability exploitation.

The paragraph adds a third-party infrastructure dependency and changes the exploitation scenario by expressly identifying artificial intelligence as a potential aid, altering the stated cybersecurity risk.

Filing text · FY2025 10-K · filed Jul 30, 2025

The security of our products and services is important in our customers' decisions to purchase or use our products or services across cloud and on-premises environments. Security threats are a significant challenge to companies like us, whose business is providing technology products and services to others. Threats [removed] to or attacks [removed] on our own infrastructure, such as the nation-state attack described in the prior risk factor, have also affected our customers and may do so in the future. The reliability of our cloud-based services and the protection of customer data depend on the security of our [removed] infrastructure, which includes hardware and other elements provided by third parties. Adversaries tend to focus their efforts on the most popular operating systems, programs, and services, including many of ours, as well as customers with sensitive data, and we expect that to continue. In addition, adversaries can attack our customers' on-premises or cloud environments, sometimes exploiting previously unknown ("zero-day") vulnerabilities. Product vulnerabilities can persist even after we have issued security patches if customers have not installed the most recent updates, or if [removed] the attackers exploited the vulnerabilities before [removed] patching to install [removed] additional malware to further compromise customers' systems. Adversaries will continue to attack customers [removed] using our cloud services as customers embrace digital transformation. Adversaries that acquire user account information can use that information to compromise our users' accounts, including where accounts share the same attributes such as passwords. Inadequate account security practices may also result in unauthorized access, and user activity may result in ransomware or other malicious software impacting a customer's use of our products or services. Weaknesses in our development processes can result in vulnerabilities in our products. Open source software can also contain vulnerabilities that may make our products susceptible to cyberattacks as we increasingly incorporate open source software into our products. Additionally, features that rely on generative AI can be susceptible to security threats.

Filing text · FY2026 10-K · filed Jul 29, 2026

The security of our products and services is important in our customers' decisions to purchase or use our products or services across cloud and on-premises environments. Security threats are a significant challenge to companies like us, whose business is providing technology products and services to others. Threats [added] to, or attacks [added] on, our own infrastructure, such as the nation-state attack described in the prior risk factor, have also affected our customers and may do so in the future. The reliability of our cloud-based services and the protection of customer data depend on the security of our [added] infrastructure and the security of third-party infrastructure upon which we rely, which includes hardware, software, and other elements provided by third parties. Adversaries tend to focus their efforts on the most popular operating systems, programs, and services, including many of ours, as well as customers with sensitive data, and we expect that to continue. In addition, adversaries can attack our customers' on-premises or cloud environments, sometimes exploiting previously unknown ("zero-day") vulnerabilities. Product vulnerabilities can persist even after we have issued security patches if customers have not installed the most recent updates, or if [added] attackers, potentially with the assistance of artificial intelligence, reconstruct and exploit the vulnerabilities before [added] patching. Attackers may utilize vulnerabilities to install malware to further compromise customers' systems. Adversaries will continue to attack customers [added] as they embrace digital transformation. Adversaries that acquire user account information can use that information to compromise our users' accounts, including where accounts share the same attributes such as passwords. Inadequate account security practices may also result in unauthorized access, and user activity may result in ransomware or other malicious software impacting a customer's use of our products or services. Our products are highly complex and weaknesses may exist in our development processes. For example, code generated by AI could include errors, deficiencies, or vulnerabilities that increase our exposure to cyberattacks. Additionally, open-source software can also contain vulnerabilities that may make our products susceptible to cyberattacks as we increasingly incorporate open-source software into our products. Accordingly, our products have and may continue to contain vulnerabilities or undetected errors.

Cite this change

"The reliability of our cloud-based services and the protection of customer data depend on the security of our infrastructure and the security of third-party infrastructure upon which we rely, which includes hardware, software, and other elements provided by third parties."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

39ChangedItem 1A › LEGAL, REGULATORY, AND LITIGATION RISKS

Summary · quote-checked

The claims-risk examples expanded from AI services to AI products and services.

The disclosure newly identifies AI products as a source of potential claims and lawsuits, adding a product category to the stated legal risk.

Filing text · FY2025 10-K · filed Jul 30, 2025

We have claims and lawsuits against us that may result in adverse outcomes. We are subject to a variety of claims and lawsuits. These claims may arise from a wide variety of business practices and initiatives, including major new product releases, AI services, significant business transactions, warranty or product claims, employment practices, and regulation. As we continue to expand our business and offerings, we may experience new and novel legal claims. Adverse outcomes in some or all of these claims may result in significant monetary damages or injunctive relief that could adversely affect our ability to conduct our business. Litigation and other claims are subject to inherent uncertainties and management's view of these matters may change in the future. An adverse impact to our financial condition and results of operations could occur for the period in which the effect of an unfavorable outcome becomes probable and reasonably estimable.

Filing text · FY2026 10-K · filed Jul 29, 2026

We have claims and lawsuits against us that may result in adverse outcomes. We are subject to a variety of claims and lawsuits. These claims may arise from a wide variety of business practices and initiatives, including major new product releases, AI [added] products and services, significant business transactions, warranty or product claims, employment practices, and regulation. As we continue to expand our business and offerings, we may experience new and novel legal claims. Adverse outcomes in some or all of these claims may result in significant monetary damages or injunctive relief that could adversely affect our ability to conduct our business. Litigation and other claims are subject to inherent uncertainties and management's view of these matters may change in the future. An adverse impact to our financial condition and results of operations could occur for the period in which the effect of an unfavorable outcome becomes probable and reasonably estimable.

Cite this change

"These claims may arise from a wide variety of business practices and initiatives, including major new product releases, AI products and services, significant business transactions, warranty or product claims, employment practices, and regulation."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

40ChangedItem 1A › GENERAL RISKS

Summary · quote-checked

The risk description expands from export controls to disagreements among governments over export controls and sanctions toward third countries.

The added language introduces intergovernmental disagreements and sanctions toward third countries as distinct geopolitical developments that may hinder foreign operations and sales.

Filing text · FY2025 10-K · filed Jul 30, 2025

In addition, our international growth strategy includes certain markets, the developing nature of which presents several risks, including deterioration of social, political, labor, or economic conditions in a country or region, and difficulties in staffing and managing foreign operations. Emerging nationalist and protectionist trends and concerns about human rights, the environment, and political expression in specific countries may significantly alter the trade and commercial environments. Changes to trade policy or agreements as a result of populism, protectionism, or economic nationalism may result in higher tariffs, local sourcing initiatives, and non-local sourcing restrictions, [removed] export controls, investment restrictions, or other developments that make it more difficult to operate and sell our products in foreign countries. Disruptions of these kinds in developed or emerging markets could negatively impact demand for our products and services, impair our ability to operate in certain regions, or increase operating costs. Although we hedge a portion of our international currency exposure, significant fluctuations in foreign exchange rates between the U.S. dollar and foreign currencies could adversely affect our results of operations.

Filing text · FY2026 10-K · filed Jul 29, 2026

In addition, our international growth strategy includes certain markets, the developing nature of which presents several risks, including deterioration of social, political, labor, or economic conditions in a country or region, and difficulties in staffing and managing foreign operations. Emerging nationalist and protectionist trends and concerns about human rights, the environment, and political expression in specific countries may significantly alter the trade and commercial environments. Changes to trade policy or agreements as a result of populism, protectionism, or economic nationalism may result in higher tariffs, local sourcing initiatives, and non-local sourcing restrictions, [added] disagreements among governments on export controls and sanctions toward third countries, investment restrictions, or other developments that make it more difficult to operate and sell our products in foreign countries. Disruptions of these kinds in developed or emerging markets could negatively impact demand for our products and services, impair our ability to operate in certain regions, or increase operating costs. Although we hedge a portion of our international currency exposure, significant fluctuations in foreign exchange rates between the U.S. dollar and foreign currencies could adversely affect our results of operations.

Cite this change

"Changes to trade policy or agreements as a result of populism, protectionism, or economic nationalism may result in higher tariffs, local sourcing initiatives, and non-local sourcing restrictions, disagreements among governments on export controls and sanctions toward third countries, investment restrictions, or other developments that make it more difficult to operate and sell our products in foreign countries."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

41SplitItem 1A › CYBERSECURITY, DATA PRIVACY, AND PLATFORM ABUSE RISKS › Cyberattacks and security vulnerabilities could lead to reduced revenue, increased costs, liability claims, or harm to our reputation or competitive position.

Summary · quote-checked

The cybersecurity risk disclosure adds deployment of AI-based and automated defenses to the company’s security approach.

The added language identifies a specific defense technology and deployment method, changing the substance of how the company describes addressing security threats.

Filing text · FY2025 10-K · filed Jul 30, 2025

To defend against security threats to our internal infrastructure, our cloud-based services, and our customers' systems, we must take a complex and multifaceted approach. This includes continuously engineering more secure products and services, and enhancing security, threat detection, and reliability [removed] features. We must also escalate and improve our development processes and the deployment of software updates to address security vulnerabilities in our own products as well as those provided by others in a timely manner. In addition, we must develop mitigation technologies that help to secure customers from attacks even[removed] when software updates are not deployed, and maintain the digital security infrastructure that protects the integrity of our network, products, and services. Further, we must provide security tools such as firewalls, anti-virus software, and advanced security and information about the need to deploy security measures and the impact of doing so.

Filing text · FY2026 10-K · filed Jul 29, 2026

To defend against security threats to our internal infrastructure, our cloud-based services, and our customers' systems, we must take a complex and multifaceted approach. This includes continuously engineering more secure products and services, and enhancing security, threat detection, and reliability [added] features, including through the deployment of AI-based and automated defenses. We must also escalate and improve our development processes and the deployment of software updates to address security vulnerabilities in our own products as well as those provided by others in a timely manner. In addition, we must develop mitigation technologies that help to secure customers from attacks even[added] when software updates are not deployed, and maintain the digital security infrastructure that protects the integrity of our network, products, and services. Further, we must provide security tools such as firewalls, anti-virus software, and advanced security and information about the need to deploy security measures and the impact of doing so.

Cite this change

"This includes continuously engineering more secure products and services, and enhancing security, threat detection, and reliability features, including through the deployment of AI-based and automated defenses."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

42SplitItem 1A › GENERAL RISKS

Summary · quote-checked

The reputation-risk discussion adds accessibility issues alongside product safety and quality as potential sources of brand damage.

The added term identifies accessibility as a newly stated source of reputation or brand damage, expanding the substance of the disclosed risk beyond a grammatical or structural revision.

Filing text · FY2025 10-K · filed Jul 30, 2025

If our reputation or our brands are damaged, our business and results of operations may be harmed. Our reputation and brands are globally recognized and are important to our business. Our reputation and brands affect our ability to attract and retain consumer, business, and public-sector customers. There are numerous ways our reputation or brands could be damaged. These include product [removed] safety or quality issues, our environmental impact and sustainability, supply chain practices, or human rights record. We may experience backlash from customers, government entities, advocacy groups, employees, and other stakeholders that disagree with our product offering[removed] decisions, public policy positions, or corporate philanthropic initiatives. Damage to our reputation or our brands may occur from, among other things:

Filing text · FY2026 10-K · filed Jul 29, 2026

If our reputation or our brands are damaged, our business and results of operations may be harmed. Our reputation and brands are globally recognized and are important to our business. Our reputation and brands affect our ability to attract and retain consumer, business, and public-sector customers. There are numerous ways our reputation or brands could be damaged. These include product [added] safety, quality, or accessibility issues, our environmental impact and sustainability, supply chain practices, or human rights record. We may experience backlash from customers, government entities, advocacy groups, employees, and other stakeholders that disagree with our product offering[added] decisions, public policy positions, or corporate philanthropic initiatives. Damage to our reputation or our brands may occur from, among other things:

Cite this change

"These include product safety, quality, or accessibility issues, our environmental impact and sustainability, supply chain practices, or human rights record."

Microsoft, Form 10-K for FY2026, Item 1A, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

Show fewer in Item 1A

Item 7 · MD&A

3 of 46 shown · Ordered by the model, quote-checked

01ChangedItem 7 › Industry Trends and Opportunities

Summary · quote-checked

The paragraph adds partnership extensions and ongoing revenue-sharing payments while removing Azure API exclusivity and the right of first refusal on capacity.

The disclosure changes the partnership’s duration, revenue arrangement, and stated Azure and capacity rights, altering dependencies and obligations rather than merely rephrasing them.

Why the model ranked it here

The partnership disclosure removes previously stated Azure exclusivity and capacity rights while adding extensions and continuing revenue-sharing payments, changing a major dependency and obligation.

Filing text · FY2025 10-K · filed Jul 30, 2025

[removed] Microsoft and OpenAI maintain a long-term strategic partnership originally established in 2019. [removed] Microsoft is a major investor in OpenAI, and the companies have reciprocal revenue-sharing arrangements. We hold rights to OpenAI's intellectual property, including models and infrastructure, for integration into our products. The OpenAI API is exclusive to Azure, runs on Azure, and is available through the Azure OpenAI Service. We also have a right of first refusal on OpenAI's new capacity needs.

Filing text · FY2026 10-K · filed Jul 29, 2026

[added] We have a long-term strategic partnership [added] with OpenAI which was originally established in 2019. [added] In October 2025 and April 2026, we extended this partnership and continue to build on our shared vision to advance artificial intelligence responsibly and make its benefits broadly accessible. Microsoft is a major investor in OpenAI and will continue to receive revenue-sharing payments. We hold rights to OpenAI's intellectual property, including models and infrastructure, for integration into our products.

Cite this change

"In October 2025 and April 2026, we extended this partnership and continue to build on our shared vision to advance artificial intelligence responsibly and make its benefits broadly accessible. Microsoft is a major investor in OpenAI and will continue to receive revenue-sharing payments."

Microsoft, Form 10-K for FY2026, Item 7, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

02ChangedItem 7 › Cash Flows

Summary · quote-checked

Cash-flow discussion changes in operating, financing, and investing directions, amounts, and stated drivers.

The paragraph substantively changes reported cash-flow directions and explanations, including debt repayments, repurchases, dividends, property additions, and investing to facilitate component purchases.

Why the model ranked it here

The cash-flow discussion reverses investment and financing trends and highlights substantially greater spending on property, equipment, and components.

Filing text · FY2025 10-K · filed Jul 30, 2025

Cash from operations increased [removed] $17.6 billion to [removed] $136.2 billion for fiscal year [removed] 2025, primarily due to an increase in cash received from [removed] customers, offset in part by an increase in cash paid to [removed] suppliers and employees and cash used to pay income taxes. Cash used in financing increased [removed] $13.9 billion to $51.7 billion for fiscal year [removed] 2025, primarily due to a [removed] $9.5 billion increase in cash used for repayments of debt, [removed] net of proceeds. Cash used in investing [removed] decreased $24.4 billion to [removed] $72.6 billion for fiscal year [removed] 2025, primarily due to a [removed] $63.2 billion decrease in cash used for acquisitions of companies, net of cash acquired and divestitures, and purchases of intangible and other assets, offset in part by a [removed] $22.3 billion increase in cash used in [removed] net investment purchases, sales, and maturities, and a $20.1 billion increase in additions to property and equipment.

Filing text · FY2026 10-K · filed Jul 29, 2026

Cash from operations increased [added] $46.8 billion to [added] $182.9 billion for fiscal year [added] 2026, primarily due to an increase in cash received from [added] customers and a decrease in cash used to pay income taxes, offset in part by an increase in cash paid to [added] suppliers. Cash used in financing increased [added] $847 million to $52.5 billion for fiscal year [added] 2026, primarily due to a [added] $6.0 billion decrease in cash used for repayments of debt, [added] offset in part by a $3.9 billion increase in common stock repurchases and a $2.4 billion increase in dividends paid. Cash used in investing [added] increased $66.9 billion to [added] $139.5 billion for fiscal year [added] 2026, primarily due to a [added] $51.4 billion increase in additions to property and equipment and a $22.2 billion increase in cash used in other investing primarily to facilitate the purchase of components, offset in part by a [added] $4.2 billion decrease in cash used in [added] the acquisition of companies, net of cash acquired and divestitures, and purchases of intangible and other assets and a $2.4 billion decrease in cash used in net investment purchases, sales, and maturities.

Cite this change

"Cash used in investing increased $66.9 billion to $139.5 billion for fiscal year 2026, primarily due to a $51.4 billion increase in additions to property and equipment and a $22.2 billion increase in cash used in other investing primarily to facilitate the purchase of components, offset in part by a $4.2 billion decrease in cash used in the acquisition of companies, net of cash acquired and divestitures, and purchases of intangible and other assets and a $2.4 billion decrease in cash used in net investment purchases, sales, and maturities."

Microsoft, Form 10-K for FY2026, Item 7, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

03Figures updatedItem 7 › Cash, Cash Equivalents, and Investments

Summary · quote-checked

Cash, cash equivalents, and short-term investments decreased, while equity and other investments increased in the rolled-forward period.

The updated figures indicate a changed liquidity and investment exposure profile, rather than merely a reporting-period rollover.

Why the model ranked it here

The liquidity profile shows materially less cash and short-term investments alongside a substantial increase in equity and other investments.

Filing text · FY2025 10-K · filed Jul 30, 2025

Cash, cash equivalents, and short-term investments totaled [removed] $94.6 billion and [removed] $75.5 billion as of June 30, [removed] 2025 and 2024, respectively. Equity and other investments were [removed] $15.4 billion and [removed] $14.6 billion as of June 30, [removed] 2025 and 2024, respectively. Our short-term investments are primarily intended to facilitate liquidity and capital preservation. They consist predominantly of highly liquid investment-grade fixed-income securities, diversified among industries and individual issuers. The investments are predominantly U.S. dollar-denominated securities, but also include foreign currency-denominated securities to diversify risk. Our fixed-income investments are exposed to interest rate risk and credit risk. The credit risk and average maturity of our fixed-income portfolio are managed to achieve economic returns that correlate to certain fixed-income indices. The settlement risk related to these investments is insignificant given that the short-term investments held are primarily highly liquid investment-grade fixed-income securities.

Filing text · FY2026 10-K · filed Jul 29, 2026

Cash, cash equivalents, and short-term investments totaled [added] $76.8 billion and [added] $94.6 billion as of June 30, [added] 2026 and 2025, respectively. Equity and other investments were [added] $36.3 billion and [added] $15.4 billion as of June 30, [added] 2026 and 2025, respectively. Our short-term investments are primarily intended to facilitate liquidity and capital preservation. They consist predominantly of highly liquid investment-grade fixed-income securities, diversified among industries and individual issuers. The investments are predominantly U.S. dollar-denominated securities, but also include foreign currency-denominated securities to diversify risk. Our fixed-income investments are exposed to interest rate risk and credit risk. The credit risk and average maturity of our fixed-income portfolio are managed to achieve economic returns that correlate to certain fixed-income indices. The settlement risk related to these investments is insignificant given that the short-term investments held are primarily highly liquid investment-grade fixed-income securities.

Cite this change

"Cash, cash equivalents, and short-term investments totaled $76.8 billion and $94.6 billion as of June 30, 2026 and 2025, respectively. Equity and other investments were $36.3 billion and $15.4 billion as of June 30, 2026 and 2025, respectively."

Microsoft, Form 10-K for FY2026, Item 7, accession 0001193125-26-323660, filed 29 July 2026.

Filing: https://www.sec.gov/Archives/edgar/data/789019/000119312526323660/msft-20260630.htm

Comparison: https://yearover.com/reports/msft/0001193125-26-323660?ref=quote

Summaries are written by a model and checked against the quoted text. The quotes are the record.

Show all 46 in Item 7 (43 more, in filing order)

Get this when MSFT files next

One email a week with what changed in the filings we cover, in the company's own words. The next report on this company will be in it. You confirm by email first; nothing is sent until you do.

We store your email address. Nothing else. Privacy.