Image generation is now inside PowerPoint
Microsoft's MAI-Image-2.5 generates inside PowerPoint and OneDrive. The gate is no longer quality. It is the eight controls you set before switching it on.
Microsoft announced MAI-Image-2.5 on 2 June 2026, and the detail that matters for most companies is not in the benchmark table. It is the distribution: the model ships inside PowerPoint and OneDrive. Not in a separate creative tool that a design team logs into, not behind a request queue, but in the application every employee already has open, next to the slide they are already building.
That is a different problem from the one most AI image policies were written to solve. A policy that says "requests go to the brand team" assumes there is a request. When generation lives in the file, there is no request, no brief and no reviewer. The asset is born already embedded in a document that is about to be emailed to a customer.
The quality argument is over, and it went the wrong way for policy
It would be easier if the model were bad. It isn't. Artificial Analysis places MAI-Image-2.5 fifth on its text-to-image leaderboard at 1304, and in the top three on its image editing board. That is a model good enough that an employee's first attempt will look plausible on a slide, which is precisely the condition under which nobody escalates.
Versely lists Mai Image 2.5 Edit at 5 credits a call for pixel-level editing, cleanup, backgrounds and text, so this is a model teams are already using deliberately. The difference is that a deliberate use has a person who chose it and a place the output was stored. An in-document generation has neither.
Five assumptions that break when the generator moves into the file
Most brand governance rests on assumptions about where assets live. Each of these stops holding the moment generation is a button in the ribbon.
- There is a version history somebody can audit. A slide's image has no lineage outside the deck. Nobody can answer "which model made this, from what prompt, on what date" a month later.
- Assets are reused, so review scales. In-document generation produces single-use images. Review effort per asset goes up rather than down.
- The brand team sees output before customers do. They see the deck, if they are on the distribution list, at the point where changing it is expensive.
- The file stays inside the company. OneDrive syncs and shares by default. A deck becomes a PDF, becomes a webinar screen-share, becomes an attachment on a proposal.
- Somebody would notice a made-up detail. They do not, reliably, when the detail is rendered rather than written. A chart drawn by an image model looks like a chart.
None of that is an argument against the capability. It is an argument that the control layer has to move to where the generation happens, which is a different piece of work from writing a policy document.
Eight controls to set before you switch it on
This assumes you already have the general structure in place. If you do not, the governance guardrails post covers approval tiers, roles and the audit trail. What follows is the delta specific to generation embedded in the productivity suite.
| Control | What you decide once | Failure it prevents |
|---|---|---|
| Surface class | Which document types may contain generated imagery at all | An internal-only illustration reaching a customer deck |
| Model allowlist | The named models permitted, by name and version | Untracked provenance and drifting house style |
| People rule | Whether generated humans are allowed, and never resembling a specific real person | A likeness complaint you cannot unwind |
| Claim rule | No generated numbers, charts, certification marks or legal lines | An unreviewable factual claim shipping as pixels |
| Brand input format | Reference images and colour values, not adjectives | A near-miss version of your palette on every slide |
| Disclosure default | Which document classes carry a label, decided in advance | A publish-day argument about whether to disclose |
| Provenance record | Model, prompt, date and requester, stored outside the file | Being unable to answer where an image came from |
| Escalation owner | One named person and a takedown path | A pulled asset with nobody accountable for pulling it |
Two of these deserve expanding.
The brand input format control is the one that actually improves output. Prose descriptions of a brand produce approximations. A reference image produces a match. If you are going to let a few hundred people generate, the highest-leverage thing you can hand them is not a style guide paragraph but three approved reference frames and the exact hex values from your brand kit. This costs one afternoon and removes most of the off-brand output before it happens.
The people rule is the one with a live cautionary case. Meta launched a Muse Image feature on Instagram that let anyone generate images referencing any public account's photos by tagging it, with every public account auto-enrolled. It was pulled on 10 July 2026, three days after launch, after SAG-AFTRA demanded an opt-out and Meta acknowledged it had missed the mark. The lesson is not about Meta. It is that likeness defaults are the fastest way to turn a feature launch into a retraction, and a company that lets employees generate people has made a likeness default whether or not it wrote one down.
Two deadlines that are already behind you
Both of these became operative on 2 August 2026, which is before this post was written and almost certainly before your policy was updated.
EU AI Act Article 50. The transparency obligations apply from 2 August 2026, and the machine-readable marking requirement under 50(2) carries a later deadline of 2 December 2026 for systems already on the market before that date. What Article 50 asks of a published asset covers the labelling side. The part that bites an in-document workflow is the Commission's own position that no single technique currently meets the marking standard, so a layered approach across metadata and watermarking is what is expected.
California AB 853. The AI Transparency Act became operative the same day, deliberately aligned to Article 50, with a further tranche of obligations for large online platforms and generative AI hosting platforms on 1 January 2027. For a company generating inside its own documents, the consequence that matters is that provenance is becoming something an outsider can query rather than something you assert.
The practical consequence for a company using in-document generation is that provenance has to survive the document. Metadata attached to an image does not necessarily survive being pasted into a slide, exported to PDF and screenshotted into a proposal. If your only provenance record lives in the file, you have no record. That is why the provenance control in the table above says "stored outside the file" rather than "embedded."
For anything that leaves the building, this is the argument for generating in a system that keeps the model name, the settings and the output together. Models in the Versely catalog each have their own page listing provider, supported resolutions and aspect ratios, and credit cost, which is what makes an allowlist enforceable: you can name a model rather than name a button. And for the brand-critical stills themselves, text-to-image with your own reference frames beats a general-purpose prompt typed into a slide.
Set the disclosure label policy at the same time, by document class, before anyone asks. It is a ten-minute decision in advance and a three-week argument afterwards.
FAQ
Should we just block it?
Rarely the right call, and usually not an enforceable one. Blocking a feature inside the productivity suite pushes generation to personal accounts on consumer tools, where you have no allowlist, no provenance and no visibility at all. Enabling it with the eight controls above gives you a worse-looking policy document and a much better actual outcome.
Who owns this, brand or IT?
IT owns the switch, brand owns the rules, and the failure mode is each assuming the other has it. The escalation-owner row in the table exists because a control with two owners has none. In practice the most workable split is IT enforcing the surface class and model allowlist, brand owning the people rule, claim rule, input format and disclosure defaults.
Does the disclosure requirement apply to an internal deck?
The obligations described above attach to systems and providers rather than to your internal slide, so an all-hands deck is a different question from a published advert. The reason to set a disclosure default by document class anyway is that internal decks do not stay internal, and deciding at publish time is how a deck ships without the label it needed.
What is the single highest-value control if we only do one?
The brand input format. Three approved reference frames and your exact colour values, distributed to everyone who has the button, remove more off-brand output than any review process you can staff. Every other control on the list catches problems. That one prevents them.