Enterprise AI is moving from isolated assistants to software that can plan, act, and coordinate across business processes over time. OpenAI is exposing the Codex system that lets AI tools work together as a public-beta API, Salesforce is packaging job-ready AI workers with a shared central management system, and Google is giving AI coding workers a governed path into cloud infrastructure. The same shift raises the cost of weak controls: Harness found that confidence in AI workers outruns inventory, testing, immediate off switches, and spend visibility, while Anthropic reported attacks using AI across cyber operations and capability theft. The winning enterprise position is no longer “use a model.” It is own the operating boundary where AI workers receive authority, data, tools, and accountability.
Salesforce introduced seven job-ready Agentforce AI workers on September 11 for customer service, IT and HR, commerce, sales, supply chain, inbound lead generation, and customer experience.
Salesforce says Agentforce and Slack have delivered 7 billion Agentic Work Units, including 3.2 billion in Q2; Hunter is in pilot with general availability planned for November 2026, while the other named AI workers are generally available now. Salesforce The product architecture matters more than the names. Salesforce combines memory across sessions, the ability to keep work running, the ability to adjust plans, predictable business rules, and coordination among multiple AI workers so work can continue across days or weeks. It also cites customer examples including 79% autonomous resolution for Anthropic conversations handled by Fin, 90% of Hibbett’s core shopper journeys handled by Hibbett AI, and a fourfold increase in conversation volume from Asana’s website AI worker, Piper. Salesforce
Salesforce is making the AI worker the new unit of enterprise labor. The value is moving from isolated AI requests to the system that connects identity, customer context, permissions, workflows, and measurable outcomes. That gives Salesforce a chance to become the operating layer above the CRM, while customers risk rebuilding their org chart around one vendor’s assumptions. The strategic question is not whether these AI workers work. It is whether the enterprise owns the policies and verified business facts that make the AI workers portable across models and vendors. Build an independent rules and permissions layer before the packaged AI worker becomes the de facto manager of a business process. Salesforce
OpenAI announced the Agents API in public beta on September 10.
Developers can create a production-ready AI worker in a single API call, choose an OpenAI-managed work area, their own infrastructure, or a partner environment, and use MCP, a standard for connecting AI workers to tools, custom functions, web search, programmatic tool calling, and multi-AI worker support. OpenAI says there are no additional Agents API fees beyond the tokens and tools used. OpenAI The API exposes the infrastructure that keeps AI workers running for hours or days, including context compaction across multiple context windows, lazy tool loading, parallel tool calls, crash recovery, and sub-worker coordination. OpenAI is partnering with Blaxel, Cloudflare, Daytona, DigitalOcean, E2B, Modal, Oracle, Runloop, and Vercel across deployment, storage, and compute options. OpenAI
OpenAI is not only selling intelligence. It is selling the software environment where intelligence becomes work. That shifts the scarce asset from model access to the policy, data, tool, and deployment choices surrounding each task. The open-source Codex system that lets AI tools work together lowers inspection costs while OpenAI retains the commercial relationship, AI model upgrade path, and usage meter. Enterprises should separate the software environment from the business rules now, then price work by completed outcome rather than by AI worker seat or token volume. OpenAI
Harness published its State of Agent DLC 2026 report on September 10, based on a July survey of 700 technology professionals in the United States, United Kingdom, France, Germany, and India.
The sample covered organizations with at least 1,000 employees, 100 developers, and $100 million in annual revenue that had already deployed AI workers in production, a pilot, or a live proof of concept. Harness notes that the results describe committed adopters, not all enterprises. Harness The gap is operational. Seventy-seven percent said they were confident they had a complete inventory of AI workers, tool-connection servers, and models, but only 44% used active discovery software; 76% believed they could disable a bad AI worker in under 15 minutes, but 33% had an immediate off switch; and 74% said they understood true spend per AI worker, while 60% still exceeded their budget in the prior quarter. Fifty-eight percent reported more problems in live systems per 100 changes after deploying AI workers. Harness
This is a governance-dimension problem, not a capability problem. Enterprises are routing variable, behavior that can change from one run to the next through controls designed for predictable software code, then treating the presence of a control as proof that it works. The next enterprise moat is a verified inventory, repeatable evaluation, gradual rollout, and immediate authority withdrawal. Treat changes to AI workers as a separate production discipline this quarter, with an owner who can stop the system without a committee meeting. Harness
Anthropic’s September 11 threat-intelligence report described malicious use of Claude over the prior eight months.
Anthropic said it documented five examples of scientists using its models in ways that could support biological-weapons development, including one researcher who used Claude for weeks to plan avian-influenza mammalian-adaptation experiments. Reuters report The report also said a suspected Russia-linked group used AI across phishing, hotel Wi-Fi hijacking, and WhatsApp takeover operations targeting Ukrainian government, military, and diplomatic sectors. Anthropic said it disrupted attacks from seven China-based labs and attributed more than 151 million exchanges from May through July 2026 to Alibaba, with activity peaking at nearly 3 million exchanges per day from more than 3,500 fraudulent accounts. Reuters report
The enterprise risk is no longer a bad answer inside a chat window. It is an AI worker that can coordinate reconnaissance, code changes, tool calls, and evasion across a long-running operation. Security teams need to bind every AI worker identity to an accountable owner, restrict tools that can cause major business effects by policy, and preserve a record of what the system decided that can be reviewed after the fact. Model safety at the vendor boundary cannot replace authorization and detection inside the enterprise. Reuters report
Palantir and Nebius announced a strategic partnership on September 8.
Palantir named Nebius its preferred infrastructure partner for AI that an organization can keep under its own control and said Nebius compute and endpoints that generate model responses will move inside the Palantir protected company boundary after an integration period. Eligible customers are intended to retain control over compute, data, and models while using Nebius cloud and AI response infrastructure. Nebius The offer joins Palantir’s permissions and separation layer, built on AIP, Ontology, Foundry, and Apollo, with Nebius’s computing built specifically for AI. Customers will be able to deploy and continually adapt models whose underlying files can be controlled and adapted with proprietary data; the companies also plan modular data-center deployments at sites where power is already available. The release discloses no contract value, capacity, pricing, customer count, or integration date. Nebius
Sovereignty is moving up the stack. The buyer is no longer choosing between a public cloud and a private server; the buyer is choosing who controls the full boundary around data, models, compute, and permissions. Palantir is trying to own that boundary while Nebius supplies the scarce physical substrate. Boards should demand a written ownership map for trained model files, training data, logs, AI response cost, and exit rights before approving a “sovereign” architecture. Nebius
Google Cloud announced a new plugin for AI coding workers on September 10.
The open google-cloud-developer plugin is available in the Google Agent Skills repository and is designed for Antigravity, Claude Code, and Codex CLI. It gives AI workers access to Google Cloud skills, official documentation through the Developer Knowledge tool-connection server, programmatic interactions, and guidance for authentication, authorization, project management, and gcloud guardrails. Google Cloud The onboarding example checks the live environment, considers identity and access practices such as avoiding accidental key leaks or commits, outlines a workflow, and offers to act before modifying resources. That places cloud permissions inside the coding-AI worker workflow instead of leaving the AI worker at the edge of the infrastructure. Google Cloud
The AI coding worker is becoming a cloud operator. That compresses the distance from intent to infrastructure change, while making authorization and rollback part of the developer experience rather than a separate security review. The next engineering metric is not lines of code or even deploy frequency. It is how quickly a team can move from a stated intent to a verified, reversible production change. Give AI workers narrow permissions, require a preview before mutation, and measure the quality of the resulting system. Google Cloud
Shelly Palmer argues that the important development is not the credit dispute around recent AI breakthroughs, but the emergence of AI systems that can coordinate large amounts of work across mathematics and science.
He cites a reported deployment of roughly 10,000 AI workers and millions of dollars in compute for a finite-time singularity proof, alongside AlphaGenome Atlas predictions for all 9 billion possible single-letter DNA variants in a one-petabyte dataset. His angle aligns with today’s read on persistent coordination, but it raises the bar: the enterprise must measure the quality and accountability of the work produced, not the number of AI workers deployed. Standing on the Shoulders of Agents
The competitive unit is shifting from an AI feature to an accountable system that can complete work across tools and time.
Choose one revenue-bearing workflow this quarter, define the business outcome and authority boundary, and build the operating model around the result. Keep models interchangeable, keep proprietary process knowledge owned by the company, and make every AI worker’s scope visible to the executive team.
The market is forming underneath the application layer, where AI workers, tools, rules, and computing meet.
Salesforce, OpenAI, Google Cloud, Palantir, and Nebius are each trying to own a different part of that coordination surface, so pricing power will migrate toward whoever controls identity, data rights, deployment, and switching costs. Expect category boundaries to blur as CRM, cloud, security, and workflow vendors compete to become the enterprise’s central management system.
Trust becomes a product attribute when an AI worker acts for the customer.
Publish what the AI worker can do, what it cannot do, when a human takes over, and how customer data is used. Package outcomes and service levels around completed work, not access to a model, and use portability as a negotiation lever with every platform vendor.
Create an AI worker operations team with ownership for inventory, evaluation, rollout, incident response, cost, and retirement.
Redesign workflows so humans handle judgment, exceptions, and accountability while AI workers handle repeatable coordination. Require a reversible change path before any AI worker can change live systems or customer records.
Agent economics are moving from seat licenses to task, tool, compute, and outcome costs.
Build a monthly view of spend and quality by workflow, include the cost of human review and failure recovery, and fund the workflows with the clearest expansion in capacity or revenue rather than the highest demo score.
Separate the model software environment from the enterprise rules and company-data layers.
Stand up a common identity, tool registry, evaluation suite, record of actions, and immediate off switch before scaling multi-AI worker work. Require every vendor to disclose data retention, the ability to move between AI models, environment controls, versioning, and how the company can leave.
The board should treat authority given to AI workers as a new control category.
Approve the risk appetite for AI workers that can change code, move money, contact customers, or alter records, and require named executives to own the consequences. A vendor’s safety claim is not the company’s accountability system.
The consequential shift is that enterprise AI is becoming persistent, connected, and operational. The broken assumption is that a model or chatbot can be governed as a static software feature. The decision is whether to build an independent authority layer now, or let a platform vendor quietly become the operating system for your business. Are you building a company that can direct accountable digital workers, or are you buying disconnected assistants and calling it transformation?
Signature: Build the system that lets AI tools work together. Price the outcomes. Redesign the org.
The Transformation Brief is written daily by Les Ottolenghi. Delivered every morning at 6:00 AM MT, a 7-minute read on the AI shifts that matter to operators and boards.
Build the harness. Price the outcomes. Redesign the org.