AI Transformation Brief

The AI Transformation Brief—September 13, 2026

Written by Les Ottolenghi | Sep 13, 2026, 8:00:32 AM
 
09.13.2026
 
 
// Daily Brief

The AI Transformation Brief

 
LOBy Les Ottolenghi5 STORIES  /  7 VANTAGE POINTS  /  11 MIN READ

// Today’s Signal

Enterprise AI is crossing a line from feature adoption to AI tools carrying out work on the company’s behalf. OpenAI is exposing the software environment where an AI tool runs that lets agents work for hours or days, Salesforce is packaging agents around business functions, and DeepSeek is making model changes a live selection of which AI model handles a business task event. Anthropic’s threat report shows the same coordination capability in hostile hands, while EU enforcement makes inventory, documentation, and authority boundaries an operating requirement. The scarce asset is not access to intelligence. It is the accountable system that decides what intelligence may do, with which data, through which tools, and with what evidence afterward.

// Top Stories

OpenAI announced the Agents API in public beta on September 10.

Developers can create a production-ready agent in a single API call, choose an OpenAI-managed sandbox, their own infrastructure, or a partner environment, and use a standard that lets AI tools connect to outside services, custom functions, web search, programmatic tool calling, and support for several AI tools working together. OpenAI says the API is available to all developers with no additional Agents API fee beyond the tokens and tools used. OpenAI The service is designed for agents that run for hours or days and can work across multiple context windows. OpenAI is partnering with Blaxel, Cloudflare, Daytona, DigitalOcean, E2B, Modal, Oracle, Runloop, and Vercel for deployment, storage, and compute options. The company says its managed system that lets AI tools work together safely handles shortening older conversation history so work can continue, loading only the tool instructions an AI needs for the current task, parallel calls, crash recovery, and assigning parts of a task to separate AI tools and combining their results. OpenAI

My Analysis

OpenAI is moving the commercial boundary up from model access to the software environment where an AI tool runs that turns model access into durable work. The scarce asset becomes the rules, information, tools, and operating environment surrounding each task, not the raw call to a model. The open-source Codex system that lets AI tools work together safely lowers inspection costs while OpenAI keeps the model upgrade path and usage relationship. Enterprises should separate the software environment where an AI tool runs from their business rules now, then price the completed outcome rather than the agent seat or token volume. OpenAI

Salesforce introduced seven job-ready Agentforce agents on September 11 for customer service, IT and HR, commerce, sales, supply chain, inbound lead generation, and customer experience.

Casey, Paige, Carter, Marshall, Piper, and Fin are generally available now; Hunter is in pilot with general availability planned for November 2026. Salesforce Salesforce says Agentforce and Slack have delivered 7 billion Agentic Work Units, including 3.2 billion in Q2. The release cites customer examples including 50% of Engine chat inquiries resolved by Eva, 60% of Perk sales pipeline built by Hunter, 90% of Hibbett core shopper journeys handled by Hibbett AI, and 79% of Anthropic conversations handled by Fin resolved without a person handling each steply. Salesforce

My Analysis

Salesforce is trying to make the agent the new unit of enterprise labor. The value is moving from an isolated model response to the system that connects identity, context, permissions, workflows, and measured outcomes. That gives Salesforce a route to become the operating layer above the CRM, while customers risk rebuilding their org chart around one vendor’s assumptions. Build a neutral central permission system before a packaged agent becomes the de facto manager of a business process. Salesforce

Anthropic’s September 2026 threat-intelligence report covers activity it disrupted between December 2025 and August 2026 across seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation.

Anthropic says the cases involved Claude Haiku, Sonnet, and Opus, with one illicit distillation case involving a Fable or Mythos-class model. Anthropic The report says one campaign targeted more than 20 distinct organizations, scanned systems across more than two dozen Ukrainian government organizations, bulk-exported mailboxes from at least two drone-component manufacturers, and exfiltrated more than 300,000 national identity records and commercial registry data for more than 500,000 companies. Anthropic says AI compressed the labor and tooling gap that once separated well-resourced operations from less capable operators. Anthropic

My Analysis

The enterprise risk is no longer a bad answer inside a chat window. It is an agent that can coordinate reconnaissance, code changes, tool calls, and evasion across a long-running operation. Security teams must bind every identity assigned to an AI tool to an accountable owner, restrict high-impact tools by policy, and preserve a decision record that can be reviewed after the fact. Vendor safety controls do not replace authorization and detection inside the enterprise. Anthropic

DeepSeek introduced V4.1-Flash as the smallest model in its new architecture family, with a 552B-parameter model design that activates only part of a very large model for each task design, 8B active parameters for input, 16B active parameters for output, and native multimodal support.

DeepSeek says the model uses one-quarter of the previous generation’s HBM for its stored context that helps an AI model respond faster and one-eighth of the previous generation’s SSD storage. DeepSeek DeepSeek says V4.1-Flash is live on its API and that V4-Pro requests will route to V4.1-Flash at V4.1-Flash rates starting September 14 at 04:00 UTC. The company is retiring the V4-Flash and V4-Flash-Vision-Exp identifiers, while compatibility identifiers temporarily route to the new model. DeepSeek also says official partners WorkBuddy, CodeBuddy, and OpenCode support V4.1-Flash. DeepSeek

My Analysis

The strategic signal is not another benchmark race. It is that model choice is becoming a live routing problem inside live business systems, with compatibility aliases, cache costs, storage footprints, and automatic migration affecting the total cost of a workflow. A model vendor can change the underlying engine without changing the customer’s endpoint, which is convenient until the customer loses control of quality, data handling, or failure behavior. Require testing each AI model on the company’s real work, automatic records of what each task costs, and an explicit rollback path for every production route. DeepSeek

DLA Piper’s September 11, 2026 Innovation Law Insights says the EU EU law governing AI systems enforcement provisions became operational on August 2, 2026.

The analysis says obligations applying to companies that use AI in their operations, meaning companies that use AI in their operations, were not postponed, and that companies must respond to information requests from the European Commission, the AI Office, and national authorities. DLA Piper The guidance recommends mapping every AI system in operation, including AI embedded in human resources, customer relationship management, security, and procurement software, plus tools adopted by individual teams. It also says companies should identify their role for each system, determine which systems are high-risk, maintain documentation before a request arrives, and define written boundaries between autonomy and human authorization. DLA Piper

My Analysis

The compliance problem has moved from a policy document to a live map of permission for an AI tool to act on the company’s behalf. If an enterprise cannot name every system, owner, data path, and stop condition, it cannot prove control when a regulator or customer asks. The practical move this quarter is to make the complete list of AI tools and where they are used a management system connected to procurement, security, legal, and incident response, not a spreadsheet owned by one technology team. Treat every without a person handling each step action as a traceable business decision. DLA Piper

// Shelly Palmer Pulse

Shelly Palmer’s latest relevant post argues that the NSA, CISA, and FBI have named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI in an advisory about industrial-scale copying useful capabilities from a larger AI model into another model activity targeting Claude, GPT, Gemini, and Grok.

Palmer’s conclusion is direct: “Every company needs a Claw strategy.” His angle aligns with today’s read on delegated capability, but the enterprise implication is broader than model theft: every company needs a plan for what its own agents can access, what they can copy, and how that activity is detected. America Names the Model Thieves

// What It Means For Your Business

WHOLE-COMPANY  /  WHOLE-MARKET

The competitive unit is shifting from an AI feature to an accountable system that can complete work across tools and time.

Choose one revenue-bearing workflow this quarter, define its business outcome and authority boundary, and redesign the operating model around the result. Keep models interchangeable and keep proprietary process knowledge owned by the company.

The market is forming underneath the application layer, where agents, tools, policies, and compute meet.

Salesforce, OpenAI, DeepSeek, and security vendors are competing to own different parts of that coordination surface, so pricing power will migrate toward whoever controls identity, data rights, deployment, and switching costs. Expect CRM, cloud, security, and workflow categories to converge around the enterprise central control system.

Trust becomes a product attribute when an agent acts for the customer.

Publish what the agent can do, what it cannot do, when a human takes over, and how customer data is used. Package outcomes and service levels around completed work, not access to a model, and use portability as a negotiation lever with every platform vendor.

Create an team responsible for AI tools that act on their own with ownership for inventory, evaluation, rollout, incident response, cost, and retirement.

Redesign workflows so humans handle judgment, exceptions, and accountability while agents handle repeatable coordination. Require a reversible change path before any agent can mutate live business systems or customer records.

Agent economics are moving from seat licenses to task, tool, compute, and outcome costs.

Build a monthly view of spend and quality by workflow, include the cost of human review and failure recovery, and fund the workflows with the clearest expansion in capacity or revenue rather than the highest demo score.

Separate the model software environment where an AI tool runs from the enterprise company rules and information layers.

Stand up a common identity, tool registry, evaluation suite, audit trail, and kill switch before scaling work involving several AI tools that act on their own. Require every vendor to disclose data retention, ability to switch AI models without rebuilding the workflow, environment controls, versioning, and how the company can leave a vendor.

The board should treat authority given to an AI tool as a new control category.

Approve the risk appetite for agents that can change code, contact customers, access sensitive records, or alter live business systems, and require named executives to own the consequences. A vendor’s safety claim is not the company’s accountability system.

 
// The Take

The consequential shift is that enterprise AI is becoming persistent, connected, and operational. The broken assumption is that a model or chatbot can be governed as a static software feature. The decision is whether to build an independent central permission system now, or let a platform vendor quietly become the operating system for your business. Are you building a company that can direct accountable digital workers, or are you buying disconnected assistants and calling it transformation?

Signature: Build the system that lets AI tools work together safely. Price the outcomes. Redesign the org.

The Transformation Brief is written daily by Les Ottolenghi. Delivered every morning at 6:00 AM MT, a 7-minute read on the AI shifts that matter to operators and boards.

Build the harness. Price the outcomes. Redesign the org.

AI TRANSFORMATION BRIEF · 09.13.2026 · fuzebox.ai