AI Transformation Brief

The AI Transformation Brief—September 18, 2026

Written by Les Ottolenghi | Sep 18, 2026, 7:51:40 AM
 
09.18.2026
 
 
// Daily Brief

The AI Transformation Brief

 
LOBy Les Ottolenghi5 STORIES  /  7 VANTAGE POINTS  /  10 MIN READ

// Today’s Signal

AI in large organizations is moving from a tool people open to a system that can decide when to act, what to touch, and when to ask for permission. Anthropic is collapsing quick chat and longer-running work into one interface. Snyk and Mandiant show the other side of that shift: once AI systems can use tools and credentials, security becomes a daily operating requirement, not a review step. Trip.Biz is applying the same pattern to a business process with policy and approval built in. The governance data is blunt: confidence is ahead of operational readiness. The scarce asset is accountable work completed by software, with independent validation around every action.

// Top Stories

Anthropic announced on September 16 that Claude Cowork and Claude chat are merging into one Claude.

The company says Claude will decide whether a request needs a quick answer or a longer task, and cloud work can continue after the user closes the laptop. The rollout starts with Pro and Max plans, with Team, Free, and Enterprise changes following later. Claude by Anthropic Reuters Anthropic also introduced Claude Docs and Claude Slides and moved Claude Design into conversations. The company says users can create documents, draft presentations, schedule recurring work, and keep a person in the approval loop by default. Enterprise administrators will receive at least 30 days' notice before organizational changes. Claude by Anthropic Shelly Palmer

My Analysis

The product boundary is moving from conversation mode to work authority. When one interface can answer, plan, use connectors, create artifacts, and keep working after the screen closes, the enterprise must govern a continuing process rather than a single response. The application UI becomes less important than the policy, identity, data, and approval layer behind it. Treat every delegated task as a small operating process with a named owner, a way to undo an action, and a record of what the system did. Do not let a vendor's convenience decision become your company's rules for who or what is allowed to act. Claude by Anthropic

Snyk said on September 17 that its Evo product accounts for 60% of new deal volume and has increased average contract value by 30%.

The company reports 81.5% month-over-month customer growth since its first general-availability capability launched in March 2026. Snyk also says it processes 2.4 million scans of the software tools AI systems use each month and 4.2 million checks on what AI systems do each day across more than 417,000 machines. These are company-reported figures, not an independent market benchmark. Snyk Snyk says 76% of customers that bought Evo in the second quarter were in production before the quarter ended. It describes a U.S. bank centralizing roughly 1,000 internal reusable instructions and tools for AI systems for 50,000 developers using Claude Code, with Snyk assessing the skills before registry entry and scanning them continuously after deployment. The bank is not named. Snyk

My Analysis

The security market is moving from scanning the finished artifact to controlling the tools an AI system uses and behavior while work is happening. That changes the buyer, the budget, and the operating rhythm: security now sits inside the development loop, not at the end of it. An AI system that can install a package, call a connector, or modify production has a larger attack surface than the code it produces. Put an independent validation layer between any generator and any consequential action, and measure the cost of review and recovery alongside defect counts. Snyk

Mandiant's September 2026 AI Risk and Resilience Report describes an intrusion at an unnamed software-as-a-service provider in which an attacker hijacked an active AI coding-assistant session.

The assistant recommended a poisoned dependency, the recommendation was accepted, and the attacker used the live session to install an infostealer, steal GitHub access tokens, and spread the Shai-Hulud worm across about 100 internal repositories. Google Cloud Mandiant report The Hacker News The report places that case inside a broader shift from AI helping attackers research to AI participating in multi-stage attacks. Mandiant says attackers used more than half a dozen methods against AI tools and open-source software in one campaign, and recommends identity controls, isolation, egress restrictions, dependency controls, and behavior monitoring. The public case study does not explain how the live session was taken over. Google Cloud Mandiant report The Hacker News

My Analysis

The incident breaks the assumption that an AI coding assistant is only a faster editor. A compromised session can become a trusted employee, a package installer, and a bridge into every repository that its credentials can reach. The control point is the identity and action path around the model, not the model's ability to explain code. Treat development AI systems as privileged digital identities for software: give them short-lived credentials, isolate their execution, restrict outbound access, and require human approval for new dependencies and production changes. Google Cloud Mandiant report

Trip.Biz launched Agent ONE on September 18 as a set of four connected AI systems for business travel: Planning, Booking, Approval, and Insight.

The company says the system turns natural-language requests into policy-compliant recommendations, routes low-risk approvals automatically, sends exceptions to people, and produces travel analysis. Trip.Biz announcement Morningstar Trip.Biz describes early performance targets of reducing a booking from around 45 minutes to 2 minutes, reducing approval waits from more than 1 hour to under 3 seconds, and generating an insight report in under 7 minutes instead of up to 1 week. The company reports 90% service-level compliance and more than 80% satisfaction across the region it serves. These are company-reported targets and results, not independent benchmarks. Trip.Biz announcement Morningstar

My Analysis

This is the enterprise pattern that matters: multiple specialized systems coordinated around a business outcome, with rules and human exceptions built into the flow. The AI system is not valuable because it can hold a conversation. It is valuable because it can assemble information, apply policy, route authority, and leave a measurable business record. Start with a business process where the current cost of waiting and leakage is visible, then design the exception path before automating the normal path. Trip.Biz announcement

A Schellman survey of more than 500 U.S. enterprise leaders found that 74% said their organization could pass an AI compliance audit, while only 27% said its governance program was fully mature.

The same research found that 46% had AI systems that can complete multi-step tasks on their own in production and 86% had tested them. Cloud Security Alliance Schellman The gap is operational. Ninety percent had allocated governance funding, but only 57% had a formal policy and 44% had documented AI incident-response procedures. Governance-mature organizations reported production use of these systems at 78%, compared with 22% for organizations still building their programs. Only 36% of boards regularly discussed third-party AI risk. The figures come from Schellman's survey and are not a peer-reviewed academic study. Cloud Security Alliance Schellman

My Analysis

Governance is becoming a speed capability because it turns permission to act into a business decision instead of a debate after the incident. The business cannot delegate authority to a system and keep accountability in a committee that meets once a quarter. Put a named executive over each high-impact AI process, document what the AI system may do, and rehearse the failure path before the system reaches production. Confidence without evidence is a liability multiplier. Cloud Security Alliance

// Shelly Palmer Pulse

Shelly Palmer's latest enterprise-relevant post, published after Anthropic merged Cowork and chat, argues that Claude is becoming a single work surface for quick questions, longer-running tasks, documents, presentations, and design.

He notes that cloud tasks continue after a laptop is closed, while work using local files still requires Claude Desktop to remain open. His angle aligns with today's read: the key shift is from answering prompts to managing work across time, tools, and approval points. Claude Ate its Own Apps Claude by Anthropic

// What It Means For Your Business

WHOLE-COMPANY  /  WHOLE-MARKET

The competitive unit is becoming the business process that an AI system can complete responsibly, not the AI feature.

Choose one revenue-bearing or risk-bearing process this quarter, define the outcome and the rules for what the AI system may do, and redesign the work around that result. Keep the model replaceable and the business rules owned by the company.

The market is forming around systems that connect models to identity, data, tools, policy, and human approval.

Model vendors, security companies, business process platforms, and vertical software providers will compete to own the point where the AI system can change a record or take an action, so pricing power will move toward whoever can prove trusted execution across vendors. Expect software categories to converge around that control surface.

Trust becomes part of the product when an AI system acts for a customer or employee.

Publish what the system can do, what requires approval, how exceptions are handled, and what evidence the customer receives. Package the service around completed outcomes and response times, not access to a model.

Create an owner for AI systems in daily operation for inventory, evaluation, rollout, incident response, cost, and retirement.

Redesign business processes so systems handle repeatable coordination while people handle judgment, exceptions, and accountability. Require a way to undo an action before any system can publish code, approve spend, or alter a customer record.

AI spending is shifting from seats to tasks, tool calls, compute, review, and recovery.

Track cost, quality, wait time, and failure recovery by business process each month. Fund the processes that expand capacity or revenue after review costs are included.

Separate the model service from enterprise identity, policy, data, and records that show what happened.

Put short-lived credentials, tool inventories, checks on downloaded software, controls on what the system can send out, and action logs in front of every development or business AI system. Require vendors to disclose data retention, portability, versioning, and exit mechanics.

Treat authority delegated to software as a new control category.

Approve the risk appetite for systems that can change code, contact customers, access sensitive records, or alter production systems. Require a named executive to own each high-impact process and demand evidence that controls work before the system scales.

 
// The Take

The consequential shift is that AI is becoming a persistent operator inside business processes. The broken assumption is that governance can be added after capability is deployed. The decision is whether to build an independent authority and evidence layer now, or let an AI provider quietly become the operating system for the business. Are you redesigning the company around accountable digital work, or are you still buying assistants and hoping the org absorbs them?

Signature: Build the system that lets AI tools work together. Price the outcomes. Redesign the org.

The Transformation Brief is written daily by Les Ottolenghi. Delivered every morning at 6:00 AM MT, a 7-minute read on the AI shifts that matter to operators and boards.

Build the harness. Price the outcomes. Redesign the org.

AI TRANSFORMATION BRIEF · 09.18.2026 · fuzebox.ai