When AI agents start doing the work themselves

· 6 min read
AI-generated image: When AI agents start doing the work themselves
AI-generated image

Read together, the day's announcements point one way: AI agents are moving from tools that suggest to systems that act, whether that means interviewing a candidate, renewing a contract, or quietly learning how your company works. The harder story underneath is governance — who owns the context these agents absorb, what happens when the rules around them misfire, and whether the money is producing anything you can measure.

That shift matters most to the person choosing tools, because an agent that only drafts is a convenience, while an agent that acts is a decision-maker you have to supervise. The line between the two is where most of the risk now sits. Before you decide whether a product deserves a place in your stack, it helps to be clear about what each of these launches actually changes, and what it quietly asks of you in return.

An assistant that learns your company from its chat history

The most consequential item is also the quietest. An always-on AI assistant that sits inside your team chat and reads along is useful from the first day — it can answer questions, summarise threads, and surface what someone already worked out last month. But the reporting on this launch is direct about the second effect: beyond productivity, the feature is a way to capture organizational context, institutional knowledge, and enterprise workflows [1].

That is the part worth slowing down for. Every day your team spends talking to an assistant, the assistant learns more about how your company runs — and that accumulated understanding lives wherever the assistant does, not with you. It is genuinely valuable, which is exactly why it is worth asking, before you adopt it, how much of it you could take with you later. The knowledge your team builds up in conversation is an asset, and an asset you cannot export is an asset you only rent. This is the same question we raise in what happens to your data when you leave: the test of any system that learns your business is whether the learning is portable.

None of this is a reason to avoid these tools. It is a reason to treat the context they gather as something you own, and to write that expectation into how you choose. The related habit — deciding in advance what AI should and should not do in your business — is the difference between a helpful teammate and a black box that knows more about your operation than you can retrieve.

When an agent renews your software, and the guardrails break

The clearest picture of agents doing real work came from an operator account rather than a launch. In the latest episode of a series on running a company with a large fleet of agents, the setup is described plainly: three humans, more than twenty-one agents, and revenue that moved from a fall to sharp growth over a year [2]. The same instalment reports three things that belong together: they added too many guardrails and broke their own agent, an AI finance role found a setting the company had missed for eight years, and an agent now handles software renewals.

Each of those is a lesson. The renewal example is the sharpest, because renewing a contract is not drafting — it is committing money on your behalf. Handing that to an agent is a decision about authority, not productivity, and it is exactly the kind of choice we argue you should make deliberately in decisions automation should never make. The guardrail failure is the counterpart lesson: controls that are too tight can stop an agent from working at all, so the goal is not maximum restriction but the right restriction. And the eight-year-old setting is a reminder that these systems are good at finding things humans stopped looking at — a real benefit, as long as a human still reviews what they surface.

Automation code becomes a governed part of the suite

A less dramatic announcement carries real weight for anyone who worries about compliance. The scripting layer that many teams use to automate work inside a major office suite is now officially a core service, covered under the same commercial terms and data protection as the rest of the platform [3]. That is a status change, not a feature, and status is what procurement and security teams actually buy.

The practical point is this: home-grown automation tends to accumulate in the corners of a business, written by whoever was handy, governed by nobody. Bringing that code under the same terms as the rest of your suite is a step toward treating automation as infrastructure rather than a favour. It also underlines a broader expectation — that the tools you rely on keep a record of what ran and under whose authority. That expectation is the whole subject of the audit trail nobody thinks about, and it is the thing most small teams only wish they had after something goes wrong.

AI agents in the interview seat

Hiring is one of the most human tasks a business does, which is what makes the next item a genuine trade-off. A Stockholm startup raised four million dollars to build a video-first hiring platform that combines AI interview agents with short-form video profiles, described as something between a professional network and a short-video app [4].

The appeal is obvious for anyone drowning in early-stage screening: an agent can conduct a first conversation at any hour and at scale. The cost is equally clear. An interview is a two-way judgement, and a candidate's read on the person across the table is part of what makes them accept an offer. There is a real question about what a first impression means when the first impression is a machine. This is not a reason to dismiss the model — screening volume is a genuine problem — but it is a reason to be honest about which parts of hiring you are automating and which you are quietly removing. The framework in what AI should and should not do in your business applies directly: automate the sorting, keep the judgement.

Whether the spending is actually working

The day's most grounding note came from the payments world, reporting back from a large hospitality technology conference. More than six thousand executives gathered, and the headline question was not which AI to buy but whether the industry's AI investment is actually working [5].

That question is the right one to end on. Every item above asks you to spend — money, trust, or the context your team generates — on the promise that an agent will do more than assist. The discipline is to insist on evidence before you scale, not after. Decide what result would prove a tool earned its place, measure it, and be willing to stop if the number never arrives. It is the same rule we set out in what to measure in the first 90 days: a tool that cannot show you what it changed has not yet earned the renewal that, increasingly, an agent may be the one to sign.

The agents are arriving. The work now is deciding, for each one, exactly how much of your business you are prepared to let it run.

Sources

  1. [1] Anthropic's Claude Tag is learning your company, one Slack message at a time — TechCrunch
  2. [2] We Added Too Many Guardrails and Broke Our Own Agent, Our AI VP of Finance Found a Setting We'd Missed for 8 Years, and an Agent Is Now the One Renewing Your Software: The Agents #007 — SaaStr
  3. [3] Google Apps Script is now a Google Workspace core service with enterprise-grade data protection — Google Workspace Updates
  4. [4] Fika Jobs raises $4M to build a video-first hiring platform where AI agents interview candidates — TechCrunch
  5. [5] Four travel and hospitality trends from HITEC 2026 — Stripe

The 360REV newsletter

What is actually changing across productivity software, written for operators and cited to sources. No more than one email a day.

Double opt-in — we send one confirmation link and nothing else until you click it. Unsubscribe from any edition. We never sell or share your address.