The day AI stopped being a feature and started acting

· 5 min read
AI-generated image: The day AI stopped being a feature and started acting
AI-generated image

The common thread today is that AI inside business software has stopped being a switch you toggle and started being something that acts on your behalf. That changes the buyer's job: the question is no longer only what a tool can do, but what it can reach, what it decides, and what happens when it gets something wrong.

Most teams adopt AI features the way they adopt any other convenience. Someone finds a tool that summarises meetings or drafts replies, it saves an hour, and it spreads by word of mouth. What rarely travels with it is a clear account of what that tool can see. When software only shows you information, an over-broad permission is a privacy question. When software acts — sends the email, updates the record, moves the deal — the same permission becomes an operational one. At 360REV we treat that boundary as a first-class setting rather than an afterthought, but the discipline matters whatever tools you run.

Audit what an agent can reach before you let it act

The most useful piece today is a plain guide to auditing an AI agent's access. It opens with a familiar scene: a friend who loved an AI meeting-summary tool until he was asked a simple question about it. "It was only then that he realized he'd never actually looked into it." [1] That is the whole problem in one sentence. The tool worked, so nobody checked what it could touch.

An access audit is not a technical ritual. It is a short list of questions you can ask about any AI tool before you trust it with real work:

  • What data can it read — only what you paste in, or your whole mailbox, calendar, and customer records?
  • What can it change or send, and can it do so without a human confirming?
  • Where does what you feed it go, and how long is it kept?
  • Who else in your company inherits that access when they turn the feature on?

Run those questions once per tool and write the answers down. The point is not to find a scandal. It is to make an informed choice instead of an accidental one. An agent that can only read the text of a single meeting is a small risk. An agent that can read everything and act unattended is a decision that deserves a moment's thought. This connects directly to the habits we have written about before in what AI should and should not do in your business: the boundary you draw around access is the boundary you draw around trust.

When the CRM itself starts to act

A second piece rounds up autonomous AI CRM tools — systems where the CRM does not just store contacts but takes actions inside your pipeline. The author frames how far the category has travelled by remembering where it started: "My very first CRM was a DOS-based system I was forced to use in 2009." [2] A CRM that could not integrate with anything is now, a decade and a half later, a CRM that can decide what to do next.

Autonomy in a CRM usually means one of a few concrete things: it drafts and sometimes sends follow-ups, it scores or re-orders leads, it updates fields it thinks are stale, or it triggers a sequence when a signal appears. Each is genuinely useful and each carries the same trade-off as the access question above. An action taken for you is only a saving if it is the action you would have taken. The practical test before you switch autonomy on is to ask which decisions you are comfortable delegating and which you want to keep. We have argued elsewhere that some choices belong to a person no matter how good the automation gets; that argument applies squarely here, and it is worth reading alongside what a CRM is actually for before you hand your pipeline to one.

Vertical software is turning AI-first

The context for both of the above comes from a look at Toast, the restaurant-focused platform now running at roughly a $6.5 billion revenue run-rate. The write-up's summary is blunt about the direction of travel: "AI Vertical SaaS is hot now." [3] The interesting part for a buyer is not the size of one company. It is that software built for a single industry is where AI is landing hardest, because a tool that already knows your industry's data can act on it more usefully than a general one.

The trade-off is depth against breadth. A vertical tool that understands restaurants, or clinics, or law firms can automate more of your specific work, but it commits you to that vendor's view of your world. A general platform asks you to configure more but keeps you portable. Neither is the right answer for everyone. The right answer depends on how standard your work is and how much you value being able to leave — a point we made in the data you should be able to export on any Tuesday.

Buying a CRM once you have outgrown the basics

For teams shopping now rather than in theory, there is a fresh roundup of CRMs aimed at small businesses. It names its reader precisely: "You have a good client base, your metrics are solid, and now you're looking to scale." [4] That is a specific moment. It is the point where a spreadsheet or a starter tool stops keeping up but a heavyweight platform would be more than you can use.

When you are at that stage, the useful comparison is not the feature grid. It is fit. Does the tool match the way your team already works, or does it demand you rebuild your process around it? Can everyone who needs it actually get in through one login, and can you get your data back out cleanly if it does not work? Those questions matter more than any single capability, and they are the ones a marketing page is least likely to answer. If you are weighing this, choose software worth using walks through the same judgement in more detail.

Know which model sits under the tool

Underneath most of today's AI features is a large language model, and a plain-language guide to the current field is a fair reminder of that. As it puts it, "Large language models (LLMs) are what most people think of when they think of AI." [5] You do not need to become an expert to buy well. But it helps to know that the model is a component your vendor chose, that different models cost and behave differently, and that the tool's answers are only as good as the model behind them plus the data it is allowed to see.

The thread ties back to where the day started. Whether you are letting an agent read your calendar, letting a CRM act on your pipeline, or picking a platform for the next stage of growth, the same two questions do most of the work: what can it reach, and what will it do without asking. Answer those before you sign, and most of the rest sorts itself out.

Sources

  1. [1] How to conduct an AI agent security audit — Zapier
  2. [2] The 6 best autonomous AI CRM tools in 2026 — Zapier
  3. [3] 5 Interesting Learnings from Toast at $6.5 Billion Run-Rate: 22%+ Growth, Profitable, No Deceleration. But AI Is Just Getting Started — SaaStr
  4. [4] The 11 best CRMs for small business in 2026 — Zapier
  5. [5] The best large language models (LLMs) in 2026 — Zapier

The 360REV newsletter

What is actually changing across productivity software, written for operators and cited to sources. No more than one email a day.

Double opt-in — we send one confirmation link and nothing else until you click it. Unsubscribe from any edition. We never sell or share your address.