AI moves inside the tools you already use
A single thread runs through the day: the assistant is moving out of its own window and into the tools where work already happens. The same shift raises an older question in a newer form, because once software can act across your accounts, someone has to decide what it may touch and keep a record of what it did.
An assistant that reaches into your other tools
For most of the past two years, an AI assistant lived in one box. You typed a question, it answered, and anything it needed to know you had to paste in by hand. The announcements today mark a different pattern: the assistant now reaches into the applications you already pay for and reads or acts on the data sitting there. Google says users will be able to use Gemini in Workspace to interact directly with Asana, Atlassian Rovo, HubSpot, Mailchimp, QuickBooks, Monday, and Salesforce through a shared protocol [1].
The mechanism matters more than the brand names. Model Context Protocol is an attempt at a common socket: instead of each vendor writing a bespoke connector to every other vendor, a tool exposes its data through one standard interface, and any assistant that speaks the protocol can plug in. For a business choosing tools, this changes the calculus. The question stops being *does this app have an AI feature* and becomes *will this app let an assistant I trust read and act on its data in a controlled way*. That is the same interoperability problem we have written about in why your tools do not talk to each other, now with a plausible plumbing standard behind it.
The trade-off is scope. An assistant that can reach seven applications can also make seven kinds of mistake, and the permission you grant once is easy to forget you granted. Treat these connections the way you would treat a new staff member with a master key: useful, and worth writing down.
A model trained for the job, not for everything
Alongside the general assistants, a narrower idea surfaced today. Salesforce and Nvidia announced Koa, which TechCrunch reports is built on an open-weight model and trained to do sales, marketing, and customer-support tasks [2]. The interesting part is the specialisation. A general model knows a little about everything; a model trained on one class of work is meant to be steadier at that work and cheaper to run.
For a buyer, this is a reminder that AI is not one commodity. A model tuned for support replies is a different purchase from a model meant to draft contracts, and the right question is *what was this trained to do* rather than *how clever is it*. Narrower often means more predictable, which for routine customer work is usually what you want.
The assistant that lives in the conversation
Slack made its own case at the same event. Its announcement describes bringing Slackbot into channels and into Salesforce, turning conversations into a single AI-powered interface for work [3]. The idea is that the place where decisions already get discussed becomes the place where the assistant acts, rather than a separate destination you have to remember to visit.
There is real value in that. The tools people actually use are the ones that sit inside an existing habit. But an assistant embedded in a conversation also blurs the line between a draft and a decision. A suggestion that appears mid-thread can be accepted before anyone has weighed it. This is why we keep returning to the idea that there are decisions automation should never make: the closer the assistant sits to the moment of choosing, the clearer your rule about who signs off has to be.
Governance arrives in the same breath as capability
The counterweight to all of this landed today too. Google introduced a capability that lets Workspace administrators configure audience sharing and sensitivity-based data conditions in a single, unified rule [4]. In plain terms: who a file can be shared with, and how sensitive its contents are, are now set together rather than in two disconnected places.
This is the unglamorous half of the AI story, and it is the half that protects you. The more an assistant can reach across your files, the more it matters that sharing boundaries are set once, clearly, and in a form you can audit. A unified rule is easier to reason about than a scatter of overlapping settings, because a boundary you cannot describe in one sentence is a boundary you cannot enforce. This is the same instinct behind the audit trail nobody thinks about: the record of who could see what is worth as much as the data itself.
Why the fraud number should change how you buy
Stripe published a figure today that belongs in every buying conversation. Analysing attempted fraud and abuse over the past year, it found that AI companies faced 4.3 times more fraud attempts than startups overall in the most recent quarter it measured [5]. The explanation is not mysterious. Fast-growing AI products attract usage that looks like demand and is actually abuse, and tools that hand out capability cheaply are a natural target.
For a business choosing software, the lesson is not to avoid young AI vendors. It is to ask how a vendor handles the abuse that comes with its own success. Does it rate-limit, verify, and monitor, or does it treat every signup as a good-faith customer. A product that has thought about fraud before you arrive is one that will still be standing when you depend on it. This sits underneath everything we mean by choose software worth using: resilience under abuse is a feature, even though no landing page lists it.
Your financial data, read where you are working
Finally, Xero described bringing a real-time view of financial data into assistants including Claude and ChatGPT, on the premise that small business owners and their advisors should not have to navigate a complex web of tools and workflows to manage their finances [6]. The pattern is the same one running through the whole day: the numbers come to where you are asking the question, rather than waiting in an application you have to open.
The promise is convenience, and it is a real one. The caution is accuracy. A financial figure quoted inside a chat still needs to be the figure of record, timestamped and traceable back to the ledger, or it becomes a confident guess. Ask where a number came from before you act on it, every time.
What to take from the day
The direction is consistent. Assistants are becoming actors inside the tools you already run, reached through shared protocols, trained for narrower jobs, and sitting closer to the moment of decision. That is genuinely useful, and it moves two older disciplines from optional to essential: deciding in advance which choices a person must still make, and keeping a clean record of what the software touched. Pick tools that make both of those easy, and the convenience is yours to keep.
At 360REV we build to that standard, with permissions and an audit trail that assume an assistant will one day act on your behalf.
Sources
- [1] Connect to more tools with Gemini in Google Workspace — Google Workspace Updates
- [2] Salesforce and Nvidia's new reasoning model is everything the AI labs should fear — TechCrunch
- [3] Dreamforce 2026: Slack's newest innovations turn AI into a true teammate — Slack
- [4] Set up sharing boundaries for Google Drive with unified data protection rules — Google Workspace Updates
- [5] What Stripe data shows about fraud at AI startups — Stripe
- [6] Xero Wherever You Work: Real-Time Financial Intelligence in Claude for Small Business and ChatGPT — Xero