ITS - Infrastructure Technology Solutions (319) 465-4463
Back to Blog

AI Update - September 2026

| By ITS
AI Update - September 2026

Everyone is shipping a personal agent

Last month I wrote about Grok Bot as a coworker with its own cloud computer. That idea is no longer a one-vendor experiment.

This month Meta pushed Muse as an always-on helper that can email, call, and work across the apps a business already uses. Microsoft rebuilt Copilot around Home, Code, and Autopilot. Autopilot is now as a persistent agent with its own identity and workspace inside your tenant. Open AI spent today at DevDay launching dots: agents that keep working after you close the window, each with a cloud computer and a browser, plus a shared workspace they call Space.  You can be fairly confident that Anthropic will be launching something soon.

All of these vendors want you to assign ongoing work to something that does not wait for the next prompt.

That is useful. It is also a lot of new surface area. If you connect one of these to email, files, or your bookkeeping, treat it like a new hire. Give it its own accounts. Limit what it can touch. Keep a log of what it did.

Pacing the frontier, two weeks later

On September 14, I wrote about Dario Amodei’s essay, “WeMust Pace the Frontier,” and the pile-on that followed from other lab leaders.My take then was that this is about research inside the labs, not the chat tools we set up for customers, and that I land somewhere in the middle.

I have thought about it more. I largely agree with Nvidia CEO Jensen Huang on this topic.

My interpretation of what Jensen said was that the labs have been looking at this as a research activity and they need to treat it as an engineering problem.  This is software and it needs to have quality control. The second point that I heard was that the labs have significantly more compute than the rest of the world, that in itself gives these models more power and capabilities.  My take on it is that maybe compute capacity is a unit of measure that needs to be tracked and looked at for regulation.  Jensen has also said that we have lots of product liability laws on the books and these companies should not release products that aren’t safe. 

Washington spent a lot of time discussing the topic and as you can imagine, there was broad disagreement, roughly following political ideologies.  One thing to come out of it was Trump’s rebrand of AI as “Super Intelligence” (SI), rather than ArtificialIntelligence.  The US and China met during a summit last week.  To my knowledge, there were no AI related agreements announced other than an agreement to keep communication going.

Nvidia put a product behind the security argument

Yesterday Nvidia announced its Open Agent Safety Platform. The piece that matters for how I think about this is Sentry.

Sentry is an out-of-band watchdog. It sits off to the side of the model, on separate hardware, and is meant to quarantine an agent that tries to break out of its boundary. OpenShell is the open runtime that traces what the agent did and enforces policy outside the model itself.

I like the direction that this signals.  If we can get start to develop and implement some standard frameworks around this, maybe the industry can build back some trust.

What businesses should do

Start with the tools you already pay for. If you are onMicrosoft 365, that is Copilot Chat or Microsoft 365 Copilot, and now theCopilot app if it is in your tenant. If you already use ChatGPT Work or Claude, use those. Pick one boring workflow: inquiries, invoices, appointment follow-up, a weekly report. Measure it.

Do not add another agent platform unless it clearly does a job the current stack cannot. A new subscription that overlaps Copilot or the chatbot you already have is just another place for data to leak and another account to govern.

If you do need systems to talk to each other, connect the apps you already have. MCP (Model Context Protocol) is the cleanest common way to give an approved assistant access to a specific tool without standing up a whole new product. Power Automate and similar workflow tools still do the unglamorous work of moving a form into the CRM and sending the welcome email. That is still where most of the time is wasted.

Same rules as August if an agent can log in:

Its own account, not yours.Only the access that job needs. A human checks anything that sends money, changes a customer record, or posts in public. Approved tools, off-limits data, and a one-to-two page policy. Monitoring still matters.

Frontier pacing is a lab and Washington conversation. Your conversation is simpler. Use what you have. Connect it on purpose

If you want help deciding whether Copilot, a connector, or an actual agent is the right next step, reach out.

Joel

ITS

Need Help With This Topic?

Our team is ready to assist.

Contact Us