It’s October… and things are getting a little scary… starting with the jobs numbers. September ticked up to 4.2% with employers adding only 29,000 jobs — 60,000 fewer than expected. Three days before those numbers came out, McKinsey estimated that 770,000 Americans will need to switch occupations every year. Those switchers would ostensibly be job-hunting in a market that’s barely hiring.
Always-on agents are getting shipped by every platform, alongside agent safety layers, which comes as a time when there’s growing concern around agents. Surveys show that most companies can’t say which agent did what, and most consumers aren’t willing to give one access to their inbox. Speed connects all of it: the products are shipping, and the workforce estimates are landing, before anyone has built the identity controls or the training they depend on.
Last week’s coverage:
Vendors Are Selling Agent Safety. Buyers Are Sharing Credentials. Nvidia and OpenClaw are selling containment, and a VentureBeat survey shows most companies still can’t say which agent did what.
Vendors Shipped Agent Coworkers. Buyers Haven’t Said Yes. OpenAI, Meta, and Microsoft are putting agents on payrolls, and only 7% of people in one poll would let one move their money.
McKinsey Says 11 Million Workers Have to Move. Most Don’t Have a Path. The jobs will exist; getting displaced workers into them is where the numbers get ugly.
AI Writing Is Converging, and the Tells Keep Changing Researchers cataloged 13,000 AI tells while a psychologist argued the bigger problem is sameness of ideas.
Here’s what I was reading.
Vendors Are Selling Agent Safety. Buyers Are Sharing Credentials.
Nvidia launched its Open Agent Safety Platform Monday with more than 100 partners and a claim that the platform would have stopped July’s Hugging Face breach. A CNBC piece quoted Nvidia’s enterprise AI VP saying that Hugging Face had reported more than 17,000 agents attacking its infrastructure over days and weeks. Hugging Face’s own July disclosure, per a separate report, describes 17,000 recorded events in an attacker action log... not 17,000 agents. Nvidia has also agreed to buy Hugging Face for about $12.9 billion, and its launch materials included no independent test results. The bottom line is that Nvidia is asking buyers to trust a safety claim that hasn’t been tested independently, about a company it’s acquiring. (Nvidia releases software platform to stop AI agents from misbehaving) (Nvidia Says Its New Agent Safety Platform Could Have Stopped the Hugging Face Breach)
Gartner called OpenClaw an unacceptable cybersecurity risk for business users back in February, and IT’s default answer to agent platforms like it has been to ban it. Now, Red Hat, Nvidia, OpenAI, and others are building OpenClaw Enterprise, billed as “Kubernetes for agents.” An OpenAI staffer on the project admitted that persistent agent deployments remain limited and that most IT teams ban these platforms outright. That’s a vendor describing its own market, which is rare. (OpenClaw slips on a suit to evade widespread business bans)
Permissions without identity let a company limit what an agent can do but not say which agent did it.
Fifty-four of 137 respondents in VentureBeat’s August agent security survey said they enforce scoped permissions at runtime. Thirty-seven of those also run agents in production, and only 15 of the 37 give every agent its own managed identity. The other 22 run some or most agents on shared credentials. Permissions without identity let a company limit what an agent can do but not say which agent did it. A CISO quoted in the piece (a former KPMG auditor) called it an accountability problem which is the right frame.
Using isolation to control agent access sounds good on paper, but even after the portal blocked it, an OpenAI agent reached Australia’s Medicare statistics service... OpenAI found out about it 54 days later. The same VentureBeat survey shows that only 12 of the 137 respondents said high-risk agents run in isolation, while 64 of the 109 organizations running agents reported an incident or near-miss in the past year. It’s a self-selected sample, which VentureBeat admitted, but points to the complexity of containment and permission management. (22 of 37 surveyed companies that enforce AI agent permissions still have agents sharing credentials)
Vendors are selling the containment layer, most buyers haven’t built the identity layer to support it. The question I’d put to any of them is simple: when something goes wrong, can you tell me which agent did it?
Vendors Shipped Agent Coworkers. Buyers Haven’t Said Yes.
If the issue of managing agent permissions isn’t concerning enough, the “always on” agents that are being shipped simultaneously by OpenAI, Meta, Microsoft, and more, are worth considering. Access sharing at the individual level is being requested more and more by the AI.
OpenAI’s Dots keep working after an employee closes the chat window. They get their own cloud computer and browser, connect to more than 4,000 apps through plugins, and report back through ChatGPT, Slack, and Microsoft Teams. A VentureBeat piece added the part enterprise buyers should read twice: OpenAI is piloting specialist Dots with their own organizational identity and credentials, and working with Microsoft to bring them under Agent 365. Custom Rules and an Activity View sit on top, with an auto-review layer deciding what needs a human’s approval. The first Dot is free for Pro and Business Premium customers. OpenAI hasn’t said what the next one costs. (OpenAI launches Dots, always-on AI agent coworkers, and ChatGPT Space where they can collaborate with human teams)
Meta’s Muse hit about 2.8 million downloads in its first two weeks. Tuesday, Meta pushed it toward small businesses — a Reuters piece added the business angle. Integrations with Shopify, QuickBooks, Stripe, and Canva come with it, and about a third of Muse users have already connected a business account, per a Wall Street Journal report that VentureBeat relayed. Employees will arrive with personal agents before IT has finished sanctioning the corporate ones. (Meta expands Muse AI agent for small businesses)
A Thales poll found that only 13% of respondents would let an AI agent read their email and 7% would let one move money between accounts. A Futurism piece set that poll against Muse’s download numbers, and added one user’s claim that Muse gave his home address to strangers on Facebook Marketplace. Downloads measure curiosity; those two percentages measure what people are willing to delegate. (The poll covers consumers, but the employees in your organization are consumers too.) (The AI Industry Has a Major Problem: Most People Aren’t Freaks Who Want an AI Agent Running Their Whole Life)
Meanwhile, Microsoft’s stock is aiming higher — but it’s not just the product that’s driving it. Piper Sandler raised its Microsoft price target to $610 from $550 on the E7 bundles with Copilot, E5, Entra, and Agent 365 news. Piper estimates that every 10% of seats moving from E5 to E7 adds $2 billion in annualized revenue. Microsoft said hundreds of customers bought millions of E7 seats in the first two months, and EY rolled it out to 400,000 employees. Microsoft is also moving from per-seat licensing to seat-plus-usage pricing, which turns what used to be a fixed line in the budget into a variable one. Piper expects Copilot and Cowork consumption revenue to reach a $2 billion annualized run rate by fiscal 2028. Nothing I read last week explained how a buyer would measure what that usage produced. (Piper Sandler Raises Microsoft Target, Sees Billions in Potential From E7 and AI)
📌 AUTHOR’S NOTE
As a Microsoft partner, that variability is why I built a Microsoft Copilot license calculator to help companies get a better sense of what the actual costs could look like, and where licensing vs agents could make the most sense. Check it out and let me know what you think.
McKinsey Says 11 Million Workers Have to Move. Most Don’t Have a Path.
McKinsey Global Institute put its base case at roughly 11 million American workers, about 7% of the labor force, changing occupations over the next decade. That works out to 770,000 people a year against a long-run average of about 215,000. The pace would run roughly three to four times the historical rate, close to the 788,000-a-year level of the pandemic years. An Axios piece added that, for those that keep their jobs, 70% of workers will need some degree of role reinvention. That news comes as employee confidence on Glassdoor fell to a record low in September, with AI mentions in employee reviews up 164% from a year ago. (How AI could change the workforce)
McKinsey expects about 41 million jobs to be created against 36 million cut by 2035. A net positive of roughly 5 million jobs. The jobs will exist. Reaching them is the problem. Only one in seven displaced workers has a direct path into a growing job, about 85% of those jobs require a credential, and roughly 76% can’t be done remotely. The shrinking work sits in office administration, retail, and transportation, where lower-wage workers are 7.6 times as likely to need a new occupation. The growth is in healthcare, construction, and management. (McKinsey: AI will create more jobs than it kills — after destroying 11 million | Fortune)
A WSJ piece described marketers retitling themselves “marketing engineers,” with Greg Bresnitz recalling the moment he settled on the label. As AI claims more of the work, reinvention is one way workers can attempt to control their destiny. But a new title is cheap and easy. Reinventing roles for 70% of the workforce takes training that somebody will have to pay for. (Move Over, Storytellers: The Marketing Engineers Are Here)
AI Writing Is Converging, and the Tells Keep Changing
Graphite, a marketing company, claims to have catalogued about 13,000 words and phrases it says flag AI-written text. The top one is “this matters,” which shows up 116 times more often in AI-generated content than in human samples. A Gizmodo piece added the model-by-model split: Claude Opus 5.5 leans on that phrase most, but its em dash use fell 99% from Opus 5, while OpenAI’s Astra is trending toward less human-sounding text. Here’s why “this matters”: for each published tell, models continue to edited them out of their next version, which makes detection a moving target rather than a control. (‘This Matters’: Researchers Identify Thousands of New Tells in AI Writing)
In a 2024 Science Advances study, 300 people wrote short stories, and the AI-assisted stories were rated more creative and were also more similar to each other. A 2026 PNAS Nexus study gave creativity tests to 22 AI models and more than 100 people, and the models’ answers were far more alike than the people’s. AI raises the floor on each person’s output and lowers the variety across the organization. A Psychology Today piece called out the mechanism: the first answer a person sees tends to pull everything after it toward itself, and AI is handing millions of people the same first answer. The author’s fix is practical, if low-tech. Write three rough lines of your own before opening the chat window. (AI makes your work easier. Yet it also makes you sound like everyone else.)
A writer can scrub every tell from a draft and the sameness is still there, because it lives in the ideas rather than the phrasing. That’s a quality problem for any team publishing AI-assisted work, and it’s a governance question before it’s a style question.
Twenty-two of 37 surveyed companies enforce agent permissions and still have agents sharing credentials. Six in seven displaced workers have no direct path into a growing job. Usage billing is arriving ahead of any agreed way to measure the result... that’s what buying speed first looks like when nobody has built the control. Are leaders running an AI strategy if they can’t say which agent did what, or what the usage bought? In my opinion, the answer is clearly no.
That’s it for this week’s BeAIReady brief!
If you appreciate the depth of reporting and how I connect the dots, please like, share, and subscribe. Each share helps us me get the word out!
~erick


