
AI agents at work moved into everyday business software in the middle of 2026. On 9 July OpenAI introduced ChatGPT Work, an agent that carries out longer tasks across connected apps and files. Microsoft's Copilot Studio documentation records that every new agent now gets its own identity, and its August release notes list usage-based billing for a newer class of agents. Security agencies published advice in the same period: the UK's National Cyber Security Centre published interim advice on 20 August, and the Australian Signals Directorate published a guide to agent "harnesses" on 11 September.
An agent is software that can plan and take actions, such as sending an email, changing a record or filing a document, instead of only answering a question. For a small business that raises four questions: what it may do, what data it can reach, what it costs and where to begin.
What happened
OpenAI put an agent into most of ChatGPT's paid plans. The ChatGPT release notes for 9 July 2026 describe ChatGPT Work as an agent for longer, more involved tasks that can work across connected apps and files and produce finished documents and reports, rolling out to paid plans other than Go. Users can follow progress, approve important actions and schedule tasks to repeat. For Enterprise and Edu workspaces it arrived switched off, with a two-week preview in which administrators could opt out before it turned on automatically. A note on 10 September adds a Data plugin for analysing connected business data and states that its queries use the connected account's existing permissions.
Microsoft gave agents identities and a meter. What's new in Copilot Studio lists two relevant changes. First, Copilot Studio now automatically creates a Microsoft Entra Agent ID for every new agent, and administrators can no longer opt out at the environment level. Microsoft's Agent ID documentation says this shows each agent's connector permissions on its identity, that Microsoft Entra ID logs its sign-ins, and that administrators can target those permissions with Conditional Access policies. Second, under August 2026: usage-based billing, measured in Copilot Credits, for agents, workflows and apps built on what Microsoft calls the GitHub Copilot harness, a newer runtime offered alongside the standard one.
The UK's cyber agency published interim advice. The National Cyber Security Centre's blog post Managing the cyber risk of agentic AI, dated 20 August 2026, is described by the NCSC as practical advice until formal guidance is ready. It tells organisations to decide how much autonomy a task really needs, not to treat a model's built-in protections as the whole answer, to give an agent only the permissions the task requires, to run agents in a sandbox, and to keep the ability to halt them immediately. For logging, it says agent activity "should be treated as a form of user activity".
Australia's cyber agency explained where control sits. ASD's publication Agentic AI harnesses, published on 11 September 2026, describes the harness as the software layer that connects an AI model to an organisation's data, tools and systems. Its point is that organisations control the harness, not the model, and that many of the highest-impact risks arise from what an agent can access and do. It complements Careful adoption of agentic AI services, joint guidance published on 1 May 2026 that ASD co-authored with agencies in the United States, Canada, New Zealand and the United Kingdom.
Key details
| Question | What the vendor documentation says | What the security guidance says |
|---|---|---|
| Permissions | ChatGPT Work lets users approve important actions. Copilot Studio agents carry their connector permissions on an Entra Agent ID. | Grant only what the task needs, and require human approval for sensitive actions. |
| Data access | OpenAI's Data plugin queries with the connected account's existing permissions. | Know which data, systems and tools the agent can reach before it is switched on. |
| Cost | Microsoft bills the newer Copilot Studio agents in Copilot Credits, including while they are being built and tested. | ASD notes that many decisions affecting operating cost are made in the harness. |
| Oversight | Agent sign-ins appear in Entra logs. ChatGPT Work shows progress as it runs. | Log and monitor agent activity, make it attributable, and be able to stop it at once. |
Microsoft's overview says credits are charged for the language model's tokens, for tools and for the harness itself, and that charging starts when you start building, which includes testing an agent. Credits are bought pay-as-you-go or on a one-year prepaid plan.
Why it matters
An agent inherits access. When an agent works with the connected account's permissions, it can reach whatever that person can reach. In a small business with a shared drive where everyone can open everything, or one login used by three people, that is far too much. Untidy permissions become a larger risk with software that reads quickly and acts without tiring.
Defaults are being set for you. These features arrived inside products businesses already pay for. Some came switched off with a deadline, and some change how identity and billing work whether or not anyone asked. Somebody needs to read the administrator notices.
The model's own safeguards are not enough. Both agencies say so directly. ASD notes that some risks, including prompt injection, where text hidden in a document or web page redirects the agent, cannot be reliably fixed inside the model alone. The controls that count sit outside it: what the agent may touch, which actions wait for a person, and what is recorded.
Cost now follows usage. A per-user licence is predictable. An agent that runs on a schedule, calls tools and reads long documents consumes credits each time.
ASD lists large organisations, critical infrastructure and government as the audience for its publication, but the ideas scale down: least access, named owners, logs and an off switch.
What this means for businesses
ASD's advice is to start with low-risk use cases and expand only as controls mature. For a small or medium business that translates into a short sequence.
- Pick one contained task. Summarising supplier emails, drafting replies for a person to send, or preparing a report from one data source. Avoid anything that pays money, deletes records or emails customers unattended.
- Clean up access first. Turn on multi-factor authentication, remove shared logins and tighten file sharing.
- Give the agent its own narrow access. Where the product allows, connect only the folders, mailboxes and systems the task requires.
- Keep approvals on. Require a person to confirm before anything is sent, changed or published.
- Name an owner. One person is accountable for what each agent does and can reach.
- Find the logs and the off switch. Know where activity is recorded and how to disable the agent quickly.
- Set a budget. Check whether the feature is included in your plan or metered.
Most of this is IT housekeeping that pays off whether or not you adopt agents. We help small and medium businesses with cyber security such as access control and multi-factor authentication, with managed IT support for accounts and devices, and with business systems and integrations so that data sits in the right place with the right permissions. If your team would like to understand these tools by building something small, Comingwave Academy has a waitlist for its AI coding classes for complete beginners. To review your setup before switching an agent on, send us an enquiry.
Key takeaways
- ChatGPT Work began rolling out on 9 July 2026 with approvals for important actions and an administrator opt-out period for Enterprise and Edu workspaces.
- Microsoft's Copilot Studio now gives each new agent its own identity and bills its newer agents by usage, from the moment building starts.
- The UK NCSC (20 August) and ASD (11 September) both say not to rely on a model's built-in safeguards.
- An agent can reach whatever its connected account can reach, so tidy permissions come first.
- Start with one low-risk task, keep approvals on, name an owner and watch both the logs and the bill.
Frequently asked questions
What is an AI agent in business software?
It is an AI feature that can plan steps and take actions in other systems, such as updating a record or sending a message, instead of only producing text. The NCSC notes that the potential impact grows with the agent's autonomy.
Can an AI agent see all of my company's files?
It can usually see what the account it is connected to can see. OpenAI's notes say its Data plugin uses the connected account's existing permissions, for example. If staff accounts have broad access, so will an agent acting for them.
How much do AI agents cost?
It depends on the product. Some agent features come as part of a paid plan. Others are metered: Microsoft bills its newer Copilot Studio agents in Copilot Credits based on consumption, including during building and testing. Check the billing page for the specific feature before you start.
Is it safe to let an agent send emails or make changes by itself?
Not at the start. Both the NCSC and ASD recommend human oversight for higher-risk or sensitive actions. Keep a person approving anything that leaves the business or alters records until you have evidence that the agent behaves as expected.