Prompt: AI agents are running into the limits of access

As agents take on more work for users, companies are deciding whether to let outside AI systems act on their platforms.

AI agents are beginning to do more than help people complete individual tasks. They are increasingly being built to act on their behalf, working across applications, pursuing broader goals and interacting with other companies' systems.

The shift has become harder to miss over the past few weeks. Meta's Muse can carry out tasks on users' behalf across websites and connected services. Meta has since expanded Muse to small businesses, letting it connect with tools including Shopify, QuickBooks and Slack and take on broader goals across the software owners use to run their businesses.

OpenAI followed with Dots, always-on agents designed to pursue goals in the background across connected applications. Microsoft has introduced its own digital teammate for enterprise teams. And this week, Google joined the trend with a Gemini workplace agent that can use business context to conduct work across applications.

Taken together, the launches point to a larger change in how people may interact with software. Instead of moving between applications themselves and using AI for help along the way, users may increasingly give an agent an objective and let it navigate those systems for them.

But Meta is already discovering one complication with that model: The systems an agent needs to use don't necessarily have to let it in.

Amazon has blocked Muse from making purchases on its site, saying Meta didn't arrange access in advance and raising concerns about how the agent identified itself and handled customer information. Shopify has taken the opposite approach, partnering with Meta to support Muse purchases through Shop Pay. The dispute exposes a challenge that could become more important as agents take on more work. Their usefulness depends not only on what they can do, but also on whether the websites, applications and businesses they need to interact with are willing to accept them.

That could turn agentic AI into more than a competition over who builds the most capable agent. It could also become a competition over which agents can access the systems where people already work, shop and conduct business.

The broader shift has already been visible in how people use AI for more complex work. OpenAI said in June that more than 70% of sampled Codex users had asked it to complete at least one task estimated to require more than an hour of human work. The company described agentic AI as changing knowledge work from individual interactions to delegated, longer-running tasks.

That kind of delegation requires more than increasingly capable models.

An AI system that drafts a paragraph needs relatively little organizational context. An agent expected to complete work across multiple applications is different. To do that, it may need access to company data, an understanding of business processes, memory of previous work and permission to take actions in enterprise systems.

Those requirements help explain why identity, permissions, memory and context are becoming more important as companies experiment with agents. They aren't simply features surrounding the model. They are part of what makes it possible to delegate work to AI in the first place.

As more agents attempt to shop, book, communicate and conduct business for users, companies may have to decide not only what their own agents can do but also how they will respond to agents arriving from elsewhere.

That leaves enterprises with decisions on both sides. They need to determine how much work they are willing to hand over to their own agents. They may also have to decide how much access they are willing to give everyone else's.

For decades, enterprise software has largely provided tools people use to do their jobs. Even the first generation of generative AI copilots mostly followed that model. They helped employees write, search, summarize, analyze and create.

Persistent agents introduce a different model. The software isn't only a tool that people operate. More and more, they can assign work to it and allow it to interact with other systems on their behalf.

The shift is still early. Many of these agents are new, and companies are still determining how much authority and access to grant them. The resistance Muse has encountered suggests that the decision won't always belong to the agent's owner.

The next phase of agentic AI may depend not only on what agents are capable of doing, but also on where the rest of the digital economy is willing to let them act.

Also in AI news this week:

AI platform sprawl undermines enterprise ROI: FICO found AI explainability gaps as companies contend with growing complexity across their AI environments.

AI power spikes demand chip-to-grid design changes: Rapid swings in AI data center power demand are creating new grid-stability challenges and forcing closer coordination from chips through utilities.

AI slop overwhelms Google’s OSS bug bounty programme: Google closed its open source vulnerability reporting program to new submissions after a surge of automated junk reports overwhelmed the system.

Anthropic, AWS step up FDE push: The companies are investing in training and credentials to expand the pool of forward-deployed engineers needed to bring AI into enterprise environments.

Boston Dynamics hires former Amazon AI leader as CEO: Former Amazon AI executive Rohit Prasad will lead Boston Dynamics as the robotics company pushes further into physical AI.

IBM’s AI-powered vulnerability clearinghouse finds hundreds of Java flaws: The tech stalwart’s Lightwell initiative identified and helped fix 400 Java vulnerabilities, exposing continuing weaknesses in software supply chain security.

Who actually controls enterprise AI? A Thoughtworks report found companies still lack a dominant model for AI oversight, even as CIOs increasingly feel responsible when the technology goes wrong.

Liz Hughes is an award-winning editor and writer covering AI and emerging technology and the former editor of AI Business and IoT World Today.

Dig Deeper on AI Technologies & Platforms