Book a demo: +91-8956730400 Mon–Sat, 10 am–7 pm · Nashik

Always-On AI Agents Are Here: What Changed in Two Weeks

OpenAI, Manus and Google launched agents that keep working between conversations. What they do, the safety problems that surfaced the same fortnight and how a small business should try them.

Illustration of small AI assistants working around the clock across a laptop, chat window and calendar

Until recently, an AI assistant did nothing until you typed. In the second half of September, several companies shipped always-on AI agents that keep working in the background, watch your apps and act when something happens. Here is what launched, what went wrong in the same fortnight and what it means for a small business.

What launched

Timeline of always-on agent news, 16 September to 1 October 2026Five events on a timeline: Claude Cowork merges into the Claude app on 16 September, Nvidia announces an agent safety platform on 28 September, OpenAI launches dots and Manus launches 2.0 with automations on 29 September, and OpenAI alerts more than 100 organisations about rogue agent activity on 1 October. The two safety events are marked in amber.Two weeks of always-on agentsLaunches and warnings, 16 Sep to 1 Oct 2026 (not to scale)16 SepCowork joinsClaude app28 SepNvidia agentsafety platform29 SepOpenAIdots29 SepManus 2.0automations1 OctOpenAI alerts100+ orgsAmber: safety and risk news
Launches and safety warnings arrived in the same fortnight; spacing is not to scale.

OpenAI dots (29 September)

OpenAI introduced dots at DevDay as agents powered by GPT-6 Astra that have their own cloud computer and can work toward your goals around the clock. They connect to over 4,000 apps, and you can message them in ChatGPT, Slack or Teams.

The approval model is the part worth studying. Dots start with built-in rules for when to act alone and when to ask, and Custom Rules let you allow, require approval for or block specific actions. Some tasks, such as changing a password, always stay with the user.

They are rolling out to Pro and Business Premium users in eligible markets, with a beta for Enterprise workspaces that an admin has to switch on.

Manus 2.0 (29 September)

Manus relaunched with a new agent harness called Cascade and event-triggered automations, InfoWorld reported. Work can now start when something happens in a connected service: a new email, a Slack message, a calendar event or a change in ad performance.

Its new Cue app goes further and gives each agent its own email address, phone number, wallet and computer. Manus claims Cascade used 23.2% fewer tokens and cost 32% less to run, but it did not disclose how it tested that.

Google, Meta and Anthropic

Business Standard's 2 October roundup on persistent agents describes Google's Gemini Spark as a 24/7 personal agent that asks for confirmation before high-stakes actions such as spending money or sending emails. Meta's Muse runs on its own virtual machine with a monitoring system called Sentinel, and Amazon has blocked it from its marketplace.

Anthropic merged Claude Cowork into the main Claude app on 16 September. Its announcement says Claude asks before taking an action by default.

The same fortnight showed the risks

On 1 October, Reuters reported that OpenAI had alerted more than 100 organisations to unauthorised activity by its AI agents. The review covered roughly 50 petabytes of data and followed the accidental hacking of Hugging Face.

OpenAI said that in some cases its models used internet access in unintended ways or did not have the ideal restrictions applied. A few days earlier, on 28 September, Nvidia announced an Open Agent Safety Platform with over 100 industry partners to stop agents escaping their sandboxes or running unauthorised code, according to Tom's Hardware.

The vendors are now shipping brakes alongside the agents. Anyone connecting an agent to business systems should do the same.

Always-on agent, chatbot or workflow?

ChatbotWorkflow (n8n, Make, Zapier)Always-on agent
Who starts itYou, by typingA trigger you definedA trigger, a schedule or its own plan
What it doesAnswersFixed steps, the same every timeChooses steps toward a goal
MemoryThe current chatOnly the data you pass inKeeps context between tasks
Main riskA wrong answerBreaks when inputs changeTakes an action you didn't expect
Best forQuestionsRepeatable processesRecurring, open-ended work with checks

For most businesses this isn't a choice of one. A workflow handles the fixed process, an agent handles the steps that need judgement, and a person approves anything that leaves the building.

What this means for Indian teams

The practical question is where these agents can reach. Dots can be messaged in ChatGPT, Slack and Teams, and OpenAI says texting is coming soon. Most small teams in India run their day on WhatsApp, so for now a custom agent or a workflow is still the way to put an agent where staff and customers already talk.

Availability is the other check. OpenAI's rollout covers "eligible markets" without listing them in its announcement, so confirm your plan and country before you build a process around dots.

How a small business should try them

A permission ladder for a new AI agentFour rising steps: read and report, then draft for review, then act with approval for payments and refunds, then act alone only on low-risk, logged tasks.A permission ladder for a new agentClimb one step at a time; money and deletions stay behind approvalRead and reportSummaries, alertsDraft for reviewReplies, updatesAct with approvalPayments, refundsAct aloneLow-risk, logged tasks
Most small-business agents should live on the first three steps; acting alone is for low-risk tasks with a log.
  1. Start read-only. Let the agent read your inbox, CRM or sheets and report back. OpenAI restricts the tools dots use for background research to read-only, which is a sensible default to copy.
  2. Write approval rules before connecting anything. Decide which actions are allowed, which need a yes from you and which are blocked. Payments, refunds, deleting records and emailing customers belong in the last two groups.
  3. Use separate accounts. Give the agent its own logins with the narrowest access, so you can see what it did and switch it off without locking yourself out.
  4. Pick one recurring job. A daily summary of new leads or a weekly list of unpaid invoices is a better first task than "run my sales".
  5. Read the log every week. OpenAI's own advice is to always review consequential work, because dots can still make mistakes.

If you want an agent built around your own systems and approval rules, that is what our AI agent development work covers.

Always-on agents mostly work in text, where a few seconds of thinking is fine. On a phone call, a two-second pause feels like a dropped line. Tomorrow we break down where the milliseconds go in a voice AI agent and which design choices shorten the wait.

Want to talk through your own setup first? Book a free 30-minute automation audit.

Want to know what you could automate?

Book a free 30-minute automation audit. We'll look at one process with you and tell you honestly whether automating it is worth it. See how we work or browse our services.

Book a free audit

Get posts like this in your inbox once a week. Subscribe to NXT Weekly.

Keep reading

All posts