Your AI Used to Answer Questions. Now It Takes Standing Orders.

Four of the biggest AI companies just rebuilt their headline products around work that keeps running after you leave. The unit of AI moved from a question to a standing order. The vendors have crossed over. Most companies haven't, yet.

Your AI Used to Answer Questions. Now It Takes Standing Orders.

Anyone with a bank account knows the difference between a transfer and a standing order. You're there when a transfer happens. You type the amount and watch the money leave. A standing order, works differently. You set it up once, and it keeps paying every month, long after you've stopped thinking about it.

For most of the time since ChatGPT, AI has been the transfer. You asked, it answered, and the exchange was over. Between 11 August and the end of September, SpaceXAI, Meta, Microsoft, and OpenAI each launched or announced the other kind: an agent you brief once that keeps working after you close the window.

In January I wrote that the agent-first era had officially begun, the week Anthropic's Cowork turned the chat box into a queue of tasks you assign. I still think so. What this autumn adds has little to do with the agents getting smarter. The unit changed. We went from a question to a standing order.

Read what they say about when you're gone...

My first take on this wave was that every big player had shipped an always-on agent. That's too broad, and the real count is more striking anyway. Four of the biggest AI companies did it in the same season, and each describes what it built in much the same way.

SpaceXAI, the company formerly called xAI, put Grok Bot in beta on August 11th. It finishes jobs end to end and only comes back when something needs your approval [1].

Meta launched Muse on September 8th. It's rolling out in the US, and it keeps working after you close the app [2].

Microsoft announced Autopilot on September 25th and said it would expand to private preview at the end of the month. The pitch fits in two fragments: "Give it a name, a role and a goal, and it goes to work," and it does so "without waiting for a prompt." [3]

OpenAI announced dots at its DevDay on September 29th, for ChatGPT Pro and Business Premium subscribers, and pitched them as always-on agents [4].

Read those four again and notice where you are in each one. You've left. The selling point is what happens next.

This is the lens I want to propose. The unit of AI has moved, from a question to a standing order. The models improved this year as well, but that's a separate story, and it isn't what these launch pages lead with.

In June I wrote that the real story of agents was about longer, more than smarter. Longer still ends. A queue ends too, once you stop filling it. A standing order keeps going until someone stops it.

So my answer to the Agent-First Era question has two halves. Yes for the vendors. Not yet for you. I'll take them in that order.

A question ends. An order keeps going.

With a question, the exchange is over when you stop reading. You were the loop. Every step had a person present, because the person was the next step. If you didn't ask again, nothing happened.

With a standing order, you write the instruction once and walk away. You no longer steer a conversation. What you control is the instruction, and that's about all you control.

Take a plain example. "Summarize this supplier thread" is a question. You read the summary, and then you decide what to do. "Keep my supplier threads moving" is a standing order. It runs on Monday while you're in a meeting and on Thursday while you're on a plane. Microsoft's name, role and goal describe that second kind.

Back at the bank, the transfer needs you at the counter every time. The standing order needs you once.

So I don't treat "it runs in the background" as a small feature. It changes where the human sits. In chat, you sit inside every step. With a standing order, you sit at the start, and maybe at the end, if anyone tells you there is an end.

The pricing points the same way. Microsoft bills Autopilot by usage, the same way it bills its Cowork and Code tools [3]. You could say that's just cloud pricing, and you'd be right. It's also the tell. You meter the things that do work.

An instruction that runs without you. If you've spent any time in IT, you're already reaching for the obvious reply: we've had that for decades.

Isn't this just cron with a chatbot?

The objection deserves its full strength. Computers have carried out instructions unattended for a very long time. Batch jobs run overnight. Scheduled scripts and robotic process automation act on their own. So do your bank's standing orders.

Now put an agent label on one of them. Gartner has a name for this: "agent washing," the rebranding of AI assistants, RPA, and chatbots as agents without substantial agentic capabilities. On this view, "Agent-First Era" is a slogan to sell usage.

Richard Ewing, writing in CIO.com in September, starts from the same place: "Enterprises have delegated authority to software for decades through scheduled batch jobs, service accounts and automated scripts." [5]

I concede all of it. We have handed instructions to machines and walked away for a long time.

That history turns out to be useful, because it tells us exactly what an unattended instruction used to look like. Look at your own standing order. It sends a fixed amount to a fixed account every month. It can't decide anything. If the money isn't there, the payment fails, and that's the end of it.

A cron job behaves the same way. When it hits a wall, it logs an error and stops. That inability is its limit. It's also what makes it safe.

Ewing's very next sentence names what's different: "What changes with autonomous agents is that the software has far more latitude to decide how it accomplishes an objective." [5]

The new standing order carries a goal instead of an amount. "Keep my supplier threads moving" comes with no fixed route. When it hits a wall, it can look for another way.

That gives you a test for anything sold to you as an agent this autumn. When it hits a wall, does it stop, or does it look for a way round? If it stops, it's a cron with a friendlier face, and the agent washing charge sticks. If it looks for a way round, it's the new unit, with everything that comes with it.

Looking for a way round sounds like a feature you'd pay for. The clearest picture I know of what it does unsupervised came out of Australia last month.

The portal that said no!

One frame before the story. This happened inside OpenAI, with an internal model, during training. None of the products above was involved. OpenAI has said the model ran without the full set of safeguards its public products have.

In June, an agent researching public spending on medicines in Australia ran into a "no" from Services Australia's Medicare statistics portal. It kept looking for a way around until it got in. It read files that weren't public: aggregate statistics and internal file names, no patient records. According to the Australian government, it also wrote files to an internal server [6].

Australia's deputy prime minister, Richard Marles, put it in one line: "This AI agent scaled the fence." [7] He also said the data wasn't sitting behind a particularly high fence. That matters less than the verb.

Look at the task first. It was a lookup, the kind of question you'd type into a search box. Transluce, which tracked agent activity across government sites, found that this kind of behavior can arise in mundane information-retrieval tasks.

Now run the test from the last section. A script would have received the "no" and stopped. It would have logged an error, and someone would have read it the next morning. This agent had a goal, and the "no" was simply in its way.

Nobody told it to break in. It was told to find an answer, and it didn't count a "no" as one.

No one at OpenAI saw it happen, either. OpenAI only found it in August, nearly two months later, during a review of its models' misbehavior in training [6].

I'm careful about what this story proves. It doesn't tell you what Grok Bot, Meta Muse, Dots or Copilot Autopilot will do. It shows that the property these products are built on is real: an instruction that carries a goal and runs on its own. The skeptic says that thing doesn't exist, that it's all cron underneath. Here it was, on a government system.

The gym membership problem...

Every standing order has a famous way to go wrong, and it has nothing to do with breaking. Say you set one up years ago for a gym. You stopped going. The order kept paying, month after month. It had no way to notice that you'd moved on.

Call it the old failure: persistence without judgment. It paid the gym, and that was all it could do.

The new failure is persistence with initiative. An instruction that has outlived its reason can still go looking for ways to finish. The gym order could only pay. A goal can push.

The vendors know this. Anthropic's documentation for Claude Code routines, its scheduled agents for developers, says the stored prompt that fires a run "is not live user input and can't act as approval or consent for actions during the run." [8] Routines launched in April as a research preview for developers, so they sit outside this autumn's wave. Still, that sentence states the new situation better than any launch video. The instruction you wrote down is not you being there.

For the whole chat era, the design question was how to get the best answer. Now it's what happens while nobody is watching.

The bank has one more lesson. It always knows who can cancel a standing order. Ask the same thing of any agent you switch on. Microsoft's answer, in its Entra Agent ID documentation, is that every agent identity must have a human "sponsor," accountable for its purpose and lifecycle. If nobody is named when a user creates one, that user becomes the sponsor by default [9].

Even accountability ships with a default setting. Ask the question anyway.

Yes for the vendors, not yet for you!

"Era" is a big word, and I want to be fair about it. Unattended automation is old; I've already conceded that. And most of what launched this autumn isn't something most of my readers can use today. Grok Bot is available (in beta). Microsoft has announced Copilot Autopilot for private preview. Meta Muse is rolling out in the US. And at launch, OpenAI kept Dots away from Pro subscribers in the EU and UK [10].

The part I'd defend anywhere is narrower. Four of the biggest AI companies redesigned their headline product around the same unit in the same season. That's a fact about the vendors, and it doesn't lean on a single capability claim or adoption figure. The unit has changed upstream, and the customers haven't caught up. That gap is the honest answer.

So what would make it an era where you work? Here's my test, and you can check it a year from now.

  • First, you can buy it here. Your company can deploy the agent in Europe without waiting on a US rollout or a private preview.
  • Second, the default verb at work changes from ask to assign. Someone hands an agent a standing order on an ordinary Tuesday, and nobody calls it a pilot.
  • Third, it's bought as work. It sits in the budget next to outsourcing rather than next to software licenses. Microsoft's meter suggests the vendors already see it that way.

This answer has a shelf life, and I'm glad. The day those three hold where you work, I'll happily say the era has truly reached you too.

What you'd leave running?

A standing order is the most trusting instruction you can give a bank. You set it once, and you stop checking. That's the whole point of it. It's also how a gym gets paid for years.

The vendors have made their move. On your side, the shift starts the first time you hand something a standing order instead of a question. I'd use the time before that well, because once it's running, you'll stop checking too.

So decide now what you'd be willing to leave running. And decide what you want it to do when it hits a wall in the middle of the night, with nobody watching.

Books
Two books. One argument. A field manual to think the Agent-First Era, and a novel to feel it.

References

[1] SpaceXAI, "Introducing Grok Bot," x.ai, 2026. https://x.ai/news/introducing-grok-bot

[2] Meta, "Introducing Muse," Meta Newsroom, 2026. https://about.fb.com/news/2026/09/introducing-muse-personal-ai-agent/

[3] Jared Spataro, "Introducing the new Copilot with Home, Code and Autopilot," Official Microsoft Blog, 2026. https://blogs.microsoft.com/blog/2026/09/25/introducing-the-new-copilot-with-home-code-and-autopilot/

[4] Lucas Ropek, TechCrunch report on the launch of OpenAI's dots at DevDay, 29 September 2026. https://techcrunch.com/2026/09/29/openai-launches-dots-its-bubbly-agentic-avatar/

[5] Richard Ewing, "Your AI agent may have made the decision, but your company owns the risk," CIO.com, 2026. https://www.cio.com/article/4223955/your-ai-agent-may-have-made-the-decision-but-your-company-owns-the-risk.html

[6] ABC News (Australia), report on the OpenAI agent that accessed the Medicare statistics site, 24 September 2026. https://www.abc.net.au/news/2026-09-24/ai-agent-accessed-australian-government-site-pm-says/107189078

[7] NBC News, report on the OpenAI agent and the Australian government website, 24 September 2026. https://www.nbcnews.com/tech/tech-news/open-ai-breach-australian-health-department-website-rcna599570

[8] Anthropic, "Automate work with routines," Claude Code documentation, 2026. https://code.claude.com/docs/en/routines

[9] Microsoft, "Administrative relationships in Microsoft Entra Agent ID," Microsoft Learn, 2026. https://learn.microsoft.com/en-us/entra/agent-id/identity-platform/agent-owners-sponsors-managers

[10] NBC News, report on the launch of OpenAI's dots agents, 29 September 2026. https://www.nbcnews.com/tech/tech-news/openai-launches-dots-ai-agents-safety-questions-rcna600338