Dominic Chiappe · People, capability & transformation

Thinking about how organisations perform in an AI-enabled world

AyEye — Workforce Management · 2026-09-14

The first employment contract for an AI worker may look like a software release pipeline

Treat agent authority as something earned through evidence, staged deployment and continuing supervision.

Archive edition · Original reporting and analysis, preserved as published. Website layout adapted for reading.

Workforce intelligence · Issue 2

AyEye — Workforce Management

Human systems in the agentic enterprise

Monday, 14 September 2026

Enterprise agents can now work across days, use tools, retain experience and collaborate. Yet most organisations cannot prove which agents they have, what controls them or how to stop a bad release. The answer may come from outside HR: combine healthcare’s proposed “L-plates” with software release engineering, then treat authority as something an AI worker earns.

The executive brief

  • Salesforce has packaged named, “job-ready” agents that can pursue goals over days and weeks, learn skills and work together. This is a product claim, but it changes the unit being sold from software feature to putative worker.
  • OpenAI has made its long-running agent harness available by API, lowering the engineering barrier to multi-agent, tool-using work.
  • Governance is far behind confidence. In a vendor-commissioned survey of 700 committed adopters, 77% believed they had a complete agent inventory but only 44% used active discovery tooling.
  • A UK healthcare commission proposes staged authorisation for adaptive AI. The same lifecycle logic could govern enterprise agents.
  • Persistent agent memory is becoming testable infrastructure. New research separates doing work from curating memories, which may turn expert know-how into a continuously improving organisational asset.

Original synthesis · confidence: medium-high · horizon: 12–24 months

The first employment contract for an AI worker may look like a software release pipeline

Salesforce is selling agents as workers. OpenAI is making them easier to build. Harness finds that enterprises cannot reliably control them. Healthcare regulators may have supplied the missing organisational idea: probation.

Reported facts. Salesforce introduced agents for service, employee support, commerce, sales and supply chains on 11 September. It says they can work towards goals over days or weeks, acquire new skills and coordinate with other agents. On 10 September, OpenAI released a public-beta Agents API that manages long sessions, tools, context and parallel subagents. These developments reduce the cost of creating software that performs extended work rather than simply answering questions. Salesforce · OpenAI

The control evidence is less comfortable. Harness surveyed 700 technology professionals in large organisations already running agents in production, pilots or proofs of concept. It reports that 77% were confident they had a complete inventory of agents, models and tool servers, while 44% used active discovery. Seventy-four per cent trusted their evaluations, but only 19% had a gate that automatically blocked every failed release. Eighty-seven per cent reported at least one agent-related security event. This is vendor-sponsored, self-reported research from committed adopters, so it should not be generalised to all enterprises. The gap within that sample is still striking. Harness report

Now connect an apparently unrelated development. On 10 September, the UK’s National Commission into the Regulation of AI in Healthcare recommended lifecycle-based, system-wide assurance. Reporting on the recommendations describes “L-plates”: staged authorisation under tighter supervision while an adaptive system demonstrates safety in real use. The proposal is for healthcare, not employment. But its logic answers the enterprise problem better than the usual binary choice between “pilot” and “production”. UK commission

New model · the agent capability licence

1. Candidate
Identity and owner recorded
2. Sandbox
Simulated work only
3. Probation
Small live scope; approval required
4. Licensed
Bounded autonomy; exceptions watched
5. Trusted
Wider mandate; continuous audit
6. Retired
Access revoked; memory archived

What to notice: deployment is no longer a single technical event. Authority expands only when evidence accumulates and contracts again when behaviour, context or the model changes.

The new conclusion. Organisations may need to manage agent authority as a dynamic capability licence. An agent would enter with a named human owner, restricted data, limited actions and mandatory approval. Its mandate would expand only after measured performance under real conditions. A model update, new tool connection, unexplained behaviour or changed business context could automatically return it to probation.

This is where HR, risk, security and engineering converge. Engineering knows how to version, test, release, observe and roll back software. HR knows how to define roles, assign accountability, assess competence and withdraw authority. Neither discipline can govern digital labour alone.

Provocation

Stop giving agents jobs. Make them earn licences.

A “job-ready agent” is marketing language, not evidence of competence in a particular organisation. The safer and ultimately faster approach is to licence specific capabilities: which outcome, using which data and tools, under which conditions, with which escalation and maximum acceptable loss.

What if we are right?

Opportunity: enterprises could increase autonomy without betting the company on a single “go-live”. Useful agents would earn broader mandates while weak ones fail cheaply and visibly.

Organisational consequence: workforce planning gains a new object — licensed machine capability — while performance management expands from people to human–agent systems.

Likely horizon: elements within 12 months in regulated and security-conscious firms; more formal enterprise-wide agent licences within two years.

What would prove us wrong? If long-running agents remain too unreliable for meaningful delegated authority, if firms keep them confined to fixed low-risk workflows or if existing software-access controls prove sufficient, a new capability-licensing layer may be unnecessary. It could also become an IT release practice rather than an HCM responsibility.

Original synthesis · capability & skills

When employees teach agents, learning becomes capital formation

A new Salesforce feature and new agent-memory research together suggest that organisational learning is about to become two-sided: developing people and developing the software colleagues that learn from them.

Salesforce says a forthcoming “AI Skills” feature will let an employee teach an agent how to complete a task once, then scale that knowledge across the workforce and interfaces. Separately, Microsoft researchers describe an agent-memory design in which the working agent cannot alter shared memory. After a task, a different curator agent reviews the trajectory and feedback, probes the environment with read-only tools and decides whether the experience deserves to become reusable memory. In their test environments, the approach improved results while reducing tool calls and cost. It is one preprint and not proof across production settings. Salesforce · Research preprint

Unexpected connection

Skills capture + validated memory + persistent agents means employee know-how can become a durable, improving productive asset. The agent is not merely trained before work; it can accumulate organisational experience after every task.

The consequence: the learning function may become a capability foundry. Its job would be to decide what people should learn, what agents should learn, which experiences can be converted into shared memory and where human judgement must remain deliberately non-transferable.

The unresolved bargain: if an expert teaches an agent a method that removes future demand for the expert’s work, who owns the resulting capability and how is the contributor recognised? Knowledge management treated sharing as a cultural good. Agent training may turn it into a measurable transfer of economic value.

Optimistic possibility

Every experienced employee could leave behind an apprenticeship engine

Handled well, this is not simply extraction. Veteran employees could encode hard-won judgement into supervised agents that coach newer colleagues, preserve rare operational knowledge and give small teams access to institutional experience. Expertise would become more available rather than disappearing when someone retires. The design condition is attribution, consent, versioning and the continuing right of humans to correct what the system “learned”.

Tenuous but plausible · confidence: medium-low

“Bring your own agent” could become the next shadow workforce

Meta’s Muse, announced on 8 September, is a consumer agent that runs in a dedicated virtual machine, remembers personal context, continues working in the background and can use email, applications, passwords and payment services with permission. Meta says sensitive actions require approval and users receive an audit trail. It is initially a US consumer product, not an enterprise system. Meta source

The tenuous connection is to bring-your-own-device. Employees did not wait for enterprise mobile strategies before using smartphones at work. Personal agents may cross the boundary even faster because their value depends on knowing the user across life domains. An employee may ask a personal agent to prepare for a meeting, negotiate travel, analyse a document or chase a supplier — quietly inserting an unregistered digital worker into a corporate process.

What to watch: personal agents gaining access to calendars, email, browsers and payments; employers blocking or brokering them; vendors offering portable agent identities; disputes about whether the employee or employer owns work generated through the employee’s long-lived personal agent.

Governance & control

Frontier laboratories ask for outside supervision as enterprises race towards inside autonomy

On 13 September, The Guardian reported unusual agreement among rival AI leaders that frontier development needs stronger pacing and independent evaluation. Dario Amodei proposed third-party evaluators with continuing, employee-level access; Sam Altman said OpenAI would adopt the same direction. Some experts dispute the more dramatic claims about near-term agent swarms, and commercial or liability incentives may also shape the public positioning. The Guardian, 13 September

The enterprise implication is more immediate than the existential argument. If model developers themselves say internal assurances are insufficient, boards should reject claims that a vendor certificate alone makes a deployed agent safe. Enterprise risk lives in the combination of model, memory, tools, permissions, objectives and local data. Independent assurance must reach that whole working system.

Outside-in analysis · geopolitics

Model nationality may become a workforce-sourcing decision

The Financial Times reports that China’s Ministry of State Security has issued its first public warning about generative AI risks to national security, including data leakage and foreign tools in sensitive settings. The available reporting does not establish specific new enterprise restrictions. Financial Times

Once a model performs persistent operational work, choosing it resembles outsourcing capability, not merely buying software. Boards may need to ask where its inference runs, who can alter it, whose laws govern it and whether the enterprise can continue operating if access is withdrawn. “AI sovereignty” could therefore enter workforce strategy through digital labour dependency.

Operating-model implication

Replace the agent register with an authority ledger

IdentityWhich agent, version, provider and human owner?
MandateWhich objective and maximum acceptable consequence?
CapabilityWhat has it demonstrated, where and how recently?
AuthorityWhich data, tools, money and decisions can it access?
SupervisionWho approves, observes, handles exceptions and can stop it?
EvidenceWhat outcomes, incidents, overrides and learning history exist?

An inventory says what exists. An authority ledger explains why it is allowed to act. That distinction will matter as agents become long-lived and interconnected.

Human control watch

Shift detected: from approving individual actions towards approving enduring mandates.

Why it matters: an agent working for weeks cannot reasonably request permission for every step. Control therefore migrates upstream into objective definition, capability licensing, spending limits, escalation rules and observation.

Primary danger: “human in the loop” becomes ceremonial when one person supervises too many agents or lacks the time, context or authority to intervene.

Capability-model update

Rising
Agent capability assessor
Digital-work licence owner
Memory curator
AI apprenticeship designer
Human–agent span designer
Independent system evaluator
Under pressure
Binary pilot/go-live governance
One-off training content
Static job descriptions
Self-attested agent inventories
Approval-heavy supervision
Vendor-only assurance

Noise

Anthropomorphic names are not workforce design

Giving agents human names and calling them “job-ready” makes products easier to understand, but it can hide the real questions: capability boundaries, failure modes, authority and ownership. Leaders should resist both extremes — pretending agents are employees and pretending they are ordinary software. They are a new managed production resource with some worker-like characteristics and some software-like risks.

Mental-model update

Yesterday’s model was a mixed workforce made visible through connected registers. Today adds movement: digital workers should not receive a fixed identity and permanent authority at deployment. They should progress through a governed career of demonstrated competence, widening mandates, continuous learning, reassessment and retirement.

Questions for the executive table

  1. Which existing function is genuinely equipped to licence an agent’s operational authority: HR, IT, risk, the business owner or a new joint body?
  2. When an employee teaches an agent a valuable method, what recognition, consent and continuing correction rights should follow?
  3. If personal agents become extensions of individual capability, should employers block them, employ them or create controlled borders through which they can work?

Evidence note. Product capabilities and usage figures from Salesforce, OpenAI and Meta are vendor-reported. Harness commissioned its own survey; its sample covers large organisations already deploying agents and is not representative of all employers. The memory study is a preprint tested in specified environments. Original conclusions are explicitly labelled and should be treated as hypotheses to test, not reported consensus.

AyEye — Workforce Management · Human systems in the agentic enterprise