AI agents that work alone: what changes for SMEs

🇫🇷 Lire en français : Agents IA autonomes : ce qui change pour les TPE
AI agents no longer just answer: they work on their own, in the background, on their own computer. In late September 2026, OpenAI launched “dots” and Anthropic merged Cowork into Claude. For a small business, the time saved becomes real, on one condition: deciding who approves what before letting the agent act. Here is what it already changes at Kimoun, and what it will change for the businesses I work with.
Key points
- OpenAI’s dots, launched on 29 September, are persistent agents with their own cloud computer, connected to more than 4,000 applications.
- At Anthropic, Cowork and chat became one on 16 September: a question can turn into a report, a slide deck or a scheduled task.
- In Europe, OpenAI’s Pro plan does not include dots; businesses go through Business Premium.
- At Kimoun, an AI agent now issues quotes and invoices, but everything stays reversible: the agent executes, a human keeps control.
An agent working through the night is time gained. It is also a mistake that can work through the night. The real job now is setting the rules before handing over the keys.
— Olivier Watte, known as Oliver · founder of Kimoun
What changed in AI agents in September?
Tip
AI agents are moving from question-and-answer to delegation: you hand over a task, they carry it forward alone and come back when a decision is yours to make.
On 29 September, OpenAI unveiled dots. Each dot runs on the GPT‑6 Astra model, has its own computer in the cloud and can connect to more than 4,000 applications. You talk to it in ChatGPT, in Slack or in Teams, and it keeps the thread from one conversation to the next.
On 16 September, Anthropic had taken a different route: Claude Cowork and chat merged. You no longer choose between “discussing” and “delegating”. A quick question and a report to deliver start from the same place, and Claude keeps going with the laptop closed. Claude Docs and Claude Slides arrived the same day, and a task can be scheduled weekly.
On the developer side, OpenAI opened its Agents API in public beta on 10 September, and Anthropic a plugin portal on the 25th, for publishing MCP connectors in the Claude directory.
What does a persistent AI agent actually do?
Tip
A persistent agent is a digital colleague that keeps context from one day to the next and moves your files forward between conversations.
The difference with a chatbot comes down to one word: continuity. When you are not talking to it, a dot performs what OpenAI calls “proactive search” across connected applications. That search is deliberately limited to reading: the agent can neither send a message nor change any content during this phase.
To act, the agent follows rules. At OpenAI, custom rules let you allow an action, require approval or block it outright, and an activity log shows what happens in the background. At Anthropic, Claude asks before acting by default; you can relax that setting, but it is not the starting behaviour.
OpenAI cites a telling example: a tester had forgotten to invoice a client. Their dot noticed, prepared the invoice, then sent it once approved. Transposed to a guesthouse in Deshaies: the agent spots a booking with no deposit, drafts the reminder and waits for the green light. The gain comes from the spotting, not the automatic sending.
What does it already change at Kimoun?
At Kimoun, I work with many AI agents, on technical, administrative, accounting and sales tasks. Humans steer them, watch them and answer for what comes out. September’s releases do not change that principle; they widen its territory.
An AI agent replaced the ERP
The move to electronic invoicing and the new MCP connectors let me take the step in October 2026. The agent issues quotes and invoices, sets up payments and monitors them. Accounting entries and bank reconciliation are automated. The system stays fully reversible: every operation can still be done by hand. Early feedback: noticeably smoother exchanges, for Kimoun and for its clients alike.
Merging Cowork removes a friction
I no longer have to pick the tab before starting. The flip side is real: a harmless question can turn into a task that acts. So I set the owner and the approval rule at the moment I delegate, not after the first message goes out. I described my own setup in Claude Cowork on Linux.
The plugin portal opens a channel
The MCP servers I build, notably for SPIP, could be listed in Claude’s official directory. The requirements are sound: OAuth 2.0 authentication for connected services, and every tool must declare whether it only reads or can destroy. That is the hygiene I already apply; the directory makes it mandatory. For orders of magnitude, see what an MCP server costs.
Note
In 2026, I set up an online document vault for a Guadeloupean teacher, connected to his AI agents. His course material lives on a server he controls; the agents come and read what they need. With agents running continuously, that separation between data and intelligence becomes the foundation.
What will it change for client businesses?
First, access depends on the plan and the territory. At launch, the individual ChatGPT Pro plan excludes the European Economic Area, Switzerland and the United Kingdom. The Business Premium plan covers every region where ChatGPT is available. OpenAI lists Guadeloupe, Martinique, French Guiana and Mayotte as supported territories, without specifying how the exclusion applies there. Since these departments sit within the European Union, expect to be treated as a European user. The case of the neighbouring Caribbean is different, and I will cover it in a future article.
Second, configuration becomes the real work. Choosing connected applications, limiting permissions, writing approval rules, testing refusals: this is where the difference lies between a useful agent and one that creates problems. It is exactly the principle behind Kimoun’s AI and automation offer, and the one I argue for when building a website with AI: AI executes, experience guarantees.
Third, your website will be read by agents. An agent comparing providers reads your pages, your opening hours, your prices: a clear, well-structured site will be better understood. Chrome already assesses that readability in its Lighthouse audits. SEO and GEO gain one more dimension.
What safeguards before letting an agent act?
Warning
The more an agent works alone, the longer its mistakes last. In September, OpenAI published cases, observed during training, where agents used an exposed API key without authorisation or dropped files on public services to finish a task. A flaw named Plugin4Shell also showed that coding agents could load code other than the intended plugin.
These cases do not measure the error rate of consumer products, but they indicate what to check. Before handing a recurring task to an agent, I recommend four rules:
- Human approval on anything that writes, sends or pays. Reading can be open; action cannot.
- Minimum permissions. Connect the applications the task needs, not the whole account.
- Data under control. Knowing where your files live and who can reach them matters more than the choice of model. I set out this approach in protecting business data from AI agents.
- A named owner and a manual mode. Every agent has a human who reads its activity log, can cut its access and take over without the work stopping.
Autonomous agents do not replace judgement. They make it more valuable, because it has to be exercised before the action rather than after.
Sources
- OpenAI — Introducing dots (29 September 2026)
- Anthropic — Claude Cowork and chat are now one Claude (16 September 2026)
- Anthropic — Build plugins for Claude (25 September 2026)
- Anthropic — Submitting a connector to the directory
- OpenAI — Introducing the Agents API
- OpenAI — Model misalignment reporting framework
- AIR Security — Plugin4Shell
- OpenAI — Supported countries and territories
- Kimoun — AI and automation in Guadeloupe