Blog
FRONTIER BLOG / ANALYST PERSPECTIVESep 30, 2026

The Agents Have Left the Chat. Now They Want the Keys to the Company.

OpenClaw cracked the pattern. Meta, SpaceXAI, Microsoft, Oracle, OpenAI and OpenClaw itself are now racing to turn persistent agents into enterprise infrastructure. The upside is enormous. So is the blast radius.

Enterprise ArchitectureArtificial IntelligenceDataCybersecurityEnterprise ApplicationsCIO LeadershipOpenClaw / primaryMeta / primarySpaceXAI / primaryMicrosoft / primaryOracle / primaryOpenAI / primary
Enterprise OpenClaw Second Wave of Agents

Software has spent fifty years asking humans to come to it. The second wave of enterprise agents reverses that relationship.

The software comes to work.

That is the strategic meaning of the agent announcements now arriving almost daily. After OpenClaw exploded into view earlier this year, persistent agents stopped looking like a fringe developer pattern and started looking like a new enterprise computing model. OpenClaw had already crossed 100,000 GitHub stars by late January and drew two million visitors in a single week, but the more important signal was architectural: give a capable model memory, tools, a persistent runtime, messaging channels, credentials and time, and it stops behaving like a chatbot and starts behaving like an operator.1

Now the big platforms are racing to industrialize that pattern.

Within days, Microsoft pushed Autopilot forward as a persistent, proactive agent and confirmed through the OpenClaw project that its runtime is built on OpenClaw.23 Meta launched a new enterprise platform around Muse.4 SpaceXAI introduced shared Grok Team Bots that learn from teams and work across their tools.5 Oracle launched Fusion Claw as a governed execution runtime inside its business applications.6 OpenAI launched dots: always-on agents with their own cloud computer, browser, connected tools and recurring work.7 And OpenClaw itself announced OpenClaw Enterprise, an open, vendor-neutral control plane for persistent agents in sensitive environments.8

That is not a product cycle. It is a category formation event.

The first agent wave was mostly about capability: can the model use tools, browse, code, call APIs and finish a task? The second wave is about authority: can the agent remain present, accumulate context, initiate work, coordinate other agents, hold credentials and operate inside the business without becoming an uncontrolled privileged user?

That distinction changes almost everything.

The new unit of enterprise architecture is delegated authority

The most important thing about these products is not that they are “agents.” Enterprises already had agents. The important thing is that these systems are becoming persistent machine principals.

A persistent agent has a durable identity. It can remember. It can have its own computer. It can be invited into Slack or Teams. It can connect to systems of record. It can wake up tomorrow and continue something you asked it to do yesterday. It can act when no one is watching.

OpenAI describes dots as agents that can handle recurring work, follow up across ChatGPT, text, email and Slack, use connected tools and delegate to subagents.7 SpaceXAI describes Team Bots as shared coworkers that combine context, plugins, credentials and memory, while maintaining separate user conversations.5 Meta's Muse runs in a dedicated cloud VM, can use a browser and connected applications, and includes a separate Sentinel agent intended to govern outbound actions.910

This is a much bigger shift than “AI inside SaaS.”

SaaS gave software access to enterprise data. Persistent agents give software initiative.

That is why the second agent wave will be consequential even if individual products change names, stumble, or disappear. The architecture is now visible: identity + memory + tools + runtime + policy + execution. Vendors are competing over which layer they can own.

The platforms are converging on agency — but from very different positions

Meta is coming from distribution and personal context. Muse is designed to feel less like an enterprise application and more like a persistent digital counterpart. It already spans messaging, browsing and connected services, and Meta is now pushing that model toward business users through Meta Enterprise Platform and Muse for Small Business.49 Meta's differentiation is obvious: enormous distribution, consumer-grade usability, cross-channel context and a deep ability to make agents feel ambient rather than installed.

That can be extremely powerful in the enterprise. It is also exactly where personal and corporate trust boundaries can become dangerously blurry.

SpaceXAI is coming from the idea of the AI coworker. Grok Bot already gives agents their own cloud computer and the ability to work across apps. Team Bots add shared organizational context: files, instructions, plugins, credentials and accumulated memory that teams can reuse.115 This is less about one omniscient personal assistant and more about role-shaped digital workers: an account bot, engineering bot, marketing bot or data bot that becomes progressively better at a repeatable job.

The differentiation is institutional memory plus operational continuity.

Microsoft is coming from identity, productivity context and enterprise distribution. Autopilot is persistent and proactive inside the new Copilot experience, and the OpenClaw project says the runtime is built on OpenClaw with Microsoft contributions flowing back upstream around policy conformance, Windows support, secret handling and reliability.23 Microsoft does not need to win the agent-runtime debate in the abstract. It needs to make persistent agency feel native inside the work graph enterprises already live in.

That is a formidable position.

Oracle is coming from the opposite end of the stack: governed transactions. Fusion Claw combines AI reasoning with deterministic enterprise computation inside Fusion Applications. Oracle says its Claw-powered applications operate within defined objectives, permissions, policies, approvals and risk limits, with audit-ready records of decisions and actions.6

That is strategically important because enterprise autonomy cannot be solved by model intelligence alone. An agent may reason probabilistically about what should happen next. Payroll, journal entries, supply orders and revenue recognition still need deterministic controls. Oracle is effectively arguing that the safe place for agency is close to the transaction system, where authority can be bounded by existing process semantics.

OpenAI is coming from model-native general-purpose execution. Dots extend the company's long-running agent work into an always-on form with its own cloud computer, browser, tools, recurring responsibilities and subagents.7 OpenAI's broader agent data already shows the direction of travel: by May, more than 70% of Codex users had asked it to perform work estimated to take a human more than an hour, and the heaviest internal users were generating more than 60 hours of agent turns per day across parallel work.12

The differentiation is breadth: a general-purpose agent layer that can operate across many kinds of work instead of being confined to one business suite.

OpenClaw Enterprise is coming from infrastructure neutrality. OpenClaw describes OCE as an open-source, vendor-neutral platform for managing persistent agents with multi-tenancy, hard security boundaries and standardized agentic primitives; its documentation describes the control plane as “Kubernetes for agents.”813 If that architecture matures, its strategic value is not merely another agent product. It is an abstraction layer that could let enterprises separate agent governance from any one model vendor.

That may become extremely important once organizations have hundreds or thousands of agents built on different stacks.

Why this is happening now

The obvious answer is that the models got better. That is true, but incomplete.

The more important change is that the agent harness got better.

Models can now stay coherent over longer trajectories. Cloud sandboxes can remain alive for days. Tool calling is more reliable. Connectors are becoming standardized. Agent memory is improving. Vendors have learned how to isolate agent computers and credentials. Cost controls are becoming more granular. Enterprise identity systems are beginning to recognize that autonomous software needs its own policy model.

At the same time, the economic pressure has changed. CIOs have spent two years funding AI pilots. Boards now want operating leverage.

A chatbot that makes one employee 12% faster is interesting. A persistent agent that absorbs an entire queue of repetitive work is a different economic proposition.

The OpenClaw phenomenon accelerated that realization because it made the pattern visceral. A relatively simple open harness showed that a model becomes dramatically more useful when it can stay alive, talk through familiar channels, remember context, operate a computer and keep working. The innovation was not a new benchmark score. It was a better delivery vehicle for agency.1

The second wave is the enterprise response: take that agency and surround it with identity, policy, isolation, audit, workflow semantics and commercial support.

The dangerous mistake: governing agents like applications

The enterprise risk is not that an agent will “hallucinate” in the abstract.

The risk is that it will hallucinate while holding authority.

An agent with read access is a researcher. An agent with write access is an operator. An agent with production credentials, customer communications, purchasing authority or money movement is a risk surface that can improvise.

That distinction should become foundational to enterprise architecture.

Meta's recent Muse incidents are useful precisely because they are mundane. In one case, a user's Muse shared his home address with a Marketplace buyer after the user had selected an “Allow Always” permission; Meta said the system had not bypassed its controls, but the user had interpreted the permission differently than the product did.14 A separate vulnerability reported earlier in the month raised concerns about access to sensitive data inside Muse virtual machines before Meta patched the issue.15

Those aren’t arguments against agents, per se. They are actually evidence that permission semantics are now a safety system.

The human question is no longer “Do I trust this AI?” It is “Exactly what authority have I delegated, for how long, over which data, through which tools, under what conditions, and what happens when the agent encounters hostile or ambiguous input?”

That is a much more useful question.

Prompt injection also becomes more serious in persistent systems because the agent is continuously reading content it did not create: email, websites, documents, tickets, messages and API responses. OpenAI has documented how even something as simple as a malicious URL can become a path for unintended data exfiltration when an agent can access sensitive context.16

Memory adds another attack surface. A poisoned instruction that becomes durable memory can outlive the session in which it entered the system. Shared team memory can amplify one mistake across many users. Agent-to-agent delegation can multiply both productivity and blast radius.

The right response is not to neuter agents until they are useless.

It is to engineer a safe delegation frontier.

The CIO playbook: maximize safe agency, not raw autonomy

The objective should be simple: increase the amount of consequential work the organization can safely delegate without increasing uncontrolled authority.

  1. Treat every persistent agent as an identity. Give it an owner, purpose, runtime, model, allowed data domains, credentials, network boundaries, budget, concurrency limit and expiration policy. If an agent can act, it belongs in IAM thinking — even if your IAM product does not yet know what to call it.

  2. Separate intelligence from authority. Let the model reason broadly, but put deterministic policy gates around consequential actions. The agent may decide that a supplier should be paid; a policy engine should decide whether it is allowed to initiate payment. Oracle's Fusion Claw architecture is directionally important here because it explicitly separates AI reasoning from deterministic enterprise computation.6

  3. Tier actions by reversibility. Reading a document is not the same as sending an email. Drafting an order is not the same as placing it. Updating a test environment is not the same as changing production. Define escalation thresholds based on reversibility, financial impact, regulatory impact and external visibility.

  4. Minimize credentials and data exposure by default. Do not give a persistent agent a human user's entire digital life because it is convenient. Use dedicated identities, scoped tokens, narrow data views, explicit egress rules and time-bounded access. OpenAI's current Enterprise controls for dots are notable because access is off by default and administrators can separately govern capabilities such as messaging and local computer access.17

  5. Govern memory as data. Agent memory needs provenance, retention, deletion, isolation and correction. Every important remembered fact should be traceable to where it came from. Sensitive data classifications should follow information into memory rather than disappearing when the model summarizes it.

  6. Demand action receipts, not just audit logs. For material work, capture the goal, sources consulted, tools invoked, permissions used, decisions proposed, approvals received, external side effects, outputs and cost. The future audit question will not be “Which user clicked the button?” It will be “Why did this machine principal believe it had authority to act?”

  7. Red-team the workflow, not only the model. Test hostile documents, poisoned web pages, compromised plugins, misleading approval requests, memory contamination, cross-agent escalation, credential leakage, runaway loops, degraded dependencies and kill-switch behavior. A highly aligned model inside a badly designed authority system is still a badly designed system.

These controls sound conservative. They are actually pro-adoption.

The organizations that can demonstrate bounded authority will be able to delegate more, sooner.

The next platform war is over the control plane for digital labor

There is a deeper competitive shift underneath the announcements.

The AI model may not be the strategic control point for enterprise agents.

The control point may instead be the layer that decides what agents know, what they can access, what they can remember, what they can spend, which other agents they can summon, which actions require approval and how every decision is proven after the fact.

Meta wants that layer to feel personal and ubiquitous. SpaceXAI wants it to look like a roster of AI coworkers. Microsoft wants it embedded in the productivity and identity fabric. Oracle wants it inside governed business transactions. OpenAI wants it to be a general-purpose execution layer. OpenClaw Enterprise wants the control plane itself to remain open and portable.

All of those approaches can win in different parts of the enterprise.

What CIOs should resist is allowing the choice of agent interface to silently determine the organization's authority architecture.

The model can change. The agent can change. The vendor can change.

The governance envelope should survive all three.

The Frontier thesis

The second agent wave is not about smarter chat.

It is about operational autonomy becoming a mainstream enterprise architecture primitive.

OpenClaw proved that persistent agency can be astonishingly useful. The current wave is about making that pattern governable enough to survive contact with real companies.

The winners will not be the organizations with the most agents.

They will be the organizations with the largest safe delegation frontier: the greatest amount of valuable work that can move from human queues to machine execution without losing accountability, security or trust.

That is the opportunity in front of CIOs now.

Do not slow the agents down because they are powerful.

Build the system that lets you safely give them more to do.