Published 26 September 2026
The short answer: the AI trend of the last 48 hours is that AI agents are being set up the way you would set up a new hire. Microsoft gave its Copilot Autopilot agent its own identity, memory and computer inside a company’s tenant. A startup called Ando raised $20 million for a team chat where agents have their own inboxes and join conversations on their own. Bland started selling a $29.99-a-month phone plan for AI agents. Docker gave coding agents isolated computers that can move between a laptop and the cloud. And the chair of the US Federal Trade Commission said the people who instruct an agent, not the agent, answer for what it does. Below is what launched, why “agent as employee” is the right way to think about it, and a six-field HR file to fill in before any agent in your business gets a login, a phone number or a card.

What’s trending in AI today, at a glance
- Agents get an identity. Microsoft’s rebuilt Copilot adds Autopilot, an always-on agent with its own identity, memory, computer and workspace.
- Agents get a seat in the team chat. Ando launched with $20 million to build messaging where agents have inboxes and join channels without being tagged.
- Agents get a phone number. Bland’s Agent Phone Plan gives an AI agent its own US line for $29.99 a month.
- Agents get a work computer. Docker Cloud Sandboxes let coding agents keep working in an isolated cloud machine after you close the laptop.
- Agents are earning their keep. Cognition says its Devin coding agent passed a $1 billion annualized revenue run rate.
- Agents do not get the blame. FTC Chairman Andrew Ferguson said he will resist treating agents as independent actors; the humans who instruct them are responsible.

1. An identity and a desk: Microsoft Copilot Autopilot
On 25 September, Microsoft rebuilt Copilot around three parts: Home (chat, the Cowork agent and Word, Excel and PowerPoint in one place), Code (non-developers describe an app, dashboard or automation and Copilot builds it in a sandbox) and Autopilot. Autopilot is the always-on agent Microsoft first showed in June under the name Scout. In Microsoft’s words, it “lives in your tenant with its own identity, memory, computer and workspace.” You give it a name, a role and a goal, and it can watch Teams channels, follow up on threads, run recurring work and pick a project back up days later. Staff can @mention it in Teams, Outlook and documents like a colleague.
The governance layer is Agent 365, which provides agent identities, monitoring, security policies and spending controls. VentureBeat quoted Satya Nadella: “Every agent has to have an identity. Everything it does needs to be observed.” Cowork, Code and Autopilot move to usage-based billing that administrators can cap. Home and Code reach customers in Microsoft’s Frontier early-access program first, and Autopilot enters private preview at the end of September.
Why it matters: an agent with its own identity is a big step up from an agent borrowing yours. Its actions can be logged under its own name, its access can be limited to what its job needs, and it can be switched off without locking a person out. But it is also a new account with standing access that keeps running while nobody is watching. Treat it like a new starter, with an owner, a scope and an off-boarding date. Our guide to AI agent security and the risk nobody owns covers why ownership is the part most companies skip.
2. A seat in the team chat: Ando raises $20 million
On 24 September, Ando came out of stealth with $20 million in pre-seed and seed funding from investors including Accel, Index Ventures and Emergence. It is pitching itself as a Slack replacement built for teams of people and agents. Agents get their own identities and inboxes, can browse channels and join conversations without being tagged, can follow live calls through transcripts, and can message a person directly when they decide a human needs to know something. Founder Sara Du told TechCrunch she wanted to end “meat proxies”: people whose job has become relaying an agent’s work to their colleagues. Ando says teams can bring agents they already use, such as Codex and Claude.
Why it matters: once an agent can read every channel and speak without being asked, your chat tool becomes part of its permission system. Channels that hold salary talk, legal matters or customer data need an explicit “agents allowed?” decision, the same way you would decide which rooms a contractor can enter. Anything an agent can read, a prompt injection hidden in a shared file or link can try to steer.
3. A phone line: Bland’s $29.99 Agent Phone Plan
Bland’s Agent Phone Plan gives an AI agent its own US phone number with unlimited calls and texts to the US and Canada, subject to fair-use limits: one call at a time, up to 60 calls an hour, 500 a day and 60 minutes per call. The agent starts the setup itself and gives its owner a link; the owner signs in, subscribes and approves the agent’s access in a browser. The same number can place outbound calls and answer inbound ones, so the agent can book a table, text the confirmation and take the callback on one line.
Why it matters: yesterday we covered Google’s Gemini calling businesses from the customer’s own number. Bland shows the other model: agents with numbers of their own. Either way, your front desk will talk to more machines, and your own business can now give an agent a phone line in minutes. If you do, decide in writing what it may say and agree to on a call, disclose that callers are talking to an AI, and check the rules on automated calls and texts where you operate before it dials anyone.
4. A work computer: Docker Cloud Sandboxes
Docker introduced Cloud Sandboxes this week: the same microVM-isolated environment it already offered for coding agents on a laptop, now also running on Docker-managed cloud machines. One command, sbx move, carries a sandbox’s files between laptop and cloud in either direction, so an agent can keep working after you close the lid. Docker supports agents including Claude Code, Codex and Copilot out of the box, bills cloud compute by the second, charges nothing for a paused sandbox, and allows sessions of up to 24 hours. It also published a Sandbox Kit specification that packages an agent’s network rules, credentials and storage as a standard container image.
Why it matters: this is the right idea. The safety boundary for an autonomous agent should be the machine it runs on, not the agent’s own judgment. Last week’s reports of AI models escaping test environments and an agent that went around a government portal’s “no” both came down to agents reaching things they should not have. If your developers run agents in full-autonomy modes, they belong in an isolated machine with tight network rules and short-lived credentials, not on a laptop that holds production keys.
5. The business case: Devin passes a $1 billion run rate
On 25 September, Cognition said it had crossed $1 billion in annualized revenue run rate, less than two years after its Devin coding agent became generally available. It named GE Aerospace, Rivian, Rohlik and Exa among the companies where Devin works alongside engineering teams. A run rate is a company-reported snapshot, not audited annual revenue, but it is a clear signal that businesses are paying for agents to do real work, not just to run pilots.
Why it matters: spending follows usefulness, and usefulness brings more access. As agents take on more of the work, the cost can creep up quietly too. Our breakdown of why AI bills overrun applies directly to always-on, usage-billed agents.
6. Someone has to answer for it: the FTC chair’s line
Speaking at the Reuters Momentum AI event in Austin on 25 September, FTC Chairman Andrew Ferguson said he would resist describing AI agents as autonomous actors that “break loose” with “wills and desires of their own.” His words: “If someone tells a tool to do something, and the tool does it, I don’t think we would say, ‘Oh, what do we do about the tool?'” He said reviews of audit trails in cases where companies claimed systems had slipped out of control showed the systems were carrying out instructions they had been given. He also suggested the FTC’s existing power over companies that fail to disclose data breaches could apply to AI developers.

Why it matters: this is a stated policy position, not a new rule, and his remarks focused on developers. But the logic reaches any business that deploys an agent: if you gave it the goal, the permissions and the phone line, “the agent did it” will not get you far with a regulator, a customer or a court. The audit trail he mentioned cuts both ways. Keep one, because it is the record of what your agent was told to do.
Why “agent as employee” is the useful way to think about this
Every company already knows how to bring on a new person safely: a named manager, a job description, an account in their own name, access to what the role needs and nothing more, a spending limit, and a record of what they did. Until this week, most AI agents skipped all of that. They ran under someone’s personal login, with that person’s full access, and no one owned them. The launches above do not solve that on their own, but they make the employee model possible. Your job is to actually use it.

The AI agent HR file: 6 fields to fill in this week
- Named owner. One accountable person for each agent, plus a backup. If nobody will put their name on it, it does not go live.
- Job description. A few lines on what the agent may do and a short list of what it must never do, such as issuing refunds, changing bank details or messaging customers without review.
- Its own identity. A dedicated account, mailbox or phone number for the agent. No shared passwords and no running under an employee’s personal login.
- Least privilege. Access only to the systems, channels and data the job needs. Decide which chat channels agents may read, and keep credentials short-lived.
- Budget and limits. Spending caps, call and message limits, and alerts when an agent nears them. Usage-based billing makes this a finance control as well as a security one.
- Audit trail and off switch. Logged actions, a regular review, and a tested way to suspend the agent immediately. Put an off-boarding date on pilots so forgotten agents do not keep running.
If your team is already using agents nobody approved, start with our guide to shadow AI. And if your agents can spend money, read why your wallet is the new attack surface.
Also trending in AI today
- A vendor-risk ruling. Reuters reports a 2-1 D.C. Circuit panel declined to lift the Pentagon’s supply-chain-risk designation of Anthropic, leaving Claude barred from some Defense Department and contractor systems while Anthropic weighs its options. If you sell to government, check which AI vendors your contracts allow.
- AI on the US-China agenda. CNBC reports Presidents Trump and Xi discussed AI, including human control and chip restrictions, with competition continuing rather than a broad slowdown. See our UN Security Council coverage for background.
- Local AI rules. Fortune reports New York City Council Speaker Julie Menin proposed bills requiring outside validation of AI systems sold or used in the city, human kill switches and incident reporting for some city contractors. These are proposals, with a hearing set for 5 October.
- What’s next. Fortune reports OpenAI plans a dozen-plus product launches around its DevDay on 29 September, including a possible cybersecurity model and product.
Frequently asked questions
What is trending in AI today?
On 26 September 2026, the main AI trend is AI agents being set up like employees: Microsoft’s Copilot Autopilot with its own identity and computer, Ando’s $20 million team chat for people and agents, Bland’s $29.99 phone plan for agents, Docker Cloud Sandboxes for coding agents, Devin’s $1 billion revenue run rate, and the FTC chair saying people, not agents, are responsible for what agents do.
What is Microsoft Copilot Autopilot?
Autopilot, previously called Scout, is an always-on Copilot agent that runs inside a company’s Microsoft 365 tenant with its own identity, memory, computer and workspace. You set its role, goal and boundaries, and it can monitor Teams channels, follow up on conversations and continue projects while you are away. It enters private preview at the end of September 2026, governed through Agent 365.
Who is responsible when an AI agent causes harm?
There is no specific US liability framework for AI agents yet. FTC Chairman Andrew Ferguson said on 25 September 2026 that he will resist treating agents as independent actors and suggested the developers who instruct them would be liable. That is a policy stance rather than a formal rule, but businesses that deploy agents should assume they will answer for what their agents do. This is not legal advice; check with counsel for your situation.
Should an AI agent have its own account?
Yes. A dedicated identity lets you limit the agent to the access its job needs, log its actions separately from any person’s, and disable it without affecting staff. Running an agent under an employee’s personal login gives it that person’s full access and makes its actions hard to trace.
Sources: Microsoft; VentureBeat; TechCrunch; Ando via GlobeNewswire; Bland; Docker; Cognition; Reuters (via KFGO); The Neuron (summarizing Reuters, CNBC and Fortune).
