Agents of Work
Let's Talk
September 15, 2026 · Agents of Work

Agents of Work AI Daily Briefing — September 15, 2026

A report that hundreds of contractors are reading real ChatGPT conversations turned an abstract privacy question into a practical one for every business whose staff use a personal AI account. Apple began rolling out its rebuilt Siri, and code in the new software shows it was engineered so Claude or ChatGPT could one day do the thinking. President Trump phoned Nvidia's Jensen Huang on stage to reject the industry's slowdown call, Beijing rebuffed it too, and Microsoft opened its rulebook for its own models to public comment. Anthropic launched a product for financial advisors, Google made it easier for small offices to leave Microsoft 365, and Slack's assistant now builds dashboards inside a chat. In Physical AI, Agility Robotics unveiled a humanoid designed to work without safety fences, and Pony.ai showed a driverless truck with a 70% cheaper self-driving kit.

The people reading your ChatGPT chats

OpenAI is paying hundreds of contractors to read real prompts typed by ChatGPT users, according to an investigation by 404 Media's Joseph Cox published on September 14. The effort is called Project Lily in internal documents. Reviewers see whole conversations between users and the chatbot, rate responses on a scale of one to seven, and critique them, with the goal of training ChatGPT to flatter users less and to stop presenting itself as human. The workers are recruited through Crossing Hurdles and Mercor and, according to the report, earn more than $50 an hour.

The privacy protections are real but incomplete. Reviewers do not see usernames, and OpenAI runs a Privacy Filter model meant to strip personally identifying details before a conversation reaches a person. Internal documents concede that "the Privacy Filter model doesn't catch everything," and sensitive details inside a conversation can still come through. "I don't think they would imagine some contractor somewhere [...] is analyzing the conversations," one person working on the prompts told 404 Media, asked whether ChatGPT's more than 900 million users know that humans may read their chats. Anthropic has confirmed that it also uses human review to improve its models, so this is an industry practice, not an OpenAI anomaly.

For a business, the distinction that matters is the account type. ChatGPT Business, Enterprise and API usage are excluded from model training by default. Consumer accounts are not: users have to switch off the "Improve the model for everyone" setting or use a temporary chat, and turning the setting off protects future conversations, not ones already submitted. If an employee has pasted a customer contract, a patient note or a payroll file into a free or Plus account, it may already be in the pool that people like these contractors read.

Siri gets smarter, and built to swap brains

Apple began rolling out Siri AI in beta on September 14, in English, alongside iOS 27 and its other annual updates. The assistant can search a user's messages, email and photos for context, see what is on screen, take actions across apps such as drafting an email or editing a photo, and hold follow-up conversations. Apple says it runs on new Apple Foundation Models developed "in collaboration with Google and its Gemini models," split between the device and Apple's Private Cloud Compute servers. It requires an iPhone 16 or later or an iPhone 15 Pro, is not initially available in the European Union on iPhone, iPad or Apple Watch, is unavailable in China, and is closed to users under 13. French, Japanese, Korean, Portuguese and Spanish arrive next month. Server-backed features, including Siri AI itself, carry daily limits, with expanded access to come for a fee.

The more interesting discovery is what is hidden in the code. A code analyst found two mechanisms in Apple's private frameworks. One, Model Delegation, lets a third-party model such as Claude act as a Siri extension, interpreting a plain-language request and creating a reminder through Siri's own tools. The other lets Apple's server-side Siri model be replaced entirely while keeping Siri's interface and tools; a demo had GPT-5.6 searching email, summarizing it and sending a message. None of this is user-facing yet, and Apple has not opened it to outside companies. The architecture follows European pressure under the Digital Markets Act to give rivals access to Siri features.

The slowdown fight moves to speakerphone

The debate over Anthropic CEO Dario Amodei's call to "pace the frontier" got louder on Monday. At the All-In Summit in Los Angeles, President Trump called Nvidia's Jensen Huang mid-appearance, and Huang put him on speaker. "They're just playing right in the hands of a lot of people that don't want to see it happen," Trump said. "We're not going to let that happen. It's a hoax." Huang replied: "You're right. We're not going to let that happen, sir." Trump did allow that "we have to do things and we have to do them prudently, but that doesn't mean we're going to stop an industry."

Beijing also said no. Foreign Ministry spokesperson Guo Jiakun responded to Amodei's essay, which urged continued US limits on advanced chip sales to China: "Fearmongering, confrontation and vicious competition will only disrupt the process of global AI governance." Trump and Xi Jinping are scheduled to meet on September 24.

Microsoft, meanwhile, published the draft Code of Conduct for its MAI models it had promised. Its models must "comply with a User's request to pause, redirect, cancel, or shut down," work only with "the permissions, resources, tools, and capabilities appropriate for the task," and treat instructions found in files or web pages as carrying "no authority by default." Any sub-agents must operate under the same limits and obey stop orders. The models "will not be designed to imitate consciousness." Public consultation runs six weeks from September 14, with a revised version due toward year-end to guide development from 2027. It is a roadmap, not a description of today's models, but it reads like a checklist any business could apply to the agents it deploys.

AI products aimed at advisors, offices and teams

Anthropic launched Claude for Financial Advisors, a set of connectors and ready-made workflows for wealth managers. It connects to BlackRock Advisor Center, Charles Schwab, Addepar, Envestnet, Vanguard, Orion and others, plus Wealthbox, Salesforce, Microsoft 365, DocuSign and data from FactSet, Morningstar and S&P Global. The workflows cover meeting preparation, post-meeting notes, onboarding, portfolio rebalancing reviews, and estate and tax briefs. Compliance is built in: advisors must approve critical tasks, and client-facing language is screened against the SEC Marketing Rule. Anthropic recommends its Enterprise plan for the audit logs regulators expect, and did not publish pricing. Arriving days after OpenAI's product for investment bankers, it confirms the pattern: the big labs are now packaging their models for specific professions, complete with the compliance paperwork.

Google gave small offices an easier exit from Microsoft. A new built-in Google Workspace setup flow connects to a Microsoft tenant, discovers users and migrates email, OneDrive files, calendars, contacts and tasks. The catch is size: automated migrations are limited to 10 Microsoft users, and the tool is currently available only to organizations on Google's Flexible Plan. That limit is a problem for an enterprise and almost exactly the size of a small business.

Slack's assistant can now build what Salesforce calls Slackforce Surfaces: dashboards, decks, reports, polls, calculators and microsites generated from a plain-language description inside a conversation. Surfaces pull from Salesforce and other systems connected to Slack, show where their data came from, and can be pinned to a channel for colleagues to filter and comment on. Automatic live updating is marked as coming soon.

Salesforce also published results from TSA's Ace, an AI agent built on its government cloud that handles about 100,000 routine traveler conversations a month across email, phone and social media — questions such as how to pack liquids — resolving 96% without a human. TSA projects $11 million in savings over three years.

The cost of AI writing the code

Anthropic disclosed an unusual internal figure: its continuous-integration job volume grew 25 times in six months, as engineers shipped eight times as much code per quarter as they did in 2021 to 2025, with Claude authoring about 80% of it. The number of tests grew tenfold. The company had to rebuild the service that decides which tests to run. The lesson applies well beyond software companies: when AI multiplies output, the checking has to scale with it, and checking is where the hidden costs land.

Physical AI

Agility Robotics unveiled Digit 5 on September 15, the fifth generation of its warehouse humanoid and the first it says is built to work alongside people without physical barriers. A new safety system combines human detection, visual and audible motion cues, and an independent safety controller built on Nvidia's IGX Thor platform; when someone comes too close, the robot avoids them, stops, or sits down. Payload rises 40%, to repeated lifts of up to 50 pounds. The battery runs 90 minutes and fast-charges in nine, a 10-to-1 run-to-charge ratio against Digit 4's 2-to-1. Early access begins in the first half of 2027, with broader availability, including in the EU and UK, by the end of 2027.

The track record behind it is real but small. Digit has logged more than 65,000 operating hours across nine customer sites, and at GXO's facility near Atlanta it moved 100,000 totes at about 98% accuracy. Agility's merger filing for its $2.5 billion SPAC deal shows the economics: $1.8 million of revenue in 2025 against a $140 million operating loss. Customers can rent a Digit for $8,500 a month plus a $25,000 deployment fee, or buy one for $200,000 plus $36,000 a year in software and maintenance and a $20,000 deployment fee. The company reports more than $300 million in multi-year Digit 5 orders from a single customer, subject to contractual milestones. At roughly $102,000 a year in rent, Digit only pencils out where it covers more than one shift of hard-to-staff work.

Driverless trucks got cheaper to equip. At IAA Transportation in Hannover, Pony.ai and GAC Commercial Vehicle unveiled a fourth-generation heavy truck whose self-driving kit — nine lidars, three radars and 13 cameras — costs 70% less in materials than the previous generation and shares its computer with Pony.ai's robotaxis. Pony.ai expects a 30% cut in transport cost per ton-kilometer and 10% lower energy use, with volume production later this year and expansion into Europe and the Middle East within two years. Those are company projections, not fleet results.

The software that controls robots is also learning from people rather than machines. Reward AI introduced OM-1, a robot control model trained on data captured while humans wear its Omnibody Hand device, which it says runs across industrial arms and humanoids and learns a new task from less than 30 minutes of data; it published no success rates. At MIT, researchers led by Navid Azizan developed HardFlow, which lets a generative model explore freely and then enforces hard safety constraints only on its final output. In tests including robotic manipulation it achieved perfect constraint satisfaction, such as avoiding collisions while finding the quickest path.

Quick Takes

  • OpenAI has bought smartphone camera startup Glass Imaging for about $300 million, according to The Wall Street Journal. The company, founded by former Apple engineers Ziv Attar and Tom Bishop, who led Apple's Portrait Mode team, had raised about $30 million. OpenAI has not confirmed the deal.

  • Bending Spoons is buying Miro for $1.36 billion in cash, days after its Airtable deal. Miro has about $600 million in annual recurring revenue and nearly 4 million paying users. Bending Spoons also owns Evernote, Vimeo and WeTransfer; the deal is expected to close in the fourth quarter.

  • Superhuman acquired AI notetaker Fathom for undisclosed terms, folding meeting transcripts and action items into its email, calendar and documents suite.

  • Perplexity's Portable Computer agent is now on Windows PCs with Nvidia RTX GPUs carrying at least 24GB of memory. It runs a local Qwen 3.8 27B model, connects to Outlook, OneDrive, Gmail and Slack, and asks permission before sending a task to the cloud.

What This Means for Your Business

Check which AI accounts your people actually use this week. Project Lily makes the difference between a consumer and a business account concrete: business and API plans are excluded from training by default, and consumer ones are not. Ask your team whether anyone uses a personal ChatGPT, Claude or Gemini account for work. If so, either move that work to a business plan or have them switch off model training and use temporary chats for anything sensitive. Write one sentence of policy: no customer, employee or financial data goes into a personal AI account. It costs nothing and closes the most common leak.

Make a decision on Siri before your employees make it for you. Any staff member with an iPhone 15 Pro or newer can now give an assistant access to their messages, email and photos on a phone that also holds work accounts. Decide whether that is acceptable on devices that touch client data, and if you manage phones, test iOS 27 before approving it. Watch the hidden hooks, too: if Apple opens Siri to Claude or ChatGPT, the assistant your team talks to could become a setting, and someone should own that choice.

Use Microsoft's code as your agent checklist, whatever vendor you use. Before any AI agent gets access to your email, files or accounts, confirm four things: it can be stopped immediately, it has only the permissions the job needs, it ignores instructions buried in documents and web pages, and anything it delegates inherits the same limits. If a vendor cannot show you how its product handles each one, keep the agent away from anything that sends, spends or deletes.

If you have been meaning to leave Microsoft 365, and your office has 10 or fewer people, Google just removed most of the friction; run the migration on a test user first. And price robots the way Agility's filing does: $8,500 a month is a staffing decision, not a gadget purchase. Unless a humanoid can cover multiple shifts of work you genuinely cannot fill, the numbers do not yet work for most small operations — but they are now public, which makes comparing them far easier.

Sources