Agents of Work
Let's Talk
October 3, 2026 · Agents of Work

Agents of Work AI Daily Briefing — October 3, 2026

Summary

The companies selling AI to small businesses are taking on enormous debts and handing their agents the keys to whole computers. Anthropic's IPO filing shows what a frontier lab's balance sheet looks like, while OpenAI, GitHub and Apple each moved this week on how much of your machine an agent should be allowed to touch. For an operator, the work is checking both the vendor and the permissions.

Highlights

  • Anthropic's filing shows two customers made up about a quarter of its 2025 revenue; ask your vendors how concentrated they are.

  • A Broadcom credit line could become unavailable just when Anthropic needs it, according to the filing.

  • OpenAI's new Dots agents get their own cloud computer and reach more than 4,000 apps; set approval rules first.

  • Apple will make it harder to give apps full access to your Mac, citing AI agents directly.

  • Chinese spies posed as an Anthropic employee to steal passwords and one-time codes; your staff are the target.

  • Google pays some publishers for AI answers, but small sites report earning under $1,000.

  • AMD paid $8.2 billion for a company that builds virtual worlds for training robots.

  • A Caterpillar dealer fit 20,852 parts bins into about 5,600 square feet with 20 robots.

  • A $4,999 Nvidia desktop can now run large AI models on your own premises.

Quick Takes

  • A cheaper desk-side AI computer. Nvidia's 64GB DGX Spark goes on sale October 23 at $4,999 from Acer, ASUS, Dell, Gigabyte, HP and MSI. It runs models of up to 100 billion parameters, and two units can be linked to handle 200 billion. In-stock 128GB systems from partners sell for roughly $7,000 to $9,000. For a firm that wants to keep client data off the cloud, that is now a realistic line item. Read more

  • Tencent rents 100,000 chips from Oracle. Tencent has leased about 100,000 advanced AI chips from Oracle data centers in Southeast Asia in a five-year deal worth about $7 billion, paying roughly 30% upfront. It is Tencent's largest overseas compute lease, a sign that Chinese firms are routing around tightening US export curbs by renting rather than buying. Read more

  • Spoken audio with its own soundtrack. Suno opened Speech to everyone in beta. You type text, pick a voice and a musical style, and it produces narration and original background music as one track. Suno warns that accents can drift mid-track and pauses may run long, so test before using it in anything customer-facing. Read more

What's Covered

  • Anthropic's prospectus: what the filing reveals about revenue, losses, customer concentration and a Broadcom loan that could vanish when needed.

  • Agents with their own computers: OpenAI's Dots, GitHub Copilot's desktop control and Apple's tighter limits on full-disk access.

  • The AI skills gap: Anthropic's $100 million program to train 10,000 engineers inside large employers.

  • Phishing AI policy experts: how a China-aligned group impersonated an Anthropic employee and a former White House official.

  • Google's payments for AI answers: who gets paid when Google's AI uses a publisher's content, and how little some sites earn.

  • Physical AI: AMD's purchase of World Labs, a robotic parts warehouse at a Caterpillar dealer, a motion-capture lab for humanoid training, and an autonomous cross-country flight.

Featured News

Anthropic's prospectus shows the cost of staying at the frontier

Anthropic's IPO filing gives small businesses their first detailed look at the finances of a company many of them now depend on. Revenue grew twelvefold in 2025 to about $4.6 billion, against operating expenses of $12.65 billion. The company reported a net loss of about $42 billion, but roughly $34 billion of that is an accounting charge tied to the rising value of financing that could convert into shares, not cash spent running the business. The filing puts second-quarter 2026 revenue at $11.5 billion and says the company is approaching profitability on an adjusted basis. It holds $20.28 billion in cash against about $518 billion in future commitments for cloud services, computing and other infrastructure.

Two details matter most to customers. First, close to a quarter of Anthropic's 2025 revenue came from just two customers, and many of its largest clients are not locked into long-term contracts. Second, the financing behind its chips is circular. Broadcom has agreed to lend Anthropic up to $42 billion in convertible notes, covering about a third of a $125.2 billion, five-year commitment for Google TPU capacity that Broadcom helps design. The filing warns that a payment or performance default could make a large share of the lease obligations due immediately while also limiting Anthropic's ability to draw on the Broadcom facility to pay them. Anthropic has already deposited restricted cash in a Broadcom account as collateral.

Nearly a third of the prospectus is devoted to risk factors. They include the possibility that advanced models could "manipulate, blackmail or behave in other unpredictable ways," which Anthropic's own testing has shown in controlled settings, and the risk that models develop capabilities no one caught before release. Backers expect a Nasdaq listing this autumn at a valuation above $2 trillion.

None of this suggests Claude is going anywhere. It does show that the price you pay per task is being set by companies carrying enormous fixed obligations, and that prices and terms can change quickly when the financing does.

Agents get their own computers, and Apple pushes back

OpenAI launched Dots at its DevDay on September 29. Each dot is an always-on agent running on GPT-6 Astra with its own cloud computer and browser, and it connects to more than 4,000 apps through plugins. Dots learn a user's preferences, keep working in the background, and can be messaged in ChatGPT, Slack or Teams, with texting coming later. They are included at no extra cost for Pro users in eligible markets, which excludes the European Economic Area, Switzerland and the UK, and for Business Premium users everywhere ChatGPT is supported. Enterprise, Edu and Healthcare workspaces get a beta. Safety settings include Custom Rules to approve or block actions, and sensitive actions such as password changes require the user's sign-off. Developer Dan McAteer said his dot "proactively picked up on an invoice I needed to send," pulled the details from an email thread and drafted it. OpenAI says specialist dots for procurement, invoicing, marketing and support are coming.

GitHub took a similar step on the desktop. On October 1 it put computer use for Copilot into public preview in the Copilot CLI and the Copilot app on macOS and Windows. Copilot can now read app content, click, type, scroll, drag and move between programs, which GitHub pitches as a way to automate older software that has no API. It asks before controlling an application, and organizations can switch the feature off.

Apple is moving the other way. On October 2 it said macOS 27 will add controls so that granting Full Disk Access, the setting that lets an app read files, mail, messages and browsing history, requires explicit user action. "As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially," Apple said. It gave no date.

Anthropic spends $100 million on the people who deploy AI

Anthropic says the bottleneck in business AI is not the model but the people who can put it to work. Its new Claude Frontier Academy commits $100 million to train 10,000 "Frontier Deployed Engineers" by the end of 2027. The program borrows from medical residencies: multi-day in-person training with Anthropic engineers, a simulated enterprise deployment from choosing a use case through security review, a graded assessment, and then a 12-week residency leading a real Claude project at the engineer's own employer. Training runs in San Francisco, New York and London, and candidates must be nominated by their organizations. The first cohorts come from Accenture, Bain, Capgemini, Commonwealth Bank of Australia, Deloitte, McKinsey, Morgan Stanley and Novo Nordisk, with the first full credentials expected in early 2027.

Anthropic's Steve Corfield put the thesis plainly: "A small team of high-agency people with the right skills, access to Claude, and a deep understanding of how their business runs can transform an entire company." Small businesses are not in the first cohorts. But the consultancies that are will be the ones selling that expertise downmarket.

Spies pose as AI insiders to steal logins

Proofpoint has detailed a campaign by TA419, a China-aligned espionage group, aimed at US AI policy experts and think tank analysts since July 8. The group impersonated Lynne Parker, a former principal deputy director of the White House Office of Science and Technology Policy, and the economist Heidi Crebo-Rediker. In a February incident, it posed as a senior Anthropic employee. The lures were invitations to join a fictitious "AI Policy Advisory Committee" or contribute to Senate Foreign Relations reports on export controls.

The technique is worth knowing because it defeats the usual advice. The first emails carried no links at all, which builds trust. Follow-ups carried shortened links leading through a Cloudflare security check to a fake OneDrive login drawn inside a fake browser window. Custom scripts then captured passwords, one-time codes and session cookies, which let the attackers into accounts even with two-step login turned on. "TA419 impersonated multiple individuals," said Proofpoint's Mark Kelly. The targets here were policy experts, but the playbook, a flattering invitation followed by a familiar login page, works on any business.

Google pays for AI answers, on its own terms

Google is paying about 100 publishers through an "AI Contribution Pilot" when their pages significantly shape answers in AI Overviews, AI Mode and Gemini, The Information reported on September 29. Payments range from less than $1,000 to more than $1 million a year. They accrue only when content shapes the answer as it is generated; a citation added afterward does not count. One early participant earns more than $1 million a year, later entrants have accumulated $50,000 to $60,000, and several small and midsize sites report earning less than 0.1% of their ad revenue. Search industry journalist Barry Schwartz noted there is "no formula that Google's sharing with those publishers." For businesses that publish content to win search traffic, it confirms the direction: Google decides what your content is worth, and it does not show you the math.

Physical AI

The week's biggest robotics deal was a chipmaker buying a world-builder. AMD agreed to acquire World Labs, the San Francisco company co-founded by Fei-Fei Li, in an all-stock deal worth about $8.2 billion, its second-largest acquisition after Xilinx. World Labs builds "spatial intelligence" models that generate and simulate interactive 3D environments from text, images and video; its Marble product creates 3D worlds used for robot training and simulation. Li becomes AMD's executive vice president and chief scientist, reporting to CEO Lisa Su, while co-founders Justin Johnson and Ben Mildenhall keep running the team. AMD and Nvidia both invested in World Labs' $1 billion round in February. "Building the compute platforms for the next generation of AI requires a deep understanding of how models are evolving," Su said. The deal is expected to close by year-end. For operators, the signal is that cheap simulated training is becoming the way robots learn new jobs, which is how per-task robot costs eventually come down.

A Caterpillar dealer shows what proven automation looks like today. Warren CAT's Store 05 in Midland, Texas installed an AutoStore system through Kardex: 20,852 storage bins packed into roughly 5,600 square feet, served by 20 AutoStore R5 robots and five picking ports. It is designed for 3,648 picking lines and 751 put-away lines a day and sized for the dealer's projected fifth-year volume. Before designing it, Kardex analyzed more than 93,000 historical orders, nearly 300,000 order lines and about 25,000 products. "Availability and responsiveness can directly affect technician productivity, customer wait times, and equipment uptime," said Fred Fox, president of Kardex Solutions. Cost was not disclosed. This is not a humanoid; it is a cube of bins and robots that bring parts to a person, and it is the kind of system a regional distributor can actually buy.

Training data is the other bottleneck. Innodata opened a motion-capture lab in New Jersey using Vicon infrared cameras that track movement with sub-millimeter accuracy, both to produce training data for humanoid and industrial robots and to independently measure how a robot performs in scripted scenarios with people. "If the training data is approximate, the robot will be too," said Andrew Knox, Vicon's managing director. Independent testing is what buyers should want before trusting any vendor's demo.

Autonomy is also reaching aviation. Joby Aviation said last month that a converted Cessna Caravan completed a 3,199-mile flight from Concord, California to North Carolina's Outer Banks with zero control inputs from the onboard safety pilot, supervised remotely from as far as 2,323 miles away. Joby pitches autonomous flight for delivering critical supplies to remote communities.

What This Means for Your Business

Know how exposed your AI vendor is, and how exposed you are to them. Anthropic's filing is unusually candid: big obligations, a credit line that can disappear in a default, and revenue concentrated in two customers. That does not mean switching providers. It means not building anything you cannot move. Keep your prompts, workflows and documents in a form you could run on another model, check whether your contract lets the vendor change prices or terms on short notice, and for any tool you depend on daily, know what the fallback is.

Write your agent rules before you turn on an agent. Dots and Copilot's computer use both ship with approval settings, and they work only if you configure them. Before any agent touches email, invoices or customer records, decide in writing what it may do on its own, what needs your sign-off, and what it must never do, such as sending money, sharing addresses or changing passwords. Then enter those rules in the product's settings and test them on a low-stakes task.

Audit full-disk and accessibility permissions this week. Apple's change will not arrive until macOS 27, but the risk is already here. On every company Mac, open System Settings, then Privacy & Security, then Full Disk Access and Accessibility, and remove anything nobody can explain. On Windows, review which apps run with administrator rights. An agent can only misuse what you have already granted.

Train staff on link-free first emails and look-alike login pages. TA419 stole one-time codes, which means standard two-step login was not enough. Move key accounts, especially email and banking, to passkeys or hardware security keys where possible, and teach people one rule: never log in through a link that arrived by email; go to the site directly.

If you are weighing automation, start with the boring robots. Goods-to-person storage like Warren CAT's is mature, measurable and sized from your own order history. Ask any vendor for the same analysis Kardex ran: your orders, your lines, your parts, and the throughput the system is designed for. If they cannot produce it, they are selling a demo.

Sources