Writing
Agents Are Getting Real, and So Is the Work
The industry is moving from smart answers to systems that act. On my side that means crude scripts, real workflows, and five questions I keep asking.
September 12, 2025
The applied-AI signal is getting harder to miss: the industry is moving from smart answers toward systems that can actually take action. The conversation is shifting away from “Which model sounds best?” and toward a more serious question: what happens when AI can browse, retrieve, route, update, and move work inside real operations?[1][2]
OpenAI published an update on its work with the US Center for AI Standards and Innovation and the UK AI Security Institute, describing security collaboration and red-teaming around agentic systems, including ChatGPT Agent.[1] OpenAI’s model release notes also now include updated “agentic principles” in the Model Spec to reflect systems that can take actions in the world.[2] And from the Google side, the direction is similar: Google’s August AI roundup highlighted more agentic behavior in AI Mode and positioned Jules as an asynchronous coding agent that can understand intent, make a plan, and get to work.[3]
That feels right to me, because that is also what this season of work already feels like on my side of the screen.
I am not spending September thinking about AI as an abstract future. I am using it to write code for the first time in a way that is immediately useful. The code is not elegant. It is not a polished product. But it is moving real work.
Right now, I am building crude but effective JavaScript file-handling scripts in Google Apps Script to help us manage workflow around quoting and folder management in Google Drive. The pattern is simple: use AI to help write the script, cut and paste into GAS, test it against the actual workflow, and keep the parts that reduce friction. It is not glamorous, but it is real applied AI.
The point is not that the scripts are impressive. The point is that the work is starting to change shape.
What the news means from where I sit
These headlines matter because they confirm that the useful future of AI is not just chat. It is action inside bounded systems.
OpenAI’s security update makes that clear in the strongest possible way. Once an AI system can take actions, the risk is no longer limited to a bad answer. OpenAI described external red-teaming of ChatGPT Agent and said CAISI identified vulnerabilities that could, under some circumstances, have allowed a sophisticated attacker to bypass protections and remotely control the computer systems available to an agent session.[1] That is not a copy problem. That is an operations and control problem.
The Model Spec update points in the same direction. If models can act in the world, then authority, scope, side effects, and boundaries have to be designed into the system instead of assumed after the fact.[2]
Google’s direction reinforces it from another angle. More agentic search behavior, harder reasoning tools, and asynchronous coding agents all point toward the same practical destination: less asking AI for isolated outputs, more delegating bounded work to systems that can carry context and complete sequences.[3]
That matches exactly what I am learning in the work.
What we are actually doing with it
In Google Workspace, we are already using AI to help create the first layer of automation around file movement and workflow structure. The immediate use case is quoting and folder management in Drive: making it easier to create, place, and manage the folders and files that operational work depends on.
It is early. It is crude. It still requires judgment. But it is effective enough to matter.
That matters more to me than a hundred generic AI demos, because this is where applied AI starts to become operational leverage: not at the level of “show me something cool,” but at the level of “help me move repetitive work with fewer dropped balls.”
At the same time, on the OpenAI side, we are just beginning to define what AI executive admin could become around schedule and task management. Not a chatbot sitting off to the side. Not a novelty assistant. Something closer to an operational layer that can help track commitments, surface what matters, and support follow-through. There is nothing built yet. There is a way I already run my own mornings — capture what came in, put it where it belongs, review what matters, execute the one thing that moves the needle — and a suspicion that the discipline is going to matter more than whichever model ends up running it.
I do not think the right mental model is “AI replaces the executive assistant” or “AI replaces the operator.” I think the better model is that AI starts by taking the friction out of coordination work: repeated sorting, repeated routing, repeated checking, repeated drafting, repeated nudging. The human still owns the judgment. The system starts owning more of the movement.
Why that is the real applied-AI story
The real story here is not that the models got smarter. The real story is that more of us are now trying to put them inside the machinery of work.
That is why VindexAI’s direction is getting clearer, not fuzzier. The position we are settling toward is that the platform follows the mission: the operating combination should be chosen by responsibility, tools, data sensitivity, deployment boundary, reliability, cost, and required human review. That is the practical answer to the exact category of problem now becoming visible across the industry.[1][2]
The same instinct is forming around authority: written responsibility for what a system may touch, human sign-off where it counts, a way to stop it, and small bounded pilots before anything expands. That is not decorative language. It is what becomes necessary the moment AI starts moving from answer generation into operational action.
The same logic applies to visibility. If AI is going to participate in real workflows, the human has to be able to see what is happening, understand the current state, and intervene without digging through a black box. The view has to be part of the software, not decoration around it, and the controls should sit beside the state they act on.
So if I had to summarize what this moment means in plain English, it would be this:
AI is starting to become useful not when it sounds intelligent, but when it helps run bounded work without making the operator surrender control.
That is where the real opportunity is.
And honestly, that is where the real difficulty is too.
Because once you start using AI to write scripts, move files, shape workflow, or define the first version of executive admin around tasks and schedules, you stop asking whether AI is real. You start asking better questions:
- What exactly is this system allowed to do?
- What state can it see?
- What should remain human?
- What evidence does it leave?
- How do I stop it when it gets something wrong?
That feels like the actual beginning.
Not theory. Not stage demos. Work.
Sources
[1] https://openai.com/index/us-caisi-uk-aisi-ai-update [2] https://help.openai.com/en/articles/9624314-model-release-notes [3] https://blog.google/innovation-and-ai/products/google-ai-updates-august-2025
If this post matches something in your own operation, we want to hear about it. Choose whether you are responding directly or offering your own story for publication below.
If this reads like your operation, there are two places to go next.
