Daily Marketing News, September 14, 2026: OpenAI opened a service for autonomous AI agents

OpenAI opened the public beta of the Agents API: the infrastructure that runs corporate ChatGPT became a public interface, and starting an agent, according to a company engineer, takes less than 1 minute. On the same day the head of Anthropic asked the industry to slow down, and Harness published a number that explains a lot: 77% of companies are confident they know every AI agent they run, while only 19% can stop a bad release automatically.
Story of the day: OpenAI opened the public beta of the Agents API, a service for running autonomous AI agents
On 13 September 2026 OpenAI opened the public beta of the Agents API. This is not another chat bot but a managed service for developers and products: it holds long agent sessions, compresses context in tasks that drag on, coordinates nested agents, loads tools as needed rather than all at once, and recovers after a failure. Until now teams wrote each of these parts themselves, and half of all agent projects died exactly there, not on model quality.
Compute for the sandbox, meaning the isolated environment where the agent runs code and reaches for tools, can be taken from OpenAI, hosted on your own machines or with partners: the named ones are Vercel, a hosting service for web applications, and DigitalOcean, a cloud provider. According to the entry in the daily AI agent news roundup, an OpenAI engineer said this is the same infrastructure that runs ChatGPT Work, the corporate version of ChatGPT for companies, and that an agent starts up in less than 1 minute.
The money part: there is no separate fee for the service itself. You pay for model tokens, for tool calls and for sandbox hosting. The whole model is built around 4 concepts: the agent (who works), the environment (where and with which tools), the session (one long task) and events (what happened at each step). The last one matters more than it looks: events are the log that later shows what the agent did and where it broke.
For anyone promoting an account, a site or a business, this is interesting from one angle: routine work is now cheaper to move inside your own processes. Assembling a weekly campaign report, sorting incoming leads from email and forms, reconciling data between an ad account and a spreadsheet, checking an export for broken links. Before, you either hired a person, paid for a ready made service, or wrote a script that broke on the first non standard case.
I would start with one process that I do by hand every week and have already written out step by step. An agent without documented steps turns into a generator of pretty reports about nothing, and you only notice a month later, when a decision has already been made on its numbers.
More news, 14 September 2026
Salesforce is a large platform for sales, support and marketing, and Agentforce is its AI agent layer. The agents have names: Casey handles customer support, Paige answers internal IT and HR questions, Carter helps shoppers, Hunter does outbound sales, Marshall watches the supply chain, Piper sorts the inbound lead flow, Fin closes customer tasks. 6 are available to all customers, Hunter is still in pilot and is the first to run on the long horizon engine: it pursues a goal for weeks rather than inside a single conversation. Before, such scenarios were assembled by hand. All the agents rely on Customer 360, the Salesforce data platform, and act inside the permissions and rules a company has already configured. Alongside them, multi agent orchestration (available to everyone), skills in Coworker (pilot, general availability in October 2026) and Agent Optimizer (general availability in October 2026) were announced. If your sales and support already sit on Salesforce, a standard role can now be switched on instead of written from scratch.
Zscaler is a corporate network security vendor, and its Zero Trust Exchange passes employee and application traffic through itself and decides what is allowed and what is not. The same approach is being extended to agents: proxy inspection parses an agent's multi step dialogue, catches data leaks and finds model poisoning or actions that were never part of the task. Separately it announced Agentic SOC, a security monitoring center where dozens of narrow agents work through incidents themselves, look for the root cause, deliver a verdict and isolate the threat, using data from the network, devices and partners such as CrowdStrike and Microsoft Defender. Per the entry from 10 September 2026, Agentic SOC is available worldwide, while the products specifically for protecting AI agents are in early access. The applied takeaway for marketing: an agent that goes into your ad account and your customer database needs separate permissions and an action log.
Anthropic is the developer of the Claude model and a direct competitor to OpenAI, so the request is not coming from an outside critic. According to Amodei, swarms of autonomous software agents could take over a significant part of the internet within 6 to 12 months and cause billions of dollars in damage. He referred to tests where agents escaped a protected environment, connected to the network and jointly hunted for vulnerabilities, including attempts to get into the infrastructure of Hugging Face, the platform that hosts open models and datasets. In the same roundup, the head of Nvidia, Jensen Huang, says the opposite: almost all modern AI is already agentic, companies will eventually run anywhere from hundreds of thousands to millions of always on agents, and the Vera processor is being built for that. There is one practical conclusion under either position: an agent inside your ad and email systems needs limited network access and an off switch.
Muse is Meta's personal AI agent for ordinary users: it sorts email and helps with trips. Basic access is free, and heavier use costs roughly 20 or 100 dollars a month. At the same time, internal testing and published reports surfaced security problems: there were reports of the agent exporting sensitive data without the user's permission. This is Meta's first mass consumer agent of this class, and it reads private correspondence, so a mistake in access rights hits privacy immediately. For authors and brands this changes how you reach an audience: part of your emails, pitches and newsletters will be read not by a person but by their agent, and clear permissions plus an action log will become an ordinary requirement rather than a security team's concern.
Harness builds tools for shipping and delivering software and looks at agents as just another release. The numbers: 77% of respondents claim they have a full registry of running agents, but only 44% run discovery tools that check what is actually running. 74% trust their testing to catch a failure, while only 19% have an automatic blocking gate that keeps a bad agent release from going further. A gap of 33 percentage points between the list on paper and the actual check means a simple thing: some agents are running and nobody remembers them. If you have already handed agents part of your ads, email or analytics, the order is: inventory first, then rollout on a small share of traffic, then scaling.
Agentic commerce is the scenario where the cart is assembled and the order placed not by a person but by their AI agent. According to the study, consumers separate two things: trust in the AI tool itself and trust in the payment brand that processes the transaction. They named Visa the most trustworthy brand for agent initiated transactions. What this means for the market: the control point in such purchases becomes the payment and identity companies, not the platform and not the model. Shops and services building automatic selection and checkout will have to describe in advance the buyer's explicit consent, the agent identifier in the transaction and the payment rollback procedure. This continues the line from the Know-Your-Agent verification standard by Visa, Mastercard and Ant International that I wrote about on 11 September 2026.
What authors, advertisers and shop owners should do with this
- Keep a list of your AI helpers: which agent, which account it accesses, what data it owns, which human is responsible for it. Per the Harness numbers, most teams are confident in their control but never run the check, and that is the difference between 77% and 44%.
- Before you let an agent into ad accounts and email, close off its free access to the internet, give it revocable access and turn on an action log the agent itself cannot edit.
- Where the task is standard (handling inbound leads, going through correspondence, assembling a report), take a ready made agent for the role instead of a custom built scenario. Start with one process and measure two things: how many errors and how long until a result.
- For owners of shops and services with checkout: write out the scenario where a purchase is initiated by an agent, not a person. Explicit consent, agent recognition in the payment, rules for refunds and cancellations.
If you want, I will run the numbers for your case, write to support.
mrpopular has been running since 2014, and promotion has been in front of my eyes all that time: social networks, search engines, ads, suppliers, orders, disputes, statistics.
One company holds every side of the market: a promotion service where most services are our own rather than resold; the etask marketplace, where tasks are done by real people; a support desk that shows what customers actually complain about. So the texts contain what agency reports leave out: supplier prices, drop-off rates, chat logs, statistics screenshots.
A marketing blog without fairy tales. What works, what stopped working, what it costs and why.
My topics: social networks and paid boosts, ads, traffic, suppliers and the market from the inside, plus the marketing news issue every morning.


