AI

AI that runs your business software on its own: how far should you trust the agent?

September 13, 2026 · 3 min read

Key takeaway

For warehouses and plants, the real question is no longer whether an AI agent can act on its own inside business tools, but how to govern its access rights before letting it do so.

Software that fills out a purchase form by itself, updates a dashboard, or files a VAT return without a single human click: that is the promise of GPT-6 Astra, OpenAI's new model announced on September 3, 2026, capable of directly operating a computer, a browser, and business software to carry out multi-step tasks.

A model classified as critical cyber risk

This launch comes with a more unusual announcement: Astra is the first model OpenAI classifies as "Critical" on its cyber-risk scale, under its Preparedness Framework. Concretely, the model scores 100% on ExploitBench, a benchmark that measures the ability to find and exploit real security flaws in stable Chrome releases, up from 78.5% for its predecessor GPT-5.6 Sol, and without step-by-step human guidance.

Connectors into enterprise software

The aspect most relevant to businesses, however, is native integration with professional software through connectors to Oracle Analytics, Power BI, Navan, and Avalara. The agent can navigate these tools under the user's own rights, consult data, fill in expense reports, or generate reports, much as an employee would by opening these applications one after another.

Reinforced safeguards for the enterprise

Given the stated risk level, OpenAI highlights reinforced safeguards for enterprise deployments: lists of authorized sites and applications, explicit confirmation requests before any action deemed sensitive, and permissions that remain bounded by the rights already granted to the human user. It is a useful reminder that the more capable an agent becomes, the more access-rights configuration turns into a security question in its own right, not a mere configuration detail.

What this changes for logistics and manufacturing

For logistics and manufacturing companies, the interest lies not in cybersecurity as such, but in what this announcement reveals about the maturity reached by AI agents capable of acting within real business tools. A significant share of the administrative work in a warehouse or a plant, order re-entry, dashboard monitoring, reconciling documents across several applications, falls exactly within the kind of repetitive, multi-step work these agents aim to automate.

This prospect does not remove the need for caution: an agent able to act on its own inside an ERP, a WMS, or a production-planning tool must be governed by clear permission rules, human oversight over actions with financial or operational consequences, and traceability of the decisions taken. This is as much an IT governance topic as an automation one, and SMEs and mid-sized industrial firms considering it would do well to treat it that way from the scoping stage onward.

The acceleration of AI agents able to operate directly inside enterprise software is no longer a research hypothesis but a commercial reality driven by the largest AI vendors. What remains to be seen is how quickly industrial and logistics SMEs and mid-sized companies, often constrained by heterogeneous systems and limited IT resources, will be able to turn this promise into reliable automation of their most time-consuming administrative tasks.