Agents get the money and the hard questions about trust

· 6 min read
AI-generated image: Agents get the money and the hard questions about trust
AI-generated image

A single thread runs through today's announcements: software is handing real work to agents that act on their own, and the people building, funding and selling that shift are spending just as much energy on how to trust and secure it. Money moved toward programs that do things, and on the same day the industry argued about accountability and spent a cybersecurity month reminding owners to check the locks.

Before reading the news, it helps to separate two words that often get blurred. A chatbot answers a question you ask. An agent is a program that uses a model to carry out a multi-step task on your behalf — it decides what to do next, calls other tools, and keeps going until the job is done or it gets stuck. That difference is the whole story of the day. A thing that answers is easy to supervise, because you read the answer. A thing that acts needs rules about what it is allowed to do, a record of what it did, and a way to stop it.

Funding follows agents that act, not just answer

For most of the past two years, the value in an AI company sat in the model itself — how well it predicted the next word. The newer bet is on the layer above the model: the agent. Nous Research confirmed it had reached a $1.5B valuation and launched AI agents aimed at business users, with the developer of its Hermes Agent raising a $90 million Series B [1].

For a business choosing tools, the valuation matters less than what it signals. Investors are pricing agents as a product category in their own right, which means more of them will arrive, and the marketing around them will get louder. That is the moment to be precise about what you are buying. An agent that drafts a reply you approve is a very different purchase from an agent that sends the reply on its own. The first saves you minutes. The second takes on authority, and authority is the thing you have to scope, log and be able to revoke. When you evaluate any agent this year, the first question is not how clever it is but how narrowly you can define what it is permitted to do.

Accountability is a design decision, not an afterthought

The harder version of that question arrives when agents stop working alone. Salesforce described the coming shift as a move from isolated large language models to interoperable multi-agent systems, where autonomous AI will, in their words, negotiate, trade, and collaborate across company lines [2]. Picture your purchasing agent talking directly to a supplier's sales agent. The productivity case is obvious. The accountability case is not.

When two programs reach an agreement, you need to answer three plain questions after the fact. What was each agent allowed to commit to? What did it actually do? And if the outcome was wrong, whose decision was it? None of those are answerable unless they were designed in from the start — an explicit limit on each agent's authority, and a record that survives the transaction. This is why the dull plumbing matters more than the demo. A business that cannot reconstruct who decided what has not automated a process; it has lost sight of one. We have written before about the decisions automation should never be allowed to make on its own (decisions-automation-should-never-make) and about drawing the line between what AI should and should not do in a business (what-ai-should-and-should-not-do-in-your-business); the arrival of agent-to-agent systems raises the stakes on both, because now the other party is a program too.

The practical takeaway for a buyer is modest and firm. Before you let any agent act outside your own walls, ask the vendor to show you the record it keeps and the limits you can set. If those answers are vague, the trust has not been designed yet, and you are the one who will carry the result.

The tools are good and you may still need your own

It is tempting to read all of this as a choice between buying agents and building them. A post from SaaStr is a useful corrective, because it is written by heavy users of bought tools. They run several AI outbound products at once — noting, for example, that one of them "runs cold outbound" — and yet still built their own AI account-based-marketing tool for their top accounts [3].

The lesson is not that general tools fail. It is that general tools are tuned for the general case, and your most valuable accounts are, by definition, not the general case. A bought agent that handles the broad middle of your pipeline well can coexist with a small, deliberate build for the handful of relationships where a generic approach would cost you real money. For most businesses the order of operations is the reverse of the hype: use the off-the-shelf tool first, learn exactly where it falls short for you, and only then spend on something bespoke — and only for the cases that justify it. Building for everything is how teams end up maintaining software instead of using it.

Protection has to scale at the same rate as creation

If agents write and ship more software, more secrets end up inside that software. A secret, in this context, is a credential — an API key, a password, a token — that a program needs to reach another system. Leave one in code that becomes public and anyone who finds it inherits that access. GitHub's argument today is that the volume of code is now outpacing the old habit of catching these by hand: "Developers aren't becoming more careless; they're being outpaced," and the tools that help people create more software should take on more of the work of protecting it [4].

That framing is worth adopting even if you write no code at all. As you add automation, you add credentials — every integration between two tools is a key held somewhere. The discipline that scales is not heroic vigilance; it is making the safe path the default, so protection grows automatically as the surface grows rather than depending on someone remembering. When you choose a platform, a fair question is whether it treats your credentials as something it is responsible for guarding, or something it merely stores.

A month to check the basics

None of the above replaces the ordinary hygiene that protects most businesses most of the time. Xero marked the occasion plainly: "October is Cybersecurity Awareness Month, and a good moment to check in on how you're protecting your business, your money and your customers' information" [5]. The timing is a prompt, not a product.

The basics have not changed because agents arrived, and they are worth a deliberate hour this month. Turn on multi-factor authentication everywhere it is offered. Review who has access to each system and remove anyone who no longer needs it. Confirm your backups actually restore, rather than assuming they do. Know how you would revoke a key or a login quickly if one leaked. These are unglamorous, and they are the steps that decide whether an incident is an inconvenience or a crisis. An audit trail you can read ties directly to the accountability question above, which is why we keep returning to it (saas-daily-briefing-2026-10-05).

The common line across the day is simple to state and hard to live by. The industry is ready to let software act on its own, and the same industry is telling you, in the same breath, that acting on your behalf is a responsibility you cannot hand away. Choose tools that make the record easy to read and the limits easy to set. The clever part will take care of itself; the accountable part is yours.

Sources

  1. [1] Nous Research confirms it hit $1.5B valuation, launches AI agents for business users — TechCrunch
  2. [2] From Autonomy to Accountability: How to Think About Trust in the Multi-Agent Future — Salesforce
  3. [3] We Run Monaco, Agentforce and Artisan for Outbound. Why We Still Also Built Our Own "AI ABM" Tool for Our Top Accounts — SaaStr
  4. [4] Secret protection must scale with software — GitHub
  5. [5] Tips to protect your business from modern cybercrime — Xero

The 360REV newsletter

What is actually changing across productivity software, written for operators and cited to sources. No more than one email a day.

Double opt-in — we send one confirmation link and nothing else until you click it. Unsubscribe from any edition. We never sell or share your address.