<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Jakub Skalbania]]></title><description><![CDATA[Jakub Skałbania is the CEO and Founder of Netwise, a 7× Microsoft Partner of the Year for CRM in Poland, and an alumnus of University of Oxford. A 16× Microsoft MVP, he writes about the intersection of enterprise CRM architecture and agentic AI.]]></description><link>https://www.onagenticcrm.com</link><image><url>https://substackcdn.com/image/fetch/$s_!-SKD!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2519ff6d-53ea-4514-bb9b-023696a35648_400x400.png</url><title>Jakub Skalbania</title><link>https://www.onagenticcrm.com</link></image><generator>Substack</generator><lastBuildDate>Sun, 02 Aug 2026 13:21:31 GMT</lastBuildDate><atom:link href="https://www.onagenticcrm.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Jakub Skalbania]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[onagenticcrm@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[onagenticcrm@substack.com]]></itunes:email><itunes:name><![CDATA[Jakub Skałbania]]></itunes:name></itunes:owner><itunes:author><![CDATA[Jakub Skałbania]]></itunes:author><googleplay:owner><![CDATA[onagenticcrm@substack.com]]></googleplay:owner><googleplay:email><![CDATA[onagenticcrm@substack.com]]></googleplay:email><googleplay:author><![CDATA[Jakub Skałbania]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[The state of the Agentic Enterprise in July 2026]]></title><description><![CDATA["Agentic arbitrage", AI Act deferrals, delegation gap and agentic e-commerce]]></description><link>https://www.onagenticcrm.com/p/the-state-of-the-agentic-enterprise</link><guid isPermaLink="false">https://www.onagenticcrm.com/p/the-state-of-the-agentic-enterprise</guid><dc:creator><![CDATA[Jakub Skałbania]]></dc:creator><pubDate>Sun, 02 Aug 2026 10:55:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!UXHG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c1b110-9d84-44da-a18c-983758b702de_2026x1736.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p style="text-align: justify;">In July 2026, two long-awaited stories from the AI world were assigned with numerical data and specific dates. Gartner put a dollar amount on what agents will do to the SaaS business model - <strong>up to $234 billion of enterprise application spending exposed by 2030</strong>. And the European Union completed, signed, and prepared for publication the <strong>first substantive amendment to the AI Act</strong>, ie. the Digital Omnibus, moving the high-risk obligations that everyone had planned for August 2, 2026 - including me, in my first article on this Substack: <a href="https://onagenticcrm.substack.com/p/processes-before-prompts-why-agentic">Processes Before Prompts - why agentic CRM will be won on the process layer</a>.</p><h2><strong>Gartner&#8217;s $234 billion - the pricing anxiety I wrote about in May now has a name</strong></h2><p style="text-align: justify;">In my May roundup I described Salesforce running three pricing models simultaneously (per conversation, per action, per user) that reflected the fact that the market had not settled on how to purchase agentic outcomes. On July 1, Gartner estimated that up to $234 billion of enterprise application software spending is exposed to what it calls &#8222;<strong>agentic arbitrage</strong>&#8220; between now and 2030, roughly 20% of enterprise application SaaS spending by the end of the decade.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a></p><p style="text-align: justify;"><strong>Agentic arbitrage </strong>is Gartner&#8217;s name for what happens when agents complete tasks across multiple systems and the humans stop opening the interfaces those systems charge seats for.</p><div class="pullquote"><p style="text-align: center;">&#8220;Agentic AI changes the economics of software&#8221;</p></div><p style="text-align: justify;">according to George Brocklehurst, Managing VP at Gartner, because agents deliver outcomes directly and some software apps simply become invisible. So, the link between user growth and revenue growth breaks (<a href="https://www.gartner.com/en/newsroom/press-releases/2026-07-01-gartner-says-us-dollars-234-billion-in-enterprise-application-software-spend-is-at-risk-from-agentic-artificial-intelligence">Gartner Says $234 Billion in Enterprise Application Software Spend Is at Risk from Agentic AI</a>).</p><p style="text-align: justify;">Two things are worth noting about <strong>agentic arbitrage</strong>.</p><p style="text-align: justify;">First, the <strong>$234 billion is not spending that will vanish</strong>. It is spending that gets repriced away from seats, toward consumption and outcomes. That is exactly the transition Salesforce&#8217;s three parallel pricing models and Microsoft&#8217;s &#8220;seats as entitlement to consumption&#8221; are.</p><p style="text-align: justify;">Second, we need to notice where the arbitrage happens. It pertains to AI agents completing work across multiple systems, so <strong>the value does not leak out of any single application</strong>. It leaks out of the seams between applications - the re-entering data, the &#8220;let me check in the other system.&#8221; Which means the companies most exposed are not the ones with the worst software. They are the ones with the least-designed processes spanning the most systems.</p><p style="text-align: justify;">The seat model is not being killed by better AI. It is being <strong>killed by the process layer that will finally get an execution engine in the form of agents</strong>.</p><p style="text-align: justify;">If you run a system of record, eg CRM, the question your 2027 budget should answer is no longer &#8220;how many licenses.&#8221; Instead it should be:</p><blockquote><p style="text-align: center;"><strong>&#8220;Which processes will agents execute end-to-end, and what are we actually paying for when they do?&#8221;</strong></p></blockquote><p></p><h2 style="text-align: justify;"><strong>The AI Act moved</strong></h2><p style="text-align: justify;">In my first article I wrote that enforcement of the AI Act&#8217;s high-risk obligations begins on August 2, 2026 and that companies deploying agents on undocumented processes would &#8220;spend 2027 paying lawyers what they should have spent in 2026 paying process designers&#8221;. The first half of that sentence is now outdated and the second half aged better.</p><p style="text-align: justify;">The European Commission proposed the <strong>Digital Omnibus on AI</strong> in November 2025. Parliament and Council reached provisional agreement on May 7, 2026. Parliament formally endorsed it on June 16, the Council gave final approval on June 29, and the final act was signed on July 8, with publication in the Official Journal expected before the original August 2 deadline, precisely so the amendment takes legal effect in time.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a></p><p style="text-align: justify;">And this change means slightly different and unclear things to the AI Act in Europe:</p><ol><li><p style="text-align: justify;"><strong>Some things are deferred</strong></p><p style="text-align: justify;">Mainly, the heavy high-risk compliance machinery. Stand-alone high-risk systems under Annex III, the list that covers employment decisions, credit scoring, access to essential services now come due on <strong>December 2, 2027</strong> (a 17-month extension). High-risk AI embedded in regulated products (Annex I) moves to <strong>August 2, 2028</strong> (2 years).</p></li><li><p><strong>Some things are not deferred</strong></p><p>Article 50 transparency obligations, disclosing to people that they are interacting with an AI system, marking synthetic content, labeling deepfakes, still take effect on <strong>August 2, 2026</strong>. So do the Commission&#8217;s enforcement powers over general-purpose AI models. Penalties in this tier reach 15 million EUR or 3% of global annual turnover, whichever is higher.</p></li></ol><p>So, now, as of August 2, 2026, the timeline looks as follows:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UXHG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c1b110-9d84-44da-a18c-983758b702de_2026x1736.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UXHG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c1b110-9d84-44da-a18c-983758b702de_2026x1736.png 424w, https://substackcdn.com/image/fetch/$s_!UXHG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c1b110-9d84-44da-a18c-983758b702de_2026x1736.png 848w, https://substackcdn.com/image/fetch/$s_!UXHG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c1b110-9d84-44da-a18c-983758b702de_2026x1736.png 1272w, https://substackcdn.com/image/fetch/$s_!UXHG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c1b110-9d84-44da-a18c-983758b702de_2026x1736.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UXHG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c1b110-9d84-44da-a18c-983758b702de_2026x1736.png" width="1456" height="1248" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/25c1b110-9d84-44da-a18c-983758b702de_2026x1736.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1248,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:434728,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://onagenticcrm.substack.com/i/209477349?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c1b110-9d84-44da-a18c-983758b702de_2026x1736.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UXHG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c1b110-9d84-44da-a18c-983758b702de_2026x1736.png 424w, https://substackcdn.com/image/fetch/$s_!UXHG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c1b110-9d84-44da-a18c-983758b702de_2026x1736.png 848w, https://substackcdn.com/image/fetch/$s_!UXHG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c1b110-9d84-44da-a18c-983758b702de_2026x1736.png 1272w, https://substackcdn.com/image/fetch/$s_!UXHG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c1b110-9d84-44da-a18c-983758b702de_2026x1736.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><strong>Timeline for the Implementation of the EU AI Act, originally presented here: https://ai-act-service-desk.ec.europa.eu/en/ai-act/timeline/timeline-implementation-eu-ai-act</strong></figcaption></figure></div><p style="text-align: justify;">Now if we read this change through Agentic CRM and Agentic Enterprise lens (service bots, voice agents, outbound sequences drafted by AI), then the obligation that applies to them is the one that was <strong>not</strong> delayed. The heavy machinery that got pushed to 2027 mostly governs a different class of systems.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.onagenticcrm.com/p/the-state-of-the-agentic-enterprise?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Jakub Skalbania! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.onagenticcrm.com/p/the-state-of-the-agentic-enterprise?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.onagenticcrm.com/p/the-state-of-the-agentic-enterprise?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><h2>The delegation gap is getting its own product category</h2><p style="text-align: justify;">In June I defined the <strong>delegation gap</strong> (the distance between the identity that requests an agent action and the identity that executes it) and I wrote that authorization, not hallucination, is the agent risk that actually materializes in production:</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;9669bab9-0532-438e-9a17-69cb611bcac2&quot;,&quot;caption&quot;:&quot;In late May and early June this year, attackers hijacked 20,225 Instagram accounts (number disclosed by Meta), among them: the Obama-era White House account, the account of the U.S. Space Force&#8217;s Chief Master Sergeant and many others. There was no hacking in any traditional sense. No broken authentication, no malware, not even a prompt injection.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The Permission Problem: your AI agents' biggest risk is authorization&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:504524684,&quot;name&quot;:&quot;Jakub Ska&#322;bania&quot;,&quot;bio&quot;:&quot;Jakub Ska&#322;bania is the CEO and Founder of Netwise, a 7&#215; Microsoft Partner of the Year for CRM in Poland, and an alumnus of University of Oxford. A 16&#215; Microsoft MVP, he writes about the intersection of enterprise CRM architecture and agentic AI.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2519ff6d-53ea-4514-bb9b-023696a35648_400x400.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-07-08T17:37:36.781Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!7zCm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4dba52c5-7f39-4530-8993-629998e6232e_2720x1880.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://onagenticcrm.substack.com/p/the-permission-problem-your-ai-agents&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:206101118,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:0,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8932736,&quot;publication_name&quot;:&quot;Jakub Skalbania&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!-SKD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2519ff6d-53ea-4514-bb9b-023696a35648_400x400.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p style="text-align: justify;">In July, the market started shipping infrastructure to cover that gap. On July 16, 1Password announced an integration that lets AI agents, starting with Anthropic&#8217;s Claude, <strong>securely use a person&#8217;s credentials without exposing those credentials to the model itself</strong>. It is de facto a dedicated credential layer for AI delegation - the agent can act as a user without ever holding what makes it that user.</p><p style="text-align: justify;">So, secrets management for humans officially <strong>became a product category</strong> (Vault, Key Vault, 1Password). Credential brokering for agents validates the architectural claim underneath the delegation gap: the fix is not a more careful prompt or a more cautious model. <strong>It is a separate, auditable layer that owns the mapping between requesting identity and executing identity.</strong> Microsoft&#8217;s addition of Azure Key Vault credential management to computer-using agents in May was the platform version of the same move; 1Password&#8217;s launch is the cross-platform version.</p><blockquote><p style="text-align: center;">If your AI agent still handles this with a service account that the agent uses for everything, you are on the wrong side of the tooling.</p></blockquote><p style="text-align: justify;"></p><h2>Agentforce goes shopping: agents enter the buying channel</h2><p style="text-align: justify;">The platform move of the month (actually announced in the end of June) came from Salesforce: Agentforce Commerce reached general availability, with three named agents (Shopper, Buyer, and Merchant)<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a> and planned native integrations into ChatGPT and Gemini channels.</p><p style="text-align: justify;">The three-agent split maps to the three parties in a commerce transaction, but the integration plan is the strategic part. Salesforce is accepting that the conversation surface where buying decisions happen may not be a Salesforce property and is positioning its agents to execute inside someone else&#8217;s channel. That is the same logic as Gartner&#8217;s arbitrage argument, run in reverse: <strong>if outcomes detach from interfaces, then a vendor&#8217;s defensible asset is not the storefront UI</strong>. It is the agent that can check inventory, confirm the cutoff, and close the transaction against the system of record, wherever the customer happens to be typing.</p><p style="text-align: justify;">For CRM practitioners this extends the migration path I described in May. Wave 1 was front-office copilots. Wave 2 was back-office operations (Agentforce Operations, April). </p><blockquote><p style="text-align: center;"><strong>Wave 3 begins now, and it is agents operating in channels the enterprise does not own.</strong> </p></blockquote><p style="text-align: justify;">Every question from my previous articles about permissions, scope, and process ownership gets harder in Wave 3 because the execution environment is only half yours.</p><p style="text-align: justify;"></p><h2>Summary of the current state of Agentic Enterprise</h2><p style="text-align: justify;">July was a pretty important month for Agentic AI.</p><p style="text-align: justify;">The price tag indicates that the seat-license model incurs up to 20% of enterprise SaaS spending to agents who execute across various systems. <strong>This translates to a staggering $234 billion, highlighting the shift in value towards the process layer.</strong> </p><p style="text-align: justify;">On the legal front, the transparency rules for customer-facing AI are set to take effect on August 2, 2026, <strong>while the complex high-risk machinery is deferred to December 2027</strong>.</p><p style="text-align: justify;">Both stories reward the same behavior: knowing your processes well enough to know where the agents, the money, and the obligations actually are. The vendors will keep shipping, analysts will keep pricing and the regulators will keep deferring / enforcing. What is still optional for a few more quarters is whether your organization does the inventory before the incident does it for you.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.onagenticcrm.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Jakub Skalbania! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>&#8220;<em>Gartner Says $234 Billion in Enterprise Application Software Spend Is at Risk from Agentic AI&#8221;</em>, July 2026, https://www.gartner.com/en/newsroom/press-releases/2026-07-01-gartner-says-us-dollars-234-billion-in-enterprise-application-software-spend-is-at-risk-from-agentic-artificial-intelligence</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>&#8220;<em>Timeline for the Implementation of the EU AI Act</em>&#8221;, July 2026, https://ai-act-service-desk.ec.europa.eu/en/ai-act/timeline/timeline-implementation-eu-ai-act</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>&#8220;<em>As AI Agents Transform Commerce, Salesforce Unleashes Its Biggest Agentforce Commerce Release Yet</em>&#8221;, June 2026, https://www.salesforce.com/news/stories/agentforce-commerce-announcement/</p></div></div>]]></content:encoded></item><item><title><![CDATA[What an 87-year old conjecture falling on a Sunday night tells us about who actually captures value from frontier AI]]></title><description><![CDATA[Jacobian conjecture, Claude Fable and a world-class mathematician]]></description><link>https://www.onagenticcrm.com/p/what-an-87-year-old-conjecture-falling</link><guid isPermaLink="false">https://www.onagenticcrm.com/p/what-an-87-year-old-conjecture-falling</guid><dc:creator><![CDATA[Jakub Skałbania]]></dc:creator><pubDate>Thu, 23 Jul 2026 10:38:20 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!mgV9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd72a0dff-0991-4436-8b3e-ea3f2a6d0db1_760x472.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Jacobian conjecture, Claude Fable and a world-class mathematician</h2><p style="text-align: justify;">On Sunday night, while most of the world was watching the World Cup 2026 final, an 87-year-old mathematical conjecture died.</p><p style="text-align: justify;">The Jacobian conjecture, stated by Ott-Heinrich Keller in 1939 with roots going back to an 1884 paper by Ludwig Kraus, was one of the central open problems in algebraic geometry. Problem 16 on Stephen Smale&#8217;s list of mathematical problems for the 21st century. It is famous for two things: being simple enough to state to anyone who knows calculus and for the graveyard of published &#8220;proofs&#8221; that all turned out to contain subtle errors. For over eight decades, some of the best mathematicians alive tried and failed.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.onagenticcrm.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Jakub Skalbania! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p style="text-align: justify;">Then, on 20th July 2026, Levent Alp&#246;ge posted a polynomial map on X. Three variables, constant Jacobian determinant of &#8722;2 and <strong>three distinct points land on the same output</strong>. Non-injective and not invertible. Result is that the conjecture was shown false.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mgV9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd72a0dff-0991-4436-8b3e-ea3f2a6d0db1_760x472.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mgV9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd72a0dff-0991-4436-8b3e-ea3f2a6d0db1_760x472.png 424w, https://substackcdn.com/image/fetch/$s_!mgV9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd72a0dff-0991-4436-8b3e-ea3f2a6d0db1_760x472.png 848w, https://substackcdn.com/image/fetch/$s_!mgV9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd72a0dff-0991-4436-8b3e-ea3f2a6d0db1_760x472.png 1272w, https://substackcdn.com/image/fetch/$s_!mgV9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd72a0dff-0991-4436-8b3e-ea3f2a6d0db1_760x472.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mgV9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd72a0dff-0991-4436-8b3e-ea3f2a6d0db1_760x472.png" width="760" height="472" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d72a0dff-0991-4436-8b3e-ea3f2a6d0db1_760x472.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:472,&quot;width&quot;:760,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:288041,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://onagenticcrm.substack.com/i/208178631?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd72a0dff-0991-4436-8b3e-ea3f2a6d0db1_760x472.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mgV9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd72a0dff-0991-4436-8b3e-ea3f2a6d0db1_760x472.png 424w, https://substackcdn.com/image/fetch/$s_!mgV9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd72a0dff-0991-4436-8b3e-ea3f2a6d0db1_760x472.png 848w, https://substackcdn.com/image/fetch/$s_!mgV9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd72a0dff-0991-4436-8b3e-ea3f2a6d0db1_760x472.png 1272w, https://substackcdn.com/image/fetch/$s_!mgV9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd72a0dff-0991-4436-8b3e-ea3f2a6d0db1_760x472.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>According to Alp&#246;ge himself, the counterexample was generated by Claude Fable 5.</p><p></p><div class="latex-rendered" data-attrs="{&quot;persistentExpression&quot;:&quot;F(x,y,z) = \\begin{pmatrix} (1+xy)^3 z + y^2(1+xy)(4+3xy) \\\\ y + 3x(1+xy)^2 z + 3xy^2(4+3xy) \\\\ 2x - 3x^2y - x^3 z \\end{pmatrix}&quot;,&quot;id&quot;:&quot;XWABUZQPQV&quot;}" data-component-name="LatexBlockToDOM"></div><p></p><p>Now, two narratives immediately occurred after this breaking math news:</p><p style="text-align: justify;">Narrative 1:</p><p style="text-align: justify;"><em>&#8220;AI just solved an 87-year-old open problem. Mathematicians are obsolete. Everyone is obsolete.&#8221;</em></p><p style="text-align: justify;">Narrative 2:</p><p><em>&#8220;It&#8217;s a stochastic parrot doing matrix multiplication. It got lucky. This means nothing.&#8221;</em></p><p style="text-align: justify;">Both narratives are wrong and they are wrong in the same way. <strong>They erase the most important person in the story</strong>.</p><p style="text-align: justify;"></p><h2 style="text-align: justify;"><strong>Who was actually at the keyboard</strong></h2><p style="text-align: justify;">Levent Alp&#246;ge is not &#8220;a guy with a Claude subscription&#8221;. He is a world-class mathematician, who won the Morgan Prize (the award for the best mathematical research done by an undergraduate in America). His Princeton PhD work was in arithmetic geometry. In 2025 he co-authored the resolution of Hilbert&#8217;s tenth problem over rings of integers of number fields (a problem posed in 1900). He was a Junior Fellow at Harvard.</p><p style="text-align: justify;">Then Alp&#246;ge decided to join Anthropic and to work on frontier models. So, the configuration that killed the Jacobian conjecture was not &#8220;a model&#8221;. </p><p style="text-align: justify;"><strong>It was a world-class mathematician, working in a frontier lab, prompted by a question from another world-class mathematician (Akhil Mathew asked about the problem), working with the best model available with the depth to recognize a real answer when he saw one.</strong></p><p style="text-align: justify;">Alp&#246;ge described how it happened - the counterexample emerged from what he called the model &#8220;ideating about a bunch of random stuff.&#8221;</p><h2><strong>Random stuff is what generators produce, results are what humans filter</strong></h2><p style="text-align: justify;">A reasoning model exploring a hard problem produces a bunch of random stuff. Wide, nonlinear search across a space of ideas. Most of it is noise. Some of it is nonsense that looks plausible and occasionally there is a candidate that might actually prove or close things.</p><p style="text-align: justify;">The AI models are the <strong>generators</strong>. The frontier models are phenomenal generators, better than anything we have ever built. But a generator without a <strong>filter</strong> produces noise at scale.</p><p style="text-align: justify;">Now, let&#8217;s see what the human filter did in this story:</p><ol><li><p style="text-align: justify;"><strong>Someone had to choose the problem</strong></p></li></ol><p style="text-align: justify;">This is the part almost everyone misses. The Jacobian conjecture could plausibly fall to a counterexample: a concrete object you can write down and verify by direct computation. That makes it a fundamentally different target than, say, the Riemann hypothesis, which requires a proof, a different class of artifact and one that <strong>today&#8217;s models cannot produce for problems of that depth</strong>. Knowing which type of result is within a model&#8217;s reach, on which problem, is itself deep expertise. Alp&#246;ge didn&#8217;t point the model at a random famous problem. <strong>He pointed it at one where the achievable artifact matched the model&#8217;s actual capability.</strong></p><ol start="2"><li><p style="text-align: justify;"><strong>Someone had to recognize the candidate</strong></p></li></ol><p style="text-align: justify;">In a stream of &#8220;random stuff,&#8221; a specific polynomial map in three variables does not announce itself as historic. To a non-expert it would look like every other line of algebra the model produced. Recognizing that this one might close required an experienced eye, ideally one built over fifteen years of doing mathematics at the highest level.</p><ol start="3"><li><p style="text-align: justify;"><strong>Someone had to verify it</strong></p></li></ol><p style="text-align: justify;">The Jacobian conjecture&#8217;s graveyard is full of proofs, long chains of reasoning where errors hide in subtle places. <strong>A counterexample is the opposite: verification is arithmetic.</strong> Compute the Jacobian determinant symbolically and it comes out to a constant &#8722;2. Substitute three points (0, 0, &#8722;1/4), (1, &#8722;3/2, 13/2), (&#8722;1, 3/2, 13/2) and they map to (&#8722;1/4, 0, 0). Non-injective map, constant nonzero Jacobian, conjecture false. I ran the check myself in SymPy because when you know the points, it takes seconds. </p><blockquote><p style="text-align: center;"><strong>Knowing that this check suffices, and what it means, is pure and high level mathematics, not prompting.</strong></p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fhv_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbeca0d39-87b2-46c1-8cec-260d5160c21f_2630x1264.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fhv_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbeca0d39-87b2-46c1-8cec-260d5160c21f_2630x1264.jpeg 424w, https://substackcdn.com/image/fetch/$s_!fhv_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbeca0d39-87b2-46c1-8cec-260d5160c21f_2630x1264.jpeg 848w, https://substackcdn.com/image/fetch/$s_!fhv_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbeca0d39-87b2-46c1-8cec-260d5160c21f_2630x1264.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!fhv_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbeca0d39-87b2-46c1-8cec-260d5160c21f_2630x1264.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fhv_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbeca0d39-87b2-46c1-8cec-260d5160c21f_2630x1264.jpeg" width="1456" height="700" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/beca0d39-87b2-46c1-8cec-260d5160c21f_2630x1264.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:700,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:408378,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://onagenticcrm.substack.com/i/208178631?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbeca0d39-87b2-46c1-8cec-260d5160c21f_2630x1264.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fhv_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbeca0d39-87b2-46c1-8cec-260d5160c21f_2630x1264.jpeg 424w, https://substackcdn.com/image/fetch/$s_!fhv_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbeca0d39-87b2-46c1-8cec-260d5160c21f_2630x1264.jpeg 848w, https://substackcdn.com/image/fetch/$s_!fhv_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbeca0d39-87b2-46c1-8cec-260d5160c21f_2630x1264.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!fhv_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbeca0d39-87b2-46c1-8cec-260d5160c21f_2630x1264.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Model + Human workflow</figcaption></figure></div><p></p><h2><strong>Why I&#8217;m writing about this on a Substack about enterprise Agentic AI</strong></h2><p style="text-align: justify;">The dominant enterprise AI narrative right now is Narrative 1 from above, dressed in procurement language: <strong>buy the best model, roll out the copilots, deploy the agents, and results will follow.</strong> The model will solve it.</p><p style="text-align: justify;">Enterprise processes are not the Jacobian conjecture, but the structure of the problem is identical. An agent operating inside your order-to-cash process, claims handling, customer service dispatch, is a <strong>generator</strong>. It will propose actions. The questions that decide whether this creates value or damage are the filter questions: </p><ul><li><p style="text-align: justify;">Who chose which process the agent operates on and whether it was the right one?</p></li><li><p style="text-align: justify;">Who defined what a correct outcome looks like?</p></li><li><p style="text-align: justify;">Who can verify that what the agent produced actually closes and catch the plausible-looking nonsense before it hits a customer or a ledger?</p></li></ul><p style="text-align: justify;"><strong>Those questions are not answered by a model</strong>. </p><p style="text-align: justify;">They are answered by <strong><span data-color="#ff5600" style="color: rgb(255, 86, 0);">people who have spent years inside the process</span></strong> - who know where the bodies are buried in your CRM data, why the exception path exists for customers with gold status, or who decides on the outcomes. </p><blockquote><p style="text-align: justify;"><strong>Process depth is to enterprise AI what Alp&#246;ge&#8217;s 15 years in arithmetic geometry were to Sunday night - the difference between random stuff and a result.</strong></p></blockquote><p style="text-align: justify;">This is why I keep repeating that <strong>agentic AI is a process engineering discipline, not a licensing exercise or a model thing.</strong> </p><p style="text-align: justify;">The organizations that will capture value are not the ones with the most seats and best models. They are the ones that pair frontier generators with the deepest domain filters and treat the filter as the scarce asset, because it is.</p><p style="text-align: justify;">Processes before prompts. Filters before generators. Always.</p><p style="text-align: justify;"></p><p style="text-align: justify;">IMPORTANT NOTES:</p><ol><li><p style="text-align: justify;">The result is days old at the time of writing. There is no paper and no peer review yet, although the verification is elementary enough that multiple mathematicians have independently confirmed the computation.</p></li><li><p style="text-align: justify;">Precision matters - the counterexample kills the conjecture in three variables and above. The original two-variable case, the one Kraus actually wrote down in 1884, remains <strong>open</strong>.</p></li></ol><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.onagenticcrm.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Jakub Skalbania! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Permission Problem: your AI agents' biggest risk is authorization]]></title><description><![CDATA[A hallucination is loud and an over-permissioned agent is silent, right up until someone asks it, politely, to hand over the keys.]]></description><link>https://www.onagenticcrm.com/p/the-permission-problem-your-ai-agents</link><guid isPermaLink="false">https://www.onagenticcrm.com/p/the-permission-problem-your-ai-agents</guid><dc:creator><![CDATA[Jakub Skałbania]]></dc:creator><pubDate>Wed, 08 Jul 2026 17:37:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!7zCm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4dba52c5-7f39-4530-8993-629998e6232e_2720x1880.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p style="text-align: justify;">In late May and early June this year, attackers hijacked 20,225 Instagram accounts (number disclosed by Meta), among them: the Obama-era White House account, the account of the U.S. Space Force&#8217;s Chief Master Sergeant and many others. There was no hacking in any traditional sense. No broken authentication, no malware, not even a prompt injection.</p><p style="text-align: justify;">The attackers simply sent a message to Meta&#8217;s AI support assistant asking it to link a new recovery e-mail to the target account. The agent, rolled out in March with real operational privileges and marketed as delivering &#8220;solutions, not just suggestions,&#8221; did exactly what it was asked to do. It had the permissions to modify recovery e-mails and&#8230; it used them.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!V-dx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe57bb64c-2430-4f52-9997-5683aa434540_2720x1840.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!V-dx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe57bb64c-2430-4f52-9997-5683aa434540_2720x1840.png 424w, https://substackcdn.com/image/fetch/$s_!V-dx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe57bb64c-2430-4f52-9997-5683aa434540_2720x1840.png 848w, https://substackcdn.com/image/fetch/$s_!V-dx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe57bb64c-2430-4f52-9997-5683aa434540_2720x1840.png 1272w, https://substackcdn.com/image/fetch/$s_!V-dx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe57bb64c-2430-4f52-9997-5683aa434540_2720x1840.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!V-dx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe57bb64c-2430-4f52-9997-5683aa434540_2720x1840.png" width="1456" height="985" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e57bb64c-2430-4f52-9997-5683aa434540_2720x1840.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:985,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:268017,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://onagenticcrm.substack.com/i/206101118?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe57bb64c-2430-4f52-9997-5683aa434540_2720x1840.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!V-dx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe57bb64c-2430-4f52-9997-5683aa434540_2720x1840.png 424w, https://substackcdn.com/image/fetch/$s_!V-dx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe57bb64c-2430-4f52-9997-5683aa434540_2720x1840.png 848w, https://substackcdn.com/image/fetch/$s_!V-dx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe57bb64c-2430-4f52-9997-5683aa434540_2720x1840.png 1272w, https://substackcdn.com/image/fetch/$s_!V-dx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe57bb64c-2430-4f52-9997-5683aa434540_2720x1840.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Instagram incident reflected as a diagram</figcaption></figure></div><p style="text-align: justify;"><strong>The agent did not hallucinate and it did not go rogue.</strong></p><p style="text-align: justify;">According to the company, the tool itself worked properly and functioned as intended, and the failure was a bug in a separate code path, which never verified that the e-mail address provided by the requester actually matched the account. The agent held execution privileges, and the one deterministic check that should have stood between its intent and the action was broken. Nothing in the conversation layer could compensate, because nothing in the conversation layer is built to.</p><p style="text-align: justify;">In my last article (&#8220;<a href="https://onagenticcrm.substack.com/p/the-button-that-broke-the-agent">The button that broke the agent</a>&#8221;) I described a small, harmless failure, when someone clicked a button, upgraded Microsoft Planner to Premium, and as a result my agent went silent. Fail-stop, narrow scope, human in the loop. Thus, the failure cost me a few uncreated tasks and several minutes of debugging.</p><p>I promised to break down the engineering of the foundation agents stand on. This is the first piece of that foundation: <strong>authorization</strong>.</p><p>The Meta case is what fail-continue scenario that I warned about, at global scale. The agent doesn&#8217;t stop. It keeps executing with permissions nobody should have given it and completed actions for requesters nobody verified.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.onagenticcrm.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading my work. Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2><strong>Hallucination is visible and over-authorization is not</strong></h2><p style="text-align: justify;">The industry has spent three years training executives to fear the wrong failure mode.</p><p style="text-align: justify;">A hallucination announces itself - a user reads a wrong answer, laughs or complains, screenshots it, sometimes posts it on LinkedIn. The feedback loop is measured in minutes. Embarrassing, sometimes expensive, but <em>loud</em>.</p><p style="text-align: justify;">An authorization failure announces nothing. An agent with write access produces correct-looking outputs on top of an access model that is quietly wrong. Nothing looks broken. You discover the problem at an audit, or after an incident, and by then the question is no longer &#8220;<em>did the agent perform the task correctly?</em>&#8221; but &#8220;<em><strong>should it have been able to perform it at all?</strong></em>&#8220;</p><p style="text-align: justify;">The 2026 data says this is now the dominant failure mode, not the edge case:</p><ul><li><p>Gravitee&#8217;s <em>State of AI Agent Security 2026<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a></em> (900+ executives and practitioners): <strong>88% of organizations reported a confirmed or suspected AI-agent security incident</strong> in the past year. Only 21.9% treat agents as independent, identity-bearing entities. 45.6% still authenticate agents with shared API keys.</p></li><li><p>The Cloud Security Alliance / Zenity research I cited in my May roundup: <strong>53% of organizations had agents exceed their intended permissions.</strong></p></li><li><p>EY&#8217;s Responsible AI Pulse survey<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a> (975 C-suite leaders at companies above $1B in revenue, published October 2025): 99% reported financial losses from AI-related risks, and 64% suffered losses exceeding $1 million &#8212; conservatively averaging $4.4 million per affected company.</p></li><li><p>Teleport&#8217;s 2026 research reports<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a> the single most persuasive delta I have seen this year: organizations enforcing least-privilege access for agents report a <strong>17% incident rate; those without it, 76%</strong>.</p></li></ul><h2><strong>The delegation gap</strong></h2><p>Traditional IAM answers one question: <em>who is this user and what may they do?</em></p><p>An agent breaks that model in <strong>both directions at once</strong> because it inserts a second identity between the requester and the action:</p><ol><li><p><strong>The agent may hold more permissions than the human it acts for</strong><br>A seller asks the agent to summarize an account. The agent, running on a service principal with organization-wide read access, happily includes data from accounts that seller was never entitled to see. The human just used the agent as a privilege-escalation path, without even knowing it.</p><p></p></li><li><p><strong>The action is attributed to the agent, not the human</strong><br>Audit logs show the agent&#8217;s identity did the write. Who asked? Why? Under what authority? The log does not say. And in most organizations it structurally cannot say: when 45.6% of teams authenticate agents with shared API keys, incident response cannot even determine which agent acted, let alone which human asked it to.</p><p></p></li></ol><p style="text-align: justify;">I call this the <strong>delegation gap</strong>. It&#8217;s the distance between the identity that <em>requests</em> an action and the identity that <em>executes</em> it. Every agent deployment has one.</p><blockquote><p style="text-align: center;"><strong>In CRM systems the delegation gap is not an abstract security concern. It</strong> <strong>is the difference between an agent that respects your sales territories, your GDPR data-subject boundaries, and your Chinese-wall obligations and an agent that flattens all of them into one god-mode service account because that was the fastest way to make the demo work.</strong></p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7zCm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4dba52c5-7f39-4530-8993-629998e6232e_2720x1880.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7zCm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4dba52c5-7f39-4530-8993-629998e6232e_2720x1880.png 424w, https://substackcdn.com/image/fetch/$s_!7zCm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4dba52c5-7f39-4530-8993-629998e6232e_2720x1880.png 848w, https://substackcdn.com/image/fetch/$s_!7zCm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4dba52c5-7f39-4530-8993-629998e6232e_2720x1880.png 1272w, https://substackcdn.com/image/fetch/$s_!7zCm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4dba52c5-7f39-4530-8993-629998e6232e_2720x1880.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7zCm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4dba52c5-7f39-4530-8993-629998e6232e_2720x1880.png" width="1456" height="1006" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4dba52c5-7f39-4530-8993-629998e6232e_2720x1880.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1006,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:293499,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://onagenticcrm.substack.com/i/206101118?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4dba52c5-7f39-4530-8993-629998e6232e_2720x1880.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7zCm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4dba52c5-7f39-4530-8993-629998e6232e_2720x1880.png 424w, https://substackcdn.com/image/fetch/$s_!7zCm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4dba52c5-7f39-4530-8993-629998e6232e_2720x1880.png 848w, https://substackcdn.com/image/fetch/$s_!7zCm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4dba52c5-7f39-4530-8993-629998e6232e_2720x1880.png 1272w, https://substackcdn.com/image/fetch/$s_!7zCm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4dba52c5-7f39-4530-8993-629998e6232e_2720x1880.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Identity propagated to an AI agent vs god-mode in CRM</figcaption></figure></div><p style="text-align: justify;">This is why we keep insisting that when we built our voice agent for Dynamics, the permission model was the longest single piece of work longer than the voice pipeline, longer than the prompts. Every tool call executes in the security context of the actual user, not the agent&#8217;s. If the seller cannot see the record through the UI, the agent cannot see it on their behalf through MCP.</p><h2 style="text-align: justify;"><strong>Least privilege is necessary but no longer sufficient</strong></h2><p style="text-align: justify;">Zenity&#8217;s research argues that least privilege alone fails for agents, because an agent can act <strong>within</strong> its granted permissions and still act wrongly - the Meta support assistant is the proof. Its permission to modify recovery e-mails was, arguably, <strong>correctly scoped for its job</strong>. The failure was not scope but verification: there was no independent, deterministic check that the requester owned the account, and <strong>no separation between conversational interaction and operational execution</strong>. Least privilege was satisfied and the account still fell.</p><p style="text-align: justify;">The emerging answer, visible across Zenity, the OWASP agentic security work, and the NIST NCCoE concept paper on agent identity published in February, is a <strong>third authorization layer</strong>:</p><p style="text-align: justify;">Not just <em>who is this agent</em> (authentication) and <em>what systems may it touch</em> (API authorization), but <strong>should this specific action execute, right now, under this policy, for this requester</strong> (action authorization).</p><p style="text-align: justify;">Notice what that third layer is. It is not a model capability and it is not a system prompt.</p><p style="text-align: justify;"><strong>It is deterministic code sitting between the agent&#8217;s intent and the system of record</strong>. It&#8217;s the same deterministic backbone I argued for in the 35.8% article, now applied to safety instead of workflows. Telling the agent to &#8220;be careful&#8221; in the system prompt is not a control. Prompts get overridden by injection, compacted out of long contexts, and eroded over multi-turn sessions. Caution is not an architecture. Neither is a system prompt.</p><h2><strong>What to do before your agent&#8217;s first audit</strong></h2><p style="text-align: justify;">Regulatory pressure makes this concrete. The EU AI Act&#8217;s high-risk obligations become enforceable on August 2 (weeks from now) and a regulator examining an AI-involved incident will expect you to reconstruct what your agent did, for whom, and under whose authorization.</p><p style="text-align: justify;">Five checks, in order of leverage:</p><ol><li><p><strong>Give every agent its own identity.</strong> No shared API keys, no reused service accounts.</p></li><li><p><strong>Propagate the human&#8217;s identity to every tool call.</strong> The agent acts <em>as</em> the requester, within the requester&#8217;s entitlements. This is the single control that closes the delegation gap, and in most CRM platforms it already exists - impersonation, on-behalf-of flows, row-level security. Use them.</p></li><li><p><strong>Enforce least privilege at the tool surface</strong>. API, table, record, field. Then assume it is not enough.</p></li><li><p><strong>Add action authorization for irreversible operations.</strong> Anything that mutates state a customer would notice (sent, deleted, paid, changed) gets a deterministic policy check, and above a defined threshold, a human checkpoint outside the conversation.</p></li><li><p><strong>Put the audit trail below the agent, not inside it.</strong> An audit layer embedded in the calling application disappears exactly when you need it. Log at the data layer, attribute both identities.</p></li></ol><p style="text-align: justify;">In my May roundup I quoted Gartner&#8217;s prediction that 40% of enterprises will demote or decommission their agents by 2027 not because the agents don&#8217;t work, but because of governance gaps discovered after an incident. The Permission Problem is that gap.</p><p style="text-align: justify;">Your agent will pass every demo and it might pass the pilot. The question that decides whether it survives contact with production (and with a regulator) is not &#8220;does it answer correctly?&#8221; It is the question nobody asks until it is too late:</p><p style="text-align: center;"><strong>Not &#8220;</strong><em><strong>did the agent do it right?</strong></em><strong>&#8221; but &#8220;</strong><em><strong>should it have been able to do it at all?</strong></em><strong>&#8221;</strong></p><p style="text-align: justify;">If you cannot answer that today, you might end up with a delegation gap with agentic enterprise slogan on top.</p><p style="text-align: justify;"></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.onagenticcrm.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Jakub Skalbania! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p><em>&#8220;<span>State of AI Agent Security 2026 Report: When Adoption Outpaces Control&#8221;</span></em><span>, Feb 2026, </span>https://www.gravitee.io/blog/state-of-ai-agent-security-2026-report-when-adoption-outpaces-control</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p><em>&#8220;Responsible AI Pulse survey&#8221;</em>, Sep 2025, https://www.ey.com/en_uk/insights/ai/how-responsible-ai-can-unlock-your-competitive-edge</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p><em>&#8220;<span>New Teleport Research Reveals AI Security Crisis in the Enterprise: Over-Privileged AI Systems Drive 4.5x Higher Incident Rates&#8221;</span></em><span>, Feb 2026,</span><strong><span> </span></strong>https://goteleport.com/about/newsroom/press-releases/2026-state-of-ai-in-enterprise-security-report/</p></div></div>]]></content:encoded></item><item><title><![CDATA[The button that broke the agent]]></title><description><![CDATA[The silent danger of shadow dependencies and why autonomy needs architectural integrity]]></description><link>https://www.onagenticcrm.com/p/the-button-that-broke-the-agent</link><guid isPermaLink="false">https://www.onagenticcrm.com/p/the-button-that-broke-the-agent</guid><dc:creator><![CDATA[Jakub Skałbania]]></dc:creator><pubDate>Sun, 21 Jun 2026 11:12:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-SKD!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2519ff6d-53ea-4514-bb9b-023696a35648_400x400.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p style="text-align: justify;">Two weeks ago, an agent I deployed quietly stopped working. It had been doing a small, useful job: reading meeting transcripts and turning them into tasks in Microsoft Planner, deciding to whom the task should be assigned and which bucket (strategy, presales etc.) it should be in. We relied on it without thinking about it, which is the highest compliment you can pay a piece of software.</p><p style="text-align: justify;">Then someone upgraded the Planner plan to Premium by&#8230; clicking a button shown by Microsoft in the Planner web, stating innocently that this plan can be upgraded to premium. One button and a perfectly rational decision to access better features. The person who clicked it was acting in good faith and did nothing wrong.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XUen!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d4a3748-26c0-43b2-b853-386221e5bfce_401x259.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XUen!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d4a3748-26c0-43b2-b853-386221e5bfce_401x259.png 424w, https://substackcdn.com/image/fetch/$s_!XUen!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d4a3748-26c0-43b2-b853-386221e5bfce_401x259.png 848w, https://substackcdn.com/image/fetch/$s_!XUen!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d4a3748-26c0-43b2-b853-386221e5bfce_401x259.png 1272w, https://substackcdn.com/image/fetch/$s_!XUen!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d4a3748-26c0-43b2-b853-386221e5bfce_401x259.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XUen!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d4a3748-26c0-43b2-b853-386221e5bfce_401x259.png" width="401" height="259" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2d4a3748-26c0-43b2-b853-386221e5bfce_401x259.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:259,&quot;width&quot;:401,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4857,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://onagenticcrm.substack.com/i/202940876?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d4a3748-26c0-43b2-b853-386221e5bfce_401x259.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XUen!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d4a3748-26c0-43b2-b853-386221e5bfce_401x259.png 424w, https://substackcdn.com/image/fetch/$s_!XUen!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d4a3748-26c0-43b2-b853-386221e5bfce_401x259.png 848w, https://substackcdn.com/image/fetch/$s_!XUen!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d4a3748-26c0-43b2-b853-386221e5bfce_401x259.png 1272w, https://substackcdn.com/image/fetch/$s_!XUen!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d4a3748-26c0-43b2-b853-386221e5bfce_401x259.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>And the agent&#8230; went silent.</p><p style="text-align: justify;">The reason? A Copilot Studio agent can&#8217;t create tasks in Planner Premium the same way it can in standard Planner. I&#8217;m fortunate enough to know both sides of this, because this is the ecosystem I live in as a Microsoft MVP and a hands-on CEO. With Planner Premium, I need to bypass the standard out-of-the-box Planner actions and instead configure the agent to use Dataverse / Project schedule API actions directly, or build an Agent Flow in Power Automate that handles the proper Dataverse-backed task creation.</p><p style="text-align: justify;">Fine - that&#8217;s a platform limitation, and platform limitations are not interesting. What&#8217;s interesting is the part I keep coming back to:</p><p style="text-align: justify;"></p><blockquote><p style="text-align: center;"><strong>Shadow dependencies in production at their worst:<br>the person who clicked that button had no idea an agent was running on the other side of it</strong></p></blockquote><p style="text-align: justify;"></p><p style="text-align: justify;">They didn&#8217;t break the agent out of carelessness. They broke it because, as far as the org was concerned, the thing the agent depended on wasn&#8217;t a foundation for an AI agent running somewhere else. It was just a setting - the plan still exists, it will now be a premium plan. <strong>Nobody had a picture of what was quietly using it and that it was my agent.</strong></p><p style="text-align: justify;">This is the reality of production AI.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!M3bD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0192603f-8292-4e37-a5fe-f9ce0b7469f1_428x80.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!M3bD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0192603f-8292-4e37-a5fe-f9ce0b7469f1_428x80.png 424w, https://substackcdn.com/image/fetch/$s_!M3bD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0192603f-8292-4e37-a5fe-f9ce0b7469f1_428x80.png 848w, https://substackcdn.com/image/fetch/$s_!M3bD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0192603f-8292-4e37-a5fe-f9ce0b7469f1_428x80.png 1272w, https://substackcdn.com/image/fetch/$s_!M3bD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0192603f-8292-4e37-a5fe-f9ce0b7469f1_428x80.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!M3bD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0192603f-8292-4e37-a5fe-f9ce0b7469f1_428x80.png" width="428" height="80" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0192603f-8292-4e37-a5fe-f9ce0b7469f1_428x80.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:80,&quot;width&quot;:428,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:21057,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://onagenticcrm.substack.com/i/202940876?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0192603f-8292-4e37-a5fe-f9ce0b7469f1_428x80.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!M3bD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0192603f-8292-4e37-a5fe-f9ce0b7469f1_428x80.png 424w, https://substackcdn.com/image/fetch/$s_!M3bD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0192603f-8292-4e37-a5fe-f9ce0b7469f1_428x80.png 848w, https://substackcdn.com/image/fetch/$s_!M3bD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0192603f-8292-4e37-a5fe-f9ce0b7469f1_428x80.png 1272w, https://substackcdn.com/image/fetch/$s_!M3bD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0192603f-8292-4e37-a5fe-f9ce0b7469f1_428x80.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p style="text-align: justify;">The failure was ultimately harmless because the agent was narrowly scoped (but its goal is not achievable with &#8220;standard&#8221; automation) and highly supervised. It operated in a <strong>fail-stop</strong> paradigm with a human in the loop who noticed the missing outputs within 24 hours. The worst-case outcome was a few tasks that didn&#8217;t get created and my anger until I found out what caused the error.</p><p style="text-align: justify;"></p><blockquote><p style="text-align: justify;"><strong>When an agent is narrow and its dependencies are traceable, failures are cheap.</strong></p></blockquote><p></p><h2 style="text-align: justify;"><strong>The danger of fail-continue</strong></h2><p style="text-align: justify;">Now keep the exact same mechanism - a silent dependency on a layer nobody is monitoring, that anyone can change with one click - and apply it to an autonomous system.</p><p style="text-align: justify;">Let&#8217;s consider agents everyone is now racing to build. Not a transcript-to-task helper, but autonomous agents working around the customer: reading the account, pulling context, deciding what to do next, and acting on it without a human watching each step.</p><p style="text-align: justify;">If someone clicks a button like in our case, in a distant space, or if someone changes a single permission, migrates a list, or enriches a record, or even swaps a connector to a &#8220;premium&#8221; version, the autonomous agent does not go silent. </p><p style="text-align: justify;"><strong>It experiences state drift and keeps running.</strong> </p><p style="text-align: justify;">It keeps acting on the customer, except now it&#8217;s acting on a foundation that quietly shifted underneath it - a permission it shouldn&#8217;t have, a record that&#8217;s now incomplete, context that&#8217;s subtly wrong. It doesn&#8217;t stop. It makes decisions <strong>based on truncated data, elevated permissions it shouldn&#8217;t possess, or corrupted context.</strong></p><p style="text-align: justify;">There&#8217;s no &#8220;that&#8217;s weird&#8221; the next morning because <strong>nothing looks broken</strong>. The agent is functioning perfectly on top of a broken foundation. This is a f<strong>ail-continue scenario, and it is the most dangerous state for an autonomous system.</strong></p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.onagenticcrm.com/p/the-button-that-broke-the-agent?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">If you like this post, feel free to share it with others!</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.onagenticcrm.com/p/the-button-that-broke-the-agent?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.onagenticcrm.com/p/the-button-that-broke-the-agent?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><h2 style="text-align: justify;"><strong>Architecture over caution</strong></h2><p style="text-align: justify;">The industry response to these risks is often a vague call to &#8220;be careful with AI.&#8221; This is a useless directive because caution is not an architecture.</p><p style="text-align: justify;">The agent in my story did precisely what it was supposed to do. The autonomous one in the hypothetical does too. Neither of them is the problem.</p><p style="text-align: justify;"></p><blockquote><p style="text-align: center;"><strong>The problem is that we are building autonomy on top of a layer we never decided to treat as a foundation.</strong></p></blockquote><p style="text-align: justify;"></p><p style="text-align: justify;">We continuously expand agents&#8217; capabilities by implementing deeper integrations, granting broader read / write access, and higher degrees of freedom. Yet, we implement <strong>zero architectural integrity in the ground it stands on.</strong></p><p style="text-align: justify;">An autonomous agent is exactly as smart, and exactly as safe, as the data layer beneath it. Giving AI agents more autonomy without giving them a grounded, governed, deliberately-owned foundation does not add features. It simply scales risk.</p><p style="text-align: justify;"></p><h2 style="text-align: justify;"><strong>The foundation is inverted</strong></h2><p style="text-align: justify;">The uncomfortable part is that the whole industry is now building top-down. Agent first because the CEO wants agents. Autonomy first because we have to have autonomous agents. Organizations prioritize the agent layer because autonomy is the strategic mandate, while treating the underlying data and integration layer as a secondary detail to be resolved later.</p><p style="text-align: justify;"><strong>We are building the systems that act before securing and locking the environments they act upon.</strong></p><p style="text-align: justify;">Defining that foundation and engineering it so that no single user interaction can quietly shift the ground beneath an active agent is complex. It requires explicit <strong>data contracts, dependency mapping, and rigid state management</strong>. This is the actual engineering challenge of the AI era, and it is exactly what I will break down in the next article.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.com/@onagenticcrm/note/p-202940876&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.com/@onagenticcrm/note/p-202940876"><span>Leave a comment</span></a></p><p style="text-align: justify;"></p><p style="text-align: justify;"></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.onagenticcrm.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Jakub Skalbania! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Agentforce ARR up 205% and Gartner says 40% of enterprises will pull their agents back by 2027]]></title><description><![CDATA[The hype meets the reality. The state of the Agentic Enterprise in May 2026]]></description><link>https://www.onagenticcrm.com/p/agentforce-arr-up-205-and-gartner</link><guid isPermaLink="false">https://www.onagenticcrm.com/p/agentforce-arr-up-205-and-gartner</guid><dc:creator><![CDATA[Jakub Skałbania]]></dc:creator><pubDate>Sun, 07 Jun 2026 20:04:27 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!E_WP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ff69ebf-a77b-431e-b169-b435678d3a81_988x321.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p style="text-align: justify;">May 2026 was a month of contradictory signals in the world of Agentic AI. Adoption metrics are breaking records, yet analysts now predict that <strong>40% of the enterprises which deployed agents to production will demote or decommission them by 2027<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a></strong>. Both are true at once, and the gap between them is an interesting story.</p><p style="text-align: justify;">On May 26, Gartner predicted that by 2027, 40% of enterprises will demote or decommission autonomous AI agents - not because the agents don&#8217;t work, but because of governance gaps discovered <em>after</em> a production incident. On May 27, Salesforce reported a genuinely strong quarter: <strong>Agentforce ARR is up 205% year over year.</strong> Despite this, <strong>its stock is down 30% year to date.</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!E_WP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ff69ebf-a77b-431e-b169-b435678d3a81_988x321.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!E_WP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ff69ebf-a77b-431e-b169-b435678d3a81_988x321.png 424w, https://substackcdn.com/image/fetch/$s_!E_WP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ff69ebf-a77b-431e-b169-b435678d3a81_988x321.png 848w, https://substackcdn.com/image/fetch/$s_!E_WP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ff69ebf-a77b-431e-b169-b435678d3a81_988x321.png 1272w, https://substackcdn.com/image/fetch/$s_!E_WP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ff69ebf-a77b-431e-b169-b435678d3a81_988x321.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!E_WP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ff69ebf-a77b-431e-b169-b435678d3a81_988x321.png" width="988" height="321" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5ff69ebf-a77b-431e-b169-b435678d3a81_988x321.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:321,&quot;width&quot;:988,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:56746,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://onagenticcrm.substack.com/i/201048696?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ff69ebf-a77b-431e-b169-b435678d3a81_988x321.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!E_WP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ff69ebf-a77b-431e-b169-b435678d3a81_988x321.png 424w, https://substackcdn.com/image/fetch/$s_!E_WP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ff69ebf-a77b-431e-b169-b435678d3a81_988x321.png 848w, https://substackcdn.com/image/fetch/$s_!E_WP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ff69ebf-a77b-431e-b169-b435678d3a81_988x321.png 1272w, https://substackcdn.com/image/fetch/$s_!E_WP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ff69ebf-a77b-431e-b169-b435678d3a81_988x321.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Salesforce (CRM) stock price in 2026</figcaption></figure></div><p style="text-align: justify;">That is the agentic enterprise in May 2026, in one frame.</p><h2 style="text-align: justify;"><strong>The money is real now, and so is the doubt about pricing models</strong></h2><p style="text-align: justify;">For most of the last eighteen months, the agentic market ran on projections. May was the month the numbers got large enough that the debate stopped being abstract. Salesforce closed Q1 FY27 with Agentforce ARR at $1.2 billion, up 205% year over year. Combined AI and Data ARR reached nearly $3.4 billion (worth noting: that figure includes roughly $1.1 billion of Informatica Cloud ARR, so it is not all &#8220;agentic&#8221;). The company reported 3.8 billion Agentic Work Units delivered to date, up 111% quarter over quarter, and more than 28.6 trillion tokens processed, up 152% quarter over quarter. <strong>More than half of Agentforce and Data 360 bookings came from existing customers</strong>. It means expansion inside the installed base, not new logos.</p><p style="text-align: justify;">And yet, just before the earnings, Bank of America reinstated coverage at <strong>Underperform with a $160 target</strong>, well below the ~$268 Street consensus, and named the structural fear out loud, calling it an &#8220;<strong>AI-driven structural reset.</strong>&#8220; Salesforce built a $30-billion-plus business selling one seat per human. If agents do some of that human work, the seat model shrinks.\</p><p style="text-align: justify;">This is the central tension of the agentic enterprise in 2026, and it is no longer theoretical. The companies selling agents are watching their own pricing model get questioned in real time. Salesforce&#8217;s response is to run three pricing models simultaneously:</p><ul><li><p>per conversation</p></li><li><p>per action via Flex Credits</p></li><li><p>per-user under the Agentic Enterprise License, plus the new Agentic Work Unit metric.</p></li></ul><p style="text-align: justify;">That&#8217;s a similar story to what I described in my previous article (&#8220;<a href="https://onagenticcrm.substack.com/p/microsofts-358-problem-with-copilot">Microsoft&#8217;s 35.8% problem with Copilot is a category problem</a>&#8221;) and what happens at Microsoft - trying to monetize the right model for work being done by agents.</p><p style="text-align: justify;">Apparently, <strong>the market has not yet settled on how to procure agentic outcomes</strong>. Vendors are forcing customers to self-select, allowing us to watch the transition from deterministic software seats to probabilistic compute consumption play out live. (important note: a meaningful share of what vendors now report as &#8220;agentic&#8221; usage <strong>was running under different product names before the agentic relabeling</strong>. Gartner&#8217;s own term for the broader pattern is &#8220;agent washing.&#8221; The Salesforce numbers are real ARR, but the year-over-year comparisons sit on top of a category that has been redefined while it grew).</p><h2 style="text-align: justify;"><strong>Governance stopped being a slide and became an operating problem</strong></h2><p style="text-align: justify;">The most important number in May wasn&#8217;t financial. It was the above mentioned Gartner&#8217;s number about <strong>40% of enterprises projected to demote or decommission autonomous agents by 2027</strong>, because of governance gaps found after an incident.</p><p style="text-align: justify;">What makes the framing sharp is why Gartner says agents fail. Not because governance is absent, but because it&#8217;s applied uniformly. Treating every agent as either locked down or fully trusted produces two failure modes: over-restrict the simple agents and <strong>you slow delivery and push teams into shadow deployments.</strong> Under-restrict the autonomous ones and <strong>you discover the access scope was wrong only after the agent has already acted.</strong> Gartner&#8217;s distinction is between an agent&#8217;s <em>ability to act</em> and the <em>scope of access</em> it was granted. Most enterprises aren&#8217;t separating the two.</p><p style="text-align: justify;">The supporting data from this year is bracing. </p><blockquote><p style="text-align: justify;"><strong>A Cloud Security Alliance study (published April 21) found 65% of organizations had at least one cybersecurity incident in the past year caused by an AI agent</strong><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>. </p></blockquote><p style="text-align: justify;">A separate CSA study with Zenity found <strong>53%</strong> had agents exceed their intended permissions and <strong>47%</strong> experienced an agent-related security incident. Across these surveys the recurring theme is identical: the risk is not the model hallucinating. </p><p style="text-align: justify;"><strong>The risk is the agent being </strong><em><strong>too good</strong></em><strong> at executing something it should never have been permitted to do</strong>, gaining write access it was never scoped for, taking actions nobody authorized.</p><p style="text-align: justify;">If you&#8217;ve read my previous articles, you know this is the argument I keep returning to: <strong>in production, governance is not a legal document, it&#8217;s a permission model expressed in code.</strong> May was the month the analyst forecasts and the breach data caught up to it.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.onagenticcrm.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Jakub Skalbania! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2 style="text-align: justify;"><strong>Microsoft moved the architecture ceiling just before Build</strong></h2><p style="text-align: justify;">While the market focused on the June 2 Build keynote, the most consequential news for enterprise agent builders actually shipped in May. On May 13, <strong>computer-using agents reached general availability</strong> in Copilot Studio, rolled out across all commercial Power Platform geographies (sovereign clouds excluded). These are agents that operate websites and desktop software through the UI rather than through APIs. That matters more than it sounds, because most enterprise software does not expose a documented API for the operations employees actually do all day. The GA build added secure credential management (Azure Key Vault), model choice across OpenAI and Anthropic, Purview audit logging, configurable human-in-the-loop review, and the ability to embed these agents directly into multi-step workflows.</p><p style="text-align: justify;">When combined with April&#8217;s Work IQ intelligence layer, which provides organizational memory and enables Agent-to-Agent (A2A) communication, Microsoft&#8217;s direction is clear. The company is packaging the grounding, Dataverse integration, and coordination plumbing into a managed surface. <strong>Context reasoning and agent delegation are becoming native Microsoft-operated layers, eliminating the need for teams to stitch together custom cognitive architectures.</strong></p><h2 style="text-align: justify;"><strong>Salesforce pushed agents into the back office</strong></h2><p style="text-align: justify;">The other notable platform move came at the end of April and shaped the May conversation: <strong>A</strong>gentforce Operations went generally available on April 29, built on the platform built by Regrello acquired by Salesforce and aimed at back-office bottlenecks, ie. process coordination, data verification, compliance clearing, approval chasing, rather than the front-office customer interactions where agentic CRM started.</p><p style="text-align: justify;">This aligns with the migration path we have tracked for months. The first wave of agentic CRM focused on sales and service copilots. The second wave is everything behind them: the unglamorous operational tasks where work actually stalls. By framing this as the &#8220;agentic enterprise,&#8221; <strong>Salesforce is acknowledging a core truth: the durable ROI of AI is not a smarter chatbot, but the total redesign of the underlying business processes.</strong></p><h2 style="text-align: justify;"><strong>What it adds up to</strong></h2><p style="text-align: justify;">May 2026 was the month the agentic enterprise stopped being a forecast and became a balance sheet, with all the scrutiny that brings.</p><p style="text-align: justify;">The revenue is becoming real. The pricing model is genuinely unsettled, and the market is pricing in that uncertainty. The platforms keep raising the architectural ceiling: computer use at GA, managed grounding and agent-to-agent coordination, back-office process automation. Simultaneously, the governance reckoning is here. Unexamined access scopes are leading to real-world breaches, guaranteeing that a significant percentage of today&#8217;s agents will be pulled offline by 2027.</p><p style="text-align: justify;">The dividing line between the AI agents that survive their first security incident and those that are quietly decommissioned remains exactly what it has always been: whether the engineering team defined the boundaries in code before the agent went live, or waited to discover them after something broke.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.onagenticcrm.com/p/agentforce-arr-up-205-and-gartner?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Share this article if you find it valuable.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.onagenticcrm.com/p/agentforce-arr-up-205-and-gartner?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.onagenticcrm.com/p/agentforce-arr-up-205-and-gartner?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>&#8220;<em>Gartner Says Applying Uniform Governance Across AI Agents Will Lead to Enterprise AI Agent Failure&#8221;</em>, Gartner, May 2026<strong>, </strong><a href="https://www.gartner.com/en/newsroom/press-releases/2026-05-26-gartner-says-applying-uniform-governance-across-ai-agents-will-lead-to-enterprise-ai-agent-failure">https://www.gartner.com/en/newsroom/press-releases/2026-05-26-gartner-says-applying-uniform-governance-across-ai-agents-will-lead-to-enterprise-ai-agent-failure</a></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>&#8220;<em>New Cloud Security Alliance Survey Reveals 82% of Enterprises Have Unknown AI Agents in Their Environments&#8221;</em>, Cloud Security Alliance, April 2026, <a href="https://cloudsecurityalliance.org/press-releases/2026/04/21/new-cloud-security-alliance-survey-reveals-82-of-enterprises-have-unknown-ai-agents-in-their-environments">https://cloudsecurityalliance.org/press-releases/2026/04/21/new-cloud-security-alliance-survey-reveals-82-of-enterprises-have-unknown-ai-agents-in-their-environments</a></p></div></div>]]></content:encoded></item><item><title><![CDATA[Five engineering competencies that separate a production AI agent from a demo]]></title><description><![CDATA[Notes from shipping AI agents into live environments, not slide decks.]]></description><link>https://www.onagenticcrm.com/p/five-engineering-competencies-that</link><guid isPermaLink="false">https://www.onagenticcrm.com/p/five-engineering-competencies-that</guid><dc:creator><![CDATA[Jakub Skałbania]]></dc:creator><pubDate>Sun, 31 May 2026 13:06:59 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-SKD!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2519ff6d-53ea-4514-bb9b-023696a35648_400x400.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p style="text-align: justify;">Last week I posted on LinkedIn that most of what is being sold to enterprises as &#8220;agentic AI&#8221; right now is a drag-and-drop canvas with an LLM dropped into one of the steps - a workflow in an agentic costume. Sierra reached a $15.8 billion valuation, Decagon reached $4.5 billion. Lindy and Gumloop are also competing on the depth of their connector libraries. The bigger the library and the smoother the canvas, the bigger the financing round. It&#8217;s RPA 2.0, or automation pretending to be agentic AI.</p><p style="text-align: justify;">The diagnosis is the easy part but the harder question, and the one that I try to address in this article, is what actually engineering a real agent should look like and how it&#8217;s different from dragging and dropping steps on a beautiful canvas.</p><p style="text-align: justify;">Demo works, pilot works&#8230; production doesn&#8217;t. The post-mortem usually ends with the word &#8220;hallucination.&#8221; That word does a lot of unhelpful work, because it makes the failure sound like it was the fault of LLMs. In reality, it is the lack of LLMs in the right places and missing engineering decisions.</p><p style="text-align: justify;">That is the topic of this post - the engineering decisions nobody is making, and why the easy drag and drop &#8220;agentic&#8221; platforms are not going to make them for you.</p><h2 style="text-align: justify;"><strong>The democratization that nobody warns about</strong></h2><p style="text-align: justify;">In 2019 I wrote an article about risks of AI democratization titled <em>&#8220;Why are progressing AI democratization and data-first approach not necessarily good things?&#8221;</em> (<a href="https://medium.com/data-science/why-are-progressing-ai-democratization-and-data-first-approach-not-necessarily-good-things-50220607c453">https://medium.com/data-science/why-are-progressing-ai-democratization-and-data-first-approach-not-necessarily-good-things-50220607c453</a>). At that time we were not even talking about Generative AI and its risks&#8230;</p><p style="text-align: justify;">And today, the situation with democratization is even stranger - Microsoft Copilot Studio shipped voice agents last year, Salesforce Agentforce 3 is in market, ServiceNow finished its Knowledge 2026 conference in May 2026 telling its audience that every Now Assist workflow is an agent now, HubSpot ships Breeze, SAP ships Joule, Workday ships Illuminate.</p><p style="text-align: justify;"><strong>The barrier to assembling an agent has fallen through the floor. </strong>That is good news but it also is the source of the trap.</p><p style="text-align: justify;">However, it&#8217;s worth pointing out that <strong>what got democratized is the assembly layer. </strong></p><blockquote><p style="text-align: center;"><strong>The architecture, the governance, the evaluation, the production engineering - none of that got democratized.</strong></p></blockquote><p style="text-align: justify;">That work still has to be done by humans who understand how a language model actually breaks, what a tool call&#8217;s failure modes are, and what &#8220;permissioned&#8221; means when an autonomous process is acting in your CRM at 3am without your involvement.</p><p style="text-align: justify;">When the assembly is easy and the engineering is hard, you get a market saturated with people who can configure an agent and a real shortage of people who can engineer one.</p><p style="text-align: justify;">That gap is the single most expensive mistake I am watching enterprises make this year.</p><h2 style="text-align: justify;"><strong>The work that didn&#8217;t get democratized</strong></h2><p style="text-align: justify;">The agent platform vendors will keep making assembly easier. Copilot Studio will keep adding orchestration primitives, Agentforce will keep adding workflow types, and startups like Sierra will keep raising.</p><blockquote><p style="text-align: center;"><strong>The bottleneck is the gap between people who can assemble an agent and people who can engineer one. It determines who ships and who pauses.</strong></p></blockquote><p style="text-align: justify;">It determines which Microsoft and Salesforce partners actually deliver enterprise value and which ones generate beautiful slideware. And it determines, in our own market, which Dynamics 365 implementations move from &#8220;<strong>Copilot-enabled</strong>&#8221; to &#8220;<strong>agent-mediated</strong>&#8221;, which is the move every executive reading this should be planning for.</p><p style="text-align: justify;">The platform is necessary but it&#8217;s the discipline that is often missing. Most teams will keep buying platforms and skipping the discipline, because the platform is what gets sold and the discipline is what needs to get done quietly and it&#8217;s not sexy.</p><p style="text-align: justify;"></p><h2 style="text-align: justify;"><strong>Five engineering competencies that are needed to build an AI agent</strong></h2><p style="text-align: justify;">I have been arguing this for months - what separates the partner who ships a production agent from the partner who ships a brilliant demo is not the model, not the platform, and not the prompt. It is <strong>five concrete engineering competencies that have to be present in the building team:</strong></p><h3 style="text-align: justify;">1. Fundamentals</h3><p style="text-align: justify;">Fundamentals include knowing what an autoregressive model actually does, what context rot looks like in a 200k-token window, what the difference between a hallucination born of insufficient retrieval and one born of conflicting tool outputs is. Also, knowing which reasoning pattern (eg. ReAct, plan-and-execute, reflection) your workflow actually needs. Without this, every architectural decision downstream is cargo cult.</p><h3 style="text-align: justify;">2. Architectural choices</h3><p style="text-align: justify;">Anthropic&#8217;s December 2024 essay <em>&#8220;Building Effective Agents&#8221;</em> is the best piece of writing in the field on this point and remains required reading. Its central, unfashionable claim is that in the large majority of cases<strong>, a single well-tooled agent beats a multi-agent system.</strong> Most enterprise AI architecture decks I see right now assume the opposite. Consultants draw seven boxes connected by arrows because seven boxes look serious. And those seven boxes are usually seven failure modes you have not thought about yet.</p><h3 style="text-align: justify;">3. Governance and safety</h3><p style="text-align: justify;">Permission models that follow least-privilege for the agent&#8217;s tool surface. Human-in-the-loop checkpoints at the points where the agent&#8217;s actions become irreversible. Audit trails that are forensic, not decorative. Rate limits, cost limits, and a kill switch that someone actually knows how to use. This is the single biggest gap in every enterprise project I have reviewed this year. Most teams think governance is something the legal team writes. In a production agent system, governance is code.</p><h3 style="text-align: justify;">4. Understanding evals and eval-driven development</h3><p style="text-align: justify;">Hamel Husain has done more than anyone to make this its own discipline, and his insistence that you cannot improve what you do not measure is the right insistence. Real evals for real and useful AI agents are hard and they might require:</p><ul><li><p>golden datasets</p></li><li><p>LLM-as-judge with calibrated rubrics</p></li><li><p>regression tests on every prompt change</p></li><li><p>A/B in production with <strong>task success</strong>, <strong>cost per task</strong>, <strong>human-intervention rate</strong> as three most important metrics</p></li></ul><p>Without this you are building in the dark and shipping by vibes. Ask any &#8220;agent builder&#8221; in a random enterprise and you&#8217;ll be surprised that they don&#8217;t even know what these things are. The fact is that most enterprises right now are shipping by vibes.</p><h3>5. Production engineering</h3><p style="text-align: justify;">Apart from proper CI/CD for agent deployment there are also tasks needed where an agent is ahead in production. These are hard tasks that very few current agent builders have a clue about:</p><ul><li><p style="text-align: justify;"><strong>idempotency</strong> on every tool call that mutates state</p></li><li><p style="text-align: justify;"><strong>retry logic</strong> that distinguishes a transient failure from a logically failed step</p></li><li><p style="text-align: justify;"><strong>state persistence</strong> and checkpointing so that an agent run can resume rather than restart</p></li><li><p style="text-align: justify;"><strong>observability</strong> through Langfuse, LangSmith, Arize, or whatever your stack chooses, but observability that actually answers the question &#8220;What was in the agent&#8217;s context when it made that decision?&#8221;</p></li></ul><p style="text-align: justify;">This is the boring layer that determines whether your agent survives its first incident and will be useful in production or it will end up as a nice demo for the board.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.onagenticcrm.com/p/five-engineering-competencies-that?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Jakub Skalbania! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.onagenticcrm.com/p/five-engineering-competencies-that?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.onagenticcrm.com/p/five-engineering-competencies-that?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><h2 style="text-align: justify;">A word on protocols</h2><p style="text-align: justify;">The five competencies above assume a stack where tool calls, memory, and agent-to-agent handoffs can actually be made to work in production. That stack is finally getting standards. MCP, Anthropic&#8217;s <strong>Model Context Protocol</strong>, has reached critical mass as the interop layer between agents and the tools, data sources, and resources they need to act. Microsoft shipped MCP support across many products and platforms last year. Google&#8217;s A2A (<strong>Agent2Agent</strong>) is the emerging protocol for agent-to-agent coordination.</p><p style="text-align: justify;">This matters more than it sounds. It is the difference between an agent locked into one vendor&#8217;s connector library and an agent that can speak to your whole stack without a separate integration each time. It is the difference between a multi-agent system whose handoffs you have to invent and one whose handoffs follow a protocol your governance team can audit.</p><h2 style="text-align: justify;">The real life cases</h2><p style="text-align: justify;">We have been in intelligent automation for a long time, mostly working within the CRM space, where automation touches either customers directly or processes involved in how companies manage their customers. In 2023 one of our projects (a natural language bot for insurance) was selected by Microsoft as one of the most transformational globally and was featured at their conferences and on Microsoft product websites. </p><p style="text-align: justify;">We do not ship intelligent automations, bots and AI agents because the platform let us. <strong>We ship them because we ran the five competencies listed above for months before our agents touch any process.</strong></p><p style="text-align: justify;">In our work we also learnt the following lessons:</p><ol><li><p><strong>Governance is harder than the model</strong>. Building the permission model so that the agent could not touch records the user or customer was not entitled to was the longest single piece of work in the project, and the most consequential.</p></li><li><p><strong>Evals are what made improvement compound</strong>. Every prompt change ran against a golden set before it merged.</p></li><li><p>The architecture starts single-agent on purpose. We tested a multi-agent version and watched coordination overhead consume the latency budget. We ship <strong>the simplest architectures possible</strong> in terms of governance, multi-agency and observability.</p></li></ol><h2>Conclusion and suggestions</h2><p style="text-align: justify;">So when your board asks where the AI agents are, and which platform you're buying, point them to a better question: </p><p style="text-align: justify;"><strong>"Who on this team can engineer an agent, not just assemble one?"</strong> </p><p style="text-align: justify;">The discipline is the part that gets skipped, because it's quiet, unglamorous, and invisible on a slide. That's exactly why it's the new moat. The teams closing the gap between assembling an agent and engineering one aren't waiting for a better canvas. They're doing the unglamorous work behind the UI that the SaaS &#8220;agentic&#8221; platforms will never do for them.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.onagenticcrm.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Jakub Skalbania! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Microsoft’s 35.8% problem with Copilot is a category problem]]></title><description><![CDATA[Why paid Copilot stalled at 4.4% of the M365 base and what every CIO running Salesforce, ServiceNow, Oracle, SAP, or Workday should do about it.]]></description><link>https://www.onagenticcrm.com/p/microsofts-358-problem-with-copilot</link><guid isPermaLink="false">https://www.onagenticcrm.com/p/microsofts-358-problem-with-copilot</guid><dc:creator><![CDATA[Jakub Skałbania]]></dc:creator><pubDate>Sun, 17 May 2026 13:55:57 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-SKD!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2519ff6d-53ea-4514-bb9b-023696a35648_400x400.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p style="text-align: justify;">On May 5, Tom Warren from The Verge posted on X what every Microsoft customer was already thinking but wouldn&#8217;t say: </p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://x.com/tomwarren/status/2051776985844601159&quot;,&quot;full_text&quot;:&quot;sounds like Copilot is gonna be removed from a bunch of places at Microsoft, because it&#8217;s fair to say it hasn&#8217;t lived up to its promise in many areas https://t.co/tO1qfxX7Lw&quot;,&quot;username&quot;:&quot;tomwarren&quot;,&quot;name&quot;:&quot;Tom Warren&quot;,&quot;profile_image_url&quot;:&quot;https://pbs.substack.com/profile_images/1601147760673267712/pGbRSFcP_normal.jpg&quot;,&quot;date&quot;:&quot;2026-05-05T21:32:08.000Z&quot;,&quot;photos&quot;:[],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:18,&quot;retweet_count&quot;:20,&quot;like_count&quot;:432,&quot;impression_count&quot;:30155,&quot;expanded_url&quot;:null,&quot;video_url&quot;:null,&quot;video_preview_media_key&quot;:null,&quot;belowTheFold&quot;:false}" data-component-name="Twitter2ToDOM"></div><p style="text-align: justify;">Tom was reacting to a deleted post by Jacob Andreou, Microsoft&#8217;s new EVP of Copilot. The wider context: Windows and Apps teams (Notepad, Snipping Tool) had quietly stripped Copilot branding from Windows 11 a few weeks earlier. </p><p style="text-align: justify;">Also, a few days earlier, Satya Nadella mentioned that &#8220;<em>the seat-based pricing is just entitlement to some consumption</em>&#8221;.</p><p style="text-align: justify;">It might look like Microsoft&#8217;s AI bet is wobbling.</p><p style="text-align: justify;">However, the correct reading is probably that Microsoft is the first enterprise software vendor-turned-hyperscaler publicly admitting that prompt-as-a-product has a structural ceiling and that the next phase of enterprise AI value will not be unlocked by Copilot in every product, but by <strong>agents inside every process</strong>.</p><h2><strong>The AI adoption numbers that should be on every executive dashboard in 2026 Q2</strong></h2><ol><li><p style="text-align: justify;">Microsoft now has over <strong>20 million paid Microsoft 365 Copilot seats</strong>, and that would sound fantastic if not the fact that over <strong>450 million people use Microsoft M365 every month</strong>. That means that only 4.4% of them use paid Copilot. Three years after huge launch and tens of billions of capex spent, fewer than 1/20 Microsoft 365 commercial users pays for Copilot.</p><p></p></li><li><p style="text-align: justify;">According to Recon Analytics' survey of 150,000+ U.S. respondents published in the report titled &#8220;<em>AI Choice 2026: Why Licenses Don&#8217;t Equal Adoption</em>&#8221;<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a> Microsoft Copilot's workplace <strong>conversion rate stands at just 35.8%</strong>, while <strong>ChatGPT converts at 83.1% workplace usage</strong>. Gemini is at 34%. A 47-point gap, so whatever is going wrong did not happen in the model layer.</p><p></p></li><li><p style="text-align: justify;">Of users who tried Copilot and stopped, <strong>44.2% cite distrust of Copilot&#8217;s answers</strong> as the primary reason - higher than ChatGPT (40.6%) or Gemini (42.8%). Recon&#8217;s accuracy NPS for Copilot deteriorated from &#8722;3.5 in July 2025 to &#8722;24.1 in September, recovering only partially to &#8722;19.8 in January 2026.</p><p></p></li></ol><p style="text-align: justify;">So, the natural question is why is M365 Copilot so poorly perceived, considering it&#8217;s essentially ChatGPT (OpenAI&#8217;s models) integrated into an enterprise product? It&#8217;s the same model but there is huge difference - ChatGPT is used by knowledge workers on a blank page where intent is declared in natural language. Microsoft Copilot meets that same worker in every possible place and every possible app, from a SharePoint site built in 2008, an Excel file with seven hidden tabs, in a Word document with suggestion to sum up a document not yet written, to a CRM form designed in 2013.</p><p style="text-align: justify;">I took part in two workshops in April for clients who planned to resign from Copilot (several hundred users each), quoting &#8220;lack of usability&#8221; as the main reason. We ran a series of meetings during which we showed what Copilot Cowork can do and how Copilot custom agents could be embedded into processes, rather than forcing users to go to Copilot chat windows. It worked. The customers stayed and engaged us in further process redesign to increase Microsoft Copilot adoption. <strong>It&#8217;s twelve months after they bought hundreds of licenses from a &#8220;licensing partner&#8221; disguised as an &#8220;AI company&#8221;</strong>, during agreement renewal. A bit late.</p><h2><strong>The 35.8% problem is a category problem, not a Microsoft problem</strong></h2><p style="text-align: justify;">It is a process problem masquerading as a Microsoft problem. Salesforce has the same problem, ServiceNow has it too. So does HubSpot, Oracle, SAP and Workday - you name them. Every system-of-record vendor is now <strong>shipping agents over data models designed before the agents existed</strong>. They and their customers will quickly discover that the agent&#8217;s adoption ceiling is set by the data model and the business workflow, not by the LLM.</p><p style="text-align: justify;">Klarna learned the dark version of this lesson the expensive way in May 2025, when its CEO, Sebastian Siemi&#261;tkowski, publicly walked back the full AI customer-service replacement and started hiring humans back: &#8220;<em>investing in the quality of human support is the way of the future for us.</em>&#8221; The lesson is not that AI failed. </p><div class="callout-block" data-callout="true"><p style="text-align: justify;"><strong>The lesson is that AI cannot rescue a process that was never redesigned for it.</strong></p></div><p style="text-align: justify;">Companies that will win value from agentic AI in the next 24 months are the ones that <strong>stop treating AI as a feature and start treating it as a forcing function for redesign</strong>. The ones that don&#8217;t will be running M365 Copilot pilots, wondering why their 35.8% never moved.</p><h2><strong>Why no amount of prompt engineering will close the 47-point gap</strong></h2><p style="text-align: justify;">Here is the thing nobody wants to say out loud at AI conferences:</p><p style="text-align: center;"><strong>enterprise work is not prompt-shaped - it is process-shaped.</strong></p><p style="text-align: justify;">A typical B2B seller does not want to ask questions in a chat window - he/she has a 16-step renewal workflow embedded in a CRM and spanning through Teams and SharePoint lists.</p><p style="text-align: justify;">A claims adjuster does not have a question - he/she has a regulator-defined sequence with mandatory legal capture and a hard SLA.</p><p style="text-align: justify;">A contact-center agent does not have a question/response need - he/she has a script, a compliance checkpoint, and a quality scorecard.</p><p style="text-align: justify;">The blank page that makes ChatGPT magical for individuals is exactly what makes Copilot frustrating for enterprise users.</p><p>For an agent to create value at work, several things have to be true at once:</p><ul><li><p>An intent must be <strong>declarable in natural language</strong> by a human or another agent</p></li><li><p>The agent needs a <strong>permissions-aware environment</strong> because it must act in the system of record, with the right scope, on behalf of the right identity</p></li><li><p>There has to be a <strong>deterministic backbone</strong> behind the stochastic narrative</p></li></ul><p style="text-align: justify;">This is exactly the architecture that vendors must start converging on. At TrailblazerDX (TDX) 2026 in April, Salesforce open-sourced <strong>Agent Script</strong>, an agent definition language built as Madhav Thattai, COO of Salesforce AI, had explained - precisely because LLM reasoning wavers as workflows get more complex (an interview at Salesforce Ben from January 2026 titled &#8220;<em>Is Salesforce Losing Confidence in LLMs?</em>&#8221;) <a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a></p><p style="text-align: justify;">Decagon ships the same idea under the label <strong>Agent Operating Procedures.</strong> </p><p style="text-align: justify;">The pattern across both: <strong>LLMs handle communication and intent; deterministic code handles execution and guardrails</strong>.</p><h2 style="text-align: justify;">Working with AI is a different shape of work</h2><p style="text-align: justify;">Capturing voice straight into Dataverse or Salesforce CRM instead of asking a seller to open a form is not a feature - it is a different shape of work. Microsoft&#8217;s latest natural voice features, including <strong>Hands&#8209;free note capture</strong> in the Sales agent in Outlook mobile might be the first official acknowledgment from Redmond that the form itself is the bottleneck.</p><p style="text-align: justify;">The customers who insist on preserving the existing form of work will get a beautiful demo and a stalled rollout. The difference between a pilot that converts and one that dies is almost never the model. <strong>It is whether the customer was willing to redesign the underlying process.</strong></p><p style="text-align: justify;">Sangeet Paul Choudary made the architectural point cleaner than I can in his February 2026 HBR article<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a>: </p><blockquote><p style="text-align: justify;">&#8220;<em>AI&#8217;s greatest economic impact will come not from automating tasks but from dramatically lowering the &#8216;translation&#8217; costs that keep teams, tools, and data from working together.</em>&#8221; </p></blockquote><p style="text-align: justify;">In an AI-adopting company, the person is the node and AI is the tool. In an AI-native company, the system itself is the node, and work gets redistributed to wherever intelligence, human or artificial, is more effective.</p><p>Sarah Wang at a16z, in Big Ideas 2026<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a>, calls the same shift the moment:</p><blockquote><p>&#8220;<em>the traditional system of record slips into the background as a commodity persistence tier &#8212; its strategic leverage ceded to whoever controls the intelligent execution environment employees actually use.</em>&#8221;</p></blockquote><h2>Microsoft is reorganizing to better align with industry needs (and to catch up?)</h2><p style="text-align: justify;">On March 17, Mustafa Suleyman moved off day-to-day Copilot product leadership to focus on what Microsoft now labels &#8220;Superintelligence.&#8221; Jacob Andreou, formerly SVP at Snap, then CVP of Product and Growth at Microsoft AI, was promoted to EVP of Copilot, reporting directly to Satya Nadella.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-5" href="#footnote-5" target="_self">5</a></p><p style="text-align: justify;">Exactly two weeks later, on March 31, Mary Jo Foley wrote her GeekWire post, &#8220;<a href="https://www.geekwire.com/2026/mary-jo-foley-what-the-heck-is-going-on-with-microsoft-lately/">What the heck is going on with Microsoft lately?</a>&#8221;, which was a polite way of asking the question everybody from the industry was already asking.</p><p>Then, on April 27 the Microsoft / OpenAI agreement was restructured:</p><ul><li><p>non-exclusive license through 2032, AGI clause removed</p></li><li><p>OpenAI free to ship in any cloud, Microsoft&#8217;s revenue share to OpenAI ended</p></li><li><p>OpenAI&#8217;s share to Microsoft capped through 2030</p></li></ul><p>The default media quote is that Microsoft is &#8220;losing the AI race&#8221;. There's also a reading where this is retreat, not strategy. I think the strategic reading is closer to the truth, although both are partially true. I am in the camp that <strong>Microsoft is resetting the value model from Copilot in every app to agents in every process</strong>. And it is doing it in front of us on the living organism, after M365 Copilot adoption sucked billions and did not bring significant market penetration.</p><h2>The questions that we need to answer in 2026</h2><p>The HFS Research and Genpact study released the same day as Microsoft&#8217;s earnings call &#8222;<em>Autonomy Requires Trust in AI</em>&#8220;<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-6" href="#footnote-6" target="_self">6</a> found that 33% of respondents identify <strong>business processes not ready for agentic integration </strong>as the leading barrier to scaling agentic <strong>AI</strong>. So, process readiness, not data, not governance, not talent, is the number 1 obstacle.</p><p>The important questions that come to my mind:</p><ol><li><p><strong>Which 3 of your top 10 business processes will not exist in their current form in 24 months?</strong></p></li><li><p><strong>Where is your system of record investing - in better forms, or in agent-mediated intent capture?</strong></p></li><li><p><strong>Who is the owner of each process you want to extend with agentic AI?</strong></p><p></p></li></ol><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.onagenticcrm.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>&#8220;<em>AI Choice 2026: Why Licenses Don&#8217;t Equal Adoption</em>&#8221;, Recon Analytics, February 2026, <a href="https://www.reconanalytics.com/ai-choice-2026-why-licenses-dont-equal-adoption/">https://www.reconanalytics.com/ai-choice-2026-why-licenses-dont-equal-adoption/</a></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>&#8220;Is Salesforce Losing Confidence in LLMs?&#8221;, SF Ben, January 2026, <a href="https://www.salesforceben.com/is-salesforce-losing-confidence-in-llms/">https://www.salesforceben.com/is-salesforce-losing-confidence-in-llms/</a></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>&#8220;<em>AI&#8217;s Big Payoff Is Coordination, Not Automation</em>&#8221;, HBR, February 2026, <a href="https://hbr.org/2026/02/ais-big-payoff-is-coordination-not-automation">https://hbr.org/2026/02/ais-big-payoff-is-coordination-not-automation</a></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p>&#8220;<em>Big Ideas 2026: Part 1</em>&#8221;, a16z New Media, December 2025, <a href="https://www.a16z.news/p/big-ideas-2026-part-1">https://www.a16z.news/p/big-ideas-2026-part-1</a></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-5" href="#footnote-anchor-5" class="footnote-number" contenteditable="false" target="_self">5</a><div class="footnote-content"><p>&#8220;<em>Microsoft Reorganizes Copilot Team, Names Jacob Andreou EVP Reporting To CEO Nadella</em>&#8221;, CRN, March 2026, <a href="https://www.crn.com/news/ai/2026/microsoft-reorganizes-copilot-team-names-jacob-andreou-evp-reporting-to-ceo-nadella">https://www.crn.com/news/ai/2026/microsoft-reorganizes-copilot-team-names-jacob-andreou-evp-reporting-to-ceo-nadella</a></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-6" href="#footnote-anchor-6" class="footnote-number" contenteditable="false" target="_self">6</a><div class="footnote-content"><p>&#8220;<em>Autonomy requires trust in AI</em><strong>&#8221;, </strong>Genpact, April 2026, <a href="https://www.genpact.com/insight/autonomy-requires-trust-in-ai">https://www.genpact.com/insight/autonomy-requires-trust-in-ai</a></p></div></div>]]></content:encoded></item><item><title><![CDATA[Processes Before Prompts - why agentic CRM will be won on the process layer]]></title><description><![CDATA[Why agentic CRM lives or dies on process design. Field notes from Jakub Ska&#322;bania  CEO of Netwise, 16x Microsoft MVP.]]></description><link>https://www.onagenticcrm.com/p/processes-before-prompts-why-agentic</link><guid isPermaLink="false">https://www.onagenticcrm.com/p/processes-before-prompts-why-agentic</guid><dc:creator><![CDATA[Jakub Skałbania]]></dc:creator><pubDate>Thu, 07 May 2026 11:34:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-SKD!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2519ff6d-53ea-4514-bb9b-023696a35648_400x400.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p style="text-align: justify;">I have similar conversations once a week. A board member, a CEO, sometimes a CIO ask very similar question: &#8222;<em>Jakub, we need to do agentic AI. We&#8217;ve looked at three platforms. Which one would you recommend?</em>&#8221; And every time my answer disappoints them, because I don&#8217;t start with the platform, nor with a model. I ask them to tell me about the process the agent is supposed to automate.</p><p style="text-align: justify;">Eight times out of ten the answer is like, &#8220;<em>Well, we have different processes, what do you mean?</em>&#8220;</p><p style="text-align: justify;">That pause is where most agent projects die before they arrive - in the gap between what a company <em>thinks</em> its process is and what its process <em>actually</em> is.</p><p style="text-align: justify;">This is my first post on this Substack and the title is also the thesis. <strong>Processes Before Prompts.</strong> I&#8217;ve been saying it to clients for some time, when we started do help with intelligent automation and later with building agentic capabilities. Time to write it down because the decisions made over the next 12 months will determine whether your firms come out of the agentic era as what Microsoft calls <em><strong>Frontier Firms</strong></em> or as the next generation of cautionary case studies titled &#8220;<em>We tried AI, it didn&#8217;t work&#8221;</em>.</p><h2><strong>Important numbers about agentic AI</strong></h2><p style="text-align: justify;">According to MIT<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>, mid-2025: 95% of corporate generative-AI pilots produce no measurable P&amp;L impact.</p><p style="text-align: justify;">McKinsey&#8217;s &#8222;<em>The state of AI in 2025: Agents, innovation, and transformation&#8220;</em><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a> shows that 88% organizations report regular AI use in at least one business function and 39% report EBIT impact at the enterprise level, whilst only 6% of organizations qualify as &#8220;high performers&#8221; who see significant enterprise-wide value.</p><p style="text-align: justify;">BCG in their &#8220;<em>The Widening AI Value Gap</em>&#8221;<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a>: 60% companies are reaping hardly any material value, reporting minimal revenue and cost gains despite substantial investment.</p><p style="text-align: justify;">IBM&#8217;s CEO study &#8220;<em>Rewiring the C-suite: The fast track to 2030</em>&#8221;<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a>: 16% of AI initiatives have been scaled enterprise-wide and only 25% have delivered the expected ROI.</p><p style="text-align: justify;">Gartner forecasts that by the end of 2027, more than 40% of agentic AI projects will be cancelled, killed by escalating costs, unclear business value, and lack of risk controls.</p><p style="text-align: justify;">So, it looks like a pattern.</p><h2><strong>It is the same disease that was causing CRM failures</strong></h2><p style="text-align: justify;">Technology was never the bottleneck. Processes were.</p><p style="text-align: justify;">In 2026, we are about to make exactly the same mistake like many companies did with treating CRM systems as software, not strategy. They license a platform, contract a partner to &#8222;implement it&#8220;, instruct users to &#8220;use&#8220; the system, and 6 months later wonder why adoption is flat and the pipeline forecast is still being managed in Excels.</p><p style="text-align: justify;">This time, however, the <strong>mistake will be more expensive, faster and with dramatically higher consequences.</strong> Because an agentic CRM does not behave like a traditional CRM. A traditional CRM is a passive system of record - it lets you store data. An agentic CRM is a system of action, which executes actions on this data. And it executes whatever process it was handed. If you haven&#8217;t handed it one, it improvises off the mess.</p><p style="text-align: justify;">As Bill Gates once said, <strong>automation applied to an inefficient operation will magnify the inefficiency</strong>.</p><p style="text-align: justify;">The agentic enterprise, what Microsoft has rebranded as the <em><strong>Frontier Firm</strong></em>, is not a software upgrade. It is a deliberate and controlled re-design of a process.</p><h2><strong>Processes before prompts</strong></h2><p style="text-align: justify;"><strong>Processes Before Prompts</strong> means that before any company deploys an AI agent into production, three things have to happen and they have to be owned by the business and not by IT.</p><p style="text-align: justify;">The first is that the process has to be <strong>discovered</strong>, <strong>mapped</strong>, and <strong>named</strong>. Not the imagined process from the playbook, bu the actual process, observed in the data. Process-mining tools such as Celonis, Microsoft&#8217;s own Power Automate Process Mining, SAP Signavio exist because most companies do not know how their work actually flows. Wil van der Aalst, Chief Scientist at Celonis, ran a tutorial at the 28th European Conference on Artificial Intelligence 2025 titled &#8220;<em>No Enterprise AI Without Process Intelligence! Using Process Mining as the Lens to Address Performance and Compliance Problems&#8221;</em>. The argument is that an agent without process context is an autonomous actor in a building with no floor plan.</p><p style="text-align: justify;">The second is that the process <strong>must have a human owner </strong>with the authority and the budget to redesign it. Not a &#8220;champion&#8220; and not a &#8220;stakeholder&#8221; - an owner. McKinsey is clear on this, stating that of the 25 organisational attributes they tested, the one most strongly correlated with measurable EBIT impact from generative AI is <strong>workflow redesign</strong>. AI high performers are more than 3x more likely to fundamentally redesign work than the rest. Direct CEO involvement in AI governance is the second strongest variable. Implementing AI is not a technical project. It is a <strong>leadership project</strong>, and the one of the causes of failure is treating it as a technical one.</p><p style="text-align: justify;">The third is that the <strong>process must be instrumented for measurement before the agent is deployed</strong>. You cannot improve what you cannot see. You cannot trust an agent whose outputs you have nothing to compare to.</p><p style="text-align: justify;">Bill McDermott of ServiceNow opened his Knowledge 2026 keynote on Tuesday with a story about an AI agent hitting a credential error and deleting the entire production database in 9 seconds at one of the startups. McDermott's conclusion is concise: </p><blockquote><p style="text-align: justify;"><em>Governance isn't a feature, it's the whole ball game. Because without it, your whole company can come down.</em></p></blockquote><p style="text-align: justify;">Here we arrive at the three main pillars: discovery, ownership and telemetry.</p><h2><strong>Specifically about agentic CRM</strong></h2><p style="text-align: justify;">I run a firm that has been implementing enterprise CRM systems since 2008 and now builds agentic CRMs on the Microsoft stack. Our voice agent connected with MCP servers is already in the future - it can take meeting notes in natural voice, link opportunities to quotes, generate tasks based on meetings and customer overlook - all permission-aware, all anchored in the actual CRM record. We did not build that without first defining with the customer what a qualified opportunity means, where tasks are stored and who owns the conversion.</p><p style="text-align: justify;">Every week we educate our clients and potential clients that giving every salesperson an AI agent, when they are not even consistent when a specific sales stage should switch, is not a strategy. <strong>It is a delegation of strategy to chaos, potantially with a Microsoft Copilot or Salesforce Agentforce logos on top.</strong></p><p style="text-align: justify;">Building an agent is just new programming, a technical task. A fairly easy piece for experienced developers and AI practitioners. <strong>Aligning on the process and building a helpful agent is the hard piece.</strong></p><p style="text-align: justify;">Salesforce&#8217;s assessed agent performance honestly in their own paper from 2025. On their CRMArena-Pro benchmark frontier LLMs scored 58% on single-step CRM tasks and 35% on multi-step ones. <strong>35% on multi-step workflows is, as one analyst put it, a non-starter for enterprise.</strong> And that was in laboratory conditions without the technical debt of a real organization.</p><h2><strong>The European (and Polish) angle</strong></h2><p style="text-align: justify;">I am writing this from Warsaw and most of the leaders and our clients reading this run businesses across the world. The Polish and European context shows the urgency. According to Eurostat only 8,4% of Polish enterprises had adopted any form of AI in 2024. It is the third-lowest figure in the European Union. And yet the Polish edition of Microsoft&#8217;s Work Trend Index<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-5" href="#footnote-5" target="_self">5</a> reports that <strong>84% of Polish business leaders plan to deploy AI agents within the next 12 to 18 months, </strong>slightly above the global average. We are, in other words, about to leap from one of the lowest AI adoption rates in Europe to mass deployment of autonomous systems in 12 months, on top of companies that have not done the process work.</p><p style="text-align: justify;">Add the <strong>EU AI Act</strong>, whose enforcement against high-risk systems begins on 2026-08-02 and Article 22 of the <strong>GDPR</strong>, which already prohibits significant decisions taken solely by automated means without meaningful human oversight. Add the overlapping NIS2 obligations across regulated sectors. </p><p style="text-align: justify;">Companies that introduce agents on undocumented processes will probably spend 2027 <strong>paying lawyers what they should have spent in 2026 paying process designers</strong>.</p><h2><strong>What to do next?</strong></h2><p style="text-align: justify;">Stop implementing AI agents, because &#8220;everyone does that&#8221;. Instead, ask each business unit owner two questions:</p><ol><li><p style="text-align: justify;"><strong>In which of our processes do we want an agent to operate?</strong></p></li><li><p style="text-align: justify;"><strong>Can we describe that process in enough detail that a new hire could perform it on day one?</strong> </p></li></ol><p style="text-align: justify;">If the answer to the second question is no, you do not have a process.</p><p style="text-align: justify;">Designate a single accountable <strong>owner per process, not per agent</strong>. Agents will multiply, retire, and be replaced by better agents with better model next quarter. Processes are durable and their owners outlive tools. That is the lesson of twenty five years of my CRM history applied to the next decade of agentic history.</p><p style="text-align: justify;">Treat the AI Act not as a compliance enforcement but as a discipline-forcing one. Article 14, with its requirement for &#8220;human oversight&#8221; of high-risk systems, read correctly, is an instruction: <strong>know your process well enough to know where the human belongs in it</strong>. This could mean that companies that take this seriously will end up with better agentic AI than their American competitors whose board members pay for AI with their credit cards without proper process redesign first&#8230;</p><h2><strong>Conclusion</strong></h2><p>Microsoft&#8217;s 2026 Work Trend Index summarises the moment in a sentence I have already quoted at several boards: &#8220;<em>the workers are ready; their organisations are not&#8221;</em>. Jared Spataro, who runs Microsoft&#8217;s AI at Work efforts is right - the constraint on the agentic enterprise is no longer what the AI can do. It is <strong>how we have structured the work around it</strong>.</p><p>The companies that come through the next 18 months will not be the ones with the best prompts, or the most agents, or the largest token budgets. They will be the ones whose CEOs and COOs decided, before the rest of the market did, that the answer to the question &#8220;<em>which model should we pick?</em>&#8221; was always &#8220;<em>how does the process really work?</em>&#8221;.</p><p></p><p><strong>Processes Before Prompts.</strong> Welcome to my Substack. Subscribe if you&#8217;d like to argue.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.onagenticcrm.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p><em>The GenAI Divide: State of AI in Business 2025</em>,  July 2025.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p><em>The state of AI in 2025: Agents, innovation, and transformation</em>, https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai, November 2025</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p><em>The Widening AI Value Gap, </em>https://www.bcg.com/publications/2025/are-you-generating-value-from-ai-the-widening-gap, September 2025</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p><em>Rewiring the C-suite: The fast track to 2030</em>, https://www.ibm.com/thought-leadership/institute-business-value/en-us/c-suite-study/ceo</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-5" href="#footnote-anchor-5" class="footnote-number" contenteditable="false" target="_self">5</a><div class="footnote-content"><p><em>Work Trend Index,</em> https://www.microsoft.com/en-us/worklab/work-trend-index</p><p></p></div></div>]]></content:encoded></item></channel></rss>