How to read the index

Once a quarter this publication records what improved, what failed, and which operating beliefs the evidence changed. It is not a release recap. A launch belongs here only if it changes what a small business can safely hand to software, what it must keep, or how it should measure the result.

This quarter's answer is unusually concrete. The vendors shipped the operating model's missing parts—gates, connectors, schedules, and portable procedures—and the same quarter showed how quickly a product built from those parts can disappear.

What improved: the gate shipped by default

Browser agents crossed from pilot to product. Anthropic made its Chrome agent generally available on every paid plan on August 26, with published prompt-injection results and confirmation before publishing, purchasing, or sharing personal data. OpenAI's cloud browser asks before actions that could be hard to reverse or create a financial, legal, or account commitment. The confirmation step is no longer a setting an operator has to find; it is how the products arrive.

Small-business packaging arrived within a week. On September 15, Anthropic's small-business product added connectors for accounting, payroll, payments, and commerce systems and dozens of prebuilt routines that stage every send, post, or payment for the owner's approval, and the major CRM vendors pushed agents into their small-business suites at their September events. The vendor matters less than the pattern: draft-for-approval is what a small business now gets out of the box.

Prices fell and procedures became portable. OpenAI cut GPT-5.6 Luna's price by 80% on July 30, then launched GPT-6 Luna at roughly half that model's new price. Help desks now bill their AI agents per resolved conversation. And a procedure written once as an agent skill—an open format published in December—now loads in dozens of assistants and coding tools, which makes company method a file the business owns rather than a feature it rents.

What failed: continuity

The clearest failure was product continuity. OpenAI withdrew its general agent mode and scheduled its standalone agent browser to stop working on August 9, moving the work into its main apps about a year after launch. The capability did not disappear, but every procedure written around those products had to be rebuilt. Procedures written around the job did not.

Security stayed unsolved in exactly the way the vendors say it is. Anthropic writes that no browser agent is immune to prompt injection, and OpenAI calls the problem unlikely ever to be fully solved. Anthropic's September threat report described a campaign in which one compromised software provider exposed about 200 downstream customer organizations, and attackers stole AI API keys and ran fraudulent discount resellers to harvest more. A small business inherits that exposure through every connector it authorizes.

Customers kept their patience short. Gartner reported in August that 87% of customers say a company using generative AI for service must offer access to a human, and in September that only 27% would try a chatbot again after a bad experience. A bot that traps a customer is now measurably worse than no bot.

What the rules did

Disclosure advanced faster than any rule about autonomy. The EU AI Act's transparency duties took effect on August 2: people must be told when they are interacting with an AI system, and deepfakes must be labeled. A July amendment delayed the high-risk obligations, hiring tools among them, to December 2027, but it did not delay disclosure.

In the United States the picture remains state by state. Colorado repealed its original AI Act before it ever took effect and replaced it in May with a narrower law requiring notice and plain-language explanations of adverse automated decisions from January 2027. Illinois has required notice of AI use in employment decisions since January. A 2024 FCC ruling still treats AI voices as artificial voices for telemarketing consent, and the proposed rule requiring AI disclosure on calls remains unfinished.

The regulators' posture points one way. On September 25, the FTC's chairman said, as reported by Reuters, that he would resist treating AI agents as independent actors, placing responsibility with the parties that build and instruct them. For a small business, the practical reading is older than the technology: the company answers for what its software says and does.

Which beliefs changed

The human gate is no longer a house caution. When every major vendor ships confirmation before purchases, posts, and sends by default, the gate is simply the industry's working assumption about current reliability. The operating question moves from whether to gate a job to where the gate sits for that job and what measured evidence moves it.

The model is a configuration line. OpenAI shipped two model generations in under three months—GPT-5.6 on July 9 and GPT-6 in September—and Anthropic released several models in the same quarter. This publication's own free advisor moved to the new generation by changing three defaults and adding one guard for a reasoning setting the newest model rejects. A business whose procedures, records, and acceptance tests live outside the model can take an upgrade in an afternoon; one whose process lives in a chat history cannot.

Felt speed is still not evidence. METR's randomized trial found experienced developers took longer with AI tools while believing they were faster, and METR described its own 2026 follow-up estimate of a speed-up as very weak evidence. The discipline does not change: time the baseline, run the shadow test, and count the review minutes.

What we changed

This edition publishes the capability register: thirteen jobs a small business can hand to current AI, each with the furthest dial setting we would defend, the human gate, a first test, a scoreboard, and the evidence behind it. It will be re-verified every quarter, and this index will record what moved.

The free advisor now reads the same register. Each opportunity in its brief links to the matching entry, and every brief includes draft-only test instructions an owner can paste into the assistant the business already uses.

What to watch next quarter

The FCC scheduled a September 30 vote on rewriting its telemarketing consent-revocation rules, which matters to any business that calls or texts customers automatically. Pennsylvania's updated telemarketing law, which covers artificial-voice calls, takes effect October 19. Colorado's attorney general is taking comments on proposed rules for its automated-decision and chatbot laws through October 26. The EU's grace period for machine-readable marking of AI-generated content from systems already on the market ends December 2.

On the product side, watch whether browser agents keep their confirmation defaults as competition sharpens, whether agent checkout produces real volume or another retreat, and whether outcome-pricing definitions stop counting customers who simply leave as resolved.

The quarter did not prove that a business can run without people. It proved that the parts of a governed loop—connectors, schedules, portable procedures, and default gates—are now standard equipment.

The scarce work is the same as last quarter: choose the job, measure the baseline, set the dial, and keep the receipt.

sources
  1. Claude in Chrome is now generally availableAnthropic, accessed September 29, 2026
  2. Using the cloud browser in ChatGPTOpenAI Help Center, accessed September 29, 2026
  3. Evolving Atlas into ChatGPT for browser-based agentic workOpenAI Help Center, accessed September 29, 2026
  4. Claude for Small Business launches new workflows, integrations, and training programsAnthropic, accessed September 29, 2026
  5. API changelogOpenAI, accessed September 29, 2026
  6. Mitigating the risk of prompt injections in browser useAnthropic, accessed September 29, 2026
  7. Threat intelligence report: September 2026Anthropic, accessed September 29, 2026
  8. Gartner survey finds 87% of customers say companies using GenAI for customer service must provide access to a human agentGartner, accessed September 29, 2026
  9. Transparency obligations under Article 50 of the AI ActEuropean Commission, accessed September 29, 2026
  10. SB26-189: Automated decision-making technologyColorado General Assembly, accessed September 29, 2026
  11. Reuters NEXT: FTC chair pushes back on treating AI agents as independent actorsReuters, via U.S. News, accessed September 29, 2026
  12. Measuring the impact of early-2025 AI on experienced open-source developer productivityMETR (arXiv), accessed September 29, 2026
  13. Measuring late-2025 AI on open-source developers (study data and caveats)METR (GitHub), accessed September 29, 2026