OpenAI Just Rented Out the Agent Harness. Agencies Still Have No Kill Switch.
OpenAI just rented out the thing most agencies were secretly building badly.
On September 10 they put the Codex harness behind one public API call. Sessions. Sandboxes. Subagents. Recovery. No extra platform fee. You pay tokens and tools. Same week they shipped a Data Agent in ChatGPT Work that talks to Power BI, Tableau, and Snowflake without SQL.
That is not another model drop. That is the factory floor.
Dreamforce opens September 15 with agents on the main stage. Salesforce already named seven Agentforce roles. The market is selling we have agents. The research is screaming something else.
Harness surveyed enterprises and the gap is ugly. Seventy-five percent say their agents are secure end to end. That same group still got hit with incidents at almost the same rate as everyone else. Seventy-six percent think they can kill a bad agent in fifteen minutes. Only thirty-three percent actually have a kill switch. Sixty-five percent of enterprises have already watched an agent act out of scope.
So the latest AI news is not agents are here. Agents have been here. The news is the harness is now a product, and most shops still cannot inventory what is running.
What actually shipped
LAYER 1 — The harness became a SKU
OpenAI Agents API is in public beta. Durable sessions. MCP tools. Multi-agent with a cap on concurrent subagents. Run it in OpenAI's sandbox, yours, or partners like Vercel and Cloudflare.
LAYER 2 — Data stopped needing a translator
ChatGPT Work's Data Agent builds dashboards from plain English. That is the research-to-slide path agencies still bill hours for.
LAYER 3 — The enterprise is still flying without instruments
Confidence sits in the mid-70s. Real testing gates sit under 20 percent. Instant kill switch sits at 33 percent. Capability moved. Control did not.
The marketing + AI section nobody should skip
Here is the part that hits agency P&L first.
Marketing teams are the first to wire agents to live surfaces. Ads. WhatsApp. CMS. CRM. Email. That is exactly where one rogue step costs money and reputation.
Visa's Trust Index this week is blunt. Buyers will let an assistant browse. Only 23 percent will let it spend. Agentic commerce is not a checkout problem. It is a permission problem.
If you sell AI for marketing agencies in 2026, stop pitching more drafts. Pitch a stack with rails.
One named agent per job. Campaign draft. Competitor watch. GEO page refresh. Not a general marketing bot.
A human gate before publish, send, or spend. No exception for it is just a test.
A kill switch the account lead can hit without calling engineering.
An inventory. If you cannot list every agent, MCP server, and model touching a client, you do not have a stack. You have a leak.
Answer engines still need pages they can cite. Marketing agents still need briefs they cannot wander off. That is the work.
Do this week
Pick one live workflow. Wire it to the Agents API or the tool you already pay for. Add the gate before it can post. Ship that, not a slide about agents.
I'm using this at Dzine Prodigy the same way we treat any production tool. Speed is the easy part. Control is the product.


Comments