Sam Altman has been saying something lately that doesn’t fit neatly on a keynote slide: it’s going to take a long time before AI goes mainstream. That’s the CEO of the company most responsible for the current hype cycle, telling everyone to lower their expectations about the calendar. And then, per Gizmodo, OpenAI turns around and ships a new always-on agent anyway.
I find that combination more interesting than either piece of news alone. A company that believes mainstream adoption is years out is still building for a world where software runs continuously on your behalf. That’s not a contradiction. That’s a bet on infrastructure before demand.
What “always-on” actually changes
Most people’s experience with AI agents so far has been transactional. You open a chat window, you ask for something, you get an answer, you close the tab. The agent exists for as long as you’re paying attention to it. Everything resets.
An always-on agent flips the default. It’s running when you’re not looking. It watches for conditions, reacts to events, and produces work you didn’t explicitly ask for in that moment. From where I sit, curating agent tools for a living, this is the single biggest dividing line in the category right now — not model quality, not context window size, but whether the thing keeps existing after you walk away.
The practical difference shows up fast:
- Trust becomes a standing question, not a per-request one. You’re not approving one action. You’re approving a policy.
- Errors compound quietly. A bad answer in a chat window is annoying. A bad assumption in a persistent loop runs a hundred times before anyone notices.
- Cost stops being predictable. Transactional agents cost what you use. Persistent agents cost what they decide to do.
- The interface problem gets harder. How does an agent tell you what it did while you were asleep, without turning into another inbox?
None of that is a reason to skip always-on agents. It’s a reason to be specific about which jobs you hand them.
The security part I keep circling back to
Gizmodo also ran a piece with a headline that stuck with me — the writer usually laughs off AI hacking reports, but found this one genuinely alarming. I have the same reflex. Most AI security coverage is theater. Someone gets a chatbot to say something rude and calls it a breach.
Persistent agents change the shape of that risk in a way I don’t think the market has priced in. A chat session is a small target with a short life. An agent with standing credentials, continuous execution, and the authority to act on inputs it reads from the outside world is a much larger one. Everything it reads is a potential instruction. Every tool it can call is a potential consequence.
If you’re evaluating an always-on agent for real work, the questions I’d start with are boring and important. What can it touch? What can it spend? What happens when the input it reads is hostile? Can you see a log of every action after the fact? If the vendor can’t answer those in plain language, that tells you where the product is in its life cycle.
Reading the rest of the tea leaves
The other OpenAI headlines from the same stretch are worth holding in the same frame. The head of data centers reportedly quit. The CFO reportedly told staff that an IPO matters less than another fundraise. Those are organizational signals, not product signals, and I’d caution against building a grand theory out of them.
What they do suggest is a company operating under real strain while shipping ambitiously. Data center leadership matters enormously when your product roadmap assumes continuous compute for millions of persistent agents. Fundraising talk matters when that compute has to be paid for before the revenue shows up. Altman’s long-timeline comment starts to read less like modesty and more like a description of the gap between what’s technically shippable and what’s economically settled.
My honest take for anyone building right now
Don’t wait for mainstream. Waiting for mainstream is how you end up integrating a mature technology at the same time as your competitors. But do calibrate. The useful move in 2024 and 2025 was learning where agents are reliable, and that’s still the useful move here.
Start with a narrow, persistent job where the failure mode is embarrassing rather than expensive. Monitoring. Triage. Drafting. Something where a wrong output gets caught by a human before it reaches a customer or a ledger. Run it for a month. Read the logs. Then decide whether to widen the mandate.
The always-on agent is coming whether or not the market is ready for it, because the companies building them have decided the infrastructure has to exist first. The people who benefit most will be the ones who spent this stretch learning the failure modes on small problems instead of discovering them on big ones.
🕒 Published: