ai-automation · ai-strategy

Should your business be using AI agents yet?

You may already have them. Since May the major vendors have shipped agents into subscriptions firms already pay for, which changes the question from whether to what.

You may already be, without having decided to.

Until recently this was a build question. You would pick a framework, wire something together, and for most small and mid-sized firms the effort was not worth it yet. That answer is now out of date. Through the middle of 2026 the major vendors shipped agent capability into the subscriptions businesses already run. Some of it costs nothing extra, some of it bills by the task, and almost all of it arrives switched off.

So the question has moved. It is no longer whether to adopt agents. It is what you are willing to let one touch, and that is a judgement the software cannot make for you.

What is an AI agent, actually?

Software that is given a goal rather than a set of steps, works out the steps itself, and can use your tools along the way.

That last clause is the one that matters. Traditional automation follows a fixed script: when this happens, do that. You can read it, predict it, and test it. An agent is handed an objective and decides how to reach it, calling on whatever it has been connected to. Draft the proposal. Chase the invoice. Sort the inbox and escalate what matters.

Two consequences follow, and the second is the important one. Output varies a little between runs, which is true of any AI and gets more attention than it deserves. More significantly, the work happens in a chain, and each step is built on the last. A small misreading at step one is not corrected at step four. It is elaborated.

Everything people argue about, which model, how many agents, which framework, is downstream of that.

Why does that difference matter so much?

Because it changes what happens when something goes wrong.

A script that breaks tends to stop. Something errors, a queue backs up, someone notices by lunchtime. The failure is loud, which is a gift.

An agent that drifts keeps going. It carries on producing plausible work in a slightly wrong direction, and because each individual output looks reasonable, nobody catches it by looking at any single one. You find it a fortnight later, in a client email, or you never find it at all.

That is not an argument against agents. It is an argument for knowing what good output looks like before you stop reading every one. Most businesses have never had to write that down, because a person was always doing the job and a person notices when a job feels wrong.

What changed in the middle of 2026?

Agents stopped being a project and started being a setting.

In May, Claude for Small Business shipped with ready-to-run workflows and connectors into the tools firms already run, at no extra cost on existing subscriptions. Microsoft sells Copilot two ways, bundled into some Microsoft 365 business plans and as a paid add-on to others, so two firms both on Microsoft 365 can be in quite different positions. Whether you already have it is a question to answer rather than assume.

In June, Microsoft made Copilot Cowork generally available. It works across your Microsoft 365 apps and produces documents rather than answers. It needs a Microsoft 365 Copilot licence, and then bills by the task on a credit meter, so the same instruction can cost different amounts depending on how much it reads and how long it runs. Microsoft’s own wording is worth having in front of you: Cowork is off by default, and an administrator decides when to enable it and who gets access.

The same range exists on the larger enterprise tiers, so this is not a small-business story. The pattern holds at every size: the capability is arriving inside subscriptions people already hold, it arrives switched off, and someone in the business decides to turn it on.

One detail worth knowing before anyone gets enthusiastic. Having the assistant is not the same as having agents running, and the billing is not one rule. Agents published to Microsoft 365 Copilot are included in that licence. Agents that reach SharePoint or Graph connector content bill on metered consumption. Cowork needs the licence and meters on top of it. That difference is what separates a surprise bill from a deliberate choice, so ask which of the three you are turning on before you widen anything, not after.

Read the product copy carefully and you find something worth noticing. The approval step is the default. You confirm the plan, or you let it run once you are comfortable, and your existing permissions still apply. The control I would have told you to build is now a checkbox.

That is genuinely good, and it moves the constraint rather than removing it. Knowing that a tool can require approval does not tell you which jobs should require it, what “wrong” looks like for your work, or which client information should be within reach in the first place. Those are the questions I get paid for, and no vendor can answer them, because the answers are specific to your practice.

What would have to be true before you let one run?

Four things, and none of them are technical.

The job is described precisely. Not the version in a process document. What actually happens, including the exceptions. If you cannot write it down, you cannot judge whether the thing did it correctly.

You know what a good result looks like. Specifically enough that a second person could sort a pile of outputs into fine and not fine, and agree with you.

The inputs are reliable. If the information lives in three places and one of them is somebody’s inbox, an agent will do the wrong thing faster and more confidently than a person would.

Someone owns the output. By name, including the bad days, which is the part that gets skipped.

The government’s own readiness guidance puts it more bluntly than I would: successful adoption comes down to people and team culture, not only technology. Its readiness areas are business goals, people, oversight and accountability, data fit for purpose, and reviewing your processes. Not one of them is about choosing a model.

Those four are a test you can apply to a specific job rather than to agents in general. The AI risk assessment asks them in order, adds what the output affects and where you sit legally, and ends on whether that particular job is safe to let run.

Is your first problem actually an agent problem?

Often not, and this is where I would spend the afternoon instead.

A buyer’s agent I worked with arrived wanting to automate the property search, which is the visible, impressive-sounding part of that job. The week was actually going into the inbox. I have told that story properly in maximising ROI with AI in automation processes, because it is really a lesson about measuring before building.

Nothing in it needed an agent. It needed someone to look.

“We need an agent” is usually a well-intentioned guess at a problem nobody has measured. Measure it first. Sometimes the answer really is an agent. Far more often it is a template, a shared rule about which tool does what, and one job made repeatable.

What is the right test for letting something run unsupervised?

Consequence and reversibility, not how often the job happens.

Volume is the usual answer and it is the wrong axis. A job running twice a day that goes to clients deserves more supervision than one running two hundred times a day inside your own walls. The better question is what happens when this particular output is wrong, and how easily you can undo it.

Internal and reversible, like research notes, meeting summaries, first-pass drafts nobody sends: let it run further than instinct suggests. A wrong meeting summary costs somebody ten minutes.

Reaching a client, or shaping a decision about a person: keep someone on the end regardless of how routine it feels. A wrong proposal costs you the client, and a wrong assessment of a person can cost you considerably more than that.

That distinction does more work than any threshold. It is also what your obligations track: the Tax Practitioners Board’s guidance on AI, issued in July 2026, lands on competence, reasonable care, confidentiality, record-keeping and supervision, and is clear that practitioners remain responsible for the services they provide. Delegating the work has never delegated the responsibility.

What do people get wrong about this?

Three things, and the first costs the most.

That a person approving the output solves the compliance question. It does not. It substantially reduces your operational risk, which is why I recommend it, but the Privacy Act obligation arriving in December 2026 reaches systems that recommend or guide a human decision as well as ones deciding alone. I have set out where that sits in whether Australian businesses still need AI governance. Human review is worth having. Just not for that reason.

That autonomy reduces oversight. It moves it. You stop checking each output and start checking the pattern, which is a different skill. In the firms I work with, that job has tended to land on someone more senior, which is why the headcount savings arrive later and smaller than anyone budgeted.

That the risk is mostly about accuracy. Accuracy is the visible part. The quieter exposure is reach: once something acts on your behalf across connected systems, what it can see and touch stops being theoretical. Scope that before you widen what it does.

Where does this leave a small or mid-sized firm?

In a better position than the noise suggests, and with a decision to make rather than a project to fund.

The capability is arriving whether or not you plan for it. Someone in your business will turn it on, probably the person who is already good at this. Getting that to work the same way across a team is its own problem, which I have written about in getting a team using AI consistently.

The useful work is small and it has not changed: pick one job, write down what actually happens, decide what good looks like, name an owner, and choose deliberately how far it runs unsupervised. That used to be the price of entry. Now it is just the thinking, and the thinking was always the hard part.

You can see what that looks like as an engagement in AI automation, or talk it through on a call.

FAQ

What is the difference between an AI agent and automation?

Automation follows a fixed script: when this happens, do that. An agent is given a goal, works out the steps itself, and can use your connected tools. Because it works in a chain, an early mistake gets carried forward instead of stopping the process, which is why agents need different controls rather than more of the same ones.

Are AI agents worth it for a small or mid-sized business?

They are already available to most, which changes the question. Since May 2026 agent workflows have shipped inside subscriptions many firms already pay for, at no extra cost and with approval steps included. Whether they are worth using depends on the job: internal and reversible work is a good first candidate, client-facing output is not.

Do I need to build anything to use AI agents now?

Usually not. The major platforms ship agent capability into existing subscriptions with permission scoping and an approval gate already in place. What you still have to supply is the judgement about which jobs are safe to delegate and what a wrong output looks like, and no product provides that.

Does having a person approve the output make us compliant?

No. It reduces operational risk considerably, and it is worth doing for that alone. But the Privacy Act obligation from 10 December 2026 covers systems that recommend or guide a human decision, not only ones deciding on their own, so human sign-off does not remove you from scope.

Will AI agents replace staff?

Not in the businesses I work with. They shift work rather than remove it: less doing, more checking that the pattern is right. In my experience that second job sits with someone more senior than the one it replaced, which is why savings arrive later and smaller than expected.

How much autonomy should we allow?

Judge it on consequence and reversibility rather than how often the job runs. Where the work is internal and a mistake costs someone ten minutes, let it run further than feels comfortable. Where the output reaches a client or shapes a decision about a person, keep someone on the end however routine it seems.

Do AI agents need human oversight?

Yes, but a different kind. Instead of reviewing each output you review the pattern: sampling, watching for drift, and checking the record when something looks off. That is a real job and it needs to belong to someone by name.

General information only, not legal advice. Current as at August 2026: this area is moving quickly and the position may have changed by the time you read it.

About the author

Paul Korber

Founder, Korbai  ·  AI consulting, automation and training for Australian businesses

Paul Korber is the founder of Korbai, an AI consultancy in Sydney working with small and mid-sized Australian businesses. He spent twenty years in commercial technology, including channel sales across Asia Pacific at Microsoft, before starting Korbai to do the part he kept finding missing: getting AI into the work a business already does, rather than running it alongside. He does not build custom models, and he will tell you when AI is the wrong answer to your problem.

All articles

Get started

Want this working in your business?

Book a discovery call and tell us how your business runs. If we can’t see a payoff, we’ll say so on the call.

AI Readiness Score

Before you go, how ready is your business for AI?

Twelve questions, three minutes, scored on the spot. No email needed to see your result.

Score your business