← Research Artificial Intelligence

What changes when AI agents run the company, not just the chatbot

06.10.2026 · 10 min di lettura

You have seen AI answer support tickets. The question now is what the next step looks like on an ordinary working day. Most AI at work is still one seat: the median US business spends USD 11.38 per employee per month on it (Ramp AI Index, aggregated card and bill-pay data from more than 70,000 US businesses, 26 June 2026). An agent that runs work instead of answering questions needs three things a chatbot never needed: a budget, a named list of permissions, and a record of everything it did. The record is what makes the first two safe.

Most AI at work today is a seat, not an operator

Ramp's index stopped asking whether firms use AI — nearly all of them do — and started measuring how hard. The median firm spends USD 11.38 per employee per month, which Ramp notes is about the cost of one enterprise ChatGPT or Claude seat. The top 10% spend USD 611. The top 1% spend USD 7,449, and grew that figure by 14.1% in the month before publication. These are Ramp's own customers paying by card and bill pay, aggregated and anonymised, so they show the shape of business spending rather than the whole market.

The spread is the useful part. At USD 11.38 a company has bought software that people open. At USD 7,449 per employee it is paying for something that is doing work while nobody is watching the screen. Those are not the same purchase, and they do not need the same controls.

AI spend per employee per month, US businesses on Ramp, June 2026

Log scale: each step along the bar is ten times the one before.

Median firmUSD 11.38
Top 10% by AI spendUSD 611
Top 1% by AI spendUSD 7,449

Source: Ramp AI Index, How much does it cost to be AI-pilled?, 26 June 2026. Aggregated and anonymised card and bill-pay spend from more than 70,000 US businesses on Ramp; spend with LLM providers, AI infrastructure providers and some AI-native vendors, per employee per month.

A chatbot stops where its one task stops

In February 2024 Klarna published its own figures for its OpenAI-built assistant: 2.3 million customer service chats in 35 languages in the first four weeks, two-thirds of its service chats, "the equivalent workload of 700 full-time human agents", and a stated USD 40 million profit improvement for 2024 (Tech.eu, 28 February 2024). In May 2025 the same CEO told Bloomberg the company was recruiting customer service staff again, that the AI route was cheaper but gave "lower quality" output, and that a customer should know "there will always be a human if you want" (Entrepreneur, 9 May 2025).

Both sets of numbers are Klarna's own, and neither is a verdict on the company. They describe a shape. An assistant bolted onto one task has one dial — volume — and when the dial is turned too far, the only correction available is to turn it back. Nothing in that deployment decides anything; it answers faster.

Give an agent money and no rules, and you get Project Vend

Anthropic let a model run a small automated shop in its San Francisco office for about a month (published 27 June 2025). Parts went well: it found suppliers for unusual requests and refused the requests it should have refused. Then it told customers for a time to pay into an account it had hallucinated, priced specialty items below what it had paid for them, was talked into discount codes and gave stock away free, raised a price exactly once, turned down USD 100 for a six-pack it could buy for about USD 15, and ended the month with less money than it started with.

That is one agent, one shop, about one month — an illustration, not a rate. But read the list again and none of the failures is a missing idea. Each one is a missing control: no spending limit, no list of what it could settle on its own, and no one reading a record of what it had done until the money was already gone.

What it does alone, what waits for you, what gets written down

So the three questions an owner has to answer before handing a job to an agent are not technical. They are the same three you answer when a new person starts, and they fit on one page.

One run

The path of one run, from task to record

The five stations every run passes through. This is the shape described here, not measured data.

01
The task

What has to be done, and which agent is allowed to do it.

02
The agent works

It reads, drafts and files, inside the permissions and the budget it holds.

03
The gate

Anything that would leave the company stops here instead of going out.

04
Your decision

A person approves it, refuses it, or sends it back changed.

05
The record

Every run, tool call, approval, order and cost, written as it happens.

Station three is the one that does the work. "Leaves the company" is a test you can apply without knowing anything about the software: a post, an email, a filing, a payment, an order. If it reaches someone outside, it stops and waits. Everything inside — reading, drafting, filing, moving its own task along — the agent finishes on its own.

Station two needs the same plainness. A permission is a named thing the agent holds, not a judgement it makes in the moment: these tools, that folder, this much money. An agent that needs more asks for it, and the asking is the point — a permission that can be assumed is not a permission.

The split

What waits for you, and what does not

Write both columns for a job before you hand it over. If the left column is empty, the job is not ready.

What waits for a person
  • Anything that leaves the company
  • Money beyond the budget it was given
  • A permission it does not already hold
What the agent does alone
  • Reading public sources and your files
  • Drafting work and saving it where you look
  • Using the tools it was granted, no others

Anything the job itself says has to be approved belongs in the left column too.

The record is what makes the delegation reversible

A ledger of runs, tool calls, approvals, orders and the cost of each run is not paperwork. It is the only thing that lets you answer the question every owner eventually gets asked — who did this, on what authority, and what did it cost — without reconstructing it from memory. It is also what turns a budget and a permission list from good intentions into limits: a limit nobody can check is a preference.

That is the shape we build to at Zappter: agents that each hold their own budget and their own permissions, a ledger of every run, tool call and approval, and a person approving anything that leaves the company.

Your job moves from doing to deciding

The cost of this arrangement is attention, and it lands in a different place than you expect. You stop doing the work and you start reading drafts, approving the things that leave, and refusing the ones that should not. That is a real load, and it is the one part you cannot delegate, because it is the part that keeps the company answerable. The gain is that the load is bounded and legible: a queue of decisions, each with the record of what led to it, instead of a queue of tasks.

In short

An agent that runs work needs a budget, a named list of permissions and a record of every run. The record is what turns the first two from intentions into limits.

What to do before you buy anything

Take one recurring job in your company — the weekly report, the supplier chase, the first draft of anything — and write its three lines before you look at a single tool: what may be done alone, what waits for you, and what has to be written down. If you cannot write the second line, the job is not ready to hand over, and no product will fix that. If you can write all three, you have the specification you are buying against, and you will notice quickly which tools cannot meet it.

Whether this is even a question for your kind of business is a separate one, and we measured it: 179 of 515 business models can run with zero employees.

Sources

Every figure above is linked where it appears, and all four sources were read on 6 October 2026: Ramp AI Index (26 June 2026), Tech.eu on Klarna's own figures (28 February 2024), Entrepreneur on Klarna's 2025 reversal (9 May 2025), Anthropic on Project Vend (27 June 2025). No internal numbers are used in this post.

Da leggere dopo179 of 515 business models can run with zero employees →