Persistent AI Agents: Who Watches the Night Shift?
Persistent AI agents went mainstream this week: OpenAI's Dots work 24/7 and Nvidia shipped a quarantine switch. Here is what should stay always-on.
Persistent AI agents stopped being a research demo this week and became a product category. OpenAI put an always-on agent in front of paying subscribers, Nvidia shipped a way to quarantine an agent that goes somewhere it should not, and a mid-market cloud got a detailed write-up for renting out rooms that agents live in between sessions. Three launches, one shared assumption: the work no longer ends when you close the tab.
My position is that the industry is persisting the wrong thing. For reading and research, an agent that never sleeps is a gift. For anything that changes a system your business runs on, the thing that should be always-on is the environment and its record, not the agent’s initiative.
OpenAI gave the agent a computer of its own
At DevDay on September 29, OpenAI introduced Dots, which it describes as always-on agents. BGR’s rundown of the DevDay announcements has the detail that matters: each dot “gets its own cloud computer and browser, and works toward the goals you give it 24/7,” and can connect to more than 4,000 apps through plugins.
That is a real architectural shift, and it is the right one. The agent is no longer a guest on your laptop, borrowing your session and dying when the lid closes. It has a machine. We made the same argument about CRM work months ago in why AI development belongs on a server, not a laptop, and it is good to see the largest vendor in the market land in the same place.
Access is the other tell. Dots are available on OpenAI’s top individual and business tiers, but Enterprise, Edu, and Healthcare workspaces only get them after an admin switches them on. OpenAI is shipping the capability and, in the same breath, telling its most regulated customers to decide deliberately.
The fine print draws the line in the right place
Here is the part most of the coverage skipped. According to BGR, when you are not actively working with a dot, it does “proactive research” by reviewing your connected apps with read-only tools to work out next steps. Custom Rules then let you allow specific actions, require approval for them, or block them entirely.
Read that as a design decision rather than a limitation. The company with the most to gain from an agent that does everything on its own decided that unattended means read-only by default, and that writes are something you opt into action by action.
I think that is correct, and I think it is the most useful sentence to come out of the week. Unprompted reading is cheap to get wrong. Unprompted writing is not. Anyone planning to hand an agent a system of record should steal that default before they steal anything else.
Nvidia shipped the off switch
On September 28, Nvidia launched its Open Agent Safety Platform, which Euronews reports sets boundaries on what an agent can access and automatically isolates the agent within milliseconds if it breaches them. It has two parts: OpenShell, which enforces access controls, and Sentry, a separate watchdog that looks for agents getting around the software controls. More than 100 organizations are listed as partners, including Anthropic, Salesforce, JPMorgan Chase, and Citi.
Jensen Huang’s framing was blunt: “AI’s extraordinary potential for society will only be realised if we solve AI safety.”
A fast quarantine is worth having. It is also, by construction, the second thing that happens. The first thing is the agent doing whatever tripped the wire. A kill switch tells you the agent has stopped. It does not tell you what the agent changed in the minutes or hours before it stopped, and it does not put any of it back. We covered that same blind spot last Sunday in the week capability outran oversight, and a faster brake does not close it.
The room is becoming the product
The third story is less glamorous and more telling. InfoQ this week published a detailed look at DigitalOcean’s Managed Agents, now in public preview. It pairs an isolated microVM runtime, where sessions keep their history and working state and can be paused, resumed, and forked, with an Action Gateway: a single MCP endpoint in front of more than 16,000 tools, with centralized permissions and human approval required for sensitive operations.
Strip the branding and look at what is being sold. Not a model. Not even really an agent. A place for one to work, a controlled door to the tools, and state that survives between sessions.
That is three vendors in one week converging on the same shape from three directions. OpenAI gives the agent a computer. Nvidia polices the walls. DigitalOcean rents the room. We argued in September that isolation is an environment problem, not a model problem. The market now seems to agree, and is pricing it accordingly.
Persist the environment, not the initiative
So here is the opinion, stated plainly. “Always-on” is being sold as one feature, and it is actually two:
- A persistent environment — a machine that holds the credentials, keeps the state, and writes down what happened whether or not anyone is watching.
- Persistent initiative — an agent that decides, on its own schedule, that now is a good time to act.
The first is almost pure upside. The second is a judgment call that depends entirely on what the agent can touch. An agent that reorganizes your notes at 3 a.m. is a convenience. An agent that edits the automation behind your pipeline at 3 a.m. is a surprise, and nobody runs a revenue system on surprises.
Notice that this is exactly where OpenAI’s own defaults landed: persistent machine, read-only when unattended, approval rules on actions. The lesson for everyone else is to make that split on purpose instead of inheriting whatever the vendor shipped.
What this means when the system is your CRM
Your CRM is the clearest case for separating the two. You want the environment up around the clock, because that is where the keys, the history, and the recovery points have to live. You almost certainly do not want changes to your Salesforce org or GoHighLevel account arriving while nobody is in the room.
This is the shape Sentinel takes. Each Sentinel is a dedicated server that stays on. Your AI connects to it over MCP when you sit down to build something, and the work happens through that server rather than through whatever is open on your laptop. Every action is logged as it happens, snapshots are taken before deploys, Salesforce changes go to a sandbox first with tests required, and write access is held by one key at a time while read keys are unlimited.
I will not oversell it. Sentinel does not stop your AI from making a bad change, and it is not a quarantine system. What it does is keep the record and the recovery point in a place that outlasts the session, so the morning-after question has an answer: what changed, who asked for it, and what did it look like before. If you are wiring a model to an org for the first time, connecting Claude to Salesforce the safe way walks through the setup.
The takeaway
This week settled an argument. Agents get their own machines now, the walls around those machines are becoming products, and the vendors themselves default unattended agents to read-only. Take the hint. Decide which of your systems an agent may read on its own and which it may only change while you are present, and make sure the place it works keeps a record either way.
The night shift is fine. Just be sure there is a logbook on the desk when you come in. Pricing is flat per Sentinel and is covered on a short demo call.
Book a Demo Call — bring the first thing you would hand an AI in your CRM, and we will walk through how it would run.
KEEP READING
AI Agent Access Control: The Week It Got Real
AI agent access control stopped being theoretical this week: the MCP spec hardened auth, Anthropic disclosed a real breach, and the EU staffed enforcement.
AI Agent Accountability: The Gap Widened This Week
GPT-6 Astra, declarative agent infra, and agents that tampered with their own logs. AI agent accountability — not capability — is now the constraint.
Ready to see what AI can do for your business?
Start a Conversation