Skip to main content
Back to blog

By Roland CadavosAlways-on agents

Always-On Agents: When Agent Work Became a Standing Job (2026)

In September 2026, agents stopped waiting for the next prompt. They ran on schedules and on their own cloud computers, and the hard part moved from what an agent could do to what it should do unsupervised.

By September 2026, the unit of agent work had quietly changed from a chat turn to a standing job. Agents no longer waited for the next prompt; they ran on their own computers, on schedules, and while their owners slept. Meta opened the month by launching Muse, a personal agent that runs in its own virtual machine and keeps working after you leave the app. OpenAI closed it at DevDay with dots, always-on agents that get their own cloud computer and work toward your goals around the clock. The question stopped being what an agent could do in one sitting and became what it should do unsupervised.

Developer tools made the same move. GitHub’s Copilot releases for VS Code added automations that run agent tasks hourly, daily, or weekly, and agent merge, which lets an agent work through review feedback, failed checks, and merge conflicts until a pull request is ready. At DevDay, OpenAI gave each Codex task an isolated cloud environment that keeps running while your computer sleeps. Anthropic’s Claude Code Desktop gained background computer use on macOS, acting in approved apps while you keep working. The pattern was consistent across vendors: start the work, walk away, and come back to results.

That shift changed the engineering problem more than any model release did. A chat turn is synchronous: you watch, you correct, you decide. A standing job runs while nobody is looking, so everything you used to supply by being present has to be written down instead—scope, success criteria, what counts as done, and when to stop and ask. OpenAI’s own developer example made the point: a dot that watches customer feedback, scopes small fixes, builds and tests them, and brings back complete pull requests to review. The work arrives finished; deciding whether it was the right work still has to happen somewhere.

Permissions became the real user interface. OpenAI shipped dots with built-in rules for when to act and when to ask, plus custom rules that allow, require approval for, or block specific actions. Background “proactive research” was limited to read-only tools, and sensitive tasks such as changing a password always stay with the user. Meta said a separate agent runs on Muse’s virtual machine, kept apart from it at the system level, and that Muse cannot see passwords or payment methods. After August’s containment lessons, that was the right instinct: an agent that never logs off needs boundaries that are enforced, not merely described.

The bottleneck moved to review and attention. When agents can open pull requests overnight, the scarce resource is the person who decides what merges. Tooling started to treat attention as something to budget: GitHub added a badge for sessions that need input and automatic cleanup once their pull requests merge, and OpenAI gave dots an activity view for following background work. The sensible response was the familiar one—small diffs, tests that encode intent, and a named owner for every automation. An agent that lands its own fixes still needs a human accountable for the merge policy.

Standing jobs also revived old operations problems in new clothes. A scheduled agent needs the properties of a good cron job: idempotent runs, a way to tell whether the last run finished, an alert when it fails quietly, and a budget. Usage-based pricing made that last point concrete; Meta launched Muse with a usage meter and paid tiers for heavier use. Memory added a subtler risk. Agents that learn your preferences over weeks can drift, so the rules, notes, and instructions an agent accumulates deserve the same review as the code it writes.

Trust remained the open question. TechCrunch framed Muse’s debut around whether consumers would hand an agent their email, calendars, and payments, and Meta said it had held the launch back from April to work through security concerns first. Developers face the same question at a smaller scale every time they connect an agent to a repository, a ticket queue, or production logs. The more an agent can do while you are away, the more its value depends on how narrowly you scoped it—and how quickly you would notice when it goes wrong.

The niche takeaway for working developers: treat every always-on agent like a service you are about to put on call. Write down its scope and its definition of done, give it the narrowest permissions that work, decide which actions need approval before it runs unattended, make its runs observable and idempotent, and name the person who owns its output. The models will keep getting better at long, unsupervised work. In 2026, the teams that designed for delegation got their time back; everyone else got a queue of pull requests nobody asked for.