The Agent Stack mascot
The Agent Stack _
Daily B2B AI automation brief · Thursday, July 9, 2026 · Issue #31

Hey there 👋

For two years the coworker-agent lived in a browser tab. You opened it, watched it work, and closed it when you walked away. The work stopped when you did.

This week it got a phone and a set of keys to your inbox.

Wednesday’s issue was about the controls becoming toggles you flip on. Today is what happens once you flip them: the thing they control just got a lot more reach. So the through-line for the day is simple — reach went up, which means the job is now attach the gate before you widen the door. Let’s get into it.


The Big Thing

🤝 Claude Cowork left the laptop — it’s on the web, on your phone, and on a schedule now

Here’s the shift, and it’s bigger than “there’s a mobile app now.”

Anthropic is rolling Claude Cowork out to web and mobile, and — the part that matters — letting it run in the background with no device online. Cowork is the mode where you hand Claude a task and it works across your files, calendar, email, messaging, the web, and whatever tools you connect until the job is done. Until this week that lived on your laptop. Close the lid, and the work stopped.

Now it doesn’t. Three things changed. Your work follows you — start a task at your desk, check it from your phone, grab the output anywhere. Work continues in the background — scheduled tasks run with nothing open. Set Monday’s client prep for 6 a.m., and Claude grinds through the email threads, transcripts, and recent news, builds the briefing doc, and leaves the follow-up email drafted but unsent. The decisions still come to you — when Claude hits a call only you can make, the question pings your phone, and nothing ships until you’ve approved it.

Sit with the second-order read. The reason this is a “big thing” isn’t convenience. It’s that the agent’s reach just expanded on every axis at once: more surfaces (web + phone), more time (overnight, between meetings), and more of your real systems (your actual inbox, calendar, and files, not a sandbox). Reporting around the launch points at Microsoft 365 as a headline connector — drafting mail, managing calendars, and updating OneDrive and SharePoint files — with the approval step as the thing standing between the agent and production.

That reframes the deployable question. It’s no longer “what can Cowork do.” It’s “did I set the boundary before I let it touch the inbox everyone actually reads.”

A few caveats worth pricing in: beta access rolls out over the next several weeks, Max users first; the Microsoft 365 write actions come with Teams staying read-only; desktop is still the full experience (local files + browser); and to mark the launch, Anthropic extended doubled Cowork usage limits through August 5.

Ship it? Deploy now — in beta, on something low-stakes. Point it at a recurring digest or a scheduled file update, keep approvals on, and watch a few scheduled runs before you widen. What you don’t do is aim it at your primary inbox with auto-send on day one. Give it more reach and a gate in the same motion — never the reach alone.

Sources: Anthropic · TechCrunch · 9to5Mac


Tour de Headlines

🌐 Chinese open-weight models are now up to ~46% of US enterprise tokens. The counterweight to a week of “more capable, more autonomous”: the thing actually reshaping stacks is price. Per CNBC (July 7), cheap open-weight models like GLM-5.2 and DeepSeek now make up an estimated 30–46% of US enterprise token usage, going by OpenRouter and Vercel figures, with GLM-5.2 reportedly growing customers roughly 80x in a week. The pattern to copy is the routing default: send routine agent turns to a cheap open-weight tier, escalate to a frontier model only when the task earns it. Two hedges, both load-bearing — those share and growth numbers are platform- and vendor-reported, not audited; and these calls route through Chinese-hosted servers, a data-jurisdiction problem that rules them out for regulated data unless you run them on an Azure- or Cloudflare-hosted path. The model isn’t the news; the adoption curve is. CNBC.

🏛️ Claude Code and Cowork come to government at FedRAMP High. Read this one right next to the Big Thing. The same week the coworker-agent gained reach, the governed version shipped for buyers who need receipts. Claude for Government runs Claude Code and Cowork in a FedRAMP High environment with local-only conversation history, tamper-evident audit logs, model- and seat-level spend limits, and a hard not-to-exceed cap tied to appropriated funds. Even if you’ll never touch a public-sector contract, treat this as the spec sheet for “autonomy with a paper trail” — the exact controls (audit log, hard spend ceiling, local history) you’d want wrapped around any agent whose reach you’re about to widen. It’s gated to public-sector orgs for now; the useful part is the control list, not the eligibility. Anthropic.

🧩 Codex becomes a first-class agent provider inside JetBrains IDEs. The quieter half of “the agent shows up where you already work.” A July 7 GitHub changelog adds OpenAI Codex as a first-class agent provider (in public preview) inside JetBrains IDEs — IntelliJ, PyCharm, GoLand, WebStorm — alongside broader agentic upgrades in the editor. The non-obvious read for eng leaders: coding-agent choice is becoming a per-IDE setting, not a company-wide bet. You can standardize the workflow that matters — review gates, tests, guardrails — and still let teams pick the provider under it. Deploy now if you’re on JetBrains; check your plan and IDE version first. GitHub.


Sponsor

You’re about to hand an agent your inbox. Your revenue calls still have no gate.

Today’s whole issue is one rule: widen an agent’s reach, attach a control in the same motion. Here’s the system in your business that got more reach years ago and still has no gauge — the live sales and CS conversation. The discovery call that got misread. The deal where two people “aligned” on different things. The rapport that never formed — and closed-lost with no warning light. RapportScore scores how your team actually connects, on every call and email, so the misfires surface while you can still fix them. You wouldn’t give an agent your inbox with no approval step. Stop running revenue conversations blind.

See your team’s score →

Tool of the Day

🧰 GitHub Copilot in VS Code (June 2026 releases)

Turn on the agentic upgrades your team can actually use today — if you already live in VS Code.

The July 8 changelog (covering VS Code v1.123–v1.127) is the most “flip it on this afternoon” item of the week. Four things stand out. Agentic browser tools are now GA and on by default — the agent can drive a real browser to test and verify its own work instead of guessing. MCP OAuth with pre-registered client IDs — credentials live in VS Code’s secret storage, not a config file you’ll accidentally commit. Full-chat session cost visibility — you can finally see what an agent run costs before it surprises you. And 1M-token context on compatible models.

Two caveats to price in: the million-token context only applies to compatible Anthropic and OpenAI models, and the cost read ties to usage-based billing. One clarification worth saying out loud, because the names collide: this MCP OAuth is client-side, in-IDE credential handling — a different layer from the enterprise-managed MCP auth (EMA) we led with on Wednesday. That was your admin setting policy once in Okta for the whole org; this is your editor holding a token safely.

The deployable move: turn on session-cost visibility first so you can see spend, then flip the browser tools on for one repo, then widen. Same rule as the Big Thing — one new capability, one control, together.

Read the changelog →


Worth a Click

  • Thrive Holdings is raising ~$2B to buy services firms and rewire them with AI. The contrarian “who captures the value” story. Josh Kushner’s Thrive Holdings is raising roughly $2B from SoftBank, Altimeter, and D1 — not to fund AI startups, but to buy controlling stakes in boring, consolidated services businesses (accounting, IT) and automate the workflows. OpenAI holds a stake and is lending research and engineering talent; the two co-built a tax-return-processing agent on Codex now used by a portfolio firm that has acquired 48 accounting shops. The bet isn’t “sell agents.” It’s “own the P&L and pocket the automation.” Worth a click if you’re wondering where the agent money actually compounds. PYMNTS.
  • The Government of Alberta used Claude to find and fix security vulnerabilities. Less a product, more a copyable playbook: scan the repos, prioritize vulnerabilities by severity and exploitability, generate candidate patches, and produce audit-ready remediation docs — with a reported cut in review-and-remediation time (customer-reported, so hedge it). The reason to click is the shape of the workflow; it’s a template you could lift for your own codebase this week. Anthropic.

The bottom line. The agent left the laptop this week. Cowork runs on your phone and overnight; your IDE’s agent can drive a browser; and both can reach into systems that used to be off-limits. Reach went up. So the discipline is to widen exactly one surface and turn on exactly one control in the same motion — never one without the other. Here’s the Thursday move: take the one agent you’d most want to give more reach, grant it one new surface (a schedule, an inbox, a repo), and attach one control at the same time (an approval gate, a spend cap, or an audit log). One door open, one gate on.

See you tomorrow.
— The Agent Stack

You’re receiving this because you subscribed to The Agent Stack. · Unsubscribe