Found Friday newsletter
FOUND FRIDAY · SEASON 5 · ISSUE 10

AI is moving from answers to authority. The defaults matter now.

The useful question is no longer whether AI can help. It is who can connect it, what it can touch, which version is running, and how quickly a business can tell when the automation quietly stopped doing its job.

What I’m seeing this week: The strongest AI stories are not just model launches. They are access gates, admin defaults, enterprise context layers, reusable skills, and the human workflow that keeps AI-assisted work recoverable.

The pattern

  • Capability is being gated by policy, identity, and data retention.
  • Agents and connectors are moving closer to real workplace systems.
  • The winners will be the teams that make defaults, rollback paths, and ownership visible before the tools spread.
AI governance controls graphicAnthropic / Enterprise Safeguards

Anthropic widens the Cyber Verification Program into three access tiers and ties them to data retention

Source: Anthropic — “Expanding the Cyber Verification Program” (page `datePublished` 2026-10-06T19:00:00Z)

Summary: Anthropic expanded its Cyber Verification Program into three tiers, giving vetted security organisations access to Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1 with the reduced cyber safeguards those models otherwise apply. Defense Access covers incident response and vulnerability work, Red Team Access adds approved penetration testing, and Specialized Access is reserved for organisations testing safety-critical systems such as power grids and interbank transfer networks, reviewed with the US government. Generally available Claude models keep safeguards that block most cyber work. Enrolled organisations must accept data retention so Anthropic can monitor for misuse, with a zero-data-retention option promised later this fall.

Why it matters

This is what safety looks like once a model is genuinely dual-use: not a refusal, a gate. The strongest capability goes to a vetted few under monitoring, and everyone else gets a deliberately weaker build of the same model. That is a reasonable answer, and it is worth understanding because the pattern is spreading to agents and to data access generally — the default build is the safe one, and capability is something you apply for. The uncomfortable part is the currency: access here is paid for partly with visibility over your own data, a trade a regulated buyer can evaluate and a small business cannot easily judge.

What to do now: Ask your AI vendors one question this quarter: what is the most capable version of this product, and what controls or data commitments are required to get it. Then decide in writing which workflows must never depend on a tier you have not qualified for, and who signs off if the vendor changes the terms.

Microsoft 365 governance controls badgeMicrosoft 365 / Agent Controls

Microsoft will let every user upload advanced Copilot agents and plugins by default on 25 October unless an admin acts first

Source: Microsoft 365 Message Center — “Manage who can upload advanced agents and plugins” (MC1472007; rollout begins 2026-09-25, completes end of October 2026)

Summary: Microsoft is rolling out a Copilot admin control that decides who may upload advanced agents and plugins — packages containing a declarative agent with actions or an MCP server. Admins can allow all users, no users, or specific users or Entra ID groups. The setting has been visible in the Microsoft 365 admin center since 25 September, and from 25 October advanced-package uploads are enabled for everyone by default unless an admin has changed it. Basic package uploads and Microsoft’s own built agents are unaffected.

Why it matters

Cloud governance is mostly a set of defaults nobody was asked about, and this is one of the few where the vendor publishes the date your silence becomes the decision. The default is permissive: after 25 October, an ordinary user in your tenant can upload an agent that reaches other systems through an MCP server, and the review that would have happened in a project plan never happens. That is not a reason to lock it down, it is a reason to decide on purpose, because “we never changed the setting” and “we approved this” look identical in an audit six months later.

What to do now: Put one calendar entry on both dates. Before 25 October, open Copilot settings and choose explicitly who may upload advanced packages — most organisations should start with a named group rather than all users. Before 1 November, do the same for the Copilot-in-SharePoint preview controls that retire that day. Then tell the help desk what to say when the first “my agent won’t upload” ticket arrives.

AI governance controls graphicOpenAI / Small Business Training

OpenAI and America’s SBDC take AI training to small businesses — with a report on what small teams actually do with it

Source: OpenAI — “Helping small businesses put AI to work” (page dated September 30, 2026)

Summary: OpenAI is partnering with America’s SBDC to expand hands-on AI training and local guidance for small businesses, and published a report on what small teams are getting done with AI. The training reaches owners through the small-business development centres that already advise them.

Why it matters

The tools stopped being the bottleneck a while ago. What small businesses lack is a person who will sit with the owner and decide what to turn on, what to keep manual, and who reviews the output. That is the job SBDC advisors already do for finance and marketing, and now AI training is arriving through the same channel, funded by the company that sells the product. That is not a reason to refuse it; it is a reason to read the report as a vendor’s account of its own customers and to keep your own decisions your own.

What to do now: If your business is small, use the free training rather than paying for a generic course, and take one decision to it: pick the single most repetitive weekly task, ask whether AI should do it, assist it or leave it alone, and write down who checks the result. If you are advising small businesses, expect owners to arrive with vendor-trained expectations and budget numbers that came from a vendor’s case study.

Google Workspace automation badgeGoogle / Workspace Automation

Gemini’s “skills” arrive with a retirement schedule for Gems — and a portable instruction format

Source: Google Workspace Updates — “Introducing skills in the Gemini app and Workspace, plus what’s next for Gems” (feed timestamp 2026-09-30T09:11 PT)

Summary: Google started rolling out skills, reusable custom instructions that can be stacked in a single prompt, across Workspace and the Gemini app, and laid out the schedule for retiring Gems: skills in Workspace from October 5, skills in the Gemini app from October 13, Gems moved to the settings panel on November 17, and Gems switch-off for business and enterprise customers no sooner than March 2027, when the “Ask a Gem” step in Workspace Studio flows stops working. Skills are also built on an open Markdown standard, so instructions written for another tool can be copied into Gemini.

Why it matters

Reusable instructions are how a team makes AI behave the same way twice, and this week Google made them portable across tools and gave them a retirement schedule. That combination turns a personal habit into an asset nobody owns. The instruction that produces your on-brand proposal today is one copy-paste away from being your competitor’s, and the instruction that encodes last year’s process is one Google audit away from being deleted without anyone reviewing what it did. Neither risk shows up in a licence review.

What to do now: Treat the instructions people write as work product. Keep a short list of the skills or prompts your team depends on, give each a named owner and a short description of what it is meant to produce, and put them on the same review cycle as your document templates. Before March 2027, decide who is allowed to create skills and who checks them, because Google will migrate the Gems and nobody will have reviewed the drafts.

Microsoft 365 governance controls badgeSharePoint / Microsoft 365

SharePoint is rolling out HTML pages, and that changes the governance conversation

Sources: Microsoft Support, “Create, upload, edit, and publish HTML pages in SharePoint”; Microsoft, “What’s new in Copilot in SharePoint: October 2026”.

Summary: Microsoft is rolling out support for HTML pages in SharePoint. Users can create HTML with Copilot in SharePoint or upload HTML from another source, store it in the pages library, render it as a SharePoint page, make additional edits, and share it with an audience. Microsoft’s October roundup frames this as part of Copilot in SharePoint’s move from generating content to reviewing, publishing, and distributing it. The important point is not whether the feature appears in one specific tenant first. It is that HTML pages move AI-generated reports, dashboards, newsletters, and small interactive pages closer to normal SharePoint publishing.

Why it matters

This is a bigger shift than it looks. SharePoint has always been the place business content goes to live, but HTML pages let AI-generated dashboards, reports, newsletters, and small interactive pages move into the tenant without becoming a full development project. That is useful, and it is exactly why it needs governance. If any agent can produce SharePoint-ready HTML, the hard questions become who owns the page, where the source came from, what data it can show, and who reviews it before it becomes “official.”

What to do now: Pick one safe internal use case, such as a project status page or meeting recap dashboard, and test HTML pages there first. Before opening the floodgates, decide who can create or upload HTML pages, where they live, how they are reviewed, and what happens when the person who generated the page leaves the project.

Hermes journey badgeField Notes / Hermes Journey
Hermes: My Agentic Journey

Field Notes from My AI Workstation: the Hermes Journey is becoming an operating system

This week was a reminder that the Hermes Journey is not one tool or one clever prompt. It is the operating layer around the work: backups, upgrade discipline, cleanup and recovery, source checks, tenant access reviews, publishing support, transcript routing, status checks, and visible places where a human can approve or stop the next step.

We did the unglamorous work that makes AI useful in the real world. We backed up the current Storm and Hermes implementation to private recovery lanes, cleaned more than 21 GB out of the local Hermes workspace without deleting recoverable data, verified the system stayed stable afterward, repaired a broken environment-file issue, documented which tenants and platforms Storm can access, and kept the next Found Friday issue moving without pretending rough edges were finished.

We also used Storm as a real beta tester, not just a writing assistant. Storm went all the way through another application’s early-access flow: finding the invite, signing up, confirming the account, redeeming access, writing a quick test plan, executing the plan in the live beta, documenting what worked and what failed, submitting feedback through the app, and reporting the results back to the owner. That is the difference between an agent that can summarize a page and an agent that can carry a bounded workflow with evidence, review, and a clean handoff.

The next layer is multi-agent coordination. We started testing Grokbot last week, and the workstation is now working with nine different agents in addition to the other assistants already in the loop. That is probably not a separate news story yet. It belongs here as a Field Notes milestone: the story is not “we tried another bot,” it is that personal AI workstations are starting to look like small teams, with handoffs, owners, testing boundaries, and a human deciding what moves forward.

That is the practical lesson. A personal AI workstation is not just a chat window. It needs memory, skills, scripts, files, backup paths, approval boundaries, visible status, and a way to recover when an automation quietly stops producing work. The magic is not that the agent can do a task. The value is that the person can see the system, trust the handoff, and know where the rollback path lives.

What to watch next: Treat your AI setup like a small operating model, not a toy. Name the workflows, back up the pieces that matter, make the status visible, and decide where human approval is required before you scale it.

Getting Started with Hermes

Want to build your own practical AI workstation? My beginner-friendly Hermes setup guide walks through the mindset, setup, safety boundaries, and first workflows for a personal AI assistant.

Get the Getting Started with Hermes guide

AI adoption is not just turning the new thing on. It is deciding who owns it, what it can touch, and how you recover when it behaves differently than yesterday.

Closing Thought

The companies that get value from AI will not be the ones that chase every release. They will be the ones that turn releases into controlled decisions: who gets access, what changes, where the logs live, and what the fallback plan is.

Need a practical AI plan for your team?

I help leadership teams, departments, and small businesses turn AI from scattered experiments into useful, governed workflows.

Talk with Rob about practical AI education