Part of our Blog

Insights

Weekly AI briefing: ChatGPT Work data

OpenAI’s Data agent, Anthropic’s customer-held logs, and this week’s shadow-AI pieces give UK SMEs a checklist: approved plugins, named data owners, and a review point before an agent acts.

Summary

This week's briefing covers OpenAI's ChatGPT Work Data agent, Anthropic customer-held safeguards, shadow AI and Windows identity for UK SMEs.

Written by Founder & Lead Architect

Reviewed by AI Build GroupEditorial review

Published Last updated

Direct answers

Quick answers

How should a UK SME switch on ChatGPT Work’s Data agent?
Install the Data plugin only for named people, connect named warehouses, keep connected-account permissions, and require a human to approve actions that change systems.
What should we ask Anthropic about Enterprise Frontier Safeguards?
Ask where activity data is stored, who can inspect misuse flags, whether zero data retention applies now, and when the customer-held storage option will be available.
How do we reduce shadow AI without blocking useful work?
Approve one workspace, name an owner for exceptions, and record which tools may see client or finance data. A ban with no alternative is how shadow AI spreads.

OpenAI’s ‘Now everyone can put data to work’ (10 September 2026), Anthropic’s ‘Developing Enterprise Frontier Safeguards with our customers’ (1 September 2026), and RuntimeWire’s 10 September report on Claude for Windows identity controls all point at the same SME decision: who may see company data, where logs live, and which Windows client is approved.

This week’s ChatGPT Work Data agent, Anthropic’s customer-held safeguards, and the shadow-AI / operating-model pieces in the 11 September newsletter give UK firms a concrete checklist: approved plugins, named data owners, and a human review point before an agent acts.

EM-01: OpenAI’s Data agent turns warehouses into a ChatGPT Work question

On 10 September OpenAI introduced the Data agent in ChatGPT Work. It connects to approved company data, investigates what changed, and builds shareable dashboards. Administrators control plugin availability and data-source plugins. AI Build can configure a ChatGPT Business workspace so the Data plugin only sees named sources.

Source: OpenAI, 10 September 2026 — https://openai.com/index/put-data-to-work/

EM-02: ChatGPT Work is an agent that drafts files and needs approval gates

The same day’s Business release notes introduce ChatGPT Work for longer tasks across apps and files, including documents and presentations, and replace the App Directory with Plugins. Compare Business vs personal on admin controls and approval of consequential actions, not just model names. OfficeMaker remains the path for branded, reviewable decks when the output must match a house style.

Source: OpenAI, 10 September 2026 — https://help.openai.com/en/articles/11391654-chatgpt-business-release-notes

EM-03: Shadow AI is now a legal as well as security problem

TechRadar’s piece, carried in the 11 September round-up, treats unapproved tools and sensitive uploads as both a security and EU AI Act issue. An approved ChatGPT Business workspace, simple usage rules and an owner for exceptions is safer than a ban staff will ignore. AI Build can write the short policy and exception path.

Source: TechRadar — https://www.techradar.com/pro/shadow-ai-is-a-security-problem-but-the-eu-ai-act-makes-it-a-legal-one

EM-04: Governance needs a RACI, not another principles slide

Ethosure’s operating-model article argues that ownership, escalation and review make governance usable. A 20–200 person firm can assign data, prompts, approvals and incidents without a full three-lines-of-defence programme. AI Build’s governance review starts there.

Source: Ethosure — https://ethosure.ca/the-ai-governance-operating-model-from-principles-to-structure/

EM-05: Windows AI clients are an identity and procurement decision

RuntimeWire’s 10 September report on a Claude for Windows build describes Entra Continuous Access Evaluation and a Windows authentication broker. Treat it as a distribution signal: verify against Microsoft and Anthropic primary docs before changing a standard. Ask how identity and sovereign-cloud paths work for each approved client.

Source: RuntimeWire, 10 September 2026 — https://runtimewire.com/article/microsoft-let-anthropic-move-in-while-openai-was-sleeping-on-the-couch

EM-06: Anthropic will keep misuse logs in the customer’s cloud

On 1 September Anthropic announced Enterprise Frontier Safeguards: activity data for misuse detection can live in customer-controlled storage, with a phased autumn rollout and zero data retention on Fable 5 / 5.1 for eligible customers until then. Ask where logs live and who reviews flags before putting Claude on client or finance data.

Source: Anthropic, 1 September 2026 — https://www.anthropic.com/news/enterprise-frontier-safeguards

EM-07: Agent oversight and sovereign AI remain an open discussion

The New Stack’s Bluesky post, included in the 11 September round-up, is a discussion signal not a measured trend. The useful questions for an SME remain: where does processing happen, which integrations are on, and what happens when the agent is wrong.

Source: The New Stack via Bluesky — https://bsky.app/profile/thenewstack.io/post/3mufbnsiu7b

EM-08: Trustworthy data still decides whether a Data agent is useful

MIT Technology Review’s 12 August piece on scaling agents with trustworthy data, still in this week’s newsletter, is the pairing for EM-01. Dashboards only help if the sources are trusted. Start with one bounded workflow and a named data owner before connecting more systems.

Source: MIT Technology Review, 12 August 2026 — https://www.technologyreview.com/2026/08/12/1141032/scaling-ai-agents-with-trustworthy-data/

What UK SMEs should do next

Pick one repeatable workflow. Record the approved ChatGPT Business workspace, the data sources the Data plugin may use, the owner, the spend or action limit, and the human review point. Measure time saved and error rate for two weeks before expanding.

Make AI delivery measurable and controlled

AI Build helps organisations identify high-value AI use cases and put the right governance, security, training and implementation controls around them. Start with an AI maturity assessment, an AI governance review or a conversation about a managed ChatGPT Business rollout.

Questions this briefing answers

How should a UK SME switch on ChatGPT Work’s Data agent?
Install the Data plugin only for named people, connect named warehouses, keep connected-account permissions, and require a human to approve actions that change systems.
What should we ask Anthropic about Enterprise Frontier Safeguards?
Ask where activity data is stored, who can inspect misuse flags, whether zero data retention applies now, and when the customer-held storage option will be available.
How do we reduce shadow AI without blocking useful work?
Approve one workspace, name an owner for exceptions, and record which tools may see client or finance data. A ban with no alternative is how shadow AI spreads.

Next step

Keep the weekly control brief coming.

Subscribe for the next AI Build weekly briefing, or talk to us when you want help turning one of these stories into a governed workflow.