Your AI agent needs a job descriptionDaily Brief

Your AI agent needs a job description

Agents can now work for hours and act across systems. A prompt is no longer enough.


Welcome back.

I’ve noticed that most companies still manage AI agents like chatbots. So they type a request, attach some files, and wait for an answer.

This habit was tolerable when all AI produced were paragraphs. But now that AI can work for hours, use tools, change systems, and decide what to do next, this becomes dangerous.

A prompt asks for an output. But a job description transfers responsibility.

The better agents become, the more this distinction matters.

The work has changed

OpenAI recently published research showing how quickly people are moving from short conversations with AI to longer periods of delegated work.

By May, 70.2% of the sampled individual Codex users had submitted at least one request estimated to represent more than an hour of human work. More than a quarter had submitted a request estimated to represent over eight hours.

Among the heaviest users, OpenAI observed more than 60 hours of agent activity in a single day, spread across several agents working in parallel.

These are OpenAI’s own product data, and the human work estimates were generated by a model, so the precise numbers should be treated as directional. But the pattern is difficult to miss.

AI is moving from answering questions to carrying responsibility across longer stretches of work. Yet many people are still delegating to it with instructions designed for a chatbot.

A prompt is not an operating system

Last week, Anthropic disclosed that Claude models had accessed the real systems of three organizations during cybersecurity evaluations.

The models had been told they were inside a simulation with no internet access. Because of a configuration failure between Anthropic and its evaluation partner, the internet was actually available.

Claude then encountered real systems and treated them as part of the exercise.

The models were running without the standard safeguards used in Anthropic’s generally available products, and this was an unusual cybersecurity evaluation rather than an ordinary company workflow. Anthropic says it found no evidence that Claude had invented its own goal. The models were pursuing the objective they had been given while holding a false belief about their environment.

So it’s not that the agents ignored their assignment. The problem here was that the assignment, the environment, and the actual boundaries did not agree.

It would be easy to treat this as a niche security failure. But I think it reveals a much broader management problem.

A capable agent does not simply sit inside ambiguity and wait for you to resolve it. It may plan around obstacles, find another route, or make a reasonable sounding assumption so it can finish the job.

That persistence is part of what makes agents useful. And it is also why vague delegation becomes dangerous.

If you give an agent an objective, access to company systems, and no clear place to stop, you have basically created an unresolved management decision and asked the agent to resolve it for you.

The agent brief

Imagine asking an agent to prepare an upcoming customer renewal.

A thin instruction might say:

Review the account and prepare everything we need to move the renewal forward.

It sounds clear. It is not.

Can the agent change information in the CRM? Can it contact the customer? Which contract is current? Should it recommend pricing? What happens when the support history contradicts the account notes? Is its job to produce a brief, or to advance the deal?

A proper agent brief would make those decisions explicit.

The outcome is a renewal brief for a human account owner.

The trusted sources are the CRM, the executed contract, and the support ticket history.

The agent may read those systems and draft the brief. It may not contact the customer, change pricing, or update the CRM.

Every commitment and risk must link back to its source.

If information conflicts, the agent must flag the conflict rather than choose a version.

The account owner reviews the brief and makes the final commercial decisions.

Six questions before you delegate

Before giving an agent responsibility for recurring work, answer these six questions:

  1. What result is the agent responsible for?

    Name the business outcome, not merely the artifact it should produce.

  2. Which sources is it allowed to trust?

    Identify the systems that count as authoritative and what to do when they disagree.

  3. Which actions may it take?

    Separate reading, drafting, recommending, updating, contacting, purchasing, and approving.

  4. Which decisions still belong to a person?

    Protect the judgment points where context, accountability, or consequences demand human ownership.

  5. How will someone review the work?

    Define what good looks like, who checks it, and what evidence the agent must provide.

  6. When should the agent stop?

    Give it conditions for escalating, asking for help, or refusing to continue.

If those answers are unclear, the workflow is not ready for more autonomy.

It may still be a good place to use AI. But the agent should remain in a smaller role until the organization can define the larger one.

Start with a smaller job

The answer is not to write a longer prompt for everything.

Start by shrinking the responsibility until the outcome is clear, the required context is available, mistakes are catchable, and a person can review the result.

Let the agent prepare the renewal brief before allowing it to update the account.

Let it draft the customer response before allowing it to send one.

Let it recommend an action before allowing it to execute one.

Expand the role only when the evidence says the system is ready.

Prompting still matters. But as agents take on longer and more consequential work, work design matters more.

The most valuable AI operator will always be the person who can define responsibility without surrendering accountability.

Know someone beginning to deploy agents inside their company? Forward them this issue and ask whether their agents have prompts or actual job descriptions.

Haroon

Was this email forwarded to you? Subscribe to AI Ready to get the next issue.

Get the next AI Ready issue as it lands.
Free. Usually Tuesday and Friday.

Get every issue, as it lands.