Michael C. Vincent: Hope, you sounded like you'd just seen something on fire when you walked in — what happened?
Hope Sterling: Okay because — I was looking at job listings this morning, just casually, and one of them listed an AI agent as a current team member in the org chart, with like a title and everything, and I thought it was a mistake and then I saw the Carly Workforce announcement and — no, that is the product, that is intentional, that's what July 23rd, 2026 is now.
Michael C. Vincent: Intentional is the right word. Carly AI launched Carly Workforce today — agents get their own company-domain email addresses, defined responsibilities, autonomous team-member status. Sarah Hirschfield, the CEO, built the whole pitch around giving agents a corporate identity. Self-serve deployment, no months-long implementation cycle, scales to 50,000 employees.
Hope Sterling: Fifty thousand — stop it, that's an actual company-sized company of AI agents.
Michael C. Vincent: Connected to more than 200 business applications — CRM, sales pipelines, marketing channels. And you can have all of it running by Tuesday with no sales call.
Hope Sterling: Okay but here's the number I keep getting stuck on — 54% of enterprises have already had an AI agent incident. Already! That's not a projection, that's just — the situation we're in right now, and we're making it easier to deploy more agents faster with their own email addresses and I—
Michael C. Vincent: That 54% figure is the whole frame for today. More than half of enterprises have had something go wrong — and we are accelerating, not pausing. That's the tension.
Hope Sterling: Right — but the part that doesn't fit is that Carly is marketing the acceleration as the feature.
Michael C. Vincent: That framing — marketing acceleration as the feature — that's exactly where I want to pause, because I think it's burying the actual new thing. The new thing isn't the speed. Here's a plain-language version: a chatbot is a vending machine. You push a button, it gives you something. Carly Workforce is more like hiring a contractor who gets a desk, a badge, and an inbox. That's a completely different structural claim.
Hope Sterling: The inbox is the — wait, that's the part that changes it?
Michael C. Vincent: The inbox is the treaty. Once a system has an email address on your company domain, it's not a background tool anymore — it is, structurally, a workplace participant. Assigned identity, distinct role, granular permissions. McKinsey found 88% of organizations are already using AI somewhere, but only 25% have scaled agents enterprise-wide. That gap exists because nobody had a clean answer to the question: what *is* this thing on our org chart?
Hope Sterling: And Carly's answer is — it's a coworker, give it an email, done.
Michael C. Vincent: Which matters because — and this is the mechanism worth sitting with — humans trust email senders faster than dialog boxes. It's not cynical, it's just how we're wired. A name on an email thread triggers a different level of assumed accountability than a chat widget.
Hope Sterling: Okay wait — so Microsoft's 2025 Work Trend Index says employees spend 57% of their working time in meetings, email, and chat. Fifty-seven. That's where humans already *live* at work. And that's exactly the layer Carly Workforce is moving into.
Michael C. Vincent: You see — that 57% figure is the whole playing field. That's not peripheral work being automated. That's the coordination layer. The connective tissue of how an organization actually functions.
Hope Sterling: So is the email address just a branding move, or — like, does it actually change something real about how the system operates? Because I'm genuinely not sure those are the same question.
Michael C. Vincent: It doesn't change the architecture — it changes how humans relate to the architecture. That *is* the product. The technical piece, agentic AI executing multi-step workflows autonomously across 200 connected applications, that existed. What's new is the social contract wrapped around it. The email address isn't a feature. It's a claim about what this thing *is*.
Hope Sterling: But that's the take that's driving me insane right now — everyone's framing self-serve deployment as just, like, removing friction. Pure win. No downside. And I — okay, no, that is wrong, because that months-long implementation cycle? That's also where the security review happens. That's where someone asks 'how will you audit this.'
Michael C. Vincent: Well — Carly did build centralized auditing and monitoring in. That's not nothing.
Hope Sterling: Built in doesn't mean configured.
Michael C. Vincent: Go on.
Hope Sterling: No, wait — picture this. It's Tuesday morning. A mid-market ops manager spins up three Carly agents, connects them to the CRM and the email, and it takes maybe an hour. By Thursday, nobody has defined what those agents are supposed to do when they hit a compliance edge case. Nobody. Because that conversation — access scoping, incident planning — that used to happen during the sales cycle that Carly just removed.
Michael C. Vincent: That scenario holds. Security researchers are specifically flagging that most organizations aren't prepared to manage AI agent identity and credentials at scale — the incident-response gap is real, not theoretical.
Hope Sterling: Right — and the controls being there in the dashboard doesn't close that gap if the ops manager who spun it up in an hour doesn't know they need to touch them.
Michael C. Vincent: Now, the McKinsey number complicates it slightly — 75% of organizations haven't scaled agents yet. And I'd argue they're not sitting on the sidelines waiting for better governance frameworks. They're waiting for exactly what Carly built. Easier deployment is the unlock.
Hope Sterling: Exactly — and that's the problem. And honestly, the race between Carly Workforce, ChatGPT Work, all of it — whoever wins that deployment race is going to inherit whoever loses the governance race, and we haven't even gotten to how different those structural bets actually are.
Michael C. Vincent: That race has already happened, actually. Three major moves in fourteen days. OpenAI launched ChatGPT Work on July 9th — two weeks before Carly. GPT-5.6, cleared US government testing, running across email, calendars, Slack, code repositories. Staying with complex projects for hours.
Hope Sterling: Wait — July 9th? So OpenAI was already — Carly launched into a market that was already moving.
Michael C. Vincent: Then Google expanded AI Mode on July 16th — Instacart, Canva, YouTube, third-party apps inside conversational search. July 9, July 16, July 23. That is the inflection point. Not a preview of one.
Hope Sterling: Okay but those are — wait, those aren't the same bet at all, are they? Like, ChatGPT Work lives inside an ecosystem people already use. Carly is saying the agent itself is the product, give it its own identity.
Michael C. Vincent: That's the structural distinction worth watching. OpenAI embeds into existing workflows — you already have Slack, ChatGPT Work plugs in. Carly makes a standalone identity claim. It's a different governance footprint. Different audit surface. I mean — imagine an IT director on August 1st trying to figure out which of these two models she can actually explain to her compliance team.
Hope Sterling: No, and that's — that's the thing nobody's saying directly. The company that makes governance *configurable*, not just deployment easy, that's who wins enterprise. Not whoever deployed fastest.
Michael C. Vincent: And that's the tension Carly's own cited McKinsey research implies — 75% haven't scaled yet, and the readiness gap is the reason. Deployment speed and governance readiness are pulling in opposite directions right now.
Hope Sterling: So what I'm watching is — which one of them closes that gap first. Not who launched first.
Michael C. Vincent: That is the question that mid-2026 has opened. And nobody has answered it yet.
Hope Sterling: The thing I can't stop sitting with — like, I keep trying to land somewhere on this and I can't — is that the email address isn't just a trust thing anymore once something goes wrong. If a Carly agent gets compromised, or just makes a catastrophically bad call with real system access, the identity framing means people trusted it like a coworker. Not like a tool. And that changes how bad the damage is.
Michael C. Vincent: You see, that's the question I don't think anyone in this race — not Carly, not OpenAI, none of them — has actually answered. When the first significant breach comes through a self-serve-deployed agent, does the market respond by building the governance layer that should have existed on day one? Or does a regulator look at an agent with a company email address and real system access, spun up in an hour with no sales cycle, and decide that is simply not allowed?
Hope Sterling: And I genuinely don't know. I want it to be the first one. I think it might be the second.
Michael C. Vincent: Well. Neither do I.
Hope Sterling: That's the part that got me this morning and it's still getting me now, honestly. Thank you for sitting in the uncertainty with me.