AI agents started in the part of the company most comfortable with tools, automation and command lines. They are not staying there.
OpenAI published enterprise usage data on August 12 showing that since February, weekly active enterprise Codex users grew 108× in legal, 41× in sales, 41× in recruiting and 26× in marketing, compared with 5× in engineering. Those are OpenAI’s own customer-platform figures, not a neutral survey of the whole market. They still point to a practical governance problem for UAE businesses: the next person giving an agent access to sensitive systems may not sit in IT.
Agentic AI is spreading into departments that handle contracts, applicants, customer data and commercial decisions, expanding the security and governance surface.
UAE SME owners, HR, legal, sales, marketing, IT and compliance teams should agree on rules before agents become departmental shadow infrastructure.
Agents can prepare research, proposals, candidate summaries, documents and follow-ups while leaving final judgment with the responsible employee.
OpenAI’s growth figures measure usage, not productivity, accuracy or business return, and they do not represent every enterprise AI provider.
Expect more business functions to adopt agents as tools connect to company data and actions rather than staying in standalone chat windows.
Create a department-level agent register and require an owner, data scope, action scope, approval rule and shutdown path for each workflow.
Employees can automate repetitive research and drafting, while companies can gain speed if access and review are designed around the task.
The data covers OpenAI enterprise users; actual availability depends on the products, plans and integrations a company uses.
Track which departments create agents, what data they access, which actions they can take and whether output quality is measured.
The Fastest Growth Is Outside Engineering
Engineering adopted coding agents early because the workflow is already digital, tool-heavy and measurable. OpenAI’s new data suggests the adoption curve is now steepening in knowledge-work departments instead.
Legal can use agents to gather context and prepare drafts. Sales can connect an agent to CRM history and proposal libraries. Recruiting can summarize candidate information and prepare communications. Marketing can use agents across research, content operations and campaign analysis.
The interesting part is not that AI can help those teams. Chatbots have done that for years. The difference is that agents increasingly connect to tools and complete multi-step work instead of stopping at an answer.
The Governance Owner Cannot Be Only IT
When AI was mostly a software-development tool, central technical governance made sense. Once legal or HR can create an agent that touches sensitive records, ownership has to become shared.
IT should still control identity, integrations, access and monitoring. But the business department has to define what good work looks like, which decisions remain human and what data is appropriate. Compliance may need to define recordkeeping. Security needs to understand the blast radius. The employee using the workflow needs to know when not to trust the output.
Our AI agent wallet guide used six controls for spending: identity, scope, limit, approval, receipt and revocation. The same structure works for non-financial agents too. Replace “budget” with the amount of authority the workflow is allowed to exercise.
OpenAI Usage Is Not the Same as Productivity
This is where the Claim Audit matters. A 108× increase in weekly active users in legal sounds dramatic. It does not prove legal departments became 108× more productive. It does not tell us whether output was correct, whether employees saved time or whether the work created value.
OpenAI itself presents the data as adoption evidence. Robius is treating it the same way. It shows where usage is growing inside OpenAI’s enterprise base. Productivity still needs separate measurement.
That is exactly what UAE companies should do internally. Do not use “more prompts” or “more tokens” as the success metric. Measure cycle time, quality, rework, escalation, customer impact and cost.
A Simple Department-Level Control Sheet
Before a department turns a useful experiment into an always-on workflow, write down the basics. If nobody can answer these questions, the agent is not production-ready.
| Field | What to record |
| Owner | Named employee accountable for the workflow |
| Data scope | Which systems, folders or records the agent can read |
| Action scope | What it can draft, edit, send, create or approve |
| Human review | Which output requires a person before it becomes final |
| Logging | What evidence is kept when the agent acts |
| Revocation | Who can disable the integration immediately |
| Success metric | Time, cost, quality or service measure that proves value |
The Robius Layer
The security lesson from the Meta sandbox incident was that an agent will use the access it receives. As agent adoption spreads beyond IT, the people granting access will become more diverse too.
That is not a reason to centralize every experiment until nothing moves. It is a reason to standardize the boring controls so departments can move safely.
The next AI governance problem is not employees secretly opening ChatGPT. It is departments quietly building operational agents faster than the company builds the rules around them.
Sources
• OpenAI: From assistance to execution: How enterprises put AI to work, August 12, 2026. https://openai.com/index/how-enterprises-put-ai-to-work/
• OpenAI: How agents are transforming work, June 25, 2026. https://openai.com/index/how-agents-are-transforming-work/
Robius.news — Dubai, UAE — 2026 | Built to be first. Built to be trusted.



