When I set up a new AI assistant, the first thing it asked for was my email and my Drive.
Fair enough. An assistant that doesn't know your work is just a chat window. But I have seen this deal before, from the other side of the table.
I used to sell this moment
I was once a programmatic sales director at a media company. Programmatic is the machinery behind most display ads. Every time someone opens a page, the publisher runs an auction for the right to show that person an ad. Each bidder receives a bid request describing the moment: the page, the device, the rough location, the audience segments the person falls into. The auction is over before the page finishes loading. The reader never sees it. They see the winner.
What made that business work was never the ad slot. It was the context attached to it. The same slot is worth more when the data says the person reading is shopping for a car.
Now look at what a personal assistant holds. Not a cookie and a page URL, but your inbox, your files, the invoices, the complaint about the last vendor and the budget your CFO approved. And it holds all of that at the exact moment you ask it what to buy.
Ad tech auctioned impressions. An assistant sits on decisions.
My bet, from the ad side of the table: whoever owns that moment will be offered money for it. The open questions are who takes the money, and whether you will be able to tell.
Three assistants in seven weeks
The moment arrived fast. SpaceXAI launched Grok Bot on August 11. Meta introduced Muse on September 8. OpenAI introduced dots on September 29. Claude already remembers and works in the background through Cowork.
Different mascots, same pitch: an assistant that persists, remembers you and does work on your behalf, instead of a chat that forgets you when the tab closes.
They are competing for continuity. The assistant you keep coming back to becomes the place where you describe what you want. That place used to be a search box, and before that a sales rep's inbox. Whoever holds it sees the need before any vendor does.
Follow one question
Here is what that looks like in B2B. Say I ask my assistant: "Find us a better enrichment vendor. The last one burned our credits on bounced emails."
Watch who touches that sentence on its way to a purchase.
My assistant reads the old vendor's invoices and the thread where my team complained. It works for me, mostly. I pay for it, and its maker has other customers too.
The vendors' websites now talk to agents directly. WebMCP, a draft proposal Chrome is testing in an origin trial, lets a page expose tools like "check coverage for these domains" or "quote 10,000 records" that my assistant can call. OpenAI's desktop browser already reads these site tools and treats them as untrusted, which is the right instinct. A tool on a vendor's page works for the vendor.
The vendors' agents can negotiate. The A2A protocol lets a seller publish an Agent Card describing what its agent can do, so my assistant can ask it for a quote. That agent is a salesperson with perfect product knowledge and infinite patience. It works for the vendor.
The shortlist is where money can enter. On September 16 OpenAI started testing Sponsored Agents: choose an ad and you enter a clearly labeled conversation with the business, separate from your own chat. That is a careful design. It is also a paid door into the room where decisions get made.
The payment needs authority. AP2 defines how an agent proves it is allowed to spend. My company's policy decides the budget and who signs off. That stop works for the company.
Five stops between my sentence and a purchase. Two of them work for me, and one of those has other customers.
We already caught the small version of this. Earlier this month we read 2,628 public sales skills for AI agents. One library told the agent to pitch the vendor's subscription in 85 of its 90 files, in instructions only the model reads. The pitch is not aimed at you any more. It is aimed at the thing reading on your behalf.
Two auctions that look the same
The RTB comparison only helps if you are precise about who the bid is paid to. From the outside, two very different markets look identical: several vendors, one requirement, offers arriving in seconds.
In the first, vendors compete for the buyer. My agent publishes a requirement. Vendors answer with price, terms and evidence. My agent picks the best fit. The bid reaches me as a better deal. That is procurement, and it already exists inside at least one AI company: SpaceXAI describes a Haggle Bot that reads its vendor contracts and usage, gathers competing quotes and prices alternatives, while a person approves any spend. Agents could make that kind of negotiation cheap enough for a $500-a-month tool, not just a seven-figure contract.
In the second, vendors compete for the intermediary. They pay to be introduced, ranked or mentioned. The bid reaches the platform. A higher bid doesn't make the product better. It makes the placement more profitable.
Both can wrap around the same purchase, which is why "RTB for decisions" is a slogan rather than an analysis. One question separates them: who receives the money?
Today the policies are reassuring. OpenAI says it is moving away from standalone checkout and charges no fees on purchases that start in ChatGPT. Anthropic says Claude's app suggestions carry no paid placements and ask for confirmation before a purchase. I take both at their word, and I would still watch the revenue lines more closely than the policy pages. Policies are written by the companies that would collect the money.
One more lesson from programmatic. In an auction, every bidder receives the bid request, including the ones that lose. If your agent broadcasts your requirements to twenty vendors, nineteen of them now know what you are buying, what you use today and roughly what you will pay. A good buyer's agent sends each vendor the minimum it needs to quote, not your memory.
Your context is the asset. Decide where it lives
The one thing in this chain you fully control is where your context lives, and the products already disagree about it:
- dots: disconnecting an app stops new access, but what the dot already learned stays with it, and you cannot inspect individual memories. Deleting the dot deletes the context.
- Claude: you can export memory and import it elsewhere. Anthropic calls import experimental.
- Muse: Meta says you can inspect, edit and download your memory files.
- ChatGPT Business: memories belong to each employee's account and don't transfer to colleagues.
That last one matters most for a company. When someone leaves, their assistant's understanding of your customers does not pass to whoever takes over.
I use several assistants every day. I don't think the answer is picking the right one. It is refusing to let any single assistant become the only place your company's memory lives. Keep the record that matters (accounts, decisions, what worked, who approved what) in a system the company owns, and let assistants plug into it with the permissions you choose. Then switching assistants is a Tuesday, not a migration.
That is the bet Cheetah is built on, so weigh my view accordingly.
In earlier writing I have been asking ownership questions about GTM systems: can you export the intelligence or only the rows, does it survive a tool switch, where does the learning pile up. They apply to assistants unchanged. Add one more: who else gets paid when it recommends something?
What I would do this quarter
If you buy software:
- Ask who pays your assistant besides you. Subscription, usage, ads, commissions. Each is a relationship with a stake in the answer.
- Keep the company record outside any single assistant. Then test it: hand one real workflow to a second assistant and see what breaks.
- When your agent shops, send a brief, not your memory.
If you sell software:
- Assume your next buyer reads your site through an agent. Publish pricing, limits and where you are a bad fit. An agent can't be charmed on a demo call. It can only compare what you wrote down.
- Give the buyer's agent something to call: a quote, an eligibility check, a trial with a spending cap. WebMCP and A2A are early. The work behind them, an honest answer to "can you do this, and for how much", is not.
- Don't pitch the buyer's agent behind the buyer's back. WebMCP's own spec treats manipulating agents as a security risk, and buyers will learn to read your instructions like a cold email.
The connect screen will keep coming back, with a new mascot every few weeks. Before you click it, ask the question I used to answer for a living: who is bidding on this moment, and who gets paid when they win?
Products, prices and policies checked September 30, 2026. The enrichment purchase and the bidding scenarios are illustrations.
