Autonomous computer operation has crossed a reliability and cost threshold that is forcing Microsoft, Salesforce, and ServiceNow to open MCP and agent interfaces they once controlled, as frontier model releases accelerate the shift.
Autonomous computer operation has crossed a reliability and cost threshold that is forcing Microsoft, Salesforce, and ServiceNow to open MCP and agent interfaces they once controlled, as frontier model releases accelerate the shift.

The software industry's oldest assumption — that machines enter applications only through doors vendors choose to build — is breaking apart after OpenAI, Anthropic, and Google shipped new frontier models within three days, each pushing autonomous computer operation past a reliability and cost threshold that application makers spent years betting AI could not cross.
"Computer Use is no longer a fallback when an API is missing — it is becoming a first-class way for agents to enter software," said Adam Evans, who led AI product work at Salesforce before the company began exposing its workflows to external agents. "Software vendors are realizing that if they do not build the machine entry point, the agent will find its own way in through the screen."
OpenAI's GPT-6 Astra, released Sept. 3, scored 72.6 percent on OSWorld 2.0, a benchmark that tests whether a model can complete multi-step tasks across real desktop applications, up from 65.7 percent for its predecessor GPT-5.6 Sol. On ScreenSpot-Pro, which measures visual targeting and click accuracy, Astra jumped to 92.7 percent from 76.9 percent, and OpenAI said it completes OSWorld tasks in about 40 minutes versus roughly 75 minutes for Sol. Anthropic's Claude Fable 5.1, out Sept. 1, reached 77.9 percent on the same OSWorld release, while Google shipped Gemini 3.8 Flash on Sept. 2, its third Flash model in six weeks, aimed at "long-horizon coding and autonomous agents."
The capability jump matters less than what it unlocks. For years the software industry ran on a clean division of labor: humans entered applications through a graphical interface, machines through an API that the vendor chose to expose. That wall is eroding. Astra can now operate professional tools directly — filling CRM records, updating spreadsheets, driving Blender and Unreal Engine 5, even laying out printed circuit boards in KiCad — while deciding on its own whether to call an API, drive a browser, run code, or click through a GUI. A new "async tool calling" feature lets the model keep reasoning and invoke other tools while one is still running, closer to how a person juggles tasks.
The economics shifted in the same window. Anthropic cut cache-read prices by 75 percent to 25 cents per million tokens, which it estimates lowers the cost of highly agentic workloads by up to 45 percent. OpenAI prices Astra at $10 per million input tokens and $50 per million output tokens, matching Fable 5.1, but argues the relevant metric is cost per completed task — on the DeepSWE v1.1 coding benchmark, it says Astra's top configuration cuts estimated API cost per task by about 57 percent versus Sol. Game studio Playco, which plugged Astra into its Playbot development tool, told OpenAI it cut manual fixes by 50 percent when the model operated Unity and Godot engines directly.
The response from enterprise software is the clearest sign the balance of power is shifting. Microsoft Chief Executive Officer Satya Nadella said in July the company is exposing more than 650,000 actions in Dynamics 365 through the Model Context Protocol, letting agents execute under the same data model, permissions, and audit trail as human users, while its pricing model moves from pure seat-based licenses to seat plus consumption. ServiceNow opened its Action Fabric in May so external agents such as Claude can trigger workflows like password resets that previously required logging into the ServiceNow interface. Salesforce's Evans has argued that autonomous agents will become the new user interface, with applications demoted to "systems of record" rather than "systems of navigation."
None of this means APIs disappear, or that agents bypass security. Astra does not gain permissions a user lacks — multifactor authentication, single sign-on, and administrator rights still apply, and OpenAI notes its "critical" cybersecurity rating under its Preparedness Framework applies only "with the right tools and access." Astra is the first model to hit that threshold, scoring a perfect 100 percent on ExploitBench and discovering two previously unknown zero-day vulnerabilities during evaluation, which OpenAI disclosed to maintainers. Its most advanced cyber capabilities are restricted to vetted defenders through the Daybreak program.
What vendors are losing is subtler: the power to define where a user enters, which page opens next, and in what order work gets done. When an agent can reach any function a human can reach on screen, "no API" no longer means "AI cannot operate my software." That is why Microsoft, Salesforce, and ServiceNow are racing to make their formal interfaces the preferred path — a highway an agent chooses over off-roading through the GUI, rather than the only road that exists.
The winners and losers will be decided by who controls the machine entry point. Microsoft, with its 650,000 exposed actions and seat-plus-consumption model, is betting it can monetize agent usage on top of its installed base; pure-play SaaS vendors that monetize navigation rather than data risk seeing agents route around their interfaces. For investors, the shift rewards infrastructure and platform owners that capture agent-driven consumption, while pressuring application vendors whose value rests on being the default front door. OpenAI's Brockman framed the moment in starker terms, closing the Astra briefing with "Welcome to the AGI era" — a claim that rests, in part, on a model that can finally do the clicking itself.
This article is for informational purposes only and does not constitute investment advice.