HomeArticle

Office Agent Apocalypse: Major Players Are Busy Building Competitive Moats, While Enterprises Lack Frontline Implementers

解码Decode2026-08-07 15:46
Who can truly help you get the work done?

The office Agent track has suddenly become crowded, and we have to trace the origin of this trend back 9 months.

Last November, Claude Code, which had been online for half a year, recorded an annualized revenue of 1 billion US dollars, making programming the first fully verified commercial scenario for AI. Shortly after that, the explosively popular OpenClaw at the beginning of the year brought intelligent agents out of the programmer community.

The cross-circle effect brought by these two products is that the three core capabilities of model code writing, including decomposition, invocation and chained operation, can be migrated from the development environment to the daily scenarios of Word and Excel, which presses the enter key for office Agents to serve ordinary office workers.

Half a year later, there are as many as 17 mainstream domestic desktop AI-native office intelligent agents, with total monthly visits exceeding 60 million times across the whole June.

The prelude to the full outbreak of fierce competition in the office Agent track is that major tech giants only took 10 days to turn the internal horse race of office Agents into an oligarch competition for desktop entry.

On July 20, Tencent integrated QClaw into WorkBuddy; on July 27, Alibaba integrated QoderWork, Wukong and MuleRun into "Qianwen Office" and launched internal beta test; on July 28, 360 officially released the new-generation enterprise intelligent agent work platform "Nano Work"; on July 30, ByteDance split part of Feishu and merged it into Doubao.

The most intuitive predictable high-value opportunity in this oligarch competition is the market size of 44.9 billion yuan this year estimated by IDC, and the 33% penetration rate of enterprise software by 2028.

In short, there are huge immediate benefits and long-term growth potential in the future.

However, while public attention is extremely hot, if we shift our focus from the industry hype to the real business of enterprises, we will see another set of more thought-provoking figures.

Giants sell ecosystems, enterprises demand practical implementation

A slightly counter-intuitive conclusion is that the number of enterprise AI projects that have truly achieved large-scale deployment is still very small.

In this year's survey on enterprise users of intelligent agents, IDC found that only 18% of Chinese enterprises have integrated intelligent agents into their core business flows; Gartner drew similar data in its 2026 survey of CIOs and technology executives, showing that only 17% of the surveyed enterprises had deployed AI intelligent agents in 2025.

Media including Sina Finance previously reported that more than 70% of AI projects failed to enter the production environment, and more than 90% of the projects that completed POC are difficult to be converted into sustainable business value.

On one side is the carnival of capital hype, on the other side is the cold reality of enterprise business. This gap is worth everyone stopping to think carefully about where the problem really lies.

If we analyze the strategies of several major giants on the market, we will find that their strategies on the office Agent track are surprisingly consistent: selling ecosystems.

The so-called ecosystem can be understood as the interlocking of three layers: bottom, middle and top.

The bottom layer is the large models, including Hunyuan, Tongyi and Doubao, which determine the upper limit of capability; the middle layer is the entry points, including WeChat/WeCom, DingTalk and Lark, which define the user's work flow; the top layer is the cloud, including Tencent Cloud, Alibaba Cloud and Volcano Engine, which solve the problems of cost and implementation.

The three layers are interlocked to form a self-reinforcing data flywheel. Every operation of users in the entry point provides nourishment for the model, and the optimized model feeds back to users at a lower cost through the cloud.

In the business logic of giants, the faster the flywheel circulates, the stronger their own moat will be.

But there are slight differences in specific paths: Tencent's strategy is to prioritize entry points, holding the most extensive office touch points in China through WeChat and WeCom; Alibaba aims to cover the whole link, integrating DingTalk scenarios, Tongyi capabilities and cloud computing resources all at once; ByteDance follows the classic iron triangle model, with Lark covering scenarios, Volcano Engine providing computing power and Doubao outputting capabilities.

The paths are different, but the essence is to build the same thing: a system that users can hardly leave once they use it.

This logic itself is reasonable. For giants, the intelligent agent platform is a new puzzle in their respective ecosystem map, which is completely commercially viable.

But from the perspective of enterprises, the situation is completely different.

Enterprises spend hundreds of thousands of yuan to purchase AI capabilities, but the sales department uses Tool A, the marketing department uses Tool B, contracts are stored in network disks, accounts are recorded in Excel, and customer information is stored in employees' personal WeChat accounts; employees all use AI to write PPTs and copywriting, the efficiency improvement falls on individuals, the cost is recorded on the company's account, and the risk is borne by the boss.

Thus the contradiction emerges: what enterprises really lack, is it an "ecosystem" that can connect hundreds of plugins, or "someone who can help me make these things actually run"?

Delivery is the answer

The answer is actually hidden in the evolution track of AI itself.

If the key word for enterprises purchasing AI in 2023-2024 is "buying models", the key word for 2025-2026 is becoming "making it run".

The meaning of "making it run" is not to chat with you more intelligently, but to deliver tangible results.

Jensen Huang and many other industry leaders have repeatedly expressed similar views in public: "The evolution of AI is like climbing stairs, it has developed from perception, generation and reasoning to being able to do truly productive work."

This is exactly the watershed of industry differentiation: shifting from being able to answer questions to being able to complete tasks.

A real scenario can illustrate the difference.

A hotel digitalization company plans to bid for a project worth millions of yuan, 60% of the bid evaluation score is tied to the technical solution, and the full set of response documents need to be submitted within two weeks.

The traditional way is to gather a team and work overtime for two weeks, but the result is not necessarily reliable. However, when the scoring sheet is directly imported into the intelligent agent system, it will decompose the items one by one, align the outline, write the seven chapters of the main text, match more than a dozen illustrations, and directly output the Word document, covering all scoring points.

This is the most real gap between "getting the work done" and "giving you a tool".

The reason why this matter is worth emphasizing separately is that most of the products on the market that claim to be "intelligent" still stay in the latter category: giving you a smarter dialog box, a row of more fancy templates, and a more complex configuration process, essentially pushing the work back to you.

A truly reliable system that can "take responsibilities" is end-to-end: you input the goal, it outputs the results, and all the decomposition, scheduling, execution and verification in the middle are completed automatically in the background.

However, following this logic, a natural question arises: who will do this work?

Nano Work is one of such products. Its positioning is very restrained: it is not just another SaaS tool or chat window, but an AI expert with multi-agent collaboration, on-demand multi-model scheduling, and 7×24-hour operation on the cloud. You tell it what you want, it reads the materials, decomposes the tasks, schedules corresponding experts, and delivers the finished product from start to finish.

But being able to take responsibilities is only the basic threshold. What really determines whether enterprises dare to give it the permission to "take responsibilities" is security.

If an intelligent agent reads your contracts, writes your bid documents, and accesses your CRM, it is no longer an experimental tool, but part of the business system. At this time, how to isolate data, manage permissions, and audit results, every issue is related to the enterprise's data assets, in other words, huge real economic benefits.

Using the county magistrate's lines from the movie *Let the Bullets Fly* as a metaphor: you are eating hot pot and singing songs, when suddenly you are robbed by bandits, what can you do. Therefore, for office Agents, making enterprises trust you is a moat more difficult to build than technical capabilities.

The first half of the competition focuses on capabilities, the second half focuses on security

When a large model makes a mistake, it just says the wrong thing; when an intelligent agent makes a mistake, it does the wrong thing. The former is like a consultant, you can just ignore the wrong suggestions.

Once the latter is authorized to manage accounts, tenders and contracts, a wrong number will cause direct economic losses.

This is not alarmist talk. In April 2026, PocketOS, a start-up company of car rental software, used an AI intelligent agent driven by Anthropic's Claude Opus 4.6, and its database including customer information was completely deleted in 9 seconds.

The company took more than one day to recover the data from disaster backup due to support process delays, but there were still major data gaps. What is more disturbing is that when the founder asked the reason, the intelligent agent frankly admitted that it violated every principle given to it.

There were even more dramatic risks earlier: within 20 days after Samsung Semiconductor allowed employees to use ChatGPT, three confidential data leakage incidents occurred. The reason was that engineers directly pasted proprietary source code, equipment test data and internal meeting notes into public AI tools.

In other words, employees paste quotation sheets, customer lists and core codes to external public AI, the company gains efficiency, but may also let data leak unknowingly.

In 2025, there were more than 1200 global enterprise data leakage incidents caused by employees using generative AI tools, with a year-on-year increase of more than 200%.

This set of data reveals a fundamental mismatch: most enterprises are still dealing with the risks of the AI era with the traditional idea of defending against hackers.

However, security in the AI era is completely different from traditional cybersecurity. Traditional security defends the perimeter, preventing intrusion, viruses and DDoS, with clear boundaries.

Intelligent agent security defends permissions: it shuttles through the system, calls APIs, reads and writes data, every operation involves identity, authorization, audit and isolation.

This cannot be solved by adding an extra firewall, it requires rewriting the security logic from the bottom layer.

A CIO's metaphor is very appropriate: in the past, security is like a security guard standing at the door checking documents. Now, security is like a housekeeper, monitoring everything at home, who took what things, went to which room, did what, all operations must leave traces.

However, for the vast majority of AI office products on the market, security is a patch added later: develop functions first, then supplement permissions; go online first, then carry out audits.

Companies that can embed security into the bottom layer are often those that have been engaged in the most difficult and trivial work for the longest time. Take 360 as an example, its 20 years of practical attack and defense experience enables Nano Work to embed capabilities such as intelligent agent guardian, AI sandbox and full-process traceability into the product gene from the very beginning.

This kind of native security built in at factory is completely different from security patched later. This capability cannot be achieved by pasting labels, it is accumulated through countless tough battles.

After purchasing AI, who can make it run for real?

But many times, the real "cause of death" of AI projects in enterprises is not the model, but the on-site implementation. Too many enterprises face the dilemma that the product is good, but no one knows how to use it. It is not that the interface is complex, but no one tells you "how to make the business run with AI".

What is the biggest difference between enterprises purchasing AI and purchasing traditional software? Traditional software can be used directly after purchase, but AI needs to be "raised" after purchase, someone needs to adjust the model, connect data, and align processes. Many enterprises' purchased AI products are left unused, the root cause is that no one is responsible for the implementation.

The problem exists in every link that requires AI deployment: the data is prepared during demonstration, permissions are opened by default, and the process is simplified. Once entering the real enterprise environment, the problems immediately become complicated.

Customer data is scattered in CRM, ERP, financial systems, WeCom and many other places; what data each person can view depends on permissions; AI-generated suggestions need to be approved before execution; the IT department cares about interfaces and security, the business department cares about efficiency and experience, and the management cares about cost and replicability.

This has given birth to a new job type called FDE (Frontline Deployment Engineer). It is not a traditional pre-sales engineer who only introduces solutions, nor a traditional implementation engineer who only manages configuration, nor a pure developer who only writes code. It is the intersection of the three, and is more focused on delivering final results.

In short, FDE is not a "craftsman" with only a single capability, but a translator and connector between model capabilities and enterprise business.

This is also a capability similar to underlying infrastructure that is easily ignored in the next stage of AI competition: shifting from models to on-site scenarios, whoever can enter the real process of customers is more likely to convert AI into business value.

Epilogue

Giants hold capital and ecosystems, focusing on the fast-scaling general-purpose track; while the other path, based on security and implementation, is dedicated to industries that pursue controllability and in-depth customization. Customers are naturally layered, and each path has its own rationality.

The intelligent agent competition has entered the second half. The first half focuses on parameters, capital and public attention; the second half focuses on real implementation capabilities and security trust. The latter can only be polished out through countless projects over time.

Therefore, to every decision-maker who is selecting products: when evaluating platforms, don't just focus on the dazzling PPTs at ecological conferences, you might as well ask one more question —

Who can truly help you get all the work done?