I was M I A for a week. Some of that was personal stuff. Some of that was taking care of normal family life. And honestly, some of it was camping by the beach with my wife, the kids, and the dogs. Which sounds peaceful. And parts of it were. But beach camping with kids and dogs is not really vacation. It is logistics theater with sand. There are snacks. There are towels. There are more towels. There is one dog making a questionable governance decision near a tide pool. And at some point, you realize the entire family operating model is being held together by a cooler, a flashlight, and one parent who knows where the dry socks are. So yes. I was away. I was doing life. And while I was doing life, the AI week did what the AI week does now. It kept moving. Very rude. Honestly. No respect for the out-of-office. OpenAI pushed Codex further into mobile and remote work. ChatGPT moved into connected personal finance workflows. Google described Gemini Intelligence spreading across Android devices. Anthropic expanded Claude deployment with PwC. And OpenAI launched a deployment company. That is not five separate stories. That is one operating problem. The work is following people away from the desk. Onto the phone. Into the browser. Across devices. Into connected accounts. Into enterprise deployment programs. Into the places where people are tired, in motion, half watching a kid chase a dog across a campsite, and still somehow expected to make a clean approval decision. So today’s question is not: Can AI help us work from anywhere? That question is too small. The better question is: What is allowed to move when the owner is away? What has to wait? What needs a second human? What creates evidence? And who can stop the workflow before the raccoon gets admin rights? Yes. The raccoon is back. Apparently it survived episode twenty-four. Bad for the campground. Useful for the metaphor. This is the away-mode control check. Not always-on management. Not panic-refreshing Slack from a beach chair. Not turning PTO into a distributed incident-response simulation. Away-mode control. The operating discipline that says: when the person is away, the rules still know what to do. Welcome back to AI Change Desk. I am Michael. Today is Monday, May eighteenth, twenty twenty-six. Quick disclosure before we get into it. AI-assisted tools were used in parts of the research and production workflow. Final editorial judgment, risk posture, and release approval stayed human-led. This is operational guidance, not legal advice. These are my opinions, and are not representative of any organization. As I am source-checking this on Sunday night, May seventeenth, the timing matters. A few of these announcements are only days old. Some are staged rollouts. Some are company claims. Some are product previews. So the posture today is simple: we are not treating vendor announcements as proof of outcomes. We are treating them as signals. And the signal is loud. AI work is no longer staying politely inside one tab, one desktop, one tool, or one approval meeting. It is becoming a moving surface. And moving surfaces need better rules. Here is the continuity. Episode twenty-two was the access lifecycle check. The point there was: access is not just approved or denied. It moves through approved, pilot, sunset, and blocked. Episode twenty-three was the trust boundary check. The point there was: if AI becomes infrastructure, somebody has to own the boundary. Episode twenty-four was the delegation quality check. The point there was: when agents do the work, someone still has to certify the work. Today is the next layer. If access has a lifecycle, trust has a boundary, and delegation needs quality control, then away-mode needs rules. Because people leave the desk. They travel. They get sick. They take care of family. They go camping. They try, very nobly, to become a person again for seven days. And the systems do not stop. The systems are not emotionally moved by your cooler setup. So the control question becomes: what happens when the work keeps moving, but the normal owner is not sitting there watching it? That is where we start. First signal. OpenAI Codex from anywhere. On May fourteenth, OpenAI announced that Codex work could be handled more directly from ChatGPT mobile. The product framing is convenience. Start work. Check progress. Respond to questions. Review outputs. Keep tasks moving while you are not at your workstation. And from a user perspective, that sounds great. Because it is great. There are real moments where a mobile check-in saves an hour. There are real moments where you do not need the big desk setup. You just need to unblock one thing. The problem is that unblocking one thing is how the goblin enters the process. Because the phone is not just smaller. It is a different decision environment. You are walking. You are between meetings. You are with family. You are in a parking lot. You are half reading a diff on a screen the size of a Pop-Tart. And the interface is asking: approve this? continue? merge? run? change scope? That does not make mobile agent work bad. It makes it governed. The control problem is not whether Codex can help from anywhere. The control problem is what kind of decision should be allowed from anywhere. Read-only status checks are one category. Draft feedback is another category. Command approval is another category. External release is another category. Merge authority is another category. And if those categories all collapse into one little button that says continue, your control design is doing yoga in a hurricane. So the operator takeaway is this. Mobile access needs an approval ceiling. Not a vibe. Not a trust-me setting. A ceiling. From mobile, can a user read status? Can they comment? Can they approve a test run? Can they approve a code change? Can they merge? Can they ship? Can they connect a new system? Can they change the agent instructions? Can they expand permissions? Every one of those is a different risk tier. If your policy treats them the same, your policy is not a policy. It is a motivational poster with Wi-Fi. Second signal. Connected personal finance in ChatGPT. On May fifteenth, OpenAI introduced a U.S. ChatGPT Pro preview for personal finance. The announcement describes connecting financial accounts through Plaid, with support for more than twelve thousand institutions, and additional Intuit Credit Karma support coming soon. OpenAI also says ChatGPT is not a replacement for a professional financial advisor. That caveat matters. Now, this is not a financial advice segment. I am not here to tell anyone what to do with their money. My own financial advice is usually: look at the subscription list, feel personally attacked, and then close the laptop. The operating signal is bigger than personal budgeting. This is connected sensitive context inside an assistant surface. Account data. Transaction history. Spending patterns. Financial questions. Personal goals. All inside a conversational interface that feels casual. And casual interfaces are powerful because they lower friction. They are risky for the same reason. They lower friction. Sensitive data plus low friction is not automatically bad. But it is never neutral. For organizations, the lesson is not: should employees use this exact consumer finance preview? The lesson is: your business tools are heading in the same direction. Connect the assistant to the records. Connect it to the systems. Let the user ask natural questions. Let the answer appear in plain language. That is useful. That is also exactly where governance gets weird. Because the assistant stops being a search box. It becomes a window into connected context. So your away-mode question changes. If a workflow touches connected sensitive data, what can happen when the primary owner is offline? Can the assistant summarize? Can it recommend? Can it draft? Can it export? Can it send? Can it update a record? Can it trigger a transaction? Can it create a report that leaves the company? Those are not the same action. They do not deserve the same button. And they definitely do not deserve the same sleepy approval at nine forty-seven at night, while someone is trying to remember where the dog leash went. Third signal. Gemini Intelligence across Android. On May twelfth, Google announced Gemini Intelligence as a new AI experience across Android devices. The announcement points across phones, Chrome, Wear OS, Android Auto, Google TV, X R, and glasses. The availability is staged, so do not hear this as everything everywhere today. Hear it as direction of travel. The device layer wants to become an AI layer. That changes the operating surface. The phone is not just where the app lives. The phone becomes part of the workflow. The browser becomes part of the workflow. The watch becomes part of the workflow. The car becomes part of the workflow. The glasses become part of the workflow. Which is great, because apparently what my life was missing was procurement risk in sunglasses. Again, not bad. Useful. But useful things need boundaries. Google’s announcement even talks about confirmation before completing sensitive tasks in the Chrome auto-browse context. That is the right instinct. But the operator question is broader. What counts as sensitive? Who defines it? Does the definition follow the user across devices? Does it follow the task across apps? Does it follow the data when it leaves the original system? If the assistant can use screen context, image context, browser context, and account context, then your control map cannot stop at the application boundary. It has to describe the task boundary. The old question was: which app is approved? The new question is: which task is approved, on which surface, with which data, under which confirmation rule? That is much less fun to put on a procurement form. But it is the form we need. Because when AI is embedded across the device, you cannot govern it as if it is still a single destination website. The work surface is moving under your feet. Fourth signal. Anthropic and PwC. On May fourteenth, Anthropic announced an expanded partnership with PwC. Anthropic says PwC plans to roll out Claude Code and Cowork, starting with U.S. teams and expanding toward a global workforce of hundreds of thousands of professionals. The announcement also describes a joint Center of Excellence, a program to train and certify thirty thousand PwC professionals, and a new AI agent operating model. That last phrase matters. AI agent operating model. Because this is where the story gets out of demo-land. The hard part is not buying access. The hard part is changing how people work, how work is reviewed, how client-facing material is approved, how evidence is retained, and how the organization explains what happened later. A scaled rollout is not a feature launch. It is a change-management program. It is training. It is role design. It is review design. It is communications. It is exception handling. It is all the boring stuff. And the boring stuff is where the adults live. This is also where away-mode control matters. When hundreds of thousands of professionals have access to stronger assistant workflows, what happens when the local owner is unavailable? Who becomes the delegate? What can the delegate approve? What must wait for the original owner? What evidence gets captured automatically? What does the client-facing boundary look like? And when a workflow crosses from internal draft to external artifact, who owns the last check? The answer cannot be: someone should probably look at it. That is not governance. That is a haunted Post-it note. Fifth signal. OpenAI Deployment Company. On May eleventh, OpenAI announced The OpenAI Deployment Company. The announcement includes a four billion dollar initial investment, plans to acquire Tomoro, and a plan to hire around one hundred fifty forward-deployed engineers. Again, we should treat that as an announcement, not outcome evidence. But as a signal, it is useful. Deployment is becoming its own layer. That matters because a lot of organizations still talk about AI like the work ends when the tool is selected. Pick the model. Pick the vendor. Approve the contract. Celebrate lightly. Maybe buy pastries. Then somehow the organization is supposed to turn that into operating value. This is also how people buy treadmills. The purchase is very inspirational. The operating model is the problem. A deployment company is a clue that the market understands what operators already know. Implementation is not a side quest. Implementation is the game. And if implementation is the game, then your control design has to follow the implementation work. Who configures the system? Who signs off on the workflow? Who validates the data boundary? Who tests the fallback? Who trains the team? Who updates the job aids? Who owns the exception log? Who decides a workflow is ready for production? And because this is today’s theme, who owns it when the normal owner is away? So let’s bring the five signals together. Codex from anywhere says AI work can keep moving from a phone. Personal finance in ChatGPT says connected sensitive context is moving into the assistant surface. Gemini Intelligence across Android says the device layer is becoming a workflow layer. Anthropic and PwC says scaled professional deployment is moving from pilots into operating models. OpenAI Deployment Company says implementation itself is becoming a formal AI layer. The common thread is not speed. The common thread is surface expansion. More places to start work. More places to approve work. More places to connect data. More places to carry context. More places to make a mistake that looks like normal productivity until someone asks for evidence. That is the away-mode problem. Not whether people should be able to work anywhere. They already can. The problem is whether your controls understand anywhere. Here is the practical move for this week. Run a forty-five minute Away-Mode Control Check. Not a giant governance workshop. Not a four-month operating model redesign with a steering committee named something expensive. Forty-five minutes. One worksheet. One live workflow. Pick one AI-enabled workflow that already matters. Not the shiny demo. Not the safe sandbox. The one people actually use when there is pressure. A sales draft. A support response. A code change. A financial analysis. A client deck. A compliance summary. A research memo. A content release. Then answer seven questions. First: Which surfaces can trigger the workflow? Desktop. Mobile. Browser. Chat. Device assistant. A connector. A vendor team. An automation. Write them down. If the answer is, we are not sure, that is the first finding. Second: What action state can the AI reach? Read. Summarize. Draft. Recommend. Edit. Execute. Send. Merge. Purchase. Update records. Delete. Publish. Do not let all of those hide under the word assist. Assist is not a control category. Assist is where categories go to die. Third: What changes when the owner is away? Does the workflow pause? Does it continue read-only? Does it route to a delegate? Does it require a second approver? Does it create an escalation? Does it time out? Does it keep going because everyone assumed someone else configured the policy? That last one is popular. It is also terrible. Fourth: What evidence is created automatically? Who asked? What did the AI access? What did it draft? What did it change? Who approved? From which surface? At what time? Under which policy? If you cannot reconstruct the decision later, you did not govern the workflow. You watched it happen. Fifth: What data class is touched? Public. Internal. Confidential. Regulated. Customer. Employee. Financial. Health. Legal. Source code. Credentials. Board material. If the workflow touches sensitive data, away-mode should get stricter, not more convenient. Sixth: What final confirmation is required? No confirmation for low-risk read-only tasks. Light confirmation for internal drafts. Named human approval for external sends. Second approval for regulated or irreversible action. Explicit no-go authority for anything that can damage customers, money, legal posture, security, or reputation. Seventh: Who can stop it? Not conceptually. Not culturally. Operationally. Who has the button? Who has the authority? Who has the backup authority? What happens after hours? What happens when the owner is camping, and the dog has eaten something that was absolutely not part of the meal plan? That is the check. Seven questions. One workflow. Forty-five minutes. If you want the shorter version, use this: what can move, what must wait, what creates evidence, and who can stop it? Then set three default rules. Rule one: mobile approval ceiling. Decide what cannot be approved from a phone. That may sound old-fashioned. It is not. It is acknowledging that not every screen is a good decision room. I personally should not approve enterprise architecture while holding a paper plate in coastal wind. This is growth. Rule two: sensitive connector rule. If an AI workflow touches connected sensitive data, it needs stronger logging, clear export limits, and stricter action boundaries. Summarize is not the same as send. Recommend is not the same as execute. Draft is not the same as publish. Those differences are the control system. Rule three: offline owner fallback. Every important AI workflow needs a named fallback. Not a department. Not an inbox. A person, or a role with an actual rotation. If the owner is unavailable, the workflow either pauses, routes, or downgrades. It should not improvise. The AI can improvise language. The operating model should not improvise authority. The bigger point is this. A mature AI program should let people step away. That is not a soft lifestyle note. That is an operational maturity test. If the only thing keeping the workflow safe is one person checking every message, every approval, every draft, every artifact, then you do not have a control system. You have a person with a laptop and a slowly deteriorating nervous system. That is not scalable. It is also not humane. AI governance cannot secretly depend on never logging off. That is not governance. That is a hostage situation with calendar invites. So yes, I was M I A for a week. Some personal things. Some family things. Some beach camping. Some dogs. A heroic amount of sand. And I came back to the same conclusion I keep landing on in this show: the goal is not to slow everything down. The goal is to make the system clear enough that useful work can move safely, and risky work knows when to stop. When you are away, the map still matters. The rules still matter. The evidence still matters. The fallback still matters. And the stop button definitely matters. So this week, run the Away-Mode Control Check. Pick one live AI workflow. Map the surfaces. Classify the action states. Define what happens when the owner is away. Confirm the evidence. Write the sensitive-data rule. Set the mobile approval ceiling. Name the fallback. And make sure someone can stop the thing before it becomes a raccoon with procurement authority. That is the show. Welcome back from wherever you have been. If you have been at the desk the whole time, please go outside for eight minutes. If you have been away, I hope the return is gentle. And if you are building AI workflows, make them strong enough that a human can go camping without turning the beach into a command center. I am Michael. This is AI Change Desk. I will see you in the next episode.