跳到正文
非凡资本

UNIQUE RESEARCH / ENGLISH ARTICLE

Once AI Starts "Going to Work," What Becomes Enterprises' Biggest Headache?

Original · Unique Research · 2026-04-22

Editor's note: The first-person report and its judgments belong to the original Chinese author. This English rendition retains the opening essay, all section headings, the full guest roster, and the complete panel transcript. ROI, outcome-based pricing, customer-case, reliability-math, market-sizing, and financing figures are source or speaker claims, not independently audited findings. Company, personal and work titles are transliterated where official English forms remain unverified. OpenClaw is retained as the source's product name. SOAR (Security Orchestration, Automation and Response) and AOP (Agent Operation Process) retain the source's technical wording. The "12 months" prediction and "last technological revolution" rhetoric are speaker opinions, not established forecasts. The source is dated April 22, 2026.

Unique Awards

What Enterprises Really Need Is Not a Smarter AI

But a "digital employee" that can enter the organization, carry a KPI, and be audited

What enterprises really need is not a smarter AI.

But a "digital employee" that can enter the organization, carry a KPI, and be audited.

Over the past two years, many enterprises have talked about AI. On the surface, they talk about models, memory, permissions, and security.

But if you actually go to the front lines and look around, you will find that bosses do not really care about these words themselves.

What they truly care about is actually just one sentence:

Can this thing really enter the organization, do work for me, and not cause trouble?

This feeling was especially obvious at a recent trends roundtable at Unique Awards · Hangzhou AI WEEK.

The panel was titled "Memory, Security, and Collaboration in Enterprise Service Scenarios," but throughout the entire session, everyone was actually answering the same question:

Should enterprises treat AI as a tool, as an employee, or as the future organization itself?

Once this question is figured out, many things that seem tangled together become clear.

Why customers are suddenly much more realistic this year than last year.

Why security problems cannot be solved only by "restricting permissions" or "blocking the external network."

Why the companies that ultimately succeed are not the ones whose models sound the loudest, but the ones who understand the industry best and dare to take responsibility for results.

At this roundtable, the several guests had different entry points, but their underlying judgments were actually quite similar:

Enterprise-grade AI has moved from "can it be done" to the stage of "what result does it produce, who takes responsibility, and how does it enter the organization."

This Year, Enterprises Buying AI No Longer Buy Stories

At the beginning of the roundtable, the moderator asked each guest to use one word to summarize the issue enterprises care about most right now.

Zhao Ming of FutureAI said: value.

Yang Hongkai of Dudao Tech said: effectiveness.

Liao Can of Yuhe Tech said: results.

Jin Lijian of Yingdao was more direct, giving one word: All in.

The four people phrased it differently, but the meaning was actually quite consistent.

Last year, many enterprises looked at AI and still said "let's research it first."

First see what peers are doing.

First run a pilot.

First write it into a report.

First organize a few rounds of discussion.

First, don't rush to actually implement it.

But this year is clearly different.

Zhao Ming put it very directly: customers now are not talking about "whether AI helps the enterprise," but want the ROI calculated clearly: exactly how much cost was reduced, how much efficiency was improved, and what the accuracy rate is.

Yang Hongkai also mentioned a very key change. In the past, when many large enterprises bought SaaS, it was often initiated by the IT department or the technology department; but now, more and more, business departments are actively initiating procurement, and not buying by license, but buying for effectiveness and service.

This is not a small change—it means the logic of enterprises buying AI has changed.

Before, it was more like an IT project.

Now, it is increasingly like a business operation.

Once it becomes a business operation, enterprises only watch two things:

First, how much more money did you help me make?

Second, how much less money did you help me spend?

If you cannot answer these, no matter how lively the story is, it is useless.

So Liao Can's word "results" is also very typical.

He said they do not make software, nor do they make tools—they make digital employees for individual positions, directly entering enterprises to "go to work," completing white-collar work end-to-end, and finally sharing revenue based on business results.

Behind this sentence is actually the most real mindset of enterprises today:

I am not here to buy an AI that can chat. I am here to buy an AI that can deliver results.

What Enterprises Fear Most Is Not That AI Is Not Smart Enough

But that it is very smart, yet you have no idea what it is doing

When enterprise AI comes up, everyone's first reaction is often security.

But the interesting thing about this roundtable is that the guests were not talking about the old kind of security problems.

They were not simply saying "should we privatize" or "can we cut off the external network," but were redefining:

In the AI era, what actually counts as security?

Zhao Ming himself has worked in cybersecurity and data security for many years. When he talked about this issue, he did not stop at surface-level discussions like "permissions are too broad, data is too much," but first broke the problem apart:

Today, the thing you are asking AI to do—if it messes it up, what category does the consequence fall into?

Some mistakes don't matter.

Some mistakes can still be fixed.

But there are others where, once wrong, the consequence is simply unacceptable.

This passage left a deep impression on me.

Because it immediately pulled "security" from an abstract concept back to business consequences.

Many companies, as soon as they talk about security, start spinning their wheels:

Are permissions too broad?

Will there be leaks?

Is it a black box?

Can it be completely sealed off?

But the truly mature way to ask is actually:

If AI gets this wrong, what price does the enterprise actually have to pay?

If it is just giving suggestions, polishing copy, or drafting something, then a little error may be acceptable.

But if it touches funds, core systems, or heavily regulated processes, that is a different matter.

Zhao Ming's subsequent set of views left a deep impression on me.

First, do not treat AI only as a tool—treat it as a "digital employee."

Since it is an employee, it should have an organizational structure, permission boundaries, and data it can and cannot see.

Second, enterprises must definitely do data classification and grading.

Which data can flow, which requires approval, which cannot leave the intranet—all must follow business logic.

Third, key nodes must retain final human confirmation.

Especially when it comes to key actions, the final button must be clicked by a human.

The most valuable part of this line of thinking is that it did not frame "the stronger the capability, the greater the risk" as an unsolvable paradox, but turned it into an organizational governance problem.

Not blindly locking AI down.

Not giving it all permissions just because it is smart.

But managing it like an employee.

Zhao Ming later mentioned another very important point.

In the past, the security industry's attitude toward third-party plugins was often "default untrusted," but now many people, when facing AI products like OpenClaw, instead take a "default trusted" stance. This is actually very dangerous. What enterprises should truly build in the future is a zero-trust approach—never trust, always verify. Andso-called verification is not just about the model itself, but that its entire execution process must be traceable, observable, and auditable. You may choose not to check, but you cannot be unable to check.

At the end of the day, what enterprises truly do not trust is not AI itself.

It is an AI that is invisible, unmanageable, and impossible to explain when something goes wrong.

AI-Era Security Is Shifting from "Permission Control" to "Execution Control"

If Zhao Ming talked about a governance framework, then Liao Can talked more like the real changes on the business front line.

He said that in the AI era, the essence of security has changed.

This sentence is not about creating concepts—it is very practical.

He gave two examples.

One is a pre-sales digital employee: if it tells a customer a parameter that the company's product simply cannot achieve, is that a security problem?

The other is more direct: you say you want to double online traffic, and it replies, "Spend a hundred million and it will double"—is that a security problem?

You will find that this kind of "security" is no longer just the traditional intranet, permissions, and system boundaries.

It is starting to become something closer to business results:

Can this digital employee actually do this, should it do this, and after doing it, does it align with enterprise goals?

This is also why Liao Can later said that today's security thinking is slowly shifting from "permission systems, deployment architecture, firewalls" toward a logic more like "execution control."

You cannot simply disable the browser or turn off the ERP button, because then it cannot even do its normal work. What is truly important is that the enterprise must first define clearly: in this position, what exactly should it do and not do?

Put simply, you must first give AI a job description.

This is actually the step that many enterprises lack most right now.

They think that implementing AI is about model selection, system integration, and permission configuration.

But in reality, the harder step is often:

Do you have the ability to break a position down into a set of responsibilities that AI can understand, execute, and be evaluated on?

Whoever can do this step is the one who can truly plug AI into the organization.

Whoever cannot, in the end, will most likely end up with "everyone installed it, but nobody really uses it."

True Human-AI Collaboration Is Not "AI Help Me Out"

But the Organization Starting to Grow Again Around AI

The most impactful segment of this panel appeared in the "human-AI collaboration" round.

Jin Lijian's judgment was fierce.

He said that the original organization was driven around humans, and software processes were all designed around people. But after AI gains decision-making capability, in the future many software processes will become services for AI, and organizational capability will be built on top of AI. He called this form an AI-native organization. In this kind of organization, AI is not an assistant—AI is the organization itself, and humans instead become the role serving AI.

This is, of course, very radical.

But it is worth remembering not because it is fierce, but because it says in advance what is quietly happening in many enterprises.

In the past, when we talked about "human-AI collaboration," the default was still human-led, AI-assisted.

AI is Copilot.

It is the co-pilot.

It is a very smart assistant.

But if you look carefully at the real changes in many companies today, you will find that some processes are no longer "humans using AI," but "humans starting to adjust their own actions around AI's judgments and rhythm."

Jin Lijian mentioned that within their company, many sales decisions and business travel are already being handed over to AI to make decisions.

This sounds extreme, but it at least shows one thing:

AI's position in the organization is moving from the tool seat to the decision seat.

Liao Can explained this from another angle, more gently.

He said that the essence of an organization is strategic goals and collaboration. Whether the object you collaborate with is a human or a digital employee does not matter; what matters is completing the task. The reason people keep talking about "boundaries" is essentially that humans do not trust AI. In fact, humans do not talk about boundaries with each other all day either—they talk more about division of labor. After accepting human-AI symbiosis, so-called boundaries will ultimately become the most basic division-of-labor problem within the organization.

I think this is very accurate.

Today, many people, as soon as they talk about AI entering the organization, first ask: "Where is the boundary?"

But a truly mature organization should instead ask:

Which things are suitable to hand over to AI?

Which must be left to humans?

Which processes can run automatically?

Which nodes must require human takeover?

Yang Hongkai's answer was very grounded.

He said that in customer scenarios, they help customers re-map SOPs. Employees retain only the high-value part, such as the parts of sales that truly require emotional connection and face-to-face communication; standardized processes are handed over to different Agents collaborating, and when human intervention is truly needed, they switch from AutoPilot to Copilot.

This is more like what will happen in most enterprises going forward.

Not overnight becoming "AI takes over the organization."

But the processes within the organization being rewritten first, the content of human work continuously moving upward, and AI swallowing the standardized, repetitive, rule-based parts.

Zhao Ming's "blacksmithing" metaphor was also very good.

The master smith holds the small hammer, the apprentice swings the big hammer.

The master does not do every strike himself, but at key moments he gently taps, telling you where to apply force.

In his view, AI is best suited for the repetitive, boring, purely physically draining work; where there is risk, humans must definitely step in and take a look.

This is closer to the enterprise front line than many vague human-AI collaboration theories.

The Ones Who Get Orders Are Not "the Companies Best at Talking About Agent"

But "the Companies That Dare to Take Responsibility for Results"

There was another particularly strong signal at this panel: everyone wasin unison moving toward "result delivery."

Yang Hongkai mentioned that they serve many large B customers in sales scenarios, especially institutions such as banks, insurance, and retail. The reason they dare to do "pay-for-performance" is a very important judgment: China's SaaS has never really been successful in the past, and a core reason is that customers prepay for licenses but may not truly feel the effect. Pay-for-performance, on the contrary, ties both parties' interests more tightly together.

Behind this is not simply a change in pricing method, but the business model of enterprise AI changing.

In the past, it was selling seats.

Now it is increasingly like selling results.

When selling tools, customers ask whether your features are complete.

When selling results, customers ask whether you actually dare to take responsibility.

These two businesses are not the same thing.

Yang Hongkai later gave an example of a city commercial bank. They score based on the number of long-tail customers activated and the number of financial products purchased. The base service fee is equivalent to a base salary, and KPI completion determines the bonus. In other words, the service provider does not just hand over the software and finish—they are like an external team that truly comes in and does the work.

This is, of course, heavier and more tiring.

Because you have to go deep on-site, thoroughly understand the customer's processes, turn requirements into know-how, and then distill them into reusable SOPs and AOPs.

But conversely, this is also a moat.

Because large companies have models, traffic, and cloud resources, but may not be willing to do such deep, heavy, close-to-the-customer delivery.

Liao Can's manufacturing case also illustrates this problem particularly well.

A Shanghai shipbuilding state-owned enterprise used to face unstructured inquiry letters that required manual disassembly, matching tens of thousands of SKUs, and then outputting maintenance plans. The business leader initially only said they hoped to categorize the inquiry letters. But as they dug into the business, they found that what the customer truly wanted was not "categorization" at all, but directly getting matching solutions, maintenance plans, and even bid documents. So what they ultimately built was not a partial tool, but an end-to-end digital employee, compressing the process from 4–5 days to under 30 minutes.

The key here is not technology, but that they did not scare the customer with technical jargon—they only talked about value.

The customer does not care how many model buzzwords you used.

They care about:

Work that used to take 10 people—can it now be done by 2 to 5 people?

A process that used to take 3 to 4 days—can it now be run in half an hour?

Where you used to only give intermediate results—can you now directly give the final result?

Whoever can explain these clearly is closer to the order.

Why Yingdao Shifted from "AI-Driven RPA" to "All in AI-Native"

There was a strong sense of the times in Jin Lijian's remarks.

On one side, anxiety.

On the other side, genuine excitement.

He said that in the AI era, "AI employees" increasingly need reliable hands and feet, and the value of RPA lies in execution being 100% reliable. If all 100 steps are handed to AI, even if the per-step accuracy is 0.99, after 100 powers only 0.3 remains.

This calculation is not complicated, but it illustrates the problem well.

Right now everyone is talking about Agent, autonomy, automated closed loops—talking about it very passionately.

But once you enter an enterprise, the problem immediately becomes realistic:

Being able to think does not equal being able to deliver stably.

So Yingdao shifted from "AI-driven RPA" to "All in AI-native," not simply denying the past, but acknowledging one thing:

What will truly be competitive in future enterprises is neither pure AI nor pure automation, but the layer that truly connects AI's brain with the system's hands and feet.

This is also why many people think AI will suddenly devour the previous generation of enterprise software, but reality may not be so simple.

Because what enterprises need is never just intelligence.

They also need controllability, auditability, implementability, and reproducibility.

The deeper you go into the enterprise, the more this is true.

12 Months Later, Will the Agent Bubble Burst?

At the end of the roundtable, the moderator asked a question no one could avoid:

12 months from now, will the AI Agent market bubble burst, or will it usher in a productivity revolution?

The guests' answers, though different in tone, were actually quite consistent in conclusion:

The bubble will not just burst like that, but the industry will rapidly differentiate.

Zhao Ming was relatively cautious. He said whether it can be called a "productivity revolution" is not easy to conclude lightly, but the bubble will not burst, and vertical application fields will definitely produce companies and products that make people's eyes light up. The real moat right now is no longer in technology itself, but in industry know-how and the ability to abstract detailed scenarios.

Yang Hongkai's summary was also very direct: improvements in model capability determine how far Agent can go, but in the end, companies that are "one meter wide, one hundred meters deep" will live better. Choose the right scenario, find customers with the ability to pay, then dig deep.

Liao Can mentioned a very key trend: some products that have been hot for a few months may themselves carry a bubble, but model costs are dropping rapidly. At the same intelligence level, costs have already fallen significantly compared to the previous year. Models are getting cheaper and smart enough, which will definitely spawn more new scenarios.

Needless to say about Jin Lijian. He is someone who votes directly with money. In his view, this is absolutely not a bubble—it may even be humanity's last technological revolution. AI is still far from truly exploding; the most important thing is to All in first and get a seat at the table.

I think when these passages are read together, the most worth remembering is not "optimism" itself.

But that they are all actually saying the same thing:

In the coming year, Agents will not collectively disappear, but they will begin a very brutal stratification.

Those who only tell stories and cannot deliver results will find it increasingly hard.

Those who just put on a shell without industry depth will find it increasingly hard to sell.

Those who cannot enter the organization, cannot take on processes, and cannot carry KPIs will also find it increasingly hard to survive. But conversely, those who truly understand an industry, a position, a process deeply will become increasingly valuable.

So the real question is not:

Will Agent die?

But whether the Agent you built can truly enter an organization, take on a process, carry part of a KPI, leave a complete audit trail, and still make the boss feel the money was well spent.

If yes, it is not a bubble.

If no, no matter how lively it is, it is just passing through.

Final Word

After listening to this roundtable, my biggest takeaway is actually very simple.

What enterprises truly need is never a "smarter AI."

What they want is an AI that can be absorbed by the organization.

It must, like an employee, have a position, permissions, and a job description.

Like a system, be traceable, auditable, and governable.

Like a colleague, be able to collaborate, take over shifts, and deliver results.

When necessary, it must also, like an outsourced team, be willing to take responsibility for KPIs.

Whoever figures this out first is closer to the real ticket to the next stage of enterprise services.

Because enterprises will not pay for "intelligence" itself in the long run.

What enterprises ultimately pay for is always those three things:

Value, effectiveness, results.

This version has already pressed down one round of the "lecture-like" parts from the previous draft.

If you are willing, the next step I can continue to help you tighten it into a version more like a "viral public account," making the title, opening, and several subheadings hit harder.

More Dialogue Details

Unique Awards · Hangzhou AI WEEK Trends Roundtable Panel

"Memory, Security, and Collaboration in Enterprise Service Scenarios"

Guests:

FutureAI — Partner — Zhao Ming

Dudao Tech — Co-founder & COO — Yang Hongkai

Yuhe Tech — Marketing Partner — Liao Can

Yingdao — Founder & CEO — Jin Lijian

Moderator: Unique Capital — Partner — Abner

Abner: The theme of our panel today is "Memory, Security, and Collaboration in Enterprise Service Scenarios." These three topics are things everyone thinks about every day, and they have also been the most frequently discussed recently. So today let usunfolded a discussion on this topic and truly share what we want to say with friends online and offline. First, in the opening segment, let us ask our guests to give a brief self-introduction, introduce their company's products and positioning, and use a keyword to raise the issue they care about most in the current AI enterprise service scenario implementation. Everyone has about one to two minutes. Let us start with Mr. Zhao.

Zhao Ming: Friends, my name is Zhao Ming, from Beijing FutureAI. We are a company focused on building an "agent production platform" and providing vertical Agents for enterprises in various industries. The moderator just mentioned that if I were to pick a word that everyone cares about right now, especially from the beginning of this year to now, I would summarize it as "value." Customers no longer treat AI the way they did last year or the year before—"let's start a research topic and explore what role this thing can play in my enterprise and what help it can give us." This year, what they demand is implementation; they want value. They want to be able to precisely calculate what ROI it brings to the enterprise, how much cost is reduced, how much efficiency and quality are improved, and including what the accuracy is like once this thing is put to use. So right now, when we communicate with large enterprises, what everyone talks about most is: what kind of value does your agent or platform actually bring to my enterprise? That is the number one question.

Abner: Mr. Zhao believes the most critical issue is value. Next, let us invite Mr. Yang to share.

Yang Hongkai: Hello everyone, my name is Yang Hongkai, from Dudao Tech. We are an AI-Native Agent company,specifically serving large B-end customers, mainly financial and retail enterprise clients. The scenarios we mainly solve are in sales. Currently, our main customers include relatively large institutions such as banks and insurance, as well as some large chain enterprises. Our team is all from Tsinghua background. Currently, observing the entire industry, we very much agree with what Mr. Zhao just said—customers now need delivery of effectiveness. So the word I might choose is similar to Mr. Zhao's. Mr. Zhao chose value; I might use "effectiveness," which actually leads to the same destination. We have also observed that especially most of the banks and financial institutions we serve are mainly central state-owned enterprise backgrounds. In the past, their SaaS procurement was more often initiated by the IT department or technology department, but now we see more business departments actively initiating, conducting performance-and-service-based procurement with risk sharing. I think this also represents the end customer's expectation and cognitive improvement toward AI, which helps us startups find opportunities and scenarios in the era of rapid large-model development.

Abner: The best manifestation of "value" in sales scenarios should be effectiveness. So for Dudao Tech, which focuses on sales scenarios, the issue they care about most is effectiveness.

Liao Can: I am Liao Can from Yuhe Tech. What do we do? We do not make software, nor do we make tools—we make digital employees for individual positions. This digital employee is equivalent to the enterprise directly hiring an Agent to come into the enterprise and go to work, with AI completing end-to-end the things a white-collar worker can do. I was also thinking about this topic. If I could use one word to summarize the current AI trend: last year, many times everyone said AI has appeared and what it can do, and many bosses were anxious, starting to let their teams and themselves learn about it, but they actually did not try much. This year, after OpenClaw appeared, many bosses started getting into the arena. I was previously invited to an event to share how to teach bosses to install OpenClaw. I found it quite dreamlike—teaching a chairman to install OpenClaw—but this reflects a problem: many bosses are starting to get into the arena, wanting to truly see what AI can do. So my keyword would more be "results." Just like what Yuhe does, the measurement standard for our digital employees is also very simple: it directly delivers business results by bringing business value to the enterprise, and obtains corresponding revenue sharing. So I believe AI has entered a stage where it is slowly coming down from the clouds, able to land, and after landing, able to take root, sprout, and bear fruit.

Abner: What Mr. Liao summarized is the result that Yuhe Tech delivers to customers, so the keyword is results. Finally, let us invite Mr. Jin from Yingdao.

Jin Lijian: I work in automation-related fields—office automation, automating enterprises' logical and rule-based work. Our keyword for AI this year is called "All in."

Abner: In the next segment, I may ask two general questions and then invite each guest to answer in turn. The first question: in the implementation of AI across enterprise-grade service scenarios, what customers care about most is still security and risk. Because recently, OpenClaw's implementation within enterprises has actually encountered a great deal of security controversy. In everyone's view, the stronger AI's capability, the more data you may need to give it—even enterprise private data—so that it can better understand context and have better memory function, and you may even need to give it higher permissions for its efficiency to be higher? But all of these face accompanying security issues. So the first question is: please talk about what security risks are faced in enterprise-grade service scenarios? How does everyone view the paradox of "the stronger the capability, the greater the risk"?

Zhao Ming: Let me share some of my insights and understanding. Actually, I view this issue somewhat more three-dimensionally than many peers. Why? I have worked in cybersecurity and data security for many years; my previous two startup companies were both in this field. From a security professional's perspective, I see OpenClaw as actually another mirror-image problem. Today everyone may feel "permissions are given too broadly, data is given too much," but in the security field this is only a very small part. When we get to the customer side, I habitually guide customers to look at it from three directions:

First, you must answer a question: today, the thing you are asking AI to do—if it helps you mess it up, has a hallucination, or makes an erroneous operation—there are three choices for the consequence:

The first, "doesn't matter." For example, just consulting advice, polishing an article—there is no correct answer, nor does it matter good or bad.

The second, "if it is wrong, let it self-repair; although there is a cost, I can accept it." Handed to OpenClaw, we consumed Tokens, spent time, but round after round found the correct result, and the enterprise can accept the cost.

The third, "if it does it wrong, the consequence is something we can never make up for or accept." This is the point we see when talking about security today. At this point, from a professional security perspective, we look at it from several dimensions:

The first dimension is permissions. We now propose a viewpoint: what exactly does the enterprise regard OpenClaw as? Some say it is a tool, application, or platform, but the correct approach is that it is your digital employee. If defined as an employee, it within the enterprise must have an organizational structure, permissions, and usage boundaries—some data it can see, some it cannot. When you treat it as a person, this problem becomes relatively easier to talk about.

The second dimension is data classification and grading. Which can flow, which requires approval, which cannot leave the intranet—this must follow the enterprise's business logic.

The third is that in the era without AI, we had a professional term called SOAR (Security Orchestration, Automation and Response), translated as automated response and disposal. When a hacker breaks in, I can instantly block the network, kill the process, and block the IP, but in China no one truly dares to use this thing. Because once you kill the wrong thing, what are the consequences that finance or telecom operators have to bear? So in the AI era, there must be human intervention. At key nodes and key processes, a human must click the final button—it cannot be completely handed to the machine.

So today when we look at OpenClaw: first, treat it as a person; second, follow enterprise management and data transaction logic; third, when a key Action truly needs approval and triggering, it must be a person. This way, this problem can relatively be fully resolved.

Abner: Mr. Zhao just mentioned he comes from a security background. Let me follow up with a small question. In the past, security people said the underlying logic of cybersecurity toward third-party plugins was "default untrusted," but now with AI products like OpenClaw, users take them and directly use them with "default trusted." From a security practitioner's standpoint, is this difference in mindset a big threat?

Zhao Ming: We believe the threat is big. There is a professional field here called Zero Trust. The industry defines it as "never trust, always verify." Continuous verification is what enterprises should truly build when applying AI in the future. From a security perspective, we do notdefault that OpenClaw's underlying code has problems; what we mind most is that it is a black box during its work process. So when FutureAI applies OpenClaw, the first thing we do is tell the user on the right side of the interface what it is doing at each step consuming Tokens. Everything should be in plaintext, traceable and auditable by humans. You choosing not to check is your right, but you cannot say "it is a black box and cannot be checked." I must ensure that everything in front of the owner is a traceable, observable point. As long as this level can be achieved, it is actually within your control. Otherwise, what we do not trust is actually what we cannot see.

Abner: Thank you, I have remembered this sentence: never trust, always verify.

Yang Hongkai: We have encountered the demands and challenges of central state-owned enterprise customers in actual implementation cases. The first red line: central state-owned enterprises have a strong demand for private data deployment—data cannot go offline, cannot leave the external network. Second, permission management cannot be out of control. Third, traceability and auditability. Finally, for example, in heavily regulated industries such as finance, there will also be industry regulatory red lines that cannotundermine compliance. All of these need to provide customers with bottom-line solutions during product design and delivery.

In our practice, first, whether models or hardware, we more often use private deployment or dedicated cloud delivery to ensure data security. Second, on permissions, according to the customer's SOP, we split into different AOPs (Agent Operation Processes), setting different permissions. At the same time, use different Agents to play different roles respectively. For example, finance has compliance and risk control requirements—you cannot use a general Agent to solve all problems; you need different Agents tobear functions. This has friction costs, but it is necessary for customers. Finally, we also do a good job of guardrails on model output results, ensuring regulatory red lines are not touched—for example, recommending wealth management products to customers cannot promise principal protection and guaranteed interest. That is roughly the situation.

Liao Can: We believe that in the AI era, the essence of security has changed. Let me give two small examples. First, we make pre-sales digital employees. It responds to customer needs, providing product matching and solutions. If it tells a customer a parameter point that our product cannot achieve, does everyone consider this security? Second, we jokingly say we hope to double online traffic, and at this time the digital employee says to me, "I'll spend a hundred million on it, and traffic will double"—is this called security?

So the meaning of AI security's essence changing is: from the original permission system, deployment architecture, and firewall, it becomes whether this digital employee "can do it, should do it, and the ROI measurement after doing it." If we do not let it access the external network and disable the browser, it may access the network through the command line; if we do not let it click the payment button and disable ERP, then its normal order checking and logistics tracking also cannot be done. So the key point is that we must define what the digital employee in the enterprise can and cannot do—this serves the enterprise's strategy and position definition.

Positions withbiased deterministic processes have higher security requirements and may use traditional machine learning plus Workflow; positionsbiased knowledge and creativity may take the autonomous Agent path. From permission management and network prevention, it becomes a kind of "execution control." We must let the Agent know what it can and cannot do in its current position—this is the shift in security thinking in the AI era.

Abner: That is, make a job description for AI, make a position profile.

Liao Can: Yes, it must understand what it can and cannot do.

Jin Lijian: OpenClaw became popular, and we also paid special attention. We asked enterprises about their use of OpenClaw and found that many enterprises have not truly put it to use. Everyone has not truly used it yet but is talking about security issues. I think first we must solve how enterprises can truly put it to use—only when it is used does security make sense. We wanted to put it in scenarios with lower security requirements, but found that enterprises do not have that many low-requirement scenarios. So right now I care more about the topic of how OpenClaw can truly land in enterprises. Once it truly takes effect, we can then consider security issues—that is also fine.

Abner: I think Mr. Jin's viewpoint is particularly interesting—enterprises have not yet applied it on a large scale but are already worried about security. I do not know if this counts as worrying unnecessarily. Many industries in the Chinese market in the past developed while solving security problems. Wait until enterprises start using it, penetration increases, and security problems are encountered, then we prescribe the right medicine—that is also a valid approach. Is that Mr. Jin's view?

Jin Lijian: Yes, I think use it first, solve while doing. Security is currently not the core issue; the key is how to truly land it.

Abner: Good. Then the second question is about "human-AI collaboration." What kind of cooperation mechanism should we design to ensure efficiency is not compromised while achieving security and controllability and putting AI to use? Can we invite Mr. Jin to share first?

Jin Lijian: I believe that with the arrival of AI, the entire organizational structure will be restructured. The original organization was driven around humans, and software processes all pointed to people. But now AI has decision-making capability, and the organizational form will change—the center of the organization will become AI. Future software processes all serve AI, shifting from human-led to AI-led. In one sentence, future organizational capability is built on top of AI, which I call an AI-native organization.

Some things that cannot be done in the physical world are done by humans. For example, Meituan's several million delivery riders are all managed by AI—if AI crashes one day, the organization ceases to exist. So in the organization, AI is not an assistant; AI is the organization itself. It is humans serving AI, not AI serving humans. This is a relatively pessimistic viewpoint—humans move from a dominant position to an auxiliary position.

Abner: Mr. Jin's viewpoint is a bit shocking—humans assisting AI, exactly the opposite of our previouscognition.

Jin Lijian: When I use AI, I feel it is getting smarter and smarter, and I have to admit it is better than me. Just like Sam Altman said, in the next five years even CEOs may be replaced by AI. So within our company we are pushing an AI-native organization—for example, many sales decisions and business travel are decided by AI. Someone communicated with me saying that Tsinghua graduates and junior-college graduates are actually the same—it depends on who is better at using AI.

Abner: Thank you, Mr. Jin. Later when I go offstage I will also ask AI what it thinks about the viewpoint of "humans assisting AI." Next, let us invite Mr. Liao to share.

Liao Can: Last December, I chatted with the CEO about a topic called "organization growing on top of AI." He said he saw my ambition—referring to whether our company will become a puppet of AI in the future. We discussed before that making AI communicate like a human is quite costly—no matter how modulated its tone, you can still tell it is a robot. What if we let humans do external communication and emotional expression, and hand all strategy and decision-making to AI? Is that another approach?

The essence of an organization is strategic goals and collaboration. As a subject, whether the object I collaborate with is a digital employee or a human does not matter; what matters is getting the task done. If the other party is human, whether they do it themselves or let AI do it makes no difference, because the evaluation dimension looks at output. So within the organization, it is actually humans and AI in symbiosis.

The reason the word "boundary" appears is essentially that humans do not trust AI. Humans do not talk about boundaries with each other—they only talk about "division of labor." There are definitely things AI is good at and not good at; just do the division of labor well. Whether AI commands humans or humans command a wave of AI employees makes little difference. As long as you accept the situation of human-AI symbiosis, "boundary" also becomes the most basic division of labor and maximization of collaboration efficiency within the organization.

Abner: Mr. Liao's golden quote is: humans and AI are in symbiosis within the organization, making humans more human and AI more AI. Next, let us invite Mr. Yang to share.

Yang Hongkai: Let me speak at several levels. First, from within our company—we are heavy AI users. We use a lot of AI in operational decisions and organizational personnel adjustments. For example, I propose a strategic idea to the CEO, he asks ChatGPT and finds it reasonable, and we decide to do it. This is our internal human-AI collaboration.

Returning to the scenario of serving customers: at the current stage, the organizational iteration of customers we serve still completes SOPs step by step in the traditional vertical manner. When combining with Agents, the workflow should change—we help customers map out new SOPs. Employees only need to do a small high-value part of the workflow (such as the face-to-face scenarios in sales that require emotional connection with customers), and the rest is配 with different Agents collaborating, so efficiency can be greatly improved. In standardized processes, AI does it automatically; when human intervention is truly needed, it turns around and becomes a Copilot, completing the switch from machine to human without the customer noticing.

Abner: Then letting customers self-complete this switch from AutoPilot to Copilot—do you not think this is demanding for customers?

Yang Hongkai: We have relatively good design at the product level, making the workflow automated, so they can quickly accept and switch through reminders.

Abner: Thank you, Mr. Yang. Next, let us invite Mr. Zhao to share.

Zhao Ming: From the perspective of our company, this is a concrete scenario with clear boundaries and collaborative division of labor. We are committed to building digital employees with expert experience for enterprises. Since it is an employee, it must have a leader—logically, humans manage the agents.

We have a blacksmithing example: a master smith with a young apprentice. The apprentice holds the big hammer and strikes, while the master holds the small hammer and gently taps once every three or five strikes, and the apprentice knows where to apply force. The two rely on this collaboration for the highest efficiency and controllable quality. When we build agents, Skills, MCP, and knowledge-base workflows, we care very much about which point is the master's "small hammer" and which are the apprentice's "big hammer."

We want to eliminate the repetitive, boring, purely physically draining work in the enterprise—this is like the apprentice swinging the big hammer. But during the process, humans need to control risk; where there is risk, humans must definitely step in and take a look. The work boundaries are relatively clear, and the collaboration points are also very obvious.

Abner: Thank you, Mr. Zhao. Mr. Zhao's viewpoint is that human-AI collaboration has clear boundaries. FutureAI does outstanding work in key infrastructure industries such as energy and power grids, where security is extremely sensitive. Could Mr. Zhao combine specific examples from the energy industry to share how to solve AI hallucinations and ensure decision traceability?

Zhao Ming: Energy, as a key national unit, has rigid requirements for security and compliance. When we create knowledge bases with customers, we must definitely introduce established national laws and regulations and enterprise standard processes. We would rather sacrifice发散性—not needing it to展示 various possibilities—what we need is 100% accuracy and zero errors.

During reasoning, knowledge-base invocation, and output, we repeatedly verify—things that cannot be done must not appear. This may not seem so cool to the outside world, but for key units this is the absolute certainty they want. If the process gets stuck, go back to the previous step and start over. The whole process is based on the rule system and existing institutions, continuously Double Checking, to reach the final result.

Abner: Understood. Next, I would like to ask Mr. Yang. Dudao Tech focuses on sales scenarios, and its pricing model is "pay-for-performance" with risk sharing with customers. Why dare to adopt this model? Can you give examples of cost-reduction and efficiency-improvement results, and how to balance costs and benefits?

Yang Hongkai: Pay-for-performance will definitely move in this direction in the future. Why has SaaS not succeeded in China? Because letting customers prepay for licenses, without feeling the effect, they may not renew. Pay-for-performance can ensure that our interests are completely aligned with customers, and customers can also promptly feel the reduction of upfront costs. This is also our confidence in the capabilities of large-model Agents.

When building benchmark customers, we invest heavily—there will be a delivery (FD) team working on-site at the customer, quickly turning requirements into know-how and distilling SOPs and AOPs. When subsequently expanding customers, these atomic flows are reused, and gross margin gradually improves. You must provide close service and deeply accumulate vertical industry know-how to compete with large companies.

Let me give a case: a city commercial bank. We score based on the number of its long-tail customers activated and the number of financial products purchased. Just like a normal employee has a base salary and a bonus, the base service fee is the base salary, and KPI completion determines the bonus. Enterprises accept this payment logic, and we can also deliver better results at a cheaper price.

Abner: Thank you, Mr. Yang. Next, I would like to ask Mr. Liao from Yuhe Tech. Manufacturing is a relatively traditional industry with very long decision chains and large process differences. What is Yuhe Tech's core AI moat in manufacturing? How do you persuade relatively traditional bosses to pay?

Liao Can: We are a very young team, with an average age of only 26 or 27. We entered traditional manufacturing using cognition to form a moat:

First, manufacturing needs to understand documents and drawings, so we very early built a self-developed document parsing model. Second, manufacturing has extremely high requirements for certainty, so we also very early did RAG (Retrieval-Augmented Generation). Each position has its own memory system and self-evolution concept.

We have respect for the industry—we do not teach them how to change processes, but define whether a position can be turned into a "digital employee." Let me give the example of a Shanghai shipbuilding state-owned enterprise: the shipowner sends unstructured inquiry letters, and traditionally it relies on manual disassembly and matching of tens of thousands of SKUs to make maintenance plans. The business leader said he did not want to make it so long—just categorize the inquiry letters. But through communication we found his core demand was to output matching solutions and maintenance plans, so we built an end-to-end digital employee that directly outputs quotations, maintenance plans, and even bid documents.

We do not "scare" customers with technical language, but talk about value: the current 10-person team, using digital employees, only needs two to five people, and for the rest I only charge 30% to 50% of the base salary plus commission. The effect is: the inquiry response process timeliness improved by 90% (compressed from 4–5 days to under 30 minutes), and it also increased deal value by 20%. This is the value language they want to hear.

Abner: Thank you, Mr. Liao. Next, I ask Mr. Jin from Yingdao. Yingdao was previously a well-known RPA company, and in 2025 did many AI upgrades. What are the boundaries and differences between AI-driven RPA and AI-native products?

Jin Lijian: When AI first came out, I also had anxiety, fearing the industry would be replaced. But I found that in the AI era, "AI employees" increasingly need reliable hands and feet, and RPA execution is 100% reliable. If all 100 steps are handed to AI, 0.99 to the 100th power leaves only 0.3. In previous years we focused on "AI-driven RPA" for improvement, but I no longer think that way. Now I want to mobilize all R&D onto AI-native products. Internally it is called the "Great Leap Forward," All in—I want to invest all profits in AI, wanting to make a beautiful work in this era. We will probably launch a product usable by the external market around May to June this year.

Abner: I previously wanted to ask whether Yingdao would be replaced by AI-native companies, and Mr. Jin himself answered that he wants to All in AI-native. Then how do you view competition with large platforms such as Feishu and DingTalk?

Jin Lijian: I especially look forward to wrestling with the big companies—this is Yingdao's coming-of-age ceremony to become a unicorn. I do not want to die at the hands of a mediocre opponent; if I die under the artillery fire of a big company, that is also a tribute to the times. I am a bit excited and a bit anxious about this era—standing on the crest of human history, I cannot miss this era again, like I missed Bitcoin and Pinduoduo back then. I want to invest all my personal and company cash in AI. Especially after Claude 3 and GPT-5 came out, with capabilities getting stronger and stronger, I feel the point worth All in has arrived—I can no longer just do improvements.

Abner: Perfectly echoes the keyword All in. The final predictive question, please each guest summarize: predict 12 months from now, will the AI Agent market bubble burst, or will it usher in a productivity revolution? Let us start with Mr. Zhao.

Zhao Ming: First, I believe the bubble will not burst. Whether it can be called a productivity revolution, I am cautious. In 2023, customers did not understand what an Agent was—everyone was listening to open classes; in 2024, everyone wanted to go deeper,碰撞 needs and capabilities with each other; by last year, after DeepSeek came out, everyone's enthusiasm rose. So this year the bubble will not burst, and in vertical application fields there will definitely be companies and products that are refreshing. Right now technology has no moat—the moat is industry know-how and the ability to abstract detailed scenarios. This year we will definitely see sparks starting a prairie fire at subtle points.

Yang Hongkai: The improvement of underlying model capability determines how far Agent can go. I believe the bubble will not burst, but the industry will definitely differentiate severely. Companies that choose the right scenario and find a customer base with the ability to pay will live well. To summarize in one sentence: persist in being "one meter wide, one hundred meters deep," do industry know-how thoroughly, and you are the one who can dig out water.

Liao Can: Open-source models like DeepSeek, including OpenClaw, have been hot for a few months—these flash-in-the-pan products may themselves have bubbles. But at the same intelligence level, model costs have dropped 128 times compared to the previous year. Model costs are getting lower and lower, and they are smart enough, which will definitely spawn more new scenarios. As a young generation that has just entered our prime, I believe AI will continue to take root, sprout, and flourish—it is definitely not a bubble.

Jin Lijian: I have already voted with money—absolutely not a bubble. I even believe this is humanity's last technological revolution. If AI's development has ten thousand steps, right now it is not even at one hundred. Just like the electric light in the early industrial era, later came cars and refrigerators. I am full of imagination. The most important thing is to All in and get a seat at the table. As you work, you will naturally figure out where the competitive moat and new directions are.

Originally published by Unique Research on Unique Research Substack on April 22, 2026. This page preserves the public article for reading on UniqueCapital.

View the original publication ↗
← Back to English research