← All issues

The Agentic Index Brief

August 9 to August 15, 2026 · Published August 16, 2026

The week in one line

SpaceX closed its $60 billion acquisition of Cursor's parent company and regulators unwound Meta's $2 billion Manus deal inside the same seven days. One product gained a frontier model within days. The other scheduled a data deletion. Ownership now reaches production faster than most features do.

Theme 1: The cap table became a product surface

SpaceX completed its $60 billion acquisition of Anysphere, the company behind Cursor, and Grok 4.6 appeared as a live model option in the editor immediately after the close. The first product consequence of the deal shipped before the press cycle about the deal ended.

The model did not stop at its new corporate family. Cognition added Grok 4.6 to Devin, reporting that it ranks third on the company's internal FrontierCode benchmark, a ranking regular readers will recognize as a take home exam. GitHub Copilot added it too, in a window where Copilot also picked up Gemini 3.7 Flash, Microsoft's own MAI-Code-1.1-Flash with native vision at a 73 percent lower list price, general availability for Agent Plugins, and a Copilot SDK for Java, five entries for anyone still running the tally from July. Elsewhere in the picker, Kilo Code added NVIDIA's Nemotron 3.5 Lightning, Netlify's gateway picked up Gemini 3.7 Flash with zero configuration, and AutoGPT added Claude Sonnet 5 support. Model distribution now moves at the speed of capital, and this week capital was moving quickly.

Then the inverse case. Manus resumed independent operations after regulators ordered its December 2025 acquisition by Meta unwound. As part of the separation, data generated by affected users on or after the acquisition date will be permanently deleted between August 23 and 24, accounts will temporarily lose service, and users must export their workflows before August 23 to restore them when the portal reopens on August 25. A forced unwind at this scale is a first for the category, and note who pays the exit fee. The merger can be reversed. The merged data cannot, so it gets destroyed.

The quieter ownership items point the same direction. Arize AI agreed to be acquired by Dynatrace for $915 million, pairing agent evaluation with production monitoring and making it the second independent agent observability company absorbed by classic observability in two weeks, after Galileo completed its move into Splunk in last week's issue. Commure's legal leadership terminated a program that paid customers and third parties referral fees written into live contracts, effective immediately, an internal legal decision rewriting customer paper. Lovable raised $400 million at a $13.3 billion valuation and, unusually for a funding item in this log, shipped alongside it: built in payments through Paddle and Stripe, plus SEO and AI search tooling with Semrush. And Traversal took an investment from Amex Ventures inside a partnership that deploys its agents across American Express's global technology infrastructure, capital and distribution arriving as a single document.

Our read: the diligence file on an agentic vendor now needs a section on the shareholder register. In one window, ownership events determined which models a product offers, whether customer data survives the year, and what existing contracts say. None of that appeared on a roadmap, and none of it could be evaluated by testing the product.

Buyer question this week: read your agreement for what happens to your data, your model options, and your pricing when the vendor is acquired. Then add the clause almost nobody has: what happens when the acquisition is reversed. Manus users have until August 23 to answer that one for themselves.

Theme 2: MCP grew a permission lifecycle

In the August 2 issue, MCP grew up: stateless sessions, rate limits, token exchange, identity. This week the enterprise added everything else an identity system needs. The protocol did not gain new powers. It gained a personnel file.

LiteLLM shipped MCP entitlements that enforce access at key, team, agent, and organization scope for both listing and calling tools, plus a post call guardrail mode that masks or rejects what a tool returns. Governance now covers the answer, not just the question. TrueFoundry put human approval at the gateway boundary: designated MCP tool calls are intercepted, an approver is notified, and the execution state is suspended until someone says yes. The same vendor also made its gateway deployable on VMware Cloud Foundation, so the approval step can live entirely inside a private cloud.

Kerno introduced automated runtime testing that introspects a running MCP server and generates test scenarios from the actual tool surface, catching authentication gaps, leaked configurations, and boundary enforcement failures before production. SnapLogic added a dedicated MCP metrics page, let pipelines be exposed directly as tools, and implemented token exchange under RFC 8693 to scope downstream credentials. Ada shipped an audit log spanning dashboard, API, and MCP, alongside connection management to monitor and revoke authorized assistant connections. Revocation is the part of every permission system that gets built last and needed first.

The assistant side kept growing surfaces for all of this to attach to. Anthropic's Compliance API expanded to cover Claude Code across the CLI and desktop app for enterprise customers, with server hosted transcripts of prompts, responses, and tool activity. Island wired Anthropic's new Inference Hooks into its control plane, routing every governed prompt and tool result through a policy engine, deterministic DLP plus an LLM judge, before Claude processes it. Last issue counted four security vendors converging on assistant ecosystems in two weeks. The ecosystems are now meeting them halfway by shipping the hooks.

And the supply side kept arriving, because the systems of record have concluded this is how their data gets consumed now. Ironclad put contract data into ChatGPT, Claude, and Slackbot. Airtable's new server lets external models build interfaces and automations. Salesloft opened live pipeline queries from inside ChatGPT. Fieldguide connected live engagement data to Claude, Copilot, and Gemini alongside three agents that draft and validate financial statements. Gainsight exposed its Skilljar learning platform, IBM added the Dun and Bradstreet Commercial Graph to the watsonx Orchestrate catalog, Fiddler put its server in public preview, Suki exposed its developer docs to coding agents, and PagerDuty put its SRE agent inside GitHub. Zapier rounded it out with a TypeScript SDK offering programmatic access to more than 9,000 integrations with OAuth handled for you. At some point the integration layer stops being plumbing and becomes the building.

Our read: the week's pattern maps one to one onto identity management, and that is the tell. A protocol crosses from developer convenience to enterprise dependency at the moment someone builds a permission lifecycle around it: grant, scope, approve, test, revoke. MCP is being managed like an identity system because functionally it is one. It decides which software may do what to which system on whose behalf.

Buyer question this week: inventory the MCP connections in your environment and answer three questions for each: who can revoke it, what scopes the credential it carries downstream, and whether anything has tested its tool surface since that surface last changed. A blank on any of the three is now a solvable problem rather than an accepted one.

Theme 3: Memory became portable, and deletable

Intercom gave Fin memory of returning customers, carried across channels so a conversation that starts in chat and moves to email does not restart from zero. It shipped Evals and Releases in the same window, testing agent changes before deployment and monitoring live conversations, which is the tooling you need before you trust software that remembers. Giga's voice agents now schedule their own callbacks and resume at the appointed time with the original call's context intact.

Taskade made agent knowledge bases sync themselves from web pages, spreadsheets, email forwards, and chat platforms on a schedule, with no manual uploads. Hyperspell launched an SDK and an Agentic Memory Network as a dedicated context layer with connectors for Gmail, Notion, and Slack, which makes memory a vendor category of its own rather than a checkbox. In last week's issue, memory arrived with an audit surface attached. This week it got logistics.

The boundary crossing entry: Harvey adopted the open Agent Handoff Protocol launched by DeepJudge, letting users move between AI platforms without losing conversational context or supporting materials. Memory moving across vendor lines under an open protocol is new. Last week it got an audit log. This week it got a passport.

And the same week produced the category's first scheduled mass deletion. Manus, above: months of user generated context destroyed on a date chosen by a regulator rather than a user.

Our read: memory crossed from feature to asset class this window. It accumulates, it transfers across channels and now across vendors, and it can be destroyed by events entirely outside the product. Anything with those properties deserves the treatment an asset gets: an inventory, an export path, and a named owner.

Buyer question this week: for each agent holding institutional context, establish where that memory physically lives, whether it exports in a form another system can ingest, and who besides you can delete it. The Manus deadline is a live worked example of why the third question matters.

Market notes

The meter got renegotiated. Zendesk exempted native actions and standard connectors from action credits entirely, including actions invoked by its AI agents and Copilot, which is a price cut delivered as a definition change. Microsoft published a Copilot Credits billing rate table, documentation for the new consumption billing model, and an official usage estimator. Composio moved from flat tiers to usage based pricing. JetBrains put quota tracking and credit top ups inside the IDE, Tines added tenant wide AI credit alerts, and FinOpsly launched a cost governance framework with pre deployment cost modeling and runaway agent detection. Last issue, spend control folded into the control plane. This week the meters themselves were repriced, documented, and estimated. When a vendor ships a calculator for its own invoice, the invoice has become a sales objection.

Autonomy moved deeper into production. Traversal introduced autonomous remediation, its SRE agent writing, deploying, and verifying fixes in production, demonstrated by having the agent heal its own environment. UiPath took Autopilot to general availability as a coding agent inside Studio, planning, building, and debugging automations from prompts with MCP support. Cognition graduated Automations to a production v3 API with queueing and depth limits, and turned Devin Local on by default for enterprise customers. Microsoft 365 Copilot agents can now call and coordinate other specialized agents. Sherlocks moved incident investigation into Slack threads, correlating telemetry and testing root cause hypotheses on command. The reliability tier got exactly once semantics: Hatchet shipped idempotency keys and Inngest lets a completed workflow rerun from any single step with everything before it memoized. Writer's rebuilt agent harness runs a single objective unattended for up to eight hours. Oracle introduced Fusion agentic applications for HR, IBM's AgentOps reached general availability, and Corelayer debuted from Y Combinator to automate first line production support in regulated environments. The industry spent years asking whether agents could act. It is now spending rather more time asking whether they can stop, retry, explain themselves, and leave the database in one piece.

Voice had a dense week. Deepgram made Flux its default text to speech for voice agents in general availability, processing full conversational context so interruptions do not derail it. Inworld's Realtime TTS-2 Flash reaches first audio in 20 milliseconds across more than 200 languages. Cartesia added keyterm prompting and configurable turn detection to Ink-2. Rime retired its legacy Arcana model, migrating all cloud traffic to Coda, trained on full duplex human conversation with sub 100 millisecond latency. Gnani shipped Timbre v2.5 with 40 voices across 10 Indian languages. And Giga launched real time synthetic voice detection that screens live inbound calls for AI generated speakers. Voice agents now screen their calls for other voice agents, which is either quality assurance or the opening move of a very polite arms race.

The regulated verticals kept threading agents into the record itself. Cedar launched the Kora platform, a suite of patient billing agents that keeps contextual memory across a patient's whole financial journey. Assort Health's new Referrals agent ingests referrals from EHRs, faxes, and PDFs, verifies eligibility, and schedules patients directly in the EHR. Lyrebird Health integrated natively with Oracle Cerner Millennium so AI generated documentation writes straight into the patient record, mdhub joined the athenahealth Marketplace and added an AI care coordinator and automated chart audits, and Hippocratic AI launched Agentic Orchestrators, a supervising layer that decides which of its voice agents engages a patient, and when. Legal deepened the same way: Harvey shipped matter grounded Outlook replies, a Command Center with adoption metrics, and an Aderant integration that drafts billing narratives from completed work, while Spellbook put a full AI document editor inside Associate so contract redlining no longer round trips through Word, and Legora connected to Box. In insurance, Sonant earned certified write back access to Applied Epic and Weav.ai launched underwriting and claims agents for property and casualty.

At the interface, Anthropic turned Claude in Chrome into a full Cowork session that syncs across desktop, web, and mobile, with a mandatory human approval step before high risk actions like submitting forms. Browserbase shipped Stagehand v4, moving core state management into a browser extension so remote sessions execute natively rather than through a lagging mirror, with parity across TypeScript, Python, and a new Go SDK. Vercel opened a headless API that lets v0 generate complete applications programmatically. LangSmith's no code Agent Builder entered public beta and its Bring Your Own Cloud deployment reached general availability on AWS. And Firecrawl indexed 41 million life sciences papers behind its API, CLI, and MCP surface.

The action item: this deadline was set by a regulator, and it does not slip

First, if your team uses Manus, export your workflows before August 23. Data generated on or after the Meta acquisition date is permanently deleted between August 23 and 24, affected accounts temporarily lose service, and the restore portal opens August 25. Product deadlines move. Regulatory ones are famously less flexible.

Second, Flowise moved its GitHub repository to Public Archive as it winds down operations, with issues and pull requests locked and the official npm packages and Docker images deprecated. Anything running Flowise is now running software that will never be patched again. Migrate on your own schedule, but pick a schedule. Entropy is perfectly happy to choose one for you.

Third, Kilo Code published scope details on the Metabase incident covered in last week's action items. If your team touched it, read the disclosure and rotate accordingly. And a gentler one: Exa published the official migration path off its legacy Websets API onto the Agent API, including a zero data retention mode. Calendar the migration before the deprecation calendar does it for you.

The Agentic Index Brief is published weekly by Agentic Index, the verified directory of 984 agentic AI vendors. Compare platforms by capability at agenticindex.io/compare. Methodology at agenticindex.io/methodology.

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.