← All issues

The Agentic Index Brief

August 16 to August 22, 2026 · Published August 23, 2026

The week in one line

Stripe agreed to buy OpenRouter in a deal reported above $7 billion, Ramp shipped a router of its own that sends each request to the cheapest model that will do, and Replit turned its free tier into a routing rule. The layer that decides which model answers your prompt is being bought by the companies that count the money.

Theme 1: The routing layer changed hands

OpenRouter agreed to join Stripe in an acquisition reported above $7 billion. Two days earlier it had shipped an analytics dashboard and API that tracks spend per model, saves custom charts, clicks through to the underlying logs, and answers usage queries from the terminal. A router that had just finished building a meter was acquired by a company whose entire business is meters.

In the same window, Ramp launched Router.com, a unified API that sends each corporate AI request to the lowest cost model that can serve it. A spend management company now sells model selection as a cost control, which is the plainest statement yet of what the routing layer is actually for.

Replit made the same argument from the other end with Free Mode, a tier running on GPT-5.6 Luna where building consumes no tokens, with harder reasoning routed out to GPT-5.6 Sol and then handed back to the free model with project context intact. The free tier is a routing rule with a marketing name.

Then the quieter half of the story, in which the model under a running agent changed and nobody filed a migration. Moveworks moved the default model behind LLM Actions in Agent Studio to GPT-5.4 mini for newly configured actions. Voiceflow retired Flash 4.1 outright and migrated every existing agent onto Voiceflow Core 4.1, with the old model removed from the selector. Zed 1.15.1 added the AWS Bedrock Mantle endpoint for GPT-5.5, GPT-5.4 and Grok 4.3 alongside Claude Fable 5 and Sonnet 5, and Kore.ai added QWEN to its picker. Claude Code 2.1.239 added Bedrock and Alpine Linux support and adjusted its cost estimates to carry a 1.1x premium for United States only inference in data residency workspaces, which puts a printed price on what used to be a purely legal preference.

Our read: model choice is drifting away from the buyer in two directions at once. Upward, into routers owned by payments and spend infrastructure, where the selection criterion is cost per request rather than fit for your task. Sideways, into vendor defaults that change on the vendor's schedule. Both are reasonable engineering decisions. Neither shows up in an evaluation you ran last month.

Buyer question this week: for each agent you run in production, name the model serving it right now, who is allowed to change that, and where the change gets announced. If the second answer is the vendor and the third is a release note nobody on your team receives, your evaluation has an expiry date you did not set.

Theme 2: The controls moved into your admin panel

For two issues the control plane was something vendors sold to each other. This week it arrived as settings an IT administrator can actually flip.

Google Antigravity shipped enterprise controls that restrict agent file access to specific working folders, require human approval for terminal commands, enforce sandboxing, and limit browser access. It also launched Remote Control, a browser first surface for monitoring long running agent tasks across multiple machines, with push notifications when an agent needs a human to proceed. The agent now pages you instead of stalling silently, which is a small change with a large effect on how many agents one person can supervise.

GitHub Copilot for JetBrains added enterprise managed settings covering plugin governance, MCP server access, OpenTelemetry and permission modes, applied consistently across every developer. Retool put access policies on PostgreSQL resources into public beta, with read and write permissions defined per user group and enforced across every query, including the ones AI agents issue. Rippling launched an AI governance product and an MCP gateway to manage agentic tool access. Outreach shipped an AI Control Hub for organization level governance, configuration change logs for its Revenue Agent, and eleven new MCP tools in the same release.

The recording layer thickened alongside the permission layer. ContraForce shipped audit coverage twice in three days, first for standard operating procedures and security rule changes, then for workspace configuration, access control and agent deployment history. Moveworks added a user attestation interaction type to its Data API that captures who acknowledged which form and exactly when. Aisera added credential health notifications so administrators hear about authentication failures and expiring integrations before an agent does.

And the perimeter kept acquiring geography. Fieldguide reached FedRAMP Moderate authorization with Knox Systems and opened a dedicated federal environment for its agents. Corti partnered with the Danish Center for AI Innovation on a sovereign AI control layer for European enterprises, with Trifork as first implementation partner. Where the compute sits is now a product feature with its own launch.

Our read: the enterprise controls landing this month keep converging on the same four questions: where an agent may read, what it must ask permission for, what gets written down, and where the work physically runs. That is not a coincidence of roadmaps. It is the shape of every access control system built in the last thirty years, arriving late and in a hurry.

Buyer question this week: take your two most used agent platforms and check which of those four controls your IT administrator can enforce centrally, rather than per project or per user. Whatever is left over is your actual policy, regardless of what the policy document says.

Theme 3: Agent configuration got a release process

Drafts, staging environments, version snapshots and rollback all shipped this week, attached to agent behavior rather than to code.

Vapi introduced assistant and tool versioning: work in drafts, publish named version snapshots, roll back when a change goes wrong. Forest Admin gave workflows drafts and version restore from the editor, plus deterministic data steps sitting beside a guidance step where the model drafts text mid run. LangSmith launched Preview Builds, temporary production like deployments spun up from a pull request branch so a change to a prompt, tool, model or dependency can be reviewed before it merges. xpander.ai added an organization wide skills registry and the ability to draft, review and roll back agent changes from inside a conversation.

The evaluation half arrived with it. LangChain shipped tuned evaluators, starting with a managed judge that attaches perceived error feedback to production traces automatically. Langfuse 4.13 traces complete agent turns across human approval flows, so the pause for a human no longer breaks the trace. Beam AI launched a Learning Hub that aggregates agent feedback and self checks, spots recurring failures and drafts the instruction fix for review, alongside a reasoning effort control that can be set per step. Gradient Labs released Collaborate, a workspace where operators, engineers and agents work as peers with version control, evaluations and continual learning built in.

And the pipeline metaphor got literal. Warp opened a closed beta for Factories, cloud infrastructure that routes a task through triage, specification, implementation, review and verification as distinct stages, with a different model permitted at each one. Browserbase brought Search into the dashboard so queries can be sampled and tested before they reach production. Both are the same instinct: stop treating an agent run as a single opaque call.

Our read: prompts, tools and agent instructions are being handled as deployable artifacts, with branches, staging, evaluation and reversion. Rollback is the tell. Nobody builds rollback for something they still think of as a setting.

Buyer question this week: ask what happens after a bad change. Can you name the version of the agent serving customers right now, and how long does reverting to the previous one take. Anything longer than a deploy means agent behavior is not under change control yet, whatever the audit log shows.

Market notes

Vendors kept expanding into their partners' territory, and this week one partner objected in writing. Cursor launched Origin, native code hosting in early beta for all paid plans, with repositories, pull requests, code browsing and real time synchronization with GitHub. One week after the SpaceX close covered in last week's issue, the editor is building the place the code lives. Then the objection: ServiceTitan terminated a nine year integration with Podium, affecting roughly 1,000 shared customers, after Podium extended its agents into a full field service management system. An integration directory is a map of who is not yet a competitor, and the map is being redrawn faster than the contracts renew.

Consolidation continued underneath. Cribl acquired the technology and intellectual property behind Radiant Security's AI native SOC and will run autonomous triage and investigation as an application on its telemetry platform. Fleetx acquired Pando, keeping the brand and the leadership team in place. R1 RCM signed a definitive agreement to acquire Humata Health, folding prior authorization into its operating system and the team into an internal agentic AI lab. Agent.ai retired its standalone platform on August 22, with its capabilities moving into the new HubSpot Agent Builder. And Rippling and Runlayer mutually withdrew their intellectual property lawsuits over MCP gateway technology, in the same window Rippling launched a gateway of its own. The category now has litigation history, which is one way to tell it has revenue.

Legal and health kept threading agents into the record itself. Harvey had the fullest week of any vendor in the log: Harvey II with a core memory that learns how an individual lawyer works inside a matter space, and Tenet, its first post trained open weight model, built on the Kimi K3 base with Fireworks and aimed at long horizon work such as regulatory analysis and trial preparation. In the August 2 issue an application vendor training its own model was the first entry of its kind in this log. Three weeks later it is a legal research feature. Clio put around the clock intake agents into Clio Grow. Oracle Health added professional fee coding, dictation and automated chart review to its Clinical AI Agent. PolyAI shipped a direct Epic integration with no middleware in the path. Owkin cleared European regulatory approval for two diagnostic models in breast and colorectal cancer, and Infinx scaled its revenue cycle agents on AWS.

The web access layer had a heavy week. Firecrawl launched a Developer Index covering more than 70 million developer artifacts, including READMEs, documentation, issues, pull requests and OpenAPI specifications, with semantic retrieval behind an API, CLI, MCP and SDKs. Exa became the retrieval layer for Firefox through a Mozilla partnership, powering Smart Window on desktop and Quick Answers on iOS with cited answers from the live web. Bright Data wired its MCP into both TrueForge and Grok Build. Apify migrated its server to the stateless MCP specification over Streamable HTTP, which is the housekeeping half of the same story.

Security operations kept industrializing. Harness launched a suite of security agents spanning AI SAST, agentic triage and remediation, a dedicated zero day agent and virtual patching. Intezer shipped Workflows, letting analysts write response logic such as isolating a host in natural language through its own MCP. ReliaQuest connected GreyMatter to Anthropic's compliance API to monitor authorized Claude activity across the enterprise, the third security vendor in three weeks to build on that surface. Crogl added a knowledge graph that correlates identity relationships across systems without demanding a unified data architecture first.

Elsewhere, the workhorse releases. Coupa announced autonomous agents for payment batch creation, sourcing events and supplier onboarding, plus Navi Connect, which exposes more than thirty spend management tools over MCP to outside systems including Microsoft Copilot. Workday took its Adoption Agent to general availability to automate release preparation. Serval made Catalyst generally available, with background agents that investigate and propose fixes before an employee files a ticket. ElevenLabs shipped an MCP server alongside async flow APIs and agent concurrency queues, and Deepgram put MCP support into its CLI with full Flux text to speech. Jasper released an MCP connector that grounds Claude output in a customer's brand voice. Instabase rebranded to SuperApp around a shared workspace that keeps a durable record of messages, files, model contributions, tool calls and approvals. Snyk extended its code analysis to Python serverless architectures and LangChain. n8n 2.36.0 refined its human in the loop approval schemas for agent tool execution. And Shopify Sidekick changed app intents to open as full page navigation rather than a modal, handing merchant actions to the third party app's own layout.

The action item: three deprecations, and one of them fails quietly

First, Langfuse set November 16, 2026 as the sunset date for its v3 API and rolled out migration controls in platform and personal settings. That is a calendar item today and an incident in November. Move it while it is still the former.

Second, Voiceflow retired Flash 4.1 and automatically migrated every existing agent to Voiceflow Core 4.1. Nothing in your configuration changed, so nothing will alert you. Re run your evaluation set against the agents you care about and compare it to whatever you measured before the swap.

Third, and this is the one to watch, Ada removed scripted proactive campaigns and deprecated the associated campaign actions in the Embed2 web SDK. Existing integrations keep loading and the deprecated calls simply do nothing, logging a console warning nobody reads. Code that fails loudly gets fixed on Tuesday. Code that succeeds at doing nothing can run for a quarter.

And one deadline from last week's issue lands today: the Manus deletion window opens August 23 and closes August 24, with the restore portal reopening August 25. If anyone on your team meant to export their workflows, that is a today problem rather than a Monday one. Separately, Kilo Code, whose breach disclosure ran in the last two issues, shipped a data export tool this week. Whatever else that is, it is the right order of operations for everyone else to copy.

Index Answer

Which agentic AI vendors publish pricing publicly?

Fewer than half, and the more useful finding is that the category has no shared norm at all. Of the 988 vendors the Agentic Index has researched for pricing as of 8 August 2026, 430 publish something and 558 publish no price at any first party source. Only 143 publish a complete entry price, which is the number that matters, because publishing a price and publishing a price you can act on are different things.

Splitting by lane is where the answer stops being a statistic and starts being useful. Coding agents publish at 84 percent. Security and SOC agents publish at 11 percent. Those two sit under the same category label and behave like different industries, because they sell to different buyers through different motions. A blended figure for agentic AI pricing transparency averages them into a number that describes nobody.

Comparability is the harder problem underneath. Of the vendors where the Agentic Index could answer the question at all, 198 of 819 carry an entry price comparable to anything else, and 474 of 864 require a sales call before you can learn a number. Where prices are published, the published entry price runs a median of $29 a month across 275 vendors, with a quarter at $10 or below and the top decile at $449 or above. A median across that spread is a fact about the middle, not a budget.

The practical move is to stop asking whether a vendor publishes pricing and start asking what the price is per unit of. 21 vendors price on an outcome and only 5 publish the rate, so outcome pricing is currently a positioning claim more often than a purchasable term. Ask which meter runs, what happens when it runs faster than forecast, and get the answer in the contract rather than the deck.

Lane by lane publication rates, medians and the full method are on the Agentic Index pricing landscape.

The Agentic Index Brief is published weekly by Agentic Index, the verified directory of 988 agentic AI vendors. Compare platforms by capability at agenticindex.io/compare. Methodology at agenticindex.io/methodology.

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.