← All issues

The Agentic Index Brief

July 12 to July 18, 2026 · Published July 19, 2026

The week in one line

Six vendors shipped hard caps, depth limits, and deny by default controls on their own agents in three days. The autonomy race has reached the part of the track where someone installs brakes.

Theme 1: The circuit breakers arrive

For two years, the pitch was about what agents can do. This week, the releases were about what they are no longer allowed to do without asking first.

Anthropic Claude Code v2.1.212 puts hard budgets on automated actions: 200 web searches and 200 subagent spawns per session, plus strict authorization prompts before file modifying commands in Plan mode. Apparently, "keep going until something happens" is no longer considered a complete operating policy.

OpenCode 1.18.2 addresses the structural version of the same risk, blocking subagents from launching their own subagents unless an administrator sets an explicit depth limit. CrewAI 1.15.3 adds interception points at step and execution boundaries, allowing teams to pause, inspect, and meter agent actions during a run instead of discovering them later in a dashboard.

Kilo Code now enforces network restrictions on sandboxed commands across TCP, UDP, IPv4, IPv6, and child processes, with an allowlist for approved destinations. GitHub Copilot's code review agent now runs behind a firewall by default. Even procurement got a governor: Coupa validates a supplier's AI credit balance before processing programmatic invoice creation.

Our read: the defaults flipped. Through the spring, autonomy shipped open and controls shipped optional. This week's releases invert that: capped, isolated, and deny by default, with the override tucked away as the setting someone must deliberately go find. That matters because defaults are the real security policy in most deployments. Most deployments never change them.

Buyer question: for every agent you run, what are the caps out of the box, and who on your side is allowed to raise them?

Theme 2: Skills got a ratings agency

The unit of agent capability is consolidating around the skill: a portable file of instructions and tool wiring that an agent can pick up and run.

Exa packaged its search and research capabilities as portable SKILL.md files that drop into Claude Code, Cursor, and Codex. JetBrains AI added an Agent Skills manager to IntelliJ IDEA, plus database skills for DataGrip over MCP. Searchable now lets users convert a chat session into a saved, rerunnable skill.

And Arcade launched SkillBench, an evaluation index that has already graded roughly 39,000 skills across six dimensions, including safety and tool boundaries, assigning each a letter grade from A to F.

Our read: when a unit of software becomes portable and abundant, the bottleneck moves to vetting. A ratings layer appearing in the same week as three new skill surfaces is the tell. Skills are about to flow into enterprise environments the way npm packages did, with the same supply chain questions attached and considerably more initiative once installed. Thirty-nine thousand graded skills means procurement finally gets a transcript.

Buyer question: when an agent in your stack imports a skill from a public repository, whose security review did that skill pass?

Theme 3: The deprecation tax

The launch gets a keynote. The sunset gets a support article.

Make will retire its Chrome app and browser extension on August 31, 2026, driven by the end of Manifest V2 support. Scenarios that rely on it will stop working, and no replacement module is coming.

HubSpot began automatically migrating every custom assistant into Breeze projects, converting the legacy versions to read only and leaving teams to port welcome messages and instructions by hand. The future is automated; the migration checklist remains stubbornly artisanal.

Factory revised its individual plan terms so that customers grant the vendor a nonexclusive license to connected codebases, the kind of clause that costs nothing until legal discovers it after signature.

And Airia launched Model Change Management, which alerts enterprises up to 90 days before a model retirement and bulk migrates the agents built on it. Deprecation risk now has its own product category.

Our read: platform velocity has a passenger side. Forced migrations, terms changes, and model retirements are now recurring costs of running on agentic platforms, and they arrive without launch videos. The change that costs you money this quarter is more likely to sit in a release note footer than in a product announcement.

Buyer question: who on your team owns reading vendor release notes and terms changes, and how would a sunset announced six weeks out actually reach them?

Market notes

Anaconda acquired Kilo Code, which shipped three changelog entries in the same week it changed owners.

Rime raised a Series A and released Coda, a text to speech model with latency under 100 milliseconds.

GPT-5.6 spread through the channel rather than from the source: Kiro added it in three tiers, and Zed picked it up through Amazon Bedrock. Model distribution is increasingly starting to resemble syndicated television: the same headline product, available through an expanding number of intermediaries.

OpenRouter collapsed text, image, video, speech, and embeddings into a single endpoint. And HubSpot's Prospecting Agent reached general availability priced per sourced lead, extending the metered billing shift we covered in the July 11 issue from tokens to outcomes. The meter has moved closer to the business result, where finance can see it more clearly.

The action item

If any Make scenario in your stack touches the Chrome extension, audit it now and plan the migration before August 31.

Make has said plainly that no replacement module is coming, and browser automations tend to be the attic boxes of software: nobody remembers putting them there, but everyone is surprised by what breaks when they disappear.

The Agentic Index Brief is published weekly by Agentic Index, the verified directory of 892 agentic AI vendors. Compare platforms by capability at agenticindex.io/compare. Methodology at agenticindex.io/methodology.

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.