← All issues

The Agentic Index Brief

September 27 to October 2, 2026 · Published October 7, 2026

The week in one line

The customer started showing up as software, and commerce began rebuilding the counter for it. Stripe gave agents a wallet with a budget, Shopify opened checkout to browser agents, and Kernel sold an agent a browser session with no account and no API key. Liberate's phone line, meanwhile, now checks whether the caller is a bot and, if so, hands it to a bot of its own, which may be the most efficient customer service call ever placed.

This issue covers September 27 to October 2. The log recorded 171 entries across 171 vendors, 132 of them Verified against a primary source and 39 Partially Verified. Plain agent capability led with 45 entries, then MCP and tool calling with 25, workflow orchestration and integrations with 19 each, and human approval and guardrails with 18. The thread running through most of them is who sits on the other side of the transaction.

The customer is an agent now

For most of this year the agent was the thing you bought. This week a cluster of releases treated it as the thing that buys.

Stripe's Link wallet for agents can now draw on financial insights the consumer has permitted. An agent can work within a budget and suggest stores from purchase history before an approved purchase. When a payment stalls, Link tells the agent what to do next, and eligible purchases can carry purchase protection. It went live first through Meta's Muse.

Shopify added WebMCP tools to checkout. A browser agent can read the active checkout, fill in contact, shipping, discount and payment details, and place the order once the shopper confirms. Merchants set up nothing, and control goes back to the shopper for steps like 3D Secure.

Kernel went a step further. An agent can now buy a browser session on its own through the Machine Payments Protocol. It requests a browser, gets a payment offer, pays with a Stripe token approved through Link and receives connection details. There is no account and no API key, and the price is $0.50 for 30 minutes. That is a signup flow designed for a customer that cannot fill in a form.

Budgets became the common language. The hosted Catalog MCP from Nevermined connects to Claude, ChatGPT and LangSmith Fleet through one consent screen that sets a spending cap and an expiry. The assistant then pays per call from that budget, and disconnecting revokes the grant. The connector from Zapier now works with Muse too, across more than 9,000 apps, limited to the apps and actions the user approves.

The other side of the counter noticed. Liberate launched AI Intercept, which screens inbound calls to an insurance carrier and spots when the caller is a consumer's AI agent rather than a person. Those calls go to Liberate's own agent for quoting and servicing, with an audit trail and escalation to a licensed human. In beta, Lorikeet now flags customer conversations that came from AI agents across chat, email, voice, SMS and WhatsApp.

And the agents started picking up the phone. Agent Phone from Vapi, a remote MCP server in public beta, lets Claude Code or Cursor place a call for a user. The agent dials, works through phone menus, waits on hold, talks to the person and reports back. Waiting on hold has finally found someone who does not mind.

Our read: commerce and service are being rebuilt for a counterparty that is software. The controls converging look more like a corporate card than a login, with a budget, an expiry, a revocable grant and a person who confirms at the moment money leaves. Every product here kept the human at exactly one point, the purchase. The harder question sits on the support side. Once a real share of inbound traffic is agents, a team needs to know which conversations had a person in them, and two vendors shipped that detection this week. Expect “was this a human” to become a standard field on every conversation record, the way channel and language already are.

Somebody else holds the leash

The agent vendor used to be the only party that could see what its agent did. This week a row of security vendors plugged in from outside, mostly through doors the agent makers built for exactly that purpose.

Anthropic's Claude Compliance API did much of the work. Lasso made its integration generally available, listing every Claude user as an agent in its inventory with the MCP servers and skills they used. Island now receives Claude Code, Cowork, Claude for Microsoft 365 and Claude Science sessions, each as one transcript tied to a verified user and scanned for regulated data, source code and secrets. Pi reads the same feed to see every Claude Code session in an enterprise organization, and reports where a developer overrode a security gate.

Airia went inline instead. Its policy checks for Claude are now generally available, so prompts and tool, MCP, skill and plugin results get an allow or deny decision before Claude acts on them. One setting covers chat, Claude Code and Cowork.

The other door is the hook. Snyk made Govern Agent Behavior generally available in Evo, starting with an approved list of MCP servers. When a coding agent reaches for one outside the list, Snyk logs or blocks it on the developer's machine through local hooks in Claude Code, Cursor, Codex and GitHub Copilot. AI Lens from DeepKeep uses the same hooks to check prompts, shell commands, file reads and MCP calls, and sends destructive commands to the developer for approval.

Platforms opened their own trust layers to outsiders. UiPath now lets admins bring their own safety vendor into its AI Trust Layer, in preview, so guardrails run under the customer's own vendor agreement and region. Enforcement from Operant reached Microsoft 365 through Purview, covering Copilot prompts, responses and tool calls. Noma now finds agents on employee laptops using the EDR or MDM a company already runs, and files each one as approved, under review or blocked.

Even the judge became a separate party. ToolCallJudge in Pydantic AI puts a second model in front of selected tool calls and asks it one risk question. A yes blocks the call, a no lets it run, and an unsure answer can become a request for human approval. Tuskira released an open source gateway that checks allow lists on every call between coding agents and the MCP servers they use. At every scale the idea is the same: the thing that decides is not the thing that acts.

Our read: agent governance is unbundling from the agent. The vendor builds the hooks and the compliance feed, and somebody else writes the policy and keeps the logs. Endpoint, email and cloud security all settled this way, and it reframes the review. The question for a coding agent is no longer only which controls it ships, but what it exposes to the controls you already own. A product with no hooks and no audit feed is starting to look like a laptop that refuses the EDR agent.

The agent got a job description

Last week the approval prompt learned to tell a read from a delete. This week the tiers got names, and agents started arriving with a role definition attached.

AutoGPT v0.8.2 gives AutoPilot three modes, Ask First, Auto and Unsupervised, and workflows it starts now pause before an irreversible action. Zite added Auto as a fourth mode beside Build, Plan and Chat. It applies most changes without an Approve click but still stops for sign ins, secrets and new apps. Claude Code made auto mode the starting permission mode on every plan and provider when nothing else is configured, extending the change logged last week.

Levelpath's Ranger wrote the most complete job description of the week. Its agents run five procurement workflows end to end and start work unprompted, such as opening a renewal review 30 days before a contract expires. Customers set an autonomy ceiling for each workflow. An approval agent can approve but cannot reject, so every rejection reaches a person. The one decision the software is not trusted with is telling someone no, an instinct plenty of managers will recognize.

Automat made Ace generally available with its own computer, email address, phone number and accounts. It takes requests over Slack, Teams, email, SMS, WhatsApp and phone. It logs every action, handles small reversible tasks alone and asks a designated manager before anything consequential. That reads less like a feature list than an onboarding checklist.

Healthcare wrote the strictest version. Heidi II turned the ambient scribe into an agent that prepares the day's charts, chases pathology results and fills referral forms. Clinicians choose between approving every step and letting routine work run. Prescribing, claims, deleting records and diagnosis always wait for sign off. The new Berry agent from Scribeberry drafts and faxes referral letters, and nothing leaves until the clinician confirms a review card.

Approval itself got committee rules. A policy in Budibase can now name the approvers, a voting rule of any, unanimous or majority, and a condition such as an order above 1,000. Agent governance now has quorum rules, which means meetings cannot be far behind. Komodor requires a tool permission policy before any agent leaves its setup wizard. The MCP servers from Glean now confirm every write by default, because not every MCP host has an approval step of its own.

Some agents, meanwhile, stopped waiting to be asked. The AI SRE from Better Stack now starts investigating every incident the moment it opens and posts a root cause summary to Slack. Triage rules in CodeRabbit can merge low risk pull requests once checks and reviews pass. The remediation loop from Trent dropped the step where a user signed off on the plan before fixes began.

Our read: the agent is being specified the way a role is, with what it may do alone, who it reports to, what always needs a signature and how high it can climb. The unit of control is moving from the single action to the workflow. Levelpath sets a ceiling per workflow, Budibase a rule per tool, Heidi a list of decisions that never delegate. The useful artifact is no longer the permission dialog. It is the written map of where the agent stops, and the vendors worth a shortlist are the ones who can hand it over.

The agent got a desktop

GitHub Copilot can now operate desktop apps on macOS and Windows, in public preview in Copilot CLI and the Copilot app. It reads the screen, clicks, types, scrolls and drags, including in software with no API or MCP integration. That widens the coding agent's job from the repository to the rest of the machine.

The screen is also getting cheaper to drive. H released Holo4, its own agentic models in a 27B dense size and a 35B mixture of experts size, as open weights. H reports 85.2% on OSWorld for the 27B at $0.08 per task, with every benchmark run published. Skyvern made its rewritten 3.0 engine the recommended one, citing about 100,000 production runs with average run time cut by more than half and cost per run down 22.5%.

The machine is now something you rent along with the agent. A new MCP server from Simular lets Claude Code, Codex or Cursor hand plain English tasks to its Sai agent, which works on a Windows cloud computer Simular hosts. Manus 2.0 added Remote Control, where a voice command from a phone has Manus operate the desktop while the screen streams live. The headless browser from Lightpanda reached 1.0 and now enforces CORS by default, so a hostile page can no longer read internal services from inside the network.

Our read: computer use is crossing from demo to utility, and the tell is that vendors now quote it per task and per run. An API was always the polite way into an application. The screen is the universal one, reaching software that never got an integration. That is also why the governance in the sections above matters most here, because an agent that can click anything inherits every permission of the person at the keyboard.

Market notes

Pricing tried every unit at once. Twin dropped credit metering for unlimited usage on every plan, at $29 a month for Plus and $149 for Pro. Retell went the other way, moving every remaining self serve workspace to prepaid credits that stop at zero unless auto recharge is on. Hatchet replaced its self serve plans with pay as you go, with the first million task runs free each month and $30 per million after.

Capy 0.4.0 lets teams run its coding agent on subscriptions they already pay for, and asks before falling back to its own credits. JetBrains launched Junie Lite, a free tier on a free model, and HubSpot put Agent Builder custom agents into its refreshed Starter plan.

The missing half from last week's census kept arriving. Akka SDK 3.6.6 runs agent evaluations as ordinary JUnit tests with a minimum pass rate gate, and its RedKit fails the suite when a prompt injection lands. Ema now writes a test set of up to 100 cases from a builder's goal and grades both the answer and the plan. Pega 25.1.4 added agent testing with an evaluation portal.

Confident AI began judging an agent's whole trajectory rather than its last answer, and LiteLLM launched Lens, agents that review gateway traces and group recurring failures. The agents reviewing agents now have agents of their own.

The plainest signal of the week came from a retirement. Pipedream put Workflows into maintenance mode and will shut it down, along with its String AI builder, on March 31, 2027, deleting all Workflows data including connected account credentials by April 30. Connect, the MCP servers and the API proxy carry on as the company's focus. A workflow company decided its future is the connector rather than the workflow.

Ada also set December 15 as the retirement date for its Chat experience, and the MCP adapters for JavaScript from LangChain reached 2.0 with breaking changes.

Vendors kept training their own models. ElevenLabs released Eleven v4 and v4 Turbo, the latter at a stated median latency of about 100 ms for agents. Voice 3 from Decagon speaks through Chord, its own speech model for customer calls, while a stronger model reasons in parallel. Speechmatics released Oak 1, a medical speech to text model listed at $0.15 per hour for batch.

Sourcegraph moved Agentic Batch Changes off Codex and Claude Code onto a coding agent it manages itself, and OpenAI made GPT-6.1 Sol the default model in the Codex CLI. Inworld acquired Ultravox, a platform for building real time voice agents.

The long running agent got cheaper to house. camelAI launched camelRun, an open source runtime for long lived agents at $0.01 per hour of active agent time plus model usage, which undercuts most parking meters. Kong launched Volcano, a hosted platform whose durable functions can resume for up to a year.

Hayhooks 2.0 from Haystack added execution that resumes on any replica after a crash. Cloud threads in Hoplite now take a goal and keep queuing runs until it is met or the budget runs out.

Where the agent runs kept moving too. Enterprise workspaces on Lovable can now switch on EU inference for every model request, both while building and inside published apps. Sonar brought its Remediation and Hunter agents to self managed SonarQube Server, including locked down VPCs, on the customer's own model provider. Okta now puts several MCP servers behind one authorization server, keeping the end user attached through every agent hop.

In the regulated verticals, the work got more specific. Clio Work now builds case chronologies, settlement calculators and firm dashboards from a description. LexisNexis brought Protégé to the Middle East, starting with the UAE. Tungsten launched invoice agents that check for fraud and duplicates before payment, each recommendation carrying a confidence indicator and a short explanation.

What the week says about the category

A hundred and seventy one entries, and one shift under most of them. The agent stopped being only the product and became a participant. It showed up as a customer at checkout, a caller on hold, a worker with a desktop and a job description, and the subject of somebody else's security policy.

Each role arrived with its paperwork. The buyer got a budget and an expiry. The caller got a detection flag. The worker got an autonomy ceiling and a manager. The auditor got hooks and a compliance feed.

The category spent the summer arguing about what agents can do. This week it filled in forms about who they are, which is usually what happens right before something becomes normal.

Index Answer

Which agentic AI platforms meet enterprise security and compliance requirements?

Fewer than a quarter of them. Of the 554 platforms the Agentic Index grades across its four horizontal lanes, 118 document all four enterprise governance capabilities in full. Those are security and identity governance, deployment and data residency, observability and auditability, and human oversight before an agent acts. That is 21.3 percent of the field.

The certificate is the easy part. Security and identity, meaning SOC 2 or ISO 27001 with single sign on and role based access, is the most widely documented of the four, at 335 platforms. Deployment and data residency is the least, at 281, covering self hosting or a private VPC and stated control over where agent data is processed.

The near misses cluster in two places. Of the 141 platforms sitting exactly one capability short, 56 miss on residency alone and 55 on human oversight alone. Only 20 miss on security alone, and 10 on observability.

So the governance gap in agentic AI is not a paperwork gap. It is about where the agent runs and who can stop it, which is the ground this week's releases were fighting over. Residency moved at Lovable, Sonar and UiPath. Oversight arrived from outside the agent at Airia, Snyk and DeepKeep.

That second pattern changes how the number reads. More of an agent's oversight now comes from a layer the customer adds rather than one the vendor ships. The 118 platforms that clear the bar document all four controls themselves, and the method and full list are on the Agentic Index enterprise security page.

The Agentic Index Brief is published weekly by Agentic Index, the verified directory of 955 agentic AI vendors. Compare platforms by capability at agenticindex.io/compare. Methodology at agenticindex.io/methodology.

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.