What is this?
AI agents are models that don't just answer — they act. They use tools, browse, write files, run code and complete multi-step tasks with minimal supervision. Agents are the industry's biggest bet for this decade. They are also its biggest new security question, because an AI that can act can be tricked into acting badly.
Key tools & players
- Claude (Anthropic) — computer use, Claude Code, and MCP, the open standard for connecting agents to tools
- OpenAI — Operator, Deep Research, Agents SDK
- Google — Gemini agents and the A2A agent-to-agent protocol
- Manus, Devin — autonomous task agents
- Frameworks: LangChain, CrewAI and hundreds more
Milestones
- 2023-2025 — AutoGPT's hype gives way to working agents, MCP becomes the USB standard for their tools, then Operator and Manus ship
- Aug-Sep 2026 — Agents become attack labour: one hits 460+ servers alone, another operator breaks into 395 organisations (our coverage)
- Aug 2026 — A US appeals court rules that users, not the agent, access a website
- Aug 2026 — Anthropic defaults Claude Code to auto mode and raises its own misalignment risk to low, a first for a frontier lab
- Aug-Sep 2026 — DeepSeek and OpenAI open-source their agent harnesses, then OpenAI rents its own out as a hosted API (our coverage)
- Sep 2026 — OpenAI rates Astra critical for cyber, a first, and locks its attack skills to vetted defenders (our coverage)
- Sep 2026 — Visa, Mastercard and Ant agree to recognise each other's checks on agents that pay (our coverage)
- Sep 2026 — Anthropic's chief asks the industry to pace itself, naming agent swarms as the reason (our coverage)
- Sep 2026 — Agents hit three public sites unbidden, one an Australian portal, and OpenAI halts training of its newest models (our coverage)
- Sep 2026 — Nvidia ships the first hardware standard for caging agents, with Cisco, Microsoft and seven more behind it (our coverage)
Mini glossary
- Tool use: a model calling external functions — search, code, payments
- MCP: Model Context Protocol, the open plug for wiring tools to agents
- Sandbox: an isolated environment that limits what an agent can touch