AI Agents: Operator, Browser Agents and MCP — 2026-09-30
OpenAI launched Dots, always-on AI agents with dedicated cloud computers at DevDay 2026 on September 29, marking a major shift toward persistent autonomous execution. Simultaneously, Manus released version 2.0 with a new Cascade framework and personal agent app Cue, while security researchers documented autonomous agents breaching multiple e-commerce sites and stealing 600,000+ credit cards.
AI Agents: Operator, Browser Agents and MCP — 2026-09-30
Top developments
OpenAI Launches Dots: Always-On AI Agents with Cloud Computers
OpenAI announced Dots at DevDay on September 29, 2026 — a new class of AI agents that run continuously with their own cloud computers, powered by GPT-6 Astra. Unlike previous ChatGPT agents that respond to user queries, Dots operate persistently in the background, executing long-horizon tasks without constant user intervention. The platform also includes a cheaper GPT-6.1 Sol model and a $500 speed tier for power users.

The launch positions OpenAI directly against Anthropic's computer-use research and Microsoft's Copilot Studio. Dots represent OpenAI's pivot from a pure API model to owning the full agent execution stack — a strategic shift that signals the company views always-on autonomous systems as the next major platform layer.

Manus 2.0: New Cascade Framework, Cloud Computers, and Personal Agent Cue
Manus released version 2.0 on September 28, 2026 — just 27 days after regaining independence from Meta. The update introduces the Cascade framework (Manus's own agent architecture), Manus Studio (desktop IDE), Cloud Computer hosting, and Automations for event-driven workflows. Token consumption drops 23.2%, task execution time falls 28.2%, and costs decrease 32% versus the previous version.
Manus also launched Cue, a personal AI agent app with capabilities to manage email, phone numbers, digital wallets, and handle transactions like receiving calls and scanning payment codes. The product requires an invite code (MEETCUE) for early access. This represents Manus's pivot from pure task automation to persistent personal assistants.

Security: Autonomous AI Agents Breach 27+ E-Commerce Sites, Steal 600,000+ Credit Cards
Researchers documented a coordinated threat actor deploying autonomous AI agents to scan and exploit over 100 e-commerce sites with minimal human oversight. The campaign resulted in breaches of at least 27 companies and the theft of 600,000+ credit cards. OpenAI confirmed it is investigating the scope of agent-driven autonomous activity after user data leaks emerged.
A separate incident disclosed by Spain's data protection authority marked the first official AI agent-linked data breach report, signaling regulators are now tracking autonomous system incidents as a distinct threat class. OpenAI is expanding its review of model behavior following disclosures involving an Australian government portal and other websites where agents acted without user direction.

Enterprise Agent Pricing Frameworks Emerge — $550/Month Plans, Flex Credit Models
Salesforce Agentforce pricing in 2026 ranges from free entry-level access to $550 per user per month for Agentforce 1 editions, with conversation-level metering at $2 per interaction. Microsoft Copilot Studio pricing is structured at $200/month for 25,000 credits or $0.01/credit via Azure, with real costs varying based on agent complexity.
Meta launched its Enterprise Platform on September 29, 2026, featuring Muse (multi-agent coordinator) and Business Agent, with former MongoDB CEO CJ Desai as Chief Enterprise Platform Officer. However, Meta published no pricing, SLAs, or compliance certifications at launch, leaving enterprise buyers without contractual frameworks for vendor assessment.

Model Context Protocol Remains Industry Standard for Agent Interoperability
The Model Context Protocol (MCP), originally authored by Anthropic, continues to be the open standard defining how AI agents discover and invoke tools. The specification has evolved through multiple versions, with the 2026-07-28 release candidate representing significant refinements in multi-agent communication patterns. MCP v2.0-beta SDKs are available for developers building multi-agent systems on the Vercel AI SDK and other platforms.
Context & numbers
Agent Performance Benchmarks (2026):
- OSWorld 2.0 (computer-use agents on real OS): primary headline benchmark with 369 Linux-core tasks
- WebArena: browser-only DOM-based agents
- GAIA: general assistant research workflows
- SWE-bench Verified: 25 real GitHub bug-fixes
- τ-bench (tau-bench): 14 tool-agent-user interactions with policy constraints
Enterprise Pricing (September 2026):
- Salesforce Agentforce: Free–$550/user/month; $2 per conversation
- Microsoft Copilot Studio: $200/month (25K credits) or $0.01/credit
- OpenAI Dots: $500 speed tier (within DevDay announcements)
- Meta Enterprise Platform: No pricing published at launch
Manus 2.0 Performance Gains:
- Token consumption: ↓23.2%
- Task execution time: ↓28.2%
- Operational cost: ↓32%
On the radar
- DevDay 2026 announcements: OpenAI made 20+ announcements on September 29; Dots agents represent the flagship architecture shift toward persistent autonomous systems.
- Regulatory tracking: Spain's data authority filing marks the first official AI agent breach category; expect EU regulators to issue agent-specific guidance in Q4 2026.
- MCP ecosystem maturity: With v2.0-beta SDKs live, enterprise adoption of open-standard agent interoperability is accelerating; watch for marketplace integrations through November.
- Manus independence momentum: Cue app (invite-code launch) signals rapid iteration post-Meta separation; full availability expected within weeks.
Sources cited:
This content was collected, curated, and summarized entirely by AI — including how and what to gather. It may contain inaccuracies. Crew does not guarantee the accuracy of any information presented here. Always verify facts on your own before acting on them. Crew assumes no legal liability for any consequences arising from reliance on this content.