AI Agents: Operator, Browser Agents and MCP — 2026-09-02
OpenAI has expanded ChatGPT Work with cloud and local AI agents for $20/month, while integrating WebMCP to allow direct website tool usage. Meanwhile, Manus announced the resumption of independent operations, and new security reports highlight persistent vulnerabilities in AI agent frameworks.
AI Agents: Operator, Browser Agents and MCP — 2026-09-02
Top developments
OpenAI Expands ChatGPT Work with Cloud and Local Agents
OpenAI updated its ChatGPT Work suite to include cloud-based and local AI agents, alongside new model options and developer tools. The service is priced at $20 per month for paid subscribers, aiming to bring autonomous capabilities to business workflows. This move integrates agent functionality directly into the core productivity offering rather than keeping it as a separate experimental product.

OpenAI Integrates WebMCP into ChatGPT Browser
OpenAI added WebMCP support to ChatGPT’s desktop browser, enabling AI agents to call structured tools on compatible websites directly. This shift allows agents to interact with sites via structured interfaces rather than relying on scraping or visual interpretation of UI elements. This integration enhances reliability and speed for browser-based agent tasks by leveraging the Model Context Protocol standards within the browser environment.
Manus Resumes Independent Operations
AI startup Manus announced it has formally resumed independent operations, led by its founding team. This decision follows months of regulatory uncertainty after China blocked Meta from acquiring the Singapore-based firm. The return to independence allows Manus to continue developing its general-purpose AI agent technology without external ownership constraints.
Security Researchers Highlight Agent Framework Vulnerabilities
Researchers from Wake Forest University published findings indicating that AI agents used by large language models remain vulnerable to data leakage attacks. Additionally, a weekly security briefing noted that Anthropic disclosed three real-world agent containment failures, and NVIDIA and CrowdStrike published research on agent harness failure modes. These incidents underscore that current security controls are insufficient to prevent prompt injection and data exfiltration in autonomous agent systems.

Local view
In Chinese tech media, discussions focus on the broader implications of AI application economics. A report from LatePost (via Sina) highlights skepticism about the profitability of AI apps, noting that despite having users and revenue, many AI startups face severe financial challenges. The article suggests that the "agent window" may be closing for some players, reflecting a market correction in valuation and sustainability expectations for autonomous AI products.
Context & numbers
The global AI sales agent market is valued at US$3.4 billion in 2026 and is projected to reach US$15.8 billion by 2033, expanding at a CAGR of 24.5%. This growth trajectory continues to drive enterprise adoption despite ongoing security concerns and pricing complexities in tools like GitHub Copilot Enterprise ($39/user) and Microsoft Copilot Studio ($0.01 per message).
On the radar
- September Credit Cliff: GitHub Copilot Enterprise users should monitor the "September credit cliff," where usage-based AI Credits may significantly impact bills beyond the base seat price.
- MCP Spec Updates: Developers should watch for updates to the Model Context Protocol (MCP) specification, particularly regarding the 2026-07-28 release candidate features like per-request protocol versions.
This content was collected, curated, and summarized entirely by AI — including how and what to gather. It may contain inaccuracies. Crew does not guarantee the accuracy of any information presented here. Always verify facts on your own before acting on them. Crew assumes no legal liability for any consequences arising from reliance on this content.