Release notes

The radar shows where things stand today. This is what changed to get there: every entry added, moved, rewritten or removed, release by release.

September 2026

27 entries changed

State of the domain

The agentic shift has stopped being a demo and started being an operations problem. Across three harvests totalling more than 6,000 signals, the strongest recurring theme is that the interesting decisions now sit at the boundaries of agents: their memory, their tools, their sandboxes, and their supply chains. Security signals arrived attached to almost everything — Langflow RCE, a LiteLLM gateway compromise, malicious Git configs in coding agents, the Hugging Face/OpenAI incident, prompt-injection and exfiltration advisories against GitHub Copilot and Copilot CLI, a pgvector HNSW index-build CVE with SQL injection in common integrations, and Milvus authentication-bypass and unauthenticated-management-port advisories. Meanwhile older, settled debates are fading: privacy-preserving training, HDFS migration, and v1-era model serving no longer need standalone opinions.

The ring shape reflects that: 58 assess and 38 trial against 26 adopt and 14 hold. This is a domain where credible categories are appearing faster than production evidence.

This release

Seven new entries, ten refreshes, one promotion, nine retirements.

The promotion is CrewAI to adopt, on the strength of named enterprise case studies (PwC, IBM, Gelato, AWS) and reported large-scale operational usage. We handle the framework risk through production controls rather than by withholding adoption — and we say so explicitly in the new agent-framework-supply-chain-risk hold, which argues against adopting agent harnesses and tool ecosystems without sandboxing, dependency control, least privilege and runtime monitoring.

New assess entries carve out categories that have outgrown their parents: agent-memory-layers (Mem0, Zep/Graphiti, Cognee, Letta, TencentDB, Redis and Oracle agent memory) is now distinct from RAG; agentic-data-control-planes (Orchestra, Kaarvi, DataBahn, Astera Centerprise AI) inverts the platform-to-agent relationship; agentic-test-automation and agentic-vulnerability-research-for-code (Kritt, OpenAI Aardvark/Codex Security) point agents at delivery quality and secure review. ai-control-protocol-evaluation and Apache Fluss stay deliberately early.

Refreshes are mostly rationale rewrites, not ring changes. mcp-by-default sharpens from generic protocol caution to a specific warning about deploying MCP without identity and tool-boundary controls. ai-risk-governance-frameworks moves the decision point from framework mapping to auditable evidence, citing CEN/CENELEC's first AI Act standard. Devin Desktop (formerly Windsurf) gains named deployments — Nubank, Ramp, Itaú, Goldman Sachs — plus a published critique.

What we're watching

The watchlist carries 45 candidates into the next cycle, each one launch post short of an entry. Our open questions: whether agentic data control planes and agentic testing carry real capability or marketing, whether provenance tooling (Cisco Model Provenance Kit, FlureeDB, SettleTop) moves past launch announcements, and whether AI-BOM practice extends credibly to datasets, licensing and serialized-model risk.

Moved ring

1

Added

7

Rewritten on new evidence

10

Taken off the radar

9

Removed entries keep their pages. Retiring is not a verdict against a technology — it means the radar no longer needs a separate opinion on it.