Release notes

The radar shows where things stand today. This is what changed to get there: every entry added, moved, rewritten or removed, release by release.

September 2026

42 entries changed

State of the domain

The centre of gravity has moved from "which framework?" to "can we operate, evaluate and contain it?" Two of the most widely deployed tools in this radar moved backwards on security evidence: LangChain/LangGraph dropped from adopt to trial after advisories covering serialization, path traversal, sandbox escape and secret exposure, and MLflow 3 moved to trial after CVE-2026-64849 — an unauthenticated SSRF — was reported as actively exploited for cloud credential theft (remediated in 3.15.0). Neither is a recommendation to stop; both are recommendations to pin versions, control exposure and patch.

Agent tooling is consolidating. AutoGen is described as entering maintenance while Microsoft Agent Framework hit 1.0 GA with Agent Harness and Hosted Agents; the MCP gateway pattern is productizing via Kong AI Gateway 2.0 GA and Nutanix's MCP Gateway. Meanwhile MCP has grown its own risk surface, with the OWASP MCP Top 10 now a standalone assess entry.

Ring counts after this release: 25 adopt, 41 trial, 57 assess, 15 hold — an assess-heavy shape that reflects a domain still generating more candidates than proven practice.

This release

This is a pruning release. Twenty-one entries were retired, overwhelmingly for absence of signal rather than disapproval: Agent2Agent Protocol, Mem0, browser-use/Stagehand, DataHub/OpenMetadata, KServe, Argo CD/Flux GitOps, Backstage AI plugins, Cline/Roo Code, plus settled holds such as standalone AutoML, bespoke ETL scripts, homomorphic encryption in production AI and blind LLM-as-judge. Several were absorbed by broader entries — serving now sits with vLLM, NVIDIA Dynamo/LLM-D and Kubernetes for AI Inference; typed tools fold into structured outputs.

Three entries reached adopt on repeated production evidence: NIST AI RMF (new use cases and profiles, Workday control-framework alignment, ICF's governed federal chatbot), LLMOps platforms (ZenML case studies plus LangSmith at Schneider Electric, Rippling, Toyota) and Dagster (US Foods, easyJet Holidays, PostHog). AI platform engineering entered trial on Nirmata, Pulumi Neo and Itential FlowAI pilots.

Six additions, all assess: Rerun (multimodal robotics/physical-AI data), agent evaluation harnesses (MAS-FIRE, workflow-arena, YGO-Bench, HarnessOpt-Bench), agent trajectory evaluation (AgentLens), Microsoft's Agent Governance Toolkit, Red Hat's asago, and the OWASP MCP Top 10. Refreshed write-ups reframe prompt injection defenses around permission bounding and tool-call monitoring, and AI-augmented CI/CD around GitInject-style attacks on agents with repository privileges.

What we're watching

Evaluation of governance itself is the strongest emerging theme: AI control protocol evaluation, lineage-aware monitor transfer, and agentic security evaluation (still vendor efficiency claims, not benchmarks). Also tracked: MCP-native data platforms (Datris), Estuary's Rust rewrite for transaction-safe agents, managed desktop sandboxes (AWS WorkSpaces for AI agents), IDE rules-as-artifacts, AI-driven cloud/AI cost platforms (North v3), and a cluster of very early open-source DataOps repos — interesting shape, no adoption evidence yet.

Moved ring

6

Added

6

Rewritten on new evidence

9

Taken off the radar

21

Removed entries keep their pages. Retiring is not a verdict against a technology — it means the radar no longer needs a separate opinion on it.