Notes de version
Le radar montre où en sont les choses aujourd'hui. Voici ce qui a changé pour y arriver : chaque entrée ajoutée, déplacée, réécrite ou retirée, version après version.
September 2026
27 entrées modifiées
State of the domain
The agentic shift has stopped being a demo and started being an operations problem. Across three harvests totalling more than 6,000 signals, the strongest recurring theme is that the interesting decisions now sit at the boundaries of agents: their memory, their tools, their sandboxes, and their supply chains. Security signals arrived attached to almost everything — Langflow RCE, a LiteLLM gateway compromise, malicious Git configs in coding agents, the Hugging Face/OpenAI incident, prompt-injection and exfiltration advisories against GitHub Copilot and Copilot CLI, a pgvector HNSW index-build CVE with SQL injection in common integrations, and Milvus authentication-bypass and unauthenticated-management-port advisories. Meanwhile older, settled debates are fading: privacy-preserving training, HDFS migration, and v1-era model serving no longer need standalone opinions.
The ring shape reflects that: 58 assess and 38 trial against 26 adopt and 14 hold. This is a domain where credible categories are appearing faster than production evidence.
This release
Seven new entries, ten refreshes, one promotion, nine retirements.
The promotion is CrewAI to adopt, on the strength of named enterprise case studies (PwC, IBM, Gelato, AWS) and reported large-scale operational usage. We handle the framework risk through production controls rather than by withholding adoption — and we say so explicitly in the new agent-framework-supply-chain-risk hold, which argues against adopting agent harnesses and tool ecosystems without sandboxing, dependency control, least privilege and runtime monitoring.
New assess entries carve out categories that have outgrown their parents: agent-memory-layers (Mem0, Zep/Graphiti, Cognee, Letta, TencentDB, Redis and Oracle agent memory) is now distinct from RAG; agentic-data-control-planes (Orchestra, Kaarvi, DataBahn, Astera Centerprise AI) inverts the platform-to-agent relationship; agentic-test-automation and agentic-vulnerability-research-for-code (Kritt, OpenAI Aardvark/Codex Security) point agents at delivery quality and secure review. ai-control-protocol-evaluation and Apache Fluss stay deliberately early.
Refreshes are mostly rationale rewrites, not ring changes. mcp-by-default sharpens from generic protocol caution to a specific warning about deploying MCP without identity and tool-boundary controls. ai-risk-governance-frameworks moves the decision point from framework mapping to auditable evidence, citing CEN/CENELEC's first AI Act standard. Devin Desktop (formerly Windsurf) gains named deployments — Nubank, Ramp, Itaú, Goldman Sachs — plus a published critique.
What we're watching
The watchlist carries 45 candidates into the next cycle, each one launch post short of an entry. Our open questions: whether agentic data control planes and agentic testing carry real capability or marketing, whether provenance tooling (Cisco Model Provenance Kit, FlureeDB, SettleTop) moves past launch announcements, and whether AI-BOM practice extends credibly to datasets, licensing and serialized-model risk.
Changement d'anneau
1Ajouté
7- Agent Memory LayersÉvaluerAI & Data Engineering
- Agentic Data Control PlanesÉvaluerData Platforms & MLOps
- Agentic Test AutomationÉvaluerDeveloper AI & Delivery
- Agentic Vulnerability Research for CodeÉvaluerDeveloper AI & Delivery
- AI Control Protocol Evaluation for Untrusted AgentsÉvaluerAI Security & Governance
- Apache FlussÉvaluerData Platforms & MLOps
- Unsandboxed Agent Framework ExecutionSuspendreAI & Data Engineering
Réécrit sur la base de nouveaux éléments
10- Agent SkillsÉvaluerDeveloper AI & Delivery
- AI Risk Governance FrameworksAdopterAI Security & Governance
- AI SBOMTesterAI Security & Governance
- Devin and WindsurfTesterDeveloper AI & Delivery
- Digital ProvenanceÉvaluerAI Security & Governance
- GitHub CopilotAdopterDeveloper AI & Delivery
- MCP by DefaultSuspendreAI Security & Governance
- MilvusÉvaluerData Platforms & MLOps
- pgvectorTesterData Platforms & MLOps
- Sandboxed Execution for Coding AgentsTesterDeveloper AI & Delivery
Retiré du radar
9Les entrées retirées conservent leurs pages. Un retrait n'est pas un verdict contre une technologie — il signifie que le radar n'a plus besoin d'un avis distinct à son sujet.
- BloomÉvaluerAI Security & GovernanceRemplacé par 3 entrées
- Federated LearningÉvaluerAI Security & GovernanceRemplacé par 2 entrées
- Figma MakeTesterDeveloper AI & DeliveryRemplacé par 1 entrée
- Hadoop HDFSSuspendreData Platforms & MLOpsRemplacé par 2 entrées
- Monte Carlo Data ObservabilityÉvaluerData Platforms & MLOpsRemplacé par 1 entrée
- PageIndexÉvaluerAI & Data EngineeringRemplacé par 3 entrées
- Pi Coding AgentTesterDeveloper AI & DeliveryRemplacé par 4 entrées
- Prefect 3ÉvaluerAI & Data EngineeringRemplacé par 2 entrées
- Seldon Core v1SuspendreData Platforms & MLOpsRemplacé par 2 entrées