The AI agents news in 2026 worth your time comes down to two shifts. Agents moved into jobs with real consequences, such as paying for things and running supply chain phone calls. The rules caught up at the same pace, with the first joint government guidance on agent security and EU transparency duties that took effect on August 2.
An agent here is software that uses a language model to choose its next step and call tools. This roundup covers what happened up to mid-September and what it changes for teams shipping agents.
AI agents enterprise news: seats now come with credits
Enterprise vendors are changing how they charge for agents, and the price list shows how they expect agents to be used.
On September 3, 2026, Salesforce announced new editions for Agentforce Sales and Agentforce Service among others. Each seat price now includes an allowance of Flex Credits, the unit Salesforce uses to meter agent work.
| Edition | Price per user per month | Flex Credits included |
|---|---|---|
| Core | $195 | 500,000 |
| Advanced | $395 | 1 million |
| Max | $550 | 2.75 million |
The structure is a hybrid. The seat pays for the person, and the credits pay for what agents do on that person's behalf. Finance teams now forecast a new quantity: how much work the software does when nobody is watching.
Flex Credits is a name that sounds like a gym membership and bills like a utility. Plan for the utility half.
For builders, the lesson is to measure consumption per task before a pilot ends. An agent that retries a failing lookup burns credits on every attempt, and metered pricing turns that bug into a line item. Our map of agentic AI companies and the layers they sell at shows where platform vendors like Salesforce sit against model providers and specialist startups.
AI agent platform startup funding in 2026
Investors are paying the most for agents that own a whole workflow inside one industry.
The clearest example this summer was HappyRobot. On August 4, 2026, Fortune reported that the company raised a $150 million Series C at a $1.2 billion valuation, co-led by Prysm Capital and Eurazeo. HappyRobot builds agents that handle the phone calls and scheduling that keep supply chains moving.
The operating numbers are the interesting part. HappyRobot counts more than 150 enterprise customers, including DHL and Uber, and says revenue grew more than fivefold since its Series B. Net dollar retention, meaning how much existing customers spend now compared with a year earlier, topped 150 percent.
Freight dispatch is an unglamorous place to build a unicorn. Anyone who has spent an afternoon on hold with a carrier understands the demand.
The lesson generalises, in our view. A narrow agent can be judged against a clear outcome, such as a booked pickup. If you are deciding what to build, our list of AI agents worth building for your business in 2026 applies the same test.
Card networks build the rails for agentic AI commerce
Agentic commerce means an agent completes a purchase for a person. The payment networks spent late 2025 building the plumbing, and that plumbing is what any shopping agent built in 2026 will plug into.
The hard problem is identity: proving a checkout came from an agent the shopper authorised. Visa's Trusted Agent Protocol is described as a framework for verifying agents and blocking malicious bots, backed by controls such as spending limits and approval workflows.
Mastercard's version is Agent Pay. On October 27, 2025, PayPal announced it would bring Agent Pay into its wallet and pilot the Mastercard Agent Pay Acceptance Framework with agents and merchants. Both lean on tokenization, which swaps the card number for a stand-in credential, plus an identity check before purchase.
Without that verification step, a merchant cannot tell a sanctioned shopping agent from a script with a stolen card and very good manners.
If your agent will ever buy anything, design for these rails from the start. Keep payment credentials out of the model's context entirely, and enforce spending limits in configuration outside the prompt, where no input can talk the agent past them.
AI security news today: prompts that become shells
The most important security story of the year is that prompt injection moved from conference demos into CVEs, the public identifiers assigned to real software vulnerabilities.
Prompt injection is an attack where text the agent reads, such as a web page or an email, contains instructions the model follows as if they came from you. On May 7, 2026, Microsoft's security team published an analysis of remote code execution flaws in AI agent frameworks, covering two now-patched bugs in its own Semantic Kernel library:
- CVE-2026-26030, Python: a vector store filter passed model-controlled input to
eval(), so one prompt could run shell commands. Fixed in 1.39.4. - CVE-2026-25592, .NET: a file download function exposed as a tool accepted any path, so an injected prompt could drop a script in the Windows Startup folder. Fixed in 1.71.0.
If you run either package, upgrade today. Neither attack needed access to your servers. The attacker only needed the agent to read their text.
Help Net Security's June 11 coverage of the OWASP GenAI Security Project's State of Agentic AI Security and Governance report says prompt injection maps to six of the ten categories in the OWASP Top 10 for Agentic Applications.
Governments followed. On May 1, 2026, CISA and allied agencies including Australia's Cyber Security Centre published Careful Adoption of Agentic AI Services. The advice is conservative on purpose: begin with low-risk, non-sensitive use cases, and avoid giving agents broad access to sensitive data or critical systems.
The same OWASP coverage points to Meta's Agents Rule of Two. An agent may hold two of these three properties without a person approving its actions:
- Access to private data.
- Exposure to untrusted content.
- The ability to communicate externally.
An agent holding all three can be steered into sending your data somewhere you never intended.
AI governance news, from Brussels to the IRS
Regulation arrived in two forms this year: disclosure duties in Europe and an audit trail in the United States.
On August 2, 2026, the transparency obligations in Article 50 of the EU AI Act took effect, as summarised by the law firm Cooley. A chatbot or AI assistant must tell people they are dealing with AI unless that is already obvious, and AI-generated content needs machine-readable marking. Generative systems already on the market have until December 2, 2026 to meet the marking requirement. Fines reach €15 million or 3 percent of worldwide annual turnover, whichever is higher.
AI expansion in government in 2026 has its best-documented case at the IRS. A GAO report published on March 24, 2026 counted 126 active AI use cases at the agency as of June 2025, up from 10 in August 2022.
More than a quarter of those use cases lacked information on expected benefits, and no single office managed AI investments strategically across the agency. The research group behind much of the work also lost 63 employees who had been working on AI. The IRS agreed with all eight of GAO's recommendations.
Most engineering teams will recognise the shape: 126 projects, and a column for expected benefits that a quarter of them left blank.
What this AI agents news means for your roadmap
Read together, the year's stories point at one checklist. Nothing on it is exotic, and all of it is cheaper before launch.
- Upgrade agent frameworks and follow their security advisories. Semantic Kernel will not be the last library with a tool that can do too much.
- Apply the Rule of Two to every agent, with human approval wherever all three properties meet.
- Keep payment credentials and spending limits outside the model, on the rails the card networks now provide.
- Add AI disclosure to any agent that talks to people in the EU, and track the December 2 marking deadline.
- Meter cost per task during the pilot, since agent pricing is moving toward consumption.
- Write down the expected benefit of each agent before you build it.
For the engineering depth behind that list, Agentic AI Engineering covers tool design and production deployment for LLM-based agents. If you plan to bring in outside help, our guide to AI agent development services covers what belongs in the contract.
Launches will keep filling the news cycle. The stories that change a roadmap tend to arrive as a CVE number or a compliance date, and those rarely get a keynote.