An Overview
AI agents moved closer to becoming practical participants in the digital economy this week. Cloudflare introduced identity and payment infrastructure for autonomous agents, Google outlined a major stateless upgrade to the Model Context Protocol, and SurrealDB made it easier for agents to access persistent data and memory through a hosted MCP service.
Security and governance were equally prominent. The European Commission began enforcing key AI Act requirements, CrowdStrike launched a hands-on agent security challenge with AWS, and Airlock Digital unveiled endpoint-level controls for autonomous software. Together, these developments show that the next stage of agentic AI will depend not only on intelligence, but also on identity, permissions, observability, infrastructure and accountability.
1. Cloudflare gives AI agents an identity and a programmable wallet
Cloudflare announced Cloudflare Wallets and cloudflare.pay, two services designed to help autonomous agents identify themselves and make online payments within limits established by their owners. A Cloudflare account will receive a stable web identity that can be extended to individual agents, allowing a merchant or service provider to determine who authorized an agent’s request.
The wallet system is being designed around a central account balance and separate virtual wallets for individual agents. Owners will be able to set spending limits, restrict agents to approved merchants and define maximum transaction values. Cloudflare has opened wallet-handle reservations, while broader wallet functionality is expected in the coming months.
This is an important step for agentic commerce because payments alone are not enough. Businesses also need to know which person or organization stands behind an autonomous transaction. Cloudflare is attempting to connect identity, authorization and spending controls within the same infrastructure, creating a foundation on which merchants can decide whether to trust an agent.
2. Google helps move MCP from local experiments to cloud-scale infrastructure
Google detailed the 2026-07-28 Model Context Protocol specification release candidate, which removes transport-level session management from MCP’s core. Earlier MCP implementations relied on initialization handshakes, persistent session IDs and session-aware routing—an approach that worked locally but created complications when servers were deployed across containers, load balancers and serverless infrastructure.
Under the updated design, every request becomes self-contained. The change allows ordinary round-robin load balancing, easier failover and serverless deployment without maintaining a persistent connection for every client. The specification also introduces clearer HTTP headers, caching controls, security improvements, multi-step approval flows and better support for long-running asynchronous tasks.
This may prove to be one of MCP’s most consequential infrastructure changes. Connecting one assistant to one local MCP server is relatively straightforward; supporting thousands or millions of agent requests across a distributed cloud is much harder. By making MCP more compatible with standard web infrastructure, Google and the protocol working group are addressing a major obstacle to enterprise adoption.
3. The european commission begins enforcing new ai act requirments
The European Commission began enforcing the EU AI Act alongside national authorities on August 2, 2026. New transparency rules require organizations to inform people when they are interacting with certain AI systems and introduce requirements concerning AI-generated or manipulated content. The Commission can impose penalties of up to €15 million or 3% of global annual turnover for relevant violations, with proportional treatment for smaller companies.
The enforcement milestone matters for AI agent providers because autonomous services can communicate with customers, negotiate transactions and perform business activities without a human appearing directly in the interaction. Organizations will therefore need clear processes for disclosure, record-keeping and responsibility when agents operate in customer-facing environments.
The practical challenge will be making transparency meaningful without overwhelming users with repetitive notices. For enterprises, compliance cannot remain a final legal review conducted after an agent has been built. Disclosure, audit trails and governance controls increasingly need to be designed into the agent’s operating workflow from the beginning.
4. Obsidian security raises $85 million as demand for agent governance grows
Obsidian Security raised $85 million in Series D funding, reaching a valuation of $1.1 billion. Crescent Cove Advisors led the round, with Greylock Partners and Menlo Ventures also participating. The company plans to expand a platform that monitors and governs AI agents operating through services such as Microsoft Copilot Studio, Salesforce Agentforce and Anthropic’s Claude.
The funding arrives as businesses give autonomous agents greater access to customer records, source code and other sensitive enterprise information. Obsidian told Reuters that nearly 70% of its customers already permit agents to interact with business data, illustrating how quickly the agent-security problem is moving from theory to daily operations.
Traditional application security is not automatically sufficient for agents. An agent may access several systems, delegate work to another agent and change its plan while pursuing an objective. Security teams therefore need visibility into identity, permissions, tool use and data movement across the entire task—not only at the initial login.
5. Crowdstrike and AWS launch the “Agents of chao” security challenge
CrowdStrike announced AI Unlocked: Agents of Chaos, a virtual AI red-teaming competition developed with Amazon Web Services. The international challenge carries a $100,000 prize and places participants inside a fictional environment where they must manipulate adversarial agents using prompt injection and other agent-exploitation techniques.
The exercise is designed to demonstrate risks such as agent hijacking, unauthorized actions and the misuse of machine identities. Instead of presenting agent security only through reports and product demonstrations, CrowdStrike is turning it into a practical experience in which participants can observe how an apparently useful agent can be redirected by carefully designed instructions.
Hands-on testing will become increasingly valuable as enterprises adopt agents faster than many employees can learn how to secure them. Red-team exercises can help developers and security teams understand that an agent’s attack surface includes its prompts, tools, credentials, memory and delegated permissions—not merely the underlying model.
6. Airlock digital introduces endpoint governance for trusted ai agents
Airlock Digital unveiled Agentic AI Control & Governance at Black Hat USA 2026. The capabilities are intended to provide command-level and session-level visibility into trusted AI agents, centralize policies and govern what autonomous software is permitted to do on employee endpoints. Customer availability is expected during the third quarter of 2026.
The distinction between trusting an application and trusting everything it subsequently does is becoming critical. An organization might approve a coding or productivity agent to run, but that does not mean the agent should have unrestricted permission to execute commands, modify files or interact with every application available on the device. Airlock is positioning its controls around this second layer of authorization.
Endpoint governance could become an important part of the enterprise agent stack because many consequential actions ultimately occur on laptops, workstations and servers. Controlling agents only at the model or cloud-platform level may leave a gap once those agents begin executing local commands or working across third-party software.
7. SurrealDB launches a hosted MCP server for agent data and memory
SurrealDB introduced a hosted version of its MCP server, removing the need for developers to install and operate a separate server for every database instance. Users can now add a single MCP URL to a compatible AI tool, sign in to their SurrealDB account and allow the assistant to work with authorized cloud resources.
Through the hosted connection, an agent can provision and manage resources, inspect database structures, write and execute queries and answer questions about stored data. SurrealDB also connects the service to Spectron, its agent-memory layer, enabling information to persist beyond a single conversation and be shared across authorized users.
This addresses two persistent problems in agent development: secure access to operational data and continuity across sessions. Agents become more useful when they can work with live information and remember previous decisions, but those capabilities must remain bound by database permissions and organizational access policies.
8. Alibaba cloud introduces a natural-language secops agent
Alibaba Cloud introduced its SecOps Agent, an AI assistant embedded inside the Alibaba Cloud Console. The agent allows users to describe security and operational objectives in natural language, after which it can coordinate workflows across cloud-security products and supporting tools.
Alibaba says the system includes more than 600 specialized skills covering over 20 security domains. Tasks include asset queries, vulnerability remediation, policy enforcement and alert response. Higher-risk actions—such as isolating networks, blocking traffic or modifying policies—are routed through a confirmation mechanism intended to keep sensitive changes under human control.
The announcement demonstrates how security platforms are evolving from dashboards into action-oriented interfaces. Rather than asking an analyst to manually move between several products, an agent can interpret the intended outcome and coordinate the required steps. The most important design issue will be maintaining approval boundaries when the agent moves from gathering information to changing production systems.
Read More
9. Rezolve ai makes its india operation a global agentic ai delivery engine
Rezolve Ai announced that its India operation will serve as the company’s global accelerator for building and deploying enterprise infrastructure for agentic AI. The organization includes 550 engineers, data scientists and AI specialists located across Hyderabad, Pune and Kolkata, supporting more than 1,000 customers worldwide.
The India operation combines AI research, platform architecture, enterprise integration and production delivery. Rezolve also reported approximately $50 million in total contract value from India-led customer and partner engagements, while clearly noting that this figure is not the same as recognized revenue or annual recurring revenue.
The move highlights an important reality of enterprise AI: providing access to an agent platform is only the beginning. Large organizations also need teams that can connect agents to internal data, define controls, redesign workflows and maintain deployments after launch. India’s combination of engineering talent and global-delivery experience makes it a natural center for that work.
Read More
10. marvell targets the memory and storage demands of agentic ai inference
Marvell announced that it would showcase a portfolio of memory, storage and connectivity technologies for agentic AI inference at FMS 2026. The lineup includes PCIe 6.0 enterprise SSD controllers, CXL memory expansion and compression, CXL switching, network-storage DPUs and photonic connectivity technologies.
Agent workloads can place unusual pressure on infrastructure because they often maintain long contexts, call several models and tools, and remain active for longer than a conventional single-prompt interaction. Marvell argues that memory capacity, bandwidth and data movement are therefore becoming as important as raw computational performance.
This is a reminder that the agentic AI race is not taking place only at the model layer. As agents handle longer-running work, infrastructure providers will compete to reduce memory bottlenecks, latency, energy use and inference cost. The companies that make autonomous workloads economically sustainable may become as influential as those building the agents themselves.
Read More
Conclusion
The clearest theme this week was the emergence of infrastructure for an economy in which software agents can act, transact and interact with one another.
Cloudflare focused on identity and payments. Google and SurrealDB improved the infrastructure connecting agents to tools, data and memory. Marvell addressed the physical computing requirements behind longer and more demanding inference workloads. These announcements suggest that the industry is beginning to build the supporting layers agents need to move beyond isolated demonstrations.
Security and governance are developing alongside that infrastructure. The EU began enforcing important transparency requirements, while Obsidian, CrowdStrike, Airlock Digital and Alibaba Cloud concentrated on monitoring behavior, controlling permissions and protecting enterprise systems.
The question is no longer simply:
“Can an AI agent complete the task?”
Businesses must now ask:
“Who authorized the agent, what can it access, how much can it spend, which actions require approval, and how will every decision be audited?”
The organizations that answer those questions effectively will be better positioned to move agentic AI from experimentation into dependable, large-scale operations.