Independent reporting on the agent economy
AgentNews.com
An eCorp Venture
AgentNews

Agent News Today — September 22, 2026

Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day and more — today's agent signal.

The AI agent economy is moving at breakneck speed, with major players racing to deploy and refine their technologies. Meta's Muse, for instance, has been making waves with its impressive capabilities, but its rapid advancement has also introduced new risks, as evidenced by a serious 0-day vulnerability that's raised concerns about the safety and security of these powerful tools. Meanwhile, Muse's momentum has allowed it to outpace ChatGPT's early mobile launch, highlighting the intense competition in this space.

As AI agents become increasingly pervasive and autonomous, regulators are starting to take a closer look at accountability and liability. The US Treasury chief's recent statement that AI bosses, not their bots, will be held responsible for criminal acts is a case in point. This shift towards greater accountability is likely to have significant implications for the development and deployment of AI agents. In related news, tech giants like Meta and Amazon are working to integrate AI agents into their ecosystems, with Amazon blocking Meta's AI agent from accessing its platform and AWS launching an open-source agent harness designed to be more efficient than its rivals.

Today's signal: • Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day (arstechnica.com) • Meta’s Muse is outpacing ChatGPT’s early mobile launch (techcrunch.com) • Treasury chief says AI bosses, not their bots, will carry the can for criminal acts (theregister.com) • Meta’s AI agent has been blocked from using Amazon.com (techcrunch.com) • AWS bolts together open source agent harness, says it sips fewer tokens than rivals (theregister.com) • It’s a long story: from .web to .epic – DNW Podcast #604 (domainnamewire.com)

Read the full story →

From the Network

All network stories →

Protocols & Infrastructure

The stack underneath
Standards

The naming problem is harder than the signing problem

Cryptographic proof that a request came from a given key is largely solved. Agreeing on what to call the thing holding the key — and who gets to issue that name — is where the competing proposals actually diverge.

Analysis · 6 min read
Discovery

What a machine-readable agent card should actually contain

A stable identity document, declared capabilities with methods and prices, and working interfaces. The third is where most implementations quietly fail — and where crawlers notice first.

Explainer · 4 min read
Infrastructure

Why exact-match domains are re-pricing

When software rather than people does the finding, a name that literally describes a capability stops being a branding preference and starts being an addressing decision. The scarce names were all registered decades ago.

Market · 5 min read

Machine Commerce

How agents pay each other
Payments

Per-request settlement arrives before per-seat pricing dies

Metered, per-call payment between software is now technically routine. The commercial models built on top of it are not — and pricing an agent's work remains mostly guesswork.

Analysis · 5 min read
Accountability

Know-your-agent is becoming know-your-operator

Several proposals have quietly converged on the same conclusion: you cannot hold software accountable, so the useful question is which legal person stands behind it — and how a stranger verifies that cold.

Policy · 6 min read
Security

The access-control gap nobody budgeted for

Surveys of organisations deploying agents keep finding the same pattern: incidents are already happening, and the controls assumed to be in place mostly aren't.

Security · 4 min read
Explainer

The agent stack, in plain language

Most coverage of the agent economy collapses several distinct layers into one word. They fail differently, they're standardising at different speeds, and confusing them is why so much of the commentary contradicts itself.

The short version: transport is close to settled, identity is contested, and the asset layer — the actual entities doing work at real addresses — is the thinnest part of the stack.

  • NamingWhat the agent is called, and who issues that name. Multiple competing schemes; no winner.
  • Identity & accountabilityProving the agent is what it claims, and which legal person answers for it. Most contested layer.
  • AttestationThird parties vouching for facts about the operator — jurisdiction, registration, licences. Barely started.
  • Transport & capabilityHow agents actually call each other and describe what they can do. Closest to settled.
  • PaymentPer-request machine settlement. Working now, ahead of the identity layer above it.
  • The asset layerThe entities themselves — real addresses, running services, declared capabilities. Thinnest part of the stack.

The agent economy, once a week, without the hype.

What actually shipped, which standards moved, and what it means if you're building or investing. No breathless launch coverage.

One email a week. Unsubscribe any time. We don't share your address.

AgentNews is one of 439 agent-native entities operated by eCorp.

The same network this desk reports on, we also build. If you hold premium agent domains, invest in infrastructure, or want to ship an agent onto an established name rather than a subdomain, that conversation happens at AgentInvestments.com.

Investors & builders →