Agent Collaboration Weekly AI News
September 21 - September 29, 2026Weekly signal
This week (Sept 21–29, 2026) saw concrete product and operational signals that agent-to-agent collaboration is moving from research into platform reality—and that security and governance are now urgent operational workstreams. Key signals: vendor releases that enable delegation, sub-agents and hand-offs; cloud runtimes improving inter-agent scale and identity flows; open protocols for agent discovery and peer-to-peer calls; and a high‑confidence security test that reframes prompt injection as an infrastructure/privilege problem.
What changed
-
UiPath rolled out multiple agent collaboration features: Agents-in-Flow chaining and hand-offs, an “advanced agents” preview that delegates slices of work to sub-agents and keeps intermediate state in file workspaces, and an Autopilot Agent preview to scaffold and debug agents (public previews and GA notes dated Sept 22–25). These releases explicitly support building specialist agents and programmatic delegation inside orchestration flows.
-
Atlassian continued a progressive rollout of enterprise agent management in Jira/Rovo: a Jira Triage Agent, refreshed Agent sessions UI, guided install flows and the ability to group work items by agent—making it easier to assign, discover and track delegated work inside product workflows. (Rolling updates through Sept 21.)
-
AWS AgentCore / Bedrock AgentCore continues to expand operational features (interactive shells, a Consent Portal for identity consent, TypeScript framework support, and runtime/observability improvements in Sept release notes) that make multi-agent, multi-runtime deployments more robust and observable. These are platform-level enablers for agent collaboration at scale.
-
Security test: Unit 42’s controlled demonstration (reported Sept 21) showed an AgentCore harness configuration could be induced to execute a shell and read plaintext process memory (exposing credentials) when default tool boundaries were permissive. That finding shifts prompt-injection risk into runtime privilege and identity boundaries—making configuration, allowedTools, identity scoping and egress controls first-order security controls for collaborative agents.
-
Interop momentum continues: the Agent2Agent (A2A) pattern/spec and vendor docs (e.g., Microsoft Copilot Studio A2A docs) are now practical building blocks for cross-framework agent calls and discovery—explicitly designed to let agents publish capability cards, discover peers and delegate tasks across vendors.
What to do with it
- Inventory and remediate: list all production harnesses and agent sessions; remove shell/file tools unless required and restrict allowedTools. Prioritize AgentCore harnesses and any runtimes that accept external content.
- Add governance for delegation: require documented agent cards, owners, identity scopes and egress rules before enabling sub-agent delegation or A2A connectors. Test hand-off paths in staging.
- Use vendor tooling: trial UiPath’s Autopilot/advanced agents in a sandbox to validate delegation patterns and build evaluation suites; use Atlassian’s agent session views to measure agent workloads and routing.
- Treat interop as an integration test: exercise A2A connections in a controlled environment and include identity/consent flows (Consent Portal patterns) and telemetry assertions.
Stop reading agent demos. Give one a job you repeat every week.
Describe the work, test the first result, and keep the agent available without running your own server.
Plans start at $29/month. Cancel anytime.
Hosted agent
OpenClaw or Hermes