Agent infrastructure: plugins, channels, sandboxes, memory & runtime security
OpenAI introduces Agent Plugins open standard for bundling skills and MCP servers; steering committee includes Amazon, Microsoft, Vercel. OpenAI publishes an open standard to package agent skills and connect to MCP servers with an industry steering committee; this sets a common extension model for agent capabilities and governance. This shapes how you design interoperable skills and orchestration layers — Principle 09 and Principle 10 in motion.
Channels SDK — Bring Any Agent to Any Channel (Slack, Microsoft Teams). CopilotKit’s SDK embeds agent UIs into Slack and Teams, exposing tools and human-approval gates as first-class components. If you’re shipping agents to customers, this removes integration friction and formalizes human-in-the-loop gates — Principle 06, Principle 09, Principle 15.
Cloudflare launches Kitesurf, a cloud-hosted browser for AI agents (beta). Kitesurf runs agents inside Workers-based sandboxes and provides a browser runtime tuned for agent workflows. That gives you a deployable containment layer and low-friction runtime for serverless agents — useful for Tech Island and sandboxing strategy (Principle 07).
Menlo Security targets real-time AI agent security with MARS platform. MARS monitors agent activity at runtime and enforces policies to block prompt injection and unsafe actions. Runtime policy enforcement like this belongs in your control plane and incident posture — tie it to the Law and the Immune System (Principles 10 and 14).
Tencent’s Team Memory shares AI agent memory across a team — with no governance yet for when it’s wrong. Tencent exposes shared, structured memory so agents on a team share context, but the piece flags missing governance for incorrect memories. Shared context accelerates coordinated outcomes but forces you to design memory validation, access controls, and correction workflows — Principle 06 and Principle 09.