The Agent Stack mascot
The Agent Stack _
Daily B2B AI automation brief · Thursday, September 10, 2026 · Issue #90

Hey there 👋

I opened the security feed this morning expecting the usual sermon: lock down your agents, inventory your skills, keep a human on the button. Instead the story flipped on me. The defenders shipped agents that fight back on their own, the same week Google confirmed the attackers already have. The fight stopped being humans defending against a tool. It is agents against agents now, running at machine speed on both ends.

That is the through line today, and it is worth slowing down for, because the two halves landed within a day of each other and neither team asked the other’s permission.

Here is my bias, for what it’s worth. I want an agent reading my alerts at 3am, absolutely. What I am not ready to do is hand that same agent the authority to quarantine a production box with no human between the verdict and the action. The vendor selling exactly that shipped today. Read on and decide where your own line sits, because this is the week the industry stopped agreeing on where it goes.


The Big Thing

A top security vendor put agents in charge of containment, at machine speed

For most of this year the pitch on AI in the security operations center was assistance. An agent drafts the summary, a human clicks the button. Zscaler just moved the button.

The company launched Zscaler Agentic SOC on September 9, available globally the same day. It is built around four specialized agents that carry an alert from noise to resolution: one triages, one investigates root cause, one renders a verdict, and one contains the threat. Underneath, Zscaler wired frontier models from Anthropic and OpenAI to its own zero-trust telemetry and a global network of decoys, the argument being that a model reasons better when it can see every connection crossing the wire and has bait laid out to catch what it misses.

The detail that should stop a builder is the handoff between those four agents. The pipeline runs triage to investigation to verdict to containment, and Zscaler foregrounds automated containment at machine speed, not an approval queue in front of each step. Machine speed is the whole point: a human sign-off at every stage is the thing that makes a SOC slow. Read the pitch and the per-step human gate is not the part being sold. So, by design, the agents move on their own.

Hold that against the rest of the quarter. AIR wanted to firewall what enters an agent’s context. CrowdStrike put a block at the endpoint with a human naming the allow-list. Tenable built a review a person signs off on. Every one of those shipped a checkpoint. Zscaler made machine-speed containment the headline, not the checkpoint. That is not a small disagreement about a UI. It is two different bets on whether a defender can afford to keep a human in the loop when the attacker no longer does.

Ship it? Watch, then pilot narrow. If you run a SOC, this is worth a real look, because the alert fatigue it targets is genuine and the telemetry-plus-decoy foundation is more than a wrapper. But point it first at high-signal feeds you understand, identity events, VPN, remote-management sessions, and run it in observe-only or human-confirms-containment mode until you have watched its verdicts for a few weeks. Nobody should let an agent quarantine production on day one on a vendor’s say-so. The capability is real; the trust is earned per environment, not shipped in the box.

Sources: GlobeNewswire for Zscaler’s release; Help Net Security and SecurityBrief on the four-agent design and the Anthropic and OpenAI model integration.


Tour de Headlines

🛰️ Google says the attackers already went agentic. Google Cloud’s Threat Intelligence Group published a tracker this week showing adversaries moving off single-prompt tricks and onto automated agentic chains that plan, execute, and iterate without a human driving each step. The effect is a shorter fuse: an attack that used to need an operator at the keyboard for every pivot can now run reconnaissance, move laterally, and pull data on its own, which compresses the window a defender has to notice. This is the mirror image of today’s lead, and the timing is the story: offense and defense both crossed into autonomy the same week. The practical move is to stop watching for single bad events and start watching sequences, the order of API calls, the pattern of file access, the rate at which something retries itself, and to run a tabletop that assumes an attacker can finish a full agentic pipeline inside one business day rather than one quarter.

💳 Visa plants a flag on the payment rail before agents start spending. Visa published a Trust Index for agentic commerce, and the numbers describe a gap it plans to fill. About 72% of US consumers have already used an AI assistant, but only 23% trust AI to handle the payment itself, while 61% say they would trust Visa to handle an agent-initiated transaction. Those are Visa’s own survey figures, so grade them as a vendor’s, but the strategy behind them is clear enough: hundreds of secure agent-initiated transactions are already done, Visa expects millions by the holiday season, and it is standing up an Agentic Ready program to be the layer that says which agent is allowed to move money. For anyone building agent-driven checkout, the design lesson lands now: put explicit user consent and a per-agent identity token in front of any purchase, and ask your payments partner what transaction-level agent verification and rollback look like before a bot spends on a customer’s behalf.

🤝 Accenture and Google will put 1,000 engineers on client floors to install the agents. The two formed the Accenture Gemini Enterprise Business Group on September 8, with a plan for a 1,000-person forward-deployed-engineer workforce, pulling from Accenture’s roughly 50,000 Google Cloud-certified staff, to build bespoke Gemini agent applications on-site for large customers. TechCrunch read it as Google racing to catch up in the deployment wars, and that framing is useful. This is how agents really reach production inside a big enterprise, a partner team embedded in the building rather than a self-serve signup. If you sell anything agent-adjacent, your buyer now sits at the end of a partner procurement path, which means your integration story has to show how you slot into a partner-deployed Gemini stack. Running well on your own is no longer the whole pitch.


Sponsor

Your team’s calls are full of signal you never grade.

RapportScore reads your recorded calls and measures how your people communicate, then coaches them on it. Real measurement, not vibes.

See your team’s score →

Tool of the Day

🛠️ MagiCrew

A self-hostable agent workforce with the approvals built in.

If today’s theme is who gets to authorize an agent, here is the version you can run yourself. MagiCrew launched on Product Hunt on September 3, sitting on top of an open-source codebase called Magic that has collected around 5,000 GitHub stars. It is an all-in-one: a generalist agent, a workflow engine, a team messenger, and a collaborative office suite in one package, pitched at giving every employee a dedicated agent worker for research, competitive analysis, reports, and slide decks instead of one shared chatbot everyone talks past.

What it is for: standing up a team’s agent workforce on infrastructure you control, with multi-agent roles, approval steps, and an audit trail treated as first-class rather than bolted on, so you get the governed-workflow shape without shipping your documents to someone else’s SaaS. Two honest limits before you commit. The license is the Magic Open Source License, based on Apache 2.0 but with added restrictions, so read the terms before you build a product on it. And self-hosting a bundle that includes a messenger and an office suite is real operational weight, not a Friday-afternoon deploy. Worth a serious look if governance and data residency are why you have been holding off on an agent platform.

See the repo →


Worth a Click

  • Zscaler’s own Agentic SOC release. Read the four-agent design, the decoy mesh, and the containment-without-a-gate claim in the vendor’s words, then decide where your line is. globenewswire.com
  • Visa’s full Trust Index for agentic commerce. The consumer-trust numbers behind the payment-rail land grab, straight from the source. investor.visa.com
  • TechCrunch on the Accenture and Google deal. A useful read on the deployment-war framing if you sell into enterprises that buy through partners. techcrunch.com

Line the week up and it tells on itself. Zscaler put autonomous agents on defense the same week Google’s own threat team confirmed the attackers already run agentic chains, so both sides of the fight are now moving faster than a person can click. And the thing everyone is truly fighting over kept sliding outward, from the model, to the context and the endpoint we covered last week, and now to the SOC that runs on agents, the payment rail that authorizes them, and the consulting bench that installs them. The base model is the boring part of the stack. The money is in the layers wrapped around it, and this week three more got claimed.

See you tomorrow.
— Ron