KDCube

Always-On Agents Move to the Runtime: DevDay Eve, AgentCore Shells, MCP Identity

OpenAI is teasing "o," a consumer-facing always-on agent ahead of its Sept 29 DevDay, while Amazon Bedrock AgentCore added persistent WebSocket shells and OpenAI-compatible gateways to its harness. Meanwhile MCP's agent-identity work stays half-finished and Archipelo's Salmon EVI pitches cryptographic proof of what age...

Highlights

  • On the eve of OpenAI DevDay (Sept 29, San Francisco), OpenAI is teasing "o," a consumer-facing always-on agent meant to run recurring research, monitoring, and comms outside a chat session — with hints it gets its own email identity. Tasks, permissions, scheduling, and memory are still unconfirmed. (TestingCatalog)
  • Amazon Bedrock AgentCore's harness added persistent interactive shells over WebSocket — up to 10 shells per session, reconnect-and-replay of 256KB of buffered output — plus custom OpenAI-compatible endpoints and lifecycle hooks. (AWS)
  • MCP's agent-identity workstream is "one spec shipped, three still open": the Aug 22 roadmap names DPoP, Workload Identity Federation, ID-JAG, and token exchange, but only the human-auth piece has landed. (DEV)
  • Archipelo shipped Salmon EVI, billed as the first cryptographic protocol to capture AI-agent execution as verifiable events — a governance layer aimed at runtime trust and audit. (AI Agents Directory)

Key Signals

  1. OpenAI teases an always-on "o" agent 72 hours before DevDay — Sept 26, DevDay Sept 29

    References to "o" as a display name and "-o" email suffix surfaced in ChatGPT configs, and it flashed briefly on the Pro upgrade page. If it ships, it pushes consumer agents from turn-by-turn chat toward unsupervised, long-running work — raising the same permission-and-budget questions operators already face with agent fleets. (TestingCatalog)

  2. AgentCore turns the runtime into an operable surface — September 2026 release notes

    Interactive WebSocket shells that persist env, working directory, and processes across inputs — plus apiBase routing to self-hosted/regional OpenAI-compatible gateways — make AgentCore behave less like a black box and more like a debuggable, governable execution environment. (AWS)

  3. Agent identity is still the unfinished half of MCP — Roadmap Aug 22; spec 2026-07-28

    The current spec went stateless (no Mcp-Session-Id, each request self-describing) and deprecated Dynamic Client Registration in favor of Client ID Metadata Documents, but the pieces that authenticate the agent rather than the human remain in draft. (DEV)

Why It Matters / What To Watch

  1. The control layer is shifting from policy docs to cryptographic proof and scoped identity.

    • Watch whether Salmon EVI–style verifiable execution gets adopted alongside the runtime governance products from last week — proof-of-what-ran is the missing complement to inventory and contracts. (AI Agents Directory)
    • Track MCP's DPoP/WIF/ID-JAG progress before wiring unattended agents into enterprise auth; today only the human-employee grant is standardized. (DEV)
  2. Runtimes are competing on operability, not just orchestration.

    • If you run agents on AgentCore, the new shells and lifecycle hooks change how you debug and gate long jobs — evaluate before your next fleet rollout. (AWS)
    • LangGraph's CLI 0.4.32 (Sept 23) leaned into self-hosted deploys with custom image URIs and security patches (AnyIO, httpx, httpcore) — a reminder that "stateful, long-running workflow" tooling is hardening its deploy path, not just its graph API. (LangChain)

Quick Links