AI Agents News, October 2026: Data Agents, Model Costs, and Control Gates
A SaaS growth leader can now ask an agent why expansion slowed, but a plausible dashboard is useful only if it respects the team’s metric definitions and data permissions. September’s AI-agent releases made that question more practical and more urgent. ChatGPT Work introduced a Data agent for company data, Google released Gemini 3.8 Flash for autonomous agents, and ServiceNow documented AI Gateway v3.4 for governed MCP connections. This October 2026 edition covers developments published from September 1 through September 29. The useful decision is which workflow can be evaluated now, at what cost, and with whose authority.

Data agents make metric ownership visible
OpenAI’s September 10 Data agent announcement placed a question-to-dashboard workflow in ChatGPT Work. The agent can connect to approved sources including warehouses and databases, combine files and documents, and produce shareable analysis. Administrators can install the Data plugin, enable its data-source plugins, and manage access. That is a real change for a RevOps team that previously waited for a reporting queue to answer every follow-up question.
The bottleneck moves to definitions. If “active account,” “qualified pipeline,” or “renewal risk” means something different in the warehouse and the sales dashboard, a fluent analysis can accelerate a bad decision. OpenAI says its own data team created shared business definitions and access rules before broad internal use; its customer examples describe early use, not proof of accuracy in another tenant. Start with one question—say, why a named cohort’s expansion rate changed—and reconcile the agent’s numerator, denominator, filters, and source rows against the existing report before anyone changes a forecast or campaign.
Lower model costs widen the test set, not the permission set
Model availability changed at several distinct surfaces. On September 2, Google’s Gemini API release notes marked gemini-3.8-flash generally available for long-horizon software engineering, autonomous agents, and enterprise workflows. On September 3, OpenAI released GPT-6 Astra and reported that it reached the Critical cybersecurity capability threshold under OpenAI’s own framework. That claim and OpenAI’s internal safety findings warrant scrutiny; neither establishes how an agent will behave against a SaaS team’s live customer records.
The pricing shift arrived later. OpenAI’s September 22 GPT-6 Sol and Luna announcement listed API input/output prices per million tokens of $2/$10 for Sol and $0.10/$0.50 for Luna, down from the GPT-5.6 promotional prices it compared against. The models were available in the API and began rolling into ChatGPT Work and Codex, while OpenAI’s dated release notes distinguished those Work and Codex models from Chat. Lower list prices make repeated classification, research, and draft-review runs easier to budget, but total cost still includes tool calls, long context, retries, and human review.
Anthropic’s September 28 Claude Sonnet 5.5 release made a different economic claim: the input and output token prices stayed at $2 and $10 per million, while Anthropic said its model used fewer tokens and cost up to 30% less per task in its own tests. Sonnet 5.5 is available through Claude Platform and the named cloud providers, with cyber safeguards and fallbacks for higher-risk requests. A buyer should therefore compare the same completed task, effort setting, review time, and failure rate rather than treating a token price or vendor benchmark as a purchasing verdict.
Voice agents gained a production endpoint too. Google’s September 15 changelog marked Gemini 3.8 Live and Live Extended Thinking generally available through the Live API. For a support or onboarding team, this warrants a bounded call-flow test—latency, interruption handling, tool confirmation, and transcript review—before a voice agent touches billing or account state. General availability describes the API surface, not the quality of a company’s particular call flow.
Tool governance and migrations can stop an otherwise capable agent
The September 14 AI Gateway v3.4 article, updated September 28, gives a concrete follow-up to last month’s scheduled ServiceNow launch. It identifies the release as version AWH in AI Control Tower v3.4 and describes server approval, scoped connection credentials, tool scanning, per-server pause controls, and call telemetry. Its scope is MCP connections that actually pass through AI Gateway. It is ServiceNow’s product account, and its note says planned features can change; a customer still needs to check the installed version and test a denied tool call in its own tenant.
Google’s September 17 Antigravity Agent update shows another operating cost: a preview version replaced the May preview and changed local tool-call parameters and file-edit behavior. Remote sandbox users who only read output steps can change the agent identifier, according to Google; local-tool users or applications parsing function_call steps need a migration. The old preview is scheduled to shut down October 5. Freeze a representative tool trace, adapt the parser, and replay a failed edit before that date if this preview is in a customer-facing workflow.
The previous issue also flagged Microsoft’s September plans for Agentic Center of Enablement and enhanced admin controls. At this cutoff, a month-level schedule alone does not establish a completed rollout. Keep those items on the verification list until a dated release note and a tenant check show the feature, region, and administrator setting. ServiceNow’s release document does not prove Microsoft’s separate controls shipped.
September developments by decision surface
| Date | Confirmed change | Decision it changes |
|---|---|---|
| Sep. 2 | Gemini 3.8 Flash became GA in the Gemini API. | Add the endpoint to a fixed agent evaluation set; do not infer app-level availability. |
| Sep. 3 | GPT-6 Astra launched with OpenAI’s Critical cyber designation. | Test authorized tool use and monitoring before granting consequential actions. |
| Sep. 10 | ChatGPT Work introduced Data agent. | Reconcile one GTM metric and its permissions before scaling self-service analysis. |
| Sep. 14, updated Sep. 28 | ServiceNow described AI Gateway v3.4. | Verify the installed version, approval path, denied calls, and pause control. |
| Sep. 15 | Gemini 3.8 Live models became GA. | Pilot one voice flow against latency, interruption, and handoff criteria. |
| Sep. 17 | Antigravity Agent 09-2026 replaced the May preview. | Migrate local tool schemas before the stated October 5 shutdown. |
| Sep. 22 | GPT-6 Sol and Luna reached the API, Work, and Codex. | Reprice a complete task, including retries and review. |
| Sep. 28 | Claude Sonnet 5.5 became available. | Compare task cost and exception handling at a fixed quality bar. |
An October pilot should answer one business question and one authority question
Pick a workflow with a measurable outcome, such as explaining a drop in trial-to-paid conversion for one segment. Give the agent read access to the required sources and a frozen metric definition. Keep CRM writes, customer messages, and price changes behind separate human approval. Record the answer, cited records, elapsed time, total model and tool cost, and the analyst’s correction time. That makes a model comparison meaningful to a growth team rather than a contest of polished prose.
Then run the failure path. Remove permission to one source, change a tool response schema, and request an action outside the agent’s scope. The run should stop visibly, name the blocked action, and leave an audit trail that a real owner can review. ServiceNow’s gateway controls and Google’s preview migration make these tests concrete; neither removes the need to authorize the underlying data source and destination. Expand only when the business answer is reproducible and the denied action stays denied.
Frequently asked questions
Which September change should a RevOps team test first?
Start with the Data agent in ChatGPT Work if the team already has a governed warehouse and a recurring metric question. Ask for the source rows behind one dashboard change, compare the calculation with the owned report, and document which workspace users can see the result. A new model endpoint is a lower-priority test when the metric definition itself is unresolved.
How should a team compare lower-cost agent models?
Use the same task set and effort setting, then count accepted outputs, retries, tool calls, and reviewer minutes. OpenAI’s Sol and Luna price table shows lower API token prices; Anthropic’s Sonnet 5.5 post reports lower task cost at unchanged token rates. Neither figure predicts a team’s cost per approved business action without its own workload data.
Does an MCP gateway authorize every business action?
ServiceNow’s AI Gateway v3.4 description covers approved MCP servers and tools routed through that gateway. A customer must still verify source-system roles, destination permissions, and what happens when a token is revoked. For a CRM update, test the gateway denial and the CRM’s own permission denial separately.
What needs checking before an October agent rollout?
Check the installed product version, model surface, tool schema, and tenant permissions on the rollout date. Google’s Antigravity changelog schedules the old preview to shut down October 5 and specifies which integrations need migration; OpenAI’s Work release notes distinguish Work and Codex model availability from Chat. A September announcement is the start of a verification checklist, not proof that every workspace is configured the same way.