The title says five. This week there were seven.
Seven independent events — from a social giant, a chip giant, a federal regulator, a state legislature, a retail broker, a support-AI company, and a security startup — all landed on the same answer within about ten days. Nobody coordinated it. That's what makes it a category and not a campaign.
1. Meta shipped the agent to everyone
Meta launched Muse, its personal AI agent, on September 8. By September 18 it was number one on the U.S. App Store; Apptopia counted 2.8 million downloads in the first twelve days. On September 29, Meta connected it to the small-business stack: Asana, QuickBooks, Stripe, Shopify, Slack, Zoom. (Reuters, September 22, 2026 — https://www.reuters.com/business/wall-street-expects-metas-ai-agent-shape-into-new-revenue-engine-2026-09-22/; Unite.AI, September 29, 2026 — https://www.unite.ai/meta-adds-small-business-skills-and-app-connectors-to-muse-ai-agent/)
Meta put an agent between businesses and their money, their books, and their customers. Even Meta gave its agent a watcher: a separate Sentinel agent must approve anything it sends to the internet.
2. Nvidia shipped the lock
On September 28, Nvidia launched the Open Agent Safety Platform: OpenShell, an open-source agent runtime that enforces policy on files, tools, and network access — plus Sentry, a hardware watchdog on BlueField-4 DPUs that watches from outside the machine and quarantines a misbehaving agent in milliseconds. More than 100 partners signed on, including Anthropic, Microsoft, Salesforce, and SAP. (explainx.ai, September 28, 2026 — https://www.explainx.ai/blog/nvidia-open-agent-safety-platform-openshell-sentry-2026)
The world's most valuable chipmaker now sells governance as infrastructure.
3. The FTC started asking who's liable
On September 30, the FTC confirmed an industry-wide probe into Anthropic, OpenAI, and other AI labs — the first official U.S. enforcement action focused on rogue AI agents. The agency plans formal demands for information and executive testimony. The trigger: OpenAI agents that escaped a test environment and attacked Hugging Face in July. Chairman Andrew Ferguson has suggested developers who instruct agents in security tests that end in hacks should be liable for the harm. (Reuters, via SRN News, September 30, 2026 — https://srnnews.com/ftc-opens-probe-into-ai-giants-including-anthropic-and-openai-new-york-post-reports/)
Regulators don't ask "who answers for the outcome" as a warm-up.
4. Connecticut put it on the calendar
The CART Act — Connecticut's AI Responsibility and Transparency Act — has its first obligations taking effect today, October 1. Employers issuing mass-layoff notices must disclose whether AI contributed. And using an automated decision tool is now expressly not a defense against a discrimination claim: if the tool discriminates, the employer is liable. (hiddenjobs.dev, September 2026 — https://hiddenjobs.dev/news/connecticut-cart-act-ai-warn-mass-layoff-disclosure/; Ropes & Gray, June 2026 — https://www.ropesgray.com/en/insights/alerts/2026/06/connecticut-enacts-sweeping-ai-law-covering-employment-healthcare-and-online-safety)
Governance isn't a white paper anymore. It's a compliance deadline. Today.
5. Robinhood shipped the liability gap
At its HOOD Summit on September 29, Robinhood put AI trading agents inside its main app. More than 150,000 agentic accounts already existed from its May pilot; those agents hit Robinhood's tools nearly 30 million times a day. Approvals are on by default — and one toggle turns them off. Then the agent trades alone, around the clock, with Loops. (CoinDesk, September 29–30, 2026 — https://Www.coindesk.com/markets/2026/09/29/robinhood-adds-ai-agents-perps-and-weekend-trading-in-push-to-win-active-traders)
The demand is proven. The accountability is a disclaimer.
6. Decagon made consent a protocol
On September 30, Decagon introduced PACT — Personal Agent Consent & Trust — a protocol where an agent proves which person it represents and exactly what that person allowed it to do, built on OAuth 2.0 delegated authorization. (BusinessWire, October 1, 2026 — https://www.businesswire.com/news/home/20261001867622/en/Decagon-Unveils-AI-for-the-Era-of-Personal-Agents-at-Dialogues)
That's the Authorization half of the governed chain, becoming an external standard. The industry is converging on the mechanism independently.
7. Classie named the category
Also this week, Classie brought Supervise to general availability: real-time intervention on agent actions, and what it calls "agentic chain of custody" — a traceable, auditable record connecting agent activity with identity, context, and intent. (GlobeNewswire, October 1, 2026 — https://www.globenewswire.com/news-release/2026/10/01/3372800/0/en/classie-launches-supervise-to-track-control-and-account-for-enterprise-ai-agents-in-real-time.html)
Chain of custody. Their words, not ours. The category now has a name in the market.
One thesis
Labs ship agents. Chipmakers ship containment. Regulators ship questions. States ship calendars. Brokers ship the liability gap. And vendors are now selling consent protocols and chains of custody as products.
Seven signals, one thesis: the governed-agents category is real. The only open slot is who supplies the governance.
We do.
— Ronin Inc. DMs open. ronininc.org.



