On 24 September Dataiku announced Agent Management (opens in a new tab), a product whose whole job is counting AI agents. For UK AI agent governance, that's the most useful signal of the week. According to AI Agent Store's weekly log of agent launches (opens in a new tab), Agent Management lists agents across platforms, tracks business KPIs next to technical performance and ranks each agent by risk. Dataiku says general availability is planned for October (as of September 2026).
In the same week Microsoft rebuilt Copilot around long-running agents, and Alibaba says it cut its voice API prices by up to 95%. This month Google also added a new managed-agent configuration to the Gemini API. Agents are running for longer and costing less. The ability to see where they all are hasn't kept up.
My view: the register is the real story. The voice price cut will get more attention, and it matters less than it looks.
- Term: AI agent register
- Definition: An AI agent register is an organisation's inventory of every AI agent it runs, recording what each agent can access, which model it runs on, who owns it and what risk tier it sits in.
What is AI agent governance, and why did it become a product this week?
AI agent governance means knowing which agents an organisation runs, what they can touch and how risky each one is. It got a standalone product this week when Dataiku announced a tool that does only that job, while Microsoft this week, and Google earlier in the month, were making agents that run longer and do more without supervision.
The timing makes sense. According to The Neuron's round-up of 25 September, Microsoft has rebuilt Copilot around long-running agents. Google's own managed agents update (opens in a new tab) adds a preview harness, antigravity-preview-09-2026, running on Gemini 3.8 Flash, together with new Files and Credentials APIs (Google, as of September 2026).
The Credentials API is the part a security lead will notice. Google says it stores the secrets and injects them at request time, so the agent never reads the token itself, but it can still use that token to reach third-party services. That makes the agent an identity inside the organisation, and one that can act unsupervised with access to systems.
- Term: Long-running agent
- Definition: A long-running agent is an AI system that carries on working through a multi-step task for hours or days, calling tools and systems, without a person approving each step.
| Date | Company | What launched | Governance angle |
|---|---|---|---|
| 24 Sept | Dataiku | Agent Management: cross-platform inventory, KPI tracking, risk ranking | The register itself; GA planned for October |
| 24 Sept | Strada | Browser automation that records and replays workflows in carrier portals and legacy systems | Full run-time logging for audit |
| 24 Sept | Ando | Team messaging app with agents as full members of conversations, launched with $20m of funding | Agents get inbox access |
| September | antigravity-preview-09-2026 managed agents on Gemini 3.8 Flash, plus Files and Credentials APIs | Agents use stored credentials | |
| 25 Sept | Microsoft | Copilot rebuilt around Autopilot, a long-running agent with its own identity | Longer unsupervised runs |
Why an agent register comes before the next agent
Nobody can risk-tier something they haven't counted. This week's launches show why the counting is getting harder. Strada's agents now go into web portals and legacy systems with no engineering needed, and Ando puts agents directly into team conversations. Both make agents easier to deploy, and both let a business unit set one up without the IT function ever seeing it.
I would put the register ahead of any new agent procurement for a UK organisation answering to a board or an audit committee. In my view the first question any risk framework asks is what the organisation has, and an agent register is how you answer it.
Strada is the exception worth noting. It ships full run-time logging with its record-and-replay agents. A log doesn't replace a register, but it's the raw material an auditor would ask for.
The catch with buying governance from a platform vendor
There's a tension here that I can't resolve. Dataiku is itself a platform for building AI, and the claim that Agent Management covers agents on other platforms is Dataiku's own. I could find no independent test of it, and it isn't generally available yet. The register that makes agent sprawl visible is being sold by one of the companies whose platform adds to that sprawl.
That doesn't make the product a bad idea. It does mean that a register kept inside one vendor's tool records what that vendor can see. A spreadsheet the risk team owns is less elegant, but no supplier's integration list decides what goes in it.
How much cheaper did voice AI get this week?
Alibaba's Qwen team released a new voice stack, Qwen-Audio 3.1, and in the same announcement cut prices on its voice APIs by up to 95%. The Decoder reported it on 23 September (opens in a new tab), and AI Weekly's daily edition for 25 September (opens in a new tab) picked it up.
"Up to 95%" is a ceiling, and it belongs to one product. According to The Decoder's breakdown of Alibaba's announcement, speech recognition fell by up to 95%, the Realtime voice API by roughly 85% and text-to-speech by about 70%. A contact centre that mostly generates speech is looking at the smallest of the three cuts. Comparing any of them with a UK team's current per-minute cost still needs Alibaba's own price list, not the headline.
I think the price cut matters less for UK contact centres than the headline suggests. I doubt per-minute cost was the main thing holding voice AI back. The harder question is where call audio goes. Under UK GDPR, sending personal data to a provider outside the UK is a restricted transfer and needs a lawful transfer mechanism. That is a job for the data protection officer, and a lower price doesn't make it go away.
OpenAI's voice changes, reported by 9To5Mac on 23 September, matter more for what UK teams can do with voice day to day. ChatGPT Voice now takes plugins for email, calendar and Slack, users can choose which model sits behind it, and voice now works inside ChatGPT Work on web and mobile.
That links back to the register. A voice assistant that can read a calendar and post to Slack is an agent with credentials, just like Google's managed agents. If an organisation's register counts only the agents its engineers built, it will miss the ones staff switched on by speaking to them.
Does the Anthropic Pentagon ruling matter to UK buyers?
Yes, but not in the way the headline suggests. On 25 September the US Court of Appeals for the DC Circuit upheld the Pentagon's designation of Anthropic as a supply chain risk (opens in a new tab), in a 2-1 ruling on the merits. It doesn't touch UK law, but it shows that a model supplier's standing can change for reasons that have nothing to do with how well the model performs.
The court's reasoning makes that point for me. Anthropic had refused to relax contract terms barring Claude's use for lethal autonomous warfare and domestic surveillance. Writing for the majority, Judge Gregory Katsas found the Department had "ample support" for treating Claude's continued use in its systems as a national-security risk, noting that those restrictions had stopped Claude doing tasks government users asked for. Judge Karen Henderson dissented, arguing the department had in effect given Anthropic an ultimatum: relax its restrictions or be blacklisted. The courts don't agree with each other either. According to an Anthropic spokesperson, District Judge Rita Lin in California ruled a similar decision unlawful, and Anthropic says it is considering further review.
For UK defence suppliers with US contracts, and for public bodies building on Claude, the lesson is about exposure, not about quality. Earlier I argued that an agent register should record which model each agent runs on. This ruling is the practical reason. When a supplier's status changes overnight, the organisations that can answer "which of our agents run on this model?" in an hour are the ones that kept the list.
It also complicates the neat story from the first section. The risk that rules out a model can be political as well as technical, and no inventory tool assigns a risk tier for that. A person has to add it.
What else happened in AI policy this week?
On 23 September Senator Bernie Sanders and Representative Greg Casar introduced the Ban Artificial Superintelligence Act. According to Sanders' own press release (opens in a new tab), the bill would permanently ban the development of artificial superintelligence, pause advanced AI development until federal safety rules exist and create a new federal agency to oversee it. The release says companies that break it would face the "corporate death penalty" and individuals up to 20 years in prison.
I'd bet against it passing. For UK readers it's a marker of how far the US debate has spread, not a rule anyone will have to follow. The same goes for reports that Donald Trump and Xi Jinping put AI safety and competition on the table (The Neuron, 25 September 2026). No outcome that UK organisations would need to act on has been reported.
AI agent governance in UK organisations: where it stands
As of September 2026, the tools for building agents are ahead of the tools for keeping track of them. Dataiku's dedicated inventory product has been announced but is not yet generally available. None of the launches covered here came from a UK regulator, so for now the governance tooling British organisations end up working with is being shaped by software vendors' product decisions.
- Term: Risk tiering
- Definition: Risk tiering is sorting AI systems into levels by the harm they could cause, so that the riskiest ones get the closest oversight.
The cheapest agent to run this week wasn't Alibaba's. It was whichever agent a team switched on and nobody recorded, because nothing will ever make its cost show up.