AI Agent Digest: Week 29, 2026 - Gemini 3.5 Pro Ships With 2M Context, MiniMax Raises $2B, and an Agent Framework Lands on CISA's Exploited List
Week 29 was the week the plumbing got serious. A flagship model shipped after being torn down and rebuilt, the dominant agent protocol locked its enterprise auth story, and an agent framework became the first of its kind to land on a government exploited-vulnerabilities list. Money moved too, in nine and ten-figure amounts. Here are the eight stories that mattered, and what we actually make of them.
1. Gemini 3.5 Pro ships with a 2-million-token context window
Google released Gemini 3.5 Pro on July 17, its most capable model yet, carrying a 2-million-token context window, a Deep Think reasoning mode on the $250-per-month Ultra tier, and big gains on long-horizon coding and tool use. What's notable is the backstory: Google reportedly scrapped the original base model after engineers found structural failures in recursive tool-calling and SVG generation, then rebuilt it. (TechTimes)
Hot take: A 2-million-token context window is a bigger desk, not a better memory. You can pile more paper on it, but the model still forgets everything the moment the session ends. The teams winning with agents aren't the ones stuffing more into the prompt, they're the ones with persistent memory that survives across sessions. Context length is a spec. Memory is an architecture.
2. MiniMax raises $2 billion
MiniMax closed a $2 billion round, roughly half from newly issued shares and the rest through convertible bonds. It's one of the largest single raises in the agent-adjacent space this year. (Crunchbase News)
Hot take: The capital is not chasing chatbots anymore, it's chasing whoever can turn models into workers that finish tasks. Two billion dollars buys a lot of runway, but it also sets a valuation that only autonomous, revenue-generating agents can justify. The pressure to ship real capability, not demos, just went up for everyone.
3. OpenAI's ChatGPT Work turns the assistant into an operator
OpenAI shipped ChatGPT Work, an agentic mode built on GPT-5.6 that autonomously executes multi-step tasks across a user's connected apps, files, and recurring workflows. This is the assistant crossing from answering to doing. (Gravity funding tracker)
Hot take: This is the most important product shift of the week, and it validates the entire category. When the biggest lab in the world reframes its consumer product as an agent that acts across your apps, the "is this real" debate is over. The next question is the uncomfortable one: do you want that agent living inside a platform you rent, or working as an employee you actually control?
4. The Model Context Protocol locks down enterprise auth
Anthropic's MCP, now sitting at tens of millions of downloads and backed by OpenAI, Google, and Microsoft, rolled out Enterprise-Managed Authorization. Admins can provision MCP connectors for a whole organization through their identity provider, starting with Okta, with users getting access on first login. Asana, Atlassian, Canva, Figma, Linear, and Supabase support it at launch, Slack soon, and the final MCP spec ships July 28. (Anthropic release notes)
Hot take: This is the least flashy story here and possibly the most consequential. Agents were stuck in pilots partly because nobody could answer "how does IT govern what these things can touch." Enterprise-managed auth is that answer. Boring infrastructure like this is exactly what turns an experiment into a deployment.
5. An AI agent framework lands on CISA's exploited list
CISA added Langflow (CVE-2026-55255) to its Known Exploited Vulnerabilities catalog, the first AI agent platform ever to make the list. The flaw lets authenticated users invoke other users' flows, and attackers are already using it to steal AI and cloud credentials. (aiagentstore)
Hot take: This was inevitable, and it won't be the last. The moment agents hold credentials and call tools on your behalf, they become the highest-value target in your stack. The lesson is not "agents are dangerous," it's "an agent with broad standing permissions is a breach waiting to happen." Scope every agent tightly, host it where you can see it, and treat its access like a privileged account, because it is one.
6. PwC and OpenAI package agentic customer service
PwC US launched agentic contact and service solutions built with OpenAI, and stood up a dedicated Center of Excellence to help enterprises redesign customer engagement around agents. (Agile Brand Guide)
Hot take: When the consultancies start packaging and selling agentic transformation, adoption stops being a technology decision and becomes a boardroom line item. That's good for the category and a warning for buyers: a six-figure consulting engagement is not the only path to an agent that answers your support queue. Smaller teams can stand one up themselves in an afternoon.
7. Qualcomm eyes Tenstorrent in an $8 to $10 billion deal
Qualcomm is in early talks to acquire AI-chip designer Tenstorrent for somewhere between eight and ten billion dollars. (Gravity funding tracker)
Hot take: The agent boom is now bending the silicon market. Running autonomous agents around the clock is a very different compute profile from occasional chatbot queries, and the hardware players know it. Consolidation at the chip layer is a bet that agents, not humans typing prompts, will be the dominant workload of the next decade.
8. Apple sues OpenAI over trade secrets
Apple filed suit against OpenAI and former Apple employees, alleging theft of hardware trade secrets tied to OpenAI's acquisition of io Products. (Gravity funding tracker)
Hot take: The talent-and-secrets wars are heating up because everyone now believes the same thing: the winner of the agent era captures an enormous market, and the margin between first and second place is people. Expect more lawsuits, more poaching, and more nine-figure retention packages. The gold rush has reached the litigation phase.
What we're watching next week
The final MCP specification lands July 28, and it will set the ground rules for how agents connect to tools across the whole industry. We're also watching whether Gemini 3.5 Pro's rebuilt tool-calling actually holds up under real agentic workloads, since that was the exact thing Google scrapped the first model over. And with MiniMax freshly capitalized, keep an eye on where that $2 billion points first.
Bottom line
This was an infrastructure week, not a hype week. Models got rebuilt instead of just rebranded, protocols grew up enough for IT to govern them, and the security bill for careless agent permissions came due in public. The through-line is that agents are moving from "can they work" to "can we run them safely and remember what they did." Context windows and funding rounds make headlines, but memory, governance, and scoped permissions are what actually ship agents into production.
That's the whole idea behind Geta.Team. An AI employee with persistent memory that survives every session, scoped permissions you control, and the ability to actually do the work, not just talk about it. Want to test the most advanced AI employees? Try it here: https://Geta.Team