1.11 Everything is called an agent

Book 2 · The Delegation ContractChapter 1 · section 11 of 14

Everybody is calling everything an agent right now: an editor window, a persistent runtime, a single function-call step, a model with a system prompt and a terminal. Agency genuinely matters, and the word, used this way, has stopped carrying any information at all.

The clearest illustration is Cursor, because it has traveled the full distance. Cursor began in 2023 as an AI-assisted code editor — a VS Code fork with a chat window — and it still sells that editor. But as of this writing it is also a platform whose agents run in cloud-hosted sandboxes, work on their own schedules, produce merge-ready pull requests, and are reachable not only from the IDE but from a web interface, a command-line client, a phone and tablet app, Slack, Microsoft Teams, an SDK in TypeScript and Python, and scheduled automations — with specialized agent products for code review, security review, and pull-request approval layered on top.42 One customer, the e-commerce company Faire, reported running more than two thousand automated agent runs a week. The agent is no longer a feature inside the editor; the editor is one client of many for a fleet of agents that live in the cloud.

A personal note from the author. I was one of Cursor’s heaviest users in its first year, heavy enough that the company sent me a promotional gift: a USB Tab key — a single-key keyboard that plugged into my laptop and did nothing but press Tab. It was a joke about how all of us used the product, and it was a good one. When Cursor arrived, the revolutionary feature was autocomplete: you hit Tab and it finished the line you were typing, because it predicted the code you were about to write. In the first year, that was the whole usage pattern — support for writing code, line by line, with the tool reading along. Today Cursor is an agent platform — cloud agents, background runs, merge-ready pull requests — and the usage pattern has inverted: where the product once finished the code I was writing, I now spend my time verifying the code it wrote. Plenty of developers say the same thing, some proudly: they no longer write code at all. A single Tab key would be a strange gift from Cursor today, because there is no key for “do the whole task.” That is how fast the category moved — an AI-first editor in 2023, background agents in 2025, a cloud-agent platform in 2026 — and in my own use the shift from autocomplete to agents felt like about a year, which is the cleanest illustration of why the word “agent” now covers so much ground: the products themselves changed jobs underneath the name.43

For the record, Cursor has reached almost the same endpoint as its competitors. The toolsets are converging: every serious vendor now sells an editor-borne agent, a cloud agent, a background run, and a review path, and the differences that remain are pricing, polish, and model access rather than shape. And shortly before this edition went to press, that last difference turned into open competitive pressure: after SpaceX acquired Cursor’s parent company, Anysphere, OpenAI announced on August 28, 2026 that it intends to wind down model access for Cursor, with a proposed shutoff date of November 12, 2026. OpenAI said it could no longer trust the acquiring company to honor its terms; Cursor — which had noted during the acquisition coverage that OpenAI models carry only about five percent of its traffic — kept shipping.44 The incident is worth more than its news value, because it shows the layer underneath the convergence: the features have become uniform, and what separates the products now is which models you can reach through them — a question that gets decided by corporate relationships, not by anything an orchestrator controls.

That drift is not unique to Cursor. GitHub Copilot started as autocomplete and now ships coding agents. The point is not that any of this is bad. The point is that the categories have stopped describing the products. When the IDE company, the chatbot company, and the terminal-tool company all sell cloud-hosted autonomous agents that open pull requests, “editor,” “chat assistant,” and “terminal tool” stop being useful distinctions, and the label will never tell you whether something has a permission envelope, can call other agents, preserves state across restarts, or may touch production. Look at the contract instead of the marketing noun.

1.11.1 Persistent agent runtimes

Persistent agent runtimes keep an agent available across sessions, channels, schedules, and tasks by adding all the machinery around the model: a gateway, a workspace, memory, skills, scheduled jobs, authentication, profiles, and routing to tools or to other agents.

Two current examples make the category concrete. Hermes Agent, from Nous Research, combines persistent memory, reusable skills, tool access, MCP, scheduled automation, and isolated subagents across terminal, desktop, messaging, and remote execution surfaces. Nanobot, from HKUDS, is a lightweight self-hosted Python runtime with a WebUI, tools, long-term memory, MCP, model routing, multi-agent delegation, and scheduled automation.4546

Two open-source harnesses deserve particular attention, because they embody a philosophy rather than a feature set. Goose, from Block — the company behind Square and Cash App — is a local-first AI agent under Apache 2.0 licensing: the runtime runs on your machine, while inference may still use a hosted provider unless a local model — such as one served through Ollama — is selected. It pairs with a wide range of LLM providers and connects to tools through MCP — an early and deep adopter of the standard, with a growing catalog of listed extensions; it is also one of three founding projects of the Linux Foundation’s Agentic AI Foundation, the same organization that now governs MCP.47 Pi, created by Mario Zechner of libGDX fame, is a minimal terminal coding agent distributed under MIT license at pi.dev, and its design philosophy is the exact opposite of the integrated appliance: it ships a small core — loop, tools, context, sessions — and deliberately leaves MCP, sub-agents, plan mode, and permission systems as primitives that you or the community supply through extensions, skills, and packages. Zechner’s own framing of that philosophy is the shortest statement of participation I know: Pi isn’t a sealed product — if you need a command, tool, provider, or workflow tweak, ask Pi to build it, and it customizes itself in place. The harness is built to be changed by the person running it.48

What makes Goose and Pi significant is not their capabilities but their ownership model — they are built to be owned, extended, and modified by the person running them, rather than rented from a lab that controls the weights, the personality, and the roadmap. An orchestrator choosing an open-source harness is making a different decision about authority than one choosing a closed harness. The closed one is usually more convenient on day one; the open one is more inspectable, adaptable, and easier to exit, which matters across a multi-year system life. Open code does not by itself create an audit trail — operational auditability depends on identity, logging, retention, configuration control, and evidence generation, whether the component is open or closed. Neither choice is automatically the right one, and the point is to make the trade deliberately, especially when the system will outlive this quarter’s demo.


  1. Cursor changelog and documentation, https://cursor.com/changelog and https://docs.cursor.com. Cloud Agents in isolated remote environments (August 13, 2026); Cursor on iPad (July 29, 2026); always-on cloud agents in Cursor Start (July 28, 2026); delivery surfaces across desktop, web, iOS, CLI, and SDK (Cursor Router); Slack, Teams, GitHub, GitLab, Azure DevOps, and Bitbucket integrations; scheduled Automations at https://docs.cursor.com/cloud-agent/automations; Faire quote (2,000+ automated agent runs weekly) from the August 13, 2026 changelog.↩︎

  2. The Tab-key gifts are documented by recipients: r/cursor, “Cursor sent me a gift for pressing Tab over 74283 times,” https://www.reddit.com/r/cursor/comments/1ox2m0c/, and public posts from other heavy users who received the single-key USB Tab gift, including Yudiz Solutions on LinkedIn (November 2025). Cursor’s own pricing guidance now distinguishes daily Tab users from daily Agent users — roughly $20 per month versus $60–$100 — per https://flexprice.io/blog/cursor-pricing-guide, which is itself evidence of the usage shift described. The account of the author’s own usage is the author’s.↩︎

  3. OpenAI, “Our decision on Cursor following its acquisition by SpaceX,” August 28, 2026, https://openai.com/index/our-decision-on-cursor-following-its-acquisition-by-spacex, announced a proposed November 12 wind-down of model access, citing contractual trust concerns. Contemporary reporting said OpenAI models represented about five percent of Cursor traffic, https://www.teslarati.com/openai-cites-distrust-of-spacex-in-decision-to-drop-cursor-partnership. The conclusion about model access as a differentiator is this book’s.↩︎

  4. Hermes Agent documentation, https://hermes-agent.nousresearch.com/docs. MIT-licensed, Nous Research.↩︎

  5. Nanobot, https://github.com/HKUDS/nanobot. Lightweight Python runtime from HKUDS.↩︎

  6. Goose documentation, https://goose-docs.ai/ (verified August 29, 2026). Open-source Apache 2.0 local-first AI agent from Block; runs on your machine with 15+ LLM providers including local models, connects to tools via MCP with a catalog of listed extensions. Founding project of the Linux Foundation’s Agentic AI Foundation.↩︎

  7. Pi, https://pi.dev/ (verified August 29, 2026). Minimal open-source MIT-licensed self-extensible coding agent by Mario Zechner (libGDX); “ask Pi to build it; it customizes itself in place” is Zechner’s own framing on the project site. Zechner’s design writeup: “What I learned building an opinionated and minimal coding agent,” https://mariozechner.at/posts/2025-11-30-pi-coding-agent. The project does not ship a built-in permission system and documents containerization patterns for stronger boundaries — see https://github.com/badlogic/pi-mono.↩︎