Meta’s forced unwind of its $2B Manus acquisition has become a test of whether an autonomous agent is a company asset or a sovereign asset. The answer implied by Beijing’s intervention is that, once software can plan, search, call external APIs, and execute across third-party services, ownership is no longer merely a commercial question.
Tencent is in advanced talks to become Manus’s largest single shareholder in a consortium with ZhenFund and HSG that would repurchase the startup from Meta at the same $2B valuation. This is not simply an investor-led rescue of a stranded deal. It is a reallocation of control toward domestic capital after a state decision that the relevant technology should not pass into foreign-platform ownership.

The National Development and Reform Commission used the Foreign Investment Security Review mechanism rather than China’s export-control catalogue to block Meta’s acquisition. That procedural choice matters because it treats the transaction as a control problem before it treats it as a technology-export problem. The distinction gives regulators room to act even where a product category has not yet been enumerated in a legacy policy list.
The resulting principle is more consequential than the single transaction: origin can outrank domicile. Offshore incorporation, global customers, or an international buyer may no longer be enough to separate a Chinese-origin agentic system from Chinese state jurisdiction. For founders and acquirers, the relevant diligence question is therefore expanding from where the company is incorporated to who can plausibly claim strategic interest in the system’s underlying capabilities, data pathways, and operational control.
Manus’s general-purpose agent is described as able to plan, search, call external APIs, and execute tasks autonomously across third-party services. A chatbot may produce language inside a bounded interaction. An agent that operates tools becomes a layer through which an organization can observe systems, move information, and initiate actions. That makes it legible to the state in the same way privileged enterprise software, payment rails, or a device operating system are legible: not as content alone, but as a continuously available control surface.
This does not mean every agent will become a nationally protected asset. It does mean the threshold is changing. The more an agent persists across tasks, retains context, has access to external permissions, and coordinates work among services, the harder it is to describe as a detachable application feature. Its value increasingly resides in the policy decisions around what it may access, what it may remember, and whose instructions it must obey.
OpenAI introduced ChatGPT Work as an enterprise agent for multi-step tasks including spreadsheets, presentations, documents, and web applications. OpenAI also released GPT-5.6 with an emphasis on multi-step reasoning, template adherence, and reference-material use. The important signal is less that another workplace assistant exists than that the product proposition has shifted toward executing a business process under managed conditions.
ChatGPT Work includes tool-access permissions, action monitoring, compliance APIs, and an Auto-review security feature that OpenAI said blocked all tested jailbreak attempts. Those features are not peripheral enterprise checkboxes. They are the operating contract for delegating work to a system that can take actions rather than merely recommend them. A platform that owns the permissioning, review, and audit layer owns more of the economic relationship than one that supplies a model endpoint.
Codex now exceeds 5 million weekly users, with more than 1 million using it for non-programming tasks. That reported spread is a useful, if incomplete, measure of how agentic behavior is moving beyond developer tooling. Yet it also sharpens the governance problem: the wider the task surface, the less plausible it becomes to manage an agent with a single blanket permission or a generic safety policy.
The durable competitive advantage may therefore sit above the model. It sits in identity, authorization, audit trails, escalation paths, domain context, and the ability to reverse a bad action. These layers can look like compliance overhead when an agent is confined to a demo. They look like product architecture once it enters payroll, finance close, procurement, customer support, or a developer’s production environment.
The governed-deployment posture Moveworks took before its ServiceNow acquisition is the useful enterprise precedent. The lesson is not that every agent startup needs a large-platform exit. It is that workflow plumbing and institutional trust are assets that become more valuable as autonomy rises. A technically capable agent without an accepted way to enter systems of record still has an adoption problem; one with deeply embedded controls has begun to resemble infrastructure.
Meta acquired Virtue AI after already using the startup’s automated red-teaming, runtime guardrails, and agent safety testing products. Virtue AI’s product suite includes VirtueGuard for real-time runtime protection and VirtueAgent Suite, an agentic gateway for enforcing enterprise security policies. Meta’s decision to internalize those capabilities instead of remaining solely a customer is a clear platform signal: security around tool calls, memory access, and multi-step execution is becoming too close to the core product to remain an optional external dependency.
That is a change in the safety market’s bargaining position. Independent safety vendors can still matter, especially where buyers want model-neutral control planes or independent evidence. But the most strategic layers are likely to be pulled inward by platforms that need their personalized agents to behave consistently across products and at consumer scale. In that environment, a safety company’s value is not just its detection quality; it is whether it can become the platform’s enforcement architecture before the platform builds or buys an alternative.

The counter-signal is equally concrete. Virtue AI’s relevance to Meta rests on monitoring tool calls, memory access, and multi-step execution chains, which are precisely the surfaces that expand when agents receive more permissions. A platform can acquire the guardrail layer, but acquisition does not itself prove that permissions are correctly scoped, reviews are timely, or recovery is possible after an autonomous action. The reliability gap familiar from AutoGPT remains: an impressive autonomous workflow is not the same thing as dependable production operation.
Step AI unveiled Step AOS in Shanghai on July 13, 2026, alongside the personal agent Amoo, the STEPX terminal brand, and the STEPX Neo smartphone. Step AOS is designed as an agentic-native operating system rather than an AI overlay on an existing operating system. This is the hardware-side expression of the same control logic visible in the Manus and Virtue AI developments: the agent is being moved closer to the layer that allocates memory, mediates permissions, and determines what software can do.
Step AI said its Step Edge on-device model ranked first among comparable on-device models across 29 benchmarks, and it presented Step AOS as a response to memory, decision-making, and action barriers. The benchmark claim should be treated carefully, because a device agent’s commercial test is not simply model ranking. It is whether a user can trust the system to act across applications, preserve the right context, and hand control back cleanly when intent is ambiguous.
Stepfun described STEPX Neo as a smartphone built on the Step AOS ecosystem and said its initial partners include Trip.com and Alipay. The dependency on an app ecosystem is the immediate counterweight to the full-stack thesis. Owning model, operating system, and hardware can create privileged access to device resources, but it can also produce an elegant closed loop with too few valuable destinations. An agentic operating system without enough accepted services risks being a technically sophisticated demo rather than a new distribution channel.
Still, the direction is significant. A conventional app competes for a place on an existing platform. An agent-native operating system can set defaults for intent routing, memory persistence, permission prompts, and handoffs between services. It can make the control layer state-legible and commercially legible at the same time. That is why ownership of the stack is being pursued even before the category’s consumer adoption is settled.
Ant Mijian introduced HOP 3.0 and an intelligent agent-native language at WAIC 2026 to advance agent orchestration and agent-to-agent communication. An inter-agent language is a small-looking infrastructure decision with large implications. Once agents coordinate rather than merely respond to a human prompt, the communication layer becomes a place to establish identity, permissions, observability, and accountability.
The emerging contest is thus not only between frontier models. It is between architectures for who coordinates work and who has the right to inspect, constrain, or interrupt it. A proprietary model can be swapped where costs or performance demand it. An orchestration layer tied to enterprise systems, a device runtime, or a national policy regime is much harder to replace because it contains the rules of action.
Perplexity CEO Aravind Srinivas said on July 12 that AI competition is shifting from model size to operational efficiency, and the company is testing a computer-use architecture that uses Zhipu AI’s open-weight GLM 5.2 as a primary worker while reserving a more capable model for difficult reasoning. That reinforces the infrastructure reading of this week. If task routing can move across models, then the scarce asset is less likely to be a single model’s parameter count and more likely to be the control plane that decides which model acts, with which tools, against which data.
Benchmark general partner Peter Fenton predicted that more than 90% of AI inference tokens could come from open-weight models within 18–24 months. Whether that forecast proves accurate, its strategic premise is clear: open-weight supply can weaken a model provider’s hold over inference margins while increasing the importance of orchestration, data control, and policy enforcement. The winners need not own every model if they own the system that assigns work among them.
This creates a sharper capital consequence for agent startups. A cross-border exit is no longer simply a question of valuation, antitrust, or a buyer’s integration plan. For Chinese-origin systems with meaningful autonomous capability, it may require a sovereignly acceptable ownership path from the start. Domestic hyperscalers, state-aligned funds, and locally controlled strategic buyers can become not merely financing options but the only credible exit channels.
That constraint will change company formation as well as M&A. Founders may design data residency, governance, model sourcing, and corporate structure around future control rights rather than future distribution alone. Foreign platforms, meanwhile, may find that licensing, commercial partnerships, or geographically segmented products are more feasible than outright acquisition. The cost is a more fragmented market; the benefit, from each state’s perspective, is fewer opaque control transfers over systems that can act inside sensitive environments.

The broad shift is therefore not from apps to agents in the usual product-marketing sense. It is from agents as feature bundles to agents as sovereign infrastructure: systems whose value and risk arise from their authority to observe, decide, and act. Safety, reversibility, provenance, and control are becoming competitive moats because they determine who can deploy that authority at scale—and who is permitted to own it.