Harnesses
Meta Muse, the Agents API and AIforce: the platform war is now a harness war
In four weeks Meta, OpenAI and Salesforce each started selling the layer around the model: a personal agent on its own VM, the Codex harness as an API, and an enterprise control plane. What shipped, when, and how to stay portable.
- Published
- 30 Sep 2026
- Reading
- 11 min
- Class
- harnesses
half-life 90dfrom 30 Sep 2026
Between 26 August and 23 September 2026, three of the biggest platforms in AI all made the same move. Meta launched a personal agent that lives on its own virtual machine. OpenAI turned the harness behind Codex into a product you can call over HTTP. Salesforce gave its whole enterprise stack a "trusted enterprise AI harness" and a control plane to run it.
None of the three announcements led with a model. They led with the scaffolding around it: the loop, the sandbox, the memory, the permissions, the approval gates, the bill. That layer — the agent harness — is where the platform war is now being fought. This piece is a dated account of what actually shipped, what each vendor is really selling, and how to adopt any of it without giving away the part that matters.
The claim everyone is now making
The formula has been circulating since March 2026, when LangChain's Vivek Trivedy put it as: an agent is a model plus a harness, and if you are not the model, you are the harness. It stuck because the effect became measurable. Databricks ran the experiment on real software work in its own codebase in 2026: hold the model constant, change what surrounds it, and one harness cost more than twice as much per completed task as another at equivalent quality.
Vercel found the same thing from a different direction, replacing eighteen specialised tools with one general-purpose command-line tool and watching both reliability and speed improve. The system around the model changes the cost and quality of the work as much as the model does. Once that is accepted, selling the harness is the obvious move — and September 2026 is when three platforms started doing it openly.
Meta's play: the harness becomes your computer
Muse launched in the US on 8 September 2026 (Meta newsroom, 8 Sep 2026) — iOS, Android and the web, with AI glasses promised later. It is a personal agent that works across your apps and accounts, driven by conversation in the Muse app or WhatsApp. Free for most uses, with subscription tiers at $20 and $100 a month depending on usage (CNBC, 8 Sep 2026).
The interesting part is not the assistant. It is the computer Meta built around it. Muse runs on what the company calls Muse Secure VM: a dedicated virtual machine per person that houses the agent, your data, and the credentials for any service you connect (Meta newsroom, 8 Sep 2026). A separate Sentinel agent runs on the same machine, separated at the system level, and nothing Muse does reaches the internet unless the Sentinel approves it. Muse itself never sees your passwords — they go into secure storage it can use but not read. Before anything sensitive happens — an email sent, a purchase made — it checks with you and shows a full audit trail.
Two design choices show where Meta thinks this is going. First, Muse keeps working after you close the app: it runs long tasks in the background and comes back when something changes or needs approval. Second, it can pay. Checkout runs through Link by Stripe with single-use card numbers, and Meta states Muse is the first agent covered by Link's purchase protections (Meta newsroom, 8 Sep 2026). 1Password support and Shop Pay are promised but not shipped. A confidential variant, where the whole VM is encrypted under a key only you hold, is promised "later this year" — treat that as a roadmap item until it lands.
Two reality checks, both worth holding onto. Reuters reported on 22 September 2026 that Meta has been testing a "human concierge": trained human contractors quietly place some of the phone calls the agent makes. Some of what looks like autonomy is a call centre behind an API. And the headline features announced on 23 September — a video avatar, and control of your Mac desktop — were still "coming soon" on that date (TechCrunch, 23 Sep 2026).
OpenAI's play: sell the harness as an API
OpenAI's Agents API went into public beta on 10 September 2026, and the framing in the announcement is unusually direct: "Build and run cloud agents with the Codex harness, fully managed by OpenAI." The pitch is that long-running agents need infrastructure more than they need a smarter model — context management, efficient tool use, subagent coordination, and environments that survive for days (OpenAI, 10 Sep 2026).
In practice, one API call creates a session with a task, a model, tools, and an environment. The harness runs the loop: tool search loads tool definitions on demand to cut token use, programmatic tool calling runs calls in parallel and chains them, and subagents can be spawned with a concurrency cap. The example in the docs wires MCP servers, a secrets vault, and a capability directory of skills into the session.
The architectural detail worth caring about is the split between harness and sandbox. OpenAI hosts and maintains the harness; the compute environment is your choice — an OpenAI-managed sandbox, your own infrastructure, or sandbox partners (reported as Cloudflare, Vercel and Oracle; the-decoder, 11 Sep 2026). One early customer, Hypha, claims separating the harness from the sandbox cut failed agent responses by 86% — a vendor-published testimonial (OpenAI, 10 Sep 2026), so treat the number as marketing until you reproduce it.
Pricing during the beta is simple: no additional fee for the Agents API itself, you pay for tokens and tools (OpenAI, 10 Sep 2026). Beta pricing is not a promise. When this reaches general availability — and OpenAI says it will iterate quickly before then — the harness fee is the obvious lever to pull.
Salesforce's play: the harness as the control plane
Salesforce arrived at the same destination by the enterprise route. The pieces shipped in sequence: Headless 360, which exposes Salesforce operations as APIs, MCP tools and CLI commands (announced April 2026); Claudeforce on 26 August 2026, which makes Claude the default reasoning model across Agentforce and Slackbot and ships a Salesforce-in- Claude plugin with 37 prebuilt sales skills; and then the umbrella itself — the "Trusted Enterprise AI Harness", published 10 September 2026 and demoed as AIforce at Dreamforce on 15–16 September 2026.
The harness is six capabilities — context, agency, action, governance, security and model routing — plus an AI Control Plane where agents are registered, identified, evaluated, observed and billed (Salesforce, 10 Sep 2026). The pitch to enterprises is the three questions that stall agent rollouts: what context an agent may see, what it is allowed to execute, and what it costs to run. Marc Benioff's summary from the August 2026 earnings call: the shift "from software as the interface to software powering every interface."
The clever part is that the harness is model-agnostic underneath the branding. Claudeforce is just one implementation; the same plumbing is promised for Microsoft Teams, Google Gemini and OpenAI's ChatGPT (Deep Analysis, Sep 2026). The catch is the calendar and the price list: the foundational pieces are available to existing customers now, but the unified experience only begins rolling out in early fiscal 2028 — February 2027 at the earliest — and AIforce pricing is unannounced (Salesforce, 10 Sep 2026). For scale, Agentforce is reported at roughly $800M ARR across 29,000+ deals as of FY2026 Q4 (aggregated from Salesforce filings; Stackscout cheat sheet, 12 Sep 2026).
What the three plays share
Read side by side, the strategies rhyme:
- The model is the replaceable part. OpenAI lets you pick the model in the session. Salesforce routes between models by cost and accuracy. Meta hides Muse Spark behind the product. All three are buying into the same judgement: model capability is converging faster than harness capability, so the durable asset sits around the model. TURION's July 2026 infrastructure survey made the same argument: separate the harness from the model, treat hooks as policy, and bet on durable execution (TURION.AI, 31 Jul 2026).
- Permissions and money live in the harness. Muse's Sentinel agent and Stripe-backed wallet, OpenAI's vaults and sandbox boundaries, Salesforce's control plane and per-user OAuth — the approval gate is the product. This is also where liability concentrates, which is why each vendor is shipping the boring parts first.
- Lock-in moves up the stack. When your prompts, skills, memory, evals and approval policies are configured inside someone's harness, switching models is easy and switching harnesses is not. That is the point. As one analysis of the market put it, the harness may become harder to replace than the model.
There is one important disagreement: what the word "harness" even means. Through 2026, Databricks, Red Hat, Builder.io and Parallel each published their own definition — an in-process library, a hosted runtime, a product wrapper — and none are interchangeable (HarnessRouter, 2026). A shared contract for the layer exists only as an attempt: the Unified Harness Protocol, an open spec backed by a commercial vendor, is the first try at letting applications drive any harness through one interface. Keep an eye on it, but do not plan around it yet.
How to buy without getting married
The pragmatic line from the same body of analysis is: buy the substrate, code the judgment. Managed harnesses have crossed the viability threshold — Microsoft's Agent Framework reached general availability in August 2026, Claude Managed Agents have been in public beta since 8 April 2026 at $0.08 per session-hour on top of tokens, and OpenAI's is free of harness fees during beta (TURION.AI, 31 Jul 2026; HarnessRouter, 2026). Rebuilding sandboxing, checkpointing and context compaction yourself is rarely the best use of a small team. Four rules keep the door open behind you:
- Keep the judgment layer in files you own. Prompts, skills, tool definitions, approval thresholds and test cases should live in your repository, in plain text, imported into whichever harness runs them. If an agent mistake costs you a customer, the fix — the new rule, the new test — is an asset. Do not store assets in someone else's control plane.
- Compare on cost per completed task, not tokens. Harness fees arrive as session-hours (Anthropic), per-action credits (Salesforce's Flex Credits, reported at 20–30 credits or roughly $0.10+ per action; Stackscout, 12 Sep 2026), or plain token bills (OpenAI, beta). Only completed-work pricing makes those comparable — and run the comparison on your own evals, because harness choice changes failure modes, not just cost.
- Export as you go. Sessions, traces and memory are the raw material of your eval sets and audit trail. Pull them out on a schedule. Both OpenAI's and Salesforce's harnesses keep state on their infrastructure by design; Muse keeps it in its VM.
- Assume every September 2026 price is provisional. Muse's $20/$100 tiers, the Agents API's zero harness fee and AIforce's blank price tag are opening moves. Re-run the numbers at general availability — this post has a 90-day half-life for exactly that reason.
Where this lands
A year ago the harness was something every team assembled from retry logic and cron jobs. In September 2026 it became the thing three platforms are willing to be judged on. For builders, that is genuinely good news: the boring, hard parts of running agents are now products. For buyers, the decision has quietly changed shape. You are no longer choosing a model. You are choosing who runs the loop, who holds the credentials, who approves the spend — and how much of that you can take with you when the pricing changes. Because it will.
Sources
- Meta: Introducing Muse — 8 Sep 2026. Muse Secure VM, Sentinel agent, payment design, US launch.
- CNBC: Meta pushes into personal AI agents — 8 Sep 2026. Free tier plus $20/$100 monthly plans.
- Reuters: Meta testing a "human concierge" for Muse — 22 Sep 2026.
- TechCrunch: Everything new coming to Muse — 23 Sep 2026. Roadmap items and Muse Spark.
- OpenAI: Introducing the Agents API — 10 Sep 2026. Public beta, harness/sandbox split, pricing during beta.
- The Decoder: OpenAI's new Agents API — 11 Sep 2026. Sandbox partners, open-source Codex harness base.
- Salesforce: Trusted Enterprise AI Harness — 10 Sep 2026; AIforce at Dreamforce — 15–16 Sep 2026; Claudeforce — 26 Aug 2026. Summarised via Deep Analysis (Sep 2026) and Stackscout's cheat sheet (12 Sep 2026).
- TURION.AI: The Agent Harness Is 2026's Real Infrastructure Bet — 31 Jul 2026. Managed-harness pricing and design rules.
- Above the Model: The Harness You Buy and the Harness You Code — Sep 2026. Databricks and Vercel findings; "buy the substrate, code the judgment".
- HarnessRouter: The Agent Harness Layer — 2026. Competing harness definitions and the Unified Harness Protocol attempt.
- Earlier on this site: Anatomy of an agent harness and Harness engineering.