Manus 2.0 moves AI agents into persistent cloud workspaces


Persistent agents
Manus 2.0 adds purchasable Cloud Computer environments for projects and automations that need continuous infrastructure.
Workspace shift
Agent products from Manus and OpenAI are converging on shared workspaces with files, browsers, cloud computers and project context.
Governance priority
Persistent agents make access controls, audit logs, sandboxing, identity and kill switches core buying criteria.
Manus 2.0 is the latest sign that agent platforms are shifting from single-session prompt windows to persistent work environments. The release adds Cascade, a new agent harness; Manus Studio, a shared workspace for people and AI; event-triggered automations; and purchasable Cloud Computer environments for projects that need dedicated, always-available execution infrastructure.1
For developer-tooling and AI workflow buyers, the strategic point extends beyond one product launch. Agent startups and major AI vendors are converging on a practical substrate for delegated work: hosted computers, browsers, files, credentials, logs and workflow state that persist after a chat ends. The model is designed for longer-running tasks, such as monitoring customer feedback, maintaining project documents, testing applications, updating analyses or responding to operational events without forcing users to re-create context each time.12
The shift also changes the procurement question. Enterprises are no longer asking only whether an AI assistant can produce a good answer. They are asking where its work lives, what systems it can touch, how long it can run, who can approve its actions and how quickly access can be revoked if the agent behaves incorrectly.134
Manus 2.0 introduces Cloud Computer as a dedicated environment for projects that need continuous operation or a stable home for automation. According to InfoWorld, Manus describes it as a purchasable environment for projects that need it, including automations or services that must remain active over time.1
That is a different posture from a chatbot that waits for a human prompt. A persistent environment gives an agent a place to keep files, run tools, maintain project state and continue work while the user is offline. Manus is pairing that infrastructure with event-driven automations, so work can begin when something happens in a connected service, such as a new email, Slack message, calendar event or change in ad performance.1
Cascade, the new agent harness, addresses a related problem: how to coordinate agent capabilities inside a project without invoking everything all the time. Manus said one tested Cascade configuration used 23.2% fewer tokens, completed tasks 28.2% faster and cost 32% less than its previous system, though the company did not disclose the test configuration or task set.1 The caveat matters, but the direction is clear: orchestration, runtime efficiency and selective tool use are becoming product differentiators.
Manus Studio extends the workspace layer. The upgraded desktop app is described as a shared environment for people and AI, with support for documents, spreadsheets, PDFs, slides, websites, code, games, video and specialized environments such as video editing and game development modules.1 In practical terms, Manus is trying to make the agent’s workplace look less like a text box and more like a project operating system.
OpenAI’s newly announced Dots and ChatGPT Space point to the same market pattern. VentureBeat reported that Dots are persistent AI agents that can keep working after a user closes a chat window, with their own cloud computer and browser. ChatGPT Space provides a collaborative layer for shared files, pages, spreadsheets and team materials.2
The overlap with Manus is notable. Both approaches assume delegated work needs continuity, shared context and an execution environment. OpenAI’s examples include agents watching customer feedback, scoping smaller fixes, building and testing changes, preparing pull requests, keeping project pages current and updating work as underlying information changes.2 Manus, meanwhile, is emphasizing automations, remote execution, persistent Cloud Computers and a shared Studio workspace.1
This convergence suggests the near-term platform battle will not be decided by model quality alone. Buyers will compare the surrounding work system: connectors, permissioning, workspace collaboration, artifact management, runtime isolation, auditability and cost controls.
Persistent agent environments create more value because they can operate across time and systems. They also create more risk because they may have access to files, browsers, code, credentials, network resources and business applications.
OpenAI’s enterprise documentation reflects this governance burden. Workspace owners can control dots access, local computer access, custom rules, cloud browser use, cloud network access, cloud computer use and password-manager use. OpenAI says dots access is off by default for Enterprise, and local computer access is also off by default.3 Those defaults show how sensitive the boundary is between an AI agent that advises and one that acts.
Manus faces the same issue. InfoWorld reported that Manus 2.0 includes remote control capabilities tied to computer use, allowing the system to operate in an authorized workspace on a user’s computer with approved files, browsers and apps.1 The more an agent resembles a junior operator with tools, the more enterprises need controls normally associated with workforce identity, endpoint security and automation governance.
Security vendors are responding. Nvidia’s Open Agent Safety Platform and OpenShell sandboxing effort are positioned as infrastructure for controlling long-lived or autonomous agents. TechCrunch reported that OpenShell is open source software designed to sandbox agents and prevent escape, while Nvidia’s broader platform also includes hardware-layer monitoring through BlueField-4 data processing units.4
DigiCert’s support for Nvidia’s platform adds another layer: verifiable identity and authority for agents. Its release describes AI Trust Manager as a way to discover and manage agents, assign cryptographic identity, define authorized actions and revoke authority through a kill switch when trust changes.5 Palo Alto Networks is similarly integrating controls around agent activity, network traffic, identity management, isolated execution and policy enforcement for agent sandboxes.6
For AI workflow buyers, the practical evaluation framework now includes four questions.
First, what state does the platform retain? Persistent agents are useful because they remember project context, keep artifacts and continue workflows. But buyers need to know where prompts, intermediate task state, files, logs, backups and connector credentials are stored, and whether that state can be exported or reconstructed elsewhere.1
Second, what can the agent access? A hosted cloud computer that can browse the web, run shell commands, connect to applications and manipulate files is powerful infrastructure. It should be governed with role-based access, short-lived credentials, scoped permissions, approval gates and audit logs.36
Third, how is the agent isolated? Sandboxing, network controls, secrets management and hardware-assisted monitoring are becoming part of the agent stack because persistent agents may run long enough and with enough authority to create operational risk.46
Fourth, who is accountable for the agent? As agents gain their own workspaces, identities and credentials, enterprises will need onboarding, policy assignment, monitoring and offboarding processes similar to those used for service accounts or non-human identities.5
Manus 2.0 is not just a feature update. It reflects a broader market turn. Agent products are becoming hosted work environments where tasks, files, tools, automations and execution state persist over time. That architecture is more suitable for real delegated work than a prompt window, but it also pushes agent platforms into the territory of cloud infrastructure, identity governance and security operations.
For buyers, the winning platforms will combine useful autonomy with clear boundaries: persistent enough to carry work forward, but constrained enough to be supervised, audited, revoked and moved when necessary.

Morocco’s Ministry of Digital Transition and Mistral AI have released open-source AI components for Moroccan Darija, including a dialect-identification classifier and a Voxtral-based speech-recognition model. The launch positions localized AI tooling as public digital infrastructure for services, startups and AI sovereignty in languages underserved by general-purpose models.

ElevenLabs has launched Eleven v4 and v4 Turbo, adding more expressive speech generation, support for more than 90 languages and lower-latency output aimed at voice-agent use cases. The release signals a shift for voice AI from content production into interactive infrastructure for support, accessibility and localization workflows.

OpenAI’s DevDay launch of Dots signals a shift from chatbots that answer prompts to agents that keep working across apps. For AI product and platform teams, the hard part is now runtime design: identity, permissions, sandboxing, monitoring and enterprise governance.

Jev and open decision-model projects point to a practical efficiency pattern for AI applications: use generative models for language, but use calibrated classifiers for bounded routing, triage, approval and scoring decisions.
Agent harness
A runtime or orchestration layer that coordinates how an AI agent uses models, tools, memory and specialized capabilities during a task.
Cloud Computer
A hosted computing environment where an agent can run tools, browse, store files and maintain work state without relying on a user’s local machine.
Persistent workspace
A shared environment where documents, files, workflows, logs and project context remain available across sessions for humans and agents.
Agent sandbox
An isolated execution environment that limits what an agent can access or do, often enforcing policy around files, networks, credentials and external tools.
Comments