Manus 2.0 AI Agents Expand the Product, but Trust Is the Real Test
Manus launched Manus 2.0 AI agents on September 28, less than one month after declaring that it had resumed independent operations. The release adds a new agent architecture, persistent cloud computers, event-driven automations, editable creative tools, and a separate personal-agent app called Cue.
This is more than a routine product update. Manus wants its software to move from completing isolated prompts into running continuing projects across files, applications, online services, and physical-world transactions. That shift places Manus against Meta, OpenAI, and other companies racing to turn chatbots into agents that can act.
The most important contest is not over which agent has the longest feature list. It is between expanding autonomy and preserving meaningful user control. Manus now wants agents to operate computers, exchange messages, accept calls, coordinate with other agents, and spend within a user-defined budget.
Those capabilities make the software more useful. They also increase the consequences of unclear instructions, unreliable decisions, excessive permissions, and weak oversight. Manus 2.0 therefore arrives with a larger technical ambition and a much harder trust problem.
Manus 2.0 AI Agents Move From Tasks to Persistent Work
Manus 2.0 changes the product from a task runner into a collection of environments where agents can continue working after the original prompt.
The company announced Manus 2.0 and Cue on Monday, September 28. Bloomberg described the move as a renewed attempt to gain ground in the fast-growing agent market in its initial agent market report.
At the center of the release is Cascade, which Manus describes as the latest version of its in-house agent harness. An agent harness is the software layer that manages models, tools, context, execution steps, and results.
Manus says Cascade keeps a project lightweight until specialized capabilities become necessary. A document, website, video, or automation can remain inside one connected project instead of becoming a series of unrelated sessions.
In one configuration tested by Manus, Cascade reportedly used 23.2 percent fewer tokens than the previous system. The company also says it finished tasks 28.2 percent faster and reduced operating costs by 32 percent.
Those figures come from the company’s own Manus 2.0 announcement. Manus did not publish enough methodological detail for an independent comparison across workloads, models, or competing products.
The direction still matters. Agent products become expensive when they repeatedly load large amounts of context or invoke specialized models unnecessarily. Routing each job to only the required capabilities can reduce that burden.
The release also introduces Cloud Computer, a dedicated environment that can remain available when the user’s local device is offline. Manus presents it as infrastructure for persistent automations, hosted applications, and multiplayer games.
That persistence changes the product’s operating model. An agent no longer needs to begin and end within one browser session. It can maintain an environment where applications, files, processes, and scheduled work continue running.
Manus has also expanded Scheduled Tasks into Automations. These workflows can begin after an event in a connected service, rather than only at a predefined time.
A new email, Slack message, calendar event, Notion update, or advertising change can trigger a task. The user describes what Manus should monitor and what action should follow.
Consider a product manager who receives customer research across email, Slack, recordings, and project documents. An event-driven agent could classify new feedback, update a summary, and prepare a weekly brief.
That resembles the broader move toward an AI workflow, where information capture, synthesis, and output become one continuing process. The difference is that Manus also wants to execute actions beyond organizing knowledge.
The result is a product that spans two layers. Cascade decides how work should be routed, while Cloud Computer and Automations provide places where that work can continue.
That combination creates the central tension around Manus 2.0 AI agents. Persistent execution offers more value than a one-time answer, but every persistent process needs boundaries, monitoring, and recovery controls.
Manus Studio Blends Generation With Direct Editing
Manus is betting that agents become more useful when users can inspect and edit their output without restarting the entire generation process.
The company has renamed and expanded its desktop experience as Manus Studio. It describes Studio as a shared workspace where people and AI can work on documents, spreadsheets, PDFs, presentations, websites, code, games, and video.
This design pushes against a recurring limitation of prompt-based creative tools. Generating an acceptable first draft can be fast, while correcting one specific element can become frustrating.
Manus illustrates the problem with video editing. A user might like an automatically generated advertisement but want to replace its music or use a different product image.
Regenerating the entire video could introduce new unwanted changes. Studio instead exposes clips, images, text, audio, and motion graphics as separate components on an editable timeline.
The user can make a direct change, then return the project to the agent for another pass. That creates a mixed workflow where manual editing and automated generation can alternate.
Manus says its Video Editor targets product advertisements, tutorials, vlogs, motion graphics, and AI-generated user-style content. The company specifies a focus on videos lasting 30 to 60 seconds.
The release also adds Alchemy mode, which combines video generation and code generation under an automated creative-direction process. Manus claims this mode improves composition, detail, motion, and pacing.
Those quality claims have not been independently validated. The more meaningful product decision is that users retain access to the timeline after generation.
Game Dev follows a similar pattern. It combines coding, image, and video models with an editing panel for assets, source code, movement, art, and scenes.
A user can begin with a playable template, modify individual elements, and publish the result as a website. Cloud Computer can provide the persistent server needed for supported multiplayer projects.
This feature bundle puts Manus into several markets at once. It touches AI coding products, website builders, presentation generators, video tools, and game-development environments.
That breadth carries a risk. Specialized creative applications have deep editing systems built around years of professional feedback. Manus must offer enough control to remain useful after the first impressive generation.
The release suggests that the company recognizes this problem. Instead of claiming that prompting should replace every interface, Manus is bringing editable interfaces back into the agent workflow.
That choice is important because direct manipulation gives users a clearer mental model. Selecting a clip, moving an object, or changing code provides more predictable feedback than repeatedly rewriting a prompt.
Manus Studio therefore represents a practical compromise. The agent handles planning and production, while the user retains access to familiar tools for review and correction.
The approach also creates a clearer division of responsibility. Users can identify exactly which element they changed, while the agent can continue from that revised project state.
Success will depend on how reliably Manus preserves those edits. An agent that unexpectedly overwrites manual changes would weaken the control model that Studio is supposed to provide.
The same issue applies across documents, spreadsheets, websites, and games. Editable artifacts matter only when their structure remains stable across repeated agent actions.
Studio broadens the product, but it also raises expectations. Manus must now compete on editing precision, project continuity, and recovery, not only on generating a convincing first result.
Cue Turns Personal AI Agents Into Digital Operators
Cue is the boldest part of the release because it gives agents identities, communications tools, computers, and limited spending authority.
Cue is a separate application for mobile devices and desktops, built on the same infrastructure as Manus. The company describes it as a place where users can create and deploy personal agents.
Each agent can receive its own email address, phone number, digital wallet, and computer. According to Manus, an agent can send messages, receive calls, complete work on its machine, and spend within a defined budget.
Cue agents can also work as a group. Manus offers the example of several agents coordinating a launch, with separate agents researching venues, building a shortlist, and drafting presentation materials.
This model changes how users interact with software. Instead of opening several applications and completing each step, a person assigns an outcome to a group of persistent software actors.
The personal-agent concept is no longer unique to Manus. Meta launched its Muse agent earlier in September, giving it a separate application and access through WhatsApp.
Meta says Muse can manage tasks including emails, travel booking, shopping, and longer-term planning. It runs inside a dedicated virtual machine, according to coverage of the Muse agent launch.
Manus Cue agents attempt to differentiate through digital identities and coordination. A phone number lets an agent receive calls, while a wallet creates a route for limited transactions.
Cue also reaches into physical businesses. Manus says a user can scan a restaurant’s QR code and ask an agent to order or hold a position in line.
These examples show why agents are becoming a strategic category. A chatbot usually waits for a question. A personal agent maintains context, observes events, chooses tools, and performs actions.
The commercial opportunity lies in becoming the layer through which users interact with many services. The company controlling that agent could influence which applications, merchants, information sources, and payment routes receive attention.
That creates pressure on major platforms. Meta can place an agent inside WhatsApp and connect it with a large consumer network. OpenAI can build agent functions around ChatGPT’s existing user relationships.
Manus lacks those distribution advantages. Its response is to package a wider range of execution tools inside one product family, then make the agent itself portable across workflows.
The company’s history adds another dimension. Meta announced an agreement to acquire Manus in December 2025, and AP reported that Manus had exceeded $100 million in annual recurring revenue.
Meta said at the time that Manus would support general-purpose agents across consumer and business products. The acquisition coverage also described Manus as serving millions of users and companies worldwide.
However, Manus announced on September 1, 2026, that it had formally resumed independent operations. The company said its founding team would continue leading it as an independent agent lab.
The short independence notice did not explain the transaction’s reversal or provide new ownership details. It acknowledged that some users had faced temporary access interruptions and data restoration requirements.
Manus 2.0 arrived 27 days later. That timing makes the release a declaration of product direction after a period of unusual corporate change.
The strategy is now visible. Manus is pursuing an independent platform that spans professional creation, persistent automation, computer control, and consumer-facing personal agents.
Cue remains in early access, and access is initially limited. That means the most ambitious capabilities have not yet faced broad, independent testing across diverse users and real transactions.
More Agent Autonomy Creates a Bigger Control Problem
The decisive question is whether Manus can make persistent agents understandable and recoverable before users grant them wider authority.
Every capability in Cue expands the potential effect of an error. A mistaken summary is inconvenient. A mistaken message, purchase, file operation, or external communication can be much harder to reverse.
Digital wallets are a clear example. A spending limit contains the maximum financial exposure, but it does not ensure that each transaction reflects the user’s actual intent.
Phone access creates another challenge. An agent must determine who is calling, what information it can disclose, when it should act, and when it should request human confirmation.
Computer access increases the number of possible actions even further. Manus says Computer Use operates in a visible workspace and only uses approved files, browsers, and applications.
Visibility is useful, but observation alone does not equal control. A user cannot continuously watch an agent that is supposed to save time by working independently.
The design problem involves approval thresholds. Requiring approval for every action makes the agent tedious, while approving too little can expose accounts, data, and money.
Meta has confronted the same tradeoff with Muse. Its separate Sentinel system reportedly evaluates whether proposed actions can proceed, should be blocked, or require user approval.
The difficulty is not limited to malicious behavior. Agents can misunderstand ambiguous instructions, lose relevant context, select the wrong account, or perform an irreversible step too early.
Research published in 2025 examined 31 participants completing tasks with Manus and OpenAI Operator. The study found recurring problems involving trust, collaboration styles, communication overhead, and users’ mental models.
Participants were generally impressed, but the researchers found that agents often presumed trust before establishing credibility. The agents also struggled to understand their own limitations.
Those findings appear in the agent usability study, which analyzed marketed use cases across 102 commercial agent products. The authors grouped those uses into orchestration, creation, and insight.
Manus 2.0 covers all three categories. Studio creates artifacts, Cascade coordinates capabilities, and Cue operates across communications and services.
That breadth magnifies the importance of transparent boundaries. Users need to understand what an agent can access, which actions require approval, and how long each authorization remains valid.
They also need dependable activity records. A useful log should show what the agent observed, why it chose an action, which tool it used, and what changed.
Recovery matters just as much. Persistent cloud environments should support checkpoints, version history, revocable credentials, and clear ways to stop active processes.
Manus has published security certifications through its trust materials, including references to SOC 2 and ISO certifications. Those controls address important organizational and infrastructure practices.
They do not independently establish that every new Cue behavior is safe or reliable. Product-level risk depends on permission design, transaction handling, failure recovery, and real-world operating results.
The Cascade performance figures require similar caution. Reduced token use and faster completion sound useful, but one company-tested configuration cannot represent every task.
A faster agent can still produce a poor result. Lower operating costs do not reveal whether the agent needed more human corrections or completed fewer intended requirements.
Manus must therefore report more than efficiency. Buyers need task-completion rates, intervention frequency, error categories, recovery outcomes, and performance across different workloads.
The company also needs clear policies for agent identity. Recipients should know when they are communicating with software, especially during calls, commercial transactions, or sensitive negotiations.
Service providers will set their own limits. Restaurants, ticketing platforms, communications services, and merchants might restrict automated activity when agents create spam, unfair access, or ambiguous liability.
Cue’s wallet and phone features bring these questions forward. They transform agent safety from a chat-interface issue into an operational and economic issue.
The central tradeoff cannot be eliminated. An agent useful enough to save meaningful time must receive some authority, yet authority creates exposure.
Manus can manage that tension through scoped permissions and predictable escalation. It cannot solve the problem through broad claims that the user remains in control.
Three Signals Will Show Whether the Push Is Working
The next phase should be judged by adoption, operational evidence, and control mechanisms rather than the number of features Manus announces.
The first signal is broad Cue availability and continued usage after early access. Invite demand can show curiosity, but recurring use will reveal whether personal AI agents solve everyday problems.
Useful evidence would include how often users create multiple agents, which tasks repeat, and how frequently people intervene. Retention would matter more than the number of accounts created.
Cue must also prove that agent coordination reduces work. A group chat filled with agents can become another source of updates, decisions, and supervision.
If people repeatedly delegate complete workflows and return to usable results, Manus will have evidence for its digital-operator model. If users mostly ask questions, Cue will remain closer to chat.
The second signal is independent verification of Cascade and Studio. Manus should publish evaluation methods behind its speed, token, and cost claims.
External testing should examine whether projects remain coherent across long sessions. It should also test whether Studio preserves manual edits when an agent resumes work.
Game Dev and Video Editor create demanding evaluation cases. Both require consistency across code, assets, timing, dependencies, and repeated revisions.
A usable first result is not enough. The product must support the final stretch where creators fix details, respond to feedback, and prepare work for publication.
The third signal is the evolution of permission and recovery controls. Cue should make spending limits, communication rights, connected services, and computer access easy to inspect.
Users should be able to pause one agent without stopping every project. They should also be able to revoke one permission without rebuilding the entire configuration.
Transaction histories need to connect each action with a user instruction or approved policy. Sensitive actions should support confirmation rules that users can understand before something goes wrong.
Watch how competing platforms respond as well. Meta can combine its agent ambitions with messaging distribution, while OpenAI and other model providers can integrate actions into existing assistants.
Manus must show that an independent specialist can move faster without sacrificing reliability. Its product breadth will help only if the pieces work together coherently.
The renewed push also tests whether Manus can rebuild trust after its abrupt corporate transition. In December 2025, Meta presented the company as part of its agent strategy.
By September 2026, Manus was again calling itself independent. Its public announcement confirmed the change but left the reasons and long-term structure unclear.
Customers evaluating persistent workflows need confidence that the service, data arrangements, and product direction will remain stable. This matters when automations become embedded in daily operations.
Manus 2.0 AI agents offer a clear vision of where consumer and workplace software is heading. Users state outcomes, while persistent agents coordinate tools and execute the intermediate work.
The release also exposes the conditions required for that vision to succeed. Agents need durable context, editable outputs, narrow permissions, visible actions, and reliable recovery.
Developers should watch the Cascade architecture and Manus API for clearer orchestration patterns. Enterprise buyers should focus on governance, auditability, and measurable intervention rates.
Knowledge workers should begin with reversible tasks. Research synthesis, draft creation, and monitored workflow updates offer practical value without granting unrestricted authority.
Then test whether the agent follows corrections across repeated work. A personal agent becomes useful when it improves continuity, not when it simply produces more output.
The real question is not whether Manus can give software an email address, phone number, wallet, and computer. The question is whether users can delegate without losing situational awareness.
Try one bounded workflow, define what the agent cannot do, and review every resulting action. If Manus makes that process predictable, its agent push will have substance beyond launch-day attention.



