
On September 28, 2026, Manus released version 2.0 of its AI agent platform. The company was blunt about it: its own blog post opens by saying this is not a version update. It describes a new architecture, called Cascade, that replaces the system underneath the entire product.
The headline feature is not a smarter model. It is a different kind of identity. Through a new layer called Cue, a Manus agent can hold its own email address, its own phone number and its own wallet, all separate from the user's. For executives deciding where autonomous software belongs in their operations, that shift deserves more scrutiny than the launch's performance figures.
What Manus Actually Launched
Cascade is the engine. Cue is the part business leaders will notice. The best way to picture Cue is to think less of a chatbot and more of a small remote team member who comes with their own contact details.
What a Cue-enabled agent can do
- Answer an incoming phone call and leave the user a summary of what was said.
- Use a restaurant's QR code to place an order or hold a place in line.
- Spend money on the user's behalf, inside a budget the user sets in advance.
None of these tasks is glamorous. That is precisely the point. They are the small, routine errands that consume staff time, and they now sit within reach of software that acts under its own name.
Why a Separate Identity Matters More Than It Sounds
Until now, an AI agent working for you was structurally still you. It used your login, your card and your inbox. Every action it took was, from the outside world's perspective, an action by you.
Giving the agent its own identity changes that arrangement. It is the difference between an assistant borrowing your identity for one errand and an assistant with an actual footprint of its own in the real world.

Editorial view: the shift raises practical questions that a smarter model never did. Who is accountable when an agent with its own phone number makes a commitment? Where does the audit trail live when the agent's inbox is separate from yours? Those are governance questions, and they belong on a leadership agenda, not just an IT ticket.
Fact-Check: The Performance Claims
Manus says its new engine uses 23.2% fewer tokens, finishes tasks 28.2% faster and costs 32% less to run. Those figures come directly from Manus's own blog post. There is no independent test and no published test configuration behind them.

The sensible reading is to treat them as a company claim rather than a verified benchmark, at least until someone outside Manus runs the same comparison. Vendor numbers are not worthless, but they are a starting hypothesis, not a procurement basis.
The Security Risk Worth Sitting With
Manus automations begin working the moment a new email or message arrives. That means content from a complete stranger can shape what the agent decides to do next.
An agent with its own wallet and its own inbox is a genuinely larger attack surface than a chatbot that only answers when someone types to it. The same independence that makes the agent useful also gives outsiders a channel to it, and, potentially, to money.
Practical Takeaways for Business Leaders
ZTS Infotech is testing Cue on scoped, low-budget errands first. Nothing that touches a client's real money is in scope until the identity model has been tested for longer than one launch week. That staged approach is a reasonable template for any organisation:
- Start with low-stakes, clearly bounded tasks.
- Set spending budgets before the agent runs, and keep them small.
- Keep client funds and sensitive accounts out of early pilots.
- Review which incoming messages are allowed to trigger an automation.
- Wait for independent testing before relying on vendor performance claims.
Opportunities and Challenges
The opportunity is straightforward: routine errands such as taking calls, placing orders and holding places in line can be delegated to an agent that does not need to borrow a staff member's credentials. The challenges are equally clear. The headline numbers are unverified, the stranger-triggered automation risk is real, and the identity model is brand new.
Expert Perspective
Why this matters. Most AI launches compete on model quality. This one competes on standing. Whether an agent can hold contact details and funds of its own is a question about trust and accountability, and those questions tend to outlast any benchmark race.
Business implications. If agents become participants with their own footprint, finance, security and legal teams will need a say alongside technology teams. Policies written for tools that borrow a human's login will not map neatly onto software that has its own phone number and wallet.
Future outlook. This is analysis, not reporting: expect other agent platforms to be asked whether they will follow. The more useful test will be how identity layers like Cue behave after the launch week, under real use and real attempts at abuse. Until that evidence exists, caution is not pessimism. It is good procurement.
Key Takeaways
- Manus launched version 2.0 on September 28, 2026, calling it a new architecture, Cascade, rather than a routine update.
- Cue gives an AI agent its own email address, phone number and wallet, separate from the user's.
- Examples include answering calls with a summary, ordering via restaurant QR codes and spending within a preset budget.
- Manus reports 23.2% fewer tokens, 28.2% faster tasks and 32% lower cost; none is independently verified.
- Automations triggered by incoming messages let strangers influence agent decisions, widening the attack surface.
- ZTS Infotech is piloting Cue on scoped, low-budget errands before any client money is involved.
What Comes Next
Manus 2.0 marks a change in what an AI agent is allowed to be. Whether that proves a durable advantage will depend on independent testing and on how well the security risks are managed. Business leaders should keep following verified reporting as that evidence arrives, and test cautiously in the meantime.
-
Writen by Anirban
USA:
India: