DISPATCH · 28 SEP 2026

Agent readiness in 2026 so far: the announcements, layer by layer

Fourteen dated announcements from February to September 2026, regrouped by the part of the stack they change.


Agent Readiness Compare editors · Spec status checked September 2026

Agent Readiness Compare editors · · 6 min read

Answer

This recap covers the 14 announcements on our news page, from 12 February to 25 September 2026. The act layer moved most: MCP became stateless, A2A reached v1.0.0 and joined the Agentic AI Foundation, and Cloudflare previewed WebMCP at the edge. Reading gained llms.txt v2 and Cloudflare's Markdown for Agents, trust gained automatic Web Bot Auth checks, and payment gained x402 batch settlement.

On this page
  1. 1. What does this recap cover?
  2. 2. What changed for discovery?
  3. 3. What changed for reading?
  4. 4. What changed for acting?
  5. 5. What changed for payment and trust?
  6. 6. What did the testing tools ship?
  7. 7. What else happened around the stack?
  8. 8. What should a web team do with this?
  9. 9. Sources

1.What does this recap cover?

Our news page lists 14 announcements from 12 February to 25 September 2026, each dated and linked to its source. This dispatch regroups them by the layer of the readiness stack they affect, so a team can see which part of its site each change touches. Five concern the act layer, two the read layer, and one each the discover, pay and trust layers. Three are releases from ora.ai, which tests readiness, and one is a Vercel report on agent skills. ora.ai is a client of the agency that publishes this site; its items are listed on the same terms as everyone else's.

2.What changed for discovery?

On 15 September Cloudflare added a "Disallow AI Training" setting that uses robots.txt Disallow rules to block AI training while keeping a site discoverable in search, together with an "Accountable" designation for crawler operators that meet stated opt-out and reporting requirements. For site owners on Cloudflare, training and search can now be separated with one setting rather than by maintaining user agent groups by hand. robots.txt itself did not change: RFC 9309 still describes rules that "are not a form of access authorization".

3.What changed for reading?

Two items. On 12 February Cloudflare launched Markdown for Agents in beta: when a client sends Accept: text/markdown, Cloudflare converts the HTML to markdown at the edge and adds an x-markdown-tokens header, at no cost on Pro, Business and Enterprise plans and SSL for SaaS. On 10 August the llms.txt proposal was revised to v2, adding link relations so a page can point to its markdown version and to the llms.txt that covers it, accepting both page.html.md and page.md URL forms, and defining what a subpath file covers.

The two fit together: markdown versions of pages are what the new link relations point to. See llms.txt v2: what changed.

4.What changed for acting?

Most of the year's movement was here.

  • 12 March: A2A v1.0.0 updated OAuth 2.0 flows (device code and PKCE added, implicit and password grants removed), added a tasks/list method and simplified the message Part structure. v1.0.1 followed on 28 May.
  • 28 July: the MCP 2026-07-28 specification made the protocol stateless, removing the initialize handshake and session IDs, and deprecated Dynamic Client Registration. See the MCP 2026-07-28 specification explained.
  • 6 August: Cloudflare opened a developer preview of WebMCP at the edge, injecting a bridge script that registers tool packs for browser agents with no origin code change.
  • 22 August: the MCP maintainers published a roadmap with five priorities, including HTTP-native transport and agent identity.
  • 27 August: A2A joined the Agentic AI Foundation, which the project describes as Linux Foundation-directed and home to sibling projects including MCP, goose and AGENTS.md.

For a site that runs an MCP server, the July specification is the item that needs action. The others change governance or add options.

5.What changed for payment and trust?

On 11 May the x402 project introduced batch settlement, which it says lets agents transact at low latency and fractions of a cent using cryptographic vouchers redeemed onchain in bulk. On 28 August Cloudflare moved bot submissions to a BotBase dashboard for operators, with review status and automatic validation of verification methods, including Web Bot Auth signatures.

Neither changes what most sites must do. BotBase matters to anyone who operates an agent and wants it verified; see Web Bot Auth in 2026.

6.What did the testing tools ship?

ora.ai published v1.0.0 of AgentReady, its MIT-licensed specification of what to implement, on 24 April. On 7 July it released Deep Scan v2, which it says derives its checklist from agents run on real tasks and separates Verified signals from Emerging ones. On 20 August it launched is-agentic.com with Vercel, with every scan run by ora.ai. Cloudflare's Is It Agent Ready remains a public scan page. We compare the two scanners on the method page and in the scanner calculator.

7.What else happened around the stack?

On 25 September Vercel published a report on agent skills, which it defines as reusable instructions that give an agent the context for a particular job. It said the skills.sh registry reached one million skills and nearly 280 million installs in seven months. Skills sit on the agent's side rather than the website's, but they shape how agents approach the tasks they attempt on sites.

8.What should a web team do with this?

  1. If you run an MCP server, plan the move to the 2026-07-28 specification.
  2. If you publish markdown versions of pages, add the llms.txt v2 link relations.
  3. If you are on Cloudflare, review the AI training setting and the default content-signal header against your written policy.
  4. If you operate an agent, check how it is verified under BotBase.

Each maps to a check in the checklist.

9.Sources

Reviewed Sep 2026