Five arcs, one split: frameworks still define the agent. Runtimes decide whether it is still there in the morning.
August asked one question for thirty-one days: does the agent keep running after you close the terminal? I already knew the polite answer. A demo survives a meeting. A runtime survives a crash, a credential rotation, and a weekend with nobody watching the process. The month was not about discovering that distinction. It was about watching the field keep selling definition tools as if they were operators.
The opening arc made the boundary expensive. A framework gives you nodes, roles, and a launch method. LangGraph will checkpoint a graph to SQLite or Postgres. CrewAI Flows will persist a Pydantic state object across kickoff(). AutoGen will still show a crowd for a tree whose last feature tag is from September 30, 2025, with a last push on April 15, 2026. None of that owns the loop after the worker dies. Hermes Agent and OpenClaw do. Hermes, tagged v2026.8.27 as v0.20.6 on August 27, treats skills as accumulated procedure with trust scores, durable sessions, and a delivery-obligation ledger so a finished answer cannot vanish between generation and send. OpenClaw treats every message, cron tick, webhook, and heartbeat as an event on one gateway, which is why channel adapters are the product and why the repo sat at 388,041 stars by yesterday’s scorecard. Restate sits next to both as the primitive most homemade loops skip: resume from the last completed step, not from the prompt. The CASE that closed the week was a loop, not a library: event queue, context assembly, tool discovery, model call, action dispatch, checkpoint. Skip the last box and you have a launch script.
The 98.4 percent finding from MBZUAI kept returning because it is the same sentence in a lab coat. Four independent agents reverse-engineered Claude Code and found 98.4 percent harness: permissions, context, sandboxing, tool routing, recovery. 1.6 percent decision logic. The industry still spends its attention in the inverse ratio. That is not a model problem. That is a budget problem wearing a research paper.
The desktop arc moved the same argument onto a machine you own. A cloud session resets. A desktop agent accumulates. Goose, Block’s open-source companion, and BeeAI Desktop, the Linux Foundation’s interop bet, are not competing chat apps. They are bets that the agent’s state belongs next to your files, your credentials, and your cron. The privacy case is real, and it is the weaker one. The compounding case is the one that changes the architecture: skills, memory, and tool paths that survive the night. Inference can live anywhere. State that wipes every morning is a product that cannot get better. Claude Code remains the reference harness, not because Anthropic invented agents, but because most of the product is the part vendors keep calling plumbing. The personal stack CASE at mid-month was the same loop as week one, with the process pinned to your hardware. Call the model wherever you want. Keep the context at home.
The multi-agent week was the week teams add a second agent and call it architecture. Supervisor works: one dispatcher, specialists with schemas, no debate. Blackboard works: agents write a structured workspace, not a transcript. Hierarchical works when the work is actually a tree, a FOIA fan-out across departments, not a single clinical judgment wearing extra titles. Swarm photographs well and produces invoices. CrewAI still wins the role-based demo, and Flows is the control plane that makes those roles replayable. Microsoft Agent Framework productized handoff, sequential, concurrent, GroupChat, and Magentic; GroupChat stays off a case file. DSPy 3.3 treated coordination as a compiler problem, which is the honest version of “the prompt is not the architecture.” The TAKE that earned the week was the refusal. Multi-agent is the wrong answer when the work does not split. Token inflation with extra names is not a pattern. It is a meeting.
The middleware week left the loop and asked how the agent touches a system you did not write. MCP is the USB-C of that question, and the July 28 spec made it small on purpose: no session, no handshake, one HTTP call, a schema. Composio is the registry bet. Strands Agents SDK is AWS’s quiet layer for the same job, framework-agnostic even when Bedrock is in the room. OpenConnector is the enterprise objection: not whether the agent can find the tool, but whether it should, and whether you can prove it. Authentication is still the hole. Catalogs discover. Hooks decide whether a call fires. Neither one can tell you who the agent is when the request leaves the process. Friday’s roundup made that concrete. The MCP roadmap named workload identity and token exchange as a spec gap, not a vendor feature. Patrick Walsh at IronCore Labs showed OpenClaw’s spotlighting tags dying at memory promotion, so an email that failed as an injection succeeded as a MEMORY.md fact. NVD scored a 10.0 against an MCP HTTP server that bound :: with auth off. USB-C with the port open and the lock optional is a LAN shell.
Yesterday’s scorecard was the decision rule, not a ranking. If the agent is the long-lived worker, pick a runtime. Hermes when that worker should get better. OpenClaw when it has to exist on the channels your users already live in, and you can live with a stable tag that lags a hot beta. If the workflow is the product, pick a framework and operate it yourself. LangGraph when the topology is a graph you must checkpoint and interrupt. CrewAI Flows when the team thinks in roles and the path has to replay for an auditor. Microsoft Agent Framework when procurement and Azure identity are the door. AutoGen is not on the list for new work. Saturday’s mixed path still holds: runtime at the edge for judgment and continuity, a service you own for authority. Flexibility is a clean ownership line, not a fear of dependencies.
Put the five arcs side by side and the month is a bifurcation, not a feature matrix. Frameworks define what the agent is. Runtimes determine whether it is still there after the process dies, the credential rotates, and the model call fails on step thirty-seven. The tools that will still matter in a year treat persistence, recovery, and skill accumulation as the product. The tools that will not treat those as an exercise for the reader. Star counts will keep lying. OpenClaw out-stars Hermes. AutoGen out-stars Agent Framework by more than four to one. The living tree is the one still tagging releases and still arguing about delivery after a gateway crash.
The surprise of the month was not a new runtime. It was how fast the scarce layer moved from discovery to identity. MCP can find the tool. Composio can catalog it. The call still leaves the process as an anonymous bearer token, and the memory file still swallows untrusted text once the spotlighting tags fall off. Persistence without provenance is how a runtime becomes an attack surface.
Hermes without skill review is drift with a flattering name. OpenClaw with business rules in MEMORY.md is a system of record you cannot replay. A graph you never made idempotent is a double email at 2:13 a.m. The month did not pick a winner. It named the failure each choice buys.
September goes one layer down. The runtime still depends on the model sitting under it, and “the model” is no longer a single resident blob in VRAM. Loading is not success. Usable latency and preserved quality are. VRAM, system RAM, unified memory, PCIe, and NVMe are different tiers, not one interchangeable number. Dense weights, routed experts, KV cache, and activations do not all need the same pool at the same time. A screenshot of a loaded model is not a workflow. llama.cpp remains the boring baseline every exotic claim has to beat. The model does not have to fit. The working set does.
August’s question was whether the agent survives the terminal. September’s question is whether the box you already own can make the model underneath that agent useful. The gap between those two questions is where the next thirty days of this field get decided.
If this was useful, forward it to one engineer who needs less noise in their feed.


