AI Tools Review
Cohere North 2: Enterprise Agent Platform Explained

Insights

Cohere North 2: Enterprise Agent Platform Explained

AI Tools Review Editorial Team10 October 2026

    Quick Answer:

    Cohere North 2, announced on 05/10/2026, is a rebuilt version of Cohere's enterprise AI agent platform. It adds a redesigned orchestration harness, memory that persists across sessions, reusable skills and shared libraries, and a North Admin console with token quotas, spending caps and alerts. It runs in the cloud, in a VPC, on-premises or fully air-gapped, works with models from outside Cohere, and has no published price. The main open question is memory: Cohere has not published retention or deletion terms for it.

    Enterprise AI agents have a different problem to consumer ones. Nobody in a bank or a telecoms company worries about whether an agent can write a witty email; they worry about who can see its memory, how much it will spend overnight and whether it can be tricked into leaking a customer file. Cohere's North 2 is built around those worries.

    This guide is based on trade coverage of the 05/10/2026 launch, including SiliconANGLE, Unite.AI and an independent analysis from Beri.net, together with creator coverage on YouTube. We could not find a technical specification or published price, so where the launch material is silent we say so rather than guess.

    Julian Goldie walks through North 2's agent harness, skills, memory, connectors, enterprise security and usage limits (chapters from 01:06 to 06:29).

    Executive Summary

    What it is: North 2 is the upgrade to North, which Cohere made generally available on 06/08/2025. Cohere describes a platform for building, sharing and governing AI agents inside large organisations, with the harness (the orchestration layer that plans and runs multi-step work) rebuilt for autonomy with human sign-off at critical points.

    • Harness: runs multi-step tasks autonomously and brings in a person only for steps that need approval.
    • Memory: each agent retains context between sessions, and Cohere says memory lets context persist across sub-sessions and agents.
    • Building blocks: skills (reusable logic), libraries (shared documents and assets), applications (decks, dashboards, documents and lightweight apps from natural language) and automations (templates and a drag-and-drop workflow builder with real-time monitoring).
    • Governance: North Admin tracks token use per user and per agent, sets consumption tiers, caps usage organisation-wide and alerts before limits are hit.
    • Security: per-agent guardrails for personal data and prompt injection, autonomy policies, and SOC 2 Type 2, ISO 27001 and ISO 42001 certifications as cited by Cohere.
    • Deployment: cloud, VPC, hybrid, on-premises or fully air-gapped; model-agnostic.
    • Not stated: price, memory retention and deletion terms, and independent benchmarks.

    Our view: North 2 is an enterprise-governance story rather than a model story. Spending caps, permissions and air-gapped deployment are what separate a pilot from something a risk committee will sign off, and Cohere has put them at the centre. The memory feature is the part that needs hard questions before it is enabled.

    Where North 2 Fits

    Cohere, the Canadian enterprise-focused AI company, has positioned itself against the consumer-first labs by selling to organisations that need control over where their data and models live. North 2 is the product expression of that strategy. It lands in a crowded market: OpenAI's agents API and cloud agents, Anthropic's enterprise tooling (see our piece on Claude enterprise inference hooks), Google's Gemini Workspace agentic features and a long tail of workplace agents such as QwenWork.

    What distinguishes Cohere's pitch is that the platform is meant to be model-agnostic and deployable behind a customer's own firewall. In an era when many enterprises will not send regulated data to a public API, that matters. For a broader view of where workplace agents are heading, see The Agentic Future of Work.

    The Redesigned Agent Harness

    "Harness" is the industry word for the software around a model that plans tasks, calls tools, manages context and decides when to stop. The same idea has become central in coding agents, as our coverage of the DeepSeek Harness and Hermes Agent shows. Cohere's version is built for business tasks rather than code.

    According to Unite.AI, North 2's orchestration system handles multi-step tasks while keeping humans in the loop. Users can create agents and automations from a simple prompt, share them across the organisation and prototype documents or apps in the chat window. The practical effect is that a team member can describe a recurring job, such as preparing a briefing before a founder call (an example Radical Ventures built, according to SiliconANGLE), and publish it for colleagues instead of filing an IT ticket.

    The key design decision is the approval model. Cohere says autonomy policies restrict each agent to its authorised actions and require human sign-off on critical decisions. That is the pattern regulators and auditors expect: autonomy for routine steps, a person for the consequential ones. What we cannot tell from the launch material is how granular these policies are, for example whether approval can be set per tool, per data source or per dollar amount.

    Skills, Libraries, Applications and Automations

    Unite.AI groups the new capabilities into four areas:

    • Skills: reusable agent capabilities that package logic an agent calls repeatedly, so teams do not rebuild the same procedure for each agent.
    • Libraries: shared organisational knowledge and assets, a central store of documents that all agents can reach.
    • Applications: generating slide decks, dashboards, documents and lightweight apps from natural-language requests.
    • Automations: prebuilt templates and a drag-and-drop workflow builder, with real-time performance reporting.

    The skills concept mirrors a pattern now common across the industry, where agent behaviour is packaged as reusable instructions rather than rewritten each time. We covered the consumer-side version of that idea in our piece on Gemini Skills. The enterprise twist is shared libraries: a single governed source of truth that agents draw on, which is also a single place to apply access controls.

    Memory: The Headline Feature and Its Open Questions

    Memory is the feature most likely to change how North 2 feels to use. Cohere says agents now retain context between sessions rather than starting from scratch each time, and Paul Teyssier, Cohere's VP of Product AI, said memory lets context persist longer across sub-sessions and agents. For a recurring task such as weekly reporting, that is a large usability gain. Our coverage of Claude memory shows the same trend on the consumer side.

    The independent analysis from Beri.net is the most useful counterpoint. Its central observation is that Cohere has published no scope, retention or deletion terms for North 2 memory: the launch post names no storage location, retention period, deletion mechanism or memory-specific admin control. That has three consequences for a buyer:

    • Data protection. Under GDPR Article 17, erasure is due without undue delay, so an organisation needs to know where memory lives and how to delete one person's data.
    • Security. Beri.net cites a 2026 paper called MemGhost that reported an 87.5% success rate for planting persistent memory against OpenClaw running GPT-5.4 in background mode, and says input filters missed it nine times in ten. We have not verified that paper; it is reported here as Beri.net's citation. Because North 2 connects to Outlook and Exchange, inbound email is a plausible attack path. Our AI agent security coverage describes related risks, and OpenClaw 2.0 shows how persistent agents expand the attack surface.
    • Audit. Beri.net notes that comparable memory features in other vendors' products have had their own audit gaps, so it is worth asking what logging exists.

    None of this means North 2 memory is unsafe. It means the launch material does not let you judge. Until Cohere answers in writing, the cautious option is to leave memory off for sensitive workloads or restrict it to low-risk agents.

    North Admin: Spend, Permissions and Monitoring

    The least glamorous part of North 2 may be the most commercially important. According to SiliconANGLE, North Admin tracks token consumption by individual user and agent, lets administrators set consumption tiers for users and groups based on request and token rates, caps usage company-wide and sends alerts before limits are reached. Unite.AI adds role and permission settings, model access control by location and user, real-time activity monitoring and the option to swap in an organisation's own models. VentureBeat, quoted by Beri.net, reports that usage tracking breaks down by model, user and department.

    Why this matters: agent loops can spend tokens quickly, and an autonomous agent that gets stuck can burn through a budget overnight. Spending caps turn an unbounded cost into a bounded one. On self-hosted deployments, Beri.net notes, caps act more as capacity allocation than as billing, limiting runaway loops. Its practical advice is to set caps per agent rather than only per user, because a single user may own several agents.

    Cohere also ties efficiency to its partnership with NVIDIA, saying its models produce more tokens per second per node on Blackwell and Hopper GPUs. Kari Briski, NVIDIA's VP of generative AI, said North 2 helps "deliver more tokens for less". These are partner claims without published numbers, so treat them as direction rather than evidence.

    Security, Compliance and Deployment

    Cohere lists SOC 2 Type 2, ISO 27001 and ISO 42001 (the AI management system standard). Per-agent guardrails cover content filtering, safety and response validation, with screening for personally identifiable information in prompts and responses and for prompt injection attempts. Cohere also describes continual testing, including red-teaming and third-party vulnerability scans, as well as observability and change logging. Bell Cyber, the security arm of Bell Canada, is named as a partner on the security side, and its chief technology and AI officer, Jawed Ahmad, said North supports the control and sovereignty requirements "built in from the start".

    Deployment is the strongest differentiator. North 2 can run on-premises, in the customer's own virtual private cloud, in hybrid setups or fully air-gapped, and the original North could run on as few as two GPUs when it launched. For defence, public-sector, healthcare and financial customers that cannot send data to a shared cloud, air-gapped support is a deciding factor rather than a nice-to-have. We would still ask to see the guardrail evaluation data: "screens for prompt injection" is a claim, not a measured detection rate.

    Connectors and Integrations

    Connectors listed at launch include Slack, GitHub, Microsoft SharePoint and OneDrive, with Unite.AI also naming Outlook, Exchange, Jira, Linear and Notion. Planned financial data connectors include PitchBook, S&P Global and FactSet, and Unite.AI adds Crunchbase, Daloopa and FiscalAI. The finance focus is deliberate: market data and filings are exactly the sort of governed content that benefits from an air-gapped agent.

    As with memory, connectors widen the attack surface. Each connector is a path for untrusted content (an email, a ticket, a shared document) to reach the agent, so connector permissions and per-agent scoping matter as much as the model.

    Customers and the Aleph Alpha Merger

    SiliconANGLE names Bell Canada's Bell Cyber, which uses North in security operations, LG CNS, which runs North internally and offers it to customers in South Korea, and Radical Ventures, which built an automation for founder-call briefings. Unite.AI lists earlier North users including RBC, Dell, stc, Ensemble Health Partners and Second Front, and says rollouts span finance, healthcare, telecommunications, manufacturing, energy and the public sector. Yohan Jin, head of AI Center at LG CNS, said North gives enterprises a secure, practical foundation for turning agentic AI into real business value. These are vendor-supplied customer statements.

    The corporate backdrop is notable. North 2 arrived less than three weeks after Cohere agreed to merge with Germany's Aleph Alpha (a merger agreement dated 16/09/2026, still subject to regulatory clearance), with the combined company keeping the Cohere name. Beri.net reports a combined valuation of about $20 billion, up from $7 billion for Cohere in September 2025. A European sovereignty angle fits an air-gapped, model-agnostic platform neatly, but the integration of two companies and product lines is a risk for customers planning multi-year rollouts.

    Pricing and Availability

    There is no public price. Cohere told VentureBeat that pricing is based on the scale and complexity of a customer's deployment, and prospective customers are directed to book a demo with the sales team. That is normal for enterprise software but means we cannot compare North 2 on cost with other agent platforms. The token spending tools suggest consumption-based elements, though the launch material does not confirm the commercial model.

    How It Compares

    • Versus hyperscaler agent platforms: Cohere's edge is deployment flexibility, including air-gapped installs, and model-agnosticism. The hyperscalers have broader ecosystems and often clearer public pricing.
    • Versus frontier-lab enterprise tools: OpenAI and Anthropic have stronger frontier models; Cohere's case is control and sovereignty. See OpenAI's agents API and Claude enterprise hooks.
    • Versus open-source agent stacks: build-your-own routes like OpenClaw 2.0 or Hermes Agent are cheaper and more flexible, but you own the governance, spend controls and compliance work that North 2 sells.
    • Versus workplace suites: Gemini in Workspace is tied to Google's ecosystem; North 2 is neutral across Microsoft and other tools.

    A Buyer's Checklist

    If you are evaluating North 2, these are the questions we would put to Cohere, drawing on the gaps above and the recommendations in Beri.net's analysis:

    1. Where is memory stored, what is the default retention, and can it be scoped per agent, per user and per tenant?
    2. How is one person's data deleted from memory, and can your data protection officer test it with a mock erasure request?
    3. Is there audit logging of memory writes, and who can read it?
    4. What measured detection rates do the prompt-injection guardrails achieve, and has memory poisoning through email and documents been red-teamed?
    5. Can spending caps be set per agent as well as per user, and what happens when a cap is hit mid-task?
    6. Can autonomy and approval policies be set per tool and per action?
    7. What is the pricing model, and does it include unit prices for tokens or seats?
    8. How will the Aleph Alpha merger affect the roadmap, support and data residency?

    Limitations

    • Launch-material evidence only. We found no independent benchmarks or hands-on reviews of North 2.
    • Memory terms unpublished. Retention, scope and deletion are not stated.
    • No public pricing.
    • Unquantified efficiency claims. The NVIDIA performance statements come without numbers.
    • Merger uncertainty. The Aleph Alpha deal still needs regulatory clearance.
    • Connector risk. Wider integrations widen exposure to prompt injection.

    Who Should Use It

    Consider North 2 if you are a large organisation in a regulated sector, need agents behind your own firewall or fully air-gapped, want to mix models from several providers, or need token governance across hundreds of users. Look elsewhere if you are a small team that wants a quick, cheap agent, need published pricing, or want the strongest frontier model without much governance overhead. Pilot carefully if you plan to turn on memory and connect it to email or document stores before Cohere has published retention and deletion terms.

    The Bottom Line

    North 2 is a serious attempt to answer the question enterprises actually ask about AI agents: not "is it clever?" but "can we control it?". Spending caps, per-agent guardrails, human sign-off and air-gapped deployment are the right ingredients, and the model-agnostic design avoids lock-in to one provider. The weak points are the ones the launch material skips: memory retention and deletion, measured guardrail performance and price. Ask for those in writing, run a limited pilot with memory off, and expect clearer answers as customers push on them. We will update this article if Cohere publishes memory terms or pricing.

    Sources

    Image: Cohere, as published by SiliconANGLE, used for review and commentary with credit.

    Last updated: 10/10/2026. Sourced from trade coverage of Cohere's launch. We have not tested North 2; features, certifications and customer statements are as reported by Cohere and the cited outlets.

    Free Guide

    Get the free guide: Claude vs ChatGPT, Gemini & Grok

    A 20-page playbook covering everything you need to choose and use the big four AI models in 2026, full cost and feature comparisons, what each is best (and worst) at, and how-tos for images, vectors, building a website, Claude Code and more.

    Pop your email in to get it free
    Preview of the free guide: Claude vs ChatGPT, Gemini and Grok, 2026 features, pricing and what-you-can-do comparison.

    Frequently Asked Questions

    What is Cohere North 2?
    North 2 is the second generation of Cohere's enterprise AI agent platform, announced on 05/10/2026. It adds a redesigned orchestration harness, memory that persists across sessions, reusable skills, shared libraries, generation of decks, dashboards and lightweight apps, a drag-and-drop workflow builder and a North Admin console for spending and permissions. It can run in the cloud, in a customer's VPC, on-premises or fully air-gapped.
    How much does Cohere North 2 cost?
    Cohere has not published a price. It told VentureBeat that pricing is based on the scale and complexity of a customer's deployment, and interested organisations are directed to book a demo with its sales team.
    What controls does North 2 give administrators over AI spend?
    North Admin tracks token use per user and per agent, lets administrators set consumption tiers based on request and token rates for users and groups, caps usage organisation-wide, and sends alerts before limits are reached. Access can also be controlled by role, model, location and user, and administrators can assign models from outside Cohere.
    Does North 2 have security and compliance certifications?
    Cohere cites SOC 2 Type 2, ISO 27001 and ISO 42001. Agents get per-agent guardrails, including screening for personally identifiable information and prompt injection, and autonomy policies that restrict each agent to its authorised actions and require human sign-off on critical decisions.
    What are the concerns about North 2's memory feature?
    Independent analysis notes that Cohere's launch material does not state where memory is stored, how long it is retained, how it is scoped or how one person's data can be deleted. That matters for GDPR erasure duties and for prompt-injection attacks that plant persistent memory. Buyers should get written answers before switching it on.

    Explore more AI tool comparisons

    In-depth reviews, benchmarks and guides to help you choose the right AI tools.

    Browse all reviews
    AI Tools Review Editorial Team

    AI Tools Review Editorial Team Expert verified

    Our editorial team consists of veteran AI researchers, software engineers, and industry analysts. We spend hundreds of hours benchmarking frontier models natively to provide you with objective, actionable intelligence on agentic AI capabilities and cybersecurity landscapes.