Quick Answer:
Manus 2.0 (launched 28 September 2026) is a new agent architecture called Cascade plus a desktop Studio, and Cue is a separate personal-agent app where each agent gets its own email address, phone number, wallet and computer. Cue is free in early access by invite code. Manus claims Cascade uses 23.2% fewer tokens, finishes 28.2% faster and costs 32% less, but that is an unverified vendor self-test.
For most of the past two years, an AI agent has been something that borrows your accounts: your browser, your inbox, your card. Manus 2.0 flips that arrangement. In Cue, the new personal-agent app that launched alongside it, every agent is given an identity of its own, complete with an email address, a phone number, a wallet with a budget you set, and a computer to work on.
That is a bigger conceptual step than a version number suggests, and it lands the same week as Claude Sonnet 5.5, OpenAI's DevDay and Antigravity's plan review. Here is what Manus actually announced, what is verified and what is not, where the security risks sit, and how it compares with the agent tools we already track.
AI Revolution X covers Manus 2.0 and Cue alongside Claude Sonnet 5.5 and Tencent's AI companion.
Executive Summary
Manus 2.0 is described by Manus itself as "not a version update" but "a new architecture, new products, and new capabilities" (The Next Web). It has three parts: Cascade, an in-house orchestration layer that Manus calls its agent harness; Studio, a desktop workspace for documents, spreadsheets, slides, websites, code, games and video; and Cue, a standalone app for personal agents.
The headline idea is agent identity. In Cue, each agent has its own email address, phone number, wallet and computer. Agents can send messages, pay for things within a budget you set, take your phone calls and leave a summary in the app, and several agents can work in a group chat and delegate to one another. Cue is free during early access, needs an invite code, and runs on web, desktop and mobile, with iOS awaiting App Store review.
- Best for: early adopters who already delegate research, admin and scheduling to agents and want to test giving them a separate identity rather than sharing their own.
- Headline claim: Cascade uses 23.2% fewer tokens, takes 28.2% less time and costs 32% less than the previous system, per Manus.
- Main caveat: that figure comes from a vendor test with an undisclosed methodology, and no independent verification exists yet.
- Biggest risk: wallets plus prompt injection. A September 2026 disclosure showed agents that read external content can be steered by hidden instructions.
- Pricing: Cue is free in early access; Manus has not published plans or per-plan features for 2.0 or the Cloud Computer.
What Manus Launched
Manus published three announcements in one go: Manus 2.0, the Cue app and the Cascade architecture beneath them. Reports date the launch to Monday 28 September 2026 (Implicator), with The Next Web publishing on 29 September. The company describes the release as a rebuild, not an incremental update.

The product line-up shown in Manus's launch graphic includes three model tiers (Manus 2.0 Max, Manus 2.0 and Manus 2.0 Lite), an Automation feature that triggers work when something happens, a video editor, game development, a Cloud Computer, remote control from a phone, a "Create in studio" workspace and the Cue app on iOS and Android. Not every one of those has full public documentation yet, so treat the graphic as a feature list rather than a specification.
Cascade: the new orchestration layer
Cascade is Manus's name for the harness that plans a task, splits it between agents and tools, and keeps context under control. Manus reports that in one tested setup Cascade used 23.2% fewer tokens, finished tasks 28.2% faster and cost 32% less to run than the previous system. Two independent write-ups make the same point about those numbers: they come from a vendor self-test, the methodology is not disclosed, and results will depend on your workload (BazaarLink). They are a reason to try it on your own tasks, not a benchmark to quote.
Studio: professional environments on the desktop
Studio is the desktop app for producing finished artefacts: documents, spreadsheets, slides, websites, code, games and video. Two environments are new. The Video Editor works on 30 to 60 second pieces with a timeline and an AI creative-director mode, and appears labelled "Alchemy" in the launch graphic. Game Dev builds multiplayer games that can be published as websites, using the Cloud Computer to host them. Remote Control lets you manage your desktop from your phone and watch what the agent is doing live.
Automations and the Cloud Computer
Automations start a task when something happens in a connected service, such as a new email, a Slack message, a calendar event or a Notion change. The launch graphic's example is an email arriving with a monthly spending PDF, which triggers Manus to produce a spending review document. The Cloud Computer is a dedicated, always-on environment for persistent work such as servers and permanent automations. It can be bought, but pricing is not listed (BazaarLink).
Cue: Agents With Their Own Identity
Cue is where the launch gets genuinely new. It is a standalone app, separate from the main Manus product, built around the idea that a personal agent should not impersonate you. Each agent gets its own email address, phone number, wallet and computer.
In practice that means an agent can send and receive messages under its own address, spend money up to a budget you define, answer calls on your behalf and leave you a summary in the app, and work alongside other agents in a group chat, handing tasks between them. Manus's pitch, echoed in coverage, is that agents start to look "much closer to digital people" than to chatbots.
- Access: early access, free, with an invite code. Reports mention a first-come, first-served code circulating at launch.
- Platforms: web, desktop and mobile, with iOS following App Store review.
- Multi-agent: specialised agents can run in parallel and message each other.
- Money: agents pay within a user-set budget. The payment network, confirmation flow and refund process are not documented in detail yet.
The design has a clear logic. Giving an agent your own email and card means every mistake is attributed to you and every compromise reaches everything you own. A separate identity with a capped wallet limits the blast radius, and lets you revoke one agent without rotating your own credentials. That is a sound instinct, and it is the most interesting idea in the launch.
It also raises the questions that make this launch harder to assess than a model release. Who is legally responsible when an agent with its own phone number makes a call that goes wrong? How do you prove to a bank, a supplier or a website that a wallet belongs to an agent acting for you? Manus has not yet published answers, and early access is the right stage to ask.
Why the Timing Matters: Meta, Tencent and Funding
Manus is a company whose ownership story changed several times in a year, and that context shapes how to read this launch. According to The Next Web, Meta agreed to acquire Manus for around $2 billion (roughly £1.5 billion) in late 2025, and Beijing blocked the deal in April 2026. After the block, Manus separated from Meta and said it would build a team for the Chinese market.
Implicator adds that Tencent has become Manus's largest external investor, and that the company is negotiating a $500 million (roughly £370 million) funding round at a $4 billion (roughly £3 billion) valuation, double Meta's original price. That round is reported as unsigned, so it should be read as a negotiating position rather than a fact.
One point needs care. Our earlier coverage of Manus Plan Mode reported, from Manus's own July blog, that the company had confirmed it joined Meta. The September reporting says the deal was blocked and the companies split. We are flagging the discrepancy rather than picking a winner: check Manus's own statements before relying on either description of its ownership.
For readers, the practical point is that Manus is now shipping as an independent company competing directly with the big labs and with Meta's own agent. Meta's Muse agent is reported to have topped app-store charts, and foundation-model vendors are increasingly folding similar desktop tasks into their own products. A launch that gives agents phone numbers and wallets is, in part, a bid for a category that is not yet crowded.
Security, Payments and Prompt Injection
Giving an agent money and a phone line is exactly the situation in which prompt injection stops being a curiosity. Two disclosures are relevant. Salt Labs reported a prompt-injection vulnerability that allowed code execution inside Manus environments, which Implicator says was patched through Meta's bug-bounty programme. Separately, a September 2026 disclosure showed that agents reading external content, including email, could be exploited through hidden instructions (BazaarLink).
Cue's architecture makes those risks more visible, not less, because an agent with its own inbox will inevitably read untrusted messages. A budget cap helps, but a cap is only as good as the way it is enforced. Before you trust any agent wallet, look for four things: a hard per-transaction and per-day limit, a human confirmation step above a threshold, an itemised log you can audit, and a clear way to freeze the wallet.
- Keep budgets small while the payment mechanics are undocumented.
- Do not connect sensitive inboxes to Automations with broad triggers; scope each trigger tightly.
- Watch for duplicated work and runaway cost: an unscoped Automation can fire repeatedly and burn credits.
- Separate identities are only protective if the agent's accounts are genuinely isolated from yours.
The wider pattern is familiar from our coverage of Hermes Agent, whose safety work centres on command-level review, and from the agent-safety discussion in OpenAI's Dots agents. Identity and spending limits are a different layer of control, and the industry is still working out which layers are mandatory.
Real-World Use vs the Announcement
It is early, and the honest position is that nobody outside Manus has published a rigorous evaluation. Independent coverage of the launch is largely descriptive. What can be said sensibly is where each piece is likely to help, and where it needs proof.
- Cascade efficiency: plausible in direction, since orchestration improvements often cut wasted tokens, but the 32% cost figure is unaudited. Re-run a representative task before and after and compare your own credit use.
- Cue agents: useful for errands that already fit a message-and-pay pattern, such as booking, chasing invoices or ordering. Unproven for anything requiring judgement about money.
- Automations: the most immediately practical feature. Trigger-based work on email, Slack, calendar and Notion is where agents save real time, provided the scope is narrow.
- Studio video and games: short-form only for now, and best judged by output rather than announcement.
A good way to test any of this is to start with a reversible task, cap the budget at a token amount, and review the log after a week. If the log shows the agent behaving predictably, widen the remit. If it does not, you have learned that cheaply.
Pricing and Access
Cue is free during early access with an invite code, on web, desktop and mobile, with iOS pending review. That is all Manus has committed to publicly. It has not published plans, pricing or per-plan feature availability for Manus 2.0, and the Cloud Computer is purchasable at an unlisted price (BazaarLink). Expect a metered, credit-based model like the rest of the agent market, and expect the free tier to end. Until numbers appear, do not build a business process that depends on a specific price.
For comparison, our tracked coding agents and assistants publish their tiers openly; see our comparison of the best AI coding agents and the AI API pricing comparison for where the market currently sits.
Limitations and Open Questions
- Invite-only: you cannot evaluate what you cannot access, and the Cue invite pool is limited.
- Unverified efficiency claims: the Cascade numbers come from Manus alone.
- Undocumented wallet mechanics: payment network, confirmation and refunds are unspecified.
- Legal and identity questions: agent phone numbers and wallets raise consent, fraud and accountability issues that policy has not caught up with.
- Ownership clarity: reports differ on Manus's relationship with Meta, so check current statements.
- Platform gaps: iOS is awaiting review at launch.
None of these are reasons to dismiss the launch. They are the checklist a cautious buyer should hold Manus to over the coming weeks.
How It Compares
Manus is competing on a different axis from the model releases dominating this week. Claude Sonnet 5.5 and GPT-6.1 Sol are about raw capability and cost per token. Manus is about the wrapper: identity, orchestration and persistence around whichever models it runs.
- Versus Gemini Spark: Spark is Google's agent inside its own ecosystem; Cue's differentiator is a standalone identity per agent.
- Versus OpenAI Dots: OpenAI's DevDay agents sit inside ChatGPT; Cue is a separate app with its own wallet model.
- Versus Hermes Agent: Hermes is open-source and self-hosted with a focus on safe command execution; Cue is hosted and consumer-facing.
- Versus Buzz and Tencent Hyra: workspace and research agents that stop short of giving the agent its own money.
- Versus the earlier Manus: see Plan Mode for the checkpoint feature that shipped in July.
The pattern across all of them is that autonomy is being wrapped in more structure: plans, budgets, reviewers and identities. Manus is the first we have seen to make the identity itself the product.
Who Should Use It
- Try it now if you have an invite, run a small business or side project, and want to test agent-run admin with a capped budget.
- Wait if you handle regulated data, client money or anything where an unauthorised payment is unacceptable.
- Ignore for now if you only want the best model for coding or writing; the model launches will serve you better this month.
- Developers should watch how Automations and the Cloud Computer are priced, since that decides whether persistent agents are affordable.
The Bottom Line
Manus 2.0 is less a model story than a trust story. The technical claims (Cascade's 32% cost cut, Studio's video and game tools) are plausible and unverified. The conceptual claim, that an agent should have its own identity, inbox, phone line and capped wallet rather than borrowing yours, is the part worth paying attention to, because it is a safer starting design than sharing your own credentials.
Whether it works depends on things Manus has not yet shown: enforceable spending controls, clear accountability, resistance to prompt injection and an honest price. If you have an invite, try it with small stakes. If you do not, watch the next few weeks for independent tests of Cascade and for the pricing page, and compare against the agent tools already in this guide. We will update this article as those arrive.
Last updated: 30/09/2026. Sourced from The Next Web, Implicator and BazaarLink coverage of the Manus 2.0 and Cue launch, and Manus's launch graphic. Figures marked as vendor claims are unverified.
Get the free guide: Claude vs ChatGPT, Gemini & Grok
A 20-page playbook covering everything you need to choose and use the big four AI models in 2026, full cost and feature comparisons, what each is best (and worst) at, and how-tos for images, vectors, building a website, Claude Code and more.






