One Month of Routing, Context, Cloud Execution, Agentic Browsing, Performance, Security and Verifiable Work
August was the month Cortex came together as a connected Enterprise AI Control Layer. September was about putting that architecture to work.
Across seven product blogs and nine newsroom announcements, Cortex advanced from coordinating intelligence and maintaining continuity toward something broader: governed execution across models, search, skills, cloud environments, browsers, development workspaces and longer-running workflows.
The month began with three forms of routing designed to connect user intent with the right intelligence, information and expertise. Context compaction strengthened the ability to sustain long-running work. Cortex Cloud introduced durable managed execution. Cortex Discover made the browser itself an agentic work surface. A three-tier inference cache architecture improved the efficiency of repeated work. Static and runtime security extended validation into actual execution. Collections, chat forks and governed workflows created a clearer path from conversation to reviewable results.
September also expanded the security story beyond the product. Pervaziv AI joined OpenAI’s call for collective cyber defense and, later in the month, joined the NVIDIA-founded Open Secure AI Alliance under the Linux Foundation.
Together, these developments reflect the next stage of Cortex.
The Control Layer is no longer only connecting capabilities around AI. It is increasingly coordinating how work is understood, routed, executed, secured, observed and verified.
Expanding the Security Mission Beyond Cortex
September brought two important developments outside the product itself.
On September 8, Pervaziv AI joined OpenAI’s Call for Collective Action on Cyber Defense, supporting an industry effort focused on using advancing AI capabilities to strengthen defenders, address high-impact weaknesses and improve the ability to verify that security fixes actually work.
Later in the month, Pervaziv AI joined the NVIDIA-founded Open Secure AI Alliance, now hosted by the Linux Foundation.
The announcement coincided with NVIDIA’s introduction of its Open Agent Safety Platform, which emphasizes independent runtime monitoring, enforceable policies and security boundaries around increasingly autonomous AI agents.
These initiatives approach AI security from complementary directions.
AI can become an increasingly powerful capability for defenders.
At the same time, increasingly capable AI agents themselves need stronger security, isolation, permissions, monitoring and verification.
That dual responsibility closely reflects how Cortex has evolved: intelligence and execution are useful, but they need controls around what an AI system can access, what it can do, what actually occurred and what evidence supports the result.
Three Routers Connect Intent to the Right Capability
September began with an expansion of the Cortex routing architecture.
Cortex Router had already established a coordinating layer for specialized AI models. The September update extended that idea with Search Router and Skill Router, creating three complementary routing paths.
Model Routing connects a request with the appropriate Cortex intelligence. Search Routing determines when current public information is needed and helps coordinate access to search services. Skill Routing brings focused engineering and security practices into the workflow when specialized expertise is useful.
The distinction matters because modern AI work rarely requires only a model.
A developer investigating a dependency issue may need reasoning from a specialized model, current information about the dependency, and an engineering practice for securely evaluating the change. A security task may require different intelligence, different evidence and different validation than a routine coding question.
The user should not have to orchestrate those layers manually.
The three-router architecture moves that responsibility into Cortex. The user expresses the objective; the Control Layer determines which forms of intelligence, information and expertise should help move the work forward.
That became an important foundation for everything else introduced during September.
Making Long-Running AI Work More Reliable
Routing the right capabilities is only useful if the system can maintain the right context as work grows.
Long-running conversations accumulate requirements, files, tool results, previous decisions, validations and intermediate reasoning. Keeping everything indefinitely creates unnecessary context pressure. Removing information too aggressively can cause an AI system to forget constraints or revive outdated decisions.
Cortex introduced semantic context compaction to address that problem.
Across evaluated benchmark scenarios, Cortex reduced eligible supplemental context by 46% while preserving required facts, retrieval success, task completion and validation. The evaluated workloads maintained 100% task success, required-fact recall, retrieval success and validation success, with no observed foreground latency regression.
The important idea is not simply reducing prompt size.
Context management has to understand what should remain protected, what can be summarized, what should be retrieved again from an authoritative source and what has become obsolete because the user changed direction.
That makes context management part of workflow reliability.
As Cortex moves toward work that can continue across devices, browsers, development environments and managed execution, maintaining the correct state becomes just as important as producing the next response.
Cortex Cloud Takes Work Beyond the AI Session
Cortex Connect established continuity in August, allowing intent and workflow progress to move among mobile, browser experiences and Visual Studio Code.
September extended that continuity into execution with Cortex Cloud.
Cortex Cloud gives eligible work a managed environment where it can continue remotely while remaining connected to the originating user, project and workflow. Users can choose between Local execution and Cortex Cloud depending on where the work belongs.
This changes an important assumption about AI assistants.
A useful answer can be produced inside a chat session. Meaningful engineering work often cannot.
Implementation, testing, validation and security analysis may need source code, tools, compute, durable state and an environment capable of continuing even when the originating device is no longer performing the work.
Cortex Cloud adds that execution layer while Cortex Connect maintains the relationship between the user and the task.
A request can begin on mobile or in a browser, reach the appropriate development context, execute through an eligible managed environment and return progress and results through the connected Cortex experience.
The AI interaction becomes less dependent on one screen or one active session.
Cortex Discover Makes the Browser an Agentic Work Surface
Six days after Cortex Cloud, September introduced another major execution surface: Cortex Discover.
Cortex Discover is a dedicated agentic AI browser rather than another browser extension. It combines native page awareness, reasoning across selected tabs, visual context, supported browser actions, file-aware workflows, durable task continuity and enterprise safety controls in one browsing environment.
The browser is increasingly where enterprise work happens.
Teams research information, inspect documentation, investigate incidents, review pull requests, manage customer systems, compare vendors and interact with operational applications. Traditional browser AI can summarize or explain this information, but the user usually becomes the integration layer when the work needs to continue.
Discover is designed to reduce that gap between understanding and completion.
Cortex can observe the current browser state, reason about selected information, coordinate the appropriate Cortex capabilities, perform supported actions within defined boundaries and inspect the resulting state.
That last step is important.
A requested action is not considered complete merely because an AI attempted it. The resulting page or application state provides evidence about what actually happened.
Cortex Discover also expanded the Cortex AI architecture from 48 to 50 specialized AI agents, adding browser-focused intelligence to the existing coordination of models, search, skills, coding, security, privacy, safety and verification. Cortex now spans nine user-facing platforms and product surfaces across major browser extensions, Visual Studio Code, Android, iPhone and the dedicated Discover browser, with Cortex Cloud providing managed execution for eligible remote work.
The browser therefore becomes another first-class execution environment within the Control Layer.
Reusing Work Without Reusing the Wrong Answer
As workflows become longer and more connected, another problem becomes increasingly important: repeated work.
Enterprise AI frequently processes the same instructions, project context, tool definitions or conversational history across successive requests. Repeating all of that computation wastes latency and capacity.
But caching AI work cannot simply mean returning an old answer.
September introduced the three-tier Cortex Inference Cache Architecture, separating reuse into three distinct layers:
- Context reuse for eligible application context whose sources and permissions remain current.
- Prompt prefix reuse for identical portions of model input that can avoid repeated prefill computation.
- Exact response reuse for narrowly approved, identical, read-only requests where the complete effective request remains valid.
This separation allows performance optimization without treating every form of reuse as equivalent.
Measurements demonstrated the potential impact: up to 150× faster prompt prefill, approximately 11× faster exact-response delivery on the measured eligible path, and up to 2.25× throughput at moderate concurrency in the evaluated workload.
The architecture also reinforces a broader Cortex principle.
Performance cannot override correctness.
A changed repository, updated document, different permission boundary or modified instruction can invalidate reuse. A cache miss is therefore a normal governed path rather than a failure.
The objective is not simply faster AI. It is avoiding unnecessary work when reuse is actually safe.
Security Extends From Source Code Into Runtime
Cortex Cloud then expanded beyond managed execution into a connected static, validation and runtime security workflow.
Before software runs, Cortex Cloud can inspect project metadata, source, dependencies, secrets, manifests, lockfiles, CI configuration and container definitions. It can build a controlled validation image, run planned tests in an isolated environment, verify that the resulting application starts correctly and assess its behavior while running.
The stages form a connected chain:
Project revision → static assessment → validation plan → qualified image → offline tests → runtime verification → security assessment → release evidence
This is significant because security findings are much more useful when their relationship to the actual release candidate remains clear.
A source finding may identify a risky pattern. A dependency finding may identify a vulnerable component. Runtime assessment can reveal behavior that becomes visible only once the software is executing.
Cortex Cloud ties these forms of evidence to the same revision, build and validation workflow rather than leaving teams to reconcile unrelated reports.
Runtime assessment includes bounded discovery, passive web analysis, curated HTTP checks and API examples and coverage testing against an isolated target. The resulting evidence can include static findings, build and test records, runtime observations, software bill of materials, provenance information, integrity data and signed attestations.
That advances the Cortex security model from identifying problems toward establishing evidence about the software that actually ran.
From Conversations to Governed Workflows
September closed the product sequence by connecting everyday AI conversations more directly with structured execution.
Chat Collections organize related discussions. Fork a Chat lets users branch from a completed response and explore another direction without disrupting the original conversation. Governed Workflows allow eligible engineering objectives to continue through specialized contributions, execution, validation and visible progress.
Each capability solves a different problem.
Collections provide organization.
Forks provide exploration.
Workflows provide coordinated execution.
Together, they help address a common progression in real AI use: a question becomes an investigation; the investigation produces alternatives; one alternative becomes work that must eventually be implemented, tested, reviewed and accepted or rejected.
That progression should not require the user to repeatedly reconstruct the objective.
The conversation can remain the place where intent develops, while the governed workflow becomes the mechanism for carrying an eligible objective toward a reviewable outcome.
It is another step away from treating chat as the final destination of enterprise AI.
September Turns the Control Layer Into an Execution System
Taken individually, September introduced routing, context management, cloud execution, an AI browser, inference caching, runtime security and new workflow capabilities.
Taken together, the architecture becomes more interesting.
A user can express an objective.
- Model, Search and Skill Routing determine which forms of intelligence, information and expertise should support it.
- Context management keeps longer-running work aligned as history grows.
- Cortex Connect maintains continuity across work surfaces.
- Cortex Discover provides a native agentic environment for work occurring inside the browser.
- Cortex Cloud provides durable managed execution when the task should continue remotely.
- Inference caching removes eligible repeated work while preserving freshness and authorization boundaries.
- Static analysis, validation and runtime assessment establish evidence about what was built and what actually ran.
- Collections and forks keep the exploration understandable.
- Governed Workflows carry eligible objectives toward reviewable results.
And security, permissions, observability, validation and human judgment continue to surround those layers.
That is a much broader system than a chatbot connected to tools.
It is increasingly an execution architecture for enterprise AI.
From Connected Intelligence to Governed Execution
July established specialized intelligence.
August connected that intelligence across models, planning, verification, devices and development environments.
September moved the architecture further into execution.
Cortex can increasingly determine what intelligence is appropriate, preserve the information required for longer-running work, move an objective across environments, execute eligible tasks locally or in the cloud, understand and act within the browser, reuse computation when it remains valid, assess software before and during execution, and return evidence that humans can review.
At the same time, Pervaziv AI expanded its participation in broader industry efforts around collective cyber defense and open AI security.
The direction continues to become clearer.
Enterprise AI cannot be measured only by the quality of an answer.
It must understand intent, use the right intelligence, maintain trustworthy context, operate inside controlled environments, respect changing permissions and state, secure the systems it touches, validate consequential work and give people evidence about what actually happened.
Cortex entered September as an increasingly connected Enterprise AI Control Layer.
It leaves the month becoming something more operational: a governed execution system designed to carry enterprise work from intent, through intelligence and action, to a result that can be inspected and trusted.


