
Hey readers!
Here's something you don't hear from a company 26 years into selling IDEs: the editor is no longer the center of the story. That's effectively what JetBrains is saying with its new Air package, and the framing is more interesting than another "AI in your IDE" launch. Let's dig into what Air actually is, why the "open protocol" angle matters, and how it stacks up against a very busy few weeks of agent news.
🛰️ JetBrains Air: betting beyond the workbench

JetBrains opens up a new AI channel as it boosts developer support - JetBrains launched Air, a package it calls an Agentic Development Environment (ADE) that lets you delegate coding tasks to multiple AI agents in parallel while keeping a human in control. - IT Europa
The pitch is built around four pieces: Air in JetBrains IDEs for orchestrating and verifying agents, Air Teams for coordinating delivery workflows, Air Governance (formerly JetBrains Central) for policy, auditing, and cost management, and Junie, JetBrains' own coding agent. What stands out is the emphasis on everything except code generation - verification, coordination, security, spend. That's a bet that the hard part of agentic work isn't the writing.
"AI can produce code, but organisations still have to produce software. Agentic development is changing how software gets made, but it hasn't changed what it costs to be wrong," says JetBrains CEO Kirill Skrygan.
The quote I keep coming back to is the admission of what this launch really means for the company:
"For 26 years, we have focused primarily on the individual developer workbench. Now, we are building for the wider system through which agentic work is initiated, executed, coordinated, reviewed, and governed."
That is a genuine repositioning. If you make most of your money selling a seat-per-developer editor, saying "the workbench is one surface among many" is not a small admission.
JetBrains Introduces Air, an Open System for Agentic Development - Unite.AI's writeup fills in the part that matters most for lock-in: Air is built around the Agent Client Protocol (ACP), an open standard JetBrains developed with Zed to define how IDEs and coding agents talk to each other. - Unite.AI
ACP covers planning, logic, tools, model routing, and observability, with a stated goal of no vendor lock-in. In practice that's JetBrains trying to be the neutral control plane rather than forcing you onto Junie or a single model. Given how many teams already run a mix of Claude Code, Copilot, and Codex across projects, a vendor-agnostic orchestration and governance layer is a reasonable thing to want, whether or not JetBrains is the one that ends up providing it.
Unite.AI also flags the rollout plan: future mobile and remote experiences, richer context, and work triggered by repository events and delivery processes rather than only an editor prompt. That last bit is the real tell. If agents start acting on a merged PR or a failing pipeline instead of waiting for you to type in an editor, the prompt box stops being where development lives.
Why this matters for you: The bottleneck JetBrains is describing - understanding, verifying, and owning changes - is exactly the one developers are already feeling. A 2026 survey of over 1,100 developers found AI helped write 42 percent of their code, yet 96 percent did not fully trust the results and 38 percent said reviewing AI-written code took more time than reviewing a human's. Whatever tool you use, the review surface is where your day is heading.
🤖 Everyone's building the same "coordinate many agents" layer
Air isn't arriving in a vacuum. The same week brought a wave of products chasing the same idea: one coordinating brain over many parallel agents.

Claude Code's "Chief of Staff" update ties multiple coding tasks together - Anthropic redesigned Claude Code's Projects so a single ongoing project carries context across related tasks, moving Claude from a one-request chatbot toward what AINave calls a code-writing "chief of staff." - AINave
Claude Code Projects Add Parallel AI Coding Threads - The companion piece gets specific: each worker thread runs as its own cloud session with a separate repo copy and branch, stitched together by shared project memory. - TechJournal
It's worth reading the honest caveat here, because it applies to Air just as much as to Claude:
Anthropic says users must resolve the overlap as a normal Git merge conflict when parallel threads modify the same code.
Parallel agents multiply throughput, not your ability to reconcile conflicting assumptions. Access is initially limited to select Claude Pro and Max users, with Team and Enterprise planned later and no dates given. The pattern across JetBrains, Anthropic, and the rest is identical: delegate widely, then pay the tax at review and merge time.
Microsoft's new Copilot unifies enterprise context for chat and code - Microsoft folded Chat, the Cowork agent, a redesigned Code environment, and the persistent Autopilot agent into one Copilot that routes tasks for you, plus governance plumbing like Copilot Managed Runtime and FinOps cost controls with usage-based billing. It's the enterprise mirror of Air's governance argument. - Computerworld
Microsoft revamps Copilot with code generation, agentic AI tools - Reuters frames the same September 25 announcement more bluntly: Microsoft wants Copilot to be a "one-stop shop" for office workers, embedding Word, Excel, and PowerPoint directly inside it. - Reuters
Wix's Base44 launches Base Code to take on Claude Code and Cursor - Base Code connects to GitHub repos, has an agent learn the codebase, and provisions a full cloud workspace with live previews, pitching "Figma for developers" with pull requests that still route through your existing review workflow. - Calcalist
The common thread: governance, cost control, and shared context are now table stakes, not features. JetBrains just happens to be the one most explicitly building the control plane rather than another agent.
🔐 The uncomfortable part: agents are a security surface
All this delegation assumes you can trust what the agent fetches and runs. Two stories this month say: not so fast.
A single git trick beat the safety lock on four AI coding agents - Researchers at Air Security (no relation to JetBrains Air) published "Plugin4Shell," claiming agents fetch a pinned plugin snapshot but never verify what they actually received, enabling code substitution. - The Next Web
Air found that the agents ask for the pinned snapshot but never check what they got.
It's reportedly affected Claude Code, Codex, GitHub Copilot, and Gemini CLI. Claude Code was fixed in version 2.1.179 and Codex in 0.146.0, while Microsoft has shipped no fix for Copilot and Google says it won't patch Gemini CLI because it's being retired. As of September 18, 2026 there was no CVE or vendor advisory, and no sign of real-world exploitation. The fix, per the researchers, is almost insultingly small:
The fix is one line. After checking out, resolve what actually sits in the working tree, then abort unless it matches the pin.

Z.ai Open-Sources ZCode After Git History Upload Apology - Beijing startup Z.ai open-sourced its ZCode agent under Apache 2.0 on September 21, 2026, three days after apologizing for a feature that uploaded encrypted workspaces - full Git history included - to Alibaba Cloud. - The Terminal
A user writeup under the handle ferstar found that 86.6% of one archive came from the .git directory (56.8% Git LFS cache, 29.6% commit objects) rather than the source files you'd expect a codebase-indexing feature to touch. Z.ai says it patched the behavior, enabled zero-data retention, and that independent assessors found the data was deleted, though developers noted that deletion couldn't be independently verified. It's a clean illustration of JetBrains' point: once agents move your code around, auditability isn't optional.
🧰 Quick hits for the model picker

Claude Sonnet 5.5 in GitHub Copilot - Generally available as of September 28, 2026, GitHub says early testing had it matching Sonnet 5 on coding tasks while using fewer steps, tokens, and tool calls, and finishing faster. Notably, it's selectable from Copilot's model picker inside JetBrains IDEs too. - GitHub Changelog
OpenAI Release Notes: GPT-6 Astra - Introduced September 3, 2026 for a limited set of organizations, Astra targets hard end-to-end work across reasoning, coding, and computer use, and adds safety monitoring that may pause a conversation if it suspects instruction misinterpretation. - OpenAI
Cloudflare Open-Sources Forge After Stainless Shutdown - Cloudflare open-sourced its API-to-SDK/CLI/docs generator (Apache 2.0) after relying on the now-shuttered Stainless, arguing closed-source generators create "unacceptable platform risk" - a theme that rhymes with JetBrains' open-protocol pitch. - The Silicon Ledger
🎮 One more thing
If JetBrains is building the control plane for agents doing your work, somebody had to build the playground for agents doing, well, everything else. SpaceMolt is a realtime MMORPG built for AI agents - a useful sandbox if you want to watch autonomous agents coordinate, compete, and generally misbehave in a space with actual stakes before you point them at your production repo.
The through-line this month is hard to miss: the industry has mostly solved "make the agent write code" and is now scrambling to solve "trust, coordinate, and pay for what it wrote." Air is JetBrains' answer, and it's a more honest one than most. We'll be watching whether ACP gets real adoption or ends up as one more protocol nobody agrees on.
See you next week.

