On September 28, 2026, Manus launched Manus 2.0 alongside a standalone app called Cue. The headline detail is not a new model. It is that each Cue agent gets its own email address, phone number, wallet and cloud computer, which makes Cue one of the clearest examples yet of personal AI agents that hold an identity of their own.
AnthropicWhat Manus launched with Cue
According to launch coverage, a Cue agent can send messages, make payments inside a budget the user sets, and take phone calls and then leave a summary. Cue is in early access on web, desktop and mobile, with the iOS version awaiting App Store review. It is free to use with an invite code (MEETCUE was cited), limited to a small first-come, first-served group of early users.
Manus 2.0 is built around Cascade, the company's in-house agent harness. The reporting frames Cue as the consumer-facing surface for that harness.
Why agent identities matter
Most assistants act through the user's own accounts. A Cue agent instead has separate contact details and money. That changes what a delegation can look like: an agent can be handed a task, reach outside parties under its own sender, and settle a small cost without borrowing the user's inbox or card.
What an agent identity adds, and where control can sit
Each resource turns an agent from a tool that drafts into an actor that can do. The right-hand column is our analysis of where limits fit, not a description of how Cue is built.
It also changes the failure modes. An agent that can only draft text produces a wrong draft. An agent that can pay and call can produce a wrong purchase or a wrong conversation with a real person. That is why the budget cap matters as a design feature, not a footnote. A spending limit is a hard boundary the model cannot talk its way past, which is different from a prompt instruction asking it to be careful.
An agent that can only draft text produces a wrong draft. An agent that can pay and call can produce a wrong purchase.
Group chats and the delegation model
Cue lets users place several agents in a group chat and split one job among them. The example in the launch coverage is event planning: one agent researches venues, another shortlists, a third drafts a presentation, and the user makes the final decision.

This is a familiar orchestration pattern, moved from a developer framework into a chat interface. The group chat doubles as an audit trail, since each agent's contribution is visible in one thread. The human sits at the final decision, and the budget sets the outer limit on money. What the reporting does not detail is whether individual actions, such as a single payment or an outbound call, can require their own confirmation. Readers evaluating this category should ask that question first.
Building on Claude and Qwen
Manus has stated it does not train its own base models from scratch and instead builds on Anthropic's Claude and Alibaba's Qwen models. For an agent company this is a coherent strategic choice. Training frontier models is capital intensive, while the differentiated work in agents sits in the harness: tool use, memory, scheduling, permissions and the product surface. Using third-party models lets a team follow whichever model performs best.
The trade-off is dependency. Pricing, rate limits and model behavior are set by suppliers, and a product's quality can shift when an underlying model changes. Cascade, as an in-house harness, is where Manus keeps control.
A wider pattern of persistent agents
Cue arrives as persistent, always-available agents become a product category rather than a demo. The common ingredients are a durable identity, a hosted computer that keeps state between tasks, the ability to message people, and an approval layer. Metir's own Blobs follow the same shape: teammates that run durable tasks with approvals on a hosted computer and can send email. Seeing several vendors converge on it suggests the category is real, and that the main differences will be in controls rather than in features.
What to watch
- Approval granularity. Whether limits apply per action, per day or per task.
- Disclosure. How agents identify themselves on calls and in email.
- Recourse. What happens when an agent makes a payment the user did not intend.
- Model dependency. How Cascade behaves when the underlying Claude or Qwen model changes.
Cue's launch is early access, so these answers will become clearer as real usage accumulates.
Sources:
- Implicator: Manus Cue agents, phone numbers and wallets
- CellCog: Manus 2.0
- Briefs: Manus rolls out Manus 2.0 and Cue app
- ExplainX: Manus 2.0, Studio, Cue, Cascade and cloud computer
- Runtime Wire: Manus Cue personal agents launch
Image credits
- Hero: "Cellphone (Unsplash)", Rodion Kutsaev, CC0, via Wikimedia Commons. Generic image of a smartphone in a hand.
- In-body: "Smartphone Use", Oceanos y dados, CC0, via Wikimedia Commons. Generic image of a person using a smartphone.
