The assistant is becoming the deployment layer
The category’s centre of gravity moved from code suggestion to operational control. On 26 Sep, Cursor introduced Rollouts, which monitors code changes during deployment and reports their health, and Security Review, which identifies exploitable bugs on pull requests. Both were positioned for Teams and Enterprise plans. That is not a nicer autocomplete story. It is a claim on the release process.
Vercel made the same argument from the infrastructure side. On 25 Sep, it introduced a GitHub Action for logging into its Container Registry, explicitly reducing reliance on long-lived credentials. The same day, Vercel Connect added support for TanStack AI with runtime authentication of MCP clients using managed tokens. On 22 Sep, Vercel Connect added Microsoft Teams support, allowing agents to receive and reply to messages through the platform.
Replit’s move was product-adjacent but pointed in the same direction. Its acquisition of Atta, reported on 27 Sep and described in Replit’s own blog changes, brings charting and analytics capabilities into Replit Conversations. Lovable’s acquisition of Sutro, reported on 18 Sep and reflected in four new Lovable blog pages on 19 Sep, added a programming-language asset to a company already being reported as crossing $600mn in annualised revenue run rate.
Distribution became a paid media sprint
The growth tempo was visible before the announcements caught up. Lovable had 40 new Google ad creatives running by 26 Sep, with the earliest first shown on 10 Sep. A later 28 Sep observation still showed 40 creatives running, with 21 new creatives first shown from 18 Sep. Vercel added 16 new Google ad creatives first shown from 22 Sep, then was still at 40 creatives running in a 28 Sep observation. GitHub added 11 new creatives first shown from 24 Sep and five more first shown from 25 Sep. Cursor added three new creatives first shown from 24 Sep.
That simultaneity matters. Four major vendors refreshed paid acquisition in the same late-September window while also shipping product, changing pricing, or updating customer proof. This was not a quiet launch cycle. It was a category-wide bid for attention, and the ceiling was notable: each of Lovable, Vercel, GitHub and Cursor was observed at 40 creatives running in the period.
Customer proof moved in parallel. GitHub added The New York Times, Spotify and Paramount Streaming to its customer page on 23 Sep, XING on 26 Sep, then Aevi plus case studies for ADEO, Aevi and Shopify on 28 Sep. Replit added Northern Health on 22 Sep. Lovable added Creandum and dig on 27 Sep. The case-study pages are becoming as dynamic as the product pages.
Packaging is being rewritten in public
Vercel’s pricing and packaging changes were the clearest commercial signal of the fortnight. On 19 Sep, it added 10GB of Container Registry image storage per month to Hobby and added $0.10 per GB-month Container Registry image storage to Pro. The same day, Enterprise teams gained Spend Management budgets with email alerts, webhooks and the option to pause production deployments.
On 25 Sep, Vercel changed the Hobby tier again, adding 1mn Function Invocations per month while removing 5,000 Image Optimization Transformations per month and four hours of Fluid Active CPU per month. It also added Data Transfer to the Pro Flat Rate CDN inclusion and removed the stated starting price of $0.128 per hour for Fluid Active CPU. The sequence is the point: storage, spend controls, function invocations, CPU exposure and CDN framing all moved inside one week.
Replit’s commercial surface changed more simply. On 23 Sep, its website replaced the CTA 'Try Free Mode' with 'Join Replit Pro'. That is a small text change with large intent. In a market where usage can turn into infrastructure cost quickly, free-mode posture and spend-management tooling are now product strategy, not website housekeeping.
Trust is the new battleground
The fortnight also showed the cost of moving into the release path. GitHub had repeated trust events: on 20 Sep, it reported a minor incident involving elevated error rates for OpenAI models provided by Copilot, resolved after about 50 minutes. On 23 Sep, GitHub reported a minor Pull Requests incident lasting about 69 minutes. On 26 Sep, it reported a minor billing-information disruption lasting about 230 minutes and another minor incident affecting several services for about 1,124 minutes.
Security headlines clustered around GitHub as well. On 21 Sep, five September CVEs were observed mentioning GitHub, including issues tied to command injection and insufficiently protected credentials in GitHub Copilot and Visual Studio Code. On 25 Sep, press coverage highlighted compromised GitHub Actions resuming malware execution and leaked private keys. On 28 Sep, further reporting said GitHub Actions had been re-enabled while the Mini Shai-Hulud payload was still active, while GitHub also introduced fresh authentication methods with Entra ID available in preview.
Cursor and Lovable were not immune to reliability pressure. Cursor reported three incidents on 20 Sep, including two major Grok Bot degradations lasting about 343 minutes and 176 minutes, then three minor incidents on 23 Sep and four further minor degradations on 26 Sep across Grok Bot, Grok 4.7 and Cloud Agent Dockerfile Builds. Lovable reported two minor incidents on 21 Sep, then on 25 Sep reported a minor .shop domain availability incident lasting about 96 minutes and a major incident involving elevated errors when enabling Lovable services lasting about 14 minutes. These are the incidents that come with becoming production infrastructure.
The smallest edits told the sharpest story
Cursor’s messaging reversal was unusually revealing. On 23 Sep, its website replaced 'Automate repetitive work' with 'Hand work to AI teammates'. On 26 Sep, it changed back, adding 'Automate repetitive work' and removing 'Hand work to AI teammates'. In the same window, Cursor restructured its sitemap heavily: on 23 Sep it added 117 product pages and five documentation pages while removing 121 product pages and one documentation page, then on 27 Sep it added eight API and Grok Bot documentation pages and 26 integration pages while removing 34 product pages.
Vercel showed a similar appetite for rapid surface-area management. On 19 Sep it added AI Gateway virtual model documentation and 16 product templates while removing two AI model pages, three careers pages and 12 blog pages. On 22 Sep it added a React Server Components demo and removed an A/B testing configuration template. On 25 Sep it added product pages for exa and a Next.js Redis session store template while removing a software engineering careers page and a library SDK blog page.
Lovable also reshaped its surface after the Sutro acquisition, adding four Sutro-related blog pages and 14 app and website builder product pages on 19 Sep while removing 19 product pages and one blog page. These edits rarely make a launch post. They are still where positioning hardens first.
| Company | Change | Date |
|---|---|---|
| Vercel | Added 10GB Container Registry Image Storage per month to Hobby. Added $0.10 per GB-month Container Registry Image Storage to Pro. | 2026-09-19 |
| Vercel | Added 1mn Function Invocations per month to Hobby. Removed 5,000 Image Optimization Transformations per month and four hours Fluid Active CPU per month from Hobby. Added Data Transfer to Pro Flat Rate CDN inclusion and removed the stated starting price of $0.128 per hour for Fluid Active CPU. | 2026-09-25 |
AI coding tools are no longer competing only on model access or editor experience. This fortnight, Cursor moved into deployment health and security review, Vercel tightened registry authentication and pricing, Replit bought analytics for Conversations, Lovable paired revenue-momentum coverage with the Sutro acquisition, and GitHub expanded customer proof while managing visible trust pressure around Actions and Copilot. The market is becoming a control-plane contest: whoever owns code creation, release safety, spend governance and proof of enterprise adoption gets to define the next buying cycle.
Each week this page takes a position and grades it in public once the horizon passes. Misses stay up. The full record.
This is the public read. OpsControl customers see this market live: every signal, graded and evidenced, the day it happens.
Track your own market
OpsControl