Daily News · 2 min read

Pydantic AI AI Updates: September 30, 2026

1. Pydantic AI 2.52 Adds Workspaces So Harness Tools Run Locally or in a Sandbox

Pydantic AI. Version 2.52.0 introduces ctx.workspace, a single API that gives tools file and command access either on the local machine or inside a sandbox, with durable execution support. Harness capabilities such as Coder, FileSystem and Shell now run through it, and the release adds E2BSandbox, SpritesSandbox (Fly.io Sprites), SSHWorkspace and BubblewrapSandbox backends, while ModalSandbox now exposes a Modal workspace instead of its own tools (ModalSandboxBackend replaces ModalSandboxSession). For teams running coding agents, the same agent code can now move between a laptop and an isolated remote environment without swapping tool implementations. Source

2. The Harness Moves Into the Main Repo and CLAI 2 Ships Its First Release

Pydantic AI. pydantic-ai-harness now lives in the main repository and ships with every Pydantic AI release, so its version jumps from 0.36.0 to 0.52.0. The same release is the first of pydantic-clai2, runnable with uvx pydantic-clai2, which ships built-in plugins for GitHub, Slack, Notion, Google Workspace, Logfire MCP and others with credentials managed through /keys or browser sign-in, plus a --agent MODULE:ATTR flag to chat with an existing Agent. The release also adds support for Claude Sonnet 5.5 and OpenAI’s gpt-6.1-sol. Source

3. Anthropic Default max_tokens Changes and a web_fetch Security Fix

Pydantic AI. AnthropicModel now defaults max_tokens to the model’s maximum output and streams such requests behind the scenes, and SubAgents no longer load agent files by default, with inherit_tools deprecated. Upgraders should review these compatibility notes, since longer default outputs can change cost and latency. Both 2.52.0 and the v1 maintenance release 1.107.7 patch GHSA-v36g-jcw9-x7cw, a moderate issue where attacker-controlled HTML with deeply nested elements could make the local web_fetch tool consume excessive CPU and memory; provider-native web fetching is not affected. Source