Daily News · 2 min read

Vercel AI Updates: October 1, 2026

1. AI Gateway Adds Browserbase Search and Fetch as Model-Agnostic Tools

Vercel. Browserbase Search and Fetch are now available through AI Gateway, letting any tool-calling model search the web and retrieve page contents with a single AI Gateway API key. The helpers ship in AI SDK 7.0.116 and later and are passed in the tools option, so the same web tools carry over when switching between model providers. Source

2. Ling 3.1 Flash From InclusionAI Lands on AI Gateway, Free Through October 13

Vercel. InclusionAI’s Ling 3.1 Flash, a hybrid reasoning model with 560B total and 25B active parameters and a 262K-token context window, is now on AI Gateway and free to use through October 13, 2026. The standard ID inclusionai/ling-3.1-flash starts billing after the promotion, while inclusionai/ling-3.1-flash-free stops serving instead, which gives teams a way to trial it without surprise charges. Source

3. Vercel Sandbox Can Now Run Inside a Team’s Secure Compute Network

Vercel. Sandboxes can attach to a Secure Compute network, sending public traffic out through static IPs and reaching private AWS VPC resources over VPC peering. A network ID can be passed when creating a sandbox in code or with --network-id in the CLI, and existing sandboxes can switch networks via sandbox.update() on their next session; the feature is limited to Enterprise teams with Secure Compute. Source

4. Vercel Agent Can Install Private npm and Custom Registry Packages

Vercel. Vercel Agent sessions now authenticate npm, pnpm, and classic Yarn against private registries using team-shared NPM_TOKEN or NPM_RC environment variables, matching how Vercel builds resolve dependencies. Credential values stay outside the sandbox so the agent cannot read them, and project-scoped variables are ignored. Source

Vercel. Origin responses whose Vary header includes Cookie are no longer stored in the Vercel CDN cache; they are served with x-vercel-cache: MISS and logged with the reason vary_key_denied:cookie. Teams that see unexpected cache misses should drop Cookie from Vary for responses that do not depend on it, or use Cache-Control: private for personalized content. Source