Automation: Zapier folds agents into Zaps, n8n fixes 14 flaws, Make adds versions
First week of October 2026: Zapier agents become a step inside a Zap, n8n ships 14 security fixes and announces version 3.0, and Make adds descriptions to scenario versions.
The three best-known automation platforms are pulling in the same direction this week: tighter control over AI agents and over changes. Zapier moves agents into regular workflows, n8n closes security holes and hardens its defaults, and Make makes changes easier to track. Here is what is new.
Zapier: agents become an AI step in a Zap
On 6 October Zapier announced that Zapier Agents is becoming AI by Zapier. The agent is no longer a separate product but a single AI step in the Zap editor. Tool calling, reasoning and autonomous action stay. What is new:
- triggers from any app Zapier supports, not just a handful;
- approvals set per tool instead of one switch for the whole agent;
- model choice through Standard, Advanced and Premium tiers, or by naming a specific model.
AI steps are billed as regular tasks. Premium models use three or five times as many tasks. You can set a per-run task limit, and runs that exceed 75 tasks pause for human review. Existing users get step-by-step migration guidance in the app. Knowledge sources from HubSpot, Asana, Zendesk, Zoom and Jira are not supported yet.
n8n: 14 security fixes and version 3.0 ahead
On 1 October n8n published 14 security advisories, 10 of them high severity. They include credential exposure in shared workflows, XSS, SQL injection in the Microsoft SQL node and code execution risks in the Git node. Fixes ship in versions 1.123.83, 2.41.4 (stable) and 2.42.1 (beta). Cloud instances were patched automatically; self-hosted users need to upgrade.
n8n has also scheduled n8n 3.0 for October. The biggest change: self-hosted n8n will require Docker, and installs run with npm or npx n8n will no longer be supported. Legacy nodes such as Function, Cron, Interval and the old OpenAI node are removed, unverified community packages are off by default, and in-memory binary data mode is gone.
Make: scenario versions and the end of multiple cycles per run
On 7 October Make redesigned the scenario toolbar. "Run once" and "Save" now sit together, and a new "Save as version" button stores a version with a description. Descriptions appear next to timestamps in the version history and can be edited later. It is available on all plans.
Since 1 October the Cycles per run setting is gone: every run now completes a single cycle. If you relied on multiple cycles, raise the maximum records the trigger processes per run or schedule the scenario more often.
What it means for your business
- If you self-host n8n, upgrade this week. Ten high-severity flaws, some touching credentials, should not wait. Before 3.0 arrives, check that your install runs in Docker and does not use removed nodes.
- Set limits before agents go live. In Zapier, decide which tools need approval and how many tasks a single run may use, so the bill stays predictable.
- Keep a record of changes. A short description on every scenario version saves hours when something breaks and you need to roll back.
If you want us to review your existing workflows or set them up properly, see our automation service or get in touch.
Sources
- Zapier: Zapier Agents is now AI by Zapier (6. 10. 2026)
- n8n Community: Security update — 01 October 2026 (1. 10. 2026)
- n8n Docs: v3.0 Breaking changes (10. 2026)
- Make Help Center: Improved scenario toolbar and version control (7. 10. 2026)
- Make Help Center: Cycles removal on October 1, 2026 (13. 8. 2026)