Pydantic AI changelog: what's new each month
Every stable Pydantic AI release summarised by month: the highlights, new features, improvements, fixes and anything you need to act on. 3 months covered; the current month updates daily.
October 2026 · so far
2 releases: 2.53.0 → 2.54.0
October brought security fixes, schema handling improvements, and new declarative plugin support for clai2. The month focused on robustness in concurrency handling, JSON schema support, and better integration with external tools.
- SubAgents agentfolders default-change warning has been removed; pass agentfolders='agents' explicitly to keep loading the agents folder.
Highlights
- Fixed a high-severity security issue where streamed requests through ConcurrencyLimitedModel could retain concurrency slots incorrectly.
- Added declarative plugin system for clai2, allowing plugins to be defined as simple subclasses.
- Improved JSON schema handling for draft-7 list-form items and boolean subschemas across multiple components.
- Added built-in plugins for PostHog, Grain, and Linear integration with credentials management.
- Enhanced error handling for background tools and durable execution engines.
New
- Built-in PostHog plugin for clai2 with /keys or browser sign-in support.
- Built-in Grain plugin for clai2 with keyring-backed sign-in.
- Built-in Linear plugin for clai2 with settings menu and /keys credentials.
- OneOf schema support in TestModel's generated data.
- Tracking of Google grounding web search queries in usage metrics.
- Tinting of clai2 file diffs based on selected /theme palette.
Improved
- TestModel now accepts boolean subschemas and caps prefixItems at maxItems.
- JsonSchemaTransformer handles draft-7 list-form items properly.
- Mistral streamed output now supports draft-7 list-form items.
- Wrap hooks now enclose complete stage lifecycles.
- Model errors from Temporal model activities are re-raised with their original type in workflow code.
- BackgroundTools that raise unexpected exceptions now end the run, consistent with sequential tools.
- ImageGeneration works correctly under FallbackModel and dataclasses.replace.
- Embedder comparison now uses identity checks.
Fixed
- Security issue where streamed requests through ConcurrencyLimitedModel could keep concurrency slots when released on different tasks.
- ImageGeneration handling under FallbackModel and dataclasses.replace.
- Durable execution engine now refuses a second instance on an agent before either binds.
September 2026
18 releases: 2.37.0 → 1.107.7
September brought major expansions to real-time capabilities, new model support across providers, and security fixes. The month focused on TypeSafe model routing, workspace abstraction for sandboxing, and improved handling of streaming and durable operations.
- SubAgents no longer load agent files by default; inherittools parameter deprecated.
- Invalid UserPromptPart.content types (non-string, non-sequence) now raise instead of silently sending dict keys.
- Tuple output fields now rejected in TypeSafeModel instead of crashing.
- Per-run capabilities= parameter rejected on DBOS to match Temporal behavior.
Highlights
- Added real-time support for Gemini 3.8 Live and OpenAI GPT-Live with live transcription and barge-in handling.
- Introduced TypeSafeModel and DecisionModel for intelligent routing and structured output with multiple providers.
- Launched workspace abstraction allowing Coder, Shell, and FileSystem tools to run locally or in sandboxes with durable execution.
- Added support for 15+ new models including Claude Opus 5.5, GPT-6 variants, Gemini 3.8 Flash, and provider-specific models.
- Fixed four security vulnerabilities in webfetch, cloud metadata blocklist, and span content leakage.
New
- Real-time sessions with OpenAI GPT-Live and Gemini Live, including transcription finalization and barge-in interrupts.
- TypeSafeModel for routing decisions with structured outputs, supporting enums, booleans, and nested fields.
- Workspace API abstracting file and command execution across local machines and sandboxes with durable support.
- Event streaming via CustomEvents and CapabilityEvents that applications can emit and subscribe to with @onevent.
- Direct image generation API with ImageGenerator and deprecated fallbackmodel in favor of fallbacksubagentmodel.
- GitHub Copilot provider with OAuth device authorization flow and openai-codex provider for ChatGPT/Codex subscriptions.
- VLLMProvider for vLLM servers and TypeSafeModel provider for TypeSafe's Jev.
- Temporal Workflow Streams integration to stream agent events via eventstreamtopic.
Improved
- Context window tracking with contextwindow in ModelProfile and contextwindowused in RunContext and realtime sessions.
- Tool call attribution for media returned by tools, and text part boundary preservation in OpenAI chats.
- One-off capabilities now have default IDs with combine rules for repeats, and per-request capabilities= rejected on DBOS.
- MCP server sessions reduced to one per durable run instead of per unit, and DynamicToolset resolved once per run.
- Anthropic model's default maxtokens raised to 16384 for Sonnet 4.5+ and now defaults to model maximum with streaming.
- Agent runs report their own usage on spans, and UI message IDs preserved across Vercel AI and AG-UI adapters.
- OpenAI logprobs fully preserved in providerdetails, and Anthropic native web searches priced and reported in RequestUsage.
- Barge-in handling in realtime sessions with interrupt(playedbytes=...) and RealtimeSession.waitforplayback().
Fixed
- Security: HTML conversion in webfetch no longer consumes excessive CPU/memory on deeply nested elements.
- Security: IPv6 zone identifiers no longer bypass cloud-metadata and private-IP blocklists.
- Security: webfetch domain lists now compared in resolver form, blocking alternate domain spellings.
- Security: InstrumentationSettings(includecontent=False) now properly excludes exceptions, statuses, instructions, and templates from spans.
- Contextsubtree() exporter cache and span-processor leaks fixed.
- DeferredToolResults.approvals validation now rejects invalid values, and DeferLoading no longer splits parallel batches.
August 2026
24 releases: 2.22.0 → 2.36.0
August brought major realtime speech capabilities, expanded provider support including Snowflake and Crusoe, and significant tooling improvements across multiple platforms. The month also included important security fixes for the development web chat UI.
- RunContext.capabilityloaded and availablecapabilityids deprecated in favor of capabilityactive and activecapabilityids.
- Pydantic AI v2.33.0 requires anthropic>=1.0.0; pin anthropic<1 to stay on older versions.
- @durableoperation now requires an explicit operation name.
Highlights
- Added realtime speech-to-speech support with Agent.realtime() and browser WebRTC integration.
- Introduced native tool deferral to hide functions until revealed via tool search or capability loading.
- Added Snowflake Cortex and Crusoe providers for broader model availability.
- Implemented first-party run cancellation with AgentRun.cancel() and RunContext.cancel().
- Fixed critical security issues in the development web chat UI's Host header validation and content-type checking.
New
- Realtime speech-to-speech support with Agent.realtime(), browser WebRTC, and server sideband.
- Snowflake Cortex provider (SnowflakeModel and SnowflakeProvider).
- Crusoe provider for additional model access.
- Native tool deferral and addition channels via ToolAvailabilityDeltaPart.
- Run cancellation with AgentRun.cancel(), RunContext.cancel(), and RunCancelled exception.
- Cost tracking in RunUsage and costlimit in UsageLimits.
- Azure AI Voice Live support via azurevoicelive setting.
- LangChain migration skill and --mcp-config support in clai CLI.
Improved
- Gemini now defaults to VALIDATED tool mode on supported models.
- Mid-conversation system prompts sent as native system messages on Anthropic.
- Bedrock now supports extra headers in ModelSettings.
- Tool signatures now include parameter descriptions in rendered output.
- OpenRouter web-search sources surfaced in providerdetails annotations.
- Sync hooks now run in a thread pool with timeout enforcement.
- Model name suggestions provided for invalid identifiers.
- Temporal workflow metrics export frequency reduced by default.
Fixed
- Fixed Temporal workflow livelock when anyio scope cancellation hits an in-flight activity await.
- Fixed Google provider dropping explicit timeout=0.
- Fixed gzip response body silent truncation.
- Fixed inherited realtime WebRTC and Azure bugs.
- Fixed concurrent provider stream shutdown issues.
- Fixed stale UIEventStream part state on cancellation.
Summaries are written automatically from the official release notes (full changelog ↗); check the original notes before relying on a detail. Pydantic AI: pricing, features and alternatives · All changelogs
