Google ADK, LangGraph, and AutoGen are three different orchestration substrates, not three versions of the same thing. ADK is Google’s GCP-native framework, and since ADK 2.0 it executes agents as nodes in a workflow graph. LangGraph is an open-source, cloud-agnostic framework built around an explicit StateGraph and checkpointer model, so you write the control flow yourself. AutoGen is Microsoft’s original conversational framework, in maintenance mode since October 2, 2025, with Microsoft Agent Framework (MAF) as its GA successor. One fact most 2026 comparisons miss: ADK has accumulated four published security advisories in five months, two of them Critical. This guide compares orchestration model, protocol support, security posture, and enterprise-readiness signals across all three, then names the decision none of them resolves.
Google ADK vs LangGraph vs AutoGen: at a glance
Google ADK, LangGraph, and AutoGen all sit at the same layer of the stack: orchestration, not governance. Whichever one runs the loop, the agent still needs to know what your business’s data actually means, and that is the gap Atlan’s context layer closes: a governed, model-agnostic tier that delivers definitions, lineage, and policy to any agent regardless of which of the three frameworks below it runs on. The quick facts and comparison table below focus on orchestration model, protocol support, and security posture; the context layer question returns later in this guide.
- What each one is: Google ADK is a graph-based multi-agent framework native to Google Cloud; LangGraph is an open-source StateGraph framework you run anywhere; AutoGen is Microsoft’s original conversational framework, now frozen in maintenance mode.
- Who runs the orchestration: with all three, you write and run the agent loop yourself, in your own infrastructure.
- Current status (2026): ADK and LangGraph are both actively developed; AutoGen receives bug and security fixes only, with Microsoft Agent Framework as the maintained path forward.
- Where they converge: all three document the Agent2Agent (A2A) protocol, so agents built on any of them can discover and hand off work to one another. ADK marks its A2A support experimental. Each can also connect to Model Context Protocol-based context sources.
- What none of them resolves: orchestration frameworks define how an agent runs, not what its data means.
| Dimension | Google ADK | LangGraph | AutoGen (→ MAF) |
|---|---|---|---|
| What it is | Graph-based, GCP-native multi-agent framework | Open-source, cloud-agnostic StateGraph framework | Conversational multi-agent framework, now in maintenance mode |
| Who runs the orchestration | You do, as nodes in a workflow graph | You do, via an explicit StateGraph | You do; new builds should target Microsoft Agent Framework instead |
| Language and runtime | Python, Go, Java, TypeScript, Kotlin | Python, JavaScript/TypeScript | Python and .NET (legacy); Python and .NET via MAF |
| Cloud alignment | GCP-native, Gemini Enterprise Agent Platform integration | Cloud-agnostic | Microsoft ecosystem (Python/.NET) via MAF |
| Current status (2026) | ADK 2.0 GA for Python, Go and TypeScript; Java on 1.x | Active, large open-source community | Maintenance mode since October 2, 2025 |
| Protocol support | A2A, marked experimental | Native A2A | Native A2A (via MAF) |
| Best for | GCP-committed teams, multi-language support | Teams needing explicit, cross-cloud state control | Teams already on AutoGen, migrating to MAF |
None of these three frameworks governs what your agent knows
Before comparing Google ADK, LangGraph, and AutoGen feature by feature, it helps to name the one axis none of the three resolves: whether the agent knows what your business’s data actually means. Orchestration frameworks define how an agent runs, not what its data means. Whether the loop is ADK’s workflow graph, LangGraph’s StateGraph, or AutoGen and MAF’s conversational pattern, the question of which “revenue” definition is correct, which table is authoritative, and who is allowed to see what belongs to a different tier. That distinction sits above the single-agent versus multi-agent architecture question entirely.
To be fair, this gap is narrowing at the operational layer. ADK ships structured session management, and MAF documents “context providers” for agent memory, features that genuinely help an agent harness track state across a run. A skeptical reader could argue the frameworks are converging toward owning the context layer, not leaving it to a separate tier. The honest distinction: operational or session context is not the same as governed business context. The comparison below treats that fairly and returns to it once the head-to-head is done. For the fuller argument, see how to implement an enterprise context layer for AI.
What is Google ADK?
Google ADK, the Agent Development Kit, is Google’s open-source (Apache 2.0) framework for building multi-agent systems. It executes agents as nodes in a workflow graph. That is a change from how ADK started: ADK 2.0’s Workflow Runtime moved the framework “from a hierarchical agent executor to a graph-based execution engine,” and the current agents documentation no longer uses “hierarchy,” “tree,” or “sub-agent” at all. The old multi-agent URL now redirects to the workflows page. Comparisons written against ADK’s launch architecture describe a runtime that no longer exists.
The version picture matters for the same reason. ADK launched at Google Cloud NEXT in April 2025 and reached its Python v1.0.0 stable release in May 2025. ADK 2.0 is GA for Python (May 2026), Go (June 2026) and TypeScript (August 2026). The Java SDK remains on its 1.x line, and a Kotlin SDK reached 1.0 GA in September 2026. Five official language SDKs is the real multi-language story here, and a genuine differentiator in the AI agent stack.
Beyond language support, ADK documents Agent2Agent (A2A) protocol support for Python, Go and Java, currently marked experimental, and integration with Model Garden on Gemini Enterprise Agent Platform, the product formerly called Vertex AI, and its 200-plus models. Mitch Ashley, VP and Practice Lead of Software Lifecycle Engineering at Futurum Group, frames the shift plainly in this third-party analyst read: “ADK shifts the question from which framework should I build agents with to which framework owns the execution layer…” Thoughtworks Technology Radar (April 2026), another analyst assessment rather than a vendor source, places ADK in its “Trial” ring: “Worth pursuing. It is important to understand how to build up this capability. Enterprises should try this technology on a project that can handle the risk.”
Real usage shows up both in the raw open-source library and in Google’s own products built on it:
- GitHub momentum: about 22,000 stars on
adk-pythonas of September 18, 2026, alongside separate repos for Go, Java, TypeScript and Kotlin. - Deloitte: built an inventory insights and discrepancy-detection solution for a major retail client using Google Cloud AI Agents and Gemini Enterprise.
- A furniture manufacturer, with partner Quantiphi: built a self-run multi-agent ADK and A2A system automating quotation-response creation.
Both entries come from Google Cloud’s “Building Scalable AI Agents” design-pattern writeup, published October 2025. They are separate customers, and Deloitte’s end client is not named in the post.
Core components of Google ADK
- Workflow graph execution: agents extend
BaseNodeand run as individual nodes within workflow graphs. - A2A protocol support: documented for Python, Go and Java, marked experimental.
- Multi-language runtime: Python, Go, Java, TypeScript, and Kotlin, each an official Google repo.
- Model Garden integration: access to 200-plus models on Gemini Enterprise Agent Platform.
- Built-in session and context management: ADK’s own docs define Session as one ongoing interaction, State as data scoped to the active thread, and Memory as recall across past sessions. Those are operational primitives. Governed business context is a different tier, a distinction worth remembering once you reach the production readiness section below.
What is LangGraph?
LangGraph is an open-source orchestration framework built around an explicit StateGraph API: you write the control flow yourself, modeling the agent as a graph of nodes and edges, with typed state passing directly between steps. That is a different trade than ADK’s workflow graph or AutoGen’s conversational pattern; more control, in exchange for owning more of the runtime. LangChain and LangGraph are related but distinct: LangGraph is the graph orchestration layer, not the broader LangChain toolkit.
LangGraph is cloud-agnostic and has the largest community of the three by GitHub stars: about 41.9k stars and 7.1k forks as of September 18, 2026. LangChain publishes production case studies for LinkedIn, Uber, Klarna, Elastic and AppFolio. Full internals, including the checkpointer model, are covered on Atlan’s dedicated LangGraph page; this section stays focused on what the comparison needs.
Core components of LangGraph
- StateGraph API: the programming model for defining nodes, edges, and control flow.
- Explicit state management: typed state that passes deterministically between steps.
- Step and loop control: direct caps on iterations to prevent runaway loops.
- Checkpointers: persistence for graph state, with a SQLite option among others.
- Broad ecosystem: interoperability with the wider LangChain tooling and the AI agent frameworks landscape more broadly.
Get the AI Context Stack brief
Every one of these frameworks sits in the same layer of the stack: orchestration. See where governed context fits relative to models, frameworks, and tools.
Get the AI Context StackWhat is AutoGen, and what replaced it?
Before Microsoft Agent Framework existed, there was AutoGen: Microsoft’s original conversational multi-agent framework, built around a message-passing, emergent-behavior pattern rather than a fixed graph or tree, where agents talk through a problem rather than following a predetermined path. This page keeps the description brief on purpose. What is AutoGen? covers the ConversableAgent primitive, the GroupChat pattern, and the full status timeline; this section only states what the comparison needs.
The current, easily-gotten-wrong fact: Microsoft moved AutoGen into maintenance mode on October 2, 2025, bug and security fixes only, no new features. Microsoft Agent Framework (MAF) is the named successor, and Microsoft’s own devblog dates 1.0 GA to April 3, 2026: “the production-ready release: stable APIs, and a commitment to long-term support,” covering .NET and Python, with Go in public preview. AG2 is a separate third-party fork, not a Microsoft product, created on November 11, 2024 under Apache 2.0 and administered by original AutoGen creators Chi Wang and Qingyun Wu. The microsoft/autogen repository was never renamed.
The common mistake worth stating plainly: legacy AutoGen still holds 61,042 GitHub stars against MAF’s 13,574, both read September 18, 2026, nearly a year after the maintenance-mode announcement. That is real adoption inertia and a fair nuance against a naive “just migrate” framing; teams have working systems and switching costs. It is also a reason for enterprise-ready AI agent planning to target MAF for any new build rather than a framework that receives no new features.
Google ADK vs LangGraph vs AutoGen: how do they compare head-to-head?
Google ADK, LangGraph, and AutoGen diverge most on orchestration model and cloud alignment, and they converge on something most 2026 comparison content misses entirely: all three document the same interoperability protocol, A2A. The table below maps nine decision axes, including one every ranking competitor page currently skips: security and CVE posture. Star counts were read on September 18, 2026.
| Dimension | Google ADK | LangGraph | AutoGen (→ MAF) |
|---|---|---|---|
| Orchestration model | Workflow graph; agents run as nodes | StateGraph and checkpointer model | Conversational, message-passing pattern, now frozen |
| Language and runtime | Python, Go, Java, TypeScript, Kotlin | Python, JavaScript/TypeScript | Python and .NET (legacy); Python and .NET via MAF |
| Cloud alignment | GCP-native | Cloud-agnostic | Microsoft ecosystem (Python/.NET) via MAF |
| Development status (2026) | ADK 2.0 GA for Python, Go, TypeScript; Java on 1.x | Active, community-led | Maintenance mode since Oct. 2, 2025; MAF GA April 3, 2026 |
| Protocol support | A2A, marked experimental | Native A2A | Native A2A, via MAF |
| Security and CVE posture | Four published advisories, two Critical, including CVE-2026-4810 at CVSS v4.0 9.3; all patched | CVE cluster (path traversal, SQL injection, serialization), all patched | No published GitHub security advisories as of September 18, 2026 |
| GitHub momentum | ~22K stars (adk-python) | ~41.9K stars, largest community | 61,042 legacy stars vs. 13,574 MAF stars |
| Enterprise-readiness signal | Thoughtworks “Trial” ring; Google-published Deloitte and Quantiphi case studies | LangChain-published case studies: LinkedIn, Uber, Klarna, Elastic, AppFolio | MAF “production-ready, stable APIs” as of April 2026 |
| Failure mode | Running a version behind any of the four advisories | Runaway loops or unpatched checkpoint injection | Building new on a maintenance-mode repo instead of migrating |
The context layer sits above whichever orchestration substrate you choose, and moves with you if you switch.
Consider a platform team evaluating a multi-agent customer-support system on Google Cloud:
- GCP-committed org: ADK’s integration with Agent Runtime lets the team deploy without standing up its own runtime, though ADK also deploys to Cloud Run, GKE, or any container environment.
- Needs cross-cloud portability: LangGraph’s explicit loop-and-step caps stop a planner agent looping indefinitely on an ambiguous tool result.
- Already on legacy AutoGen: the team faces a third decision, debug the existing system as-is or begin migrating its checkpointed state to MAF.
Each framework suits its lane. None of them resolves whether the agent actually knows what your business’s data means, which is exactly the scaling problem that shows up after the framework decision is made.
Take the Context Maturity Assessment
Before you commit to a framework, or migrate off one, score where your business context stands today and what it would take to make any of these three actually accurate in production.
Take the assessmentWhat are the security risks of Google ADK, LangGraph, and AutoGen in production?
This is the comparison axis every ranking page on this topic currently skips, and it is sourced material, not a smear on any one framework. All of the CVEs below are patched. The point is who owns the patch cadence and whether your team runs a current version, which matters for AI agent governance planning as much as the CVE details themselves.
| Framework | CVE | Severity | Flaw type | Affected versions | Status |
|---|---|---|---|---|---|
| Google ADK | CVE-2026-4810 (GHSA-rg7c-g689-fr3x) | Critical: CVSS v4.0 base 9.3 | Code injection and missing authentication, allowing unauthenticated remote code execution | 1.7.0 up to 1.28.1; 2.0.0a1 up to 2.0.0a2, on Python OSS, Cloud Run, and GKE | Disclosed April 13, 2026; fixed in 1.28.1 and 2.0.0a2 |
| Google ADK | CVE-2026-18236 | Critical | Continuation forgery | Per the advisory | Published July 29, 2026 |
| Google ADK | CVE-2026-79707 | High | Path traversal in the builder endpoint | Per the advisory | Published September 4, 2026 |
| Google ADK | CVE-2026-79696 | Critical | Code injection in adk web |
Per the advisory | Published September 9, 2026 |
| LangGraph / LangChain | CVE-2026-34070 | High: CVSS 7.5 | Path traversal in legacy load_prompt |
langchain-core before 1.2.22 |
Patched in 1.2.22; published March 26, 2026 |
| LangGraph | CVE-2025-67644 | High: CVSS 7.3 | SQLite checkpoint SQL injection | langgraph-checkpoint-sqlite before 3.0.1 |
Patched in 3.0.1; published December 9, 2025. The advisory notes LangSmith deployment customers are not impacted |
| LangChain Core | CVE-2025-68664 | Critical: CVSS 9.3 | Serialization injection that can leak secrets | langchain-core before 1.2.5 and before 0.3.81 |
Patched in 1.2.5 and 0.3.81; published December 23, 2025 |
| AutoGen / MAF | No published GitHub security advisories as of September 18, 2026 | — | — | — | Scoped to the GitHub Advisory Database for microsoft/autogen and microsoft/agent-framework |
This table is a snapshot, not a feed. ADK alone published four advisories in five months, two of them Critical and both in the last two weeks before this update, so check the live advisory list rather than trusting any published table for patch decisions. A team on an older ADK version has a live exposure, exactly the kind of access control gap that turns a framework decision into a security incident. LangChain and LangGraph carry a documented cluster instead of one severe finding, and the three above are a subset: both repos have published considerably more since. Teams self-hosting these packages own the prompt injection and patch cadence directly. The AutoGen and MAF row describes what a GitHub Advisory Database search returned on one day, not a claim of inherent safety, and MAF is the newest of the three with less time in production for issues to surface. Whichever framework you run, observability into what an agent actually did is what turns a patched CVE into a confirmed fix, and it is why teams report agents fail in production for reasons that have nothing to do with the model.
When should you choose Google ADK, LangGraph, or AutoGen/MAF?
The decision comes down to cloud commitment, control needs, and existing investment rather than a single “best” framework. The table below maps common situations to a default, with the reasoning, and includes the one situation this page will not resolve for you: choosing among more than these three.
| Your situation | Lean ADK | Lean LangGraph | Lean AutoGen/MAF | Why |
|---|---|---|---|---|
| GCP-committed, need multi-language support | Yes | Native Go, Java, and Kotlin support alongside Python | ||
| Need explicit, deterministic state control across complex branching | Yes | StateGraph gives direct control of loops and state | ||
| Need cross-cloud portability | Yes | Cloud-agnostic by design | ||
| Already running legacy AutoGen in production | Migrate to MAF | Legacy repo gets bug and security fixes only | ||
| Already on Python/.NET and Microsoft tooling, need conversational multi-agent collaboration | MAF (not legacy AutoGen) | MAF is the maintained, GA successor | ||
| Also evaluating CrewAI or OpenAI’s Agents SDK | See the broader comparison note below |
If you are choosing among more than these three, CrewAI and the OpenAI Agents SDK are the other frameworks most enterprise teams shortlist. Rather than re-running a scorecard this page’s scope deliberately narrows away from, start with how to choose an agentic framework for enterprise for the full five-framework comparison, or AI agent frameworks compared for the broader landscape.
Framework choice is real, consequential, and reversible; it determines engineering ergonomics, cloud alignment, and security patch ownership. It does not determine whether the agent knows what your business’s data means, the thread this page returns to next.
How Atlan approaches the agent stack above ADK, LangGraph, and AutoGen
Google ADK, LangGraph, and AutoGen all orchestrate the agent loop. Orchestration frameworks define how an agent runs, not what its data means: which “revenue” definition is correct, which table is authoritative, who is allowed to see what. According to Gartner (June 2025), over 40 percent of agentic AI projects will be canceled by the end of 2027 due to escalating costs, unclear business value, and inadequate risk controls. Brian Hopkins, VP of Emerging Tech Portfolio at Forrester, put it plainly: “Three-quarters of enterprise leaders tell us they’re adopting agentic AI. Only a small minority have it running in meaningful production beyond ‘agentish’ chatbots.” Both support the same read: framework adoption alone is not producing production success.
The Context Layer for AI is the governed, model-agnostic tier that sits above ADK, LangGraph, and AutoGen or MAF alike. The Atlan MCP Server delivers governed context, definitions, lineage, policy, and ownership, to any agent regardless of which framework it runs on, since MCP is framework-agnostic by design. The Context Engineering Studio builds that business understanding; the Context Lakehouse stores it in an Iceberg-native, portable format, the antidote to the lock-in practitioners describe calling agent frameworks “the new monoliths.” This is distinct from ADK’s session management or MAF’s context providers, which handle operational state, not governed business meaning. See why MCP matters for AI agents and agent interoperability protocols for how that delivery works underneath any agent harness your team builds.
The outcome is measurable, and it isolates the variable: context, not framework, moves accuracy. At Workday, Atlan reports a 5x improvement in AI response accuracy through MCP-delivered context. Sridher Arumugham, Chief Data and Analytics Officer at DigiKey, put it directly: “Atlan is much more than a catalog of catalogs. It’s more of a context operating system.”
See Governed Context in Action
See how Atlan delivers governed context to any agent stack, regardless of which orchestration framework sits underneath it.
See How the MCP Server WorksFrameworks converge on protocols; context still decides production reliability
The Google ADK versus LangGraph versus AutoGen choice is real for engineering ergonomics, cloud alignment, and security patch ownership, and the honest 2026 answer is that all three now converge on the same interoperability protocol: Agent2Agent. AutoGen specifically should route new builds to Microsoft Agent Framework, not the legacy repository, regardless of how many stars the older project still holds.
The decision that actually determines production reliability is the governed context layer above whichever framework you choose: model-agnostic, portable, independent of the orchestration substrate underneath it. That is where the accuracy gap comes from. As frameworks commoditize and converge on shared protocols, context is the part of the stack that compounds. Pick the framework that fits your team and your cloud, then invest in the layer that decides whether what you built is actually right.
FAQs about Google ADK vs LangGraph vs AutoGen
1. What is the difference between Google ADK and LangGraph?
Google ADK executes agents as nodes in a workflow graph and is native to Google Cloud, with integration into Gemini Enterprise Agent Platform, the product formerly called Vertex AI. LangGraph is cloud-agnostic and built around an explicit StateGraph API, so you own state and loop caps directly. Both document the same interoperability protocols, so the choice mostly comes down to cloud commitment and how much orchestration control you want to write yourself.
2. Is AutoGen still relevant in 2026, or is it deprecated?
AutoGen is not deprecated, but it has been in Microsoft-declared maintenance mode since October 2, 2025: bug and security fixes only, no new features. It remains relevant for existing production systems, but new builds should target Microsoft Agent Framework, its official GA successor. AG2 is a separate third-party fork, not a Microsoft product.
3. What replaced Microsoft AutoGen?
Microsoft Agent Framework (MAF) is AutoGen’s official successor, reaching 1.0 GA for Python and .NET on April 3, 2026. A separate, community-governed fork called AG2 also exists, created in November 2024 by AutoGen’s original creators, for teams staying on an open community path instead.
4. Do Google ADK, LangGraph, and AutoGen all support the same interoperability protocols?
Mostly. ADK documents A2A support for Python, Go and Java, currently marked experimental. LangGraph, CrewAI and Microsoft Agent Framework all document A2A, which is the path for AutoGen teams. Semantic Kernel does not: Microsoft documents A2A under Agent Framework, and community samples are not native support. Each framework can separately connect to MCP-based context sources.
5. Is Google ADK production-ready for enterprise use?
Thoughtworks Technology Radar, a third-party analyst assessment, placed Google ADK in its “Trial” ring in April 2026, worth pursuing on a project that can handle some risk. Google publishes case studies from Deloitte and from a furniture manufacturer working with partner Quantiphi, and ADK 2.0 is GA for Python, Go and TypeScript. Check your version against all four published ADK advisories first, two of which are Critical and landed in July and September 2026.
6. What are the security risks of using Google ADK or LangGraph in production?
Google ADK has four published advisories: CVE-2026-4810, an unauthenticated remote-code-execution flaw rated CVSS v4.0 9.3 and patched in 1.28.1 and 2.0.0a2, plus CVE-2026-18236, CVE-2026-79707 and CVE-2026-79696, two of them Critical. LangChain and LangGraph carry a documented, patched cluster covering path traversal, SQLite-checkpoint SQL injection, and a serialization flaw that could leak secrets. The operational risk is running an unpatched version, not an inherent flaw in either framework.
7. Can you migrate an existing AutoGen deployment to another framework?
Yes. Microsoft publishes an official migration guide for moving Semantic Kernel and AutoGen projects to Microsoft Agent Framework, the most direct path since MAF is AutoGen’s designated successor. Moving to Google ADK or LangGraph instead means rewriting the orchestration logic against a different programming model, since neither offers an official AutoGen migration tool.
8. Do I still need a context layer if I use ADK, LangGraph, or AutoGen?
Yes. Orchestration frameworks define how an agent runs, not what its data means. Your business’s definitions, lineage, policy and ownership live in a different tier. A governed context layer above whichever framework you choose delivers that business context to any agent, which is where production accuracy and reliability actually come from.
Sources
- Agent Development Kit: Making it easy to build multi-agent applications, Google Developers Blog
- Agents, ADK, Agent Engine and A2A enhancements at Google I/O, Google Developers Blog
- ADK 2.0 release notes, adk.dev
- Graph-based workflows, adk.dev
- Sessions, state and memory, adk.dev
- Agent2Agent support in ADK, adk.dev
- Building Scalable AI Agents: Design Patterns With Agent Engine on Google Cloud, Google Cloud
- I/O '26 news for agent developers on Google Cloud, Google Cloud
- google/adk-python GitHub repository, GitHub
- langchain-ai/langgraph GitHub repository, GitHub
- microsoft/autogen GitHub repository, maintenance-mode banner, GitHub
- AutoGen maintenance mode announcement, Discussion #7066, GitHub
- microsoft/agent-framework GitHub repository, GitHub
- Microsoft Agent Framework version 1.0, Microsoft Agent Framework devblog
- Context providers, Microsoft Learn
- Agent Development Kit (ADK), Thoughtworks Technology Radar
- Google ADK Is Not a Toolkit – It Is an Agent Execution Framework, Futurum Group
- CVE-2026-4810, National Vulnerability Database
- GitHub Security Advisory GHSA-rg7c-g689-fr3x, CVE-2026-4810, GitHub
- Published security advisories for google-adk, GitHub Advisory Database
- GHSA-qh6h-p6c9-ff54, CVE-2026-34070, langchain-ai GitHub Security Advisories
- GHSA-9rwj-6rc7-p77c, CVE-2025-67644, langchain-ai GitHub Security Advisories
- GHSA-c67j-w6g6-q2cm, CVE-2025-68664, langchain-ai GitHub Security Advisories
- Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027, Gartner
- The State of Agentic AI in 2026: Companies Are Chasing, Few Are Catching, Forrester