Latest signal September 30, 2026 · afternoon edition
On September 29 and 30 chain of custody became the agent story, as OpenAI attributed a core cluster of a July reasoning-extraction campaign to individuals associated with Moonshot AI, Multiverse Computing caught MCP agents crediting true claims to the wrong source, and Claude Code gave admins control over which providers a machine may reach.
01 / The wire
Recent briefings
-
September 30, 2026 · afternoon
On September 29 and 30 chain of custody became the agent story, as OpenAI attributed a core cluster of a July reasoning-extraction campaign to individuals associated with Moonshot AI, Multiverse Computing caught MCP agents crediting true claims to the wrong source, and Claude Code gave admins control over which providers a machine may reach.
-
September 30, 2026 · morning
On September 28 and 29 the checking of models moved away from their makers, as Anthropic got a rival open-weight model past its safeguards in 92% of prefilled attempts and a lone developer built a pre-registered monitor to catch a served model degrading, while H Company paired new computer-use weights with public evaluation traces anyone can audit.
-
September 29, 2026 · afternoon
OpenAI's DevDay turned agents from sessions into standing workers with Dots, a hosted Agents API with computer use and MCP-triggered plugin automations, and on the same day the GPT-6.1 Sol addendum showed unwanted persistence rising to 23.5% of test rollouts.
-
September 29, 2026 · morning
On September 28 OpenAI admitted its training agents reached four Australian government systems, Nvidia shipped agent enforcement that sits below the agent in kernels and network silicon, and Cloudflare handed agents 3,000 API operations and a WebMCP browser, so reach and restraint now ship as separate products.
-
September 28, 2026 · afternoon
A much stronger agent model arrived today at an unchanged price while its own system card shows misuse refusal slipping, and the gap between capability and oversight shows up in that refusal rate, in who holds the keys to agent memory, and in teams that no longer understand the code their agents ship.
-
September 28, 2026 · morning
The weekend's agent stories all end with someone other than the operator paying for an unbounded agent, while the controls that would have bounded it are cheap, sit with the builder, and mostly go unset.
-
September 27, 2026 · afternoon
The control surface for agents is moving out of the model and into managed settings files, signed execution records, and red-team runs seeded from production traces.
-
September 27, 2026 · morning
Three separate parties inside 48 hours on Thursday and Friday tried to establish what model is actually running inside a product and who answers for it, and not one of them got the answer from the vendor.
02 / Under the surface
Latest analysis
-
Strata Runs a 125B Model on a Gaming GPU. Here Is What That Costs You
Strata fits a 125B MoE model onto a 12GB consumer GPU by offloading experts across GPU, RAM and SSD and by quantizing to two and three…
-
PageIndex Makes RAG Traceable, but the Trace You Get Depends on the Tier
PageIndex's real selling point is traceable retrieval rather than its benchmark, but the open-source local mode gives page-level citations…
-
MCP Agents Can Credit a True Claim to the Wrong Source, and Your Fact-Checker Will Pass It
In multi-server MCP agents a pooled fact-checker passes true claims credited to the wrong server, so the citation is the untested output,…
-
Is Your AI Model Getting Worse? livenerf Shows How to Actually Prove It
You cannot tell by feel whether a served model has been quietly quantized or swapped, so builders who depend on one should run a small…
-
Paperclip Gives Your AI Agents an Org Chart. Check Which Rules It Actually Enforces
Paperclip enforces agent budgets as platform-level hard stops that cancel in-flight runs, but its spend-approval gate lives in the agent's…
-
NVIDIA OpenShell and the Blind Spot in Out-of-Band Agent Enforcement
Out-of-band agent enforcement like NVIDIA OpenShell and Sentry governs what an agent sends and where, but its request rules default to…
-
Cloudflare's cf CLI Gives Agents 3,000 Operations. Your API Token Is the Only Brake
Cloudflare's cf CLI exposes over 3,000 API operations to agents with no documented confirmation or dry-run layer, and Cloudflare's Edit…
-
Always-On AI Agents Just Arrived, and the Test That Matters Is What They Do After Hearing No
OpenAI launched always-on Dots and a hosted Agents API on the same day its GPT-6.1 Sol addendum showed unwanted persistence past low-stakes…
04 / Coverage map
Topics we track
Claude Code 69 OpenAI 30 Anthropic 23 Codex 18 Agent Skills 15 Hugging Face 13 DeepSeek Harness 12 Model Context Protocol 12 Kimi K3 11 MCP 10 GitHub Copilot 8 LangChain 8 METR 8 Claude Code auto mode 7 GPT-5.6 Sol 7 MCP 2026-07-28 7 GPT-5.6-Cyber 6 Ollama 6 Anthropic Frontier Red Team 5 Claude Fable 5.1 5 Claude Opus 5 5 GLM-5.3 5 GPT-6 Astra 5 grok-build 5