01 / The wire
Recent briefings
-
August 4, 2026 · afternoon
Three separate stories today all break at the same joint, systems that verify which identity signed an action but never verify what caused that identity to sign, which is the exact gap Cloudflare is now selling a product into.
-
August 4, 2026 · morning
Every significant agent launch on today's board answers the same two questions, where the agent is allowed to work and how a human checks what it did, which means the industry has quietly stopped competing on agent capability and started competing on containment and review.
-
August 3, 2026 · afternoon
Three projects on today's board run frontier-scale models on machines that cannot hold them by streaming weights off NVMe, which moves the binding constraint on local inference from RAM to storage bandwidth and makes every headline memory number misleading on its own.
-
August 3, 2026 · morning
The harness, not the model and not the prompt, became the unit of engineering this week, and it is now carrying the permission model, the review gate, and the security posture that used to live somewhere else.
-
August 2, 2026 · afternoon
Agent skills finished their transition from a convenience feature into a package ecosystem, complete with a measured supply chain, an OWASP top ten, and enterprise signing registries, while the format itself still ships with no signatures and no capability model.
-
August 2, 2026 · morning
Streaming experts off disk instead of holding them in RAM went from one clever hack to the default architecture for running open frontier models locally, and the same week it landed, Unit 42 published what an attacker built out of the open-weights plus open-harness stack.
-
August 1, 2026 · afternoon
Agent state that used to live somewhere invisible is being dragged into the open, by the MCP spec that deleted the hidden session, by YC scoping memory and permissions per person and per room, and by two disclosures where the exploit was configuration and text the operator never saw.
-
August 1, 2026 · morning
Three separate disclosures this week put the failure at the harness layer rather than the model layer, with Anthropic classifying its own real-world breaches as an operational failure, AI Now showing no model update fixes the README injection class, and a GitHub board led entirely by skill routers and connector gateways.
02 / Under the surface
Latest analysis
-
@cloudflare/computer Lets the Model Pick Its Own Runtime. That Tool Description Is Your Cost Policy.
@cloudflare/computer moves the isolate-versus-container choice out of your architecture and into the agent's own tool call, which turns the…
-
ChatGPT Atlas Shuts Down August 9. Read the Shutdown Notice, Not the Launch Post.
Atlas lasted under ten months, and its shutdown notice is the more useful document than its launch post, because it names the state a…
-
WASTE Keeps a File of Everything It Got Wrong. Read docs/LEARNED.md Before You Read the Benchmark.
WASTE's most checkable claim is not 0.6 tokens per second, it is docs/LEARNED.md, a dated append-only record of hypotheses the project…
-
Project Perception's Load-Bearing Word Is "Actuator," Not "Agent"
Project Perception removes the human from the middle of the security loop while keeping them at both ends, so the only control that…
-
pdf-inspector: Firecrawl Says 54% of Your PDFs Never Needed OCR
Pdf-inspector's real argument is that roughly half the documents in a typical pipeline are already machine-readable and get sent to OCR…
-
Fresh-Context Review: The Agent That Wrote Your Code Is the Worst Judge of It
A context window that wrote the code cannot honestly review it, self-preference research shows the failure gets worse exactly when the…
-
WASTE Runs Kimi K3's 2.78 Trillion Parameters on a Laptop, and the Bottleneck Moved to Your SSD
WASTE proves a 2.78-trillion-parameter model no longer has to fit in RAM, but it relocated the constraint rather than removing it, from…
-
Unit 42's Autonomous AI Attack Report Is a Configuration Audit, Not a Capability Warning
Every control the attacker disabled in Unit 42's autonomous-attack campaign is a documented, supported setting in harnesses developers…
04 / Coverage map
Topics we track
Claude Code 17 Codex 11 OpenAI 10 Kimi K3 9 MCP 2026-07-28 7 Agent Skills 6 Hugging Face 6 MCP 6 Claude Opus 5 5 Model Context Protocol 5 OpenAI Presence 5 Anthropic 4 GPT-5.6 Sol 4 grok-build 4 MAI-Cyber-1-Flash 4 QM 4 xAI 4 1Password for Claude 3 AgentForger 3 Claude Security 3 Hermes Agent 3 Ollama 3 opencodex 3 TurboFieldfare 3