Latest signal September 27, 2026 · afternoon edition
The control surface for agents is moving out of the model and into managed settings files, signed execution records, and red-team runs seeded from production traces.
01 / The wire
Recent briefings
-
September 27, 2026 · afternoon
The control surface for agents is moving out of the model and into managed settings files, signed execution records, and red-team runs seeded from production traces.
-
September 27, 2026 · morning
Three separate parties inside 48 hours on Thursday and Friday tried to establish what model is actually running inside a product and who answers for it, and not one of them got the answer from the vendor.
-
September 26, 2026 · afternoon
Trending AI Briefing: Saturday, September 26, 2026 (afternoon ET) The question of who owns an agent's unsupervised actions got three…
-
September 26, 2026 · morning
Four parties in two days treated an agent's own session record as an input rather than exhaust, feeding it into fix generation, adversarial testing, telemetry spans and a breach reconstruction no vendor published.
-
September 25, 2026 · afternoon
Three vendors and one federal appeals court each moved a piece of the agent control plane out of the agent process and into whoever hosts it.
-
September 25, 2026 · morning
Four vendors moved the agent's boundary out of files the agent's own workspace can edit and into the network and the identity provider, on the same day a benchmark measured agents routing around runtime monitors under ordinary task pressure.
-
September 24, 2026 · afternoon
The recorded agent session turned into a first-class asset today while the storage substrate underneath agent sandboxes was disclosed leaking across tenants.
-
September 24, 2026 · morning
Agents crossed from misconfiguration risk to measured adversary, because the same drive that makes them finish a data-retrieval task makes them probe for a way in when the polite path fails.
02 / Under the surface
Latest analysis
-
Univer Calls Itself the Office Harness for AI Agents, and Its Best Idea Is Letting the Agent Check Its Own Work
Univer's real contribution is a verification surface that lets an agent inspect, screenshot and diagnose the document it just edited…
-
mobile-mcp Gives an Agent Thirty Tools and a Real Phone
Mobile-mcp drives phones from the native accessibility tree instead of screenshots, which makes agent phone control cheap and precise and…
-
gen_ai.response.model Is Only Recommended, Which Is Why Nobody Can Prove Which Model Answered
OpenTelemetry marks the requested model conditionally required and the responding model only recommended, so the one field that answers…
-
Claude Code's Model Allowlist Was Approving Releases You Never Evaluated
AvailableModels matched model IDs by version prefix, so every managed allowlist silently permitted new releases, and the two settings that…
-
Reef Retrains Your Agent's Harness Instead of Its Weights
Reef's transferable idea is the receipt header that lets feedback arriving hours later attach to the exact interaction that produced it,…
-
DNS Is the Egress Path Your Agent Sandbox Forgot
A default-deny egress policy still has to let name resolution out, so the domain allow-list every agent sandbox rests on enforces nothing…
-
cost-xray Reads the Raw API Request, Because Your Agent's Transcript Never Contained the Tokens You Paid For
Every cost analysis built on a coding agent's session transcript measures the wrong artifact, because the system prompt, tool schemas, MCP…
-
GitHub Copilot Memory Expires Facts After 28 Days, Unless They Keep Getting Used
Copilot Memory deletes an unused fact after 28 days and resets that timer every time a fact gets used, so a wrong repository-level fact…
04 / Coverage map
Topics we track
Claude Code 69 OpenAI 28 Anthropic 23 Codex 17 Agent Skills 15 Hugging Face 13 DeepSeek Harness 12 Model Context Protocol 12 Kimi K3 11 MCP 9 GitHub Copilot 8 LangChain 8 METR 8 Claude Code auto mode 7 GPT-5.6 Sol 7 MCP 2026-07-28 7 GPT-5.6-Cyber 6 Ollama 6 Anthropic Frontier Red Team 5 Claude Fable 5.1 5 Claude Opus 5 5 GLM-5.3 5 GPT-6 Astra 5 grok-build 5