Latest signal August 13, 2026 · morning edition
Five vendors spent the past week shipping infrastructure whose primary user is an agent rather than a person, a browser, a wallet, a 14-day runtime, a local model tuned for tool calls, and a fleet of always-on desktop VMs, while the middleware underneath all of it is still the same unpatched agent frameworks.
01 / The wire
Recent briefings
-
August 13, 2026 · morning
Five vendors spent the past week shipping infrastructure whose primary user is an agent rather than a person, a browser, a wallet, a 14-day runtime, a local model tuned for tool calls, and a fleet of always-on desktop VMs, while the middleware underneath all of it is still the same unpatched agent frameworks.
-
August 12, 2026 · afternoon
Four vendors spent this week retiring the human approval click as an agent safety control and replacing it with a classifier, an enrollment program, a cloud perimeter, or an environment identity, and the one layer none of them hardened is the harness hosting all four.
-
August 12, 2026 · morning
Nobody shipped a frontier model in the last 48 hours, and five separate parties instead published arguments about substrate, which language agent-written code should land in and which compiler, VM, and GPU driver should run it.
-
August 11, 2026 · afternoon
Almost nothing shipped in the last 48 hours is a new agent, it is an attachment to an agent harness developers already run, and the connective tissue those attachments pass between each other turned out to be readable by a cheaper model.
-
August 11, 2026 · morning
On the same day, one vendor put its strongest agentic capability behind identity verification and hardware keys while another gave a capable agent model away under Apache 2.0, and the split is now a deliberate product decision rather than an ideology.
-
August 10, 2026 · morning
Agents stopped borrowing human software this week, with a human-shaped agent browser switched off the same week a browser written for agents shipped, and coding agents getting their own compute fleets and their own message bus.
-
August 6, 2026 · afternoon
Three separate disclosures this week describe attacks in which the model never gets a turn at all, and the defenses that shipped in the same 48 hours moved enforcement off the prompt and into the request path.
-
August 6, 2026 · morning
The scaffolding around the model is now the product, and yesterday it started editing itself, which arrived in the same 24 hours as a zero-click exfiltration proving nobody has a containment story for a harness that rewrites its own prompts and skills.
02 / Under the surface
Latest analysis
-
Needle 2 Is a 45M-Parameter Model That Can Only Call Tools
Needle 2's real claim is that device control needs no world knowledge, and its own benchmark tables support the architecture while…
-
AgentCore's Multi-Agent Collaboration Is a Shared /tmp Directory
AgentCore runtime instances make multi-agent collaboration a shared filesystem on one EC2 box, and AWS's own security page says the agents…
-
RovoBlast Turned a URL Parameter Into a Prompt, and Rovo Ran It
The instruction channel nobody governs is the query string, because a prompt arriving through a URL parameter enters an authenticated…
-
Cua's Metal Capability Shim Made llama.cpp 11x Faster by Changing Two Answers
The GPU inside a macOS VM was never the bottleneck, its self-reported capability profile was, and Cua's shim proves that a capability probe…
-
Corsair Makes the Approval Gate a Database Row Your Agent Cannot Reach
Corsair's load-bearing move is putting both the credentials and the pending approval into your database instead of the model's context,…
-
Claude's Compliance API Now Covers Claude Code. Nothing Covers What Your Harness Sent.
Agent audit tooling now records the conversation that reached the server, and nothing records the context your harness attached to it on…
-
witr Answers Why Is This Running, and Coding Agents Just Made That Question Expensive
Witr's copyable idea is not the process tree but its refusal to hedge, since it names one primary source and marks its uncertainty…
-
Unsloth Desktop Runs Claude Code on Your Own GPU. Two Defaults Break It First.
Unsloth Desktop's Anthropic-compatible endpoint makes Claude Code run against a local GGUF in one command, but two defaults sabotage it out…
04 / Coverage map
Topics we track
Claude Code 25 Codex 11 OpenAI 10 Kimi K3 9 Agent Skills 7 MCP 2026-07-28 7 Hugging Face 6 MCP 6 Model Context Protocol 6 Anthropic 5 Claude Opus 5 5 OpenAI Presence 5 GPT-5.6 Sol 4 grok-build 4 MAI-Cyber-1-Flash 4 QM 4 xAI 4 1Password for Claude 3 AgentForger 3 Amazon Bedrock AgentCore 3 AWS 3 ChatGPT Atlas 3 Claude Security 3 Cloudflare OS 3