News
The latest from the AI agent ecosystem, updated multiple times daily.
Every agent safety story ends with a human clicking approve. New research measures that human.
A preregistered five-experiment study published on 15 July found AI advice collapses people's willingness to say "I don't know" from 44 per cent to 3 per cent, while roughly doubling their confidence. Abstention is the only output an approval gate exists to produce. The agent industry has built its entire oversight story on the one cognitive act that AI exposure degrades fastest.
Thinking Machines admitted its open model isn't the best. The admission is the business plan.
Mira Murati's lab open-weighted Inkling and said up front it isn't the strongest model, open or closed. Read as open-core, the disclaimer is positioning: the model is a loss-leader base to feed Tinker, the paid fine-tuning platform, and it quietly reprices a lab that couldn't raise on being a frontier contender.
Grok's coding CLI uploaded your whole repo. The opt-out never governed that.
A wire-level teardown caught xAI's Grok Build CLI shipping entire repositories, git history and unredacted secrets to a Google Cloud bucket, with the training opt-out doing nothing to stop it. The story isn't the leak. It's that the one privacy control users are handed was pointed at the wrong layer, and the fix arrived as a silent server flag with no word on what gets deleted.
GitHub did agent security by the book. A public issue and the word 'Additionally' leaked a private repo.
GitLost turned a stranger's GitHub issue into a private-repo data leak. The sharp angle isn't 'prompt injection again' — it's that GitHub's least-privilege, allowlist-everything design still fell, because the last trust boundary in an agentic system is enforced by a model's probability, not by code.
Godot's AI code ban isn't about quality. It's rationing the mentors of tomorrow.
Godot will soon reject all AI-authored code, framing it as a trust and competence problem. Read against the Foundation's own words, the real scarcity it's protecting is the human apprenticeship pipeline that turns contributors into maintainers — something no AI submission can enter.
An AI read his MRI and disagreed with his doctor. He left with less certainty, not more.
The viral 'Claude Code read my MRI' story is being sold as the democratised second opinion. What actually happened is the opposite: the machine handed a patient two confident, contradictory readings and no one to stand behind either. The scarce good in radiology was never the reading. It was the accountable reading, and that is exactly what the consumer AI workflow strips out.
Claude Code hid a secret marker in its own prompts. The target list is the tell.
Anthropic quietly rewrote a punctuation mark in Claude Code's system prompt to fingerprint reseller and Chinese-lab traffic. The panic called it surveillance; the target list and the obfuscation say it was a weak, throwaway weapon in the distillation war, and a self-inflicted wound to a tool that runs on trust.
AI can now finish the proof, and mathematicians are arguing about what's left
An IEEE Spectrum essay asks what mathematics is for once AI can do the part humans found hardest. The worry is not wrong answers but a discipline built on human struggle losing the struggle. The four-colour theorem already showed how this argument goes.
OWASP's agentic security report says your coding agent is the attack surface
OWASP's 2026 State of Agentic AI Security has stopped listing hypothetical threats and started counting real ones. Coding agents account for most of the new attack data. Prompt injection is the thread running through nearly all of it.
A Waymo engineer is bringing self-driving's test rigs to voice agents
Coval raised US$28m to build the simulation and evaluation layer that voice AI agents lack. Founder Brooke Hopkins is porting the reliability playbook she used at Waymo. The bet: every company will run a voice agent, and almost none can test one.
A nine-person startup rebuilt web search from scratch because agents don't click
Seltz launched with US$12.5m in seed funding and a search engine built only for AI agents. It rewrote the crawler, index and ranking in Rust rather than wrapping Google. The wager is that agent traffic, not human browsing, is the next search market.
Runlayer raised US$30m to be the bouncer for your company's AI agents
Felicis led a US$30m Series A into Runlayer, a control layer between enterprise AI agents and the data they reach for. Vinod Khosla reportedly wanted the whole round. The pitch: nobody can yet see what their agents are touching, and that gap is now a budget line.
AI and crypto super PACs have amassed over US$321m to shape the 2026 midterms
Super PACs funded by the AI and crypto industries have raised more than US$321 million this cycle to target candidates seen as hostile to light-touch regulation, per FEC filings reviewed by The Nation. The flagship, Leading the Future, entered the year with US$70 million in cash.
A satirical incident report imagines seven AI security gates waving the same malware through
Andrew Nesbitt's viral satire CVE-2026-LGTM walks a malicious package past seven AI-powered security scanners, each failing for a different reason and none for the right one. It is fiction, but every failure mode it lampoons is real. The kicker: a stated root cause about LLMs in series.
A drop-in router picks a different model for every request, using an on-box scorer not a prompt
Weave open-sourced Router, a proxy that sits in front of Anthropic, OpenAI and Gemini and chooses the best model per request. Point Claude Code, Codex or Cursor at localhost and it routes with a tiny on-device classifier rather than an LLM judge. Keys stay on your machine.
DeepSeek open-sourced its speculative-decoding stack and claims up to 80% faster generation
DeepSeek bolted a new decoding module, DSpark, onto its V4 checkpoints and open-sourced DeepSpec, the MIT-licensed toolkit to train such modules. It reports throughput gains of 51% to 400% over Eagle3 and DFlash. The catch is the storage the training pipeline demands.
OpenAI is shipping GPT-5.6 only to customers the US government approves one by one
OpenAI's most capable model, GPT-5.6 Sol, is launching to a small group of partners whose access the US government clears individually. Sam Altman told staff the setup is temporary and not the company's preferred long-term model. It is the first US frontier model shipped behind a government-managed access list.
Your coding agent's reasoning is a summary, and the raw version was never an audit log
A developer opened Claude Code's saved reasoning and found a 600-character signature and no readable text. The easy reading is that Anthropic took away an audit trail. The sharper one, backed by Anthropic's own faithfulness research, is that the reasoning trace was never a faithful log to begin with, and the fight to see 'the real thinking' is aimed at the wrong target.
Six of seven LLMs gave medical researchers a method that doesn't exist
TriNetX, a health-records platform, lets medical students churn out papers at speed. The new twist is AI: asked how to fix a common statistical bias, six of seven LLMs suggested approaches impossible to run on the platform, and those methods are already turning up in published papers.
Gemini 3.5 Flash gets computer use built in, with an injection kill switch
Google has folded computer use into its mainstream Gemini 3.5 Flash model as a built-in tool, so agents can drive a browser, phone or desktop without a separate model. The notable part is the defence: an optional system that halts a task the moment it detects a prompt injection.
OpenAI's Codex was quietly writing 640TB a year to users' SSDs
A logging bug in OpenAI's Codex agent has been hammering users' SSDs with up to 640TB of writes a year. One developer clocked 37TB in 21 days. By Codex's own estimate, the regression burned low-single-digit millions in drive wear.
Ford rehired 350 'gray beard' engineers to fix what AI couldn't
Ford spent three years quietly bringing back 350 veteran engineers after its AI quality tools failed to stop costly defects. Their job is twofold: retrain the AI, and mentor the juniors it was meant to replace. Ford has since topped JD Power's quality survey.
Anthropic says Alibaba ran 25,000 fake accounts to copy Claude
Anthropic has accused operators tied to Alibaba and its Qwen lab of spending six weeks harvesting Claude's most valuable skills, in a complaint to US senators. It calls the effort the largest distillation attack it has seen. The target was agentic reasoning, not chatbot chitchat.
When OpenClaw hit 3,400 PRs a week, its merge rate collapsed
A Greptile study of openclaw/openclaw shows pull requests leaping from two a week to 3,400, as the merge rate fell from 48% to under 9.3%. The fix was Vouch, a trust system that blocks unvouched contributors.
Why the big AI labs are putting philosophers on the payroll
The Economist reports AI labs are hiring philosophers in-house to decide how agents should behave. Anthropic's Claude's Constitution was co-written by two; OpenAI says it consulted hundreds.
Anthropic's Claude Tag puts one shared Claude inside your Slack channel
Claude Tag lets Team and Enterprise users tag @Claude into a Slack channel. The twist is a single shared identity per channel that remembers history, so any teammate can pick up where another left off.
Alibaba's Qwen team trained a model to be the environment agents learn in
Qwen-AgentWorld is a pair of language world models that simulate agentic environments. Training agents by RL inside the simulation beat training in the real environment alone, the paper reports.
OpenAI's first custom chip, Jalapeño, was taped out in nine months
OpenAI revealed Jalapeño, an inference-only accelerator built with Broadcom. Its standout claim is speed of development: design to tape-out in about nine months, helped along by OpenAI's own models.
Bland raised US$50m for voice agents after 180 investor rejections
Voice-AI startup Bland has closed a US$50m Series C led by Dell Technologies Capital, pushing total funding past US$100m. The pitch behind the round: its agents already handle more than 3.5 million calls a week, some lasting up to 45 minutes, in regulated industries.
Chrome's agent starts doing your errands on Android this month
Google's auto browse, an agent that acts across the open web, begins rolling out on Chrome for Android at the end of June. It is gated: built on Gemini 3.1, limited to US AI Pro and Ultra subscribers on Android 12 phones, and required to ask before it buys anything.
C1's identity agent can only do what you can already do
C1 has launched C1 Autonomous Worker, an AI agent that carries out enterprise identity chores like revoking stale admin grants or assembling audit evidence. Its key constraint is the selling point: it runs through the same policy engine as human staff and can act only within its operator's existing permissions.
Odyssey raises US$310m to chase a GPT-3 moment for world models
Odyssey, founded by autonomous-driving veterans, has raised a US$310m Series B at a US$1.45bn valuation to build AI that simulates the physical world. The round, led by Natural Capital with Amazon, GV and AMD Ventures, comes with AWS as preferred cloud and a chip deal with Annapurna Labs.
DeepMind now treats its own AI agents as insider threats
Google DeepMind has published an AI Control Roadmap that assumes its internal agents may be misaligned and builds system-level containment around them. The most telling detail is in the data: of a million coding-agent tasks it monitored, most flagged events were not sabotage but overeagerness.
Engineering leaders rediscovered a 1985 problem and called it cognitive debt
A CTO Craft dinner crowned "cognitive debt" the new technical debt, and an MIT brain-scan study gave it a scientific sheen. Both are looking in the wrong place. The real liability is old, organisational, and shows up on the org chart, not the EEG.
AI is breaking the hiring funnel at both ends at once
A Harvard Business Review piece argues the early hiring funnel now fails on both sides: AI-polished resumes have lost their signal at the top, and real-time assistance quietly games live interviews at the bottom. The result is a process that selects for performing the interview, not doing the job.
The cute delivery robot has become a sidewalk turf war
Pavement delivery robots have spread across US, UK, Japanese, South Korean and German cities, and the welcome is wearing thin. Toronto has banned them from sidewalks since 2021, San Francisco confines them to quieter streets, and a Chicago resident is now campaigning to suspend them citywide.
F5 buys SurePath AI to catch the AI tools employees never told IT about
F5 has acquired shadow-AI detection startup SurePath AI as the centrepiece of a new AI Security Platform. SurePath finds unsanctioned AI usage by watching network traffic rather than integrating with each app. Terms were not disclosed.
OpenAI gives enterprise admins a way to cap runaway agent credit spend
ChatGPT Enterprise now lets admins set credit limits per workspace, group and individual, and shows usage by user, product and model across ChatGPT and Codex. It is a quiet admission that seat-based pricing falls apart once staff run agents instead of chats.
MCP is going stateless, and it's deprecating Sampling to get there
The next Model Context Protocol spec drops the session handshake that pinned each client to one server. To get there it deprecates three original features, including Sampling, the hook that let a server borrow the client's own model.
Bayer's production agent system bets on 'harness engineering' over bigger models
Thoughtworks and Bayer have published a case study on PRINCE, a production agentic RAG system that mines decades of preclinical drug-safety studies. The lesson they draw is that reliability came from engineering around the model, not from the model itself.
A developer's rule: reject the AI's code if you cannot explain it
As coding agents make writing cheap, the bottleneck shifts to reviewing the diff. Vinicius Brasil says he often throws out everything the agent produced and starts again. The variable that changed between attempts was him, not the model.
150 near-identical AI books expose the 'you cannot detect AI' myth
Security researcher Michal Zalewski says the claim that AI text is statistically indistinguishable from human writing misses the point. Search Amazon for 100000 whys and you get roughly 150 near-identical children's books. The tell is not the prose, it is the sameness.
Anthropic's robodog test: Opus 4.7 beat last year's fastest humans by 20x
Anthropic re-ran Project Fetch, its experiment with an off-the-shelf robotic quadruped. Claude Opus 4.7, working with no human help, was about 20 times faster than the quickest human team from a year ago. It still cannot reliably nudge a beach ball.
Claude will now check your government ID, and the reason is agents
Anthropic is rolling out identity verification on Claude through KYC vendor Persona, asking for a government photo ID and a live selfie. The checks reach Free, Pro and Max users from 8 July. The trigger is not conversation, it is agents acting on your behalf.
Grok arrives on Amazon Bedrock, but enterprises are not switching
AWS has added xAI's Grok 4.3 to Bedrock at US$1.25 per million input tokens with a one-million-token context. The pricing is aggressive; the reported enterprise demand is not.
A new npm scanner targets malware that hunts for Claude and OpenAI keys
npm-scan, released this week, claims to catch supply-chain attacks that npm audit, Snyk and Socket miss, including packages built to steal AI provider keys. Its pitch leans on behavioural detection over CVE lookups.
The token-compression tool with 60k stars may be saving less than it claims
RTK, a Rust CLI that strips shell output before it reaches a coding agent, has passed 60,000 GitHub stars on a 60 to 90% savings pitch. A widely shared critique argues that figure measures the wrong thing.
Midjourney's new body scanner runs on tech it licensed from Butterfly Network
Midjourney has launched a healthcare arm built around a full-body scanner it says images you in under 60 seconds. The imaging silicon is not its own. It is licensed from Butterfly Network, whose shares jumped about 31% on the news.
One developer found 10,000 GitHub repos quietly serving the same Trojan
A developer documented 10,000 GitHub repositories distributing Trojan malware, all different contributors, none forks. They evade takedown by deleting and re-pushing the same commit every few hours, and the download links score zero on VirusTotal.
A new spec wants agents to discover tools the way search engines discover pages
The Agentic Resource Discovery spec (ARD) lets an AI client ask one question: which tool, Skill, MCP server or agent fits this task? It argues the bottleneck has moved from invocation to discovery.