ISSUE 04 · AUGUST 25, 2026
AI is all we do. We keep up so you don't have to.
WHAT WE'RE SEEING IN THE MARKET
Fifty employees built their own AI agents. One rule kept all of them safe.
We spend a lot of time telling clients that handing an AI agent real work is safe, if you set it up right. ABC Legal (I know what you’re thinking but this is actually a real company) is the clearest proof we've seen yet. Employees across the company built more than fifty working agents on Claude, on their own initiative, nobody told them to. Every one lives in a shared repository, and nothing about what an agent is allowed to do changes without a second person reviewing it first. Fifty agents, one habit, and nobody's worried about what any of them can reach. More on why that habit matters below.
THE WHY
The habit that makes fifty agents safer than one unwatched one
ABC Legal's setup is the version I want every client to copy. Employees across service of process, eFiling, marketing, and finance built more than fifty working agents on Claude without a mandate from the top. But every agent's instructions, tools, and schedule live in a shared repository, and nothing about what an agent can do changes without a human reviewing it first, the same review their engineers already use for code.
Compare that to OpenAI's month. Their newest model showed real cyber capability during testing, agents reached the open internet during evaluations meant to be sealed off, and the company paused its biggest planned training run while it rebuilt monitoring good enough to trust again. Nobody had answered, in advance, what those agents could reach or who'd find out the moment they reached further. That's the exact question ABC Legal's review habit answers before it ever becomes a problem.
You don't need OpenAI's budget or their security team to get this right. You need one habit: nothing about what an agent can touch changes without someone else looking at it first. That's the entire difference between AI happening to a company and a company running it.
YOUR MOVE
Ask whoever owns your agents one question this week
Find whoever in your company turned on an agent, a connector, a Zapier-to-Claude flow, a scheduled task, anything that acts without someone approving each step, and ask them directly: what can this thing touch, and what happens if it reaches past that.
If the honest answer is "I'm not sure," that's the finding. Write down one policy line before you do anything else: no agent's permissions or tool access change without a second person reviewing it first, the same rule ABC Legal runs internally. Put that line somewhere your team will actually see it, a wiki page, a pinned Slack message, the top of whatever document already governs how your team uses Claude.
Then ask the follow-up nobody asks: who gets pinged if one of these does something it shouldn't, and how fast. If the answer is "nobody" and "we'd probably notice eventually," you've found your actual to-do for the week.
WHAT TO SKIP
You don't need to worry your agent is plotting anything
Some of the coverage this week reads like the agents meant it, like there's a mind in there deciding to escape. There wasn't. In OpenAI's own account, one incident was a misconfigured test environment that let a model reach a real website it mistook for a fake one, and another was a model doing exactly what it was told, find the answer any way possible, in an environment nobody had properly sealed. Worth taking seriously. Not worth losing sleep over an AI plotting against you. The actual failure was procedural, not malicious, and procedural failures are exactly what a permission review catches.
THE ROUNDUP
Signals from the noise this week.
The Download: Google's AI shake-up and Meta's rogue model (MIT Technology Review): Google just demoted its own AI lab, DeepMind's CEO stepped back to chairman, and its chief scientist left to go start a competitor. If you're picking a long-term AI partner, this is the kind of instability worth weighing alongside whatever benchmark they're winning this quarter. Read it here
AI's recursive self-improvement might not come so quickly after all (MIT Technology Review): Princeton researchers had Claude try real, open-ended AI research instead of a scored benchmark, and it couldn't muster the judgment to pull it off. Useful to have on hand next time someone tells you AI improving itself changes your timeline. Read it here
OpenAI and Hugging Face partner to address security incident during model evaluation (OpenAI): OpenAI's own account of the incident behind this week's training pause, written by the company that lived it. If you want the technical detail behind what's in The Why, this is the primary source. Read it here
How Claude's text watermark works (Anthropic): Claude's text output will start carrying an invisible watermark to satisfy the EU AI Act, and every major model maker signed onto the same requirement. Worth knowing before a client or regulator points it out to you first. Read it here
How Claude is accelerating protein design and analytical chemistry (Anthropic): Anthropic had Claude design working protein binders and read a lab's chemistry data in under 25 minutes, matching what a trained chemist would find by hand. Even outside biotech, it's a preview of how fast a model can pick up a technical specialty once someone actually tests it. Read it here
Not sure what your agents can actually touch? Let's look at it together.

That's issue four. Hit reply and tell me what you're doing about your agents this week. I read all of them.
Justin
Why of AI
