Morning Brief: Tuesday, September 1
Seventy-one feeds. Two weeks. 4,591 items reduced to what follows. (what we track, how we crawl, subscribe)
Tuesday concentrates on enterprise agent identity and boundaries. Four InfoWorld pieces land the day after Meta's inbox-deletion incident — agent identity standards, Broadcom on data-trust and boundary enforcement, AWS's cloud-migration toolkit, JetBrains shipping an MCP server in Compose Multiplatform. DoltLite ships built from 2,000 agent PRs.
The InfoWorld cluster is the vendor read on Monday's failure mode: the harness needs identity, boundaries, and standard protocols. The most honest headline of the four is "4 standards solve agent identity. None solves the harder question: Is it still the agent you approved?" — which names the gap between authentication and continuous authorization that Meta's incident made concrete. Schneier's "Hiding Prompt Injection in Legal Filing" (yesterday) puts the injection thread into a new adversarial surface: court documents that agents will read.
Top (5-7 min)
- 4 standards solve agent identity. None solves the harder question: Is it still the agent you approved?
- InfoWorld, 2026-09-01. Direct successor to Monday's Meta email-deletion incident. Names the gap the standards catalogue does not close: continuous authorization for a running agent, not just authentication at spawn.
- Broadcom says that enterprise AI agents need two things: Data they can trust and boundaries they can't cross
- InfoWorld, 2026-09-01. Vendor framing of the boundary problem from a security-adjacent incumbent. The two-things framing lands the same day as the identity-standards piece and reads as coordinated messaging from the enterprise-AI vendor bench.
- DoltLite: A SQLite fork with Git-style version control, built with 2k agent PRs
- HN, 2026-09-01. Concrete number on the enterprise-verification thread: a SQLite fork accepted 2,000 agent PRs. Extends the New Stack "commits doubled, verification did not" piece from Saturday with a specific project claiming to have absorbed that volume.
- A look at AWS's agentic toolkit for cloud migration
- InfoWorld, 2026-09-01. AWS ships an agentic wrapper for cloud migration workloads. Migration is the highest-stakes enterprise workflow to hand to an agent — the piece is the enterprise-vendor bench claiming the boundary story is now solvable in production.
- Compose Multiplatform 1.12.0 welcomes coding agents with MCP server
- InfoWorld, 2026-09-01. JetBrains ships MCP support in Compose Multiplatform. MCP is the protocol the identity-standards piece treats as one of the four surfaces — this is one of the concrete implementations landing in a mainstream IDE stack the same week.
- Hiding Prompt Injection in Legal Filing
- Schneier, 2026-08-31. Schneier picks up prompt injection embedded in court documents. New adversarial surface: filings that agents will process as input. Extends Willison and Embracethered on Auto Mode into a domain where the injected payload arrives via legal channels.
- Fal's H3 Max Live breaks the infinite videogen barrier
- Latent Space, 2026-09-01. Real-time video generation with no fixed clip length. Infra milestone — the interesting bit is that Fal (not one of the hyperscalers) shipped it first. Continues the neoclouds-vs- hyperscalers thread InfoWorld ran Sunday.
Themes this week
- Enterprise agent identity and boundaries
- InfoWorld: 4 standards solve agent identity (Tue), InfoWorld: Broadcom on data trust and boundaries (Tue), InfoWorld: AWS agentic migration toolkit (Tue), InfoWorld: Compose Multiplatform ships MCP (Tue), InfoWorld: Governance by design (Mon).
- Agent harness failures — injection widens
- Schneier: Hiding prompt injection in legal filing (Mon), HN: Meta researcher's AI agent deletes emails (Mon), Lobsters: Embracethered on Auto Mode injection (Sun), Simon Willison: Breaking Claude Code Opus 5 Auto Mode (Thu).
- Enterprise AI code volume vs verification
- HN: DoltLite built with 2k agent PRs (Tue), Slashdot: Amazon HR lead writes 100k lines (Mon), New Stack: Commits on GitHub doubled, verification did not (Sat).
- OpenAI as policy actor, not just vendor
- OpenAI: Supporting California's youth AI safety bill (Mon), OpenAI: Polimill Japan public AI infrastructure (Mon), OpenAI: Expanding access to AI with ChatGPT ads (Mon).
Scan (10 min)
- Tuesday feeds
- 4 standards solve agent identity. None solves the harder question, InfoWorld, 09-01
- Broadcom says enterprise AI agents need two things: data trust and boundaries, InfoWorld, 09-01
- A look at AWS's agentic toolkit for cloud migration, InfoWorld, 09-01
- Compose Multiplatform 1.12.0 welcomes coding agents with MCP server, InfoWorld, 09-01
- Why tech needs a new kind of English major, InfoWorld, 09-01
- DoltLite: A SQLite fork with Git-style version control, built with 2k agent PRs, HN, 09-01
- Fal's H3 Max Live breaks the infinite videogen barrier, Latent Space, 09-01
- Training a Misaligned Reward Seeker, Alignment Forum, 09-01
- Rewiring Democracy Series on The Renovator, Schneier, 09-01
- How engineered microbes could help feed the world's crops, MIT Tech Review, 09-01
- Apple shares 'shocking evidence' against former employee accused of stealing data for OpenAI, TechCrunch, 09-01
- U.S. Navy begins search for its first tranche of 'loyal wingman' uncrewed fighters, The Air Current, 09-01
- RotaryCell: Making an unmodified rotary phone work over LTE with an ESP32-S3, HN, 09-01
- 2004 RuneScape fit a multiplayer RPG into 56k dial-up, HN, 09-01
- The Robot Framework language, Lobsters, 09-01
- Coherence and orphan instance rules, Lobsters, 09-01
- HTML Browser Page Uses Display Pixel Clock EMI Leakage to Transmit VHF Morse Code, RTL-SDR, 09-01
- Monday carry — agent-harness widens
- Meta Security Researcher's AI Agent Accidentally Deleted Her Emails, HN, 08-31
- OpenAI To Cut Off AI Models For SpaceX-owned Cursor, Slashdot, 08-31
- Multikernel Linux Tree Released, Slashdot, 08-31
- Understanding ChatGPT Work, HN, 08-31
- Amazon's HR Lead Uses AI Tool to Write 100,000 Lines of Code, Slashdot, 08-31
- Hiding Prompt Injection in Legal Filing, Schneier, 08-31
- Is Someone Hacking DoD Refrigerators?, Schneier, 08-31
- A milestone in expanding access to AI, OpenAI, 08-31
- OpenAI supports California's bill to advance youth AI safety, OpenAI, 08-31
- Polimill builds Japan's next-generation public AI infrastructure, OpenAI, 08-31
- Introducing Adaptive Intelligence: Undermining the economics of every bot attack, Cloudflare, 08-31
- TimesFM-3: A zero-shot foundation model for multivariate forecasting, Google Research, 08-31
- Late-week carry — agents, memory, harness
- Our decision on Cursor following its acquisition by SpaceX, OpenAI, 08-29
- [AINews] OpenAI shuts off Cursor, Latent Space, 08-29
- Commits on GitHub have doubled in four months. Verification capacity has not., The New Stack, 08-29
- Breaking Claude Code Opus 5 Auto Mode, Simon Willison, 08-27
- Just a rumour of a bug is enough to find a security exploit, Simon Willison, 08-28
- Aider, Claude Code, and OpenClaw ran an identical model. Token use varied 70-fold., The New Stack, 08-27
Tail
- Enterprise agent vendors coordinate the answer
- Four InfoWorld pieces on Tuesday — identity standards, Broadcom on boundaries, AWS migration toolkit, JetBrains shipping MCP — read as coordinated vendor messaging the day after Meta's inbox-deletion incident. The most honest of the four is the identity-standards headline: four protocols solve authentication, none solves continuous authorization. That is the shape of the gap Monday's failure sat in.
- DoltLite quantifies the verification thread
- Saturday's New Stack piece said commits on GitHub doubled while verification capacity did not. Tuesday DoltHub says its SQLite fork was built with 2,000 agent PRs — a specific project claiming to have absorbed exactly that volume. The two frames are not contradictory: DoltHub's PRs were reviewed by a small human team, which is the constraint the New Stack piece named.
Feed silences (>72h since last item)
Sources that publish frequently but have gone quiet:
- Apple ML Research (4d) — last item 2026-08-28.
- ClickHouse (4d) — last item 2026-08-28.
- Hugging Face Blog (4d) — last item 2026-08-28.
- Nature Machine Intelligence (4d) — last item 2026-08-28.
- Netflix Tech Blog (4d) — last item 2026-08-28.
- BSD Now (5d) — last item 2026-08-27.
- GitHub Blog (5d) — last item 2026-08-27.
- Grafana Labs (5d) — last item 2026-08-27.
- Martin Fowler (5d) — last item 2026-08-27.
- cursor-blog (5d) — last item 2026-08-27.
- All Things Distributed (6d) — last item 2026-08-26.
- DuckDB (6d) — last item 2026-08-26.
- METR (6d) — last item 2026-08-26.
- Pluralistic (6d) — last item 2026-08-26.
- Pydantic (6d) — last item 2026-08-26.
- Terence Tao (6d) — last item 2026-08-26.
- Clojure releases (7d) — last item 2026-08-25.
- OCaml.org (7d) — last item 2026-08-25.
- FreeBSD Foundation (8d) — last item 2026-08-24.
- GitHub Engineering (8d) — last item 2026-08-24.
- Steve Yegge (8d) — last item 2026-08-24.
- Supabase (8d) — last item 2026-08-24.
- Ink & Switch (11d) — last item 2026-08-21.
- Citizen Lab (12d) — last item 2026-08-20.
- TigerBeetle (12d) — last item 2026-08-20.
- Antithesis (14d) — last item 2026-08-18.
- Hillel Wayne (14d) — last item 2026-08-18.
Build provenance
build: 2026-09-01 | crawler-sha: 34c428f (Walsh-Research/1.2, compliance v1.4) | feeds: 71 active | items-considered: 4591 (14d, incl. 2525 arxiv-cs-ai) | warehouse: 40946 items | published: 17