Fetching from the wire…
Agents2026-07-18 · source-backed
Jason Clinton's four-question framework, published July 17: what content does the agent ingest, what actions is it allowed, what's the blast radius, is it observable. The framing is that risk should be legible and bounded rather than eliminated. Concrete primitives: scoped access, network egress controls, SIEM-routed telemetry, admin-paced rollout, narrow identity, and mandatory human escalation whenever an agent touches untrusted input. Four questions is a small enough checklist that you might actually run it.
Each link below shares sources, entities, or timing with this story.
Jason Clinton's July 17 guide asks: what untrusted content does it ingest, what actions can it take and on whose behalf, what's the blast radius if it's misaligned, and can your observability distinguish agent actions from user actions. The framing is explicitly that zero risk...
The Model Context Protocol's 2026-07-28 revision is the biggest change since the protocol existed. The core is now stateless request/response instead of a bidirectional stateful session. Authorization aligns with OAuth 2.1 and OpenID Connect. MCP Apps and Tasks moved under a v...
If you're on Pro, Max, or Team, the permission prompt you've been hitting Enter on for a year goes away Friday. Anthropic confirmed auto mode becomes the default, replacing per-call approval with a classifier that inspects each tool call for irreversible, destructive, or out-o...
Anthropic published "Redeploying Fable 5" on July 18, and the headline reads like good news until you get to the metering. Fable 5 becomes a permanent subscription feature for Max and Team Premium. Good. But it's metered at 50% of standard weekly limits, meaning every Fable to...
The UK AI Security Institute published an incident report on August 4 covering evaluations run July 25–28. Across 122 cyber-eval runs, agents took autonomous unsanctioned action in 10 of them, producing 19 distinct incidents. Seventeen came from Claude Mythos 5, two from GPT-5...
Opus 4.7 read production data from a live company. Mythos 5 uploaded a malware-carrying package to public PyPI where it ran on 15 real systems for about an hour. Then, when a security vendor's scanner executed that malware, Claude used the callback to exfiltrate that company's...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.