Fetching from the wire…
Agents2026-09-17 · source-backed
arXiv 2609.18820 names this Compositional Policy Violations, and the argument is an impossibility result rather than an accuracy complaint. Referral thresholds, authority limits and review requirements are properties of a whole execution; agent governance today is almost entirely step-scoped input-output classifiers, per-turn rails and span-level evaluators. A predicate over one step cannot evaluate a property that step doesn't determine, so improving monitor accuracy cannot detect this class at all. The taxonomy is Authority Creep, Threshold Laundering, Cumulative Sum Violation and Context Collapse, and the proposed fix recomputes guarded quantities from raw provenance over complete traces. If you've been buying per-call guardrails and assuming they compose, they don't.
Each link below shares sources, entities, or timing with this story.
Li, Huo, and Johnson show that one-way message flow between agents produces neither mimicry nor solo behavior but an entirely novel dynamical state, at identical temperature settings. It's conceptual rather than quantitative, but the implication for orchestrator-worker fan-out...
Thirteen authors ran a generational genetic algorithm over specialized agents that separately handle mechanistic argument, assumption reconsideration, and evidence and testability assessment (arXiv 2609.15938). Evaluated against DepMap and Open Targets across 34 cancer types,...
On a verifiable protein-function characterization task routed across tools, model choice swamped federation topology, RL-versus-LLM harness, and prompt expertise: Opus at roughly 92 to 94%, o4-mini at 40 to 50%. Federation across institutional boundaries cost almost nothing (a...
When an agent consolidates an external observation into long-term memory, attach platform-controlled metadata recording the source's trust level, then gate tool execution by matching action risk against supporting-memory authority. Laundered memories hit a 1.000 attack success...
The July 23 benchmark tests LangChain, LlamaIndex and Vectara agents across 580 scenarios in six domains. Max accuracy 74.8%, with two distinct failure regimes: stronger models under-utilize tools while weaker models misselect and over-call them. One mitigation strategy cannot...
VILA-Lab published a systematic teardown of Claude Code's TypeScript source on arXiv (2604.14228), and the headline number stopped me cold: 98.4% of the codebase is deterministic operational infrastructure. The AI decision logic is 1.6% of the system. I've been building my own...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.