David Soden AI News

AI News Weekly

Intelligence  ·  Innovation  ·  Impact

ISSUE 36

Week of August 31, 2026

 

Executive Summary

The week's centrepiece was Unit 42's account of an enterprise breach carried out end to end by AI agents in under ten hours, without zero-days, ending with an 80-page audit left for the victim. Everything else read as a response to that. Broadcom, CrowdStrike and Okta launched agent identity and runtime control products, Palo Alto Networks raised guidance and bought its seventh company of the year, and three security and agent infrastructure startups raised fresh capital. Survey data pointed the other way: adoption is running well ahead of visibility, rollback capability and data quality, with most leaders reporting agents need more oversight than they save. Vendors also began selling outcomes rather than seats, and MCP settled in as the default connection layer.

 

$3.5 billion

NVIDIA convertible bond investment in MediaTek

 

$550 million

Wonderful Series C funding

 

10 hours

agentic ransomware breach duration

 
 
 

📌  This Week's Spotlight

AI agents ran a complete ransomware attack in under ten hours: Palo Alto Networks' Unit 42 documented an enterprise breach that agents completed in under ten hours, work the researchers say human red teams typically need about two weeks to finish. Entry came through a public API. Agents then ran reconnaissance, mapped the internal network, scraped code repositories for tokens, reached secrets management systems and took master admin credentials for root access, with specialised pivot agents validating access across cloud, identity, CI/CD, container and SaaS environments. One report counts over 50 MITRE ATT&CK techniques executed. One states no zero-day vulnerabilities were used, the speed and adaptation did the work. On completion, an agent left the victim an 80-page security audit listing the vulnerabilities it had exploited. Two of the accounts date the disclosure to 2 September 2026; the victim is unnamed.

The accounts differ on who was driving: two describe a human threat actor using frontier models and agentic attack frameworks, the third emphasises multiple purpose-built agents operating in parallel and adapting in real time rather than following scripts. The attacker hijacked CI/CD workflows to steal cloud keys and repurposed the victim's own cloud AI services, masking activity as legitimate traffic. Multi-party code review blocked a Terraform backdoor attempt during the incident. Unit 42's guidance is containment at machine speed: revoke credentials, freeze CI/CD pipelines and isolate cloud accounts simultaneously rather than sequentially, and treat AI as core infrastructure by inventorying every model endpoint, API key, MCP gateway and tool integration.

The context is a market already repricing around this risk: CrowdStrike's 2026 Threat Hunting Report says AI agent-triggered detections are rising 2.5 times faster than human-triggered ones, with one campaign sending nearly 200,000 model requests in two minutes. In the same week, Broadcom, CrowdStrike and Okta all announced agent identity and runtime control products, Palo Alto Networks raised guidance on AI-driven demand, and Rubrik Zero Labs found 88% of surveyed leaders cannot roll back agent actions without disrupting systems. The attack path ran through public APIs, code repositories, secrets stores and CI/CD pipelines that most enterprises already own. The controls being sold are the ones the incident says were missing.

 
 
 

🚀  01 / Major Product Launches & Technology Advances

Anthropic: Claude Fable 5.1 is generally available at roughly 25% below the cost of Fable 5, driven by lower cache read pricing, with reported savings up to 45% on complex tasks and Enterprise Frontier Safeguards offering zero data retention on customer-controlled cloud infrastructure. Claude Mythos 5.1 runs more permissive safeguards but is restricted to vetted US organisations through Cyber Verification and Life Sciences Verification programmes, with expansion planned and no date given. Anthropic also released the Model Hardware Standard as a research preview, letting agents discover and operate microscopes, liquid handlers, robotic arms and manufacturing equipment, and published blueprints for shopping and merchant agents covering catalogues, carts and checkout. The capability claims come from Anthropic's own testing, and the accountability frameworks for physical and purchasing actions have not arrived with the tooling.

Broadcom: At VMware Explore 2026 the company announced AgentMinder, VMware vDefend and VMware Avi Load Balancer for agentic AI on its Private AI Cloud, with no pricing disclosed for any of the three. AgentMinder treats an agent as an enterprise identity tied to a declared mission, intent and approved tool set, authorising each action at runtime and logging sessions through OpenTelemetry, with general availability given as 31 August 2026. vDefend adds automatic discovery of agentic components and shadow AI monitoring; Avi Load Balancer adds AI-aware load balancing and tool misuse prevention. Note that parts of the wider portfolio, including AI gateways in VCF Private AI Services and Tanzu Platform, are described as future capability, so buyers should ask for dates before committing.

CrowdStrike: Falcon Guardian launched at Fal.Con 2026 as an AI detection and response product, alongside Safe Mind, extending CrowdStrike's endpoint approach to AI agents with live inventory, runtime visibility and enforceable governance across endpoints, SaaS, cloud and browser. An expanded OpenAI partnership runs in two directions: Guardian will secure OpenAI's Codex agents, and GPT-5.6 Cyber will sit inside CrowdStrike's Frontier AI Readiness and Resilience service for authorised defensive use under expert supervision. No general availability date, pricing, customer count or independent benchmark accompanies either announcement, so the buying question is simply whether agent activity is inventoried at all today.

Google: Two open-source releases target measurable failure modes in agent engineering. EnvHarness, built with Washington University in St. Louis and UNC Chapel Hill, converts static agent benchmarks into environments that change as a policy trains, reporting a 9.0 point gain on out-of-distribution ALFWorld tasks and 9.8% fewer execution steps on SWE-bench Verified, with the practical limit that environments must be resettable. Mantis is an agentic harness for vulnerability identification, validation, reproduction and fixing, aimed at conventional AI code scanning where true-positive rates often fall below 7%; it analyses repository history and architecture rather than brute-force file scanning and cuts token usage by 85%. Separately, DeepMind's Koray Kavukcuoglu said Gemini is moving from chatbot to agent, citing Gemini 3.5 and naming Gmail, Sheets, Maps and Search.

MCP vendors: Beeline, GK Software, GovCore and Docusign all announced Model Context Protocol servers in the same window, and Docusign will open its server to all AI agents on 30 September. The shared design point is that agents inherit human permissions rather than bypassing them, with GovCore citing audited tool calls, alignment to 20 NIST 800-53 control families and data residency in the US or Canada, and Beeline keeping classification, pay equity and hiring decisions human-driven. None of the four accounts provides independent verification of these controls. The commercial significance is that MCP is becoming the default connection layer between systems of record and third-party agents, and the permission, audit and residency terms are being set now.

Genpact and Quiq: Genpact launched an agentic Record-to-Report suite for the financial close, with Journal Entry, Reconciliation and Intercompany modules, claiming up to 40% reduction in peak close effort and resolution of up to 99% of intercompany breaks in real time, with Tenneco piloting. Pricing is outcome-based rather than per seat or token, which shifts efficiency risk to the vendor but requires an agreed baseline and acceptance of anonymised cross-client learning on process data. Quiq extended its agentic assistants into live voice with Voice Assist, which can execute actions mid-call such as sending a tracking link without the human agent leaving the conversation. Neither set of performance figures has been independently verified.

 

📊  02 / Market & Economic Impact

Palo Alto Networks: Fiscal fourth-quarter revenue of $3.41 billion beat the $3.35 billion forecast and adjusted EPS of $1.02 beat 98 cents, with revenue up 34% year on year, though the company posted a net loss of $282 million against net income of $254 million a year earlier. Full-year guidance was raised to $14.10-$14.20 billion. CEO Nikesh Arora attributed demand to rising AI-driven attack risk and called AI a "long-term tailwind." The company also paid $500 million in cash and stock for Console, a two-year-old IT help desk automation startup valued at $157 million before the sale, in what TechCrunch counts as its seventh acquisition of 2026 alongside Chronosphere at $3.35 billion, CyberArk at $25 billion and Koi at $400 million. For customers on Cortex or Prisma, that pace of consolidation is a roadmap and renewal question, not just a market one.

HPE: Third-quarter results beat expectations on record orders and backlog, with networking revenue up 10% to $2.9 billion (orders up 36%) and Cloud and AI revenue up 25% to $9 billion, followed by a $3.5 billion inference-server contract with a hyperscale client. FY27 targets were set at 13%-17% revenue growth and free cash flow of at least $5 billion. Shares still fell 5.4% at Thursday's open. HPE flagged that the FY27 outlook reflects a shift toward AI revenue at lower gross margins, offset by operating expense control. Buyers negotiating AI infrastructure should read that as a vendor trading margin for volume.

Arm and the inference shift: Arm reported record Q1 fiscal 2027 revenue of $1.29 billion, up 22%, split $715 million royalty and $574 million licensing, with data-centre royalty revenue more than doubling and non-GAAP operating margin at 41.2%. The stock closed at $242.59 after selling off on possible smartphone royalty declines. At Hot Chips 2026, SambaNova argued decode now consumes 75%-97% of inference time because agentic workloads shift work from single answers to ongoing reasoning and tool calling. NVIDIA separately invested $3.5 billion in MediaTek convertible bonds around NVLink Fusion custom XPUs. The common thread is that supplier economics are repricing around inference rather than training.

Agentic AI funding: Three rounds landed in the same window. Huskeys raised $27 million led by Blackstone, taking total funding to $35 million, with strategic participation from Okta and Zscaler funds tied to integration partnerships. Acrab raised US$130 million from existing investors including Vertex Ventures SEA & India, on more than US$350 million raised cumulatively, with no revenue yet reported. Wonderful raised $550 million in a Series C led by Insight Partners at a $5 billion valuation, double its $2 billion mark six months earlier, with Salesforce investing for the first time. Elsewhere in the material, HiddenLayer is named at $100 million and AIR Security at $50 million. Capital is being priced on the premise that autonomous agents need identity, security and integration layers that current infrastructure does not provide.

Outcome-based pricing: Genpact launched its agentic Record-to-Report Suite sold on outcomes rather than seats or tokens, citing one client example that lowers cost per invoice from $5 to $2, and forecasting over $1 billion in contracts by 2026 on that basis. Globant's MuleSoft AI Pod is also priced against outcomes rather than hours or seats. The reporting describes outcome-based pricing as emerging but still rare at scale in enterprise software. It shifts efficiency risk to the vendor, but only if the buyer can agree a defensible baseline from its own current process.

Advertising returns: Google Ads changed how target-based bidding works for budget-limited campaigns, so algorithms now bid towards the set target regardless of prior overperformance. A campaign with a $10 target CPA delivering at $5 will drift towards $10 unless the target is lowered, converting banked efficiency into a spending threshold. In India, a year of real-world trials of agentic ad platforms produced efficiency gains in mid-funnel work such as bid management and pacing, with the most credible tests showing 14% incremental improvement, well below pitch estimates, and no strategic intelligence. The market is settling on supervised autonomy, with humans on high-impact decisions.

 

🤝  03 / Strategic Partnerships, M&A & Ecosystem Expansion

Palo Alto Networks: The company paid $500 million in cash and stock for Console, a two-year-old IT help desk automation startup founded in 2024 by Andrei Serban that had raised $29 million and carried a $157 million valuation before the sale, with the technology going into the Cortex platform. TechCrunch calls it the seventh acquisition of 2026, alongside Chronosphere at $3.35 billion and Koi at $400 million; the earnings coverage puts Chronosphere at nearly $3.4 billion and adds CyberArk at $25 billion without giving a count. CEO Nikesh Arora was an angel investor in Console. For customers already on Cortex or Prisma, the integration of IT service management, observability and identity into one stack will reshape the roadmap and the renewal conversation, and Console's nearest rival, Serval, is now valued at $1 billion.

CrowdStrike and OpenAI: The two companies expanded their partnership in both directions. OpenAI's Codex agents will be secured by CrowdStrike's Falcon Guardian, which provides live agent inventory, runtime visibility and enforceable governance across endpoints, SaaS, cloud and browser. In return, OpenAI's GPT-5.6 Cyber reasoning model goes into CrowdStrike's Frontier AI Readiness and Resilience Service for risk assessments, attack path analysis and remediation prioritisation, restricted to authorised defensive use under expert supervision. No general availability date, pricing or financial terms were disclosed, and neither the partnership announcements nor the Fal.Con launch of Guardian provide independent performance data or customer references.

Genesys: The vendor added Adobe, AWS, Deepgram, ElevenLabs, Meta, Salesforce, ServiceNow and Sierra to its Genesys Cloud Agentic Orchestration ecosystem, positioning the platform as an orchestration layer rather than a replacement for existing systems. Salesforce and ServiceNow bring Agent2Agent interoperability, Sierra and ElevenLabs agents run alongside Genesys Virtual Agents, AWS supplies foundation model access and Meta extends WhatsApp messaging and voice. Buyers should note an unresolved ownership question in the same reporting: one story lists Intercom Fin as a standalone option, another states Salesforce acquired Fin, formerly Intercom, for $3.6 billion, with no date given and no reconciliation between the two accounts. Confirm ownership before shortlisting.

Cloud providers and integrators: Four tie-ups landed in the same window. Tech Mahindra opened an AWS Agentic Process Transformation Centre of Excellence, whose first solution, Collections Guru, was deployed at Target Group in the UK for roughly 40% efficiency gains in arrears management. Hoxton Wealth joined AWS's Forward Deployed Engineering initiative, backed by a $1 billion investment that embeds AWS engineers with customer teams, with no contract value or measured result disclosed. Clearlake Capital, with $185 billion in assets, is giving portfolio companies access to Google Cloud's AI stack including Gemini Enterprise, following an existing OpenAI partnership supplying GPT-5.6 to over 50 portfolio companies and earlier deals with Databricks and West Monroe, so it is buying from several vendors rather than consolidating. Globant launched the MuleSoft AI Pod with outcome-linked pricing and claims of up to 80% of manual integration tasks automated. Only the Tech Mahindra announcement carries a named customer result.

NVIDIA and MediaTek: The two expanded their partnership around NVLink Fusion custom XPUs, with NVIDIA investing $3.5 billion in MediaTek convertible bonds. No date was given for the agreement. It sits alongside a broader repricing of silicon around inference rather than training, with SambaNova arguing at Hot Chips 2026 that decode now consumes 75% to 97% of model inference time because agentic workloads shift work from single answers to ongoing reasoning and tool calling.

Strategic investors in agent security: Three funding rounds came with commercial attachments rather than capital alone. Huskeys raised $27 million led by Blackstone, taking total funding to $35 million, with funds from Okta and Zscaler carrying strategic partnerships covering integration of security solutions; the company names TikTok, Legoland, Ro, Blackstone and Hugging Face as customers. Wonderful raised $550 million in a Series C led by Insight Partners at a $5 billion valuation, double its level six months earlier, with Salesforce investing for the first time as a strategic investor. Acrab raised US$130 million from existing investors including Vertex Ventures SEA & India, taking cumulative funding above US$350 million, and has not yet reported revenue. The common premise being funded is that autonomous agents need identity and security layers that current infrastructure does not provide.

 

the magazine

Inference Weekly Issue 36 cover

Inference Weekly  /  Issue 36

Read This Week as a Magazine.

Every story in this issue, laid out across 9 pages and designed to be read properly. Yours to keep and to share.

Download the PDF ↓
 

🏭  04 / Industry-Specific Deployment & Adoption

Genpact: The Record-to-Report Suite puts agentic AI into the financial close through three modules, Journal Entry, Reconciliation and Intercompany, with Genpact claiming up to a 40% reduction in peak close effort, first-pass reconciliation yields above 95% and resolution of up to 99% of intercompany breaks in real time. Tenneco is piloting it. The commercial structure is the notable part: Genpact sells outcomes rather than seats or tokens, with one cited example cutting a client's cost per invoice from $5 to $2, and forecasts over $1 billion in contracts on that basis. Two conditions apply. Humans still handle exceptions, so the figures describe assisted rather than autonomous close, and Genpact improves its agents using anonymised learning across clients, which finance and legal teams should examine before signing.

Tech Mahindra, Globant and Clearlake: Agentic AI is now being packaged as a delivery model rather than a product. Tech Mahindra opened an AWS Agentic Process Transformation Centre of Excellence covering telecom, healthcare, banking, retail and manufacturing, with its Collections Guru agent deployed at Target Group in the UK for roughly 40% efficiency gains in arrears management. Globant's MuleSoft AI Pod pairs AI agents with human experts for integration work, priced on outcomes rather than hours, claiming up to 80% of manual integration tasks automated. Clearlake Capital, with $185 billion in assets, is giving portfolio companies access to Google Cloud's AI stack, following an earlier OpenAI deal covering over 50 portfolio companies. Of these announcements, only Tech Mahindra's carries a named customer result; the rest are vendor figures.

Contact centres: Quiq launched Voice Assist, extending its agentic assistants into live calls with the ability to execute actions mid-conversation, such as sending a tracking link, without the human agent leaving the call. Genesys expanded its Cloud Agentic Orchestration ecosystem to include Adobe, AWS, Deepgram, ElevenLabs, Meta, Salesforce, ServiceNow and Sierra, positioning itself as an orchestration layer over existing systems. Salesforce was named a Leader in the 2026 IDC MarketScape for Agentic CCaaS. Two cautions for shortlists. Market ownership is moving, with one story reporting Salesforce acquired Fin, formerly Intercom, for $3.6 billion while another still lists Intercom Fin as standalone. And CMS Wire argues the binding constraint is content infrastructure: fragmented product information and policies lead agents to give confident but conflicting answers, so a content audit and escalation rules are prerequisites, not follow-ups.

MCP servers in systems of record: Four vendors opened Model Context Protocol access within the same week. Beeline launched Beeline MCP for workforce data across sourcing, engagement and compliance, keeping classification, pay equity and hiring decisions human-driven. GK Software announced GK Agentic for retail backends at NRF Europe. GovCore made GovCore MCP generally available with 22 tools covering licensing, renewals, enforcement and payment reconciliation, aligned to 20 NIST 800-53 control families with data held in the US or Canada. Docusign opens its MCP Server to all AI agents on 30 September, naming Claude, ChatGPT, Gemini, Copilot and Slack as clients. The shared design claim is that agents inherit human permissions rather than bypassing them, though none of the announcements carries independent verification of those controls.

Adoption surveys: The published numbers do not agree and the definitions behind them are not reconciled. A recent MIT survey puts agent adoption at 35% with a further 44% planning to adopt; McKinsey's 2026 Global Survey says 88% use AI in at least one function but only about a third have scaled enterprise-wide; KPMG UAE reports 97% of UAE firms with agents in workflows. Returns are narrower than adoption: DevPro Journal reports only 16% to 30% of companies seeing productivity, time-to-market or customer experience gains, and Rubrik Zero Labs found over 80% of more than 1,600 IT and security leaders say agents require more manual oversight than the efficiency they provide. Sector readiness is uneven, with nearly 75% of manufacturers expecting autonomous deployment within two years against 20% with mature governance, and Validity finding 75% of marketers naming data integration and quality as the biggest obstacle while only 32% fund it.

 

⚖️  05 / Regulatory, Policy & Risk Insights

Palo Alto Networks Unit 42: Researchers documented an enterprise breach in which AI agents completed reconnaissance, network mapping, repository scraping, secrets access and master admin credential theft in under ten hours, work human red teams are said to need about two weeks to finish, with over 50 MITRE ATT&CK techniques executed and no zero-days used. Unit 42's guidance is containment at machine speed, revoking credentials, freezing CI/CD pipelines and isolating cloud accounts simultaneously rather than sequentially, plus an inventory of every model endpoint, API key, MCP gateway and tool integration under rate limits and least privilege. Multi-party code review blocked a Terraform backdoor during the incident, which makes it the one control with evidence behind it in this account.

Governance and control surveys: Rubrik Zero Labs, surveying more than 1,600 IT and security leaders, reports 86% expect AI agents to outpace their security measures within a year, only 23% claim full visibility over agents (a figure the report itself calls likely overstated), and 88% cannot roll back agent actions without disrupting systems. In manufacturing, nearly 75% expect autonomous deployment within two years while only 20% have mature governance. KPMG UAE reports 26% able to enforce AI security strategies, and Solo.io cites 86% of enterprises without enforced AI identity access policies. The consistent finding is that rollback capability and agent visibility lag deployment, and those are the controls that determine whether an autonomous action is recoverable.

Audit trails and traceability: Brian Kuan's open-source halo-record writes agent actions, tool calls, model calls, data accesses and approvals to an append-only hash-chained file, with secrets and personal data redacted, plugging into OpenTelemetry and LangChain. The stated limit is important: the chain proves nothing was altered after writing but cannot prove nothing is missing, which is why an independent witness service is proposed. Adoption pressure is coming from the AIUC-1 standard and insurance requirements. The Agentic Traceability and Testing Handbook, published 31 August 2026, maps AI-assisted verification to DO-178C, ISO 26262 and IEC 62304, indicating that regulated-sector evidence requirements are being written around the runtime rather than the model.

Anthropic: Mythos 5.1 is restricted to vetted US organisations through Cyber Verification and Life Sciences Verification programmes, with expansion planned but no date given, while EU AI Act compliance is covered by output watermarking and a detection API. Separately, the Model Hardware Standard research preview lets agents operate microscopes, liquid handlers and robotic arms, and published blueprints cover shopping and merchant agents with guardrails constraining pricing to real catalogue data. The accountability position is unresolved: IBM's Kaoutar El Maghraoui notes physical errors differ from software errors, advocacy groups raise surveillance and personalised pricing risks, and experts say merchants have no framework for disputed AI-generated purchases.

MCP server providers: Beeline, GK Software, GovCore and Docusign all announced Model Context Protocol servers in the same window, with Docusign opening its server to all AI agents on 30 September. The shared claim is that agents inherit human permissions rather than bypassing them. GovCore states audited tool calls, full audit trails, alignment to 20 NIST 800-53 control families and data residency in the US or Canada; Beeline keeps classification, pay equity and hiring decisions human-driven. None of the accounts provides independent verification of these controls, and the permission, audit and data-residency terms for the connection layer between systems of record and third-party agents are being set now.

Google Ads: Target-based bidding for budget-limited campaigns now bids more aggressively to reach the set ROAS or CPA target regardless of prior overperformance, so a campaign delivering at $5 against a $10 target CPA will drift towards $10 unless the advertiser lowers the target. Earned efficiency becomes a spending threshold rather than a ceiling. Because the platform controls the bidding rules, the signals, the inventory and the metrics, autonomous buying systems cannot be assumed aligned with the buyer. Indian trials of agentic ad platforms found the most credible tests delivered 14% incremental improvement, well below vendor pitches, and the pattern settling there is supervised autonomy with independent baselines and incrementality testing held outside platform reporting.

 

🔐  06 / Security, Trust & Governance

Palo Alto Networks Unit 42: Researchers documented an enterprise breach completed in under ten hours, work they say human red teams typically need about two weeks to finish, with two accounts dating the disclosure to 2 September 2026. Entry came through a public API, after which AI agents ran reconnaissance, scraped code repositories for tokens, reached secrets management systems and took master admin credentials, executing over 50 MITRE ATT&CK techniques with no zero-days. An agent then left the victim an 80-page audit of the vulnerabilities it had exploited. Unit 42 advises containment at machine speed, revoking credentials, freezing CI/CD pipelines and isolating cloud accounts simultaneously rather than in sequence, plus an inventory of every model endpoint, API key, MCP gateway and tool integration. The accounts differ on whether this was a human operator using frontier models or multiple purpose-built agents adapting in real time, and CrowdStrike's 2026 Threat Hunting Report separately reports AI agent-triggered detections rising 2.5 times faster than human-triggered ones.

Surveys on governance readiness: Deployment is running ahead of the controls. Rubrik Zero Labs, surveying more than 1,600 IT and security leaders, found 86% expect AI agents to outpace their security measures within a year, only 23% claim full visibility over agents (a figure the report itself calls likely overstated), and 88% cannot roll back agent actions without disrupting systems. In manufacturing, nearly 75% expect autonomous deployment within two years while only 20% have mature governance. KPMG UAE reports 26% can enforce AI security strategies. Solo.io cites 86% of enterprises lacking enforced AI identity access policies. The recurring gap is not model capability but visibility and reversibility, the two controls that determine whether an agent's mistake is recoverable.

Broadcom and CrowdStrike: Both are selling agent identity and runtime control as platform features rather than separate security purchases. Broadcom's AgentMinder, announced at VMware Explore 2026 with general availability given as 31 August 2026, treats an agent as an enterprise identity tied to a declared mission and approved tool set, authorising each action at runtime and logging sessions through OpenTelemetry, alongside vDefend for shadow AI monitoring and Avi Load Balancer for tool misuse prevention. CrowdStrike launched Falcon Guardian at Fal.Con 2026 for agent inventory and runtime control, and expanded its OpenAI partnership so Codex agents are secured by Guardian and GPT-5.6 Cyber runs inside CrowdStrike's FAIRR service. Neither vendor has published pricing, benchmarks or customer references, and parts of Broadcom's portfolio, including AI gateways in VCF Private AI Services and Tanzu Platform, are described as future capability. Ask for dates before committing.

Audit trails and traceability: Brian Kuan released halo-record, an open-source Python package that writes every agent tool call, model call, data access and approval to an append-only file where each line carries a hash of the line before it, making edits or reordering detectable. Kuan states the limit openly: the chain proves nothing was altered after writing, not that nothing is missing, which is why he proposes an independent witness service holding periodic counts and hashes. Two engineering arguments landed the same week. Itamar Syn-Hershko of NeverBlink AI argues databases cannot get a shadow mode because schema changes and migrations are irreversible, and proposes a five-level autonomy ladder. Dr. Aditya Vikram Kashyap names the agentic commit boundary, the point at which a proposed action becomes a committed external change, citing benchmarks showing task success rates often under 50% and stability across repeat attempts below 25%. The Agentic Traceability and Testing Handbook, published 31 August 2026, maps AI-assisted verification to DO-178C, ISO 26262 and IEC 62304.

MCP server launches: Beeline, GK Software, GovCore and Docusign all announced Model Context Protocol servers in the same window, with Docusign opening its server to all AI agents on 30 September. The shared design claim is that agents inherit human permissions rather than bypassing them. GovCore says agencies choose which models, tools and workflows are active, with audited tool calls and alignment to 20 NIST 800-53 control families, and that regulatory data stays in the US or Canada. Beeline says high-stakes decisions on classification, pay equity and hiring remain human-driven. None of the four announcements carries independent verification of these controls. MCP is becoming the default connection layer between systems of record and third-party agents, which means permission, audit and data-residency terms are being set now, in contracts signed this quarter.

Agent security funding: Investors are backing the premise that current infrastructure cannot govern autonomous agents. Huskeys, an Israeli cybersecurity firm, raised $27 million led by Blackstone, taking total funding to $35 million, with strategic investments from Okta and Zscaler that carry integration partnerships. CEO Itai Gafni argues the web application firewall layer has been largely unchanged for nearly 30 years and needs an agentic layer with new identity infrastructure; named customers include TikTok, Blackstone and Hugging Face. Elsewhere in the market, HiddenLayer raised $100 million and AIR Security $50 million, while Palo Alto Networks continued a seven-acquisition year including Console at $500 million, CyberArk at $25 billion and Chronosphere at roughly $3.4 billion. For buyers already on these platforms, consolidation on that scale will reshape the roadmap and the renewal conversation.

 

Prefer to read it as a magazine? Issue 36 is a 9-page PDF.

Download ↓
 

🛒  07 / Marketing, Commerce & Consumer Trends

Google Ads: Google has changed how target-based bidding works for budget-limited campaigns, so algorithms now bid more aggressively towards the set ROAS or CPA target regardless of prior overperformance. A campaign with a $10 target CPA that had been delivering at $5 will drift towards $10 unless the advertiser lowers the target, converting banked efficiency into a spending threshold rather than a ceiling. No date is given for the change. The account notes that Google earns more when advertisers spend more, and that Meta and TikTok face the same tension between advertiser return and shareholder growth, with Meta's most recent quarter showing rising revenue and rising costs driven by AI investment. The proposed remedy is independent baselines held outside platform reporting, media tied back to business economics and explicit governance over automated buying.

Indian AdTech: A year after startups raised significant investment on promises of autonomous planning, buying, optimisation and reporting with minimal human input, real-world trials show efficiency gains in mid-funnel work such as bid management, pacing and budget reallocation, producing modest CPA improvements largely by cutting human lag, but no genuine strategic intelligence. The most credible tests showed 14% incremental improvement, well below pitch estimates, and AI often optimised narrowly for the assigned metric at the expense of brand objectives. The settling pattern is supervised autonomy, with humans on high-impact decisions and AI on repetitive low-risk tasks. Performance held up in high-transaction, data-rich categories such as quick commerce, subscription apps and fintech, and was weaker in considered-purchase sectors including automobiles and real estate.

Anthropic: The company published blueprints for Claude-based shopping and merchant agents covering catalogues, carts, checkout, preference databases and purchase histories, with guardrails constraining pricing to real catalogue data and blocking manipulative upselling. Consumer appetite is unsettled: a Gartner survey found 11% willing to let AI make purchases, while an Accenture survey found 74% comfortable with routine tasks and 32% with partial purchase decisions. Advocacy groups raise surveillance and personalised pricing risks, and experts warn merchants lack frameworks for disputed AI-generated purchases. A Sciences Po seminar on 11 September 2026 examines agent-initiated commerce including Amazon's Buy for Me, Walmart/OpenAI Instant Checkout and Visa Intelligent Commerce. The fraud and dispute gap is the item to resolve before deployment.

Contact centre platforms: Quiq launched Voice Assist, extending its agentic AI Assistants into live calls with real-time guidance and mid-call actions such as sending a tracking link or gift voucher on the same thread. Genesys expanded its Cloud Agentic Orchestration ecosystem with Adobe, AWS, Deepgram, ElevenLabs, Meta, Salesforce, ServiceNow and Sierra, positioning itself as an orchestration layer over existing systems. Salesforce was named a Leader in the 2026 IDC MarketScape for Worldwide Agentic CCaaS Platforms, and one story states Salesforce acquired Fin, formerly Intercom, for $3.6 billion, while a separate survey still lists Intercom Fin as a standalone option. Buyers shortlisting platforms should confirm ownership before signing, and note that vendor performance figures vary in basis: 83% automated resolution at Aissist.io, up to 80% of conversations at Salesforce and a 20% reduction in agent conversation time at Quiq.

Content and CRM data: CMS Wire argues the binding constraint on customer-facing agents is content infrastructure rather than the model, because fragmented product information, policies and claims lead agents to present conflicting or outdated answers with confidence and without the judgement to escalate. The recommended pre-scale checks are a content audit naming authoritative sources per category, drift detection through expiration dates and review triggers, and risk-based escalation for legal, financial and safety topics. Validity's survey of 500 global marketers reinforces the point: 25.6% rate CRM data 76-100% complete and accurate, 62% report direct revenue loss from data quality, and 75% name data integration and quality as the biggest challenge for agentic AI, yet only 32% prioritise data quality, unification and governance in AI investment. Some 44.7% let AI operate without human review.

Fobi AI: Fobi launched AgenticBrain, a conversational platform that connects to existing enterprise systems and lets customers search, book, modify orders, authenticate, track and request services through channels including WhatsApp and iMessage, with persistent memory retaining customer history and preferences. Target sectors are travel, hospitality, retail, financial services, telecommunications, healthcare, utilities and government. The announcement carries no launch date, pricing, named customers or named executive, and no independent verification of its data sovereignty or agent-to-agent transaction claims. For digital channel owners, this is a launch notice only, and evaluation rests on references and technical due diligence.

 

🎓  08 / Education & Workforce Development

Genpact: the Record-to-Report Suite is sold on efficiency, but the vendor's own framing puts role redesign at the centre of it. Genpact describes finance staff moving from processors to supervisors and exception handlers, supported by reskilling, and its material states that AI contextual awareness remains limited so humans still handle exceptions. The claimed 40% reduction in peak close effort and 99% real-time resolution of intercompany breaks therefore describe an assisted close, not an autonomous one. Finance leaders signing an outcome-based contract are also committing to a staffing model change, and should plan the supervisor and exception-handler capability before the savings are booked.

Workforce exposure to agents: SDxCentral cites IDC forecasting that 40% of Global 2000 job roles will involve working with AI agents by the end of this year. Set against that, Rubrik Zero Labs, surveying more than 1,600 IT and security leaders, found over 80% say AI agents require more manual oversight than the efficiency they provide, and 88% cannot roll back agent actions without disrupting systems. The practical reading for HR and operations leaders is that agent deployment is creating supervision work rather than removing headcount, and that the supervision role is currently undefined in most organisations.

Hoxton Wealth and AWS: Hoxton has partnered with AWS under its Forward Deployed Engineering initiative, backed by a $1 billion investment that embeds AWS engineers with customer teams to co-develop and deploy agentic AI within days. Hoxton CTO Mansel Oliver cited an internal knowledge base intended to democratise expertise currently held by senior staff, alongside AI-generated client reports to lift adviser productivity. AWS director Mark Jopling said the aim is to leave Hoxton self-sufficient. No contract value, timeline or measured result is given, so the knowledge transfer commitment is the item to test in the contract.

Wonderful: the Israeli-Dutch company raised $550 million in a Series C led by Insight Partners at a $5 billion valuation, double its level six months earlier, and employs 650 staff across 35 markets. Its differentiator is a forward-deployed engineer model, where senior technical staff embed in customer environments and hand control back over time, aimed at banking, telecommunications, healthcare, utilities, insurance and retail. The reporting notes the scalability of this engineer-heavy model remains uncertain and that agentic deployments still need human intervention. Buyers relying on embedded vendor engineers should agree in writing when and how internal teams take over.

Beeline: Beeline MCP gives AI agents a single governed connection to workforce data across sourcing, engagement and compliance, with agents inheriting human permissions through identity verification and role-based access. Beeline states that high-stakes decisions on worker classification, pay equity and hiring remain human-driven. The company reports over 450 customers and $1 trillion in managed workforce spend, so the permission model it sets here will shape how contingent workforce data is exposed to third-party agents. The story provides no independent verification of those controls.

Skills programmes reported by headline only: three items appeared in this week's coverage without accompanying detail, so they carry no verified figures. FinTech Magazine reported on Lloyds investing £100m in AI, skills and careers. Oracle published a post on new AI-powered learning experiences through Oracle University. Wells Fargo listed a Software Engineering Senior Manager role covering GenAI and agentic AI in its fraud and claims technology domain. Taken together they indicate large financial institutions are funding agentic AI skills internally, but none of the three can be relied on for numbers or timelines until the underlying material is reviewed.

 

🎯  09 / Key Takeaways & Strategic Guidance

The attack surface moved before the controls did: Unit 42's account of an agent-driven breach completed in under ten hours, against roughly two weeks for a human red team, is the week's hard data point. No zero-days were used. The path ran through a public API, code repositories, secrets stores and CI/CD pipelines, all of which the enterprise already owns, and the recommended response is simultaneous containment rather than sequential. That timeline is not compatible with a ticket queue. CrowdStrike's finding that agent-triggered detections are rising 2.5 times faster than human-triggered ones points the same way. If your incident runbook still assumes hours of human decision time, this is the week to test it.

Vendors are selling agent identity as platform, not product: Broadcom's AgentMinder treats an agent as an enterprise identity with a declared mission and approved tool set, authorising each action at runtime. CrowdStrike's Falcon Guardian extends endpoint detection to agent activity, with OpenAI's Codex agents as the first named subject. Okta shipped Agent SSO, and Huskeys raised $27 million with strategic investment from Okta and Zscaler on the argument that autonomous agents need new identity infrastructure. Separately, Beeline, GK Software, GovCore and Docusign all opened MCP servers, with permission inheritance, audit trails and data residency terms being written now. The buying decision is whether to consolidate agent governance into the stack that already runs the infrastructure, or hold it separate. Note that parts of Broadcom's portfolio, including AI gateways in VCF Private AI Services and Tanzu Platform, are described as future capability. Ask for dates.

Adoption is running ahead of recoverability: The survey numbers do not agree on adoption, from 35% in one MIT figure to 88% in McKinsey's, and the definitions are not reconciled. The governance numbers are more consistent and more useful. Rubrik found over 80% of 1,600 IT and security leaders say agents require more manual oversight than the efficiency they provide, only 23% claim full visibility, and 88% cannot roll back agent actions without disrupting systems. Kashyap cites task success rates often below 50% and stability across repeat attempts below 25%. Validity found only 25.6% of marketers rate CRM data as 76-100% complete and accurate, while 44.7% let AI operate without human review. The practical test before any production sign-off is not whether the agent works, but whether you can see what it did and undo it.

Watch the pricing, and treat vendor figures as unverified: Genpact is selling record-to-report outcomes rather than seats, forecasting over $1 billion in such contracts and citing a fall from $5 to $2 cost per invoice, but its 40% and 99% claims describe assisted rather than autonomous close, and it improves agents using anonymised learning across clients. Globant's MuleSoft AI Pod is also outcome-priced, with all figures self-supplied. Of the four services announcements, only Tech Mahindra's Collections Guru at Target Group carries a named customer result. On the demand side, India's AdTech trials produced 14% incremental improvement against far larger pitch estimates, and Google's bidding change now converts banked efficiency into a spending floor unless targets are reset. Fobi's AgenticBrain and Change Agents' Catch-Up are announcements with no customers, pricing or performance data attached. The pattern across all of it: demand a defensible baseline measured on your own process, and independent evidence outside the vendor's reporting.

 
 
 

📋  Recommended Actions

Governance

Test whether you can roll back an agent action this week, since Rubrik Zero Labs found 88% of 1,600 IT and security leaders cannot do so without disrupting systems and only 23% claim full agent visibility, a figure the report itself calls overstated.

Investment

Fund agent inventory and runtime authorisation before more pilots, using what CrowdStrike Falcon Guardian, Broadcom AgentMinder and Brian Kuan's open-source halo-record now offer, and price AI capacity around inference, which SambaNova puts at 75% to 97% of model time.

Focus

Stop scaling contact centre and marketing agents until content and data foundations hold, given Validity found only 25.6% of marketers rate CRM data 76-100% accurate and India's AdTech trials returned 14% incremental improvement against far larger vendor claims.

Partnerships

Demand named customer results before signing, since only Tech Mahindra's Collections Guru at Target Group carried one this week, and confirm ownership on shortlists after the reported Salesforce acquisition of Fin and Palo Alto's seventh 2026 deal, Console at $500 million.

Compliance

Review MCP connection terms now that Beeline, GK Software, GovCore and Docusign, whose server opens to all agents on 30 September, are setting permission, audit and data-residency defaults, and require evidence of the controls each vendor claims, as none is independently verified.

 
 

The Whole Issue, Page by Page

Take Inference Weekly 36 With You.

Page 1Page 2Page 3Page 4Page 5Page 6Page 7Page 8Page 9

Read it, keep it, forward it to your team. No sign-up, no gate.

Download Issue 36 ↓
 
 

Stay Curious  ·  Stay Building  ·  Stay Ahead

AI News Weekly  ·  davidsoden.com

Stay Ahead of the AI Curve

Get curated AI news, enterprise insights, and strategic guidance delivered weekly. Join the leaders who read AI News Weekly.

Subscribe Now