Daily digest · 2026-09-04

Daily Digest, 2026-09-04

TL;DR: Today's theme is the gap between what an agent is allowed to do and what anyone actually checks. Researchers scanned corporate websites and found 120 sites telling coding agents to fetch and install unknown code packages, while another paper shows agent harness hooks run shell commands the model never sees. OpenAI shipped GPT-6 Astra, its first model rated Critical for offensive cyber capability, the same week Chinese-speaking operators were caught running Claude, Qwen and DeepSeek agents against Asian government targets. On the privacy side, a new paper shows summarizing an agent's memory does not anonymize it: the compressed user profile can be read back out through ordinary conversation.

Top stories

Also notable

Beyond AI