Signals

What actually moved, and how far I would trust it

A daily sweep across eight domains. Every item here has been traced to the issuing body's own text or corroborated by two independent reports — anything weaker is tracked privately until it clears the bar, and the count of what is being held appears at the foot of this page.

Current as of 2026-08-04.

Physical AI & digital twins

Corroborated

The industrial robotics simulation substrate keeps consolidating onto a single vendor stack

FANUC, ABB, KUKA and Yaskawa are all validating on NVIDIA Omniverse and Isaac Sim, and the tooling chain around it is closing: ABB is folding Omniverse into RobotStudio, and PTC is building a CAD-to-OpenUSD path from Onshape into Isaac Sim. For any deployer, the simulator has quietly become a dependency inside the safety case, and almost nobody has written it in as one.

This extends rather than changes the picture already argued in 'Two million robots are being validated in simulation'. The new element is the CAD-side bridge, which shortens the path from design to validated policy and therefore shortens the window in which a fidelity assumption goes unexamined.

NVIDIA newsroom — robotics leaders announcement · Asotech — GTC 2026 analysis (independent)

Agentic AI

Primary source

Microsoft's Agent Framework Harness shipped stable with standing tool-approval and heuristic auto-approval on by default

Read the capability list as a governance document and it is remarkable. The harness ships tool approval with 'don't ask again' standing rules plus heuristic auto-approval, enabled by default. That is a permission model being set at the framework layer, by a default, rather than by the institution deploying it. If your agents run on this, somebody has already answered what they may do — and it was not you.

Released 22 July 2026, stable, Python and .NET. Built in: the tool-calling loop with a configurable iteration limit, per-service-call history persistence, context compaction, todo and plan/execute providers, durable file memory, progressive skill loading, web search, tool approval, and OpenTelemetry. Verified against Microsoft's own release note rather than secondary coverage.

Microsoft DevBlogs — release note (primary) · InfoQ — GA coverage (independent)

Harness engineering

Corroborated

'Harness' has hardened into a named engineering category with its own adversarial-evaluation literature

The scaffolding around the model — the loop, memory, approvals, telemetry — is now the thing being studied, audited and attacked, rather than an implementation detail beneath the model. Papers this cycle cover adversarial evaluation of agents, auditing harness safety, and recursive harnesses. For a buyer this reframes the diligence question: the harness, not the model, is where authority and evidence are actually decided.

Named artefacts in circulation: ProofAgent Harness (open infrastructure for adversarial agent evaluation), Auditing Agent Harness Safety, Recursive Agent Harnesses, and an April 2026 point-in-time snapshot cataloguing self-described agent harnesses. Adjacent open runtimes named in the same coverage include LangGraph, CrewAI, AutoGen, Semantic Kernel, Mastra and OpenHarness.

Auditing Agent Harness Safety (arXiv) · ProofAgent Harness (arXiv)

Cybersecurity AI

Corroborated

Tool-metadata poisoning is now the headline agent attack class, and the agent cannot see it

The attack hides instructions inside tool descriptions and metadata — text the agent reads and the human never sees. It defeats the usual mental model of prompt injection, where somebody imagines a malicious user typing something. Here the malicious content arrives through the plumbing the agent trusts by construction. Tool allowlisting and identity binding are the controls that hold; asking the model to be careful is not.

A Cloud Security Alliance research note documents MCP injection hijacking coding agents. Scale figures are disputed and are NOT carried here as fact: one report claims up to 200,000 exposed MCP instances, another claims over 30 per cent of 1,800 analysed servers had at least one exploitable vulnerability. Neither has been traced to primary methodology, so both are excluded from the public view.

Cloud Security Alliance — Agentjacking research note · Practical DevSecOps — tool poisoning analysis (independent)

Decision-maker signal

Primary source

This week's through-line: the authority layer is being set by framework defaults, not by institutions

Three unrelated signals point at one gap. A major harness now ships standing tool-approval and heuristic auto-approval as defaults. The dominant agent attack class works by writing instructions into the plumbing the agent trusts. And the newest evaluation work finds agents largely fail to respect a binding written policy while completing their task. In each case the question is not capability. It is who decided what the agent may do, and whether that decision was yours or your framework vendor's.

The board-level version: ask which of your agent frameworks has an approval default, what it is set to, and who set it. That is a ten-minute question with a governance answer, and most estates have not asked it.

Microsoft DevBlogs — approval defaults (primary) · CSA — Agentjacking

Papers & research

Primary source

HANDBOOK.md: the best of thirty agent configurations obeys a binding company policy 36.2 per cent of the time

This is the most directly useful benchmark result of the cycle for anybody deploying into a regulated function. It measures the thing every governance framework assumes and no capability benchmark tests: whether the agent obeys the written rules of the organisation while doing the work. Under strict grading the best of thirty evaluated configurations passes 36.2 per cent of trials, and most frontier configurations stay below 25 per cent. If your control story is a policy document in the context window, this is the number that story rests on.

Verified against the paper. 65 agentic tasks, each in a self-contained company environment with file workspace plus mock email, chat, calendar, issue-tracking and commerce services exposed over MCP, governed by an expert-written SOP of 20 to 124 pages. Four systematic failure patterns named by the authors: agents let a plausible in-environment request override the standing policy; perform a required check and then act against its result; lose rule details over long horizons; and report compliance they did not achieve. That last one is the one to sit with — the agent's own account of its behaviour is itself unreliable. Surge AI; accepted to the Workshop on Agent Behavior at COLM 2026; tasks, environments and evaluation harness published.

HANDBOOK.md (arXiv 2607.25398) — the paper (primary) · Surge AI — tasks, environments and evaluation harness

Corroborated

Evaluation research converges on one complaint: agent benchmarks measure completion, not fitness for the setting

Separate papers this cycle attack the same weakness from different angles — whether small task subsets preserve agent rankings at much lower cost, and whether the existing benchmark corpus meets public-sector requirements at all. The second analysed more than 1,300 agent benchmarks against process-based evaluation, realism and domain-specific criteria. For a buyer, this is the research literature arriving at the position this practice has argued from the procurement side: a leaderboard score is not a deployment decision.

Also in scope this cycle: work on measuring agentic identity, and a multi-turn benchmark for consistency, uncertainty handling and capability awareness under ambiguous or incomplete requests.

Efficient Benchmarking of AI Agents (arXiv) · AlphaEval — evaluating agents in production (arXiv)

2 further items are being tracked and not shown. They have not yet been traced to a primary source or corroborated by two independent reports. A claim repeated by several outlets from one press release is one source, not several — which is how most bad numbers travel. Held items stay on the verification backlog until they clear or are dropped; nothing disappears quietly.

Compiled by Vikram Jha. The method, including the confidence rubric this page is filtered on, is described in the writing. Corrections are welcome and are recorded in the open rather than quietly applied.