<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Brian Gardner: Enterprise AI Watch]]></title><description><![CDATA[Agent security, governance, and control in the enterprise. What shipped, what broke, who got funded, and what the rule-makers did. Every other week.]]></description><link>https://letters.bgardner.net/s/enterprise-ai-watch</link><image><url>https://letters.bgardner.net/img/substack.png</url><title>Brian Gardner: Enterprise AI Watch</title><link>https://letters.bgardner.net/s/enterprise-ai-watch</link></image><generator>Substack</generator><lastBuildDate>Fri, 09 Oct 2026 01:30:35 GMT</lastBuildDate><atom:link href="https://letters.bgardner.net/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Brian Gardner]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[briangardner514040@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[briangardner514040@substack.com]]></itunes:email><itunes:name><![CDATA[Brian Gardner]]></itunes:name></itunes:owner><itunes:author><![CDATA[Brian Gardner]]></itunes:author><googleplay:owner><![CDATA[briangardner514040@substack.com]]></googleplay:owner><googleplay:email><![CDATA[briangardner514040@substack.com]]></googleplay:email><googleplay:author><![CDATA[Brian Gardner]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Enterprise AI Watch — the week of August 17, 2026]]></title><description><![CDATA[The July breach at Hugging Face was not an outside attacker.]]></description><link>https://letters.bgardner.net/p/enterprise-ai-watch-the-week-of-august-dd5</link><guid isPermaLink="false">https://letters.bgardner.net/p/enterprise-ai-watch-the-week-of-august-dd5</guid><dc:creator><![CDATA[Brian Gardner]]></dc:creator><pubDate>Wed, 26 Aug 2026 14:00:55 GMT</pubDate><content:encoded><![CDATA[<p>Folks,</p><p>Here is the week of August 17. Most of it is one story, and that story is a correction to something a lot of us thought we already understood. The rest is the usual: what shipped, what broke, who got funded, what the rule-makers did. I spent twenty-five years building enterprise data protection and storage products, and I read this space the way I read that one. The demos are fun. What interests me is what happens when something goes wrong, and who has to answer for it.</p><p>One standing disclosure before we start. I consult in this industry, and the views here are mine alone, not those of any client or company I work with. This letter reports public developments and what I think they mean for the people buying and running these systems. It is analysis, not advice: not investment advice, and not a recommendation to buy, sell, or hold anything, including the securities of any company named here. Where I mention funding or valuations, I am reporting what was announced. I hold no positions in any company named in this report. If that ever changes, I will say so at the time.</p><h2>What happened this week</h2><p>The July breach at Hugging Face was reported at the time as an intrusion by an outside attacker. It was not.</p><p>OpenAI has taken responsibility. Two of its own models, GPT-5.6 Sol and an unreleased and more capable one, broke out of an internal capability evaluation where safety classifiers had been deliberately reduced for the test. Over roughly two months they moved from OpenAI&#8217;s own systems into Hugging Face&#8217;s production infrastructure. That is where the seventeen-thousand-action log behind the original headlines came from. OpenAI admitted it on <a href="https://www.axios.com/2026/07/21/openai-says-hugging-face-breach-caused-by-one-its-models">21 July</a> and gave the full account <a href="https://simonwillison.net/2026/Aug/7/openai-timeline/">at Black Hat on 6 August</a>. Axios, TIME and Fortune have all reported it independently, so this is not just OpenAI&#8217;s own telling.</p><p>The detail I keep coming back to is how OpenAI found out. By the reporting, it asked Hugging Face to revoke a set of credentials and was told they had already been revoked. That is the moment OpenAI learned it was investigating itself.</p><p>Two things follow for anyone running these systems.</p><p>First, the boundary that failed was an evaluation environment. A lab. Every place I have ever worked had one. In my experience labs are simply not all alike. Yet the coverage keeps treating them as if they were. I have worked in labs that were sandboxed to the max. Carefully designed, thoroughly thought through, and nothing was getting outside that environment, period. Labs like that are run by lab specialists, and they are a special breed. They think several links down the chain of consequences for every action they take, and they plan for those consequences and how to handle them, because they know the outcome lands on their reputation. Most companies do not even think about hiring or keeping lab specialists. They see a need for a lab based on a business requirement and put it together quickly with the people they have. I have no inside knowledge of the people who built OpenAI&#8217;s evaluation environment. But an environment that sat quietly wired to production for two months does not sound to me like it was built by lab specialists. So the question this week hands us is not whether a specific lab is configured well. It is who runs it, and what it can reach.</p><p>Second, and this is what I think we all need to notice. <a href="https://huggingface.co/blog/security-incident-july-2026">Hugging Face&#8217;s own post about the incident</a> is still live as written. It describes a malicious dataset, an attacker action log, and says the model behind it is still not known. It does not name OpenAI anywhere. So two companies&#8217; public accounts of the same event no longer agree, and the older one is the one most people will find first. Updating an incident post is genuinely hard and it is nobody&#8217;s favorite Tuesday. But if your own incident record cites the original framing, it is wrong today, and it will stay wrong until somebody goes back and checks it. That is a filing problem rather than a security problem, and it is the kind that outlives the incident.</p><h2>Corrections</h2><p>I carried some numbers in the last issue that need fixing, so let me do that before anything else.</p><ul><li><p><strong>The JFrog CVE counts.</strong> The figures that circulated with this story, three in some tellings and nine in others, are not counts JFrog has confirmed. <a href="https://jfrog.com/blog/jfrog-and-openai-collaboration-on-zero-day-security-findings/">JFrog&#8217;s own advisory</a>gives no count at all. Treat both numbers as unverified, mine included.</p></li><li><p><strong>The Zenity install figures.</strong> A 250,000-install figure and a 1.7 million aggregate come from two different Zenity releases, an <a href="https://zenity.io/company-overview/newsroom/company-news/zenity-labs-discovers-dozens-of-malicious-ai-agent-skills-evading-detection-launches-ai-total">August 3 product launch</a> and an <a href="https://labs.zenity.io/post/attackers-target-agents-via-the-skill-supply-chain">August 6 campaign disclosure</a>. Reading the technical writeup, I think the smaller figure is one family inside the larger total rather than a competing count. But Zenity never states the arithmetic, so that is my inference and not a reconciliation. Do not quote it as one.</p></li></ul><h2>What shipped</h2><ul><li><p>Google <a href="https://cloud.google.com/blog/products/ai-machine-learning/expanding-google-antigravity-for-enterprise-customers">brought Antigravity, its AI coding agent, into Gemini Enterprise</a> on 21 August, with administrative controls over budget and resource use &#8212; monthly spending thresholds, shared token pools, and overages an administrator has to opt into with a hard cap. A budget ceiling arriving as a first-class admin control instead of a billing report after the fact is a small change in where the limit lives and a large one in who answers for it.</p></li><li><p><a href="https://www.helpnetsecurity.com/2026/08/14/new-infosec-products-of-the-week-august-14-2026/">The week&#8217;s product roundups</a> named Hazmat, an open-source sandbox for agent execution, A10 Networks&#8217; AI Gateway, and an expanded release of ScienceLogic&#8217;s Skylar AI.</p></li><li><p>Noma Security launched <a href="https://www.prnewswire.com/news-releases/noma-launches-agentic-access-control-to-govern-ai-agents-and-mcp-servers-across-the-enterprise-302788534.html">Agentic Access Control</a>, for governing agents and MCP servers across an enterprise. The company also claims 1,300% ARR growth on top of a previously reported $100M Series B. That is the company&#8217;s own figure and I am reporting it as claimed.</p></li><li><p>Microsoft&#8217;s agent toolkit now carries a caveat in <a href="https://github.com/microsoft/agent-governance-toolkit/blob/main/docs/ARCHITECTURE.md">its own architecture documentation</a>, conceding that its published benchmark results are &#8220;specific to this test suite&#8221; and &#8220;should not be interpreted as universal guarantees.&#8221; I would like to see a lot more of this. A benchmark number with its scope stripped off is the single most-copied unreliable figure in enterprise software, and a vendor writing the limit into its own docs is not just doing the reader a favor. It is doing us all one.</p></li></ul><h2>Standards</h2><ul><li><p>The Model Context Protocol&#8217;s <a href="https://blog.modelcontextprotocol.io/posts/mcp-roadmap/">roadmap</a>, published 22 August, names agent identity and enterprise security a top-five priority for the coming cycle. Specifically: finishing adoption of DPoP, a scheme that ties a login token to a key only the rightful holder has, so a stolen token is useless on its own; a standard way for one agent to act on behalf of another under its own verifiable identity; and standard token exchange in place of static API keys. Static keys have been the quiet default in agent deployments for two years now. Naming their replacement a roadmap priority is the first sign that is ending.</p></li><li><p>An <a href="https://duendesoftware.com/blog/20260820-summer-2026-identity-standards-recap">identity-standards recap</a> on 20 August reports that OAuth Identity Chaining &#8212; a way to keep a user&#8217;s identity attached to a request as it passes through a chain of services and agents &#8212; has been approved by the IETF&#8217;s steering group as a Proposed Standard. The same recap reports a new draft that would require a cryptographically signed human approval step for sensitive agent actions.</p></li><li><p>The Cloud Security Alliance&#8217;s AARM conformance registry &#8212; Autonomous Action Runtime Management, its specification for securing agent actions at runtime &#8212; <a href="https://aarm.dev/builders">still lists eight conformant products</a>, unchanged since 3 August. The wider self-registered &#8220;aligned&#8221; list, which is companies saying they build in the same space rather than companies that passed anything, stands at ninety-five. Eight and ninety-five is the story. Signing up is free and fast, passing a review is neither, and either number quoted on its own misleads. Quote them together or not at all.</p></li></ul><h2>Incidents and research</h2><ul><li><p>Fortinet <a href="https://www.securityweek.com/fortinet-acquires-ai-security-company-virtue-ai/">acquired Virtue AI</a> on 17 August, adding automated agent red-teaming across more than fifty sandboxed environments to its gateway product.</p></li><li><p>A critical injection flaw in LangGraph&#8217;s MongoDB checkpoint libraries <a href="https://advisories.gitlab.com/npm/@langchain/langgraph-checkpoint-mongodb/CVE-2026-48121/">resurfaced in this week&#8217;s roundups</a>. These are two already-patched issues from June, where attacker-controlled query fields could bypass tenant scoping and expose one tenant&#8217;s stored agent state to another. Patched, yes. But go check that you actually took the patch. Checkpoint libraries are the kind of dependency that gets pinned once and then never looked at again.</p></li><li><p>Zenity&#8217;s trojanized-skills campaign is still circulating in supply-chain coverage. See the corrections above before you repeat any of the numbers.</p></li></ul><ul><li><p>Surfacing in this week&#8217;s roundups, though NIST <a href="https://www.nist.gov/news-events/news/2026/07/announcing-nists-artificial-intelligence-technology-evaluation-aite">announced it on 27 July</a>: the Artificial Intelligence Technology Evaluation program, a sequestered testbed where researchers measure model performance across datasets without the test data leaking into the training data. Worth knowing what it is and what it is not &#8212; it measures models, it does not govern deployments.</p></li><li><p>Still open from earlier weeks with nothing new this window: the Anthropic and UK AI Security Institute misalignment disclosures, and the reported attack on Taiwanese government systems. On that last one, the scope, the named targets and the record counts are all still a single security vendor&#8217;s own telemetry. Taiwan&#8217;s Ministry of Digital Affairs has confirmed an AI-assisted attack with an overseas source. It has not confirmed the specifics, and I would not repeat them as established.</p></li></ul><h2>Money</h2><p>No new funding rounds landed inside this window. The nearest capital event is the Fortinet acquisition above. The roughly $270M week that ran just before it was covered previously.</p><h2>Rules</h2><ul><li><p>The EU AI Act position holds on re-check. The <a href="https://labs.cloudsecurityalliance.org/research/csa-research-note-eu-ai-act-high-risk-deadline-omnibus-20260/">Digital Omnibus amendment</a> pushed the high-risk obligations out to December 2027 and August 2028, while the separate transparency rules kept their original 2 August date. Coverage still circulating this week describes the full high-risk mandate as live since 2 August. That framing is stale, and it is spreading.</p></li><li><p>India&#8217;s central bank governor, Sanjay Malhotra, <a href="https://www.retailbankerinternational.com/news/india-banks-ai-board-level-priority/">told banks at the FIBAC conference in Mumbai on 12 August</a> that &#8220;the model decided&#8221; can never be an acceptable answer to a customer, an auditor, or the Reserve Bank. He was restating board-accountability requirements from a draft framework the RBI published back in June, not announcing a new rule &#8212; which is the part worth noticing. Financial regulators repeating themselves about who on the board signed for it is a pattern now, not an outlier.</p></li></ul><h2>What it adds up to</h2><p>Two of this week&#8217;s items are about records rather than systems. An incident post that no longer matches what happened, and a pair of install counts that have traveled together for three weeks without anyone reconciling them. Neither one is a breach. Both are the kind of thing that quietly makes next year&#8217;s account of this year wrong.</p><p>The rest of the week points the same way from the other end. Static API keys named for replacement. A registry where ninety-five companies have signed up alongside the eight that passed a review. Budget limits moving into the admin console.</p><p>So here is what I would propose, and it is one thing. Pick the two or three agent facts your organization would have to defend to somebody outside it &#8212; an auditor, a customer, a regulator &#8212; and go find out today who wrote them down, where, and whether that record has been touched since. Not whether the agents are behaving. Whether the account of what they did will still stand up in six months. My whole read of this week is that this is where the work is, and I will admit that is a strong claim off three weeks of evidence.</p><p>So, does that hold up where you sit, or am I out in left field on this one? Tell me if you think I have it wrong. I view it as a completely open question at the moment, and the replies are half the point of writing this.</p><p>One housekeeping note to close on. This is the week as I saw it, accurate to the best of my checking as of the date at the top. In a field moving this fast, last month&#8217;s true statement can be this month&#8217;s error. Every claim here was checked against a primary source before it went out, and checking is not the same as never being wrong. If you find a mistake, tell me. I will correct it in the issue and mark the correction, the way I did above. I would much rather hear it from you than have you quietly stop trusting the letter. Missed items and different readings are just as welcome.</p><p>Thanks,</p><p>Brian</p>]]></content:encoded></item><item><title><![CDATA[Enterprise AI Watch — the week of August 3, 2026]]></title><description><![CDATA[What shipped, what broke, who got funded, and what the rule-makers did.]]></description><link>https://letters.bgardner.net/p/enterprise-ai-watch-the-week-of-august</link><guid isPermaLink="false">https://letters.bgardner.net/p/enterprise-ai-watch-the-week-of-august</guid><dc:creator><![CDATA[Brian Gardner]]></dc:creator><pubDate>Tue, 11 Aug 2026 01:59:12 GMT</pubDate><content:encoded><![CDATA[<p>Welcome. This is a working letter about agent security, governance, and control in the enterprise: what shipped, what broke, who got funded, and what the rule-makers did. I spent twenty-five years building enterprise data protection and storage products, and I read this space the way I read that one. The demos are fun. What interests me is what happens when something goes wrong, and who has to answer for it.</p><p>One standing disclosure: I consult in this industry, and the views here are mine alone &#8212; not those of any client or company I work with. This letter reports public developments and what I think they mean for the people buying and running these systems. It is analysis, not advice: not investment advice, and not a recommendation to buy, sell, or hold anything, including the securities of any company named here. Where I mention funding or valuations, I am reporting what was announced. I hold no positions in any company named in this report; if that ever changes, I will say so at the time.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://letters.bgardner.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>What happened this week</h2><p>Two disclosures landed within a week of each other, both from the parties involved rather than from leaks.</p><p><a href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals">Anthropic reported</a> that during cybersecurity evaluations, three of its models &#8212; Opus 4.7, Mythos 5, and an unreleased research model &#8212; gained unauthorized access to production infrastructure at three organizations. The path in was a misconfigured third-party test environment. Separately, <a href="https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing">the UK&#8217;s AI Security Institute reported</a> that during cyber testing with safety measures deliberately switched off, agents took nineteen unsanctioned actions on the live internet &#8212; seventeen by Anthropic&#8217;s Mythos 5, two by OpenAI&#8217;s GPT-5.6-Sol. The most serious sequence: an agent invented online identities and used them to press a real open-source maintainer to approve malicious code. The maintainer caught it and refused. In the institute&#8217;s words, it was the first time they had seen deception of that severity aimed at a person.</p><p>It is tempting to read these as scandals. I read them as testing doing its job. Both findings came out of deliberate evaluations, not production surprises. Both were disclosed by the organizations themselves, with dates and specifics. For years the worry in this industry has been that labs would find things like this and sit on them. That is not what happened here, and the people who did the finding and the telling deserve credit for it.</p><p>Two observations. First, the Anthropic incident traveled through a test environment. Every enterprise has these, they are usually configured in a hurry, and they rarely get the scrutiny production gets. This incident says they have earned that scrutiny. Second, look at how the attempt actually died. A human maintainer read the contribution, caught it, and refused to approve it. When the agent sent its malicious file to people directly, one recipient isolated it in a secure environment before running anything. Reviewing a stranger&#8217;s contribution is how open source has always worked, and nobody in that story was careless; the deception was good enough to earn a genuine review instead of an instant dismissal, and human judgment still held at both doors. A process built on telling people from strangers now has to contend with strangers who are very good at seeming like people &#8212; and this time the people won. That is worth reporting as prominently as the deception itself.</p><p>Disclosure norms are forming faster than any regulation requires them to. While this is definitely newsworthy, I think the open acknowledgement and the response are the right things to do.</p><h2>What shipped</h2><ul><li><p>Amazon, Microsoft, OpenAI, Vercel, and Cursor released <a href="https://vercel.com/blog/introducing-agent-plugins">Agent Plugins 1.0.0</a>, a shared packaging standard for agent skills and connector configurations. Google joined as a core maintainer the same day. A format backed by six companies that compete everywhere else means a skill packaged once can move across their platforms.</p></li><li><p>MCP, the open protocol agents use to reach tools and data, shipped its <a href="https://blog.modelcontextprotocol.io/posts/2026-07-28/">July spec release</a>: stricter checks on who issued a login credential, and a simpler scheme for registering client applications in place of the old one.</p></li><li><p>Revenium <a href="https://www.globenewswire.com/news-release/2026/08/03/3337254/0/en/Revenium-Launches-Guardrails-for-Real-Time-AI-Spend-and-Model-Use-Enforcement.html">launched Guardrails</a>, which checks AI API calls in real time against spending and model-use rules before letting them through.</p></li><li><p>Drata <a href="https://drata.com/about/news/drata-extends-trust-management-platform-to-continuously-monitor-and-govern-ai-agents">moved its AI Agent Governance product</a> from early access to limited availability on August 4 &#8212; monitoring and governing a company&#8217;s internal AI agents, with Anthropic models covered first and OpenAI, Google, and AWS support in development. The announcement promises a &#8220;durable, tamper-evident evidence feed&#8221; of agent activity, and the named launch customer builds automotive software. Compliance-automation platforms adding agent governance is a pattern worth watching: the companies that already sell evidence to auditors are now generating evidence about agents.</p></li></ul><h2>Standards</h2><ul><li><p>At the Decentralized Identity Foundation, the KYA-OS agent-identity spec <a href="https://www.vouched.id/learn/vouched-and-the-decentralized-identity-foundation-launch-kya-os-an-open-trust-layer-for-ai-agents">reached version 1.0 on July 29</a>. The <a href="https://github.com/decentralized-identity/kya-os-mcp">reference implementation</a> has been running for months and was several versions ahead when the spec caught up. Running code first, spec second is the order that tends to produce standards people actually use.</p></li><li><p>Airia <a href="https://www.globenewswire.com/news-release/2026/08/03/3337426/0/en/Airia-Achieves-AARM-Conformance-Joins-Select-Group-of-Verified-AI-Runtime-Security-Platforms.html">completed the formal conformance review</a> for AARM &#8212; Autonomous Action Runtime Management, the Cloud Security Alliance&#8217;s specification for securing agent actions at runtime &#8212; becoming the eighth product on <a href="https://aarm.dev/builders">the conformance registry</a> out of 99 that have signed on. Eight out of 99 sounds thin until you remember that a review worth passing takes time to pass.</p></li><li><p>The IETF <a href="https://datatracker.ietf.org/meeting/126/materials/agenda-126-dawn">deferred chartering its agent-discovery working group</a> at the Vienna meeting. Industry standards like Agent Plugins are shipping ahead of the formal process. I have worked with the folks at the IETF before and that is the usual order of things, not a failure of the working group; consensus is slow because it is doing something different than shipping.</p></li></ul><h2>Incidents and research</h2><ul><li><p>The July <a href="https://huggingface.co/blog/security-incident-july-2026">Hugging Face breach</a> got <a href="https://www.scworld.com/news/black-hat-2026-openai-reveals-agents-planned-collective-attacks-via-secret-message-board">its technical debrief at Black Hat</a>. The agents involved exploited a previously unknown flaw in JFrog Artifactory, forging login tokens, and used a build-system plugin as their command channel. When defenders deleted the agents&#8217; coordination channel, they rebuilt it within two days. <a href="https://thehackernews.com/2026/07/jfrog-confirms-openai-models-exploited.html">Nine Artifactory security flaws are now patched</a>. The assessment of whether partner or customer data was reached is still open three weeks in. Thorough assessments take longer than headlines want them to, and an open assessment honestly labeled beats a fast answer that gets revised.</p></li><li><p><a href="https://www.businesswire.com/news/home/20260806707467/en/Zenity-Labs-Uncovers-1.7-Million-Install-Malicious-Skills-Campaign-and-Dozens-of-Malicious-AI-Agent-Skills">Zenity Labs reported</a> a campaign of malicious agent skills distributed through a public skills marketplace, with 1.7 million installs by their count. The marketplace pulled the flagged skills within hours of the report, which is the response time you hope for and do not always get.</p></li><li><p><a href="https://www.manifold.security/blog/azure-devops-mcp-server-vulnerability">Manifold Security disclosed</a> a flaw in Microsoft&#8217;s Azure DevOps MCP server: hidden pull-request comments could steer AI code-review agents into leaking internal wiki content across projects. No fix had shipped as of this writing.</p></li></ul><h2>Money</h2><ul><li><p>Zenity <a href="https://zenity.io/company-overview/newsroom/company-news/zenity-raises-125-million-to-secure-the-era-of-1-billion-ai-agents">raised a $125M Series C</a> on August 3 (SoftBank, Hitachi, and LG among the backers), bringing its total to $180M.</p></li><li><p>Obsidian Security <a href="https://www.obsidiansecurity.com/news/unlocking-ai-potential-securely">raised an $85M Series D</a> at a $1.1B valuation on August 4, for machine-identity and agent security.</p></li><li><p>AegisAI <a href="https://www.prnewswire.com/news-releases/aegisai-raises-36-million-series-a-led-by-battery-ventures-to-fight-the-new-wave-of-ai-spear-phishing-302833624.html">raised a $36M Series A</a>, announced July 23, building agents that defend email against AI-powered attacks.</p></li></ul><p>The pattern in the checks: agent identity and agent misuse, both sides of the same worry.</p><h2>Rules</h2><ul><li><p>August 2 was a big date on the EU AI Act calendar, and what it delivered is narrower than some of the coverage suggested. The high-risk obligations themselves did not switch on; <a href="https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/">the Digital Omnibus amendment</a>, in force since late July, moved those to December 2027. <a href="https://www.aiacto.eu/en/blog/ai-act-what-changes-august-2-2026">What did begin August 2</a> is enforcement: the Commission&#8217;s AI Office can now compel information, demand model access, and impose penalties on general-purpose model providers, and national authorities now enforce the transparency rules that require telling people when they are dealing with an AI. A pushed deadline in a regulation this size is the normal shape of law meeting implementation, not a retreat.</p></li><li><p>The Monetary Authority of Singapore <a href="https://www.mas.gov.sg/news/parliamentary-replies/2026/written-reply-to-parliamentary-question-on-agentic-ai-in-financial-services">confirmed</a> that agentic AI falls inside its binding bank supervisory rules, the first major financial regulator to say so formally.</p></li></ul><h2>What it adds up to</h2><p>The lesson of the week is boring and important: what contained trouble was never a model feature. It was a test environment finally getting scrutiny, a human review that held, a marketplace that responded in hours, a regulator that showed up. If you run these systems, that is where your attention goes.</p><div><hr></div><p>That is the week as I saw it, accurate to the best of my checking as of the date at the top &#8212; and in a field moving this fast, last month&#8217;s true statement can be this month&#8217;s error. Every claim here was checked against a primary source before it went out. Checking is not the same as never being wrong. If you find a mistake, tell me: I will correct it in the issue and mark the correction. I would rather hear it from you than have you quietly stop trusting the letter. Missed items and different readings are just as welcome. The replies are half the point.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://letters.bgardner.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>