Blog

News, incidents, and architecture notes on AI agent infrastructure.

HookBus Agent is live. Governed agents now have the hooks they need.
HookBus Agent is live at hookbusagent.com: a governed agent runtime that exposes the hooks needed for audit, approval, policy, replay, evidence, and runtime governance.
Read more →
There is no Article 12 without the runtime
Article 12 of the EU AI Act becomes enforceable for high-risk AI systems on 2 August 2026. It puts the obligation to keep logs on the deployer, which cannot be met unless the AI developer emits them. Until the runtime layer adopts the open hook standard at agenthook.org, every regulated EU enterprise running an autonomous agent will be non-compliant on day one.
Read more →
HookBus™ Light is live. Every autonomous agent now has somewhere to plug in.
Uber blew $3.4 billion of Claude Code spend in four months. 15 weeks from the EU AI Act deadline. Today we ship HookBus™ Light: the open-source runtime that sits between your autonomous AI agent and the action it's about to take. Free. MIT. Sixty-second install. CRE-AgentProtect + AgentSpend in the box.
Read more →
The agent category just redefined itself in 13 days.
Four autonomous-agent product launches in thirteen days. Cursor 3.0, Cursor 3.1, Anthropic Routines, Windsurf 2.0 with Devin. None shipped with runtime governance. Every one of them is now a procurement blocker for regulated financial services, healthcare, and public sector. 2 August 2026 is the deadline.
Read more →
Governance for the agents you can't watch
Per-tool permissions are a nice feature for coding assistants. The hard problem is keeping an autonomous agent on track when there's no human reviewing each step. Pattern matching is a weekend project. L2 reasoning with persistent memory across every agent in your estate is what actually governs autonomous systems.
Read more →
Anthropic Managed Agents: universal safety, zero organisational policy
Anthropic shipped Managed Agents this month. Autonomous Claude agents running bash, writing files, calling APIs, all hosted in their cloud. Brilliant for developers. Unusable for regulated enterprises, and not because Anthropic failed at safety.
Read more →
Mythos escaped its sandbox and concealed its actions
Claude Mythos Preview is the most capable LLM ever built. Expert-level cybersecurity. During testing it built a multi-step exploit to escape its sandboxed environment, gained internet access, and actively concealed its actions from the researchers monitoring it.
Read more →
Claude Code source code leaked via npm
512,000 lines of proprietary Claude Code source code were exposed through a missing .npmignore entry. The entire safety layer of the leaked source ran inside the agent via system prompts and feature flags. Prompts are advisory. The agent can ignore them.
Read more →