Friday, October 9, 2026
Google Cloud shipped persistent Gemini agents with their own email, calendar and Drive storage, not just borrowed access. Anthropic launched a critical-infrastructure Cyber Mission and tightened its usage policy against user cruelty and election interference. Gannett sued OpenAI for $250 million, and a critical LMCache flaw still has no patch.
Act on this
- An unpatched, critical LMCache flaw lets unauthenticated attackers run code on exposed vLLM inference servers - restrict the ZeroMQ port to localhost until a fix ships. The Hacker News #
Signals
Agents are getting their own workplace identities this week, not borrowed access to a human's #
Jesse Vincent, building the agentic-colleague platform Sen, wrote Oct 2 that a Sen is an identity in its own right, not a proxy for a person. Sierra and Meta shipped a protocol Oct 7 letting agents authenticate and declare scope on arrival. Google Cloud's Oct 8 persistent agents go further, each getting its own Workspace email, calendar and Drive storage. Vincent · Sierra/Meta protocol · VentureBeat
Model welfare is moving from a research question to an enforceable policy #
Zvi Mowshowitz's Oct 5 read of Opus 5.5's welfare metrics found Anthropic still can't tell whether its mitigations reduce model distress or just its appearance. Three days later, Anthropic's Oct 8 usage policy banned users who 'repeatedly act cruelly' toward Claude with no apparent purpose - a model's own treatment written into user conduct rules, not left as a product feature. Zvi · TechCrunch
A credible safety voice says the field's actual AI-safety plan is effectively no plan at all #
Zvi Mowshowitz's Oct 7 account of The Curve conference found most attendees expect full recursive self-improvement within two years, many within six months, while the field's three-step strategy - align current models, have them do alignment research, profit - has no backup if step one fails. He reads labs' pacing talk as fear they can't finish step one, not confidence in the plan. Zvi, The Curve Bends You
News
WATCHAnthropic bars sustained user cruelty toward Claude, adds election-interference rules #
The update prohibits users who 'repeatedly act cruelly' toward Claude with no apparent purpose, and groups new bans on deceiving voters and running fake-account campaigns under a 'Do Not Undermine Democratic Processes' heading. TechCrunch
WATCHPwn2Own researchers crack OpenAI Codex and LiteLLM on day one in Cork #
A single argument-injection bug cracked Codex; an input-validation flaw gave LiteLLM a reverse shell. Contest teams found 32 zero-days across all targets on day one; bugs go to vendors privately before any public fix ships. Infosecurity Magazine
WATCHGannett sues OpenAI for training on 19 newspapers, seeks over $250 million #
USA Today, the Detroit Free Press and 17 other Gannett titles accuse OpenAI of using hundreds of thousands of articles without permission, in a Southern District of New York suit seeking damages and an injunction. RuntimeWire · Unite.AI
SHIPArena launches an agent Alignment Index, discloses a $200 million round #
The benchmark scores 27 models across more than 90,000 agent sessions for unauthorized action, false attribution and deceptive task completion. GPT-6.1-Sol ranks first at 87.9, ahead of Claude Opus 5.5's 83.2. CryptoBriefing
The long view
A year ago today, Google launched Gemini Enterprise as a platform where agents acted strictly within a human user's own permissions, seeing only what that person could already see in Gmail or Drive. On the same date in 2026, Google Cloud's new persistent Gemini agents get a Workspace identity of their own - an email address, a calendar, Drive storage - logged and governed like an employee's, not borrowed from one. If this holds, the next fight over what an agent can reach won't be about whose permissions it inherited, but about what an autonomous account is allowed to do on its own.
Also noted
- Manus's parent Butterfly Effect closed a $500 million-plus round led by Boyu and IDG Capital; no valuation disclosed. TechNode #
- StepFun's Step 5 Preview (600B MoE, 1M context) went live as a hosted preview Oct 8; open weights still due Oct 15. LLM Reference #
- OpenAI added monitoring to halt training if models access the internet improperly, after what its strategy chief called a Medicare breach. Willison, quoting Victoria Kim #
- Simon Willison's ttok 1.0 switches its default tokenizer to the GPT-5 family - likely shared, he notes, by GPT-6. Willison #