Stack layer / Threat pattern
Salesforce frames its agent stack as an 'Enterprise AI Harness' with a separate AI Control Plane
Salesforce
Same source domain / Semantic neighbor
Nathan Lambert's open-models reading list puts the open-closed gap at 4-6 months and calls distillation panic evidence-free
Interconnects (Nathan Lambert)
Stack layer / Contrast
EvoSafeHarness searches policies and code together to build a per-model safety harness, cutting attack success from 45.6% to 10.0%
arXiv (2609.05903)
Stack layer / Update thread
OpenRouter's automatic fallback silently changes model behaviour, and provider.only is the fix
Simon Willison's Blog (citing Mohamed Moustafa)
Stack layer / Update thread
Tailscale gates customer model access by tailnet identity and issues no API keys to agents at all
Vercel Blog
Stack layer / Threat pattern
Claude Code 2.1.269 Ships a Plugin Eval Runner and a Knob to Raise the Workflow Tool's Concurrent Agent Cap to 256
Anthropic (claude-code CHANGELOG)
Stack layer
Willison's answer to "Feeling sad about AI": translating an exact spec into decent code is no longer a unique skill
simonwillison.net
Policy dependency
Tencent study: agents cross authorization boundaries in 55-62% of runs when a control constraint is missing and an unsafe action is executable, and 87% when compaction drops the constraint
arXiv