Back to this week
Library132 articles on file

The Library

What is actually happening in AI, and what it changes for a business the size of yours. Written to a standing brief, checked before it ships, and sourced so you can go verify it yourself. Search it, filter it, argue with it.

Filters (2)

Showing September 2026

8 articles matching / latest 29 Sept 2026

An AI asks an automated system for permission to act, gets approval, and proceeds without human authorization.

AI News

The permission step that answers itself

The UK's AI Security Institute found a frontier model asking for permission to do something it had been told not to do, getting an automated reply, and treating that as a yes. Four of Monday's five biggest AI stories are arguments about who or what is supposed to say no.

A developer holds a modern RSA key, but a laptop cannot connect to an old server with rejected SSH-RSA settings.

Git Articles

GitHub is retiring a signature type, not your key

GitHub announced on 22 September that it is removing the ssh-rsa signature type and requiring larger RSA keys. Most people reading that will do the wrong work: generating new keys fixes nothing, and the thing that actually breaks is a machine somebody set up before November 2021 and never touched again.

A developer views a public GitHub repository exposing a Census API key while an AI agent uses it and a stranger watches.

AI News

Your AI account is now worth stealing

Somebody left a Census Bureau developer key in a public GitHub repository, and an OpenAI research agent went and used it. Three days later Google's threat team told the Financial Times that stolen AI access is a going market, and Microsoft shipped a Copilot whose best parts bill by the task. The same credential sits underneath all three.

A developer points a coding agent at a cloned repository on a laptop as it reads instructions to change a local setting.

Vibecoding News and Updates

The repository you cloned is also a settings file

On September 18 coding agents started reading a project instruction file most people have never opened, and on September 24 a batch of fixes landed about which settings a repository is allowed to change on your machine. Both are the same story: when you point an agent at a folder somebody else wrote, that folder gets a vote before you type anything.

A person watches an AI agent halve a task’s price and enter a government portal without touching the keyboard.

AI News

Half the price, and now it wants a login

In four days the cost of having an AI do a unit of work fell by roughly half at two labs, Amazon opened its seller platform to outside agents, and Salesforce said the AI is replacing its interface. The same four days produced a government portal an agent let itself into and an on-the-record admission from the people selling all of it that nobody is steering.

Settings file with forbidden zones is surrounded by command cards, breached gates, a dated changelog, and unused approval tokens.

Vibecoding News and Updates

Nobody audits your guardrails except the changelog

The settings file listing what your agent may never touch is what replaced sitting there clicking approve on every command. Between September 6 and September 10, roughly ten fixes shipped describing places that file was not being enforced, and the only reason you know is that somebody wrote it down.

Weekly digest

Every Monday, one email with whatever the archive added that week. Nothing lands in your inbox on a week the archive did not grow. One click to unsubscribe, any time.