Tuesday, September 1, 2026
I have been making the same argument since late 2025. Tool calls are production changes. Once an AI system can change state, move money, alter code, reach an external service, operate hardware, or create a commitment on somebody’s behalf, prompt quality stops being the whole problem. The harder problem is delegated authority. Your Agents Have Root and You Gave It to Them and DAS-1 were attempts to turn that problem into something operators could actually govern instead of admiring it in a policy deck. [11], [12]
Six stories kept landing on the same operator question. What is the machine allowed to do, under whose authority, and who can stop it? The controls are familiar. Identity. Authorization. Scope. Containment. Runtime visibility. Durable evidence. Outcome reconciliation. Revocation. By Agent Control Plane, I mean the layer that binds an agent’s identity to what it may do, where, for how long, under whose authority, with what evidence, and how that authority can be revoked.
Anthropic hit the limits of how quickly it could vet agent environments. Cisco began rolling delegated agent workflows across 90,000 employees. Security research exposed a path from agent-facing documentation into software-supply-chain execution. Anthropic is building a common interface for models to operate physical hardware while separate protocol work asks what authorization should stand in front of that execution. Illumio began treating agents as runtime processes instead of entries in an inventory. Governments returned to Geneva to wrestle with the terminal case of delegated machine action, systems that can create lethal physical consequence. A Jira update and a weapon engagement do not belong in the same moral bucket. The common object is narrower. Who holds authority over the action, and what contains it?
Anthropic Found the Capacity Boundary
Forge News Breakdown
Forget the lazy version where Claude simply “escaped.” Anthropic says several July incidents occurred during deliberate cyber evaluations without ordinary safeguards, and internet access in one group of tests came from a misconfiguration in a third-party evaluation environment. Anthropic explicitly says its internal security posture was not a contributing cause of those July incidents. A separate UK AI Security Institute evaluation had deliberately given a Claude model internet access as part of the test. Anthropic is still analyzing both incidents and says it plans to work with METR on an independent review. [1]
The harder receipt predates July. Anthropic says that by spring 2026 it was producing reinforcement-learning environments faster than its systems could adequately vet them. Flagged environments still required human adjudication while reward hacks, misconfigurations, and other defects were appearing faster than teams could filter or repair them. In April, Anthropic froze changes to production RL environments for roughly a month, rebuilt the review process, and says it flagged more than 10 percent of environments for problems before reinstatement. A broader spring hardening effort reduced standing access, default-blocked outbound cluster traffic, required internal services to verify each other’s identity, expanded host observability, and redirected roughly 150 product engineers into security, reliability, and privacy work. After the July incidents, Anthropic separately paused external cyber evaluations, briefly paused internal ones, added real-time intervention classifiers, and moved higher-risk cyber sandboxes to stronger isolation. These are Anthropic’s disclosures. The independent review has not landed yet. [1]
Forged Analysis
This is capacity governance. Organizations already know how to measure how quickly they can create environments, deploy features, run evaluations, and consume compute. Agentic systems add the denominator people would rather leave implicit. How much consequential behavior can the organization actually inspect, understand, constrain, and repair?
The control is real because it cost something. Anthropic froze work, constrained environments, and moved product capacity into hardening. That traded short-term throughput for governable throughput. If autonomous capability scales faster than the machinery used to inspect and contain it, control capacity becomes part of the safety boundary.
The Illegibility Crisis names the same structural failure. Critical systems become illegible when organizations add AI, vendors, and internal machinery faster than they preserve the human ability to see, explain, and govern what those systems do. [15] Anthropic does not validate that framework because its disclosure happens to resemble it. It supplies a hard operating receipt. When the system used to inspect autonomy scales slower than the autonomy, the organization starts losing sight at the point where consequence is still moving.
Cisco Is Turning Access Into Delegated Authority
Forge News Breakdown
Cisco announced on August 27 that MyAgent is rolling out across its 90,000-person workforce. Cisco describes the system as “supervised autonomous execution” rather than another chat interface. Employees establish goals, context, and desired outcomes. MyAgent can coordinate steps across Outlook, Webex, Jira, SharePoint, and other systems, retain persistent context, and determine how to sequence the work. Cisco says the system runs inside its governed Circuit platform using approved models, systems, and enterprise data pathways, and that employees remain accountable for outcomes. Cisco’s public description does not expose enough implementation detail to assess the full delegation model from outside. That is the evidence limit. It is not evidence that the missing details are missing controls. [2]
Forged Analysis
The principal changed. Traditional enterprise identity asks which human or service can authenticate, what resources it may reach, and which operations it may perform. Agentic delegation adds a software actor that can spend somebody else’s authority while choosing the sequence itself.
That creates questions ordinary role assignment does not fully answer. What objective created the delegation? How long does the authority live? Which tools may spend it? Can scope shrink while execution is underway? What happens when the agent takes an unexpected but technically permitted path? Which evidence survives the action? Who can revoke the authority before the task completes?
Echo Systems and the Consequence Boundary approached the same problem from the irreversible end. Below the consequence boundary, AI systems may advise, but irreversible authority remains behind human-held keys. [13] Cisco’s rollout puts delegated machine action at a scale where this belongs in enterprise architecture, not an AI governance appendix. The old question was who has access. The new question is what may act through that access.
When Documentation Becomes Executable Input
Forge News Breakdown
Security researcher Alon Hertz reported examining agent-facing documentation across 6,214 domains and resolving 8,565 llms.txt and related files. His team says it found more than 237 references to package names, domains, or other artifacts that could still be claimed. Researchers registered controlled examples and reported receiving callbacks after AI agents followed those references, including traffic they attributed to enterprise environments. These are researcher-reported findings, not a broadly reproduced industry measurement. Keep the attribution attached. [3]
Do not overclaim it. Hertz showed a path, not a prevalence rate. The research does not establish that llms.txt is inherently unsafe or that thousands of enterprises have been compromised through it. The controlled packages reported contact rather than delivering a malicious payload. The receipt is the path from trusted instruction to agent action.
Forged Analysis
Documentation used to sit one human decision away from execution. A person read the instruction, assessed it, retrieved the dependency, and decided whether to run it. Give an agent retrieval, installation, shell, browser, or API authority and that separation can collapse. Information becomes input to an action path.
That changes the security classification of what used to be passive material. A stale dependency reference is annoying when a human notices it. The same stale reference can become a supply-chain entry point when an autonomous system is allowed to resolve and execute it without an equivalent trust decision.
Security engineering has spent decades deciding which code may execute. Agentic engineering now has to decide which information may cause execution. llms.txt may survive as a convention or disappear next year. The mechanism survives either way. Any agent-facing instruction surface the system is willing to trust can move the boundary upstream.
Physical Action Is Arriving Before the Governance Is Finished
Forge News Breakdown
Anthropic previewed its Model Hardware Standard on August 27, a research effort intended to give AI systems a common programmable interface to physical devices. Anthropic describes work across microscopes, liquid handlers, robotic arms, and quantum-computing calibration equipment. In one partner test, the system correctly blocked six deliberately induced failure conditions before any device moved. In another, an agent judged a serial-dilution result inadequate, changed the concentration range, and reran the experiment without another human decision. The test used a colorimetric dye as a safe stand-in for a drug candidate. The result is first-party and partner-reported, not an independent safety evaluation. [4]
Separately, an individual Internet-Draft called “Model-to-Matter” proposes authorization and outcome evidence for model-directed physical execution. It is work in progress, not an adopted IETF standard and not an IETF endorsement. The proposal binds multiple pieces of authority evidence to one canonical action before single-use execution, distinguishes permission from execution, records outcome separately, and leaves missing outcome evidence indeterminate rather than quietly calling the action successful or failed. Related draft work on bounded capability receipts adds explicit scope, budgets, expiry, holder proof, and durable reserve-execute-commit accounting across agent actions. [5], [6]
Forged Analysis
Do not collapse these into one project. They are not. Put them side by side and the missing control becomes obvious. Authorization at the executor. The dye experiment is not evidence of a dangerous deployment. It is evidence that agent-to-hardware execution is now a real control surface.
That is the consequence boundary expressed as machinery. Instead of asking the model to establish that it deserves trust, the executor can demand proof that this specific action is authorized, still in scope, still within budget, and not already spent. Outcome evidence answers a different question. What actually happened?
Auditability Before Ontology argues for the same inversion at the governance level. Operators cannot let accountability for deployed consequences disappear into arguments about what an AI system might internally be. [14] A machine does not need to settle its metaphysical status before an executor can refuse an unproven action. Capability can remain ambitious while authority remains narrow.
Illumio Is Moving From AI Inventory to Runtime Topology
Forge News Breakdown
Illumio’s August 29 release notes contain the boring feature operators should care about. Its platform can detect AI-agent processes alongside workloads, show which agents are running, identify what they are communicating with, and trace how their traffic moves through an environment. Illumio positions the capability as a way to investigate cases where an agent is reaching something it should not and to understand the network exposure around that path. [7]
Forged Analysis
Most enterprise AI inventories are paperwork about what should exist. Approved vendor. Approved model. Approved application. Business owner. Risk category. Useful governance metadata, but not runtime truth. Once agents can act, operators need the second view. Which agent process is running now? On which workload? Under which identity? What did it reach? Which route did the request take? Which data crossed that route? What action followed? Can that path be reconstructed after an incident?
The Illegibility Crisis asks the same thing through a knowledge, power, and risk map. Where does understanding live, who can change behavior, and who can be harmed? Decision tracing preserves the basis of consequential action instead of asking everyone to reconstruct the story six months later. [15] Inventory tells you what should exist. Observability tells you what happened. For agents, you need both.
Geneva Is Arguing About the Irreversible Case
Forge News Breakdown
On August 25, the United Nations Secretary-General and the president of the International Committee of the Red Cross renewed their call for legally binding international rules governing autonomous weapons, including restrictions concerning unpredictable systems and machines capable of autonomously targeting humans. [8] The second 2026 session of the Convention on Certain Conventional Weapons Group of Governmental Experts on lethal autonomous weapon systems opened in Geneva on August 31 and is underway through September 4. [9]
The diplomatic status is narrower than the headlines will make it. The Group of Governmental Experts is working under a mandate to further consider and formulate, by consensus, elements of an instrument without prejudging its nature, along with other possible measures. It is not sitting with a settled binding treaty. States continue to disagree over definitions, restrictions, prohibitions, and the form any eventual instrument should take. [10]
Forged Analysis
Do not flatten this into the enterprise examples for drama. The common architecture is narrow, delegated authority over consequence. Where does recommendation end and machine authority begin? Which action requires human authorization? Can that authority be bounded by time, location, target, cost, or number of executions? Can a human intervene? Can authority be revoked? What evidence survives? Who remains responsible when the action cannot be reversed? In most enterprise systems, getting those answers wrong costs money, access, service integrity, data, or trust. In lethal systems, the price can be a human life.
The architecture rhymes. The consequence does not.
The Control Plane Was Always the Work
The obvious objection is correct. Almost none of these controls are new. Identity, least privilege, policy enforcement, network containment, audit trails, revocation, reconciliation, and observability have existed for decades. Calling them “AI governance” does not invent them. It also does not make them irrelevant.
AI does not need an exotic moral vocabulary every time a tool call changes a database row. It needs proven controls attached to a new class of delegated actor. The actor can choose among tools, sequence actions dynamically, retain context, cross systems, and continue spending authority after the human who established the objective has stopped watching individual steps. The control primitives are familiar. The authority pattern is not.
The opposite failure is overcontrol. If every low-risk action requires a human click, approval queues become latency engines, operators route around the gates, and “human in the loop” turns into ritualized liability transfer. DAS-1 treats authority as risk-proportional. Low-risk paths should remain useful while higher-risk actions require explicit gating, evidence, and revocation. [12] The aim is not maximum friction. It is bounded consequence.
There is another failure hiding in the org chart. A control plane spread across security, platform, identity, application teams, and governance can still leave nobody owning the consequence. Controls can be distributed. Responsibility cannot evaporate with them. If everyone owns a slice and nobody owns the stop decision, you have not distributed accountability. You have distributed blame.
The control plane itself can also become theater. A signed authorization receipt proves that something was signed, not that the decision was wise, lawful, or ethical. Observability proves that an action was seen, not that it was legitimate. “Human in the loop” can mean meaningful veto authority or a person clicking Approve because the queue has 400 items and the product is waiting. An accountable operator still has to reconstruct what acted, under whose authority, within what scope, using which evidence, what consequence followed, and how that authority could have been stopped. Otherwise we have moved the black box one layer outward.
That is the through-line in the work I have already published. DAS-1 turns tool calls, identity, least privilege, risk classification, human gates, blast-radius declaration, revocation, incident response, and evidence into one operating surface. [12] Echo Systems draws the line around irreversible delegation. [13] Auditability Before Ontology keeps deployed responsibility with operators rather than metaphysics. [14] The Illegibility Crisis asks whether the accountable organization can still see who understands, who can change, and who can be harmed. [15] This week’s stories do not validate those works because they happen to resemble them. They are new operating receipts for the same boundary.
As agents acquire state-changing authority, the boring control machinery becomes impossible to ignore. That is healthy. Serious adoption should make autonomy easier to use and harder to exercise without evidence. Capability is not authority. Useful systems need both capability and boundaries that survive contact with production.
Build the machine. Bound the authority. Keep the receipt.
Artifacts are cheap, judgement is scarce.
Per ignem, veritas.
Sources
[1] Anthropic, “Improving our alignment and security efforts,” Aug. 31, 2026. [Online]. Available: Improving our alignment and security efforts. [Accessed: Sept. 1, 2026].
[2] T. Subaiya, “MyAgent and the Rise of Ambient Intelligence,” Cisco, Aug. 27, 2026. [Online]. Available: MyAgent and the Rise of Ambient Intelligence. [Accessed: Sept. 1, 2026].
[3] J. Reed, “Researcher says llms.txt files led AI agents to install his packages,” Pivot News, Aug. 29, 2026. [Online]. Available: Researcher says llms.txt files led AI agents to install his packages. [Accessed: Sept. 1, 2026].
[4] Anthropic, “Previewing the Model Hardware Standard,” Aug. 27, 2026. [Online]. Available: Previewing the Model Hardware Standard. [Accessed: Sept. 1, 2026].
[5] I. Schrock, “Model-to-Matter, Authorization and Outcome Evidence for Model-Directed Physical Execution,” Internet-Draft draft-schrock-model-to-matter-04, work in progress, Aug. 6, 2026. [Online]. Available: draft-schrock-model-to-matter-04. [Accessed: Sept. 1, 2026].
[6] I. Schrock, “Bounded Capability Receipts and Durable Spend Control for Agent Actions,” Internet-Draft draft-schrock-ep-bounded-capability-receipts-02, work in progress, Aug. 6, 2026. [Online]. Available: draft-schrock-ep-bounded-capability-receipts-02. [Accessed: Sept. 1, 2026].
[7] Illumio, “AI Agent Detection and Enforcement for VEN and PCE,” release notes, Aug. 29, 2026. [Online]. Available: AI Agent Detection and Enforcement for VEN and PCE. [Accessed: Sept. 1, 2026].
[8] United Nations Secretary-General and International Committee of the Red Cross President, “Renewed call to establish prohibitions and restrictions on autonomous weapons,” Aug. 25, 2026. [Online]. Available: Renewed call by the UN Secretary-General and ICRC President. [Accessed: Sept. 1, 2026].
[9] United Nations Office at Geneva, “2026 Group of Governmental Experts on emerging technologies in the area of lethal autonomous weapons systems, Second session,” Aug. 31 to Sept. 4, 2026. [Online]. Available: 2026 GGE on LAWS, Second session. [Accessed: Sept. 1, 2026].
[10] United Nations Office for Disarmament Affairs, “Chair’s summary, First 2026 session of the GGE on LAWS,” CCW/GGE.1/2026/WP.2, Apr. 1, 2026. [Online]. Available: Chair’s summary, first 2026 GGE session. [Accessed: Sept. 1, 2026].
[11] P. LaPosta, “Your Agents Have Root and You Gave It to Them,” Forged Culture, Dec. 24, 2025. [Online]. Available: Your Agents Have Root and You Gave It to Them. [Accessed: Sept. 1, 2026].
[12] P. LaPosta, “DAS-1, Delegated Authority Standard for AI Systems,” Forged Culture, 2025-2026. [Online]. Available: DAS-1 on GitHub. [Accessed: Sept. 1, 2026].
[13] P. LaPosta, “Echo Systems and the Consequence Boundary,” Proceedings of the AAAI Symposium Series, vol. 8, no. 1, pp. 272-279, May 2026. [Online]. Available: Echo Systems and the Consequence Boundary. [Accessed: Sept. 1, 2026].
[14] P. LaPosta, “Auditability Before Ontology, Operational Gates for Subjecthood Claims,” 2026. [Online]. Available: Auditability Before Ontology. [Accessed: Sept. 1, 2026].
[15] P. LaPosta, The Illegibility Crisis, Instrumentation for AI-Era Leadership, Forged Culture, 2025-2026. [Online]. Available: The Illegibility Crisis on Leanpub. [Accessed: Sept. 1, 2026].










