Plus: Google’s brain drain hits Gemini, and the money bets on governed agents. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
The Agent Stack mascot
The Agent Stack _
Daily B2B AI automation brief · Thursday, June 25, 2026 · Issue #18

Hey there 👋

Same week, same trick — played twice, in opposite directions. OpenAI pointed AI at the world’s open-source code to patch it. Anthropic has a tool, Mythos, that points the same kind of AI at code to break it. The model doesn’t care which way you aim it.

And while the labs argue over who patches the planet, Google keeps losing the people who build the models. Three marquee researchers gone in a week. The model good enough to rebuild Gemini is, it turns out, the most rentable part of the whole stack.

So here’s the question underneath today’s issue: what do you actually own when the model swaps out from under you? The same week the money is quietly answering it — betting on governed agents over autonomous ones. Five minutes — let’s go.


The Big Thing

OpenAI Is Now Patching the Planet’s Open-Source Code — With the Same AI That Can Break It

On Monday, June 22, OpenAI announced Patch the Planet — a name that nods to “Hack the Planet” from the 1995 film Hackers. The pitch: aim AI at the open-source code the entire software world runs on, find the bugs, and fix them. It’s partnered with the security firm Trail of Bits.

Here’s how it works. Trail of Bits security engineers work directly with open-source maintainers — reviewing code issues, developing patches and tests, and building reusable security workflows. OpenAI’s own tooling, Codex Security, assists. The whole thing is framed to reduce maintainer burden, not pile onto it: engineers triage findings before they ever reach the maintainer’s inbox.

Why this matters more than another “big company helps open source” headline. Open source is the bedrock under nearly every commercial codebase, and it’s chronically decentralized and under-resourced. Log4j is the canonical disaster — one volunteer-maintained library, one bug, the entire internet scrambling. The asymmetry has always favored offense: a handful of unpaid maintainers guarding code that a global pool of attackers gets to probe at leisure. The new wrinkle is that AI changes that math on both sides at once — it can now auto-find bugs and auto-write exploits. Anthropic’s Mythos is the publicized offense-capable version of exactly this. OpenAI just flipped the same capability to defense. TechCrunch reads it as both a real need and a competitive swipe at Anthropic — both can be true. The uncomfortable read for builders: whichever side automates first sets the tempo, and you don’t get to pick which side that is for the libraries you didn’t write.

Now the honest part. This was announced this week, on Monday. It’s an initiative — a program, not a product. You cannot sign up, point it at your repo, and walk away. It’s unclear how it scales. So don’t let anyone on your team treat it like a tool you can deploy on Thursday.

What you can deploy is the principle it forces. If one lab can auto-find and patch bugs across the open-source supply chain, assume attackers have the same auto-bug-finder pointed the other way. That changes your homework, not your shopping list.

So make it concrete this week. Start by inventorying your highest-risk open-source dependencies — a working SBOM (software bill of materials) for the handful of libraries that, if compromised, take your product down with them. Turn on AI-assisted dependency and code scanning in CI so a new advisory or a freshly introduced flaw surfaces in the pull request, not in an incident channel three weeks later. Pin the critical few to known-good versions and put them on a watch list so a quiet upstream change can’t slip in unnoticed. And run the whole exercise from the attacker’s seat: assume someone has already pointed the same auto-bug-finder at the exact libraries you depend on, and patch in that order. None of this is novel security advice — what’s new is that the cost of not doing it just dropped for the other side, too.

Ship it? WATCH the program, ACT on the principle. You can’t deploy Patch the Planet — but you can do everything it implies before Friday, and watch whether Codex Security eventually turns into something you can point at your own repos.

Sources: OpenAI (Patch the Planet) · Trail of Bits · TechCrunch


Tour de Headlines

🧠 Google’s brain drain becomes a flood — and it’s reshaping who builds your models. Talent flow is a leading indicator, and the arrow points away from Google. On June 24 (Bloomberg, via TechCrunch), Jonas Adler and Alexander Pritzel — both key to Gemini — left for Anthropic. On June 20, John Jumper, a DeepMind director who shared the 2024 Nobel Prize in Chemistry with Demis Hassabis for AlphaFold, also left for Anthropic. The week before, Noam Shazeer — at Google since 2000, re-acqui-hired for roughly $2.7B to work on Gemini — left for OpenAI. Don’t overreact: Gemini still ships, and these are individuals, not the whole bench. But with OpenAI and Anthropic prepping to go public, equity is a powerful magnet. The builder takeaway: if you’re anchoring a multi-year agent bet to a single primary lab, senior-talent flow is the cheapest leading indicator you have. The hedge is architectural — build model-agnostic, behind an abstraction you control, so an org-chart shift at one lab is a config change, not a rewrite that strands your stack.

Sources: TechCrunch · Bloomberg

🏦 The money is betting on governed agents, not autonomous ones. Read the structure of the deal, not just the dollar amount. Taktile, a New York fintech, raised a $110M Series C led by Goldman Sachs (reported in the June 24 VC roundup). Its product lets banks and insurers combine AI agents, rules, relevant context, and human oversight to automate decisions across underwriting, claims, fraud, onboarding, and AML. That’s the tell: the fundable pattern in regulated industries isn’t full autonomy — it’s agents wrapped in rules and a human in the loop. For builders in any vertical where a wrong call is expensive — finance, health, insurance, legal — treat that wrapper as the reference pattern. The rules layer plus a human checkpoint is what makes an agent shippable there: the difference between a demo and something a compliance team will sign off on. One caveat — this is a single secondary source, a VC funding roundup, so we’ll hold to the raise size, the lead investor, and those use cases, nothing more.

Source: Tech Startups (VC funding roundup, Jun 24)

🧑‍💻 AI was supposed to kill engineering jobs. New data says they’re the most resilient. Here’s the counter-narrative our readers actually live. New data suggests software engineering roles are among the most resilient to AI displacement — contrary to the “AI kills coding jobs” story everyone keeps repeating (TechCrunch, June 24, Marina Temkin). We have the headline and the framing, not the dataset, so no invented numbers here. The honest read: agents are changing the composition of the work — more orchestration and review, less line-by-line typing — not collapsing the headcount. The leverage is moving to people who can spec a problem cleanly, review an agent’s output with judgment, and orchestrate several of them at once — the parts that don’t reduce to autocomplete. If that’s where you point your own skill-building, the trend is a tailwind, not a threat. The job is shifting fast. It isn’t disappearing.

Source: TechCrunch


Sponsor

AI can rebuild Gemini. It still can’t tell you the deal’s slipping.

RapportScore reads the human signals in every sales and customer call and scores how well your team actually connects — deterministic measurement, not vibes. The models get poached and patched; the relationships are still won by people. See where rapport breaks before the deal does.

See your team’s score →

Tool of the Day

🧰 Perplexity Comet Enterprise

An AI browser IT can actually govern: silent MDM install, domain-scoped agent actions, and per-session audit logs.

To be clear up front: this is GA, not new — it’s been generally available since March 17, 2026. So treat this as an option to evaluate, not a launch to chase. Comet Enterprise is Perplexity’s AI-native browser built for organizations, and the reason it pairs with today’s governance theme is the admin layer. You get silent MDM deployment across macOS and Windows, hundreds of browser policies, and control over exactly which actions the agent can take — answer-only versus act, and act only on approved domains. It carries SOC 2 Type II, CrowdStrike Falcon integration, domain-level agent controls, and per-session audit logs. Activity inherits your enterprise data-retention, audit, and permission settings, and no data is used to train models. If you’re handing agents a browser, this is the kind of perimeter to measure others against. The sane pilot: push it via MDM to a small group in answer-only mode first, then enable actions on a short list of approved domains and read the per-session audit log before you widen the blast radius. Let the logs — not a vendor demo — tell you when the agent has earned more rope.

See Comet Enterprise →


Worth a Click


Own the supply chain; rent the brain. In one week, AI patched the planet’s open-source code and poached the planet’s top researchers — and both run on the same trick: a model good enough to read a codebase or rebuild Gemini. That model is the rented part. What you own — your dependency list, your audit log, your human-in-the-loop, the lab you anchored your stack to — is what’s left standing when the model swaps. This week proved the model layer is the most fluid thing in the stack. So pick the parts you own on purpose.

Stay sharp — The Agent Stack
Your daily 5-minute brief on AI agents, agentic workflows, and the automation tools B2B builders actually ship. Published weekday mornings by Pixiu Media Holdings LLC.

You’re receiving this because you subscribed to The Agent Stack. · Unsubscribe