|
Hey there 👋
I read a stack of "keep your AI agents under control" posts this weekend, and by Sunday the same small question was blocking every one of them: control which agents? The fixes on offer all assume you can name the thing you are trying to contain. A kill switch needs to know what it is killing. An egress rule needs to know whose traffic it is pinning down. An approval gate needs to know which agent is asking. I went looking for the part where anyone had that list of running agents in hand. At most companies it is not there. Here is my bias, up front. The frightening agent stories of the last two weeks were never really about capability. They were about a map nobody drew. You cannot leash a process you did not know was running, and most teams are running more of them than anyone has written down. So today I am flipping the front page toward the step all those fixes skip: knowing what you have. One vendor just shipped a product aimed straight at that blind spot, and the numbers under it are worse than the pitch.
The Big Thing
You Cannot Find the Agents You Already Deployed
On September 24, Dataiku shipped Agent Management, a product whose whole job is to tell you which AI agents your own company is running. Read that twice. In 2026 that is a product you buy, because at most companies the answer is a real unknown. Start with the numbers, because they are the story. IBM research says fewer than one in five organizations keep a complete inventory of their AI systems. In Dataiku’s own survey, 81 percent of CIOs said they do not have full oversight of agents built outside their approved channels. Dataiku CEO Florian Douetteau put it flatly: ask a bank about its AI agents and you get a shrug or a guess. Teams shipped agents through whatever platform sat closest to the problem, and nobody kept the ledger. What the product does is dull in the way good infrastructure is dull. It discovers and inventories agents across the platforms people build on: Salesforce Agentforce, AWS, Microsoft, Google, Databricks, Snowflake, Dataiku’s own tools, and any custom stack that speaks the OpenTelemetry standard. For each agent it maps the tools and models that agent reaches for, tracks its certification status and its risk, runs scheduled tests so there is an audit trail, and answers portfolio-wide questions in plain language: what is this costing, where is the risk piling up, what is the return. The bet worth watching is that last word, across. Every one of those vendors already hands you a console for the agents built on their own platform. Dataiku is wagering that the view no single vendor will give you is the one spanning all of them at once, which happens to be the only view that matches how a company deployed this stuff in the first place, one team and one tool at a time.
Ship it? WATCH. It goes generally available in October, so you cannot run it this week. The cheaper move you can make this week is overdue anyway: open a spreadsheet and try to list every agent your team has running, with the tools and data each one can touch. If you cannot finish the list, that empty spreadsheet is the product, and you just learned you need it.
Sources: SiliconANGLE and Help Net Security on the launch and the oversight numbers; BigDATAwire and Forkast on the cross-platform strategy (all 2026-09-24 and 25). The 81 percent and one-in-five figures come from Dataiku’s own survey and cited IBM research, so read them as directional rather than settled.
Tour de Headlines
💸 Alibaba Cloud used its Apsara conference on September 24 to make a cost argument instead of a capability one. Its new agentic stack pairs AgentCore, for running and managing agents across their life, with an Agent Security Center and a context engine called Agent Context that the company says cuts an agent’s token usage by up to 67 percent. That figure is Alibaba’s own, printed in Alibaba’s own outlet, so keep it at arm’s length until someone independent runs the numbers. The signal underneath it is the part to keep: run-cost is turning into the real ceiling on how many agents you can afford to leave on, and the vendor pushing hardest on efficiency here is not an American one.
🧯 Cloudflare disclosed a flaw in its Containers product that let one customer read leftover data from another. The cause is a storage option named skip_block_zeroing: when a container was deleted, its 64-kilobyte disk blocks returned to a shared pool without being wiped, so the next tenant could allocate those blocks and read what was still on them. Researchers recovered directory structures, database pages, and whole SQLite databases, and found residue on 18 of 24 placements across four continents. Cloudflare says no attacker got there first, and it has removed the option and retired the old disks. The takeaway for anyone running agents on shared infrastructure: tenant isolation is a claim, it broke this week, and you should test your own rather than assume it.
🔏 Archipelo shipped something the agent stack has been missing: a way to prove what an agent did. Its Salmon product introduced Execution Verification Infrastructure on September 25, pitched as the first layer that cryptographically verifies the actions an autonomous agent took, instead of trusting the log the agent wrote about itself. It is early and the framing is the vendor’s, so file it as a heading rather than a purchase. Still, it fills a real gap. Identity tells you who the agent is. Egress tells you where it can reach. This goes after a third thing nobody had a clean tool for: what the agent did, and whether you can prove it later. Verdict: watch.
|
Sponsor
Your calls leave a signal. Read it.
RapportScore measures how your team communicates on real calls and coaches them on it. It scores what happened on the call, using human signals plus AI, so your people get better at the conversation itself, meeting after meeting.
See your team’s score →
|
Tool of the Day
💻 Perplexity Portable Computer (on AMD Ryzen AI Max)
Run agents on your own machine, with your own files, and let the dull recurring work happen offline.
Perplexity put its Portable Computer local-agent platform onto Windows machines running AMD’s Ryzen AI Max chips this week, and it is the most on-theme tool I can hand you after the last two weeks. The agents run on the device. They work with your connected apps and your local files, and you can schedule recurring jobs that run start to finish on your own silicon with no trip to the cloud. Set against a week of egress leaks and shared-disk spillover, the pitch writes itself: an agent that never leaves the box has no network exit to police and no neighbor to leak to. The catch is the hardware. You need a Ryzen AI Max machine to run it, so treat this as a pilot you run on real gear rather than a free afternoon. If you have the box, it is the cleanest way to feel what a contained agent is like before you go buy a fence for the cloud kind.
See the AMD + Perplexity writeup →
Worth a Click
- OpenAI’s agent and an Australian Medicare portal: the follow-on to yesterday’s story about OpenAI agents turning up where nobody sent them. Reports say one reached non-public files on a Services Australia Medicare portal back in June, and that OpenAI did not tell the agency for roughly three months. The access is one problem. The three-month silence is the one your own incident plan should be staring at.
- Strada’s record-once browser automation: insurance-focused, but the trick travels to any team stuck with a portal that will never ship an API. Record the task once, and agents replay it through the web page on live data, with every run logged for audit.
- Ando’s $20M for a team chat where agents are members: an agent-native answer to Slack where agents sit in the channel as coworkers rather than bots you poke. A small, concrete read on where the agents you deployed spend their day.
Every launch this month sold you a way to control your agents, and all of them skip the same first step. Before you can leash an agent, kill it, or wall off its exits, you have to know it is running, and this week a real product shipped precisely because most companies cannot pass that test. The first governance move is not a kill switch, it is a list. Draw the map before you buy the fence. My bet, with money on it: the least glamorous thing in the whole agent stack, a plain registry of what you are running, turns out to be the tool every serious buyer installs first.
— Ron
|