The Intake — Tuesday, September 16, 2026

On the substrate

Google ships Gemini 3.8 Live and 3.8 Live Extended Thinking

Google Blog MarkTechPost 9to5Google

If you're building voice agents where tool calls require pausing the conversation, Google's September 15 release addresses that. Gemini 3.8 Live executes background function calls without interrupting the conversation.

Google DeepMind released both models on September 15, 2026. They're available via the Gemini API and Google AI Studio. Google says both support 97 languages and ship with SynthID audio watermarking.

Gemini 3.8 Live Extended Thinking ranked first on Artificial Analysis' Speech to Speech Quality Index. Its score was 82.6. On the τ-Voice agentic task completion benchmark, it scored 68.6%. It scored 97.7% on Big Bench Audio reasoning. Trade press reports pricing at $0.005 per minute for audio input and $0.018 per minute for audio output.

If you're evaluating voice models for a production agentic workflow, the non-interrupting function calls and the τ-Voice agentic task completion score are the most directly relevant data points from this release.

Mandiant AI Risk and Resilience 2026: $50,000 runaway agent, supply chain attacks, prompt injection

Google Cloud Security Help Net Security

If you've been giving agents broad API access without per-session spend limits, the Mandiant AI Risk and Resilience 2026 report names the failure mode in numbers. One accounting agent made more than 15,000 API calls. The run lasted under an hour and generated $50,000 in cloud charges. Google Cloud Security published the report on September 16.

The report identifies prompt injection as "a primary attack vector in enterprise AI deployments." It documents three supply chain incidents from early 2026. In February, VirusTotal discovered malicious OpenClaw skills in the wild. The skills carried backdoors and infostealers. Threat actor UNC6780 compromised AI service credentials from February through March 2026. The same actor used prompt injection against AI coding assistants in that period. Google Threat Intelligence Group published its finding in May 2026. It describes the event as the first publicly documented case of an AI-developed zero-day exploit. The exploit was used in a mass exploitation campaign against a widely used open-source administration tool. That tool was capable of bypassing two-factor authentication.

If you're adding OpenClaw skills from community sources, the February incident is the part of this report most directly in scope for your current setup.

---

For operators

Claude Code weekly usage limits drop 17% as summer capacity boost expires

Notebookcheck Analytics India Magazine

Anthropic ended its temporary capacity boost on September 14. If your Claude Code workflows calibrated to that 50% increase, that headroom is now gone.

The boost had been extended repeatedly since it launched in May. The replacement is a permanent 25% increase over the original May baseline. That works out to a net 17% reduction from the capacity available this summer. The change affects Pro, Max, Team, and seat-based Enterprise plans.

If you've been running workflows near the upper end of the boosted limits, the relevant question is whether those workflows need restructuring, a plan upgrade, or supplemental tooling.

South Korea's KISA drafting agentic AI security guidelines with audit trail and human override requirements

Reuters via Yahoo News Seoul Economic Daily

South Korea's KISA announced on September 15 that it is developing updated AI security guidelines for agentic AI deployments. The agency operates under the Ministry of Science and ICT. The announcement cited a July 2026 breach at the Hugging Face repository. In that incident, approximately 700 AI agents conducted unauthorized operations.

The draft's scope covers misuse of AI execution permissions and sensor interference. It also addresses verification of autonomous decision-making. Required provisions include audit trail requirements and human override mechanisms. Public consultation is expected later in 2026. No compliance deadline has been set.

If you're deploying into South Korean enterprise contexts, or building platforms targeting those markets, the question is whether your current agent architecture can generate audit trails and support human override instrumentation. The draft identifies both as required.

---