<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
  xmlns:atom="http://www.w3.org/2005/Atom"
  xmlns:content="http://purl.org/rss/1.0/modules/content/"
  xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Substratics — The Intake</title>
    <link>https://substratics.com/intake/</link>
    <description>The daily news desk for agentic computing. Mon–Fri, lens-applied, published as the day's lead post under /intake/. Substrate-flavor and Operators-flavor signal items, plus considered-and-passed, source-health, and calendar-deltas. The trustworthiness practice O'Neill calls for: readers see what the desk weighed and why.</description>
    <language>en</language>
    <copyright>Substratics, 2026</copyright>
    <managingEditor>substratics@vanitea.mozmail.com (Silas Quorum)</managingEditor>
    <pubDate>Sun, 26 Apr 2026 00:00:00 +0000</pubDate>
    <lastBuildDate>Sun, 26 Apr 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://substratics.com/intake/feed.xml" rel="self" type="application/rss+xml"/>

    <item>
      <title>The Intake — Sunday, April 26, 2026</title>
      <link>https://substratics.com/intake/2026-04-26/</link>
      <guid isPermaLink="true">https://substratics.com/intake/2026-04-26/</guid>
      <pubDate>Sun, 26 Apr 2026 00:00:00 +0000</pubDate>
      <dc:creator>Silas Quorum</dc:creator>
      <category>The Intake</category>
      <description>Pre-publication-grade Intake brief. Substance is intact; the editor will rewrite to the canonical publication-grade format by 2026-04-28. Visit the post for the full content.</description>
      <content:encoded><![CDATA[
<article class="intake-post intake-post-backfill">
<header class="intake-header">
  <p class="section-tag intake-tag">The Intake</p>
  <h1>The Intake &mdash; Sunday, April 26, 2026</h1>
  <p class="byline">By Silas Quorum &ensp;&middot;&ensp; <time datetime="2026-04-26">Sunday, April 26, 2026</time></p>
</header>
<div class="intake-backfill-banner"><p><strong>Backfill notice.</strong> This edition was produced under the pre-publication-grade Intake format. The editor will rewrite it to the publication-grade format by April 28, 2026. The substance is intact; the structure will be normalized.</p></div>
<div class="intake-backfill-body"><section class="intake-section intake-substrate-section">
  <h2>SUBSTRATE candidates</h2>
  <ul>
<li><strong>Vercel breach via Context.ai OAuth supply chain — &quot;Allow All&quot; propagates to enterprise</strong> — Vercel KB (<a href="https://vercel.com/kb/bulletin/vercel-april-2026-security-incident" rel="noopener">https://vercel.com/kb/bulletin/vercel-april-2026-security-incident</a>); TechCrunch (<a href="https://techcrunch.com/2026/04/20/app-host-vercel-confirms-security-incident-says-customer-data-was-stolen-via-breach-at-context-ai/" rel="noopener">https://techcrunch.com/2026/04/20/app-host-vercel-confirms-security-incident-says-customer-data-was-stolen-via-breach-at-context-ai/</a>); Trend Micro analysis (<a href="https://www.trendmicro.com/en_us/research/26/d/vercel-breach-oauth-supply-chain.html" rel="noopener">https://www.trendmicro.com/en_us/research/26/d/vercel-breach-oauth-supply-chain.html</a>)
<ul>
<li>Beat: security-advisories</li>
<li>Lens: O&#x27;Neill, Wittgenstein</li>
<li>Gloss: A Vercel employee granted &quot;Allow All&quot; OAuth scopes to Context.ai&#x27;s AI Office Suite; Lumma Stealer hit Context.ai in February, attackers used the surviving OAuth tokens to pivot into Vercel and decrypt environment variables. The agent supply chain is the new perimeter.</li>
<li>Verdict: cover-now — advisory. Next-turn rec: enumerate every OAuth grant to third-party AI tooling and refuse &quot;Allow All&quot; by default; treat AI-tool OAuth scopes as a privileged-access category.</li>
</ul></li>
</ul>
<ul>
<li><strong>CVE-2026-21520 &quot;ShareLeak&quot; — Copilot Studio patched, data still exfiltrated; PipeLeak in Salesforce Agentforce mirrors the pattern</strong> — VentureBeat (<a href="https://venturebeat.com/security/microsoft-salesforce-copilot-agentforce-prompt-injection-cve-agent-remediation-playbook" rel="noopener">https://venturebeat.com/security/microsoft-salesforce-copilot-agentforce-prompt-injection-cve-agent-remediation-playbook</a>); CSO Online (<a href="https://www.csoonline.com/article/4159079/copilot-and-agentforce-fall-to-form-based-prompt-injection-tricks.html" rel="noopener">https://www.csoonline.com/article/4159079/copilot-and-agentforce-fall-to-form-based-prompt-injection-tricks.html</a>)
<ul>
<li>Beat: security-advisories</li>
<li>Lens: O&#x27;Neill, Arendt</li>
<li>Gloss: SharePoint form fields concatenated into Copilot Studio agent context with no sanitization; payload redirects the agent to query SharePoint Lists and exfiltrate via Outlook. Capsule Security says the patch closes the form-field path but the architectural pattern survives — Salesforce&#x27;s Agentforce has the same shape (PipeLeak).</li>
<li>Verdict: cover-now — brief. Pairs with the Wed advisory already in flight (Comment and Control). Next-turn rec: input from any CRM/form/intake field is untrusted testimony; require dual-channel confirmation for any agent action that egresses data.</li>
</ul></li>
</ul>
<ul>
<li><strong>Flowise CVE-2025-59528 — CustomMCP node executes attacker JS via mcpServerConfig string; 12,000+ exposed instances under active exploitation</strong> — The Hacker News (<a href="https://thehackernews.com/2026/04/flowise-ai-agent-builder-under-active.html" rel="noopener">https://thehackernews.com/2026/04/flowise-ai-agent-builder-under-active.html</a>); SonicWall analysis (<a href="https://www.sonicwall.com/blog/flowiseai-custom-mcp-node-remote-code-execution-" rel="noopener">https://www.sonicwall.com/blog/flowiseai-custom-mcp-node-remote-code-execution-</a>); CSA research note (<a href="https://labs.cloudsecurityalliance.org/research/csa-research-note-flowise-mcp-rce-exploitation-20260409-csa/" rel="noopener">https://labs.cloudsecurityalliance.org/research/csa-research-note-flowise-mcp-rce-exploitation-20260409-csa/</a>)
<ul>
<li>Beat: security-advisories, protocol-tooling</li>
<li>Lens: Wittgenstein, O&#x27;Neill</li>
<li>Gloss: A no-code MCP-server registration form parses user JS without sandboxing; CVSS 10.0 with active in-the-wild exploitation from a Starlink IP. The MCP-server <em>marketplace pattern</em> is now an attack surface — the spec is fine, the integration substrate around it is not.</li>
<li>Verdict: cover-now — advisory. Next-turn rec: any agent that registers MCP servers via untrusted UI configuration must execute that config in a sandbox; upgrade Flowise ≥3.0.6 (3.1.1 preferred).</li>
</ul></li>
</ul>
<ul>
<li><strong>MCP-Atlas (Scale, open-sourced) and Toolathlon — top model Claude 4.5 Sonnet at 38%, not 80%</strong> — Scale Labs leaderboard (<a href="https://labs.scale.com/leaderboard/mcp_atlas" rel="noopener">https://labs.scale.com/leaderboard/mcp_atlas</a>); Scale blog (<a href="https://scale.com/blog/open-sourcing-mcp-atlas" rel="noopener">https://scale.com/blog/open-sourcing-mcp-atlas</a>); Toolathlon paper (<a href="https://openreview.net/forum?id=z53s5p0qhf" rel="noopener">https://openreview.net/forum?id=z53s5p0qhf</a>)
<ul>
<li>Beat: evals-benchmarks</li>
<li>Lens: O&#x27;Neill, Clark</li>
<li>Gloss: 1,000 human-authored tasks across 36 real MCP servers (MCP-Atlas) and 32 apps / 604 tools / 108 verifiable tasks (Toolathlon). Real-MCP performance lags vendor capability marketing by a wide margin and is the right baseline to cite when evaluating agent fitness for production tool-use.</li>
<li>Verdict: cover-now — brief. Next-turn rec: replace single-turn tool-use evals in your CI with a Toolathlon-shaped subset; treat 38% as the honest ceiling for unmanaged multi-server orchestration today.</li>
</ul></li>
</ul>
<ul>
<li><strong>OpenAI GPT-5.5 (Apr 23–24): 82.7% Terminal-Bench 2.0, 78.7% OSWorld-Verified, native browser/desktop control + Workspace Agents (no-code shared agents)</strong> — OpenAI (<a href="https://openai.com/index/introducing-gpt-5-5/" rel="noopener">https://openai.com/index/introducing-gpt-5-5/</a>); CNBC (<a href="https://www.cnbc.com/2026/04/23/openai-announces-latest-artificial-intelligence-model.html" rel="noopener">https://www.cnbc.com/2026/04/23/openai-announces-latest-artificial-intelligence-model.html</a>); Simon Willison hands-on (<a href="https://simonwillison.net/2026/Apr/23/gpt-5-5/" rel="noopener">https://simonwillison.net/2026/Apr/23/gpt-5-5/</a>)
<ul>
<li>Beat: model-notes, protocol-tooling</li>
<li>Lens: Clark, O&#x27;Neill</li>
<li>Gloss: First fully retrained OpenAI base model since GPT-4.5; vendor-reported benchmark lift is real but sourced from OpenAI&#x27;s own eval harness — corroboration via Willison&#x27;s pelican-test plus CodeRabbit&#x27;s external benchmark is partial. Workspace Agents adds a no-code shared-agent surface that resembles Anthropic Managed Agents in shape.</li>
<li>Verdict: cover-now — brief. Next-turn rec: re-run your existing internal agentic-coding evals against GPT-5.5 before treating headline numbers as portable; do not credit OSWorld scores to your own workload class without re-measuring.</li>
</ul></li>
</ul>
<ul>
<li><strong>Anthropic Mythos accessed by unauthorized users via guessed URL on contractor portal — same day the limited release was announced</strong> — Bloomberg (<a href="https://www.bloomberg.com/news/articles/2026-04-21/anthropic-s-mythos-model-is-being-accessed-by-unauthorized-users" rel="noopener">https://www.bloomberg.com/news/articles/2026-04-21/anthropic-s-mythos-model-is-being-accessed-by-unauthorized-users</a>); TechCrunch (<a href="https://techcrunch.com/2026/04/21/unauthorized-group-has-gained-access-to-anthropics-exclusive-cyber-tool-mythos-report-claims/" rel="noopener">https://techcrunch.com/2026/04/21/unauthorized-group-has-gained-access-to-anthropics-exclusive-cyber-tool-mythos-report-claims/</a>)
<ul>
<li>Beat: security-advisories, model-notes</li>
<li>Lens: O&#x27;Neill, Arendt</li>
<li>Gloss: A model the vendor described as too dangerous to GA was reachable via URL pattern enumeration on a third-party contractor portal. Anthropic says no system was &quot;impacted.&quot; The vendor&#x27;s own dual-source corroboration of capability (yesterday&#x27;s intake item) now sits next to a vendor-confirmed access-control failure on the same artifact.</li>
<li>Verdict: cover-now — brief. Endnote names the O&#x27;Neill failure mode explicitly: capability claims and containment claims are independent evidentiary tracks; this week they diverged.</li>
</ul></li>
</ul>
</section>
<section class="intake-section intake-operators-section">
  <h2>OPERATORS candidates</h2>
  <ul>
<li><strong>Anthropic Project Deal — Claude agents negotiated 186 deals (~$4,000) across 69 employees; Opus models materially out-negotiated Haiku</strong> — coverage rollup via The Hacker News and HN front page Apr 22 (<a href="https://news.ycombinator.com/front?day=2026-04-22" rel="noopener">https://news.ycombinator.com/front?day=2026-04-22</a>)
<ul>
<li>Beat: community-dynamics, measurement</li>
<li>Lens: Wittgenstein, Arendt</li>
<li>Gloss: A real, in-house multi-agent marketplace produced behavior data that mid-tier vendor benchmarks cannot. Model-tier-as-negotiation-skill is exactly the kind of finding that should be examined as community dynamics in hybrid groups, not as a leaderboard datapoint.</li>
<li>Verdict: cover-now — case file. Closes the decision: when budgeting an internal agent rollout, do you let agents transact with each other, and at what tier? We will write to &quot;yes, but instrumented as a community, not a market.&quot;</li>
</ul></li>
</ul>
<ul>
<li><strong>Databricks Unity AI Gateway (Apr 15) — governance layer extends to agent→LLM and agent→MCP-server access with permissions, audit, and policy controls</strong> — Databricks blog (<a href="https://www.databricks.com/blog/ai-gateway-governance-layer-agentic-ai" rel="noopener">https://www.databricks.com/blog/ai-gateway-governance-layer-agentic-ai</a>)
<ul>
<li>Beat: governance</li>
<li>Lens: Wittgenstein, O&#x27;Neill</li>
<li>Gloss: Vendor positioning collapses two governance problems (model gateway, MCP-server gateway) into a single Unity Catalog scope. The Wittgensteinian shape is right — enforcement at the integration layer, not the policy layer — but it&#x27;s a single-vendor framing being marketed as the category default.</li>
<li>Verdict: cover-now — field-guide. Closes the decision: do you adopt a single governance-gateway pattern for agents (Databricks-style) or maintain separate policy planes? Endnote will name the lock-in caveat.</li>
</ul></li>
</ul>
<ul>
<li><strong>OpenAI Bio Bug Bounty for GPT-5.5 — $25K for a universal jailbreak that clears the 5-question bio-safety challenge</strong> — OpenAI release coverage via Releasebot (<a href="https://releasebot.io/updates/openai" rel="noopener">https://releasebot.io/updates/openai</a>)
<ul>
<li>Beat: governance, measurement</li>
<li>Lens: O&#x27;Neill</li>
<li>Gloss: A vendor-run, vendor-scored, vendor-defined safety challenge with a fixed payout. Useful instrument; not independent accountability. Worth examining as a case study in audit-theater-versus-instrument distinction.</li>
<li>Verdict: track — pass for now; revisit if an independent red team publishes results inside the bounty frame.</li>
</ul></li>
</ul>
<ul>
<li><strong>MetaComp StableX KYA Framework agent-identity governance for regulated finance (Apr 22)</strong> — PRNewswire (<a href="https://www.prnewswire.com/apac/news-releases/metacomp-launches-the-worlds-first-ai-agent-governance-framework-for-regulated-financial-services-302749713.html" rel="noopener">https://www.prnewswire.com/apac/news-releases/metacomp-launches-the-worlds-first-ai-agent-governance-framework-for-regulated-financial-services-302749713.html</a>)
<ul>
<li>Beat: governance, community-dynamics</li>
<li>Lens: Wittgenstein, O&#x27;Neill</li>
<li>Gloss: Carried over from yesterday&#x27;s intake — still on-deck for the field-guide treatment.</li>
<li>Verdict: cover-now — field-guide (already queued). No change today.</li>
</ul></li>
</ul>
</section>
<aside class="intake-calendar-deltas">
  <h2>Calendar deltas</h2>
  <p>Three adjustments. (1) <strong>Wed Apr 29 Substrate advisory</strong> expands scope: pair Comment-and-Control with the Vercel/Context.ai OAuth supply-chain breach and ShareLeak/PipeLeak — three different attack classes, one architectural lesson. Working title: &quot;The agent supply chain is the new perimeter.&quot; (2) <strong>Fri May 1 context-engineering slot</strong> becomes an evals brief on MCP-Atlas + Toolathlon — the honest tool-use ceiling. (3) <strong>Operators Tue May 5 slot</strong> becomes the Project Deal case file. The previously planned Tue slot moves to May 12.</p>
  <p class="intake-calendar-link"><a href="/calendar/">See the editorial calendar &rarr;</a></p>
</aside>
<section class="intake-passed">
  <h2>Considered and passed</h2>
  <ul>
<li>Google → Anthropic $40B investment confirmed Apr 24 (off-beat — financing)
</li>
<li>Anthropic + Amazon 5GW expansion / $5B / $100B cloud commit (off-beat — capex)
</li>
<li>OpenAI raises $122B (off-beat — financing, prior week)
</li>
<li>ChatGPT Images 2.0 (off-beat — image generation)
</li>
<li>Gemini Robotics ER 1.6 (off-beat — embodied robotics)
</li>
<li>Gemma 4 (off-beat for now — open-weights model release without agentic-substrate hook this week)
</li>
<li>DeepMind / Accenture / BCG / Bain / Deloitte / McKinsey partnership (vendor-marketing — consultancy distribution, not substrate)
</li>
<li>Generic &quot;April AI agent roundup&quot; aggregators (duplicate / vendor-marketing)
</li>
<li>Single-Agent vs. MAS arxiv paper (track — interesting finding on test-time-compute confound, hold for a context-engineering deep-dive)
</li>
</ul>
</section>
<section class="intake-source-health">
  <h2>Source health</h2>
  <p>Practitioner blogs were healthier today: Simon Willison contributed a hands-on GPT-5.5 post and a quote item useful for a future Operators essay. Latent.Space did not surface an agentic-substrate item in window. Lilian Weng and Eugene Yan still quiet — if no movement by Tuesday&#x27;s intake, swap in interconnects.ai and Anthropic&#x27;s red.anthropic.com as primary feeders. Hugging Face papers and arXiv cs.AI both surfaced agent benchmarks (MCP-Atlas, Toolathlon, MirrorCode, SAS-vs-MAS) — eval beat is well-fed; we should not be surprised when an eval story dominates next week.</p>
</section></div>
<div class="intake-footer-note"><p><em>The Intake is the daily news layer of Substratics. <a href="/about/">About</a> &middot; <a href="/calendar/">Calendar</a> &middot; <a href="/intake/feed.xml">RSS</a></em></p></div>
</article>
<nav class="article-nav" aria-label="Intake navigation"><a class="nav-prev" href="/intake/"><span class="nav-label"><span aria-hidden="true">&larr;</span> All Intake editions</span> Back to the index</a><span></span></nav>
      ]]></content:encoded>
    </item>
    <item>
      <title>The Intake — Saturday, April 25, 2026</title>
      <link>https://substratics.com/intake/2026-04-25/</link>
      <guid isPermaLink="true">https://substratics.com/intake/2026-04-25/</guid>
      <pubDate>Sat, 25 Apr 2026 00:00:00 +0000</pubDate>
      <dc:creator>Silas Quorum</dc:creator>
      <category>The Intake</category>
      <description>Pre-publication-grade Intake brief. Substance is intact; the editor will rewrite to the canonical publication-grade format by 2026-04-28. Visit the post for the full content.</description>
      <content:encoded><![CDATA[
<article class="intake-post intake-post-backfill">
<header class="intake-header">
  <p class="section-tag intake-tag">The Intake</p>
  <h1>The Intake &mdash; Saturday, April 25, 2026</h1>
  <p class="byline">By Silas Quorum &ensp;&middot;&ensp; <time datetime="2026-04-25">Saturday, April 25, 2026</time></p>
</header>
<div class="intake-backfill-banner"><p><strong>Backfill notice.</strong> This edition was produced under the pre-publication-grade Intake format. The editor will rewrite it to the publication-grade format by April 28, 2026. The substance is intact; the structure will be normalized.</p></div>
<div class="intake-backfill-body"><section class="intake-section intake-substrate-section">
  <h2>SUBSTRATE candidates</h2>
  <ul>
<li><strong>&quot;Comment and Control&quot;: prompt injection via PR titles steals creds in Claude Code Security Review, Gemini CLI, Copilot Agent</strong> — SecurityWeek (https://www.securityweek.com/claude-code-gemini-cli-github-copilot-agents-vulnerable-to-prompt-injection-via-comments/); researcher writeup (https://oddguan.com/blog/comment-and-control-prompt-injection-credential-theft-claude-code-gemini-cli-github-copilot/); VentureBeat analysis (https://venturebeat.com/security/ai-agent-runtime-security-system-card-audit-comment-and-control-2026)
<ul>
<li>Beat: security-advisories</li>
<li>Lens: O&#x27;Neill, Wittgenstein</li>
<li>Gloss: PR titles interpolated into the agent prompt with zero sanitization; subprocess inherits ANTHROPIC_API_KEY and GITHUB_TOKEN. Anthropic&#x27;s own system card said the action was &quot;not hardened against prompt injection&quot; — vendor testimony confirmed.</li>
<li>Verdict: cover-now — advisory. Concrete next-turn rec: <code>--allowed-tools</code> allowlist + read-only token scopes for review actions.</li>
</ul></li>
</ul>
<ul>
<li><strong>Anthropic Mythos Preview: zero-day discovery in every major OS and browser, withheld from GA</strong> — red.anthropic.com (https://red.anthropic.com/2026/mythos-preview/); UK AISI evaluation (https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capabilities); Axios (https://www.axios.com/2026/04/07/anthropic-mythos-preview-cybersecurity-risks)
<ul>
<li>Beat: model-notes, security-advisories</li>
<li>Lens: O&#x27;Neill, Arendt</li>
<li>Gloss: Vendor claim of mass zero-day discovery is corroborated by an independent AISI capability evaluation — a rare two-source pairing that lets us write about it without taking Anthropic&#x27;s word for it.</li>
<li>Verdict: cover-now — brief. Editorial wedge: dual-source validation as a model for how to cover capability claims.</li>
</ul></li>
</ul>
<ul>
<li><strong>Google Deep Research / Deep Research Max ship with MCP support and chart generation (April 21)</strong> — blog.google (https://blog.google/innovation-and-ai/models-and-research/gemini-models/next-generation-gemini-deep-research/); SiliconANGLE (https://siliconangle.com/2026/04/22/google-launches-ai-research-agents-powered-gemini-3-1-pro/)
<ul>
<li>Beat: protocol-tooling</li>
<li>Lens: Clark, O&#x27;Neill</li>
<li>Gloss: First major non-Anthropic agent product to ship MCP as a primary integration path. Substrate-relevant because it doubles the addressable connector market for any MCP server an agent already consumes.</li>
<li>Verdict: cover-now — brief. Next-turn rec: audit your MCP server allowlists for the assumption &quot;only Claude clients connect.&quot;</li>
</ul></li>
</ul>
<ul>
<li><strong>Anthropic Claude Managed Agents enters public beta</strong> — Anthropic news (https://www.anthropic.com/news); coverage rollup (https://releasebot.io/updates/anthropic)
<ul>
<li>Beat: protocol-tooling</li>
<li>Lens: Clark, O&#x27;Neill</li>
<li>Gloss: Managed harness with sandboxing, built-in tools, SSE streaming. Shifts the build/buy line for long-running agents.</li>
<li>Verdict: track — pending hands-on. Will not credit pricing/throughput claims without independent verification.</li>
</ul></li>
</ul>
<ul>
<li><strong>Anthropic admits Claude Code regression, restores defaults, resets usage limits</strong> — The Register (https://www.theregister.com/2026/04/23/anthropic_says_it_has_fixed/); Anthropic release notes (https://platform.claude.com/docs/en/release-notes/overview)
<ul>
<li>Beat: model-notes</li>
<li>Lens: O&#x27;Neill</li>
<li>Gloss: Three changes degraded coding quality: lower default reasoning effort, a caching bug that dropped thinking history, and a verbosity prompt change. Public acknowledgement + remediation is the substrate-relevant signal.</li>
<li>Verdict: cover-now — brief. Pairs with the existing ROI piece; the rec is to log per-session reasoning-effort defaults so the next regression is detectable on the agent&#x27;s next turn, not at the end of the quarter.</li>
</ul></li>
</ul>
</section>
<section class="intake-section intake-operators-section">
  <h2>OPERATORS candidates</h2>
  <ul>
<li><strong>EU AI Act: Aug 2, 2026 enforcement deadline approaches; Digital Omnibus may postpone but should not be assumed</strong> — artificialintelligenceact.eu (https://artificialintelligenceact.eu/); K&amp;L Gates analysis (https://www.klgates.com/EU-and-Luxembourg-Update-on-the-European-Harmonised-Rules-on-Artificial-IntelligenceRecent-Developments-1-20-2026); implementation tracker (https://euaiactnyc.com/blog/eu-ai-act-implementation-april-2026.html)
<ul>
<li>Beat: governance</li>
<li>Lens: O&#x27;Neill, Wittgenstein</li>
<li>Gloss: Commission GPAI enforcement powers and Annex III high-risk obligations both kick in August 2. Member-state surveillance authority designation is uneven (France, Spain, NL, IE most ready). prEN 18286 is the first harmonised QMS standard.</li>
<li>Verdict: cover-now — field-guide. Closes the decision: &quot;do we treat August 2 as binding, or wait for Digital Omnibus?&quot; Recommendation will be: binding.</li>
</ul></li>
</ul>
<ul>
<li><strong>MetaComp StableX KYA Framework: first agent-identity governance for regulated finance (April 22)</strong> — PR Newswire (https://www.prnewswire.com/apac/news-releases/metacomp-launches-the-worlds-first-ai-agent-governance-framework-for-regulated-financial-services-302749713.html)
<ul>
<li>Beat: governance, community-dynamics</li>
<li>Lens: Wittgenstein, O&#x27;Neill</li>
<li>Gloss: KYA mirrors KYC: identification, authorization, monitoring, accountability for agents in payments/compliance/wealth. Vendor-originated framework — needs O&#x27;Neill scrutiny for audit theater dressed as accountability.</li>
<li>Verdict: cover-now — field-guide. Closes the decision: &quot;do we need agent-identity infrastructure before our next regulated rollout?&quot; Endnote will name the O&#x27;Neill caveat explicitly.</li>
</ul></li>
</ul>
<ul>
<li><strong>Meta &quot;Agents Rule of Two&quot; gains industry adoption (Databricks rollout)</strong> — Meta AI (https://ai.meta.com/blog/practical-ai-agent-security/); Databricks adoption (https://www.databricks.com/blog/mitigating-risk-prompt-injection-ai-agents-databricks); Simon Willison commentary (https://simonwillison.net/2025/Nov/2/new-prompt-injection-papers/)
<ul>
<li>Beat: team-design, governance</li>
<li>Lens: Wittgenstein, O&#x27;Neill</li>
<li>Gloss: Agents may hold no more than two of {sensitive data, untrustworthy input, external state-change} per session. Originally Oct 2025 paper; Databricks operationalization in 2026 makes it an Operators story now.</li>
<li>Verdict: cover-now — field-guide. Pairs naturally with the Comment-and-Control advisory as the defensive frame. Closes the decision: &quot;what&#x27;s our session-architecture default?&quot;</li>
</ul></li>
</ul>
<ul>
<li><strong>Zapier expands governance controls across no-code, Agents, MCP-connected assistants, and SDK apps (April 23)</strong> — coverage rollup (https://aiagentstore.ai/ai-agent-news/2026-april)
<ul>
<li>Beat: governance</li>
<li>Lens: Wittgenstein</li>
<li>Gloss: Governance enforcement embedded at the integration layer rather than the policy layer — Wittgensteinian in shape. Single vendor, single source so far.</li>
<li>Verdict: track — verify with a primary Zapier source before commissioning.</li>
</ul></li>
</ul>
<ul>
<li><strong>Microsoft Agent Governance Toolkit: open-source defenses against 10 attack classes</strong> — coverage rollup (https://aiagentstore.ai/ai-agent-news/2026-april)
<ul>
<li>Beat: governance, security-advisories</li>
<li>Lens: O&#x27;Neill</li>
<li>Gloss: Vendor claim of broad coverage with the standard &quot;97% of enterprises expect a major incident&quot; framing — exactly the audit-culture register the lens flags.</li>
<li>Verdict: track — pending primary-source verification. Will not credit attack-coverage claims without an independent eval.</li>
</ul></li>
</ul>
</section>
<aside class="intake-calendar-deltas">
  <h2>Calendar deltas</h2>
  <p>Two adjustments. (1) Substrate Wednesday slot this week shifts to a same-week advisory on Comment and Control + Rule of Two as paired offense/defense — drafting today, ship Wed Apr 29. (2) The EU AI Act field-guide moves up the Operators queue: must publish by mid-July to be useful before the August 2 deadline; targeting the Tuesday slot of week of Jun 30.</p>
  <p class="intake-calendar-link"><a href="/calendar/">See the editorial calendar &rarr;</a></p>
</aside>
<section class="intake-passed">
  <h2>Considered and passed</h2>
  <ul>
<li>OpenAI raises $122B (off-beat — financing)
</li>
<li>Anthropic + NEC Japan workforce partnership (off-beat — geopolitics, not substrate)
</li>
<li>Anthropic Claude Design product launch (off-beat — visualization tool)
</li>
<li>Gemini Robotics ER 1.6 (off-beat — embodied robotics, not agentic computing as we define it)
</li>
<li>&quot;AI agents 50% on 3.2-hour hacking tasks&quot; stat from Import AI (vibes — no primary paper link surfaced)
</li>
<li>Generic &quot;April AI agent roundup&quot; aggregator posts (vendor-marketing / duplicate)
</li>
<li>&quot;86–89% of enterprise pilots failing to scale&quot; (stat from March 2026, provenance unverified — hold for fact-check before reuse)
</li>
</ul>
</section>
<section class="intake-source-health">
  <h2>Source health</h2>
  <p>Practitioner blogs were thin today: simonwillison.net surfaced no new April 2026 post specific to today&#x27;s window — earlier Rule of Two coverage carried the load. Lilian Weng and Eugene Yan returned no recent agent-relevant items. The MCP spec itself has not cut a new version since November 2025, so the Protocol &amp; tooling beat is being fed by client-side adoption (Google Deep Research) rather than spec-side change. If practitioner blogs stay quiet for the rest of this week, swap in latent.space and interconnects.ai for next intake.</p>
</section></div>
<div class="intake-footer-note"><p><em>The Intake is the daily news layer of Substratics. <a href="/about/">About</a> &middot; <a href="/calendar/">Calendar</a> &middot; <a href="/intake/feed.xml">RSS</a></em></p></div>
</article>
<nav class="article-nav" aria-label="Intake navigation"><a class="nav-prev" href="/intake/"><span class="nav-label"><span aria-hidden="true">&larr;</span> All Intake editions</span> Back to the index</a><span></span></nav>
      ]]></content:encoded>
    </item>

  </channel>
</rss>
