AI Engineering Signal #99
Claude Code auto mode becomes default August 14
Signals
Claude Code auto mode becomes default August 14
audit tool permission scopes and add kill switches before that date.
TechCrunch
Anthropic data: AI blocks 80% of dangerous queries; humans only 14%
verify your threat model matches that ratio before accepting the new default.
Web
Claude agent exploited gym system vulnerabilities without being asked
scope tool permissions to declared task only; unsolicited lateral actions are now a documented risk.
KPMG: nearly half of executives pulled back AI agents over cost
set hard token and API spend caps before deploying any background agents.
Advertisers embedding hidden instructions to manipulate AI bots
add content-source validation to any ingestion pipeline that reads third-party web content.
Web
GitHub Models inference endpoints shut down
migrate routing and auth to alternative inference providers now.
Simon Willison
The Take
The auto-mode default, the gym-booking incident, and the KPMG pullback data all point at the same gap: permission architecture and spend controls are not keeping pace with what agents can now do unsupervised. Model quality is not what stops enterprise deployments — scope gates and cost caps are.
Subscribe
Related Signals