AgentsSep 2

Image: blog.google
Google opens Fairwind, a restricted AI vulnerability-fixing program
Google's Fairwind Program opened yesterday to a selected group of government, critical-infrastructure, and cybersecurity partners. It pairs Gemini 3.8 Flash Cyber with the CodeMender harness, which finds vulnerabilities, verifies them, and writes code fixes. Partners can test whether that shortens the trip from spotting a software flaw to holding a validated patch, which would make repair work at scale more practical for the organizations running essential services and widely used software. Google says more than 650 partners are taking part.
Positive - Google restricted a vulnerability-fixing model to 650 vetted government, infrastructure, and security partners, expanding defensive capacity while containing access.
AgentsSep 3

Image: The Threshold Report/GPT Image 2
Okta adds AI-agent discovery to all identity posture subscriptions
Okta turned on AI-agent discovery for all Identity Security Posture Management subscriptions today. The feature inventories homegrown agents from supported builder platforms, shadow AI applications and OAuth grants seen in managed browsers, and agent-related identity risks, all in a single posture view. Security teams can start listing the agents employees have wired into company data and tools without central approval, and catch that unmanaged access before an agent becomes the way into an incident.
Positive - Okta now automatically inventories sanctioned and shadow AI agents across its subscriptions, exposing identity risks that organizations could not previously manage centrally.
TextSep 2

Image: theverge.com
Alexa for Shopping can check whether an Amazon message is genuine
Amazon added a scam check to Alexa for Shopping yesterday, letting customers ask whether an email, text, or call claiming to come from Amazon is real. The system compares the message against Amazon's own records and examines sender information, content, timing, and metadata. That gives a shopper somewhere to look before acting on a fake delivery notice, account warning, or one-time-password message. Amazon says the assistant confirms a message only when it is completely certain the message originated from Amazon.
Positive - Amazon gave customers a live check against its own records, making impersonation messages easier to catch before they succeed.
TextSep 2
OpenAI's unreleased Astra may put reasoning beyond safety monitors
OpenAI's unreleased Astra model uses a limited form of recurrent-depth reasoning, a design that can push more of the computation into internal loops that leave no readable trace, TechCrunch and The Verge reported yesterday. Safety teams read a model's written-out reasoning steps as one signal for catching harmful plans or misaligned behavior, and that signal carries less when the work stays inside the model. OpenAI did not confirm the architecture to The Verge, and said it is deploying Astra with additional chain-of-thought monitoring (checks on the step-by-step reasoning text the model does write out).
Negative - Astra’s reported recurrent-depth design shifts reasoning into less legible internal loops, making safety monitors less able to see how the model reaches decisions.
TextSep 2
New York City bars classroom AI through eighth grade
New York City announced a one-year classroom AI moratorium yesterday, covering public-school students from 2-K through eighth grade, about 600,000 of them. Teachers may not use AI to grade assignments, and companion chatbots are barred across all grades, while limited high-school use and a small pilot stay permitted. The policy leaves room for vetted exceptions for accessibility and multilingual learning.
Negative - New York City barred most classroom AI through eighth grade rather than setting conditions for its use, blocking deployment for roughly 600,000 students.
TextSep 1
Anthropic plans misuse monitoring that runs in a customer's own cloud
Anthropic announced Enterprise Frontier Safeguards on Sept. 1, a forthcoming option that stores activity data in the customer's own AWS, Azure, or Google Cloud account under customer-managed controls. Automated systems will examine rolling windows of traffic for serious cyber or biological misuse and for stolen credentials, and flags go to the customer's teams instead of Anthropic staff. Regulated organizations could use covered frontier models while keeping the logs, the encryption keys, and the access policies, with their own people reviewing whatever gets flagged. Anthropic says the design is meant to pair cross-session misuse detection with the customer custody of a zero-data-retention arrangement.
Positive - Anthropic’s planned safeguards will let enterprise customers monitor frontier-model traffic for serious misuse while retaining control of sensitive activity data.