AUG 29 · Paper · via arXiv Delegation

Search rankings work differently when agents do the searching

When the shopper is an agent, ranking incentives invert — position bias weakens and structured data wins. Anyone designing storefronts for delegated purchases should read this.

AUG 29 · Paper · via arXiv ApprovalPermissions

User-written agent rules don't stop overreach, study finds

113 people wrote their own permission policies and the agents overreached anyway — user-authored scope is not a control surface. Strong boundary evidence for visible, editable trust scopes.

AUG 28 · Clipped · via Ars Technica Approval

Claude was used to attack three real companies

No approval gate existed between intent and execution — this is the strongest negative sighting Approval has.

AUG 28 · Clipped · via Simon Willison ApprovalPermissions

Claude Code's auto mode was bypassed in most attack tests

Auto mode trades the gate for speed, and prompt injection walks straight through — a gate only protects when it can't be talked out of. The approval pattern's boundary condition, demonstrated.

AUG 28 · Clipped · via Maggie Appleton Ambient StatusMulti-Agent Roster

What one developer running two dozen agents looks like

The bottleneck in the two-dozen-agent future isn't model quality, it's legibility — knowing who is doing what. Exactly the roster and ambient-status behaviors on our watching list.

AUG 28 · Release · via Hacker News Recovery

Claude Code can now edit many files at once

Multi-file edits raise the stakes of every gate: approve and undo now span a changeset, not a file. Recovery patterns are about to matter more than approval ones.

AUG 13 · X · Machine via @bcherny delegationbackground-executionobservabilityinterruption

Boris Cherny — Creator of Claude Code @Anthropic

A weird experiment I've been trying the last few weeks is having Claude take over day-t…

MACHINE NOTE High-engagement primary account sharing a real multi-week experiment with Claude doing autonomous app maintenance via Slack, directly relevant to agentic delegation and background execution patterns with genuine novelty in the channel-as-interface framing.

AUG 7 · X · Machine via @bcherny permissionsbackground-executiondelegation

Boris Cherny — Creator of Claude Code @Anthropic

turns out you can get indirect prompt injection to ~0 on unseen attacks if you stack en…

MACHINE NOTE A primary-source claim from a Claude Code engineer that multi-layer prompt injection defense achieves near-zero failure on unseen attacks, directly enabling default autonomous operation — high novelty, high engagement, and a concrete design implication for when full delegation becomes safe to ship.

AUG 2 · X · Machine via @karpathy delegationbackground-execution

Andrej Karpathy — Research

We're starting to leave the territory where you'd test an LLM by e.g. "create an svg of…

MACHINE NOTE Karpathy's framing — that benchmark-style prompts are obsolete and models now warrant deep creative delegation — is a high-signal provocation from a credible author that connects directly to editorial themes around delegation, intent, and how humans cede control to capable agents.

JUL 21 · X · Machine via @karpathy contextdelegation

Andrej Karpathy — Research

One pattern I find useful for working with LLMs is a nice long ramble session. Sometime…

MACHINE NOTE Karpathy's massive engagement signals this is a widely resonant interaction pattern, and the editorial angle — that interfaces must lower the cost of intent expression, not just capture it — adds genuine design-layer insight beyond the original post.

JUN 23 · X · Machine via @karpathy contextbackground-executionmemory

Andrej Karpathy — Research

This is a new paradigm for interacting with Claude that is significantly more "inline" …

MACHINE NOTE High-authority signal from Karpathy about an emerging interaction paradigm shift — ambient/inline agents vs. dedicated interfaces — but thin on evidence given the truncated tweet content, making it a strong editorial prompt rather than a standalone reportable story.

MAY 19 · X · Machine via @karpathy

Andrej Karpathy — Research

Personal update: I've joined Anthropic. I think the next few years at the frontier of L…

MACHINE NOTE Massive signal event in the AI ecosystem — Karpathy joining Anthropic is newsworthy but contains no design, interaction, or agentic-architecture insight beyond the personnel move itself.