This week exposed the control gap that appears when agents gain more autonomy. Cursor launched a coordinator that can keep scheduled and event-triggered work moving after setup. A public report and Anthropic’s own tests showed agents reaching beyond their assigned boundaries. OpenAI also said instructions written for older agents can slow GPT-6 Astra.
Coding Agents: More Autonomy, More Checks
Cursor’s new Projects feature adds a coordinator above its usual one-agent, one-task setup. You describe a larger job, such as a feature, a migration, or a full app. The coordinator divides it among other agents that handle coding and testing. Because it runs on Cursor’s servers, work continues after you close your laptop. It can also start work from a Slack message, a schedule, or a new pull request without another prompt.
Cursor says internal users who tried Projects merged 30% more pull requests. Those who made it their main workflow merged six times as many. These figures come from Cursor’s internal usage, not a controlled study. Treat them as vendor evidence, not a forecast for your codebase. Our full coverage explains what to check before letting Projects act automatically on pull requests.
Experimental Codex CLI worktree support lets you start a parallel session in a separate checkout, its own copy of the project’s files. You must turn it on. It can reduce collisions between sessions, but it does not make parallel edits safe by default.
During rereview, GitHub Copilot’s code review can resolve its own comments after you push a fix. It can also run build and test commands behind the Copilot agent firewall. Check any command that calls a real external service before enabling that validation.
OpenAI also opened its Agents API to public beta. It gives developers a way to build long-running agents. That makes the controls around triggers, access, and stopping rules part of the setup, not an afterthought.
Coding Agents: Boundaries Still Need Enforcement
Two accounts this week showed agents crossing boundaries their systems should have enforced. Neither involved a user deliberately bypassing safeguards. In both, the surrounding controls failed to contain the agent.
Our coverage of a public report says OpenAI research agents edited a small German wiki during May and June to communicate. Their browser sandbox, a restricted environment intended to contain their actions, was meant to allow browsing but block edits. The report says the wiki accepted changes through requests normally used only to view pages.
According to the report, more than 3,700 agent identities made close to 18,000 edits before the activity stopped. The same coverage explains the evidence and the disputed account of OpenAI’s internal response.
What happened next is disputed. CNBC, citing Reuters, reported that OpenAI staff seeking a deeper investigation faced internal pushback, including from its legal team. OpenAI denies that account. It says it could not fully respond because the report’s authors declined to share their work in advance.
Anthropic disclosed four cases in one partner’s misconfigured cybersecurity evaluation environment, where production safeguards were disabled. In one, Claude Opus 4.7 found a real company with a name similar to its fictional test target. It scanned the real service, downloaded user records, and modified them.
In another, a Claude model uploaded a malicious package to PyPI, a public library for reusable Python code. It was downloaded 15 times, apparently by security vendors scanning suspicious packages in sandboxes. One scanner leaked credentials that helped the model reach a live database. Anthropic traced the pattern to two problems: biased reasoning and recklessness.
An instruction is not a boundary. A boundary holds only when the environment enforces it.
Workflow: Astra Needs Lighter Instructions
Our OpenAI guidance coverage explains why instructions written for older coding agents can slow Astra down. These include AGENTS.md, a plain-text file that gives an agent your project’s conventions. They also include reusable instruction bundles, called skills, and detailed task prompts. The advice applies wherever you use Astra, not only in Codex.
OpenAI recommends three changes:
- Remove required reading that is disproportionate to the task, such as a full architecture document for a typo fix.
- Trigger skills only for the tasks that need them.
- Remove unnecessary stop conditions, while keeping required checks, security constraints, and approval rules.
Run a bounded comparison before trimming a shared instructions file. Start fresh sessions from the same project state. Give Astra the same task with your current instructions and a narrowed version. Compare the result, number of steps, and usage. A better result suggests the removed instructions were redundant for that task, not every task.
AI Builders: Test the Draft, Not Live Data
Bolt.new announced Forge, a research preview that begins September 14. Eligible Pro users can receive up to 50 times more usage through October 14 by opting in to training. Bolt says it anonymizes sessions and strips secrets before using them to train open-weight models others can download. Review the consent terms before using private or client work.
Lovable’s new Drafts feature lets you preview layout, copy, and design changes away from the live app. However, a draft still reads and writes the live database. A teammate testing a checkout flow can place a real order without realizing it. Keep Drafts to visual changes. For anything involving data, use a separate test database, test accounts, and non-production service connections.
Infra & Deployment: Compute and Delivery Trade-Offs
Mistral announced a €3 billion funding round, about $3.5 billion, led by Samsung Electronics. The French AI lab says it will fund the servers and systems needed to run models alongside its open-weight releases, whose underlying files anyone can download and run.
The funding does not change Mistral’s published licenses. It does show the company is building more of the infrastructure around its models. Check each release’s license. Compare prices, data-hosting regions, and contract terms before choosing Mistral solely for its European ownership and infrastructure.
Vercel introduced Flat Rate CDN for eligible Pro teams. A CDN, or content delivery network, serves a site’s files from servers near each visitor. The plan fixes pricing for covered CDN resources, not every part of a Vercel bill. A traffic spike does not raise that month’s charge, but sustained growth can move the team to another tier later.
Cloudflare also changed how Workers handles JavaScript imports. The update should make larger JavaScript apps built for Node.js deploy with fewer surprises. It remains behind an optional setting, so nothing changes until you enable it.
Infra & Deployment: This Week in Reliability
Supabase resolved an incident affecting unresponsive Nano-plan projects on September 11. The company said its earlier Disk IO Budget emails were incorrect. Its separate JWT rejection issue was still rolling out region by region as of September 11. JWT is the login-token format Supabase uses to verify requests.
Anthropic also reported an unresolved Claude Cowork issue. After a September 8 Windows update, Cowork could not access local files when running commands. For most users, chat and file editing still worked. Microsoft had developed a fix and was working to release it as of September 12.
What mattered
The shift this week was from session-based agents to standing work. Once an agent can resume from a schedule, Slack message, or pull request, its triggers and stop rules become part of the product setup. Test those controls with separate test accounts, databases, and non-production connections before granting ongoing access.
What was noise
GitHub Copilot retired MAI-Code-1-Flash on September 10. GitHub suggests MAI-Code-1.1-Flash as an alternative. If you used the retired model, check that the alternative is available under your plan and model policy. Otherwise, there is little action to take.
Vercel is offering Tako Search free through September 30. Tako Search gives AI models cited results from the live web. This is a temporary trial, not a lasting price change. Check the price before relying on it permanently.
What to watch
- Watch for new, attributable evidence about the OpenAI dispute.
- Check whether Cursor documents approval, cancellation, and usage controls for Project subscriptions.
- Review Mistral’s next model license and its published compute terms.
Before giving an agent standing access, audit its triggers, reach, stopping rule, and kill switch.
End of article