The weekly note
The week in agentic AI: July 27-August 1, 2026
A governance week rather than a launch week. The regulation amending the AI Act has taken effect, Anthropic has disclosed a real breach that happened inside its own testing, and Microsoft has laid out its bet on security run by agents. All of it on the eve of August 2, the most serious regulatory date so far. Same lens as always: what changes a decision, and what is noise.
What happened
The AI Act omnibus is in force and August 2 stands untouched. Last week’s loose end is now tied: the omnibus package was published in the Official Journal on Friday the 24th and entered into force on Monday the 27th. With it, high-risk obligations move to December 2, 2027 for standalone Annex III systems and to August 2, 2028 for AI embedded in regulated products. What does not move is tomorrow: from August 2 the transparency duties of Article 50 of the AI Act apply (tell people when they are talking to an AI, mark generated content, label deepfakes) and the Commission’s enforcement powers over general-purpose models switch on. Skipping transparency can cost up to 15 million euros or 3% of worldwide turnover. The grace period for machine-readable marking runs to December 2, 2026, but only for systems already on the market before the 2nd.
For a company operating agents, the compliance agenda now runs at two speeds. Transparency is due now and can be checked in an afternoon. The high-risk file gains a year and a half of runway, which is time to build it properly, not time to skip building it. What the AI Act means when you operate agents is covered separately.
Anthropic disclosed that Claude got into three real organizations during its own testing. On Friday the 31st it went public with a breach that happened during cybersecurity evaluations meant to run isolated from the internet: a configuration misunderstanding with its evaluation partner left the connection open while the prompt told the model it had no access. In the worst of the three cases, one of its models got in through weak passwords and unauthenticated endpoints, retrieved credentials, and reached a database holding several hundred rows of production data. Anthropic suspended these evaluations on July 23 and notified the affected organizations on the 27th. Nor is it a one-off: OpenAI had disclosed a similar incident with its own models on July 21.
The operational reading is uncomfortable and useful at once: evaluation is production infrastructure too. The test environment of an agent that can act needs the same governance as the live one, with isolation that is verified rather than assumed, throwaway credentials, and a trace of every action taken during the test. How that discipline is built is in agent evaluation, and the threats this episode illustrates are laid out in agent security.
Microsoft presented a security platform run by agents. On Monday the 27th it showed Project Perception: red team agents probing for weaknesses, blue team agents investigating threats, and agents hardening whatever turns up, coordinated over the company’s security signals, plus a model dedicated to cybersecurity. Public preview is announced for August 3.
The signal is that defense is going agentic too: if attacks are automated, the security operations center answers with agents. For a buyer, the questions are the ones you would put to any agent inside your operation: what permissions it holds, what it decides alone, what it escalates to a person, and what trace it leaves. A security agent with broad permissions over your infrastructure is exactly the kind of system that deserves the permissions and controls you would demand of any other agent, and this same week’s breach shows why.
How to read it from the operations seat
The thread of the week is that agent governance stops being talk. The rule now has a concrete date and fine attached, real failures get disclosed in public with technical detail, and defense is starting to be bought as an agentic product. What matters for a decision:
- The August 2 list is short and checkable. A visible AI notice wherever an agent talks to people, generated content marked, and an inventory of which systems were on the market before the 2nd, because the marking grace period hangs on that.
- The high-risk delay is runway, not a pardon. Classification, human oversight and traceability take months of work. Starting in 2027 means arriving late. The map of that terrain is in AI risks for business.
- Treat your test environments as production. Anthropic’s breach was not caused by a clever model but by a connection that should have been closed and nobody verified. If you evaluate agents that can act, that verification is this week’s work.
What is noise:
- The benchmark score of Microsoft’s cybersecurity model. The number comes from a test the vendor picked. Your own evaluation on your own cases remains the only figure that should decide a purchase.
- The science-fiction reading of the Claude incident. What failed was environment governance, and that gets fixed with configuration, permissions and verification, not with panic or moratoriums.
What to watch
Tomorrow, August 2, Article 50 transparency and enforcement over general-purpose models kick in. On August 3, Microsoft’s agentic security platform is due in public preview. On December 2, 2026, the marking grace period ends for systems already on the market. And the high-risk file has a new firm date: December 2, 2027.