Limiting what the agent can do is the part people still underestimate. If a prompt injection slips through, runtime controls and decision logs are what keep it from turning into an exfiltration or hijack incident.
What you actually get with FRIDAY:
1. Your evenings back.
2. The three options that fit instead of the three thousand that do not.
3. The thing you half-saw last week - found again.
4. The price drop you would have missed - flagged.
5. The brand you never even heard of that fits you perfectly.
Small things, every week, that add up to hundreds of hours.
🎥 ARC-AGI-3 winning team - Millennia of minds, compressed into words.
https://t.co/6fQNL96ukt
ARC-AGI-3 is a benchmark built to punish “agent theatre”. Not whether your system can solve a puzzle, but whether it can work out what the puzzle even is
🎥 Understanding the inner thoughts of AI
https://t.co/nNL5wjaC9b
Interpretability is quietly turning into the audit function for frontier AI.
Not a philosophy club. Not pretty diagrams.
It’s the difference between “we ran evals” and “we can
This is genuinely worth a read.
Very important things that are shaping narratives. There could be a world where safety becomes a real issue. People will go where safety is or marketed best, and that could be the risk.
Very interesting read and watch.
🎥 AI Optimism vs AI Pessimism
https://t.co/t561yltu5f
AI governance is growing up. That’s good news. But the next fight is uglier: who gets to wrap themselves in “safety”, then quietly ship enforcement, monitoring, and compliance that never shrinks
A reminder: we exist because shopping online stopped being fun somewhere around tab number eleven.
Endless options, paid placements, reviews you cannot trust, and all the work of choosing dumped on your evenings.
Someone had to be on your side of the counter, so we built it.
🎥 Why Toilets and MSG Are Winning the AI Boom | Bloomberg Tech: Asia 6/26/2026
https://t.co/8QuxWBRV81
the AI boom isn’t being “won” by the flashiest models. it’s being won by whoever can turn boring, physical, regulated reality into
Meet Hermes Shield.
AI agents can now read, decide, and act — send, browse, run code, move money.
The catch: once an agent can act, one poisoned input can turn its own power against you.
We map that blast radius. Free. Local. Read-only.
We scanned the 12 most-installed agent frameworks:
→ 520 dangerous actions inherited on install
→ 474 reachable by a single line of untrusted text
Private beta open 👇
🔔 @ethereumJoseph is now following @harleyfoote_ (5.4K followers, account created 8 years ago)
Description: Hermes 🟧🟧🟧➡️🛡️➡️🟧🟧🟧 Shield - The Action Firewall For AI Agents. Chief Exec @ Friday Research
Knowing your blast radius eliminates a lot of the risk of your data being stolen and put on the web. Attacks can control your PC.
That’s why we build Hermes Shield, to make it easy to develop agentic workflow commercially.
Think VPN/Anti virus but for prompt injection. That’s us…
@harleyfoote_@Hyperdegen7 Interesting work. Which frameworks had the highest number of reachable dangerous actions, and how are you detecting them automatically?
The cleanest proof of this is EchoLeak — CVE-2025-32711, CVSS 9.3. One crafted email, zero clicks, and M365 Copilot read your private docs and shipped them out through an invisible image URL it rendered itself. Simon's right that it's structural, not a bug you patch: hold any two legs and you're safe, but no real team gives up private data, inbound content, or outbound calls. Which leaves exactly one leg you can actually cut — gate the action before the model acts, don't trust the model to police its own exfil.
🎥 How Apple Will Use Broadcom Chips
https://t.co/cdVuh8htNp
Apple’s $30bn+ Broadcom chip deal isn’t a “Made in America” victory lap. It’s a jurisdiction play. In 2026, the most important hardware decisions aren’t in the keynote. They’re in the
Strip it back to cost and latency and x402 looks different. The plumbing is the whole story here. Whoever owns the settlement layer owns the economics, not whoever owns the chat box.
https://t.co/FTnKbe4aMb