Today we are releasing Cloudflare OS, a chatbot with connectors, just like every other tech company is doing.
Except actually, it's different. This is a remake of Sandstorm[.]io, my startup from 10 years ago, except this time built on Cloudflare Workers (the platform I've spent the last 9 years building) and deeply leveraging AI. This is more or less the culmination of my secret 10-year master plan.
This is a full-on personal app vibe coding platform, in which the sandbox is so secure that you can pretty much go wild -- the AI cannot introduce a significant security bug. We believe a company's security team can feel comfortable giving non-technical users permission to vibe code and then sleep soundly at night.
How is that possible? It's the Sandstorm security model, revisited. A "Gadget" is the same thing as a Sandstorm "Grain": a fine-grained app instance. For example, if you have a document editor app, each document runs as a separate instance of the app, in a separate sandbox (one "Gadget").
This means two things, both of which I think are Big Deals:
1. The platform can manage all access control, by controlling who can access the Gadget at all. There is no way the Gadget can accidentally leak itself to an attacker -- even an attacker who has access to other Gadgets based on the same app.
2. Since everyone is running their own copy of the code, everyone can freely *modify* their copy of the code.
Think about #2 a bit more.
What if, when you wanted a new feature in the software you are using, you could just prompt your agent to add it?
This doesn't work in the cloud Software-as-a-Service model, because you are not running your own copy of the app.
Sandstorm tried to change that 10 years ago, but the world wasn't ready, because not enough people had the skills or patience to actually modify their software. AI has changed that. Now you just ask the agent -- the same agent that you are using to help you interact with the Gadget can also modify the code of the Gadget.
And it is so fun.
https://t.co/qzwdrAQhtK
AI agents are everywhere at @Uber. It’s great to see, but the thing that keeps me up at night is how we are going to secure them. This is something that I have been thinking about for a while.
Today, our agents run 50,000+ sessions per day across thousands of endpoints. And this isn't just engineering anymore. Employees across the company use agents that read code, run commands, call internal tools, analyze data, and act on real systems.
That scale forced us to confront an important question: How do you secure agents when your security tools can't even see them?
Traditional Endpoint Detection & Response (EDR) sees the file write, but not the prompt that triggered it. It sees the network call, but not the agent's reasoning. The intent, the thing that separates malicious from benign, is invisible.
So we built Agentic Detection and Response (ADR):
• Capture the full causal chain: prompt → reasoning → tool call → outcome, across Cursor, Claude Code, Codex, and every agent our employees use.
• Triage cheaply: a fast, high-recall first pass handles the flood of benign sessions.
• Reason deeply: only suspicious events get expensive LLM analysis, enriched with source code, threat intel, and policy context.
• Red-team continuously: an offline explorer evolves hard attack variants before attackers find them.
After 10+ months in production, the results speak for themselves:
• Hundreds of credential exposures detected across 26 categories.
• Shift-left prevention blocking secrets at 97.2% precision, before they ever leave the laptop.
• Zero false positives on our enterprise benchmark, with 2-4x the F1 score of state-of-the-art baselines.
• Every attack detected on AgentDojo, the public prompt injection benchmark.
Just as valuable as the detections are the lessons from running this in production:
• The workflow is the unit of security, not the individual tool call. Attacks hide in causally-linked chains that look benign step by step.
• Credential leakage is a far more common operational issue than prompt injection.
• Approval fatigue is real: when users approve 50+ actions per session, human oversight becomes a rubber stamp.
You can't secure agents you can't observe. And nobody can solve this alone. That is why we recently joined the Open Secure AI Alliance (OSA), and why today we're taking the next step: open-sourcing ADR.
The release includes the ADR Sensor, the detection framework, and ADR-Bench, the first enterprise agentic AI security benchmark: 302 tasks derived from real production telemetry and full coverage of all 17 attack techniques across 5 tactics, so the community can rigorously evaluate their own defenses.
Code: https://t.co/tmI0oQ1F2U
Paper: https://t.co/0xbswUbiF5
The future of AI security won't be built behind closed doors. Excited to see what the community builds on it, and what we all learn together! @UberEng
14:00 から Room D で Built Our Own Background Agent at LayerX というどこかで見たことある感じのタイトルで @itkq と登壇します
いま取り組んでいる AI 時代の社内向け Platform の思想・設計・実装をチラ見せ #aidevex_findy
We recently posted about Pinecone, Sierra’s internal agent every employee uses for everything from writing code to GTM. Mihai wrote up how the Pinecone team designed the MCP service behind it, including nuanced issues like access control and context overload. Check it out:
Introducing Claude Managed Agents: everything you need to build and deploy agents at scale.
It pairs an agent harness tuned for performance with production infrastructure, so you can go from prototype to launch in days.
Now in public beta on the Claude Platform.
You can now enable Claude to use your computer to complete tasks.
It opens your apps, navigates your browser, fills in spreadsheets—anything you'd do sitting at your desk.
Research preview in Claude Cowork and Claude Code, macOS only.
Cardiologist wins 3rd place at Anthropic's hackathon. Out of 13,000 applications. Built in 7 days by Michał Nedoszytko MD. Coded day and night - in the hospital, in the cloud, while flying from Brussels to San Francisco.
A few years ago, it would have been impossible for a doctor to build this alone in just a couple of days. AI changed that.
The project is called https://t.co/wAliajqjVF. It is an AI agentic care platform for patients. Including reverse AI scribe it is a companion that guides the patient from the moment they leave the doctor's office.
Powered by the massive context window of Opus 4.6, it allows patients to explore their full medical history, connected devices, Evidence Based resources and external data sources — all in one place.
Today, the barrier to entry has vanished; even a practicing physician can build an application from scratch.