TLDR IT 2026-09-21
Anthropic taps Accenture 🛑, Codex sandbox escape 💻, Cloudflare saves 100TB ☁️
Anthropic tabs Accenture as embedded evaluator to help with AI slowdown proposal (3 minute read)
Anthropic has chosen Accenture and its AI business Faculty as its first embedded evaluator to help implement a proposed slowdown in AI development. The partnership aims to evaluate models, conduct alignment assessments, and test safeguards. Anthropic and Accenture each expect to invest at least $1 billion in the project over the next five years.
Researchers escape OpenAI Codex sandbox to run commands on host (5 minute read)
Researchers disclosed two flaws that allowed OpenAI Codex to escape its sandbox, including one that could execute commands on a developer's machine from the strictest read-only mode without an approval prompt. OpenAI fixed both issues, but the incident is another reminder that coding agents should be treated like privileged software: keep clients updated, limit local permissions, and be cautious about opening untrusted repositories with agentic tools.
Why AI Cannot Save an Enterprise That Doesn't Understand Its Data (6 minute read)
AI can only be as effective as the enterprise's understanding of its own data, relationships, and decision-making rules. Without a clear ontology and traceable path from data to action, AI can automate the wrong interpretation at scale. This makes governance, context, and organizational learning more important, not less.
What model access failure costs the business (7 minute read)
AI agents complicate traditional IAM because one employee action may now pass through a model, agent, plugin, service account, API, and downstream application before anything actually happens. Companies need to govern agents as identities themselves, including defined permissions, attributable actions, access reviews, and audit trails that can reconstruct the full chain from the human request to the resulting business action.
Supabase Auth With an Unsupported SMS Provider (19 minute read)
Supabase Auth can support unsupported SMS providers through the Send SMS hook, while GoTrue handles code generation, hashing, expiry, and session issuance. This approach keeps authentication logic within GoTrue and delegates only SMS delivery to a custom endpoint, avoiding the security risks of building a separate auth subsystem.
Automate workflows with custom starters and steps, third-party integrations, and webhooks in Workspace Studio (4 minute read)
Google is expanding Workspace Studio with custom triggers, Apps Script-powered steps, webhooks, and integrations with tools including Slack, Jira, Salesforce, HubSpot, Asana, and QuickBooks. The end-user rollout begins September 21, and the important detail for IT is that these capabilities are off by default with admin controls for integrations, webhooks, approvals, and URL allowlists - exactly the governance layer increasingly needed for employee-built automations.
Curated news 🗞️ and trends 📈 in IT strategy 💻, information security 🔐, and cloud computing ☁️.
Join 570,000 readers for
one daily email