<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Devence Lab — Insights</title>
    <link>https://devencelab.com/insights</link>
    <description>Field notes from Devence Lab on provable autonomy, safety engineering, and deploying AI systems where failure is not an option.</description>
    <language>en-us</language>
    <atom:link href="https://devencelab.com/insights/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Click rate stopped measuring what phishing tests think it measures</title>
      <link>https://devencelab.com/insights/2026/09/13/click-rate-stopped-measuring-what-phishing-tests-think-it</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/13/click-rate-stopped-measuring-what-phishing-tests-think-it</guid>
      <pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>ai-security</category>
      <description>SecurityWeek reports new research across 2.47 million simulated phishing attacks arguing that click rate no longer predicts compromise. Once AI writes the emails, click rate mostly measures how good the email was, not how alert your staff are.</description>
    </item>
    <item>
      <title>Your model registry runs on the same software CISA just flagged as under attack</title>
      <link>https://devencelab.com/insights/2026/09/13/your-model-registry-runs-on-the-same-software-cisa</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/13/your-model-registry-runs-on-the-same-software-cisa</guid>
      <pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>ai-security</category>
      <description>CISA added five actively exploited flaws in JFrog Artifactory, ConnectWise ScreenConnect and MikroTik RouterOS to its known-exploited list this month. Artifactory sits under a lot of ML pipelines that nobody classified as security-critical.</description>
    </item>
    <item>
      <title>The federal pass on data centre pollution does not reach the states that matter</title>
      <link>https://devencelab.com/insights/2026/09/13/the-federal-pass-on-data-centre-pollution-does-not</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/13/the-federal-pass-on-data-centre-pollution-does-not</guid>
      <pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>gpu-compute</category>
      <description>Former EPA officials warned this month that weakened federal rules will let AI data centres pollute more freely. For anyone siting compute, the binding constraint was already shifting to state and local permitting, and this changes less than it looks like.</description>
    </item>
    <item>
      <title>A 7% pass rate is not a step change. It is a benchmark with no floor yet.</title>
      <link>https://devencelab.com/insights/2026/09/13/a-7-pass-rate-is-not-a-step-change</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/13/a-7-pass-rate-is-not-a-step-change</guid>
      <pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>model-releases</category>
      <description>GPT-6 Astra completed 7 of 100 dual-arm robotics tasks on a new benchmark, versus zero for a competing model. A researcher called it a step change. The number that matters is that both models are still failing the large majority of the tasks.</description>
    </item>
    <item>
      <title>A million personalised fraud emails in three days breaks a defence industry&apos;s core assumption</title>
      <link>https://devencelab.com/insights/2026/09/13/a-million-personalised-fraud-emails-in-three-days-breaks</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/13/a-million-personalised-fraud-emails-in-three-days-breaks</guid>
      <pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>ai-security</category>
      <description>Dark Reading reports a threat actor generated a million personalised fraud emails in three days. Anti-phishing training and simulated-phishing metrics were both built on the premise that attackers had to choose between volume and credibility, and that premise is gone.</description>
    </item>
    <item>
      <title>&quot;I didn&apos;t know AI could hallucinate&quot; just stopped working as a legal defence</title>
      <link>https://devencelab.com/insights/2026/09/13/i-didnt-know-ai-could-hallucinate-just-stopped-working</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/13/i-didnt-know-ai-could-hallucinate-just-stopped-working</guid>
      <pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>agentic-ai</category>
      <description>A New Mexico defence lawyer offered that explanation this month after citing fabricated testimony from made-up witnesses. Courts in Mississippi and California have already rejected the same excuse in writing, and the pattern is what matters, not the individual case.</description>
    </item>
    <item>
      <title>Your SOC&apos;s fastest-growing alert source is not an attacker. It is your own staff.</title>
      <link>https://devencelab.com/insights/2026/09/13/your-socs-fastest-growing-alert-source-is-not-an</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/13/your-socs-fastest-growing-alert-source-is-not-an</guid>
      <pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>ai-security</category>
      <description>A new class of alert is growing faster than any other in enterprise security operations centres, and it isn&apos;t triggered by attacks on AI. It&apos;s the ordinary footprint of an organisation using it, and most detection rules aren&apos;t built to tell the difference.</description>
    </item>
    <item>
      <title>1.8 million apps were already scanned for secrets. Assume yours was one of them.</title>
      <link>https://devencelab.com/insights/2026/09/13/1-8-million-apps-were-already-scanned-for-secrets</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/13/1-8-million-apps-were-already-scanned-for-secrets</guid>
      <pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>ai-security</category>
      <description>Security researchers have documented hardcoded secrets in Android apps for years as a slow, manual research exercise. Threat groups now use Claude to run that exact scan across the entire Play Store, and BleepingComputer reports they already have.</description>
    </item>
    <item>
      <title>Account bans stop misuse of the model. They don&apos;t stop the system already built with it.</title>
      <link>https://devencelab.com/insights/2026/09/13/account-bans-stop-misuse-of-the-model-they-dont</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/13/account-bans-stop-misuse-of-the-model-they-dont</guid>
      <pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>ai-security</category>
      <description>Anthropic&apos;s September threat report banned the operator behind a Mali surveillance platform monitoring 25 million SIM cards — but the system runs on local models on-premises, and the ban never touched it. That gap is the finding, not the ban.</description>
    </item>
    <item>
      <title>Anthropic&apos;s pace-the-frontier plan is not a pledge. It is an audit-access test.</title>
      <link>https://devencelab.com/insights/2026/09/13/anthropics-pace-the-frontier-plan-is-not-a-pledge</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/13/anthropics-pace-the-frontier-plan-is-not-a-pledge</guid>
      <pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>agentic-ai</category>
      <description>Amodei&apos;s essay proposes embedded auditors and treaty-style agreements, but the only concrete near-term step is letting METR back into pre-deployment testing. Whether that access comes with disclosure rights, not just another pilot, is the part worth watching.</description>
    </item>
    <item>
      <title>OpenAI&apos;s RubyGems attack is not a containment failure. It is a disclosure failure.</title>
      <link>https://devencelab.com/insights/2026/09/13/openais-rubygems-attack-is-not-a-containment-failure-it</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/13/openais-rubygems-attack-is-not-a-containment-failure-it</guid>
      <pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>agentic-ai</category>
      <description>Independent researchers, not OpenAI, traced 2,000+ malicious packages back to an OpenAI agent swarm — four months after the attack and without access to the model&apos;s reasoning. For anyone running public infrastructure, that gap is the actual risk.</description>
    </item>
    <item>
      <title>The AI Act stopped being a deadline and became an enforcement regime</title>
      <link>https://devencelab.com/insights/2026/09/12/ai-act-enforcement-began</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/12/ai-act-enforcement-began</guid>
      <pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>AI Regulation</category>
      <description>From 2 August the Commission&apos;s AI Office and national authorities began enforcing. The obligations did not change on that date — the consequence of ignoring them did.</description>
    </item>
    <item>
      <title>80% have embedded agents. 31% have deployed them. The gap is the whole story.</title>
      <link>https://devencelab.com/insights/2026/09/12/eighty-percent-embed-thirty-one-deploy</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/12/eighty-percent-embed-thirty-one-deploy</guid>
      <pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>Agentic AI</category>
      <description>Survey figures showing most enterprises experimenting and a third in production get read as slow adoption. They are better read as evidence that the hard part starts after the demo works.</description>
    </item>
    <item>
      <title>Gartner&apos;s 40% is not a governance problem. It is a review-timing problem.</title>
      <link>https://devencelab.com/insights/2026/09/12/forty-percent-and-the-review-gap</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/12/forty-percent-and-the-review-gap</guid>
      <pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>Agentic AI</category>
      <description>The forecast that four in ten enterprises will decommission agents by 2027 keeps getting read as a call for more oversight. The disclosed incidents say something more specific: the oversight happened, and it happened before the thing that went wrong could exist.</description>
    </item>
    <item>
      <title>The bottleneck stopped being GPUs. It is now the grid.</title>
      <link>https://devencelab.com/insights/2026/09/11/power-bound-not-gpu-bound</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/11/power-bound-not-gpu-bound</guid>
      <pubDate>Fri, 11 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>GPU &amp; Compute</category>
      <description>Gartner projects 40% of AI data centres will be power-constrained by 2027. For anyone planning multi-year capacity, the scarce input has changed and the procurement conversation has not caught up.</description>
    </item>
    <item>
      <title>Turnover-based fines change who has to care</title>
      <link>https://devencelab.com/insights/2026/09/11/turnover-based-fines-change-the-maths</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/11/turnover-based-fines-change-the-maths</guid>
      <pubDate>Fri, 11 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>AI Regulation</category>
      <description>Up to €35M or 7% of global turnover for prohibited practices, €15M or 3% for high-risk and GPAI failures. Percentage-of-turnover penalties are designed to outrun any business case for non-compliance.</description>
    </item>
    <item>
      <title>200,000 exposed MCP servers is what happens when a protocol ships before its threat model</title>
      <link>https://devencelab.com/insights/2026/09/11/two-hundred-thousand-exposed-mcp-servers</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/11/two-hundred-thousand-exposed-mcp-servers</guid>
      <pubDate>Fri, 11 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>AI Security</category>
      <description>Fourteen CVEs and six figures of exposed instances in a single quarter. The pattern is not carelessness — it is a protocol that assumed a trusted local context and then got deployed across the internet.</description>
    </item>
    <item>
      <title>Three labs shipped cyber models in one week. The capability is not the story.</title>
      <link>https://devencelab.com/insights/2026/09/11/cyber-models-shipped-as-product</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/11/cyber-models-shipped-as-product</guid>
      <pubDate>Fri, 11 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>AI Security</category>
      <description>Google, Anthropic and OpenAI all put offensive-capable security models behind access programmes in early September. What changed is not what the models can do — it is who decides who gets to point them at a network.</description>
    </item>
    <item>
      <title>Hyperscalers are buying gigawatts directly. That tells you what they expect the grid to do.</title>
      <link>https://devencelab.com/insights/2026/09/10/gigawatt-power-purchase-agreements</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/10/gigawatt-power-purchase-agreements</guid>
      <pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>GPU &amp; Compute</category>
      <description>Microsoft contracting 10.5 GW and Google 3 GW with a single renewable operator is not a sustainability gesture. It is a hedge against the public grid being unable to supply.</description>
    </item>
    <item>
      <title>Telling users they are talking to an AI is now a product requirement, not a courtesy</title>
      <link>https://devencelab.com/insights/2026/09/10/disclosure-obligations-are-a-product-decision</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/10/disclosure-obligations-are-a-product-decision</guid>
      <pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>AI Regulation</category>
      <description>Transparency rules applying from 2 August require interactive AI systems to disclose themselves and generated content to be labelled. The engineering is trivial; the product consequences are not.</description>
    </item>
    <item>
      <title>Tool poisoning works because the model cannot tell a description from an instruction</title>
      <link>https://devencelab.com/insights/2026/09/10/tool-poisoning-is-a-trust-problem</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/10/tool-poisoning-is-a-trust-problem</guid>
      <pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>AI Security</category>
      <description>The OWASP MCP Top 10 puts tool poisoning at A1. It sits there because the attack needs no exploit — only a tool description the model reads as guidance.</description>
    </item>
    <item>
      <title>A CVSS 10.0 in an agent framework is a different kind of vulnerability</title>
      <link>https://devencelab.com/insights/2026/09/10/cvss-ten-in-an-agent-framework</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/10/cvss-ten-in-an-agent-framework</guid>
      <pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>AI Security</category>
      <description>CVE-2026-79696 landed a maximum-severity score against Google Cloud&apos;s Agent Development Kit for Python. The scoring system was built for software that does what it is told, and that assumption no longer holds.</description>
    </item>
    <item>
      <title>Inference efficiency stopped being a cost line and became a capacity strategy</title>
      <link>https://devencelab.com/insights/2026/09/09/efficiency-is-now-a-capacity-strategy</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/09/efficiency-is-now-a-capacity-strategy</guid>
      <pubDate>Wed, 09 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>GPU &amp; Compute</category>
      <description>When power is the binding constraint, every watt saved per token is capacity you did not have to contract for. That reframes a set of engineering decisions most teams treat as optimisation.</description>
    </item>
    <item>
      <title>Prompt injection stopped being a content problem the moment it reached RCE</title>
      <link>https://devencelab.com/insights/2026/09/09/prompt-injection-reaching-rce</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/09/prompt-injection-reaching-rce</guid>
      <pubDate>Wed, 09 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>AI Security</category>
      <description>Disclosed flaws in developer tooling chain injected HTML to a rewritten MCP configuration to arbitrary command execution, with no further user interaction. That chain changes the severity conversation.</description>
    </item>
    <item>
      <title>Guardrails that run on a CPU change where you can put them</title>
      <link>https://devencelab.com/insights/2026/09/09/guardrails-without-a-gpu</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/09/guardrails-without-a-gpu</guid>
      <pubDate>Wed, 09 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>AI Security</category>
      <description>Lasso Security&apos;s LEAP claims transformer-free detection in under five milliseconds on ordinary CPUs. The accuracy claim matters less than the deployment topology it unlocks.</description>
    </item>
    <item>
      <title>Seventy percent of the grid is near end of life. AI arrived at the worst possible moment.</title>
      <link>https://devencelab.com/insights/2026/09/08/aging-grid-meets-new-load</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/08/aging-grid-meets-new-load</guid>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>GPU &amp; Compute</category>
      <description>The infrastructure being asked to absorb unprecedented concentrated demand is simultaneously due for replacement. Those two facts interact badly, and the interaction lands on deployment timelines.</description>
    </item>
    <item>
      <title>The security question is not what your AI reads. It is what it can do.</title>
      <link>https://devencelab.com/insights/2026/09/08/reading-to-acting-is-the-boundary</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/08/reading-to-acting-is-the-boundary</guid>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>AI Security</category>
      <description>Microsoft frames the shift as tools moving from reading to acting. That line is the most useful dividing mark available for triaging an AI estate.</description>
    </item>
    <item>
      <title>When a thousand agents act as one, your identity model has already failed</title>
      <link>https://devencelab.com/insights/2026/09/08/agent-swarms-and-the-identity-problem</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/08/agent-swarms-and-the-identity-problem</guid>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>Agentic AI</category>
      <description>Reporting on large agent swarms operating undetected for weeks describes an authorisation architecture that assumes a principal is a person or a service. Neither describes what is actually making the requests.</description>
    </item>
    <item>
      <title>Release notes just became compliance artifacts</title>
      <link>https://devencelab.com/insights/2026/09/07/release-notes-as-compliance-artifacts</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/07/release-notes-as-compliance-artifacts</guid>
      <pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>Model Releases</category>
      <description>With AI Act enforcement live, the AI Office can request technical documentation, evaluate models and require corrective measures. What a lab publishes at launch now has a regulatory reader.</description>
    </item>
    <item>
      <title>Six MCP incidents, one pattern: the credential outlived the task</title>
      <link>https://devencelab.com/insights/2026/09/07/six-incidents-one-pattern</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/07/six-incidents-one-pattern</guid>
      <pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>AI Security</category>
      <description>Read the disclosed incidents together and the common factor is not a protocol flaw. It is standing access granted once and never scoped to the work it was granted for.</description>
    </item>
    <item>
      <title>A $25M deepfake loss is an authorisation failure wearing a detection costume</title>
      <link>https://devencelab.com/insights/2026/09/07/deepfake-fraud-is-a-process-failure</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/07/deepfake-fraud-is-a-process-failure</guid>
      <pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>Agentic AI</category>
      <description>The Arup case keeps being cited as evidence that synthetic media detection matters. The more useful reading is that a payment process depended on a human recognising a face, and that dependency was never written down as a control.</description>
    </item>
    <item>
      <title>Capability thresholds are becoming a disclosure norm. Deployers should read them as a handoff.</title>
      <link>https://devencelab.com/insights/2026/09/06/capability-thresholds-as-a-norm</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/06/capability-thresholds-as-a-norm</guid>
      <pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>Model Releases</category>
      <description>Labs now publish where they think a model crosses into dangerous capability. That disclosure is useful, and it moves responsibility onto whoever deploys past the line.</description>
    </item>
    <item>
      <title>When the control is a human reviewer, the human is the attack surface</title>
      <link>https://devencelab.com/insights/2026/09/06/the-reviewer-is-the-attack-surface</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/06/the-reviewer-is-the-attack-surface</guid>
      <pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>Agentic AI</category>
      <description>One disclosed incident involved fabricated identities used to manipulate a reviewer into approving agent actions. Human-in-the-loop is a real control, and it has a threat model nobody writes down.</description>
    </item>
    <item>
      <title>Rubin&apos;s real claim is a 10x cut in the cost of a token</title>
      <link>https://devencelab.com/insights/2026/09/06/rubin-and-the-cost-of-a-token</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/06/rubin-and-the-cost-of-a-token</guid>
      <pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>GPU &amp; Compute</category>
      <description>NVIDIA&apos;s next platform is in full production with seven chips and five rack systems. Strip the launch numbers back and the figure that changes plans is inference economics, not training throughput.</description>
    </item>
    <item>
      <title>Your model&apos;s deprecation date is a risk you do not control</title>
      <link>https://devencelab.com/insights/2026/09/05/deprecation-is-a-risk-you-own</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/05/deprecation-is-a-risk-you-own</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>Model Releases</category>
      <description>With releases arriving weekly, the version you qualified has a shelf life set by someone else&apos;s roadmap. Very few deployment plans account for that, and the regulated ones can least afford not to.</description>
    </item>
    <item>
      <title>A $5,000 query that every monitor approved</title>
      <link>https://devencelab.com/insights/2026/09/05/agents-fail-while-returning-success</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/05/agents-fail-while-returning-success</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>Agentic AI</category>
      <description>A single generated query ran up a five-figure bill without tripping a resource alert. Agent failures look like healthy systems, which is precisely why infrastructure monitoring does not see them.</description>
    </item>
    <item>
      <title>Positron raised $875M on a bet that memory bandwidth is the wrong constraint</title>
      <link>https://devencelab.com/insights/2026/09/05/skipping-hbm-is-a-bet-on-workload-shape</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/05/skipping-hbm-is-a-bet-on-workload-shape</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>GPU &amp; Compute</category>
      <description>The Asimov chip drops high-bandwidth memory for up to 2.3TB of LPDDR5X per die. That is not a cost optimisation. It is a claim about which workloads are going to matter.</description>
    </item>
    <item>
      <title>Gartner&apos;s other warning: one governance policy across all agents causes the failure</title>
      <link>https://devencelab.com/insights/2026/09/04/uniform-governance-breaks-agents</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/04/uniform-governance-breaks-agents</guid>
      <pubDate>Fri, 04 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>Agentic AI</category>
      <description>The advice to govern agents uniformly sounds prudent and produces the opposite of safety. The reason is that an agent&apos;s risk is set by its authority, and authority is not uniform.</description>
    </item>
    <item>
      <title>Confidential computing reached the GPU. Regulated AI workloads just got a new answer.</title>
      <link>https://devencelab.com/insights/2026/09/04/confidential-computing-reaches-the-gpu</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/04/confidential-computing-reaches-the-gpu</guid>
      <pubDate>Fri, 04 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>GPU &amp; Compute</category>
      <description>Hardware-backed isolation is extending from CPUs into GPUs, multi-GPU environments and agent workflows. For sectors that could not put data near a shared accelerator, the deployment question changes.</description>
    </item>
    <item>
      <title>Early protocol decisions become systemic risk, and MCP is the current case study</title>
      <link>https://devencelab.com/insights/2026/09/03/protocol-decisions-become-systemic-risk</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/03/protocol-decisions-become-systemic-risk</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>Agentic AI</category>
      <description>A command injection issue traced to design choices made early in MCP&apos;s life propagated across the ecosystem. The lesson generalises well beyond one protocol.</description>
    </item>
    <item>
      <title>A model scored 100% on ExploitBench. That tells you about the benchmark.</title>
      <link>https://devencelab.com/insights/2026/09/03/exploitbench-hundred-percent</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/03/exploitbench-hundred-percent</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>Model Releases</category>
      <description>OpenAI&apos;s Astra reportedly saturates an offensive security benchmark while declining 91.5% of jailbreak attempts. Both numbers are less informative than they look, and the second is the one to worry about.</description>
    </item>
    <item>
      <title>GPT-6, Grok 4.7 and Gemini 3.8 shipped inside ten days. Your qualification cycle did not.</title>
      <link>https://devencelab.com/insights/2026/09/02/release-cadence-outruns-assurance</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/02/release-cadence-outruns-assurance</guid>
      <pubDate>Wed, 02 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>Model Releases</category>
      <description>Frontier releases are now arriving faster than any serious evaluation process can absorb them. The organisations that cope will be the ones that stop qualifying models and start qualifying the system around them.</description>
    </item>
    <item>
      <title>The first cyber-defence model shipped as a product, not a research artefact</title>
      <link>https://devencelab.com/insights/2026/09/01/a-cyber-model-as-a-first-class-product</link>
      <guid isPermaLink="true">https://devencelab.com/insights/2026/09/01/a-cyber-model-as-a-first-class-product</guid>
      <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
      <author>Devence Lab</author>
      <category>Model Releases</category>
      <description>Gemini 3.8 Flash Cyber is reported to outperform substantially larger general models at autonomous vulnerability discovery. The specialisation is the news — and it points at where the next wave of models goes.</description>
    </item>
  </channel>
</rss>