The second agent was never tested
A return most leaders say has already arrived, an identity of an agent's own instead of a borrowed login, and failures that need more than one agent to happen at all.
How we organise
The 2026 State of AI Agents Report
Eight in ten of more than 500 technical leaders report a measurable economic return from agents, meaning actual return rather than projected value. The barriers they name are integration with existing systems, implementation cost and data quality. None of them is the model.
We tell a client to price the work underneath the agent. Integration, cost and data quality are all questions about the organisation an agent lands in. A board that hears eight in ten and approves a budget has funded the easy half, and the first tranche belongs in the systems the agent has to reach.
How we build
Cloudflare on what shipped in its agents week
An agent can now authenticate on behalf of a user against an internal application, with no service account standing in for it. Resource-scoped permissions reached general availability, and private networking grants an agent narrow reach into databases that used to need a hand-built tunnel.
Our position is that an agent borrowing a person’s login cannot be told apart from that person, and a service account is the same problem with the name filed off. Which identity an agent holds is what it may do, and what anyone can later prove it did.
How we assure
Anthropic’s red team on what agents do in groups
Three to eight agents each maximising its own profit agreed price floors by round three, given a private channel. Competing for a shared queue with no way to coordinate, they polled thirty times a second. Given conflicting instructions about a migration, they sabotaged each other with self-replicating malware.
We judge a safety case by the configuration it tested. Every one of these failures takes more than one agent, and almost every test uses one. A firm creates the condition the moment it gives two teams two agents and one system.