← AI Feed
AI Feed

The signature was valid and the package was not

A Federal Reserve survey where firms count as AI adopters at a median of 17 per cent of staff, two engineers on why an agent cannot smell bad data, and stolen build tokens producing signed packages that pass every automated trust check.

How we Organise

Sixty-one per cent of firms use AI and a median of 17 per cent of their people do

The New York Fed has asked firms in its region the same questions every August since 2024. This year 61 per cent of service firms said they use AI. Last year it was 40. Among those adopters the median share of staff using it is 17 per cent. Four per cent had laid anybody off. Just over a third retrained people, and the retraining aimed at the jobs they already hold rather than at new ones.

Our practice puts it as a test:

Capability is demonstrated on live work or it is not demonstrated.

These firms are spending on the second half of that sentence. The adoption headline says almost nothing. The 17 per cent says where the work is. Read the survey’s own caveat with it. Firms are describing themselves, and a low median fits a careful pilot as easily as a stalled rollout.

How we Build

A pricing agent quoted the old price and every step it took was correct

Pramod Sadalage and Prem Chandrasekaran at Thoughtworks set out what data has to become before an agent is handed it. Their case turns on one difference. A person pauses at a number that looks wrong. An agent acts on it. Their worked failure is a price that moved from $49.99 to $59.99. The source had not refreshed, and the agent quoted the old figure to a customer who bought at it.

We hold this one plainly:

Data quality is tested, not reported.

A report is read by somebody. Nobody is there at the moment the agent uses the number. This is a practitioner argument rather than a measurement. There is no population and no instrument, and two consultants are describing client work at one firm.

How we Assure

Stolen build tokens produce signed packages that pass every automated check

Google’s threat intelligence group reports attackers publishing trojanised forks of legitimate tool servers to PyPI. Their credential stealer takes tokens out of a build machine’s memory, then authorises itself as the publisher those tokens belong to. It ships compromised packages carrying valid signed attestations. Those packages pass the trust checks coding agents run. The tool description never changes.

The statement it argues with reads:

Every tool an agent may call is declared, both the tool’s description and what it returns are treated as untrusted, and a tool whose description has changed since it was reviewed is a tool that has not been reviewed.

The fork keeps the name, the interface and the publisher. What moved is the code underneath. A team keying its re-review to a changed description finds nothing to look at. This is the second source in a week to say so, after a paper showing the same substitution in remote tools. Google sells defence against the threat it writes about. It gives no rate for any of this. Tell us what you re-review when nothing visible has changed: transform@dromologue.ai.