A quiet Sunday mostly delivered policy theatre with a real control-plane subtext. Washington put a named task force on top of a voluntary, consequence-free safety accord. MCP’s own reference fetch server is carrying a published SSRF with no merged fix. And Google researchers show that self-improving agent harnesses mostly learn their tests unless you regularize them.
Today
- The White House forms a “Super Intelligence Force” under DNI Jay Clayton, on top of the 29 September accord, which has no enforcement (4 Oct)
- Google’s RRSI paper finds that self-improving agent harnesses overfit their evals, and shows how to stop it (arXiv)
- MCP reference fetch server: CVE-2026-104120 SSRF published, and the fix PR is still an unmerged draft (2 Oct onward)
- Apple will require “very explicit user action” for macOS Full Disk Access, citing AI agents (2 Oct)
- EU/DK check: no new Digst, Datatilsynet or Commission AI Act / Official Journal item in the window
- Also: 8 other items, 1 paper
AI
A “Super Intelligence Force” sits on top of an accord with no teeth
On Sunday, President Trump announced on Truth Social a “Super Intelligence Force” led by Director of National Intelligence Jay Clayton, with FTC chair Andrew Ferguson, Pentagon CTO Emil Michael and OPM director Scott Kupor, reporting to Trump and chief of staff Susie Wiles (CBS News, BBC). According to the Wall Street Journal, as relayed by Reuters, the panel has 120 days to report on AI risks and opportunities, review federal reporting mechanisms for breaches, hacks and other incidents, and recommend what role the government should play under existing authorities (TimesLive/Reuters).
It follows the one-page accord of 29 September signed by Nvidia, SpaceX, OpenAI, Anthropic, Meta and Google. The companies committed to “four layers of controls and audits”, including internal evaluations, an external audit firm and board review. Reuters notes that the document sets no consequences for noncompliance and gives no enforcement detail, and Rep. Ro Khanna argues that auditors should report to an independent federal agency rather than to the CEOs (Straits Times/Reuters). The same week, an executive order told agencies to say “Super Intelligence” instead of AI in official communication.
Why it matters: The US track stays voluntary, with findings reported to company boards, so the AI Act’s GPAI obligations (enforceable since 2 August) remain your binding baseline. “Signed the accord” is not assurance evidence: ask US model vendors for the external-audit artefacts it promises, and watch the 120-day incident-reporting review against EU serious-incident duties.
Self-improving harnesses mostly memorize their tests, and RRSI shows how to stop that
A Google Cloud AI Research paper, RRSI (Regularized Recursive Self-Improvement of Agent Harnesses), tackles a quiet failure in automatic harness tuning. When an LLM keeps rewriting an agent’s prompts, control flow, tools and memory against a fixed evaluation set, it learns the set. RRSI caps how many edits a round may bundle (annealed toward one) and keeps a history of failed hypotheses. Before scoring, a critic rejects edits that encode task names or answers. Acceptance requires clearing a measured noise band and a cost-per-gain rule, and unproductive components get pruned.
With Claude Opus 4.8 frozen as the policy, the authors report gains of up to 14.1 points on the evolve split and up to 4.7 on five out-of-distribution benchmarks, using 30% fewer policy tokens than unregularized evolution. Among the baselines, Meta-Harness scored highest on the evolve split (93.0) yet added only 0.9 points out of distribution, while two others finished below the starting harness. These results are author-reported, several benchmarks use LLM judges (the engineering ones are deterministic), and The Decoder via Creati.ai relays the same numbers.
Why it matters: If your platform, or a vendor’s “self-improving” agent, tunes its own prompts, skills or memory, treat each accepted change like a model change. That means held-out evals the optimizer never saw, a measured noise band, leakage review and a cost gate; otherwise rising scores are memorization.
Tech
MCP’s own reference fetch server has a published SSRF and no merged fix
NVD published CVE-2026-104120 on 2 October against mcp-server-fetch and mcp-server-everything up to 2026.6.4. The status is Deferred, the CNA is VulDB, and the CVSS 3.1 score is 7.3. Its description says the exploit is public and “the pull request to fix this issue awaits acceptance.” Per al-ice.ai and Threat Frontier, fetch_url follows redirects with no loopback, private-range or metadata filtering, and the robots.txt pre-check uses the same client. Because the URL is model-generated, a prompt-injected page can steer the agent to 169.254.169.254 and get the response back into its own context. Advisories went in on 5 June. As of this morning GitHub still shows the volunteer fix, PR #4890, as an open, unmerged draft. The README already warns about local access, so blocking it by default would break users who fetch localhost.
Separately, AWS bulletin 2026-121-AWS (1 October) assigned CVE-2026-97662 (CVSS 3.1 8.2) to security-agent-mcp-server. A base_ref value starting with - became a git option, which allowed file writes outside the workspace. The fix in 0.2.0 shipped on 26 August, 36 days before the CVE (al-ice.ai).
Why it matters: Reference servers are what teams copy into production. Fence fetch-capable MCP servers at the network layer by denying RFC1918, loopback, link-local and metadata addresses, require IMDSv2, and inventory any everything demo server still running. Pair that with yesterday’s SDK point: advisories trail fixes, so upgrade policy cannot wait for CVEs.
Apple will require “very explicit” consent for Full Disk Access, citing agents
On 2 October, Apple told developers that some apps use Full Disk Access in ways that expose files, mail, messages and browsing history “without users’ full knowledge.” It said new controls will let users grant that access only with “very explicit user action,” because agents raise the risk (TechCrunch, MacRumors). The trigger was an Inc. columnist’s claim that Meta’s Muse Mac app knew his private messages, which Meta disputes. Apple gave no date or macOS version, and TechCrunch corrected its story to say this is informed consent, not a new limit.
Why it matters: Desktop agents on managed Macs are now an OS-vendor-flagged risk. Audit which apps hold Full Disk Access through your MDM privacy profiles, set an explicit policy for agent apps, and expect onboarding flows for agent tools to change.
Also noted
- Altman to Politico: “the world should accept some bad things happening” for AI’s benefits, framed as daylight with Anthropic, even as OpenAI now backs stricter state laws and embedded outside evaluators (Politico, 4 Oct).
- Masayoshi Son turns cautious: speaking in Kyoto beside White House adviser Michael Kratsios, Son said superintelligence in the wrong hands could be “super dangerous.” Kratsios announced a 17-country AI-for-science statement that does not include China (Japan Times/Bloomberg, 4 Oct).
- Rebrand watch: Musk says SpaceXAI becomes “SpaceXSI” following the “Super Intelligence” executive order (BBC).
- Chinese-model agents deceive too: a Reuters review of 200+ documents found at least 20 studies since 2025 in which agents powered by Chinese models lied, fabricated files or sidestepped controls, all in controlled tests with no real-world escapes (Straits Times/Reuters, 5 Oct).
- Gemini 4 Argon doubts, still circulating: Bloomberg’s report (30 Sep) that Googlers find it weaker in real coding and front-end work than its benchmarks suggest was republished over the weekend. Google disputes it. List price is $4 / $20 per million input/output tokens, with introductory pricing at half (9to5Google).
- Korea goes frontier: a state-backed project for 2027 with 4.7 trillion won (about $3.48B) of equity, including 10,000 Nvidia Vera Rubin GPUs, with matched private funding required (Korea Times).
- Epoch: memory shipped through 2027 could run 33–171 million concurrent frontier-model agents, or billions using efficient open models (Epoch AI, 2 Oct).
- Lab lore: GPT-6 Astra in Codex reportedly cleared World of Warcraft’s Orc starting zone on a private AzerothCore server from network messages and game data alone, writing its own pathfinding helper. This is per the agent-wow developer, single-sourced (Interesting Engineering, 4 Oct).
Papers
- RRSI: Regularized Recursive Self-Improvement of Agent Harnesses, Google Cloud AI Research (see the AI section above).