AI Watch: Week 33, 2026

Week 33, 2026
Coverage window 6 – 14 August 2026.

For the interpretation of this week, why skills became the thing that needs approving and why the read-only phase of agent integration ended without an announcement, see the companion essay: Weekly AI Tools That Matter to Me: Part 4, Week 33. This page is the record; the essay is the read.

This week’s record

Skills became the unit of governance, at three vendors, in eight days.

  • Anthropic shipped skill and plugin security scanning for Enterprise on 6 August, automatically checking third-party skills and plugins for malicious content on upload or edit.
  • Google made custom skills generally available in Gemini Enterprise on 13 August, and made them administratively gated: administrators must enable skills and skill-sharing in Feature Management, can configure skill availability, and approve skill-sharing requests.
  • Treasure AI turned saved workflows into Work Folder Actions on 13 August, defining an action explicitly as a work folder skill, convertible in both directions.

Until this week the governable objects in an agent platform were the model, the connector and the session. A skill was a convenience. In eight days all three vendors began treating skills as artefacts that arrive from outside, need scanning, need an approval workflow, and need a sharing boundary. That is software supply chain vocabulary, applied to prose.

Two other threads ran through the same window.

  • Anthropic published its EU AI Act Article 50(2) marking commitments on 11 August, as a signatory to the Code of Practice on Transparency of AI-Generated Content, covering embedded watermarks in generated text and signed provenance metadata in generated files.
  • The read-only phase of agent integration ended, quietly. The previous edition counted seventeen new read data stores at Gemini Enterprise against exactly one new write action, and called the ratio a governance posture. Nine days later the GitHub connector reached GA with the ability to merge pull requests and push files. In the same window ChatGPT gained the ability to update Google Drive source files directly, and Treasure AI agents gained read and write access across every work folder. None of it was announced as a change of posture.

Quiet this week, verified: Anthropic newsroom (newest item 24 July), OpenAI newsroom, Microsoft Copilot under the relevant-only rule.

What changed this week

PlatformWhat changedSource
Anthropic Claude (Enterprise)Beta (Aug 6)Skills / Supply chainSkill and plugin security scanning, beta. Enterprise plans can enable automatic checking of third-party skills and plugins for malicious content whenever someone uploads or edits one. The first named supply-chain control on the skill surface at any of the three platforms, arriving a week before Google shipped the approval workflow for the same object class. No published statement yet of what the scan detects, what happens on a positive result, or whether artefacts are re-scanned when policy changes.Claude release notes
Anthropic (policy)Committed (Aug 11)Provenance / RegulationEU AI Act Article 50(2) marking commitments published. Anthropic has signed the Code of Practice on Transparency of AI-Generated Content as a provider of both generative AI models and generative AI systems. Claude models launched in the EU on or after 2 August 2026 will support machine-readable marking at launch: embedded watermarks in generated text, and digitally signed provenance metadata in generated files where supported. Marks apply across Claude Platform (API), Claude, Claude Code, Claude Cowork and Claude Tag, wherever Claude is offered, worldwide, with the caveat that some platforms or features may not support every marking type. Third-party detection support is committed, with documentation to follow. Models launched before 2 August fall under the law’s transition period, with marking support described as in progress. Two corrections to trade coverage: this is a statement of commitments and plans, not a declaration that marking is live everywhere today; and the widely reported 2 December 2026 backfill date does not appear in the vendor’s own document. Note also that a detected mark indicates the model processed the content, not that it authored it.How Claude marks AI-generated content
Google Gemini Enterprise (skills)Generally available (Aug 13)Skills / GovernanceCreate, upload and share custom skills, generally available. Skills are reusable custom instructions that help the assistant perform specific tasks; end users can create, upload and share them. Administrators must turn skills and skill-sharing on in Feature Management, can configure skill availability, and approve skill-sharing requests. Every clause after the first is a governance clause. Skills shipped GA with an off switch, an availability scope and an approval queue already attached, which is the reverse of how connectors arrived across the industry.Gemini Enterprise release notes
Google Gemini Enterprise (connectors)Generally available (Aug 12)Connectors / Write scopeGitHub connector with data federation, generally available. Search and act on repositories, issues and pull requests from the Gemini Enterprise agent, with tool actions including creating branches, adding issue comments, merging pull requests and pushing files. Read against the previous edition’s seventeen-reads-to-one-write count, this is the ratio changing without anyone saying so.Gemini Enterprise release notes
Google Gemini Enterprise (models)Generally available (Aug 12–13)ModelsGemini 3.7 Flash generally available in the global, us and eu regions, behind an administrator feature toggle in the Google Cloud console. Also AlphaEvolve HPC solution (12 August), distributed containerised infrastructure for large-scale evolutionary code optimisation, recorded for completeness and out of scope for this series’ agentic-work focus.Gemini Enterprise release notes
OpenAI ChatGPTShipped (Aug 13)Connectors / Write scopeGoogle Drive in Library. With the Drive plugin connected, Drive files and folders are browsable directly from Library, including items shared directly with the user, reachable from the composer or by @ mention without re-uploading. Docs, Sheets and Slides can be kept open beside the conversation, and a folder can be selected and worked across as a unit. Where supported and authorised, ChatGPT can update the source file directly. The write clause sits at the end of an availability note rather than in a headline, which is how this capability class has arrived on every platform this week.ChatGPT release notes
OpenAI ChatGPTShipped (Aug 10)Agentic commerceRestaurant reservations through OpenTable, Resy and Yelp, with availability and booking inline. Rolling out across all plans on mobile, web and desktop; OpenTable globally, Resy in the US, Yelp in the US and Canada. ChatGPT Work does not include restaurant reservation search. The exclusion is more informative than the feature: OpenAI is maintaining a deliberate capability split between the consumer and work products, and the thing withheld from work is a transaction. The work tier is not simply the consumer tier with SSO.ChatGPT release notes
OpenAI ChatGPTShipped (Aug 6–7)ProductApp experience updates (7 August): paste formatting retention, bringing documents and saved files into conversations, improved search and session resumption. A further entry dated 6 August sits at the window boundary.ChatGPT release notes
OpenAI ChatGPT Enterprise & EduShipped (Aug 13)Administration / ObservabilityChat model defaults. Workspace owners and administrators can set the starting chat model and reasoning level from Workspace settings, Models, choosing an administrator default or the user’s last choice for new chats; defaults cannot grant access to unavailable models or override enforced workspace requirements. Requires ChatGPT Desktop 26.812.10818 or later. Updated model picker preserving workspace availability and access controls. Audit logs in the Global Admin Console, with access and event coverage depending on workspace and administrator role. Read alongside Gemini Enterprise’s connector tracing from the previous edition, this is the same movement: administrators are being given the ability to answer what happened inside the platform’s own console.ChatGPT Enterprise & Edu release notes
Google AntigravityShipped (Aug 7–13)ReliabilityFour releases in seven days, no new capability. 2.8.1 (13 August), chat responsiveness, one fix. 2.8.0 (12 August), persistent sidebar folder state and reliable file and artifact previews, one improvement and six fixes. 2.7.1 (11 August), side-by-side previews for image diffs, screen-reader and keyboard accessibility work, eleven improvements and twenty fixes. 2.6.0 (7 August), faster opening of long conversation histories, more reliable custom hooks and subagents. Following 2.5.0’s enterprise sign-in work at the end of July, this is what a product does after it has been adopted rather than demonstrated. The changelog now carries separate tabs for Antigravity 2.0, CLI, SDK and IDE, a product-surface split to itemise next edition.Antigravity changelog
Anthropic (newsroom)No items in windown/aNo items in window. Newest remains Claude Opus 5, 24 July 2026. Verified in browser.Anthropic newsroom
Microsoft 365 CopilotNo items in windown/aNothing to report under this series’ relevant-only rule. No release section dated inside the window was located. Agent 365 connected agents via Agent2Agent was expected to reach general availability in August; nothing announced as of 14 August, a second consecutive edition with that expectation unmet.Copilot release notes

Cross-notes to the MarTech series

Also covered in MarTech Watch, Week 33:

  • Klaviyo published 260-plus MCP tools with full write scope on 11 August: read data, build segments, run campaigns, author flows, manage catalogs, callable from Claude, OpenAI or a custom agent. The largest published agent surface any customer engagement platform has shipped, arriving with no published session lifetime and no permission model. MoEngage’s 30-day session ceiling remains the only hard governance number anyone has put in writing.
  • Treasure AI isolated agent execution per chat on 12 August, stating openly that customer records, exports and downloaded data written outside a work folder had been accumulating in a location no file browser exposed, and describing the migration of those files somewhere visible. The most direct agent-governance disclosure of the week from either series.
  • Treasure AI’s Work Folder Actions are explicitly defined as work folder skills, which puts a data platform in the same design conversation as the three agent platforms above.
  • Adobe Journey Optimizer’s MCP server exposes five read-only channel configuration tools as of 9 July, and Adobe’s Loyalty Challenges release in late July shipped Coworker skills for challenge operations. The skills-as-governed-object pattern is already present on the application side.

The platforms are building the approval surface at roughly the same speed the application vendors are building the things that need approving. That is a better outcome than the alternative, and it is not what this series expected to be writing three editions ago.

Also next week

Itemise the Gemini Enterprise entries dated 1 to 11 August and recount the read-to-write action ratio. Establish what Antigravity CLI, SDK and IDE are, and when each appeared. Resolve whether skill scanning has published semantics at Anthropic and what an administrator actually sees when approving a skill share at Google. Trace the EDITED MCP server. Watch for Agent 365 connected agents via Agent2Agent, a third time.


How this is compiled. Each edition is assembled from official release notes, changelogs, and corporate newsrooms, with AI assistance for the first-pass scan, then reviewed and edited by me before publishing. Items are checked against the primary source; anything I could not confirm is flagged inline. Dates and status reflect what was published as of the current-as-of date above and can change.

Corrections and method notes. This is the first edition, so it sets a baseline: a few items reflect current state rather than a within-week change, and are dated accordingly. Found something inaccurate? Tell me and I will fix it next edition.

AI Watch is compiled and edited by Andrea Veggiani, Head of Cross-Channel Marketing & MarTech Solutions at BitBang.