AI Watch: Week 37, 2026

Week 37, 2026
Coverage window 4–10 September 2026.

For the interpretation of this week, and why a configuration file that refuses to load is a bigger change than a frontier model release, see the companion essay: Weekly AI Tools That Matter to Me: Part 7, Week 37. This page is the record; the essay is the read.

This week’s record

Fail-closed became the default: in one release train, three separate misconfigurations stopped being ignored and started stopping the product.

  • Claude Desktop v1.46388.1 (4 September) made an unreadable Claude Code managed-settings file refuse to start the session and name the source, where previously it ran without those settings, and added disableBypassPermissionsMode, which removes bypass permissions mode from Code sessions and Cowork tasks entirely.
  • Claude Desktop v1.49585.0 (8 September) made an invalid “Required organization” device-policy value block sign-in with a configuration error instead of being ignored, and added continuousAccessEvaluation for the bundled Microsoft 365 connector: tokens that can live about 28 hours but are revoked within minutes when an administrator revokes sessions.
  • GPT-6 Astra (9 September) meets the Critical threshold for cybersecurity under OpenAI’s Preparedness Framework, ships with production misalignment monitoring that stops the task outright in the API, and for enterprises is off by default at launch.
  • The OpenAI Agents API (10 September) entered public beta, exposing the Codex harness with multi_agent subagents, automatic context compaction across multi-day sessions, and a choice of sandbox including deployment inside the customer’s own VPC.
  • Gemini Notebook Enterprise (9 September) now blocks website URL ingestion outright in projects with VPC Service Controls, because a live web crawl would breach the perimeter.
  • A Windows update released 8 September, including KB5124008, stops Cowork reaching local files. Cloud sessions and Claude Code are unaffected. This edition was compiled in a cloud workspace for exactly that reason.

What changed this week

PlatformWhat changedSource
Anthropic (Claude Code)Shipped (Sep 4)Breaking change / governance(breaking) An unreadable managed-settings.json, drop-in, device-management plist or Windows policy registry value now makes Claude Code refuse to start and name the source; previously sessions ran without those settingsChangelog
Anthropic (Claude Desktop)Shipped (Sep 4)GovernancedisableBypassPermissionsMode: removes bypass permissions mode from Code sessions and Cowork tasks, so the configured permission policy always appliesChangelog
Anthropic (Claude Desktop)Shipped (Sep 4)GovernanceblockReadsOutsideWorkingDirectories: file tools refuse reads outside the session folder and allowedWorkspaceFolders, and sandboxed shell commands lose access to the home directoryChangelog
Anthropic (Claude Desktop)Shipped (Sep 4)GovernanceallowedMcpServers scope narrowed to servers users add themselves; a server from a managed-mcp.json file that the allowlist previously filtered out now loads, and deniedMcpServers is the way to block itChangelog
Anthropic (Claude Desktop)Shipped (Sep 4)Breaking change / governance(breaking) relaunchEnforcementHours moved from bootstrap. to lifecycle. in served configuration, is no longer read at the old path, and the default window before a required restart is now 24 hours instead of 1. configRecheckIntervalMinutes added, 2 to 30 minutes, unset now means 10 where the app previously checked every 30Changelog
Anthropic (Cowork)Shipped (Sep 4)Product release / governanceFolder scope expanded to the home folder, Windows Documents, AppData, the macOS Library folder and whole drives, with credential and shell-startup locations explicitly excluded (SSH keys, AWS and Google Cloud credentials, and bash, zsh and PowerShell profiles)Changelog
Anthropic (Claude Desktop)Shipped (Sep 8)GovernanceAn invalid “Required organization” device-policy value now blocks sign-in with a configuration error, shown in the diagnostic report, instead of being ignoredChangelog
Anthropic (Claude Desktop)Shipped (Sep 8)Governance / identitycontinuousAccessEvaluation for the bundled Microsoft 365 connector, default enabled: CAE tokens can live about 28 hours but are revoked within minutes when an administrator revokes sessions or a tenant network policy no longer allows them. microsoftAuthBroker: required makes sign-in fail rather than fall back to the browser, keeping the refresh token with the broker; earlier versions treat required as disabledChangelog
Anthropic (Claude Desktop)Shipped (Sep 8)Product releaseRuntime updated to Electron 44 (Chromium 152); macOS 13 Ventura or later now required. Tool search on by default for Claude API, Vertex AI and Bedrock deployments without a custom base URL; toolSearchEnabled no longer neededChangelog
Anthropic (Cowork)Open issue (Sep 10)AdvisoryKnown issue: a Windows update released 8 September including KB5124008 stops Cowork reaching local files, so tasks fail or the workspace does not start. Affects Cowork on the local machine and on third-party inference deployments; cloud sessions and Claude Code are unaffected. Reinstalling does not helpChangelog
AnthropicPublished (Sep 10)Market signal”Detecting and countering misuse of AI: September 2026”: threat intelligence report covering eight months of identified and disrupted operations and how malicious use has evolved since the 2025 reportsNewsroom
Google (Gemini Enterprise)Shipped (Sep 9)Breaking change / governance(breaking) Gemini Notebook Enterprise website URL ingestion blocked in projects with VPC Service Controls, because direct ingestion performs a live web crawl generating outbound traffic beyond Google networks. Google Docs and YouTube URLs remain supportedRelease notes
Google (Gemini Enterprise)Private preview (Sep 9)Product releaseCustom actions and custom fields in data stores: generate and enable custom actions from custom entities, and modify field descriptions to give the model more contextRelease notes
Google (Gemini Enterprise)GA (Sep 10)Pricing / packagingPay-as-you-go edition and AI developer tools opened to all projects linked to an invoiced Cloud Billing account, removing the prior email-based restrictionRelease notes
Google (Gemini Enterprise)GA / Preview (Sep 4–10)Product releaseSlack app gains channel mentions, with responses returned privately, and multi-turn conversations. Semantic search in Google Cloud Marketplace (Preview, Sep 8); Monday federated data store GA, project management, and new data stores and actions in Preview (Sep 4)Release notes
OpenAILaunched (Sep 9), phased rolloutProduct release / governanceGPT-6 Astra. Meets the Critical threshold in cybersecurity under the Preparedness Framework: ExploitBench 100%, SRE-Bench 88.0% in one attempt, and two previously unknown zero-days discovered and used during evaluation, both being disclosed. The shipped model refuses advanced offensive tasks. Production misalignment monitoring stops potentially unauthorised activity; in the API the task stops. Enterprise access is off by default and an administrator must enable it. Scope-adherence evaluation: Sol exceeded authorised scope in 48% of cases without safeguards, Astra in none. Written reasoning is harder to monitor than Sol’s when explicitly tested for evasion. ZDR supported; $10 / $50 per million input / output tokensGPT-6 Astra
OpenAIPublic beta (Sep 10)Agentic AIAgents API in public beta: the Codex harness managed by OpenAI, with multi_agent subagents and max_concurrent_subagents, automatic context compaction for sessions running days, tool search and programmatic tool calling, vault_ids for secrets, and a choice of OpenAI-hosted sandbox, own infrastructure or partner environments including deployment inside the customer’s VPC. No additional fees beyond tokens and toolsIntroducing the Agents API
OpenAILaunched (Sep 9–10)Product release / companyChatGPT for Financial Services; “Now everyone can put data to work”; GPT-Live-1 voice in the API; Paul Christiano joins the OpenAI Foundation Board (Sep 9)News
Google AntigravityShipped (Sep 3, late capture)Product release2.12.2: Gemini 3.8 Flash reasoning models reachable using Application Default Credentials in Antigravity EnterpriseChangelog

No changes this week (scanned, nothing net-new)

Scanned for the 4–10 September window with no net-new release:

  • Google Antigravity: 2.12.2 of 3 September is the newest; nothing shipped inside the window.
  • Google Workspace: updates of 9 September cover Sheets pivot calculated fields and similar; nothing touching agentic work.
  • Google Gemini apps: no material agentic-work change.
  • Microsoft 365 Copilot: scanned under the relevant-only rule; nothing touching agentic work or MarTech. The one Microsoft-adjacent change of the week is Anthropic’s Continuous Access Evaluation support for the bundled Microsoft 365 connector, recorded above.
  • chiefmartec: no post since 5 May 2026, fifth consecutive edition.
  • Marketing AI Institute, Every, Latent Space, Ben’s Bites: scanned; nothing requiring a primary trace this week.

Watching next (Week 38)

  • The Anthropic threat-intelligence report of 10 September, in window and not yet read in full.
  • The GPT-6 Astra system card, particularly the monitorability decline and what Private Safety Processing means for enterprise data handling.
  • OpenAI Daybreak and the less restrictive cyber safeguards said to be weeks away.
  • Agents API: session lifetime, how vault_ids handles credentials, and whether an administrator can constrain which environments a session may use.
  • allowedMcpServers: whether the narrowed semantics leave a managed server running that administrators believed was blocked.
  • microsoftAuthBroker: required rollout ordering, since earlier versions treat it as disabled.
  • KB5124008: whether Anthropic ships a workaround or Microsoft reverts.
  • Gemini Enterprise connector write actions, in Preview since 28 August and not yet GA, fourth edition.
  • ChatGPT Work session lifetime and revocation path, fourth edition unanswered.

How this is compiled. This record is built from official changelogs, release notes and vendor newsrooms, read as rendered pages in a browser, with an AI first-pass scan followed by human review and editing. Every item is checked against a primary source before it appears here. Anything not confirmed against a primary source is flagged inline. Dates and status are as of the current-as-of date above and can change.

Corrections and method notes. Corrections are welcome and late-captured items are logged transparently rather than backdated. This edition carries one late capture, Antigravity 2.12.2 of 3 September. Two route notes are recorded for the method: claude.com blocks the javascript_tool read path and must be read with page-text extraction, and a Gmail query using the label-ID form returns zero results silently where the display-name form returns hundreds, which is a failure mode that looks exactly like a quiet week. This edition was compiled in a cloud workspace because the local file shell was unavailable for the whole run, caused by the Windows defect recorded in the table above.

AI Watch is compiled and edited by Andrea Veggiani, Head of Cross-Channel Marketing & MarTech Solutions at BitBang.