Week 37, 2026
Coverage window 4–10 September 2026.
For the interpretation of this week, and why a configuration file that refuses to load is a bigger change than a frontier model release, see the companion essay: Weekly AI Tools That Matter to Me: Part 7, Week 37. This page is the record; the essay is the read.
This week’s record
Fail-closed became the default: in one release train, three separate misconfigurations stopped being ignored and started stopping the product.
- Claude Desktop v1.46388.1 (4 September) made an unreadable Claude Code managed-settings file refuse to start the session and name the source, where previously it ran without those settings, and added
disableBypassPermissionsMode, which removes bypass permissions mode from Code sessions and Cowork tasks entirely. - Claude Desktop v1.49585.0 (8 September) made an invalid “Required organization” device-policy value block sign-in with a configuration error instead of being ignored, and added
continuousAccessEvaluationfor the bundled Microsoft 365 connector: tokens that can live about 28 hours but are revoked within minutes when an administrator revokes sessions. - GPT-6 Astra (9 September) meets the Critical threshold for cybersecurity under OpenAI’s Preparedness Framework, ships with production misalignment monitoring that stops the task outright in the API, and for enterprises is off by default at launch.
- The OpenAI Agents API (10 September) entered public beta, exposing the Codex harness with
multi_agentsubagents, automatic context compaction across multi-day sessions, and a choice of sandbox including deployment inside the customer’s own VPC. - Gemini Notebook Enterprise (9 September) now blocks website URL ingestion outright in projects with VPC Service Controls, because a live web crawl would breach the perimeter.
- A Windows update released 8 September, including KB5124008, stops Cowork reaching local files. Cloud sessions and Claude Code are unaffected. This edition was compiled in a cloud workspace for exactly that reason.
What changed this week
| Platform | What changed | Source |
|---|---|---|
| Anthropic (Claude Code)Shipped (Sep 4)Breaking change / governance | (breaking) An unreadable managed-settings.json, drop-in, device-management plist or Windows policy registry value now makes Claude Code refuse to start and name the source; previously sessions ran without those settings | Changelog |
| Anthropic (Claude Desktop)Shipped (Sep 4)Governance | disableBypassPermissionsMode: removes bypass permissions mode from Code sessions and Cowork tasks, so the configured permission policy always applies | Changelog |
| Anthropic (Claude Desktop)Shipped (Sep 4)Governance | blockReadsOutsideWorkingDirectories: file tools refuse reads outside the session folder and allowedWorkspaceFolders, and sandboxed shell commands lose access to the home directory | Changelog |
| Anthropic (Claude Desktop)Shipped (Sep 4)Governance | allowedMcpServers scope narrowed to servers users add themselves; a server from a managed-mcp.json file that the allowlist previously filtered out now loads, and deniedMcpServers is the way to block it | Changelog |
| Anthropic (Claude Desktop)Shipped (Sep 4)Breaking change / governance | (breaking) relaunchEnforcementHours moved from bootstrap. to lifecycle. in served configuration, is no longer read at the old path, and the default window before a required restart is now 24 hours instead of 1. configRecheckIntervalMinutes added, 2 to 30 minutes, unset now means 10 where the app previously checked every 30 | Changelog |
| Anthropic (Cowork)Shipped (Sep 4)Product release / governance | Folder scope expanded to the home folder, Windows Documents, AppData, the macOS Library folder and whole drives, with credential and shell-startup locations explicitly excluded (SSH keys, AWS and Google Cloud credentials, and bash, zsh and PowerShell profiles) | Changelog |
| Anthropic (Claude Desktop)Shipped (Sep 8)Governance | An invalid “Required organization” device-policy value now blocks sign-in with a configuration error, shown in the diagnostic report, instead of being ignored | Changelog |
| Anthropic (Claude Desktop)Shipped (Sep 8)Governance / identity | continuousAccessEvaluation for the bundled Microsoft 365 connector, default enabled: CAE tokens can live about 28 hours but are revoked within minutes when an administrator revokes sessions or a tenant network policy no longer allows them. microsoftAuthBroker: required makes sign-in fail rather than fall back to the browser, keeping the refresh token with the broker; earlier versions treat required as disabled | Changelog |
| Anthropic (Claude Desktop)Shipped (Sep 8)Product release | Runtime updated to Electron 44 (Chromium 152); macOS 13 Ventura or later now required. Tool search on by default for Claude API, Vertex AI and Bedrock deployments without a custom base URL; toolSearchEnabled no longer needed | Changelog |
| Anthropic (Cowork)Open issue (Sep 10)Advisory | Known issue: a Windows update released 8 September including KB5124008 stops Cowork reaching local files, so tasks fail or the workspace does not start. Affects Cowork on the local machine and on third-party inference deployments; cloud sessions and Claude Code are unaffected. Reinstalling does not help | Changelog |
| AnthropicPublished (Sep 10)Market signal | ”Detecting and countering misuse of AI: September 2026”: threat intelligence report covering eight months of identified and disrupted operations and how malicious use has evolved since the 2025 reports | Newsroom |
| Google (Gemini Enterprise)Shipped (Sep 9)Breaking change / governance | (breaking) Gemini Notebook Enterprise website URL ingestion blocked in projects with VPC Service Controls, because direct ingestion performs a live web crawl generating outbound traffic beyond Google networks. Google Docs and YouTube URLs remain supported | Release notes |
| Google (Gemini Enterprise)Private preview (Sep 9)Product release | Custom actions and custom fields in data stores: generate and enable custom actions from custom entities, and modify field descriptions to give the model more context | Release notes |
| Google (Gemini Enterprise)GA (Sep 10)Pricing / packaging | Pay-as-you-go edition and AI developer tools opened to all projects linked to an invoiced Cloud Billing account, removing the prior email-based restriction | Release notes |
| Google (Gemini Enterprise)GA / Preview (Sep 4–10)Product release | Slack app gains channel mentions, with responses returned privately, and multi-turn conversations. Semantic search in Google Cloud Marketplace (Preview, Sep 8); Monday federated data store GA, project management, and new data stores and actions in Preview (Sep 4) | Release notes |
| OpenAILaunched (Sep 9), phased rolloutProduct release / governance | GPT-6 Astra. Meets the Critical threshold in cybersecurity under the Preparedness Framework: ExploitBench 100%, SRE-Bench 88.0% in one attempt, and two previously unknown zero-days discovered and used during evaluation, both being disclosed. The shipped model refuses advanced offensive tasks. Production misalignment monitoring stops potentially unauthorised activity; in the API the task stops. Enterprise access is off by default and an administrator must enable it. Scope-adherence evaluation: Sol exceeded authorised scope in 48% of cases without safeguards, Astra in none. Written reasoning is harder to monitor than Sol’s when explicitly tested for evasion. ZDR supported; $10 / $50 per million input / output tokens | GPT-6 Astra |
| OpenAIPublic beta (Sep 10)Agentic AI | Agents API in public beta: the Codex harness managed by OpenAI, with multi_agent subagents and max_concurrent_subagents, automatic context compaction for sessions running days, tool search and programmatic tool calling, vault_ids for secrets, and a choice of OpenAI-hosted sandbox, own infrastructure or partner environments including deployment inside the customer’s VPC. No additional fees beyond tokens and tools | Introducing the Agents API |
| OpenAILaunched (Sep 9–10)Product release / company | ChatGPT for Financial Services; “Now everyone can put data to work”; GPT-Live-1 voice in the API; Paul Christiano joins the OpenAI Foundation Board (Sep 9) | News |
| Google AntigravityShipped (Sep 3, late capture)Product release | 2.12.2: Gemini 3.8 Flash reasoning models reachable using Application Default Credentials in Antigravity Enterprise | Changelog |
No changes this week (scanned, nothing net-new)
Scanned for the 4–10 September window with no net-new release:
- Google Antigravity: 2.12.2 of 3 September is the newest; nothing shipped inside the window.
- Google Workspace: updates of 9 September cover Sheets pivot calculated fields and similar; nothing touching agentic work.
- Google Gemini apps: no material agentic-work change.
- Microsoft 365 Copilot: scanned under the relevant-only rule; nothing touching agentic work or MarTech. The one Microsoft-adjacent change of the week is Anthropic’s Continuous Access Evaluation support for the bundled Microsoft 365 connector, recorded above.
- chiefmartec: no post since 5 May 2026, fifth consecutive edition.
- Marketing AI Institute, Every, Latent Space, Ben’s Bites: scanned; nothing requiring a primary trace this week.
Watching next (Week 38)
- The Anthropic threat-intelligence report of 10 September, in window and not yet read in full.
- The GPT-6 Astra system card, particularly the monitorability decline and what Private Safety Processing means for enterprise data handling.
- OpenAI Daybreak and the less restrictive cyber safeguards said to be weeks away.
- Agents API: session lifetime, how
vault_idshandles credentials, and whether an administrator can constrain which environments a session may use. allowedMcpServers: whether the narrowed semantics leave a managed server running that administrators believed was blocked.microsoftAuthBroker: requiredrollout ordering, since earlier versions treat it asdisabled.- KB5124008: whether Anthropic ships a workaround or Microsoft reverts.
- Gemini Enterprise connector write actions, in Preview since 28 August and not yet GA, fourth edition.
- ChatGPT Work session lifetime and revocation path, fourth edition unanswered.
How this is compiled. This record is built from official changelogs, release notes and vendor newsrooms, read as rendered pages in a browser, with an AI first-pass scan followed by human review and editing. Every item is checked against a primary source before it appears here. Anything not confirmed against a primary source is flagged inline. Dates and status are as of the current-as-of date above and can change.
Corrections and method notes. Corrections are welcome and late-captured items are logged transparently rather than backdated. This edition carries one late capture, Antigravity 2.12.2 of 3 September. Two route notes are recorded for the method: claude.com blocks the javascript_tool read path and must be read with page-text extraction, and a Gmail query using the label-ID form returns zero results silently where the display-name form returns hundreds, which is a failure mode that looks exactly like a quiet week. This edition was compiled in a cloud workspace because the local file shell was unavailable for the whole run, caused by the Windows defect recorded in the table above.
AI Watch is compiled and edited by Andrea Veggiani, Head of Cross-Channel Marketing & MarTech Solutions at BitBang.