OpenAI now says it will publish a technical report in the coming weeks on the Hugging Face security incident that hit its models during internal evaluations, with external advisors reviewing under Safety and Security Committee oversight. In coding tools, Anthropic capped Claude Code sessions at 200 WebSearch calls and 200 subagent spawns, and OpenAI shipped a plugin to run Codex inside Claude Code's terminal.
Frontier Lab Watch
OpenAI Vows Technical Report on AI Safety Incident
OpenAI acknowledged the questions circulating about the Hugging Face security incident involving its models during internal evaluations. The company called the event unprecedented and confirmed an ongoing review with external advisors under Safety and Security Committee oversight, with a technical report of findings due in the coming weeks. (We recognize there are a lot of questions and speculative details circulating related to the Hugging Face incident. — OpenAI).
AI Coding Tools
Claude Code Adds Session Caps and Auto Mode
Anthropic set hard limits of 200 WebSearch calls and 200 subagent spawns per Claude Code session to stop runaway agents and token drain. The update adds auto-backgrounding for long tasks and defaults to auto mode. (Claude Code now hard-caps runaway agents: 200 WebSearch calls and 200 subagent spawns per session. No more infinite loops draining tokens. Auto-backgrounding and default auto mode round out the release. — X).
OpenAI Ships Codex Plugin for Claude Code
A new official OpenAI-built codex-plugin-cc runs Codex inside the Claude Code terminal, with no tab switching or copy-paste. It handles task delegation, adversarial reviews, background fixes, and status tracking using an existing ChatGPT subscription. (🤯This is insane… you can now run Codex inside Claude Code. — X).
Veritas Kanban 6.1.0 Unifies AI Coding Agents
The open-source Veritas Kanban 6.1.0 release adds first-class support for managing Codex, Claude Code, GitHub Copilot CLI, and other harnesses from one Kanban interface, with capability detection, approvals, and telemetry. Buzz becomes the flagship ACP-based agent while each tool keeps its native execution paths. (🐝 Buzz is now a first-class agent harness in Veritas Kanban 6.1.0. — X).
Claude Code Releases v2.1.220 with Stability Fixes
The July 25 update focuses on bug fixes and reliability, cutting crashes and improving response consistency across CLI sessions. It follows the prior sub-agent changes. (Claude Code 2.1.220 has been released. — X).
Enterprise AI Adoption
Trend Micro Identifies Four Agentic AI Control Gaps
A July 26, 2026 Trend Micro research paper argues agentic AI carries unique risk because systems reason, plan, and act autonomously across enterprise environments without constant oversight. The report names four gaps existing governance programs miss: no structured agent inventory, weak least-agency limits on agent scope, inadequate supply-chain risk treatment for AI tools and plugins, and no monitoring of inter-agent communication. It recommends inventory exercises, permission constraints, vendor risk routing, behavioral baselines, and explicit approval gates for high-impact autonomous actions to reduce compliance and audit exposure under frameworks like the EU AI Act. (Trend Micro Identifies Four Agentic AI Controls Enterprises Are Missing: Inventory, Least-Agency, Supply Chain, and Communication Monitoring — AI Governance Institute).