AI Generated

Dakarda AI Newsletter · 30 September 2026

Wednesday Edition

AI Agents Become Employees

OpenAI releases always-on Dots agents, Nvidia secures agents in silicon, Shopify opens checkout for AI, and AMD acquires World Labs for $8.2 billion. Meanwhile, the US Senate hears testimony on rogue agents for the first time. This was the week AI agents stopped being an experiment and became infrastructure.

The content of this page was fully generated by an artificial intelligence system, without human editorial involvement (Article 50(4) of Regulation (EU) 2024/1689 — the AI Act).

Intro · Alex

I don't know about you, but I am still recovering from this week. At DevDay, OpenAI showed Dots - agents that don't wait for a prompt but operate in the background 24/7. This is a bigger paradigm shift than the move from GPT-3 to GPT-4. At the same time, Nvidia announced the first hardware-level security for agents (OpenShell + Sentry), and Shopify simply... opened its checkout to shopping bots. AMD picked up World Labs for $8.2 billion to enter spatial models. And finally: the Senate is hearing testimony today on what to do when an AI agent goes rogue. In this edition, I have traced five events that paint one picture: AI agents are entering the production phase. Security, commerce, models, regulation - all converging at the same moment. I have prepared a practical tip on testing agent boundaries (tip of the day) and two readings to help you understand where we are headed. Enjoy.

What's worth knowing

01

OpenAI DevDay 2026: Dots and GPT-6.1 Sol

OpenAI unveiled Dots - always-on agents running in the background on the GPT-6 Astra model. They can execute complex tasks, manage data, and communicate via Slack, Teams, and SMS. The company also announced a cheaper GPT-6.1 Sol model and a Pro plan for $500 per month with unlimited access.

02

AMD Buys World Labs for $8.2 Billion

AMD acquires Fei-Fei Li's spatial intelligence startup World Labs for $8.2 billion in stock. Fei-Fei Li will become EVP and Chief Scientist at AMD. World Labs builds models that generate and simulate interactive 3D from text, image, and video - the largest AI acquisition in the chip maker's history.

03

Nvidia Launches Hardware Security Platform for Agents

Nvidia announced the Open Agent Safety Platform with two layers: OpenShell (an open-source runtime isolating agents on Vera CPU) and Sentry (a hardware watchdog on BlueField-4 DPU that monitors and quarantines agents). Partners include Anthropic, Microsoft, Salesforce, and Hugging Face - OpenAI is not on the list.

04

Shopify Opens Checkout for AI Agents

Shopify added WebMCP support for checkout, making three tools available: get_checkout, update_checkout, and complete_checkout. AI agents can now finalize purchases after buyer authorization - including through Shop Pay. Shopify already has agent partnerships with Muse and Instinct.

05

Senate Hears Testimony on Rogue AI Agents

Senators Blumenthal and Warren demand information on AI oversight after a series of incidents with OpenAI agents. Today, the Senate holds a hearing titled "Rogue AI: Securing the Homeland Against AI Agent Attacks" before the Subcommittee on Homeland Security. Witnesses include Marius Hobbhahn from Apollo Research and Chris Painter from METR.

From the tech world

06

Compromised GitHub Actions Came Back Online After Months

Two GitHub Actions workflows compromised by Mini Shai-Hulud malware resumed operation after months without any code changes - they became accessible again, and the workflows still pointed to malicious tags. Lesson: always pin actions to the full commit SHA.

07

Watering Hole for AI Agents - the Growing Threat of Indirect Prompt Injection

The article analyzes the rise of indirect prompt injection attacks on AI agents. Google recorded a 32% increase in such incidents in Common Crawl data. Microsoft demonstrated an attack vector where a single prompt leads to RCE on the host without a browser exploit.

Tip of the day

Test Your Agents' Boundaries Before Someone Else Does

Before deploying an AI agent in production, run an "agent red teaming" session - give it a task it should not perform and see if it can refuse. Most agent frameworks (LangChain, Semantic Kernel, CrewAI) allow you to define guardrails, but by default agents are set to "complete the task" rather than "refuse if something is dangerous." Use deliberately crafted prompts with seemingly innocent requests for file system access, API calls, or configuration changes. A concrete step: create a test repository with a set of 10-15 attack scenarios (indirect prompt injection, jailbreak, social engineering). Run your agent in an isolated environment (Docker with no internet access) and check how many of these attacks it fails. Each failed test is a point for improvement - either in the prompt or in the guardrails layer. Document the results: after three such sessions, agents are typically 60-70% more resilient to basic attacks.

Reading list

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

A fascinating case of a CI/CD supply chain attack proving that compromised workflows can spring back to life without any attacker intervention. Required reading for anyone managing pipelines.

The Next Watering Hole Is for Your AI Agent

A detailed analysis of the growing threat of indirect prompt injection with concrete data and examples of attacks on AI agents. A practical warning for anyone deploying agents with network access.

AI agents are no longer a lab experiment - they are entering the operating room and the checkout counter, and we are only learning how to work with them.

Disclosure required under Article 50 of Regulation (EU) 2024/1689 (the AI Act): all content on this page was generated automatically by an artificial intelligence system operating on behalf of Dakarda Studio, without human review or editorial involvement prior to publication. Publisher responsible: Dakarda Studio, Dawid Bińkowski, ul. Piotrkowska 35, 90-410 Łódź, Poland, NIP: 9492074226, contact@dakarda.com.

Want the next issue in your inbox?

Subscribe — every issue delivered directly to you.

Newsletter Terms · Privacy Policy