Daily AI Zine
Friday, August 28, 2026
Issue No. 043 · Tokyo · full edition

✦ Today's Big Thing

Anthropic opens a hardware safety standard for agents

The practical signal today is not another chat feature. It is a proposed safety layer for AI systems that operate physical devices.

6 min read · 7 sections

In Brief
  1. Anthropic opened a research preview of the Model Hardware Standard for safer physical-agent operation.
  2. Claude Code auto mode faces a reported prompt-injection attack pattern involving downloaded archives.
  3. The MCP roadmap is moving toward agent support and HTTP unification.
  4. fal introduced H3 Max, a fast post-trained video model with strong internal preference results.
  5. OpenAI’s GPT-5.6 builder guidance keeps pushing teams toward smarter model selection.

Today's Big Thing

The one thing that matters

Watch it

Anthropic opens a hardware safety standard for physical agents

The most important move today is about containment outside the screen.

Anthropic is opening a research preview of the Model Hardware Standard, described as a shared specification for AI agents to safely operate physical systems. This is early, but it matters because agents are moving from files, browsers, and code into devices, robotics, and production environments where a bad action has a larger blast radius. Treat this as a watch item, not an implementation plan. The useful shift is to separate “agent can decide” from “agent can actuate.” Any workflow that touches real-world equipment, locations, access, or movement should have explicit permission boundaries before the agent gets tools.

My AI Ecosystem

Your actual stack

Test it

Claude Code auto mode gets a sharper archive-safety warning

A prompt-injection researcher reportedly found an attack against Claude Code auto mode by tricking it into downloading and uncompressing a zip archive. The claim is not an Anthropic disclosure, so treat it as reported risk rather than settled fact. The practical takeaway is simple: auto mode needs file-ingest boundaries. For any agent run, downloaded archives should be explicitly allowed in the task brief or blocked.

Watch it

MCP roadmap points toward agents and simpler transport

The Agentic AI Foundation reportedly published a new MCP roadmap focused on AI-agent support and unifying communication around HTTP. MCP is the connector layer that lets AI tools reach files, services, and apps through a standard interface. If the roadmap holds, the useful direction is fewer bespoke connectors and clearer agent access rules. Watch for client and server updates before rebuilding anything.

Test it

Hot signal: fal pushes speed into video generation

fal introduced H3 Max, a post-trained version of MiniMax H3 optimized for speed by fal’s inference team. The company says its human preference evaluations rank H3 Max first for overall quality, prompt understanding, and aesthetics against leading video models. That is a vendor claim, but the direction is practical: faster video generation can make creative testing cheaper before committing to a heavier production pass.

CoWork Corner

Claude CoWork, day to day

CoWork: no new product move, tighten connector hygiene

Claude CoWork is the workspace Adrian uses for persistent projects, operational records, and AI-assisted workflows. No meaningful CoWork product change was found in today’s candidates. Revisit a basic Claude Desktop and MCP habit instead: keep only the connectors a project actually needs, and name the allowed tools in the project note before starting agent work. One-click MCP server installation makes setup easier, but easier setup also makes connector sprawl more likely.

Tier 4 · quiet day, honest fallback

GPT Desk

OpenAI, ChatGPT, Codex

Use it

Use GPT-5.6 as a routing exercise, not a prestige model

OpenAI’s builder guidance for GPT-5.6 highlights startups using smarter model selection and new Responses API capabilities to build more cost-efficient agents. Adrian should care because Grey Group OS, Daily Ops, Goodsense, and proposal work all contain mixed tasks: drafting, search, extraction, judgment, and final polish do not need the same model. Today’s action: pick one repeat workflow and write a three-lane routing rule for cheap draft, careful reasoning, and final client-facing output.

Test it

Give Codex one business-user build lane

OpenAI’s enterprise research says companies are adopting agentic AI with ChatGPT and Codex, and that frontier firms are pulling ahead in adoption. Adrian should care because SET, Street Attack Japan, and Goodsense have operational ideas that should not wait for a full engineering cycle. Today’s action: choose one non-core internal tool, such as a briefing generator or follow-up tracker, and make Codex produce a working first pass plus acceptance checks.

Small Money Systems

Small, repeatable, real

Use it

Small system: AI proposal upgrade sprint

System: build a one-hour proposal upgrade lane that turns a rough production or Japan-business pitch into a tighter deck outline, email, budget-note draft, and follow-up script. Customer: small agencies, founders, or overseas teams pitching work in Japan. Offer: they send a rough brief and receive a polished bilingual sales pack structure. Price: ¥35,000 per sprint. Existing assets: Grey Group proposal habits, Goodsense positioning, Japan-English workflow, and past deck patterns. AI workflow: ChatGPT drafts and restructures, then Codex or Claude Code turns repeat steps into a reusable intake form and output template. First action: create one sample before-and-after from a non-confidential dummy brief. Repeatability: each sprint reuses the same intake and pack format. Effort: one hour. Expected value: small direct revenue and warmer leads for larger production or strategy work.

Test it

Small system: agent archive-safety checkup

System: sell a lightweight checkup for teams using Claude Code, Codex, or other coding agents that flags risky file-ingest habits, especially downloaded archives. Customer: small dev teams, creative studios with websites, and operators shipping on GitHub and Netlify. Offer: a short written risk note, a safe-agent task brief template, and a rule for when agents may unpack files. Price: ¥25,000. Existing assets: Grey Group OS operating notes, Claude Code usage, GitHub repos, and delivery checklists. AI workflow: Claude Code reviews repo instructions and task files, while ChatGPT turns findings into client-facing language. First action: write the one-page “no archive unless named” policy. Repeatability: the same policy and checklist can be applied to each small repo. Effort: one hour. Expected value: paid cleanup work and reduced delivery risk.

Build Next

Deployable now

Use it

Build an agent archive stop rule

What to build: a simple repo instruction and task-template check that blocks agent runs from downloading or unpacking archives unless the task brief names the source and reason. Why now: a reported Claude Code auto mode attack uses a downloaded zip as the risky step, while Anthropic has already framed auto mode as a safer way to skip permissions. Effort: one hour. Expected impact: lower delivery risk when agents work quickly. Dependencies: an existing repo, current agent instructions, and willingness to make the agent stop instead of improvise.

Test it

Build a GPT job chooser for repeat workflows

What to build: a small chooser that labels each task as draft, reasoning, extraction, or final output before sending it to the right GPT lane. Why now: OpenAI’s GPT-5.6 builder guidance emphasizes smarter model selection and new Responses API capabilities for cost-efficient agents. Effort: half day. Expected impact: lower API waste and more consistent output quality. Dependencies: one repeat workflow, OpenAI API access, and a clear definition of which outputs are safe as drafts versus client-ready.

Try This Today

One action, right now

Add this rule to one active coding-agent task brief: the agent may not download, unzip, or execute external files unless the brief names the file source and purpose. Then run one normal task and see whether the rule interrupts useful work or only blocks risky improvisation.