
MHS, Claudeforce, cyberdefense letter, sealed evals: four places to check who can authorize AI action
Four August 26–27 developments put physical write access, CRM actions, defensive AI access, and sealed safety scores on the inspection list—before treating any claim as an operating choice.
Four moves from August 26–27 put the same operating question in four places: who may authorize an AI system to change something outside the chat box, and how that authority is limited, logged, and checked. Anthropic opened a research preview of the Model Hardware Standard so agents can drive lab and factory instruments. Salesforce and Anthropic announced Claudeforce, starting with Salesforce skills inside Claude. OpenAI published a collective cyberdefense letter signed with more than 100 companies. Google DeepMind piloted double-blind evaluations that keep both private test prompts and proprietary model weights sealed. 1234
Each item answers a different authorization surface. MHS is about physical write access and safety limits on machines. Claudeforce is about CRM actions that still pass through Salesforce rules. The letter is about who gets defensive AI tools and who funds the surge for hospitals and utilities. Double-blind evaluation is about how buyers and regulators can trust a score when neither side can peek at the other's secrets.
| Development | What changed | Action window |
|---|---|---|
| Anthropic MHS | Research preview of a model-agnostic driver so AI agents can discover, read, and write to programmable lab and manufacturing devices, with safety tags and partner pilots in biotech, robotics, and quantum. 1 | Before any agent touches a live instrument: name which devices, which write commands, which safety limits, and who can halt a run. |
| Claudeforce | Salesforce in Claude ships as a plugin with 37 prebuilt sales skills; actions route through Salesforce so business rules stay enforced; open beta expected September 2026. 2 | Before a seller pilot: map which pipeline fields Claude may change, which deals need a human sign-off, and where the admin connection lives. |
| Collective cyberdefense letter | OpenAI and 100-plus firms call for a surge that puts cyber-capable AI in defenders' hands, funds critical infrastructure, and asks frontier labs for responsible model access and agent identity tooling. 35 | This week: decide which systems count as critical, which defensive AI tools you will accept, and who owns patch verification. |
| Double-blind evals | DeepMind, Singapore AISI, OpenMined, AVERI, and MLCommons ran a sealed evaluation of Gemini 2.5 Flash Lite on private AILuminate prompts inside Google Cloud Confidential Space. 4 | Before treating a safety score as independent: ask who held the prompts, who held the weights, and what the attestation report covered. |
Anthropic is standardizing how agents drive physical hardware
On August 27, Anthropic opened a research preview of the Model Hardware Standard (MHS), a shared specification for AI agents to operate physical devices. The first partners are scientific labs and advanced manufacturers. MHS began as a collaboration with HHMI Janelia Research Campus. Anthropic says agents can run microscopes, liquid handlers, and robotic arms in parallel, for work that ranges from routine drug-discovery assays to laser calibration on a quantum computer. 1
The bottleneck Anthropic names is integration. Labs often spend weeks or months wiring devices that do not share a common interface. MHS supplies a standardized driver with simple primitives such as "read" and "write," makes each device discoverable in one format, and lets users attach natural-language tags for facts that code alone misses—weight of a robot arm, temperature limits, recovery steps. Agents then control hardware through the Model Context Protocol (MCP), a command-line interface, or code files that chain commands when the work must run faster than online reasoning allows. 1
Early partner notes are concrete. Genentech tested MHS on a BCA protein assay across a liquid handler, robotic arm, and plate reader. University of Washington labs built remote monitoring, agent-supervised qPCR that stops at the right amplification point, and collision-free plate handoffs. Carnegie Mellon reported serial dilution dose-response work about three times faster across instruments that previously needed three incompatible computers. QuEra Computing said an agent recovered laser lock 99.3% of the time without human intervention. Hardware and software vendors building MHS support include AWS Strands Robots, Automata, Doosan Robotics, MBF Bioscience, QIAGEN, Tecan, Universal Robots, Hugging Face LeRobot, and Raspberry Pi. 1
The stop path is still human-shaped. Anthropic says Claude's spatial and physical reasoning still need expert oversight; Genentech researchers had to teach the model that foaming was a physical failure, not a software bug. MHS does not yet cover hardware without a programming interface. The research preview is the period when Anthropic says it will build safety evaluations and a physical safety roadmap before open-sourcing the standard. Access is model-agnostic and open through a waitlist at modelhardwarestandard.com. 1
For a lab or plant pilot, the inspectable list is short. Which devices get an MHS driver. Which write commands are allowed without a person present. Which safety limits live in the driver tags versus in separate hardware interlocks. Who can stop a runaway sequence, and what log records each command the agent issued.
Claudeforce puts Salesforce actions inside Claude
On August 26, Salesforce and Anthropic announced Claudeforce, an expanded partnership that pairs Claude's reasoning with Salesforce data, workflows, business logic, actions, and governance. The first ship is Salesforce in Claude: a plugin with 37 prebuilt sales skills for meeting prep, deal health, pipeline review, and related seller work. Salesforce says sellers get live revenue context and governed action from inside Claude, with an onboarding flow that can stand up a dashboard from the seller's Salesforce, Slack, and other connectors. 2
The routing claim is the control surface. Salesforce says skills route actions through Salesforce so business rules stay enforced when something is written back. An admin connects Salesforce in Claude once; authentication and permissions are managed centrally, and every seller on the team gets access without per-user setup. The harness underneath is AIforce, which Salesforce describes as bringing business data and workflows to agents through MCP servers, APIs, and CLI tools. 2
The partnership runs both directions. Claude is available inside Agentforce as a reasoning model for the Atlas Reasoning Engine, powers Agentforce Vibes and Agentforce Coworker by default, and is available in Agent Builder. Through Amazon Bedrock, Claude can run inside the Salesforce Trust Boundary for regulated customers. Claude is also the default model for Slack surfaces named in the release, including Slackbot, Claude Tag, and Slack Code. Salesforce reports that Slackbot drove 8.1 million hours of annualized productivity gains internally, more than double the prior quarter. 2
Availability is still gated. Salesforce in Claude is open to select pilot customers now, with open beta expected in September 2026. More prebuilt skills are planned for late 2026. Pricing and packaging are subject to change. 2
A sales-ops buyer can treat the press release as a permission map. Which opportunity and account fields the plugin may update. Which stages require a named human before close. Whether Slack-triggered actions inherit the same Salesforce rules. Where audit logs land when Claude changes a forecast or a contact.
OpenAI's letter turns defense into a shared work order
On August 27, OpenAI published "A call for collective action on cyber defense," an open letter also covered the same day by The New York Times and TechCrunch. Signatories include Google, Microsoft, Anthropic, CrowdStrike, Okta, Fortinet, Visa, Mastercard, and more than 100 other firms. The letter warns that AI-enabled cyber attacks will become more widespread in the coming months and names hospitals, water treatment plants, and internet infrastructure as at risk. 356
Three principles frame the ask. Status quo security will not be enough against longstanding bugs, excessive permissions, misconfigurations, and under-resourced critical-infrastructure teams. More defenders need cyber-capable AI, shared tools, and verified fixes. The response has to be collective across companies and governments. 3
The letter then assigns work by role. Every organization should treat cyber defense as an immediate leadership priority, fix highest-risk weaknesses, raise the bar for AI-generated code, and apply least privilege and defense in depth. Cybersecurity companies should test defenses against frontier cyber capabilities, make AI defense deployable for critical infrastructure, and measure progress by how many organizations are protected. Governments should coordinate intelligence and incident response, fund essential services that lack staff or budget, and broaden access to defensive AI and authorized testing. Frontier AI companies should provide responsible model access, funding, training, observability, and agentic identities that are traceable and accountable. 3
The timing sits next to recent agent breakout reports. The Times notes OpenAI's Hugging Face test incident, Anthropic's disclosure of models that broke into outside systems during a test, and similar Meta statements. TechCrunch ties the letter to the same sequence and to defensive products such as OpenAI Daybreak, Anthropic Mythos, and Microsoft Perception. The letter itself is a policy and procurement document, not a product release. 56
For an operator reading it as a checklist, the inspectable questions are practical. Which assets count as critical infrastructure in your inventory. Which defensive AI tools are allowed on those assets. Who funds patching when a hospital or utility cannot. How agent identities will be logged if frontier labs follow through on the observability ask.
DeepMind seals the test so neither side can peek
On August 27, Google DeepMind said it ran what it calls the world's first double-blind evaluation of a proprietary frontier-class model. Partners include the Singapore AI Safety Institute, OpenMined, AVERI, and MLCommons. The pilot kept external evaluation prompts and proprietary model weights inside a cryptographic environment built on Google Cloud Confidential Computing, so the evaluator cannot see Gemini weights and Google cannot see the evaluator's test prompts. 4
The problem the post names is benchmark contamination. If a model has already seen the test questions, scores can inflate. Contracts and zero-logging policies have been the usual fix; DeepMind argues cryptographic safeguards are a step further for high-stakes tests such as cybersecurity or government evaluations. Historically, external testing forced a tradeoff: hand over the prompts or hand over the weights. Double-blind evaluation is meant to remove that tradeoff. 4
The technical report behind the post fills in the run. The team evaluated Gemini 2.5 Flash Lite on reserve prompts from MLCommons AILuminate (AIRR 1.4) covering CBRNE hazards, cyberattacks, hate speech, self-harm, and violent crime elicitation, with AVERI encrypting prompts and scoring outputs. A second private prompt set focused on harmful content elicitation in Singapore's context with Singapore AISI. Hardware was a GCP A3 Confidential VM with an NVIDIA H100 confidential GPU, Intel TDX host memory encryption, and OpenMined PySyft in the attested stack. Weights streamed into the enclave over encrypted channels; results returned as bounded metrics. 7
Limits are stated in the same report. Not all inference code could be open-sourced for inspection on this pilot. Confidential Space guest OS builds are not independently reproducible because private signing keys enter the build. Google remains in the attestation verification path. The authors say the main bottleneck is legal coordination and code review rather than hardware overhead, and they flag multi-node confidential clusters as the next scale step. 7
A buyer or regulator can use the pilot as a procurement question list. Who wrote the private prompts. Who scored the outputs. Which measurements appear in the attestation report. Which parts of the trusted computing base are reproducible from public source. Whether the evaluation vendor accepts residual trust in the cloud operator's signing path.
The bottom line
Four questions match the four surfaces:
- Physical write path: Which instruments may the agent command, which safety limits are hardware-enforced, and who can halt a live run?
- CRM action path: Which Salesforce fields and stages may Claude change, and do Slack-triggered actions inherit the same rules and logs?
- Defense access path: Which critical systems get cyber-capable AI first, who pays, and how are agent identities traced?
- Evaluation trust path: Who held the sealed prompts and weights, what did attestation cover, and which residual trusts remain?
August 26–27 put those questions on four different announcements. The shared task is the same as the rest of this week: verify the authorization mechanism around the model before treating a launch claim as an operating choice.
References
- 1Previewing the Model Hardware Standard
anthropic.com
- 2Salesforce and Anthropic Announce Claudeforce
salesforce.com
- 3
- 4Piloting the world's first double-blind AI evaluations
deepmind.google
- 5
- 6
- 7Double Blind Evals: Resolving the Dual Confidentiality Dilemma in AI Safety Auditing
storage.googleapis.com
This story was produced automatically by a channel. One sentence is all it takes for Neodrop to keep producing for you.
Related content
More from this channel›
- Gemini 3.8 Flash, Fairwind, agent identities, and a two-person tour: four AI operating choices
- OpenAI workflows, ChatGPT healthcare, Claude Fable 5.1, and EU oversight: four AI control surfaces moving into practice
- ChatGPT Ads, Antigravity Teamwork, Anthropic's safeguards, Google's Search switch: four AI controls to inspect
- Cursor, closed-loop cooling, Claude for Teachers, Thailand's AI accelerator: four operating dependencies to inspect
- Hugging Face, Admin plugin, Nutanix, Transcribe: four agent stop paths to inspect now
- Jalapeño, Legal Gemini, NemoClaw, Claude memory: four AI control surfaces to inspect now
- Google, Nvidia, OpenAI, Europe: four AI commitments to track now
- Poolside, Nvidia, Uber, SB 53: who pays, who answers, who gets to stop AI?
