Five rivals agree on one agent standard, a 15-year glueball hunt lands, AI writes a complete viral genome, Anthropic gates data before Claude sees it, and Cloudflare rethinks access for agents
Hello, dear TEA-mates! Here is what you need to know today.
1. 🔌 OpenAI and Four Rivals Agree on One Standard for AI Agents
OpenAI, Amazon, Anysphere (maker of Cursor), GitHub, Microsoft, and Vercel published Agent Plugins, an open standard that lets a single agent extension run across competing products. Vercel initiated the proposal, and the steering committee has five members: Amazon, Cursor, Microsoft, OpenAI, and Vercel. A plugin is simply a folder with a small plugin.json file at its root, bundling two things developers already use: Model Context Protocol servers, which connect an agent to live tools and data, and Agent Skills, which are reusable sets of instructions. ChatGPT, Codex, Cursor, GitHub Copilot, Kiro, and VS Code support the format at launch. The spec is narrow on purpose, defining only how a plugin is packaged and found, and leaving marketplaces, installation, permissions, sandboxing, and trust to each client. Dax Raad, who builds the SST developer-tools framework, said he was "very much against" it, calling it "a thin standard", while developer advocate Angie Jones wrote "We neeeeded this." (Read More)
🫖 TEA For Thought: "This is a good start. One standard for AI agents is much needed."
2. ⚛️ BESIII Says X(2370) Is Dominated by Pure Gluons
The BESIII Collaboration at the Beijing Electron Positron Collider reported that the particle X(2370) is dominated by a pseudoscalar glueball component, announced in a plenary report at the International Conference on High Energy Physics in Brazil on August 5. Glueballs are particles built entirely from gluons, the force carriers that bind quarks inside protons and neutrons, with no quarks of their own. X(2370) first surfaced in BESIII data from J/ψ decays in 2011. Using roughly 10 billion J/ψ events, the collaboration measured its spin-parity as 0⁻⁺ in 2024, matching lattice QCD predictions for the lightest pseudoscalar glueball, and has now added several previously unreported decay modes plus flavor-singlet behavior. BESIII describes this as a complete chain of evidence, while noting that states with identical quantum numbers can mix, so the particle need not be perfectly pure. The collaboration runs about 700 scientists across roughly 96 institutions in 15 countries. (Read More)
🫖 TEA For Thought: "Oooff. More like this will happen."
3. 🧬 Stanford Used AI to Design 16 Working Viruses
US researchers have used AI to design whole viral genomes for the first time, and the resulting viruses are fully functional and replicate in the lab. The AI models, Evo1 and Evo2, were trained on genetic code from viruses, bacteria, plants and people, then refined to produce bacteriophages, viruses that infect only specific species of bacteria. The Stanford team synthesised the 302 most promising designs, and 16 proved effective at killing E. coli. Assistant professor Brian Hie told the BBC "this was new territory for us." The phage genome runs about 5,400 base pairs, against roughly 500,000 for the smallest living cell and three billion for a human. The team excluded viruses that infect complex organisms from the training data and worked in a secure lab. In a commentary published in Science alongside the work, Dr Thomas Inglesby and Dr Moritz Hanke of Johns Hopkins wrote that it raises "urgent biosafety and biosecurity questions." (Read More)
🫖 TEA For Thought: "This will not be the first one, and there will be more to come. Eventually, humans might just destroy themselves. And hopefully God will give humans another chance to start over."
4. 🛡️ Anthropic Lets Companies Block Data Before Claude Sees It
Anthropic launched inference hooks for Claude Enterprise, a system that routes every prompt and tool call response through the customer's own data loss prevention server before Claude processes anything. The DLP server inspects the content and returns an allow or deny verdict, and Claude proceeds only once it has one. The same check runs on tool calls, so when Claude reaches a tool through MCP, skills, or plugins, that tool's response is inspected before it reaches the model. Until now, inline enforcement was limited to Claude Code's client-side hooks. Inference hooks extends it to every Claude Enterprise surface, including chat, Claude Code, Cowork, and connected tools, through a single configuration at the organisation level with no separate integration per product. The webhook-based protocol has a published schema and plugs into existing infrastructure from Netskope, Palo Alto Networks, Proofpoint, Zscaler, or custom servers. Shadow mode, role-based exclusions, and percentage-based rollouts let teams phase it in. It is in beta today. (Read More)
🫖 TEA For Thought: "This one definitely comes in handy, and every company, especially big enterprise companies, requires it."
5. 🔐 Cloudflare Proposes an Access Model Built for Agents
Cloudflare published the Agent Access Model, a proposed security architecture for AI agents that it frames as the successor to Google's BeyondCorp. BeyondCorp removed implicit trust from the network. This model removes it from the task, authorizing every single action against three things: who the agent is, what task it was approved to perform, and which resources the run has already touched. Rather than making each access decision smarter, the approach shrinks the agent's capability so there is less to judge. Its five principles include credentials that are short-lived and bound to a proof key the model never receives, enforcement in the harness and the network rather than in the prompt, and a Trust Ratchet whose capability state can only narrow during a task. The reference architecture names four active controls (Agent Identity Broker, Task-Scoped Access Engine, Mediation Layer, Trust Ratchet) plus an Agent Activity Log and a Grant Review Loop, and builds on existing standards including OAuth 2.0 Token Exchange (RFC 8693) and DPoP (RFC 9449). (Read More)
🫖 TEA For Thought: "Cloudflare has been pretty active recently with its open-source OS, as well as the wallets and this agent access model. It seems like Cloudflare is determined to build the ecosystem around AI agents in terms of security, payment, and the whole enterprise infrastructure, which is something that everyone is trying to tap into."
🛠️ Skill of the Day
The Lock-In Auditor: before you commit to a tool, vendor, or file format, find out what it would cost you to leave.
You are a procurement analyst who specializes in switching costs.
I am about to commit to [TOOL, VENDOR, PLATFORM, OR FILE FORMAT]
for [WHAT I WILL USE IT FOR].
Do not tell me whether to adopt it. Tell me what leaving would cost.
Work through these five points in order:
1. What would I have to export, and in what format? Name specifically
what does not export cleanly.
2. What would I have to rebuild from scratch somewhere else?
3. What gets held hostage if I leave: my data, my workflows, my
integrations, my audience, my history?
4. How long would a realistic switch take, in hours or days, and who
has to do that work?
5. What is the cheapest thing I can do TODAY to keep the exit door open?
Give me points 1 to 4 as a plain table, then point 5 as three concrete
actions I can start this week.
Flag clearly any place where the honest answer is "you would not
realistically be able to leave."Paste into ChatGPT, Claude, or your tool of choice. Replace the bracketed bits with your own.
TEAHEE Moment
Stay sharp, stay informed. See you Monday.
If you enjoyed this TEA, follow along on social for more:






