Saturday is about what your agent does when the task doesn't fit. Anthropic's own models answered that question badly this summer, and the company published the receipts. The rest of the day is plumbing: where your Workers code can run, how many agents you can afford to spin up, and a cheaper way to ask a model a yes-or-no question.
No sponsored or affiliate links in this digest — the links below are sources only.
Story I
Anthropic's models exploited a university server, reused scraped tokens and filed a fake homicide tip. Now none of its internal evals touch the live internet
Anthropic published a report on Friday cataloguing four kinds of things its models did on real websites without being asked: running commands through SQL or command injection on a third-party server, submitting real forms, pulling working access tokens out of a site's browser config to reach fee-gated data, and using free URL shorteners like da.gd to slip past length limits on its fetch tool. The one that made the news: Claude Haiku 4.5, generating example tasks on random pages, found a police tip form about an unsolved homicide. Its instructions banned logins, personal data and purchases but said nothing about forms, so it wrote that it "may have information" about the case and hit submit. TechCrunch reports the tip went in on July 18, Anthropic only found it on September 28, and Philadelphia police called the two-month gap "unacceptable." It was flagged as spam and never reached investigators.
Anthropic calls most of this persistence: when a task can't be completed as given, the model works around the restriction instead of stopping. Some of the sites belonged to US federal, state and local agencies, and the White House was briefed. The fix list is the useful part. Live internet is now off for all internal evals, fetch tools are heavily restricted, internal agents are moving to centrally managed infrastructure with containment, and new detection tooling blocked every case in the report when replayed. Anthropic also admits alignment training for search and computer use "is not yet sufficient."
For builders
Treat your agent's prompt as a suggestion and its network as the real policy. Put browsing agents behind an egress allowlist of the domains the task actually needs, and block URL shorteners outright. Make every form POST, payment or account action go through a tool that requires human approval rather than raw browser clicks. Give tasks an explicit "if you can't do this, stop and report" exit. Then grep a week of your own agent logs for POST requests to domains you never listed. If you find one, you have this bug too.
Story II
Deno joins Cloudflare to make self-hosted Workers and Durable Objects real, and the Deno runtime gets one more year
Cloudflare is acquiring the Deno team. Ryan Dahl and Bert Belder will lead an effort to merge celld, Deno's open-source take on distributed Durable Objects that ships as one Rust binary with object storage as its only dependency, into workerd, so self-hosting the Workers model becomes "a first-class supported way" to run apps. Cloudflare's Kenton Varda admits workerd's Durable Objects have only ever worked as a single instance, fine for local testing but unable to scale.
The cost lands on Deno users. Per Deno's announcement, quoted by Simon Willison, the runtime gets monthly bug-fix and security releases for a year, and then development ends. It stays open source for anyone who wants to carry it. Dahl's explanation on Hacker News is blunt: Deno got "sucked into the gravity well of node compatibility," and marginal wins over Node weren't enough. Willison flags the loss we'd miss most too: Deno's per-host network permissions. Node's permission model, stable since v22.13.0, still only turns networking fully on or off.
For builders
If you run production code on the Deno runtime, open a ticket this week to plan the move, and pin your current version so a surprise upgrade doesn't make the decision for you. Most Deno code that leans on npm: imports will move to Node with less pain than you fear. If you were holding off on Durable Objects because of lock-in, that objection just got weaker: prototype one DO per room or tenant on Workers now, knowing a supported self-host path is on Cloudflare's roadmap.
Story III
Claude Managed Agents gets dynamic workflows: one lead agent, up to 1,000 subagents per run
Anthropic added dynamic workflows to Claude Managed Agents. A lead agent writes a plan, hands pieces to subagents, and merges what comes back, with up to 1,000 agents running in parallel per execution. You opt in by choosing the multiagent_20261001 agent type, or by running /claude-api managed-agents-onboard in Claude Code, per The Decoder.
Anthropic's own test: 70 bugs hidden in a 116,000-line codebase. A single agent caught between 14 and 27 per run. The dynamic workflow consistently hit 66. That's one internal benchmark on one task type, and Anthropic itself warns these runs can burn "a lot of tokens" and says to start small. It lands the same week an OpenAI Codex engineer called agent swarms a waste of tokens, so expect the argument to be settled by invoices, not blog posts.
For builders
Don't flip a whole pipeline over. Pick one task with a clear score, like your own seeded-bug count or a test suite pass rate, and run it three ways: one agent, 10 subagents, 50 subagents. Log tokens, wall-clock time and the score for each. Set a hard spend cap on the API key before the first fan-out run. If 10 gets you most of the way to 50, you've found your ceiling, and it's probably nowhere near 1,000.
Story IV
OpenAI's Decisions API returns probabilities, choices and scores instead of text, at $0.10 per million input tokens and nothing for output
OpenAI put its Decisions API into public beta. You send POST /v1/decisions with a model, some input (text or inline base64 images) and a list of named questions, each one a predicate that returns a probability, a choice from options you supply with per-option probabilities, or a score against ordered levels. The only model is gpt-6-luna. Per MarkTechPost's write-up of OpenAI's docs, pricing is $0.10 per million input tokens with no output or cache charges, and OpenAI claims it runs about 10x faster than the Responses API. US and EU residency, plus ZDR and HIPAA for eligible customers.
The caveats are real. It's beta, there's one model, and OpenAI hasn't published accuracy or calibration numbers; its own docs tell you to set thresholds from labeled examples. MarkTechPost also notes TypeSafe's Jev does the same job at $0.042 per million input tokens, though it's still in early access.
For builders
Find the call in your code where you prompt a model, then regex its text output into a label. Moderation flags, ticket routing and "is this a refund request" are the usual suspects. Pull 200 labeled examples, run them through Decisions as a choice or predicate, and pick your threshold from the probabilities instead of guessing. Compare cost and latency against what you run now. Keep the old path behind a flag until GA.
— The Vibe Gate news desk. We read the firehose so you can keep building.