News
Everything New at ibl.ai
Articles and platform releases in one stream, newest first — what we published and what we shipped. Every release runs on infrastructure you control, because you own all the code and the data.
Recently
997 articles · 38 releasesLetting a K-12 AI Agent Run Code Without Letting Data Out
An AI tutor that can actually run a student's Python is worth far more than one that can only talk about it — but only if the district can say where that code ran and what it could reach. Agent sandboxes answer that with a Linux VM that starts with no network at all.
Why PII Redaction Breaks Enterprise AI — and What Fixes It
Redaction removes the relationships that made enterprise data worth training on. Transformation models keep them by swapping real identities for consistent synthetic ones — and runtime filtering catches the PII that arrives after training, in chat, in uploads, in screenshots.
Agent Sandboxes: A Real Linux VM, Locked to Hosts You Allow
ibl.ai agents can now run code in a full Linux virtual machine that has no network by default — opened only to the hosts an organization allowlists, with API secrets the agent can use but never read, and runtime billed per second.
Agentic Vibe 2.0: Build an AI App From Your Coding Agent
Agentic Vibe 2.0 turns Claude Code, OpenAI Codex or Cursor into an ibl.ai app builder: one install of 154 skills, four questions, and a working AI app with sign-in, an agent, users and admins, memory, analytics and billing — shippable to the web, desktop and mobile.
Analytics: What Every Model Costs, Down to the Call
The rebuilt ibl.ai analytics puts nine tabs behind one date range and agent picker — usage, users, topics, replayable transcripts, memory, audit trails, and a Cost tab that breaks AI spend down by provider, model, user and individual call, with p50 and p95 latency per model.
Charge for Your AI App on Your Own Stripe Account
Apps built on ibl.ai can now sell access on the organization's own Stripe account: the admin picks free, one-time or monthly, clicks Connect with Stripe, and members pay in Stripe's embedded checkout — no commission, no webhooks, and no platform key inside the app.
Code Mode From Your Phone: Pair It to Your Desktop
Code Mode, the coding agent in Agentic OS, now runs from a phone: scan a QR code on the desktop app, and the phone drives the same agent editing files, running commands and committing in a workspace on your own computer — with every change still approved or denied from the chat.
Platform Update — September 25, 2026
Ten services and packages moved in seven days — PII and PHI filtering now covers in-chat file uploads end to end, including image pixel redaction and PDF rebuild, every detection is recorded in a new read-only privacy-flags audit endpoint, and the CLI moves nginx to nginx.org 1.30.5 with per-service ModSecurity enforcement.
Who Audits the AI Writing Into the Nurse's Flowsheet?
Oracle Health made its Clinical AI Agent for nurses available in the US on September 14, 2026, for structured documentation at the bedside, in fields that sit outside FDA device oversight.
An Agent That Moves Money Needs Row-Level Permissions
AWS open-sourced TOLAP on 22 September 2026 under Apache-2.0: row filtering and column masking enforced inside agent tools, across three SDKs and fourteen framework integrations.
Whose Agents Run Your Operations? The Managed Agent War
Five vendors now sell managed enterprise agent platforms, from AWS Bedrock AgentCore in October 2025 to Google's Gemini Enterprise Agent Platform in April 2026. All of them operate the agents for you, and that is the whole buying decision.
Most University AI Work Is Judgment, Not Generation
At published September 2026 prices, a million classification decisions cost $12,500 on GPT-6 Astra, $125 on GPT-6 Luna and $42 on TypeSafe's Jev — so most of the 99% saving is model choice, not a new model class.
Agent Infrastructure Went Open Source. The Record Didn't.
Chutes and researchers at Harvard and Chicago released 6,122,413,756 production LLM requests across 9,174 models — in twelve metadata fields that hold no prompts, no responses and no tool calls.
The AI Intel Report That Nearly Triggered a Ship Raid
CNN reported on 18 September 2026 that a chatbot-written intelligence report put armed personnel and aircraft in motion against a Chinese cargo ship. Four anonymous sources; the real cargo was never established.
Open Weights Tied Grok 4.7. What That Does to Procurement
Xiaomi's MIT-licensed MiMo-V2.6-Pro scored 46 on Artificial Analysis's Intelligence Index on 22 September 2026 — the same score as Grok 4.7, released a day earlier. DeepSeek V5, meanwhile, has not shipped.
Distributing Your Agent Platform Changes What You Own
Pine Labs and Google Cloud announced Gemini-powered merchant agents on 24 September 2026, serving over 1 million merchants on ₹17.15 trillion of FY26 transaction value, and distribution is what changes the ownership question.
Four Frontier Models in a Day: The Real Cost Is Migration
Four frontier models shipped on September 22, 2026, and seven Claude models were retired during 2026. AWS puts one production model migration at two days to two weeks — the recurring cost is migration, not licensing.
DoWI 8430.01 Bans External AI Hosting, Not Just Training
DoW Instruction 8430.01, signed August 31 and effective September 8, 2026, bars non-public department information from any generative AI service that does not reside on department systems and is not approved — with a six-question buyer checklist keyed to the instruction's own clauses.
Hospitals Buy the Charting Bot, Not the Early Warning
Documentation AI sells because its benefit is visible on day one; sepsis early warning saves more lives but the saved death is a counterfactual. Medicare now pays up to $61.84 per eligible case for it.
105 Forward-Deployed Roles, 5 Sales Roles: AI's Last Mile
On September 21, 2026 the job boards of OpenAI, Anthropic and Palantir list 105 forward-deployed engineering roles against 5 in sales development — Palantir posts 77 while carrying about 70 salespeople.
YC Open-Sourced QM: The Harness Became Infrastructure
Y Combinator open-sourced QM on 31 July 2026 under an MIT license, and says it runs the harness internally across four departments — not across its portfolio. The substance is scoping.
Agent Memory Fails at State Transitions, Not Retrieval
On StateMemBench, released August 2026, leading agent memory systems answered with the current state only 13–20% of the time. The failure is not retrieval quality — nothing marks a fact as superseded.
Clinical AI Trials Outlive the Models They Evaluate
Claude Opus 4.1 was retired on 5 August 2026, a year after release, while a 2013 PLOS Medicine study of 600 trials found a median of 21 months from trial completion to publication — and only 19.4% of completed AI imaging trials publish at all.
NYT v. OpenAI Discovery and the Law Firm AI Checklist
The unsealed filings reported on September 17, 2026 in NYT v. OpenAI are about training data, not client files. The user-log question was decided earlier on the same docket: 20 million ChatGPT logs, affirmed January 5, 2026.
94% of the Mid-Market Uses GenAI. 2% Have Scaled It
Kaufman Rossin found 94% of mid-market companies use generative AI tools and 2% have AI embedded across the business — and in the same sample only 33% run integration or API management.
LLMs Can't Invent: What That 2024 Paper Means for Buyers
"Theory Is All You Need" is not new and not a proof: Felin and Holweg published it in Strategy Science 9(4), 346–371, in 2024, arguing that LLMs are backward-looking and imitative rather than originating.
Platform Update — September 18, 2026
Thirty-seven production releases in a week — the LLM model catalogue now auto-syncs behind a verification gate, credit is charged in real time with calls enforced against the balance, VM secrets let agents use credentials whose values never enter the sandbox, and the desktop app gains iOS and Android builds.
Backline Is a Control Plane, Not a Quantum Computer
Xanadu and AMD released Backline on September 10, 2026 under Apache 2.0. Its sub-3-microsecond figure is a 2.305 μs FPGA-to-CPU round trip over RoCE v2 — the GPU path is 4.5 μs, and the quantum side is simulated.
Beijing's AI Eye Clinic Hit 3.8% Clinician Adoption
A Nature Medicine Comment published 10 September 2026 reports that Beijing Tsinghua Changgung Hospital's AI-TEC agent clinic was used in 41 of 1,113 examinations — 3.8% — before workflow changes lifted it to 23%.
When Your Software Vendor Applies for a Bank Charter
Block applied on 8 September 2026 for an uninsured national trust bank that cannot take deposits or lend, and the OCC has taken 40 de novo charter applications in 18 months against 48 in the 14 years to 2024.
Generation Is Commoditized. Judgment Is the New Frontier
TypeSafe announced Jev on September 15, 2026 — a decision model priced at $0.042 per million input tokens with output unmetered. It is not the first model built to judge: CriticGPT and Prometheus 2 both shipped in 2024.
Claude Pulled From Sensitive Work for Two Unrelated Reasons
The DoD says 90% of classified AI workloads have moved off Anthropic — a first-quarter decision finishing this month. The new story is Nvidia, Palantir and Booz Allen restricting Claude over June 9 retention terms.
When Three Labs Pace the Frontier, Your Roadmap Slows
Dario Amodei published "We Must Pace the Frontier" on September 12, 2026 and Altman and Musk agreed within a day. He asks for slack rather than a halt, arguing a focused 1-2 year effort on interpretability and evaluation could close the gap; NIST measured open weights trailing by 8 months.
Spain Logged the First Breach Executed by an AI Agent
On 14 September 2026 Spain's AEPD published the first breach notification it has received in which the attack was executed through an AI agent — an attacker's agent, not a rogue corporate one.
Finance AI With No Audit Trail Is Evidence, Not Speed
Gartner reports 93% of audit leaders and auditors using AI, while a May 2026 poll found only 38% of chief audit executives have any AI strategy, and PCAOB AS 1105 makes an untraceable entry a rework bill.
Keep reading
Agentic AI Blog →
All 997 articles on agent architectures, LLM infrastructure, and what it costs to run AI you actually own.
Platform Updates →
All 38 releases across the applications, the infrastructure tooling, and the open source repositories behind them.
Combined RSS feed →
This same merged stream as RSS — the 50 most recent items, articles and releases together.
ibl.ai publishes two things: analysis of how agentic AI is actually deployed, and the release notes for the platform we build. This page merges both so you can see what changed without checking two archives. ibl.ai is family-owned and operated from New York, NY, and the platform is model-agnostic and self-hosted — run any LLM, on any cloud, in your VPC, on-premise, or fully air-gapped, and you own all the code and the data.