← Writing
·4 min read

The Agent Grows a Rulebook

The Signal for August 5, 2026 — a court says users (not agents) do the shopping, Anaconda buys its way into agent security, and a stealth startup bets AI can deploy AI. An operator's read on the day.

The SignalAISecurity

Wednesday, and the throughline writes itself: the AI agent stopped being a demo and started being a party to real decisions — legal, operational, and financial. Today you get a court telling us who's actually "accessing" a website when a bot shops, a platform vendor bolting security onto agents by acquisition, and a fresh startup betting the hard part isn't the model but the deployment. Three items, one theme — agents are now consequential enough to need rules, guardrails, and someone to answer for them.

A court says the user shops, not the agent

Start with the ruling that quietly reshapes agentic commerce. The Ninth Circuit vacated the preliminary injunction that had barred Perplexity's Comet browser from operating on Amazon, finding Amazon unlikely to succeed on its Computer Fraud and Abuse Act claim. The reasoning is the part operators should read twice: the panel concluded it was the users — not Perplexity's agent — who "accessed" Amazon under the federal computer-hacking statute.

The operator's take: if you run a site or a storefront, the legal presumption just shifted toward letting agents through the front door on the user's behalf. That cuts both ways. If customers want to point a shopping or research agent at your service, "we'll sue the bot's maker" is a weaker play than it was last week — so your defenses need to live in your terms of service, your rate limits, and your bot-management layer, not in a hoped-for injunction. And if your own products send agents out to third-party sites, the exposure is increasingly yours as the user, so read the fine print before you automate at scale.

Anaconda buys its way into agent security

The security layer is consolidating to match. Anaconda acquired Enkrypt AI, a security and compliance platform that finds and mitigates risks hidden inside enterprise AI, folding red-teaming, runtime guardrails, and governance directly into its stack. Anaconda frames it as embedding security, governance, and compliance controls across the platform to help enterprises secure agents at scale — and it lands weeks after the company's July pickup of the Kilo Code agent, so the direction is clear: own the build and the guardrails in one place.

The operator's take: this is the build-vs-buy question showing up right where it hurts. Agent security — red-teaming, prompt-injection defense, policy enforcement — is genuinely hard to staff, and platform vendors know it, which is why they're acquiring it and bundling it. Bundling is convenient and it's also lock-in. Before you accept the packaged guardrails, make sure they're inspectable, exportable, and mapped to a control framework you already report against, so "secure by default" doesn't quietly become "secure only inside this vendor."

A startup bets AI can deploy AI

The money is chasing the least glamorous part of the stack. June AI emerged from stealth with $20 million in pre-seed funding led by Marc Benioff's TIME Ventures, with a roster of enterprise-software heavyweights — Michael Dell, Diane Greene, Aaron Levie, and CrowdStrike's George Kurtz — behind it. The pitch: AI still requires manual work to become enterprise-ready, and June wants the AI to handle the implementation and deployment itself.

The operator's take: they're aiming at the right target. Implementation — the integration, the data plumbing, the change management — is where most enterprise AL value goes to die, not the model. That said, $20 million in pre-seed and an all-star cap table is a bet on a thesis, not a shipped result. If a vendor tells you the AI will implement itself, ask what it does when it hits your legacy quirks and your access controls, and who owns the outcome when the autonomous deployment gets it wrong.

Also on my radar

The throughline for a Wednesday: the agent era grew a rulebook this week. A court sorted out who's liable when a bot acts, a platform vendor bought the guardrails, and the smart money went to the boring problem of actually getting agents into production. The capability question is settled; the accountability question is the one you now get paid to answer. That's the Signal for today.

Paul Sapio is the CIO of Mikhail Education and a full-stack AI engineer. Open to contract work in security, networking, AI, and SaaS development — reach out.