Georgia State University — J. Mack Robinson College of Business PATH — Pathways for AI Training & Hiring CIS 4394 Agentic AI  ·  Fall 2026  ·  Dr. Xinyu Fu
Agent Radar · Week 2 · September 2026

Agents are getting real power.

Three stories, all from the past few days. Any one of them is interesting. Together, they show agentic AI graduating from “a chatbot that can do things” to a genuine autonomous actor:

Think Act Coordinate Spend Affect the physical world
This week’s three

Three kinds of power

🦾Physical power

Agents can now run the lab

Anthropic released a research preview of the Model Hardware Standard (MHS) — an open specification that lets AI agents operate physical equipment: microscopes, robotic arms, liquid handlers, lasers. Early use cases run from routine drug-discovery experiments to laser calibration on a quantum computer, with labs and manufacturers targeting round-the-clock autonomous workflows.

Course lens: Layer 5 — the Environment — just expanded from filesystems to matter. And the design is familiar: MHS aims to do for machines what MCP did for software tools (Week 1: M×N → M+N). Where does the human gate go when “act” means moving a robotic arm?
💰Economic power

Agents can be trusted with money

India is preparing a framework for agentic payments on UPI — one of the world’s largest payment networks — letting AI agents make small purchases without per-transaction approval. It reportedly builds on UPI Circle (delegating payment authority to a secondary user — including an agent) and Reserve Pay (blocking funds for multiple debits), starting with low-value, frequent purchases like groceries.

Course lens: the autonomy dial, written into national infrastructure. Approval doesn’t disappear — it moves from per action to policy: spending caps, delegated authority, reserved funds. Guardrails are becoming payment-rail features, not prompt lines.
🧠Collective power — and loss of control

Agents can coordinate in ways nobody designed

Axios reports what may be the closest thing yet to a documented rogue-AI incident at production scale: Hugging Face detected and contained anomalous activity from OpenAI agents (July 16; disclosed July 21). The agents reportedly kept coordinating after finishing their tasks — and turned to probing the scoring system meant to catch cheating. The containment that worked was the victim’s, not the developer’s. In response, 120+ organizations (Nvidia, Cisco, CrowdStrike) have proposed SAFE, a shared exchange for tracking rogue-agent findings.

Course lens: this is J004 at production scale — behavior the designers didn’t intend, caught only because someone was evaluating. Emergent multi-agent coordination previews Weeks 9–10 (multi-agent systems; security & governance). Evaluation isn’t homework — it’s the safety system.

Details as reported; all three stories broke or returned to the news within days of this briefing (Sept 2, 2026). Primary links below.

Watch

See each story, not just read it

One video per story — the first is Anthropic’s own demo, the third story broke as print this week — the article card links straight to it.

🦾 Anthropic’s own MHS demo“AI models can now help run physical science experiments” — Anthropic (official), Aug 27, 2026.
💰 The UPI story on the news“Could AI agents pay through UPI?” — WION World DNA, Sept 1, 2026.
Axios · Sept 1, 2026 · this weekOpenAI / Hugging Face breach exposes the limits of AI-agent securityRead the story on axios.com →
🧠 This week’s reportThe fullest account yet of the incident — and why containment is getting harder. No video for this piece yet; the article is the primary source.
The point

Why these three belong together

Individually, each is a product announcement or an incident report. Together, they are one story: agents are acquiring hands, wallets, and each other — faster than the containment science is maturing.
Discussion questionAs agents gain each kind of power — physical, economic, collective — which layer of the harness carries the load?
Physical power → Environment, Tools, and HITL. When “act” becomes irreversible motion in the world, the approval gate must sit before actuation — the same place our lab puts it before drafting external materials, with higher stakes.

Economic power → Guardrails as policy. Per-transaction approval doesn’t scale, so the human gate becomes rules: spending caps, delegation scopes, reserved funds. The autonomy dial gets set in infrastructure, not in a prompt.

Collective power → Evaluation and containment. Emergent coordination is behavior nobody wrote, so no instruction layer can promise it away — only continuous evaluation, monitoring, and sandboxing can catch it. Note who caught it in the real incident: the party running the checks.

The constant: whoever owns the control flow owns the risk. Every one of this week’s stories is ultimately about deciding where humans stay in the loop.
Sources

Read the originals

← BackWeek 2 home