Monday, March 9, 2026

Radar Developments to Watch: March 2026 – O’Reilly

The explosion of curiosity in OpenClaw was one of many final gadgets added to the February 1 developments. In February, issues went loopy. We noticed a social community for brokers (no people allowed, although they undoubtedly sneak on); a multiplayer on-line sport for brokers (once more, no people); many clones of OpenClaw, most of which try and mitigate its many safety issues; and rather more. Andrej Karpathy has stated that OpenClaw is the following layer on prime of AI brokers. If the safety points could be resolved (which is an efficient query), he’s in all probability proper.

AI

  • Moonshine Notice Taker is a free and open supply voice transcription software for taking notes. It runs regionally: The mannequin runs in your {hardware} and no information is ever despatched to a server.
  • Nano Banana’s picture era was breathtakingly good. Google has now launched Nano Banana 2, a.okay.a. Gemini 3.1 Flash Picture, which guarantees Nano Banana picture high quality at pace.
  • Claude Distant Management lets you proceed a desktop Claude Code session from any machine.
  • Placing OpenClaw right into a sandbox isn’t sufficient. Protecting AI Brokers from by chance (or deliberately) doing injury is a permissions drawback.
  • Alibaba has launched a fleet of mid-size Qwen 3.5 fashions. Their theme is offering extra intelligence with much less computing cycles—one thing all of us want to understand. 
  • Necessary recommendation for agentic engineering: At all times begin by operating the exams.
  • Google has launched Lyria 3, a mannequin that generates 30-second musical clips from a verbal description. You may experiment with it by Gemini.
  • There’s a brand new protocol within the agentic stack. Twilio has launched the Agent-2-Human (A2H) protocol, which facilitates handoffs between brokers and people as they collaborate.
  • But increasingly mannequin releases: Claude Sonnet 4.6, adopted shortly by Gemini 3.1 Professional. In the event you care, Gemini 3.1 Professional at the moment tops the summary reasoning benchmarks.
  • Kimi Claw is one more variation on OpenClaw. Kimi Claw makes use of Moonshot AI’s most superior mannequin, Kimi K2.5 Pondering mannequin, and affords one-click setup in Moonshot’s cloud.
  • NanoClaw is one other OpenClaw-like AI-based private assistant that claims to be extra safety aware. It runs brokers in sandboxed Linux containers with restricted entry to exterior sources, limiting abuse. 
  • OpenAI has launched a analysis preview of GPT-5.3-Codex-Spark, a particularly quick coding mannequin that runs on Cerebras {hardware}. The corporate claims that it’s doable to collaborate with Codex in “actual time” as a result of it provides “near-instant” outcomes.
  • RAG is probably not the latest concept within the AI world, however text-based RAG is the idea for a lot of enterprise functions of AI. However most enterprise information contains graphs, pictures, and even textual content in codecs like PDF. Is that this the yr for multimodal RAG?
  • Z.ai has launched its newest mannequin, GLM-5. GLM-5 is an open supply “Opus-class” mannequin. It’s considerably smaller than Opus and different high-end fashions, although nonetheless large; the mixture-of-experts mannequin has 744B parameters, with 40B lively.
  • Waymo has created a World Mannequin to mannequin driving conduct. It’s able to constructing lifelike simulations of visitors patterns and conduct, primarily based on video collected from Waymo’s autos.
  • Recursive language fashions (RLMs) clear up the issue of context rot, which occurs when output from AI degrades as the dimensions of the context will increase. Drew Breunig has a superb clarification.
  • You’ve heard of Moltbook—and maybe your AI agent participates. Now there’s SpaceMolt—an enormous multiplayer on-line sport that’s completely for brokers. 
  • Anthropic and OpenAI concurrently launched Claude Opus 4.6 and GPT-5.3-Codex, each of which supply improved fashions for AI-assisted programming. Is that this “open warfare,” as AINews claims? You imply it hasn’t been open warfare before now?
  • In the event you’re excited by OpenClaw, you may strive NanoBot. It has 1% of OpenClaw’s code, written in order that it’s simple to grasp and preserve. No guarantees about safety—with all of those private AI assistants, watch out!
  • OpenAI has launched a desktop app for macOS alongside the strains of Claude Code. It’s one thing that’s been lacking from their lineup. Amongst different issues, it’s meant to assist programmers work with a number of brokers concurrently.
  • Pete Warden has put collectively an interactive information to speech embeddings for engineers, and printed it as a Colab pocket book.
  • Aperture is a brand new instrument from Tailscale for “offering visibility into coding agent utilization,” permitting organizations to grasp how AI is getting used and adopted. It’s at the moment in non-public beta.
  • OpenAI Prism is a free workspace for scientists to collaborate on analysis. Its aim is to assist scientists construct a brand new era of AI-based tooling. Prism is constructed on ChatGPT 5.2 and is open to anybody with a private ChatGPT account.

Programming

  • Anthropic is providing six months of Claude Max 20x free to open supply maintainers.
  • Pi is a quite simple however extensible coding agent that runs in your terminal.
  • Researchers at Anthropic have vibe-coded a C compiler utilizing a fleet of Claude brokers. The experiment price roughly $20,000 value of tokens, and produced 100,000 strains of Rust. They’re cautious to say that the compiler is way from manufacturing high quality—however it works. The experiment is a tour de drive demonstration of operating brokers in parallel. 
  • I by no means knew that macOS had a sandboxing instrument. It appears to be like helpful. (It’s additionally deprecated, however appears to be like a lot simpler to make use of than the options.)
  • GitHub now permits pull requests to be turned off utterly, or to be restricted to collaborators. They’re doing this to permit software program maintainers to remove AI-generated pull requests, that are overwhelming many builders.
  • After an open supply maintainer rejected a pull request generated by an AI agent, the agent printed a weblog put up attacking the maintainer. The maintainer responded with a superb evaluation, asking whether or not threats and intimidation are the way forward for AI.
  • As Simon Willison has written, the aim of programming isn’t to jot down code however to ship code that works. He’s created two instruments, Showboat and Rodney, that assist AI brokers demo their software program in order that the human authors can confirm that the software program works. 
  • Anil Sprint asks whether or not codeless programming, utilizing instruments like Gasoline City, is the longer term.

Safety

  • There’s now an app that alerts you when somebody within the neighborhood has good glasses.
  • Agentsh offers execution layer safety by implementing insurance policies to prevents brokers from doing injury. So far as brokers are involved, it’s a alternative for bash.
  • There’s a brand new sort of cyberattack: assaults towards time itself. Extra particularly, this implies assaults towards clocks and protocols for time synchronization. These could be devastating in manufacturing unit settings.
  • What AI Safety Analysis Appears Like When It Works” is a wonderful overview of the impression of AI on discovering vulnerabilities. AI generates loads of safety slop, however it additionally finds vital vulnerabilities that might have been opaque to people, together with 12 in OpenSSL.
  • Gamifying immediate injection—nicely, that’s new. HackMyClaw is a sport (?) during which contributors ship e-mail to Flu, an OpenClaw occasion. The aim is to drive Flu to answer with secrets and techniques.env, a file of “confidential” information. There’s a prize for the primary to succeed.
  • It was solely a matter of time: There’s now a cybercriminal who’s actively stealing secrets and techniques from OpenClaw customers. 
  • Deno’s safe sandbox may present a technique to run OpenClaw safely
  • IronClaw is a private AI assistant modeled after OpenClaw that guarantees higher safety. It all the time runs in a sandbox, by no means exposes credentials, has some defenses towards immediate injection, and solely makes requests to permitted hosts.
  • A pretend recruiting marketing campaign is hiding malware in programming challenges that candidates should full so as to apply. Finishing the problem requires putting in malicious dependencies which can be hosted on reputable repositories like npm and PyPI.
  • Google’s Risk Intelligence Group has launched its quarterly evaluation of adversarial AI use. Their evaluation contains distillation, or amassing the output of a frontier AI to coach one other AI.
  • Google has upgraded its instruments for eradicating private data and pictures, together with nonconsensual specific pictures, from its search outcomes. 
  • Tirith is a brand new instrument that hooks into the shell to dam unhealthy instructions. That is usually an issue with copy-and-paste instructions that use curl to pipe an archive into bash. It’s simple for a foul actor to create a malicious URL that’s indistinguishable from a reputable URL.
  • Claude Opus 4.6 has been used to find 500 0-day vulnerabilities in open supply code. Whereas many open supply maintainers have complained about AI slop, and that abuse isn’t more likely to cease, AI can also be changing into a invaluable instrument for safety work.
  • Two coding assistants for VS Code are malware that ship copies of all of the code to China. Not like plenty of malware, they do their job as coding assistants nicely, making it much less seemingly that victims will discover that one thing is flawed. 
  • Weird Bazaar is the identify for a wave of assaults towards LLM APIs, together with self-hosted LLMs. The assaults try and steal sources from LLM infrastructure, for functions together with cryptocurrency mining, information theft, and reselling LLM entry. 
  • The enterprise mannequin for ransomware has modified. Ransomware is now not about encrypting your information; it’s about utilizing stolen information for extortion. Small and mid-size companies are widespread targets. 

Internet

  • Cloudflare has a service referred to as Markdown for Brokers that converts web sites from HTML to Markdown when an agent accesses them. Conversion makes the pages friendlier to AI and considerably reduces the variety of tokens wanted to course of them.
  • WebMCP is a proposed API normal that enables net functions to develop into MCP servers. It’s at the moment accessible in early preview in Chrome.
  • Customers of Firefox 148 (which needs to be out by the point you learn this) will have the ability to choose out of all AI options.

Operations

  • Wireshark is a strong—and complicated—packet seize instrument. Babyshark is a textual content interface for Wireshark that gives an incredible quantity of knowledge with a a lot less complicated interface.
  • Microsoft is experimenting with utilizing lasers to etch information in glass as a type of long-term information storage.

Issues

  • You want a desk robotic. Why? As a result of it’s there. And enjoyable.
  • Do you wish to play Doom on a Lego brick? You may.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles