The Boardroom Brief Thursday, September 3, 2026 · Maverick Curated for the people in the room. All signal, no noise. Three minutes. Then back to the meeting. | CrowdStrike Can See Your Agents | In this brief CrowdStrike launched Falcon Guardian. It finds AI agents on the endpoint and ties a prompt to what the machine actually did. The AI gateway is still pre-beta. Anthropic shipped Claude Fable 5.1. Mythos stays trusted-access. Enterprise Frontier Safeguards land later this fall, not tonight. OpenAI says Astra meets its Critical cyber bar. Not out broadly. Monitors can stop a task. Boomi put an Agent Control Plane between agents and systems of record. MCP gateway, token caps, a person on high-risk writes. Orchestry put Microsoft 365 agents, the Power Platform under them, and the files they can read in one console. F5 wired AI Guardrails into MuleSoft Agent Fabric. Inline scan of prompts and completions. Generally available now. Kong made AI Gateway 2.0 generally available. One MCP front door. Unauthorized tools stay invisible at discovery. | | 1 | On 1 September CrowdStrike launched Falcon Guardian, the next version of Falcon AIDR. This is not Falcon IQ from this week's Fal.Con keynote. Guardian discovers known and unknown AI agents on Windows, macOS, and Linux endpoints. It fuses prompts, skill use, tool calls, MCP servers, and identity with Falcon endpoint telemetry, so a prompt can be tied to what the machine actually ran. You can say which supported agent types are allowed to operate. A native AI gateway is planned as a control point for model traffic. CrowdStrike says that gateway is pre-beta, with GA in Q4. Falcon Complete coverage for Guardian comes later this quarter. Do not lock CrowdStrike's "millions" in avoided SIEM cost. (CrowdStrike) | | 2 | On 1 September Anthropic released Claude Fable 5.1, generally available, and Claude Mythos 5.1. Same underlying model. Mythos keeps the extra cyber and biology access and is limited to trusted-access programs, currently a set of US organizations. Cache-read tokens dropped 75 percent, to $0.25 per million. Headline input and output stay $10 and $50 per million. Anthropic estimates typical bills fall about 25 percent, and highly agentic work up to about 45 percent. Those are Anthropic's estimates. Enterprise Frontier Safeguards store monitoring logs in the customer's S3, Azure Blob, or GCS under customer keys. Flags go to the customer. No Anthropic human review is required by default. EFS rolls out in phases later this fall. Eligible customers get zero data retention on Fable 5 and 5.1 until it is ready. Quotes on the launch page are partner testimonials. (Anthropic) | | 3 | On 1 September OpenAI said Astra meets the Critical cybersecurity threshold in its Preparedness Framework. First model it has put at that level. OpenAI says that with the right tools, Astra can find previously unknown flaws and develop exploits across many well-protected systems without a person guiding each step. It is not broadly released. OpenAI plans to make it available soon, with advanced cyber access limited at first to testers, then Daybreak Blue. Chain-of-thought monitors can stop a task. A perfect score on ExploitBench used Daybreak Blue access, not the default production config. Astra was not involved in the Hugging Face incident. (OpenAI) | | 4 | On 2 September Boomi announced an Agent Control Plane. Vendor-neutral, it sits between agents and systems of record such as Salesforce, SAP, Oracle, and Workday. An AI gateway, built on Boomi's Lunar.dev acquisition, is the enforcement layer: MCP gateway plus LLM gateway in the traffic path. High-risk transactional actions can be held for a person. Per-agent identity, rate limits, and token caps. It runs in public cloud, a customer VPC, or on-prem. Gartner's line that 40 percent of enterprises will demote agents by 2027 is Gartner's, quoted in a Boomi release. A $2.1 million Forrester figure sat in a paper Boomi commissioned. (Boomi) | | 5 | On 1 September Orchestry launched AI & Agents on its Microsoft 365 governance platform. One place for the agents on a tenant, the Power Platform they sit on, and the content they can read. Each agent gets a risk score with the findings behind it. An admin can delete an agent across sources and keep the record for audit. A scoped admin role lets security own agent risk without full tenant rights. It is rolling out on the Enterprise plan. AI readiness scoring across 13 signals is on all plans. Orchestry's story of 3,000 "anyone" links in a 20,000-site tenant is Orchestry's example. (PR Newswire) | | 6 | On 2 September F5 and MuleSoft said F5 AI Guardrails now sit inside Agent Fabric's Omni Gateway. The gateway sends LLM calls to the F5 Scan API and inspects inbound prompts and outbound completions before the model runs or the answer comes back. The pitch is prompt injection, jailbreaks, toxicity, off-limits topics, and PII at runtime, without a second proxy. Dual-deploy includes self-hosted Kubernetes and private VPC. F5 says it is generally available now, with a Dreamforce demo window 15-17 September. "Simplifying compliance" with the EU AI Act, GDPR, and HIPAA is F5's language, not a certification. (F5) | | 7 | On 1 September Kong made AI Gateway 2.0 generally available in Konnect. MCP Server Bundling puts many upstream MCP servers behind one Kong route and returns one tool catalog. Combined with MCP ACL, a caller only sees the tools it is allowed to run. Unauthorized tools are invisible at discovery, not only blocked later. A pricing catalog now tracks text, audio, image, video, and cache read/write. Identity Principals can key rate limits, cost, and route access, not only the old Consumer object. Native AWS SigV4 for Bedrock AgentCore. If you still run AI plugins on Kong Gateway 3.x, 3.14 remains LTS. 3.18 is when those plugins become opt-in. (Kong) |
| The Move CrowdStrike can now see agents on the laptop. F5, Boomi, and Kong all want to sit in the path between the agent and the model, or the system of record. This week, get one number from security: how many AI agents are running on managed endpoints. If they cannot produce it by Friday, the number is "we don't know." Then name the three agent types that are allowed to run. Everything else waits. Seven bullets. One move. |
| Maverick The Boardroom Brief theboardroombrief.news |
|