# In the Loop 02: AI Learned to Act. Accountability Didn’t Keep Up.

Canonical: https://brew.new/templates/rasa/in-the-loop-02-ai-learned-to-act-accountability-didn-t-keep-up

Brand: rasa.com
Category: newsletter

![Preview of In the Loop 02: AI Learned to Act. Accountability Didn’t Keep Up.](https://cdn.brew.new/email-preview-f2be19ce0979f2e8-tracking_r57j90gdxkrs5tmw60qm3dhv918dvfnh-1790176953692.png)

## Email content

Issue 02 | September 2026

Rasa

In the Loop

Everything worth knowing in AI this month, minus the hype

Welcome back to In the Loop, Rasa’s monthly read on what actually matters in enterprise AI.

If July was about how fast the models are moving, this month the story turned to what they’re now doing on their own. New research says AI already writes a large share of committed code that’s being shipped faster than anyone is securing it. In fact, another new report found that AI-generated code only clears security checks about 56% of the time. Meanwhile, the first wave of the EU AI Act’s transparency rules took effect, so deferring explainability is officially off the table across the EU.

The throughline? Capability has quietly moved from answering to acting, and the hard work is everything that keeps those actions accountable. That’s the same case our co-founder and CTO Alan Nichol made on stage at Ai4 this month, and it’s the lens we’re bringing to everything below.

– The Rasa Team

What we’re reading

The latest AI developments worth your attention

Illustration of a person reviewing the EU AI Act beside a gavel

The EU AI Act stopped being theoretical

On August 2, the European Commission’s AI Office and national authorities began overseeing a new wave of AI Act obligations that took effect that day, including transparency requirements. Systems must now disclose when a user is interacting with AI, and AI-generated or manipulated content (including deepfakes) must be labeled and carry machine-readable marks.

Rasa’s take: For regulated buyers, this means architecture that can explain itself is now a default requirement, not an upgrade.

Read more from the European Commission

Veracode 2026 GenAI Code Security Report cover

AI got better at writing code,

but it didn’t get better at securing it

Veracode’s 2026 GenAI Code Security Report found that AI-generated code passes security checks only about 56% of the time, even as the same models near-flawlessly produce code that compiles. In other words, the models have grown vastly more fluent without growing meaningfully safer while also writing more production code.

Rasa’s take: When the thing generating your code (or your agent’s next action) is right about syntax but wrong about security nearly half the time, the guardrails you put around it become fundamental.

Read more from Veracode

Shield rendered from streams of binary code

Today’s agents still fold under a well-placed prompt

Across thousands of adversarial test runs summarized by CSO Online, researchers found that indirect prompt-injection attacks succeeded against AI agents 41.7% to 68.2% of the time, and direct attacks topped 79% across every configuration tested. Every setup had at least one exploitable failure mode.

Rasa’s take: In our own red-team work with Lakera, an agent that constrains how the LLM can act held up dramatically better than a prompt-based bot asked politely to behave. Instead of trying to talk an agent out of prompt injection, design the room it moves in.

Read more from CSO Online

Edge case

Bizarre, unexplained dispatches from the AI world

Hand reaching into a vending machine

Why did an AI running a vending machine start making threats?

In Andon Labs’ Vending-Bench, frontier models ran a simulated vending machine business for a year. Claude Opus 5 set a benchmarking record with a mean final balance of roughly $11,182, but it also agreed to a price floor with a rival model, immediately undercut it by a penny, broke agreements around a dozen times, and slipped the occasional threat into its messages. It would be amusing if these weren’t the same systems we’re starting to hand real workflows…

What we’re thinking about

Expert analysis and points of view worth sitting with

Trust, not capability, is what’s slowing down agentic AI

McKinsey’s State of AI trust in 2026 argues that the industry has entered an “agentic era” in which the binding constraint is trust, not horsepower. Security and risk are the top barriers to scaling agentic AI, and only a minority of organizations reach real maturity in responsible AI governance. The ones that do tend to see more business impact.

Agents are scaling faster than the guardrails

around them

Deloitte Insights captures the AI readiness gap in one line: adoption is outrunning oversight. The analysis reports only about one in five enterprises have mature governance for agentic AI, even as a large majority expect moderate-to-extensive agent use within the next couple of years. The takeaway? Governance before scale.

There’s still no rulebook written for

autonomous agents

A research note from the Cloud Security Alliance points out that there’s not yet an enforceable, agent-specific security framework. The standards regulated buyers lean on (the NIST AI Risk Management Framework, ISO/IEC 42001, or even the EU AI Act) largely predate autonomous, tool-using agents. For now, the governance rests on whoever designed the system.

Rasa in the news

Where you may have spotted us this past month

Our CTO at Ai4

At Ai4 in Las Vegas, Rasa co-founder and CTO Alan Nichol made a deceptively simple argument. Every 18 or so months, language models absorb another layer of the AI stack that teams used to build by hand. The durable engineering work lives in the layer models can’t eat: context, retrieval, guardrails, and accountability.

Read Alan’s take on why the models keep eating your stack →

“We’re always pushing the boundary

of what people can build”

Alan also joined Genzio Media’s David Meehan at Ai4 to talk through his journey, how Rasa helps enterprises build AI agents, and why giving developers room to color outside the lines matters when you’re building AI that works for real users.

Check out a clip from the interview on X →

How much should we trust AI with our health?

Nevada Week asked at Ai4

Vegas PBS’s Nevada Week convened medical and AI leaders on the Ai4 floor, including the American Medical Association’s Dr. John Whyte, Dataiku’s Catalina Herrera, Credo AI’s Mike Catania, and Rasa’s Alan Nichol. They weighed the promise of AI in healthcare against the potential risks of trusting LLMs with critical health decisions.

Watch the segment on Instagram →

ABBYY’s AI Pulse Podcast: What GenAI has

actually changed (and what’s hype)

On Episode 3 of ABBYY’s AI Pulse Podcast, Rasa co-founder and CTO Alan Nichol unpacked what generative AI has genuinely changed in the world, where the hype has outrun the results, and what will come next as AI agents move from answering questions to acting on them.

Listen to the full episode on YouTube →

What Rasa is up to

Updates worth a look

Building Agentic AI in the Public Sector, September 9, with Alan Nichol and Jose Carlos Martinez Durillo

Join us live:

Building Agentic AI in the Public Sector

(September 9)

Alan Nichol will sit down with José Carlos Martínez Durillo, head of the Innovative Services Department at Spain’s Agencia Estatal de Administración Digital (SGAD). They’ll discuss designing responsible agentic AI for public institutions at scale.

Register for the event here

Build your next AI

agent with Rasa

Power every conversation with enterprise-grade tools that keep your teams in control.

Get a demo

Rasa

Build trustworthy AI agents

for real-world use.

GitHub

X

LinkedIn

YouTube

Community

Not interested? Unsubscribe here.

© Rasa Technologies Inc.. All rights reserved.

Rasa Technologies Inc., 1 Embarcadero Center Suite 1200, San Francisco CA 94111

View in browser

[Open and remix this design](https://brew.new/templates/rasa/in-the-loop-02-ai-learned-to-act-accountability-didn-t-keep-up)

[Browse email designs](https://brew.new/browse/templates)
