Archive 20.07.2026

Page 4 of 8
1 2 3 4 5 6 8

Interactive world simulator for robot policy training and evaluation


Imagine you want to teach a robot to push an object on a table. The standard recipe in robot learning is to collect hundreds of expert demonstrations on a real robot, train an imitation learning policy on that data, and then evaluate the policy by running it many times on the same real robot. Both stages (data collection and evaluation) are slow, expensive, and hard to reproduce: hardware breaks, lighting changes, objects drift out of place, and every new task means more hours in the lab.

A natural question is whether we can replace some of this real-robot work with a simulator. Classical physics-based simulators are powerful, but building one for a new task means manually modeling geometries, contacts, friction, and deformation, and the resulting simulator often still does not match reality closely enough for policies trained inside it to transfer.

In our work, we take a different route. We build an Interactive World Simulator: a learned, action-conditioned video prediction model that, given the current image and a sequence of robot actions, predicts the next frames purely in pixel space, with no physics engine inside. You can plug in a teleoperation device and control the robot through this learned world model for more than 10 minutes at 15 FPS on a single RTX 4090, and the predicted video stays stable and physically plausible.

The key idea is that, if the simulator is faithful enough, we could unlock two long-standing bottlenecks in robot learning:

– Data generation for training becomes cheap, because we can collect demonstrations inside the simulator.
– Policy evaluation becomes scalable and reproducible, because we can roll many policies through the simulator under identical conditions.

What the world simulator can do
We trained our world simulator on four manipulation tasks that span very different physical regimes: T pushing (rigid-body contact), rope routing (deformable–rigid interaction with a clip), mug grasping (fine-grained gripper dynamics), and pile sweeping (manipulating piles of objects). All four behaviors are learned from interaction data alone, with no physics priors hard-coded.

A few examples of what the model captures:

Rope routing: it correctly distinguishes between the rope actually being inserted into the clip and the rope swinging past it without making contact. Crucially, it does not bias toward either outcome — it follows what the actions imply.

Mug grasping: it captures fine-grained effects such as the mug slipping out of the gripper, or the handle being nudged and rotated.

Pile sweeping: it can generate video for multiple viewpoints consistently

You can try this directly on our project page: just open a browser and play with it using your keyboard!

How we built the interactive world simulator

At a high level, Interactive World Simulator is trained in two stages. First, we trained an autoencoder that compresses RGB images into compact 2D latent representations and reconstructs them back into images. This lets the model reason in a lower-dimensional space while still producing high-fidelity pixel-level outputs.

Second, we froze this autoencoder and trained an action-conditioned dynamics model in the latent space. Given past visual latents and robot actions, the model predicts the next latent state, which is then decoded back into an image. At inference time, this process is repeated autoregressively: predicted frames become part of the context for predicting future frames. Because prediction happens in latent space and uses consistency models, the simulator can run interactively while remaining stable over long horizons.

How is it different from prior works?

This differs from several existing approaches to robot simulation and world modeling. Classical physics simulators can be powerful, but they often require manually specifying object geometry, contact dynamics, friction, and deformation, and the resulting simulation may still have a large sim-to-real gap. Recent video-generation and world-model methods offer a more data-driven alternative, but many are either not explicitly conditioned on robot actions, too slow for real-time interaction, closed-source, or unstable under long-horizon rollouts.

In contrast, our Interactive World Simulator is action-conditioned, produces physically accurate pixel-level predictions, and supports stable interactions for more than 10 minutes at 15 FPS on a single consumer RTX 4090 GPU. This makes it practical not only as a visual prediction model, but as an interactive engine for collecting policy-training data and evaluating robot policies reproducibly. It has multiple applications.

Application 1: scalable data generation

If our simulator is good enough, can demonstrations collected using this world model actually replace real demonstrations for training imitation learning policies?

To answer this, we collected demonstrations entirely inside our world simulator and then trained imitation learning policies on 0% real-world data and 100% generated data. We deployed the trained policies directly on the real robot. The deployed policies do not just complete the tasks. They remain robust under continuous human perturbations. This demonstrates that the generated data quality is comparable to real data.

Application 2: faithful policy evaluation

Evaluating a robot policy in the real world is hard: you need to reset the scene, rerun the policy many times, and compare across checkpoints under matched conditions. In practice, this is not scalable and reproducible.

In contrast, we could roll out policies in our world model for reproducible evaluation. We evaluated the same four policies (DP, ACT, π0, π0.5) inside the simulator and on the real robot, with the same initial configurations. Each point in our evaluation is a policy checkpoint, scored in both real world and world model. We observe a strong correlation between the two scores, across tasks and across policies. Qualitatively, good policies that succeed in the simulator also succeed on the real robot, and bad policies that fail in the simulator also fail on the real robot.

Looking forward

Action-conditioned video prediction has long shown great potential for robotics, but existing approaches have been either too slow for interactive use or too brittle under long-horizon inference. By addressing both of these — stability and computational efficiency — the Interactive World Simulator becomes a practical engine for two things at once: training imitation policies on simulator-generated data that perform comparably to those trained on real-world demonstrations, and evaluating policies in a way that closely tracks real-world performance.

Going forward, we will extend the framework to more diverse environments and increasingly complex manipulation tasks, to further unlock the potential of large-scale robotic data. An important direction for future work is to study how the performance of world models scales with increasing amounts of interaction data and computational resources. Understanding these scaling behaviors could guide the design of larger and more capable world models for robotics.

License and Registration?

Increasingly, White House Calls Shots on AI You Get to Use

As bleeding edge AI gets ever more adept at finding security vulnerabilities in everyday software, the White House is playing a decisive role in when you actually get to use that AI.

Cases in point: The makers of ChatGPT and Claude both deferred to the U.S. government to decide when the latest versions of their AI would get a green light for distribution to the general public.

Observes writer Samantha Subin: “Last month the Trump administration blocked Claude Mythos 5 and Fable 5 due to ‘national security concerns,’ reinstating access after weeks of intense negotiations with Anthropic. (And) OpenAI last month said it would limit new AI models to ‘trusted partners’ to comply with government requests.”

In other news and analysis on AI writing:

*Anthropic to K-12 Teachers: C’mon and Take a Free Ride: The maker of ChatGPT competitor Claude is granting K-12 teachers in the U.S. free access to the AI.

Observes writer Zac Hall: “Claude for Teachers includes access to both Claude Cowork and Claude Code — giving educators access to the latest AI technologies from Anthropic.

“The company also recently published a fluency guide for educators interested in using AI in the classroom.”

*China’s New Free AI Nearly as Good as ChatGPT et al: Consumers smarting from what they see as pricey rates for U.S.-created AI can now use a Chinese alternative, which can be downloaded and used for free – provided you have the computing power to run it.

Observes lead writer Meaghan Tobin: “Moonshot said that the model, Kimi K3, was the world’s largest open-source AI system, allowing anyone to use, modify and build on it freely.

“According to benchmarks run by Vals AI, an independent company that evaluates the performance of AI models, Kimi K3 performs just below Anthropic’s Fable 5 model while outperforming OpenAI’s flagship GPT-5.6 Sol model.”

Both Fable 5 and GPT-5.6 Sol are currently the very best that AI Anthropic and OpenAI have to offer.

*AI Email Provider Superhuman Upgrading Its AI Replies: While the pursuit of the perfect AI email reply continues, Superhuman is apparently getting closer to that ideal, according to writer Ivan Mehta.

Observes Mehta: “In the last few days, after gaining access to the beta, I have sent emails with little-to-no-editing for some generated drafts.”

The in-development upgrade is designed to learn from how you use the auto-reply feature – and ideally, get better at drafting reply emails for you.

*Microsoft Pushing Its Own AI Over More Established Competitors: While the Microsoft ecosystem offers access to a number of AI engines, the company has decided to push its own, in-house developed AI over alternatives like ChatGPT and Claude.

Microsoft’s pitch: Our AI is more efficient and less expensive than ChatGPT and Claude – a claim that engenders skepticism among many experienced users.

*Study: AI Agents Still Unreliable: Despite the relentless hoopla over AI agents, a stubborn fact remains: They don’t work very well.

For example, a new Cisco study finds that while 85% of enterprises are developing AI agents, only 5% of those businesses are actually using those AI agents in day-to-day operations.

Observes writer Michael Nunez: “For enterprises stuck in pilot purgatory, the path forward starts with a mindset shift: Stop asking whether your agent can do something impressive once, and start asking whether it can do it correctly a thousand times in a row.”

*Great News for Consumers: Some AI Titans in Price War: The makers of ChatGPT, Grok and Muse Spark are in a price-slashing free-for-all – which hopefully will spell cheaper AI costs for all consumers down the line.

Observes lead writer Lorelei Smillie: “The rhetoric is notably different from a year or so ago, when OpenAI executives were publicly musing about one day charging thousands of dollars for monthly subscriptions to top-tier AI models to better reflect the growing value they provide to businesses.”

*Novelist: ChatGPT is Silencing a Generation of Students: Not one to mince words, novelist Dave Eggers believes the advent of ChatGPT will end-up discouraging a generation of students from writing.

Observes writer Vincent Lautier: “Providing ready-made prose at the click of a button eliminates, in his view, the very concept of thinking for yourself and finding your own voice.”

As for ChatGPT’s impact on teachers, in Eggers’ view:
“ChatGPT’s effect on teachers’ lives is nothing short of ‘catastrophic,’ because the tool now makes it impossible to know whether an essay was written by a student or spat-out by a machine,” according to Lautier.

*ChatGPT’s Maker Reportedly Developing Portable, AI-Powered Speaker/Companion: OpenAI is apparently working on a kind of ChatGPT-powered speaker you can tote around – which also learns about you over time by monitoring your emails and other digital interactions.

Like ChatGPT, the in-development portable speaker has a personality and is being designed to feel like a companion, according to writer Barry Elad.

*ABC News: All-in On AI Writing: In a remarkable move, ABC News has issued AI writing tools to staff, which they’ll be using to author articles based on ABC News radio bulletins.

Observes writer Cam Wilson: “The broadcaster says AI will assist staff and not supplant editorial decision-making — but the union representing journalists says management refused to commit to a provision that AI would not replace workers.”

Unthinkable just four years ago, ABC’s decision to unabashedly embrace AI news writing is a watershed moment in the integration of AI and journalism.

Share a Link:  Please consider sharing a link to https://RobotWritersAI.com from your blog, social media post, publication or emails. More links leading to RobotWritersAI.com helps everyone interested in AI-generated writing.

Joe Dysart is editor of RobotWritersAI.com and a tech journalist with 20+ years experience. His work has appeared in 150+ publications, including The New York Times and the Financial Times of London.

Never Miss An Issue
Join our newsletter to be instantly updated when the latest issue of Robot Writers AI publishes
We respect your privacy. Unsubscribe at any time -- we abhor spam as much as you do.

The post License and Registration? appeared first on Robot Writers AI.

New AI blood test predicts heart disease 15 years early

A new AI-powered blood test could give people a remarkably early warning of serious heart and circulation problems. Developed by researchers at the University of Hong Kong, CardiOmicScore analyzes thousands of proteins and metabolites to estimate the risk of six major cardiovascular diseases, including heart attack, stroke, heart failure, and atrial fibrillation. Unlike genetic risk scores, which remain fixed throughout life, the system captures biological changes linked to a person’s current health, lifestyle, and environment.

Artificial Intelligence (AI) In Cybersecurity

Artificial Intelligence (AI) In Cybersecurity: Applications, Future, and Real Examples

AI In Cybersecurity

Cyberattacks are big threats to information systems, organizational infrastructure, and connecting networks. Since the processes and workflows have transformed into digital, Information Technology, banking and financial, healthcare and other industries are often susceptible to data thefts or cyberattacks. Identifying malicious viruses and protecting data assets is the primary task of companies in this virtual world.

Adoption and implementation of Artificial Intelligence in cybersecurity is the perfect solution to overcome the risks like data leaks and network security attacks.

How Is AI Used In Cybersecurity?

Artificial Intelligence in Cybersecurity is not a new topic, it has been used for many years. Cybersecurity is one of the most significant applications of AI. The role of AI in cybersecurity is to reduce data risks and refine the security levels of an organization.

In this digital age, AI-based cybersecurity solutions will help organizations and individuals stay ahead of malware attacks. AI solutions in cybersecurity will analyze enormous data sets, detect irregular patterns, and predict the possibility of data risks. Hence, leveraging the power of intelligent AI software solutions for cybersecurity, the companies can augment the security processes and blocks cyber activities.

The use of AI for cybersecurity, along with Machine Learning (ML), deep learning, and predictive analytics, will add value to your security processes as it determines the probability of attacks and prevents unauthorized access to information systems or networks.

One more interesting thing is that the entire bug detection and insights delivery will be done automatically without once interaction within fraction of minutes. It will drastically reduce response times and improve security levels across the processes.

Though AI technology can be used in many ways, here we have listed the best AI applications in cybersecurity.

5 Best Applications of AI In Cybersecurity

  1. AI In Cybersecurity for Anomaly Detection

Using Artificial Intelligence in cybersecurity, organizations can automatically detect abnormalities, such as undefined network access, suspicious user behavior, multiple systems unlocking attempts, etc.

Leveraging ML and deep learning techniques, AI solutions in cybersecurity will assist organizations in automatically identifying vulnerabilities, analyzing user behaviors, and triggering alerts on malware attacks.

  1. AI For Cybersecurity Network Security

It is one of the popular AI Applications in Cybersecurity. AI-powered cybersecurity solutions will continuously monitor the company’s network infrastructure and block access if they are considered suspicious.

This is why the popularity of AI-powered threat detection and response applications has increased in the IT, FinTech, Banking, and Healthcare industries. They help companies stay safe from sudden network breakdowns and productivity.

Get an app quote for AI App Development!

[contact-form-7]
  1. AI for Cybersecurity For Spam Filtering

AI-based cybersecurity applications will detect spam mail and prevent its reach to your mail inbox. Learning from previous experiences, Artificial Intelligence tools will recognize fraudulent emails and protects users’ accounts from malicious malware.

  1. AI In Cybersecurity For Defense

Here is another significant benefit of using AI for cyber defense. A blend of AI, ML, deep learning, predictive analytics, and data analytics capabilities will ensure incredible performance in forecasting terrorist threats.

AI-powered systems and self-configuring applications will find software bugs and execute an immediate response to vulnerable incidents automatically. This potential application of AI is gaining popularity in the Defense sector for safeguarding systems and applications from opponents.

  1. AI In Cybersecurity For File Protection

Ransomware is risky software that blocks the user’s access to their systems or documents. AI technologies will play a key role in preventing illegal entry into your systems. Hence, AI decision intelligence tools track the patterns of users, predict frauds based on irregular behaviors of users, and protect personal systems from attacks.

These are the top five AI use cases in cybersecurity. AI-based tools, applications, and systems can identify threats, prioritize, and solve complex security issues automatically.

From small to mid-size companies to multinational organizations that serve across government and private must invest in AI technologies to secure their information assets from hackers and firewall their brand value in this virtual environment.

 

How Will AI Impact Cybersecurity In The Future?

Artificial Intelligence will transforms human lives. The impact of AI in cybersecurity will anticipated to grow with profitable results. AI solutions analyzes patterns and detects malicious hidden threats faster in seconds. Hence, the future of AI in cybersecurity will automate the time-consuming tasks and reduce the need of cybersecurity professionals.

The analysts from one of the global largest technology conglomerates like IBM are estimating that a single data breach will leads to million dollar business loss for companies in the coming years.

However, compared to 2021, the average cost of a data breach has reached to USD 4.35 million in 2022, up by 2.6% from the previous year. Hence, deployment of AI security tools is the best cost-mitigating approach for organizations to ensure security to their systems or assets.

On the other side, Statista-like world’s most popular database companies says that artificial intelligence (AI) will be widely used for protecting sensitive information systems against phishing attacks and ransomware attacks in the future. Such market trend will derive more value to the AI in cybersecurity and anticipated to generate USD 46.3 billion dollar business by 2027. Take a look at the market growth of AI in cybersecurity:

market-growth-of-AI-in-cybersecurity

 

The above figure depicts the market growth of AI in cybersecurity. From USD 10 billion in 2020, the size of AI is forecasted to increase to nearly USD 46 billion by 2027.

Hire #AI app developers and build potential AI-enabled solutions that ensure high-level security and retain your business assets safe from cyber-attacks!

 

Conclusion

It has been proved that AI tools are the greatest assets for cybersecurity. Data breaches, malware attacks, system or file crashes, network leaks, password hacking bots, everything can be prevented by integrating AI technologies into your systems. Hence, invest in AI development and protect before hackers damage systems and triggers security alerts.

Get in Touch!

[contact-form-7]

AGIBOT X2 Series Showcases Embodied AI at the World Cup, Marking a Historic Sports Companion Debut

This marks the first time an embodied AI humanoid robot has served as a full-scenario companion at a World Cup, signaling embodied AI's expansion from industrial and laboratory settings into one of the world's most celebrated sporting stages.

A new robotic hand capable of switching between multiple grippers using a single motor

For robots to be used in various settings, such as factories, logistics, service industries and households, they must be able to stably handle a diverse range of objects differing in shape, size, weight and rigidity. However, conventional robotic hands often require multiple motors and complex control systems, presenting challenges in terms of weight, cost, failure risk and control difficulties.

The Manufacturing Skills Gap Starts in The Classroom – Engineering Professor Claims

Deloitte reports that over 2 million jobs could go unfilled in the manufacturing space, due to a shortage of skilled workers. Now really is the time for industry experts and educators to come together and work together on closing the skills gap in higher education.

Undergrads’ weed-killing robot wins top prize

Andrew James (from left), Neil Morrison, Natalia Kurz and Michael Neiss work on a prototype of their weed-killing robot ahead of The Farm Robotics Challenge, which they won on May 21.

By Holly Hartigan

A team of Cornell undergraduates beat 95 other teams to take the grand prize at The Farm Robotics Challenge with their invention: an autonomous robot that kills weeds with electricity.

Their robot can travel through a vineyard or orchard without a human operator, zapping weeds with a small amount of electricity, saving labor and energy and preventing crop loss, without the use of herbicides.

Led by Andrew James, an agricultural sciences major in the College of Agriculture and Life Sciences (CALS), the team of agricultural specialists and engineers studied the existing electrical weeding technology, developed their own low-energy system and built a working prototype over the course of four intense months.

Natalia Kurz, a biological engineering major in CALS, said the project required a lot of late nights. “There were fears for us, like, was it just going to be for nothing?”

Now, James and his co-founders are using the $50,000 grand prize to form a company – Rootline Robotics – to continue working on the robot. Agricultural technology firm Reservoir sponsored the award and will host the startup at its incubator in Sonoma, California.

“I’ve always been interested in building a startup within the ag-robotics space,” James said. “So after winning this competition and seeing all the amazing support from so many different industry stakeholders in this really exciting collaboration, it makes a lot of sense to keep going.”

The problem of weeds

Weeds are a huge challenge in orchards and vineyards because they steal water and nutrients, especially in the spring, according to Steve Selin, owner of South Hill Cider in Ithaca.

“The weed pressure is very strong, and the grasses grow right up to the trees because we can’t afford to weed whack or mulch them as much as we would like to in order to control them,” he said. “If the trees get really stressed out, they’ll just drop the fruit.”

To control weeds, organic growers typically employ string trimming, mowing and mulching, which are all very labor intensive. Existing electric weeders require an operator, consume a lot of energy and cost $150,000, on average, which is out of reach for most growers, James said.

Selin provided feedback to the students as they developed their robot and said he is excited to try out Rootline’s new technology.

“In May and June, if you could do something to knock the weeds back enough that they’re not going to compete with the trees, then the rest of the year you wouldn’t have to worry about it,” he said. “You can let them come back and have positive impacts, like shading the soil, which would help the soil microbes to have a healthier ecosystem.”

The interdisciplinary nature of robots

“Robotics is many different systems in one,” Kurz said. “It is interdisciplinary by definition.”

Next, the Rootline team will work on improving its technology and validating it with growers before bringing it to market, all while Kurz and Neiss finish their degrees.

Neiss said the way the team came together felt a bit like destiny.

“If you have many different minds in one room that gives you the ability to reach solutions that are going to be the most feasible and effective,” he said.

DataRobot OpenCode: your coding agent, your model choice

DataRobot OpenCode: your coding agent, your model choice

There are over 70 coding agents on the market: Claude Code, Codex, Cursor, Copilot, Devin, and a long tail of smaller entrants showing up in engineers’ newsfeeds every week. Someone runs a benchmark, posts the leaderboard, and by the end of the week, half the org wants to try whatever is in first place. The pace behind that impulse is real: these tools are improving every few weeks.

The problem is what “trying a new model” actually costs. Claude Code only runs Anthropic’s models. Codex only runs OpenAI’s. Pick one and you’re locked into the model provider that comes with it.

If you want to try a different model, such as something open-weight and less expensive for a given task, you’re not just changing a setting. You’re switching the whole tool. Chasing a model, price point, or benchmark means adopting a new coding agent, and a new vendor.

In organizations, that’s where the review shows up. Every new coding agent presents the same three questions:

  • Does it train on your code by default?
  • Where does inference physically run?
  • Is pricing per seat or per token?

The answers change tool to tool, but the review itself is nearly identical every time, and legal, security, and finance end up doing it from scratch each time.

To bridge this gap, DataRobot OpenCode delivers a state-of-the-art coding agent that supports model choice across closed, open, and bring-your-own options, all while maintaining rigorous governance.

Getting started only takes a few minutes.

How DataRobot OpenCode works

DataRobot OpenCode runs on the DataRobot LLM Gateway, the same governed entry point already used for every model on the platform, so the agent inherits that governance instead of routing around it.

All of it sits behind one already-approved key. Switching from a closed frontier model to an open-weight one for a cost-sensitive task is a config change, not a new vendor relationship.

DataRobot agent skills, including Agent Assist, come preinstalled, so OpenCode is enterprise-ready on day one, not just model-flexible. That’s the same skills layer DataRobot ships for Cursor, Claude Code, and Gemini, applied here to an agent that isn’t tied to any single vendor’s models.

Installation is three commands from the DataRobot CLI. No separate API key to request, no model configuration to write by hand.

You can install and launch OpenCode in your terminal or run it from the DataRobot UI:

brew install datarobot-oss/taps/dr-cli
# installs the DataRobot CLI in your terminal; not needed inside the DataRobot UI

dr plugin install opencode
# installs the OpenCode plugin

dr opencode
# launches OpenCode, already wired to the Gateway with DataRobot skills

Pick a model from the LLM Gateway via:

/models

Then, launch Agent Assist to use natural language to design, test, build, and deploy production-grade agents:

dr assist

Try it

Get started today. Run the following commands in your terminal:

brew install datarobot-oss/taps/dr-cli
dr plugin install opencode
dr opencode

The post DataRobot OpenCode: your coding agent, your model choice appeared first on DataRobot.

Delegation chains, the confused deputy, and the protocols you actually deploy

Delegation chains, the confused deputy, and the protocols you actually deploy

Agents rarely act alone. A user asks an agent to do something. The agent calls a tool. The tool calls another agent. By the time work gets done, three or four actors have touched the request, each acting on behalf of the one before it.

Identity has to survive that chain. At every hop, you need to answer two questions, not one. Who originally requested this? And which actor is making this specific call? Lose either answer and you lose the ability to authorize the call correctly or explain it afterward.

Two claims carry the whole chain

The standards already model this. RFC 8693 defines token exchange: an actor trades the token it received for a new one to make the next call, without discarding who came before. The token carries two claims that matter here.

The sub claim is the subject, the original principal. It is the user who started the whole thing, and it does not change as the request moves down the chain.

The act claim is the actor, the party making the current call. It does change. And when one agent calls another, act nests: Agent B acting on behalf of Agent A acting on behalf of the user. Nested act is the only honest way to represent a multi-hop chain, because it keeps every link instead of collapsing them.

Top: the chain preserved. Bottom: the chain flattened into a re-minted token; the original principal is gone and downstream over-grants.
Figure 1. Top: the chain preserved. sub stays the user, act nests at each hop, and you can inspect every link. Bottom: the chain flattened into a re-minted token. The original principal is gone and downstream over-grants.

The failure mode has a name

The shortcut is to flatten the chain. Instead of exchanging tokens and nesting act, an agent re-mints a fresh token that says, in effect, “this is me, calling on my own behalf.” It is simpler. It also destroys the chain.

Now sub points at the agent, not the user. The original principal is gone. Attribution is gone with it: the downstream tool sees the agent and has no idea whose request set this in motion. And because the tool only sees the agent’s identity, it authorizes against the agent’s permissions, which are broader than what this specific task should allow. You over-grant on every downstream call.

This is the confused deputy: a process acting with authority that was granted to someone else, used for a purpose the grantor never intended. The flattened token is how the confused deputy gets created in an agent system. The preserved chain is how you avoid it. The difference is whether you can still inspect, at the tool, who asked and who is acting.

Where the chain lives or dies in practice

This is not only a standards story. The chain is preserved or destroyed at two protocol surfaces the primary audience is deploying right now.

Agent to tool runs over the Model Context Protocol (MCP). The mid-2025 MCP spec adopted OAuth 2.1 and RFC 9728 protected-resource metadata. That matters because it lets an agent discover what authorization a tool requires instead of hardcoding it. The agent reads the resource’s metadata, learns where to get a token and what scope it needs, and asks for exactly that. Discovery is what makes scoped, per-tool authorization practical at runtime.

Now the deployed reality, because the spec is not the same as what is running. A large share of MCP servers in the wild ship with weak or absent authorization. The protocol supports doing this correctly. Many deployments do not. That gap is the entire subject of this series: the standards exist, and the systems built on top of them skip the parts that protect the chain.

Agent to agent runs over A2A and its Agent Cards. An Agent Card is a discoverable declaration of what an agent is, what it can do, and which authentication schemes it accepts. It is how one agent learns how to call another without a human wiring the two together in advance. The card is also where an agent advertises whether it expects a delegated token or will happily take anything. Read the cards in your ecosystem. They tell you where the chain is respected and where it is about to be flattened.

These two surfaces, MCP and A2A, are the concrete places the delegation chain is either inspectable end to end or quietly collapsed into a token that lies about who is acting.

MCP carries agent-to-tool calls and A2A carries agent-to-agent calls. These are the two surfaces where the delegation chain is preserved or destroyed.
Figure 2. MCP carries agent-to-tool calls and A2A carries agent-to-agent calls. These are the two surfaces where the delegation chain is preserved or destroyed in practice.

The take-away

Delegation is not a token handed down the line. It is a chain, and a healthy chain is one you can inspect at every hop: sub fixed on the original principal, act nested through every actor that touched the request. Flatten it and you have built a confused deputy that over-grants and cannot be audited.

In your own systems, the chain is preserved or lost at MCP and A2A. Check two things. Do your agents exchange and nest tokens, or re-mint flat ones? And do the MCP servers and Agent Cards in your ecosystem actually require delegated authorization, or do they accept whatever shows up?

You can now describe an agent, give it an identity, and carry that identity through a chain of calls. The next question is where the rules for all of this live. Who decides what an agent is allowed to do, and what happens the moment an agent has to act somewhere its own platform does not reach? That is the next post.

The post Delegation chains, the confused deputy, and the protocols you actually deploy appeared first on DataRobot.

Engineers develop robot that judges its surroundings and walks, runs, and jumps like an animal

An era in which robots decide "how to walk" on their own has arrived. A four-legged robot has been developed that, much like a person or an animal, autonomously chooses the appropriate gait strategy for its surroundings—changing its gait on stairs, leaping over gaps and keeping its balance on forest trails.

Navigating How the Rapid Enterprise Push Toward Localized AI Mandates a Radical Shift in Cloud Strategy

We are currently witnessing a profound architectural inversion in the world of enterprise computing that will define the next decade of corporate IT strategy. For the better part of a decade, conventional IT wisdom dictated that all significant computing workloads […]

The post Navigating How the Rapid Enterprise Push Toward Localized AI Mandates a Radical Shift in Cloud Strategy appeared first on TechSpective.

Page 4 of 8
1 2 3 4 5 6 8