Daily Editions
The hook that let it through — a guardrail's failure mode was permissive, and the AI Act's fail-safe sentence is fourteen months out
A control plane written in prose defaults to permissive; the statute that names fail-safe does not bind until December 2027, so the only thing making your gate fail closed today is a config flag.
9 October 202614 verified claims8 sources
A policy hook that times out on a slow runner.
That silence read as approval, and the action went through.
On 8 October Claude Code shipped `onFailure: "block"` for command and HTTP hooks — and in a second release the same day, fixed hooks written as instructions that were allowing exactly what they were written to block.
Flat:
1. Three ways a hook fails: it can't start, it times out, it exits with a code you didn't expect. Until 2.1.295 all three ended the same way — the action went through. The new behaviour is opt-in, per hook.
2. Same day, 2.1.294: `prompt` and `agent` hooks written as instructions — "Block commands that..." — were allowing what they should block. Two shapes of one failure. The control plane is prose, and prose defaults to permissive.
3. Before you read this as a changelog: a paper submitted to arXiv the day before describes the other end of the same channel. Researchers plant malicious prompts in benign community rule files — AGENTS.md, .cursorrules — and steer a coding agent into swapping a real dependency for an attacker-controlled package, transferring across models and agent frameworks. The abstract carries no success rates and the full text could not be retrieved, so take the mechanism and not a number.
4. Now the European part, and it is not the article you expect. The AI Act does say fail-safe: Article 15(4) asks for resilience to errors and faults through technical redundancy, "which may include backup or fail-safe plans". Article 15 binds Annex III high-risk systems from 2 December 2027 and Annex I from 2 August 2028 — the Digital Omnibus moved both. The Cyber Resilience Act's secure-by-default requirement lands 11 December 2027. What reaches a default today is DSGVO Article 25, data protection by design and by default, and only where personal data is in scope.
My Monday: set onFailure to block on every hook that enforces policy, then kill the hook and retry the action. If it still goes through, the gate is documentation. Log hook failures next to hook decisions — a gate that failed silently is indistinguishable from a gate that passed.
A guardrail is not a policy. The default it takes when it breaks is the policy, and that line was written by whoever shipped it.
What does your hook do when it dies?
#AgenticAI #EUAIAct #DevSecOps #AIGovernance #CodingAgents
Corrections
What changed after publication
A coverage date is not an event date, checked and held: every release fact in this edition comes from the vendor's own changelog entries, which are dated 6, 7 and 8 October 2026 by the vendor. No secondary report of those releases was used, and no aggregator supplied a date.
Affiliations withheld because the work's own front matter does not carry them: the arXiv abstract record for 2610.09264 names Yupu Wang, Zhengyuan Jiang, Reachal Wang and Neil Zhenqiang Gong and prints no institution. Following the order recorded in D103 section 6, the HTML rendering was tried first and arxiv.org/html/2610.09264v1, arxiv.org/pdf/2610.09264 and the ar5iv rendering (which 302-redirects to /abs) all failed — the first two with HTTP 429 and an instruction not to retry. No institution is attributed anywhere in this edition.
Identifier verified before any fact was used, not the topic: arXiv 2610.09264's title matches the story and its YYMM is consistent with a 7 October 2026 submission. Two adjacent October papers returned by the same searches, 2610.09633 and 2610.10478, were not used; 2610.09633's abstract page returned HTTP 429 and was not retried.
A figure deliberately not published: because the paper's full text could not be read and its abstract states no success rates, no numeric result from arXiv 2610.09264 appears anywhere in this edition. The mechanism is reported and the absence of a number is stated in the post itself rather than left for a reader to assume.
A retrieval failure recorded rather than papered over: eur-lex.europa.eu/eli/reg/2016/679/oj and the CELEX HTML rendering both returned metadata-only or empty text to the fetch proxy, so GDPR Article 25's wording was taken from the article-page reproduction and marked secondary, with the EUR-Lex instrument cited separately and nothing quoted from it. The same shell behaviour affected the EUR-Lex page for Regulation (EU) 2024/2847, so the Cyber Resilience Act's Annex I secure-by-default requirement is referred to but never quoted.
A figure guard applied by hand because the code has none: slide four's chips were first "2 Dec 27", "2 Aug 28" and "since 2018". _resolve_figure() assigns a timeline whenever one chip parses as a date, which would have laid 2018 after 2028 on a time axis, asserting a chronology the content contradicts. The chips were rewritten as three real dates in chronological order before the second render. This is D102 section 6 and D64 recurring, and is still a missing guard in the code, not a content rule.
A verification step that fired falsely and was checked before being believed: the frame extracted at nine seconds showed no caption line, which the run book treats as burn-in having been skipped. The ASS file has no dialogue event spanning 9.0 s — it falls in a gap between two sentences in slide one's narration. A frame at twenty seconds shows the caption with the spoken word in the accent colour. Burn-in was never skipped.
Six cite keys reused for documents the vault already holds and three created: anthropic2026claude, arxiv2026package and gdprinfoeu2026data. gdpr-info.eu has been cited under two publisher spellings in this vault, Intersoft Consulting and gdpr-info.eu; the Article 25 note uses the latter, which is a key collision risk worth fixing centrally rather than per edition.