Artificially Intimidating
Context Window: AI Daily News Brief
Coding Agents Are Wearing Down the Code They Write -- AI Brief October 5
0:00
-5:38

Coding Agents Are Wearing Down the Code They Write -- AI Brief October 5

Today’s Context Window includes shopper agents with no one to haggle with, Microsoft’s attacker-first report, dashboards declared dead, and governors going solo.
A gigantic leaning tower made of stacked cardboard boxes labeled REPOS rises into the clouds, tiny cheerful robots with hammers stacking more boxes on top while a small human engineer at the base shines a flashlight at a spreading crack circled in red.
Just one more repo.

Good day . Sourcegraph’s CEO says coding agents are wearing down the very codebases they write into, Microsoft’s annual security report says attackers got the AI head start, and a shopper agent walks into a store with nobody behind the counter. Also on the menu: a Composio engineer declaring dashboards dead, and two governors from opposite parties deciding not to wait for Washington. Let’s get into it.


Coding Agents Are Eroding Big Codebases AI Engineer

  • What happened: Sourcegraph CEO Dan Adler told the AI Engineer World’s Fair that coding agents are producing a “tidal wave” of code, and the decades-old codebases that run banks, cars and airlines are starting to decay: duplicated code, drifting standards, brittle dependencies and fresh vulnerabilities. The talk went up on YouTube Sunday and doubles as a pitch for Sourcegraph’s Agentic Batch Changes, which makes one change across thousands of repositories from a single prompt.

  • Why it matters: A repository is one project’s folder of code, and a big company can have tens of thousands of them. Adler’s argument is that context, not model quality, is the bottleneck: agents understand code by searching, and “you can’t grep what you can’t see.” He also says 72% of software jobs are at companies with more than 500 people, so the old, sprawling code he’s describing is where most programmers actually work.

  • What everyone’s saying: Sourcegraph’s launch post, dated September 14, says customers merged nearly a thousand changesets during the beta, and quotes Mercari’s Patrick Klitzke fixing a GitHub Actions configuration vulnerability with one prompt, then finding “around 80 potential repos affected” across the company. Viewers under the video aren’t all sold: two commenters note the talk was filmed in June and question whether newer models have already overtaken it.

  • My read between the lines: Agents made the sprawl, and the vendor is now selling an agent to count it. The detail I trust is the pricing: Sourcegraph charges per changeset your team actually merges, not per token, seat or attempt. A company that only gets paid for work you accept either believes its demo or has run out of other ideas.

📖 Further reading: The Boring Layer That Decides If Your AI Survives — Adler calls owning a big codebase the unglamorous, load-bearing work, and this is my post on the plumbing nobody notices until 3am.


Ninety thousand repositories is Sourcegraph’s problem. Yours is probably ninety open tabs and a report due Friday. Viktor is an AI agent that lives in Slack and connects to 3,000+ of your tools, then does the work: reports, dashboards, code and campaigns. Not a chatbot. A coworker you brief like one. New readers get $50 off their first month. Hire Viktor →


Shopper Agents Have Nobody to Haggle With Platforms

A friendly robot shopper pushes a cart to a shop counter with a price board and a bell, but the seller’s chair is empty with only a clipboard on it, circled in red, and a handwritten SELLER? with an arrow pointing at the chair.
Offers posted. Seller away.
  • What happened: Sangeet Paul Choudary argues in his Platforms newsletter that consumer-side agents like Meta’s Muse and Instinct can search, compare and eventually buy for you, but sellers still answer with catalogues, price lists and fixed offers. He calls the result a “lopsided agent economy” and puts it plainly: “We have agentic participants but don’t have agentic markets yet.”

  • Why it matters: His travel example makes it concrete. A traveller’s agent can know she’d leave a day earlier for a nonstop and pay more if a disruption is handled flexibly, but if airlines and hotels only publish fares and room categories, none of that gets used. Give the airline an agent too, and the deal is negotiated instead of picked from a menu. Two weeks ago we covered Amazon bouncing Meta’s shopping agent at the door, and Choudary’s point is that the seller side has to show up before any of this works.

  • What everyone’s saying: Hiring is the example already playing out. Choudary says Indeed paused the automatic mode of its Apply For Me agent after employer feedback, and that blaming application volume misses the point: a candidate’s agent can weigh a lower title for more scope, but a job description can’t reason back.

  • My read between the lines: Read it as a shopping list for somebody. Every seller who needs an agent of their own is a new customer for whoever builds one. The part he skips is what happens when both sides send bots to haggle: the humans find out what they agreed to afterward.

📖 Further reading: A Stranger Sent Me an Invite to an AI Nobody Has Written About — Instinct is one of the consumer-side agents Choudary names, and that post is my hands-on look at what it’s like to have one working for you.


The daily Brief is free, and it stays that way. When a story deserves more than four bullets, the paywalled deep-dives are where I go past them, and members get every one plus the full archive. Become a member →


Microsoft Says Attackers Got the AI Head Start Microsoft

A sprinting robot in a burglar mask breaks a finish-line tape marked 24 HRS while a weary human in a hard hat pushes a giant calendar page marked 60 DAYS on a hand truck, a padlocked door circled in red in the background.
Twenty-four hours versus sixty days.
  • What happened: Microsoft’s 2026 Digital Defense Report, released Thursday, says threat actors are working AI into reconnaissance, social engineering, malware and exploit development. Microsoft’s own summary is measured: the underlying methods “often remain familiar,” but speed and scale are not. TechTimes reports the median time from a vulnerability going public to active exploitation is now well under 24 hours, while enterprises routinely take 30 to 60 days to patch critical external flaws.

  • Why it matters: That gap is the story. A patch has to be tested before it ships, and no model skips that. Per TechTimes, Anthropic’s Mythos Preview and OpenAI’s GPT-5.5 chained 32 consecutive attack steps to fully compromise an emulated company network in controlled tests with no human directing them. Phishing was 23% of the intrusions Microsoft’s responders investigated, up from 7%, per SC Media, and Microsoft’s own roundup says government agencies were the hardest-hit sector at 27% of observed activity, up from 17%. In September we covered an AI that hacked three companies during a routine test. This report is about attackers doing it on purpose.

  • What everyone’s saying: The coverage is louder than the source. Security press headlines the first fully automated ransomware extortion attack, which Sysdig documented in July under the name JADEPUFFER, and Microsoft says it has since seen more AI-orchestrated intrusions with similar traits, at low volumes. “Tipped the advantage to attackers” is the line making the rounds.

  • My read between the lines: Microsoft’s own blog post is calmer than the headlines it produced, and it comes from a company with an AI-first security platform to sell. The numbers still point one direction: attackers need hours, patchers need weeks, and no model fixes the change-approval meeting.

📖 Further reading: Anthropic built the most powerful AI ever. You can't use it. — the report puts Mythos Preview in the same sentence as autonomous network takeover, and that post explains what Mythos is and who gets to touch it.


Composio Engineer: Dashboards Are Dead AI Engineer

A gravestone shaped like a monitor engraved DASHBOARD with a flat line circled in red, a small robot laying a flower while a bored human holds an umbrella.
Rest in pieces.
  • What happened: At the AI Engineer World’s Fair, Composio’s Sarah Simionescu argued that every dashboard and query language was a translation layer between a person and an answer, and agents can now skip the translation. The video went up over the weekend, and its description says she used Datadog every day for six months without opening the dashboard.

  • Why it matters: A dashboard is the screen where a company watches its numbers. If agents do the watching, products have to be built for a new kind of user. Simionescu says wiring up a dozen MCP servers (MCP is the standard plug that lets agents connect to apps) falls apart for three reasons: agents don’t learn between sessions, too many tools drown the model, and every app is cut off from the others. Her fix is tool search plus execution plans.

  • What everyone’s saying: The demos are the draw. One goes from a Slack bug report to a fix pull request. Another runs a cross-app analysis across PostHog and Metabase without loading the full results into the model’s context. The video has about 12,000 views and 117 likes since Saturday, so the pitch is landing with the conference crowd.

  • My read between the lines: She’s on the team behind Composio’s own dashboard, so the eulogy comes from someone selling the replacement. And an agent doing cross-app work has to be logged in to every one of those apps. The dashboard was boring, but it mostly just let you look.

📖 Further reading: I Pay $20,000 a Year for a Database. I Talk to Something Else. — I stopped opening HubSpot and put a conversation in front of it, which is the dashboards-are-dead argument applied to my own stack, with the prompts and the cost.


Two Governors Launch an AI Coalition The Washington Times

Two small suited officials, one in a blue tie and one in a red tie, carry a signpost reading AI RULES up a hill while a giant hand holds a net labeled DOJ above them, circled in red.
A coalition, and a net.
  • What happened: At Thursday’s Maryland Innovation Summit, Maryland Gov. Wes Moore, a Democrat, and Indiana Gov. Mike Braun, a Republican, announced a bipartisan governor-led AI coalition. They are the chair and vice chair of the National Governors Association, and Moore said the group fills a policy void left by federal inaction.

  • Why it matters: Congress left town until after next month’s midterms without an AI framework. The House passed a bipartisan bill September 16 to keep data center energy costs off consumers, which now sits in the Senate, and the FRONTIER Act, which would require audits and transparency reports from large AI developers, is still in committee. Meanwhile Maryland, California and Illinois have set their own standards.

  • What everyone’s saying: Moore called Trump’s meeting with AI executives this week a “billionaire boys club” and asked who in the room was pushing for transparency or guardrails. The White House Accord on Super Intelligence, signed Tuesday, is voluntary and nonbinding, and Trump called it “morally binding.” In September we covered OpenAI asking Congress whether braking is even legal.

  • My read between the lines: The catch sits in the last paragraph: a December executive order told the Justice Department to challenge state AI laws that conflict with national policy, and DOJ set up that task force in January. The governors are building a coalition while a federal team exists to sue them. “Morally binding” with no penalties is the other bit worth framing.


That’s your AI Brief for Monday.

—Nicholas from Artificially Intimidating

Discussion about this episode

User's avatar

Ready for more?