The New Claw Times

The latest news on OpenClaw, AI agents, and automation

AI & Automation News — The New Claw Times

Saturday, April 18, 2026
News 3 min read

TrustModel.ai Audit Flags 63% of Top Chrome Extensions and AI Browser Agents for Security Risks

The first large-scale independent trust audit of browser-based tools found that 63% of the top 100 Chrome extensions and 10 leading AI browser agents introduce meaningful security and data exposure risks. Only 9 of 108 extensions earned 'Highly Trusted' status, while 43% have access to every website a user visits.

By The New Claw Times

Don't miss a story

Get our daily briefing in your inbox →

Free. Every morning. No spam.

Latest
Commentary
3 min read

CBS News Asks 'Should You Let AI Agents Shop for You?' as Retailers Deploy Without Consumer Guardrails

CBS News ran a consumer risk editorial on AI shopping agents during its morning news cycle on April 17, featuring Boston Consulting Group, Tasklet's CEO, and security researchers all saying the same thing: agents can shop for you, but the trust layer is not ready. The piece contrasts these warnings with Amazon, Walmart, and Amex racing to deploy agentic commerce products.

News
3 min read

India Forms Inter-Ministerial AI Governance Body as Autonomous Agents Spread Through Banking and Payments

India's government announced the formation of the AI Governance and Economic Group (AIGEG) on April 17, a high-level inter-ministerial body chaired by Electronics and IT Minister Ashwini Vaishnaw. AIGEG will coordinate AI policy across ministries as companies deploy autonomous agents in banking, payments, and supply chains without a dedicated regulatory framework. The body's mandate includes reviewing existing AI mechanisms, studying emerging risks, identifying regulatory gaps, and developing a deployment roadmap for the next decade.

Commentary
2 min read

Harvard Business Review Publishes Research on China's Meituan AI Agent as the Agentic Commerce Archetype

HBR published research on April 17 analyzing Meituan's Xiaomei AI agent as the leading real-world deployment of what it calls an 'orchestrator plus execution agent.' Launched in late 2025, Xiaomei completes food delivery transactions from natural language intent with zero screen interaction. The research examines why Chinese platforms are 12 to 18 months ahead of Western counterparts in commercial agent deployment, and what design patterns the rest of the industry is converging toward.

News
3 min read

Three Surveys Quantify the Enterprise AI Agent Security Gap: 88% Had Incidents, Only 21% Have Runtime Visibility

A VentureBeat three-wave survey of 108 enterprises, Gravitee's survey of 919 executives, and Arkose Labs' 2026 report converge on the same finding: enterprises are deploying AI agents far faster than they are building the security infrastructure to monitor them. 88% reported AI agent security incidents in the last 12 months. 82% of executives believe their policies protect them. Only 21% have runtime visibility into agent actions. 97% of security leaders expect a material agent-driven incident within 12 months. Only 6% of security budgets address the risk.

News
3 min read

Cloudflare and GoDaddy Launch AI Agent Identity Standards for the Open Web With isitagentready.com and Agent Name System

Cloudflare and GoDaddy announced a strategic partnership on April 17 to build the identity and access control layer for AI agents on the open web. GoDaddy is integrating Cloudflare's AI Crawl Control into its hosting platform for its 21 million+ small business customers. Cloudflare launched isitagentready.com, a tool that scores any website on how well it supports AI agents, and a Cloudflare Radar dataset tracking agent standards adoption across the internet. Both companies are backing GoDaddy's Agent Name System (ANS), an open standard using DNS and PKI to give AI agents verifiable identities.

★ Editor's Picks
Deep Dive

Claude Opus 4.7 Launches With Task Budgets, xhigh Effort, and Autonomous Self-Verification: Anthropic's GA Frontier Is Now Explicitly Agentic

Anthropic's Claude Opus 4.7 is the first generally available frontier model built around production agent primitives. Task budgets let developers cap token spend on autonomous loops. A new xhigh effort level sits between high and max for cost-performance tuning. The model autonomously devises verification steps before reporting tasks complete. It leads GPT-5.4 and Gemini 3.1 Pro on knowledge work and agentic coding benchmarks, but the margins are razor-thin, and competitors still win on agentic search and multilingual tasks. Pricing stays at $5/$25 per million tokens. The real story: Anthropic is shipping the operational guardrails that make long-running autonomous agents financially and technically viable in production.

7 min read
Deep Dive

MCPwn: The First Major MCP Exploit in the Wild Is a CVSS 9.8 That Owns Your Nginx Server in Two HTTP Requests

A critical authentication bypass in nginx-ui's MCP integration is being actively exploited to take over Nginx servers without credentials. CVE-2026-33032, codenamed MCPwn by Pluto Security, exposes 12 MCP tools to any network attacker through a single missing middleware call. The fix was 27 characters. The implications reach every team bolting MCP onto production infrastructure.

8 min read
Deep Dive

Agentic Endpoint Security Is Now a Product Category: How Palo Alto, Norton, and a Hacked Samsung TV Got Us Here

Palo Alto Networks completed its acquisition of Koi on April 15, formally defining Agentic Endpoint Security as a new product category. The same week, researchers demonstrated OpenAI Codex autonomously rooting a real Samsung Smart TV, and Norton launched the first consumer security product designed to monitor AI agent behavior in real time. Three events, one conclusion: the endpoint has changed, and the security stack must change with it.

7 min read
More Stories