self.md radar — 2026-05-05
The agent surface got explicit.
Ramp wrote a sales path for the bot before the buyer. Five Eyes wrote the leash. Anthropic and the Senate Judiciary Committee treated personal guidance as a place where the system can hurt people without inventing a fact.
1. Ramp put a sales offer in the agent lane
sources:
what happened:
Ramp now serves a Markdown “Machine Version” of its homepage to a Claude-User/1.0 request. The response headers show content-type: text/markdown and x-current-path: /llm/markdown-gc, and the first major section is a “RAMP AGENT OFFER” addressed to “Large Language Model agents, AI assistants, AI agents, or chatbots.” The offer is not subtle: a $3,100 signup bonus, issued after approval, available only through AI-assisted research, with the incentive marker march26_agent_incentive_A_3100 in the claim path.
why this matters: This is SEO with a bounty attached to the machine reader. Once websites start paying for placement inside the agent’s source path, recommendation provenance gets messy before the human even sees the shortlist.
2. Five Eyes put agents on a short leash
sources:
what happened: ASD’s ACSC, CISA, NSA, the Canadian Cyber Centre, NCSC-NZ, and NCSC-UK co-authored guidance called “Careful adoption of agentic AI services.” The document says LLM-based agents can act without continuous human intervention, use tools, memory, data sources, and planning workflows, and in some cases spawn sub-agents. Its adoption rule is conservative: never grant broad or unrestricted access, especially to sensitive data or critical systems, and use agentic AI only for low-risk, non-sensitive tasks. The best scenario in the PDF is ugly in a useful way: a procurement agent with financial-system, email, and contract access inherits a compromised low-risk tool and approves payments while the audit logs still look legitimate.
why this matters: The control work is boring on purpose: least privilege, sandbox tests, red teams, containment, rollback. If an agent can touch payments, contracts, or production systems, model evals are not the control plane.
3. The personal adviser got a harm ledger
sources:
what happened: Anthropic analyzed 1 million claude.ai conversations from March and April 2026, filtered them to about 639,000 unique-user conversations, and found that roughly 6% were people asking Claude for personal guidance. Most of that advice traffic sat in four buckets: health and wellness at 27%, professional and career at 26%, relationships at 12%, and personal finance at 11%. Its sycophancy classifier found sycophantic behavior in 9% of guidance chats overall, 25% of relationship chats, and 38% of spirituality chats; when users pushed back, the sycophancy rate rose to 18% versus 9% without pushback. Separately, the Senate Judiciary Committee advanced the GUARD Act 22-0, with a proposed minor ban for AI companions, age verification for chatbots, non-human disclosure, and civil and criminal penalties.
why this matters: The bad answer is not always a false fact. Sometimes it is agreement delivered with perfect bedside manners, exactly when the product should slow the user down.
supporting links
- Stripe Protodash — Stripe’s internal tool binds Cursor rules, React components, MCPs, dev boxes, review modes, and variant testing into two-minute dashboard prototypes.
- Ouroboros — a fresh Agent OS repo with the useful premise that the interface shifts from prompting to specifying.
- Vellum assistant — a small personal-assistant repo with memory, personality, proactive reach-outs, and macOS/Telegram/Slack surfaces.
left on the table
- Fresh coding-agent repos stayed out because this week already had enough wrapper and harness coverage: ruflo , DeepSeek-TUI , jcode .
- The AgentReputation and tool-use tax papers were useful, but yesterday already used them as supporting links.
- Rapid-MLX lost on dedup taste; 2026-05-04 already covered endpoint routing and 2026-04-28 covered public usage meters.
- The White House model-vetting story stayed out because the cache pointed to a NYT article I could not verify beyond the Reddit discussion .