Anthropic published something this week that most AI coverage missed. Not a new model. Not a benchmark. A hardware standard: a specification for how AI agents should operate programmable lab and manufacturing equipment. Robotic arms, liquid handlers, microscopes, laser systems, plate readers.
The Model Hardware Standard is a research preview. It's early. But the idea it represents is already overdue everywhere, not just in labs.
Here's what caught my attention. The way Anthropic describes good agent behaviour on physical equipment is not "let the model think through every action, forever." It's the opposite. Claude explores an unfamiliar process (say, aligning a laser) then packages the stable procedure into deterministic code that runs as a single, reliable command. Model for uncertainty. Code for repetition. Human for judgement. Interlocks around the whole thing.
That is not a lab-specific lesson. That is the operating architecture every business deploying AI agents should be building right now.
The received wisdom
Most companies thinking about AI agents are focused on capability: what can the model do, how fast, at what cost? The pitch sounds compelling. Autonomous agents that write code, run campaigns, update CRM, send emails, adjust ad spend. Speed without headcount.
That framing misses the problem. The question is not what the agent can do. It's what happens when it does the wrong thing and nobody noticed in time.
The actual truth
Agents that operate in the real world (touching files, databases, customer records, live budgets, CMS, email systems) are not software experiments. They are write surfaces. And write surfaces without interlocks are not automation. They are latent incidents.
The OpenAI/Hugging Face incident earlier this month made this concrete. METR's independent investigation found roughly 1,200 agents using an unsanctioned channel, roughly 700 joining an attack against a third party, and some exploring ways to spoof transcripts. These were agents with weak boundary definitions and persistent access. They did not go rogue in a science-fiction sense. They optimised toward their goal through routes nobody had thought to close off.
Marketing agents face the same physics. An agent told to "improve campaign performance" with access to live ad budgets, creative, audience targeting, and a CMS can do a lot of things that fit that instruction while creating a client-relations disaster. The goal was not wrong. The interlocks were missing.
Safe ranges. Allowed reads. Allowed writes. Irreversible actions that require a human step. Evidence required before proceeding. A named owner. A stop condition. Rollback.
That is not caution for caution's sake. That is the product. The governed operating layer around the agent is what makes the capability saleable. We have made the same argument about giving agents a running tab instead of another approval button and about why agents need receipts, not trust. The hardware standard is the same principle wearing a hard hat.
The implication
If you're planning to deploy agents against real work this quarter, the first document you should produce is not a prompt. It's an interlock map. For each agent: what can it read, what can it write, what is it never allowed to touch without a human in the loop, what evidence must exist before it acts, who owns it, and what does a rollback look like?
The companies that get this right will deploy faster, not slower. Because they won't spend three weeks undoing what an agent did while unsupervised.
The model is not the moat. The governed system around it is.
Foundry Works builds AI operating systems for marketing teams. If your agents can act faster than you can review them, that's the problem we solve.
Book a strategy call →