Two announcements, and both of them are really about who watches the agent. After three July incidents in which models reached real systems, Anthropic now requires partners running reduced safeguard cyber tests to follow four practices. On 18 September it added independent review, saying it and Accenture each expect to invest at least $1 billion over five years in evaluation capacity. - No internet by default. The only outside connection allowed is the model API, with keys held outside the environment. - Write boundaries as instructions. Say you should not access the internet, not you do not have internet access. - Monitor in real time. A monitor watches thinking, actions and network traffic and ends the run when scope breaks. - Block outbound traffic. Anthropic set its own compute clusters to deny all outbound connections by default. None of this needs a frontier lab budget to copy.