The strongest zero-human company signals entering September 2, 2026 are not new agent interfaces. They are control systems: a release gate for critical cyber capability, customer-held monitoring data, a governed agent inventory, and the first information-gathering steps in EU AI Act enforcement.

1. Capability: Astra Crosses OpenAI's Critical Cyber Threshold

On September 1, OpenAI said its pre-release Astra model meets the Critical cybersecurity capability threshold in the company's Preparedness Framework. OpenAI defines that threshold around autonomous zero-day exploit development across hardened systems or end-to-end attacks from a high-level goal.

OpenAI reports that Astra found previously unknown vulnerabilities during internal evaluations and built exploit chains against hardened targets. Those results are provider-reported, not independent validation. The company says it delayed parts of development and release, restricted advanced cyber access, added monitoring that can stop activity, and will publish fuller testing in the system card at launch.

The defensible signal is the release decision, not a benchmark victory: capability evidence changed who may access the model, how it is monitored, and what happens when a task is flagged.

2. Safeguards: Monitoring Data Moves Into Customer Custody

Anthropic announced Enterprise Frontier Safeguards on September 1. The proposed design stores activity data in customer-controlled cloud infrastructure under customer encryption keys, access policies, and audit logging while Anthropic's automated systems inspect a rolling window for serious misuse signals.

Flags go to the customer for review, and Anthropic says no Anthropic employee needs to inspect the underlying content. Customer-owned storage, customer-managed keys, and automated review are separate opt-in controls.

EFS is not yet broadly available: Anthropic says phased rollout begins later this fall. The announcement describes architecture and design partners, but provides no independent evidence yet about detection quality, false positives, or operational failure modes.

3. Inventory: AWS Agent Registry Reaches General Availability

AWS made AWS Agent Registry generally available on August 31. It catalogs agents, tools, skills, MCP servers, and custom resources, with semantic and keyword search, CloudTrail audit trails, infrastructure-as-code support, tagging, and cross-account sharing.

Current auto-detection is narrower than the long-term vision: AWS says the release can detect agents on AgentCore runtime and gateways across an organization. Detection across broader AWS and non-AWS environments, richer security assessments, and invocation-time policy enforcement appear in the roadmap rather than the current feature set.

A registry record is also not proof that a capability is safe. AWS's technical guidance says operators still need duplicate checks, security scans, metadata standards, and human approval before a resource becomes discoverable for production use.

4. Policy: EU AI Act Enforcement Starts With Information Requests

In an official September 1 press briefing, a European Commission spokesperson said the Commission sent requests for information to more than 30 AI companies across safety and security, copyright, and transparency. The spokesperson described them as the first enforcement steps under the AI Act.

The Commission did not name recipients or confirm whether OpenAI or Anthropic received a request. It did confirm recent exchanges with both companies about cyber risks. A request for information is an evidence-gathering step, not a finding of non-compliance.

5. The Operating Pattern

These developments converge on a practical rule: as autonomous capability rises, controls cannot live only in policy documents. Model access, monitoring custody, capability inventory, approval evidence, and regulator responses need explicit owners and machine-readable state.

For a zero-human company, the minimum control plane is becoming clear: know which agents and tools exist, bind each to an owner and version, store activity evidence under a defined custody model, stop risky execution automatically, and preserve a human decision point for release and investigation.

Related: Read the field notes on Astra's critical cyber gate, customer-held safeguard logs, and AWS Agent Registry governance.