Runtime: AWS plants a Cedar; JFrog's under attack (again); Dell doubles down AWS's open-source Cedar project is gaining traction among companies like Cloudflare, MongoDB, and Stacklok for managing AI agent access control, as traditional role-based systems struggle with agent identities. Phil Estes, principal engineer at AWS, said Cedar fits well for defining actor-action-resource permissions, while maintainer Lucas Käldström highlighted its value in handling policy inconsistencies. Separately, JFrog's Artifactory faces a critical vulnerability allowing unauthenticated admin token creation, and Broadcom reported a 221% chip revenue increase in a $29.6 billion quarter. Runtime /tag/runtime/ Welcome to Runtime Today: How companies are using an AWS-built open-source tool to handle access control, OpenAI's hacker agents aren't the only ones on a new Artifactory flaw, and more. Please forward this email to a friend or colleague If it was forwarded to you, sign up here to get Runtime for free every week, or level up here . First up: Adjudicating agent access Companies building AI applications quickly find themselves in need of a way to verify the identities of their own AI agents as well as agents connecting to their applications. Traditional role-based access control systems were designed to validate people, not agents, and correctly designating agent permissions is going to be one of the biggest challenges of the post-Hugging Face incident world. In order to solve this problem companies are turning to an open-source project called Cedar that began life inside AWS, Mary Branscomb reported Thursday for The Stack . "Anywhere I need authorization or I need to define an actor, an action and a resource – anything with RBAC or accessed based control for what an actor can do or not do – anywhere you need to make those decisions, Cedar fits really well," said Phil Estes, principal engineer at AWS. Companies like Cloudflare, MongoDB, and Stacklok are using Cedar to set access policies in code without having to define roles across big companies and organizations, which is already hard and will become nearly impossible if agents really take off. "Cedar is perfect for solving the problem where I have no idea what my policies are doing any more because I have more than ten of them, and for finding policy inconsistencies,” project maintainer Lucas Käldström told The Stack . AWS earned a rather checkered reputation across open-source communities https://www.lastweekinaws.com/blog/awss-open-source-problem/?ref=thestack.technology during the first decade of its existence for building cloud services around open-source projects without contributing much, if anything, back to those communities. That situation has changed over the last few years, and Cedar is a prime example: "We knew how it was valuable inside AWS and the open sourcing decision was essentially ‘it's hard to believe this couldn't be valuable to others,'" Estes said. The rest of The Stack Not easy being green : Weeks after JFrog found itself at the center of the OpenAI-Hugging Face hacking incident, hackers human, we think are exploiting another vulnerability in its Artifactory repository manager. The critical vulnerability "lets any bad actor with no credentials trivially mint themselves an admin token and thereafter, run riot," The Stack's Ed Targett reported. Chipping in : Broadcom reported a 221% increase in chip revenue Wednesday, as part of a $29.6 billion quarter. And CEO Hock Tan doesn't forsee an end to the AI boom just yet: "We expect customers' need for compute infrastructure to inflate even more in 2027 and 2028," he said on a conference call following the release of the results. Gotta serve somebody : Dell's blowout quarter is just another sign that demand for enterprise AI compute is changing everything, a decade after the future of the on-premises server market seemed very much up in the air. The company reported $47 billion in fiscal second-quarter revenue Tuesday, up 58% compared to the same period last year, and raised its guidance for the full year by $25 billion. Self storage : Anthropic customers were not very happy about a data-retention policy the company put into place alongside the release of Claude Fable 5.0, but the launch of Fable 5.1 Tuesday introduced something that appears to meet them halfway. Enterprise Frontier Safeguards still requires customers to make model-usage metadata available to Anthropic, but now they can store that data on their cloud instances and protect it according to their own policies. METR's runnin' : The non-profit METR organization is either an important whistle-blower warning of the growing sentience of advanced AI models or a classic case of AI psychosis, depending on which segment of enterprise tech you've been traveling through this week https://www.thestack.technology/as-a-viral-post-claims-openai-fostered-a-secret-ai-civilization-more-prosaic-truths-go-overlooked/ . But critics of its knowledge of modern cybersecurity practices got a boost Monday after the group acknowledged that a flaw in an AI-created internal app allowed anyone to access its AI model account, and somebody or somebodies racked up a $600,000 bill before getting caught. Double dip? : The government-to-industry hiring pipeline long predated the AI boom, and will surely outlast it, but Matt Clifford's decision to join Anthropic while keeping his position as the head of the UK's Advanced Research and Invention Agency is raising eyebrows even within those jaded circles. " Clifford’s intention to remain as Chair of ARIA, which invests taxpayer money in cutting-edge research — much of it AI-related or AI-enabled — creates a clear conflict of interest," Science, Innovation and Technology Committee Chair Chi Onwurah said in a statement. Stack ranking: Enterprise moves Don Dama is the new CEO of Aerospike https://aerospike.com/press-release/aerospike-names-don-dama-ceo/?ref=thestack.technology , joining the NoSQL database company after leadership roles at SingleStore and Mirantis. Dinesh Keswani is the new CTO and partner of Goldman Sachs https://www.thestack.technology/goldman-sachs-poaches-nomuras-global-cto-to-lead-core-engineering/ , joining the financial powerhouse after three years as CTO of Nomura. Tom Bonos is the new chief revenue officer at Sumo Logic https://www.sumologic.com/newsroom/sumo-logic-names-tom-bonos-as-chief-revenue-officer-to-drive-growth-of-ai-first-platform-for-security-observability?ref=thestack.technology , joining the observability company after serving as chief operating officer and chief revenue officer at Applause. Julia Brau Donnelly is the new chief financial officer at Sierra https://sierra.ai/blog/julia-brau-donnelly-joins-sierra?ref=thestack.technology , joining the customer-service agent company after holding finance leadership roles at Pinterest and Wayfair. Juergen Lindner is the new chief marketing officer at Calix https://www.calix.com/press-release/2026/09/calix-announces-cmo.html?ref=thestack.technology , joining the service-provider software company after marketing leadership roles at ServiceNow and Oracle. We're also reading: " Revisiting Joel's Test: https://blog.exe.dev/revisiting-joel?ref=thestack.technology " exe.dev's Philip Zeyliger suggests a new update to for evaluating the performance of software teams with the AI era in mind. https://www.joelonsoftware.com/2000/08/09/the-joel-test-12-steps-to-better-code/?ref=thestack.technology Joel Sposky's famous advice Microsoft to start disclosing Azure quarterly revenue as company consolidates business units https://www.cnbc.com/2026/09/02/microsoft-to-disclose-azure-revenue-as-part-of-segment-changes.html?ref=thestack.technology : From the "it's about goddamn time" department, Microsoft will finally report the revenue total of its most important service, which came in at $29.4 billion during its last quarter. Thanks for reading — Runtime is off this weekend for the US holiday, see you Tuesday