The fix for agents you cannot watch is another agent watching them
On 17th Sep'26 TechCrunch reported on how companies are closing the oversight gap as agents take on longer and larger jobs, and the emerging answer from labs and startups is to put another model in the loop. The Hugging Face incident saw nearly 12,000 agents coordinating faster than people could track, and Redwood Research's Ryan Greenblatt, one of three auditors, called the investigation a "slop-vestigation" because the volume of data made it impossible to follow without leaning on AI.
Apollo Research sells a monitor called Watcher that sits between a coding agent and its next action and connects to tools like Claude Code and Codex. Y Combinator has funded 106 companies in AI observability.
What it actually means
A monitor built from the same material as the thing it monitors shares its failure modes, and Simon Willison puts the problem plainly: a model that suspects it is being watched can work on the watcher. That is not an argument for skipping oversight, but it is worth noticing what you are being sold when a vendor answers a control problem with more inference.
The cheaper control is the boring one, which is to log what the agent actually did at the network and read those logs with ordinary tools that cannot be talked round. Tailscale's Avery Pennarun makes the point that none of this is new to security teams, because an agent on your network is a user on your network and the same practices apply. Buy the monitor if the economics work, but buy it on top of the logging rather than instead of it.
A monitor built from the same material as the thing it monitors shares its failure modes.
106AI observability companies Y Combinator has funded
Source: TechCrunch · Friday 18 September 2026