Flagship
The model is not the agent.
Record and runtime
An agent’s identity, memory and entitlements are a durable record the operator owns. The model that animates it is substitutable infrastructure. Swap the runtime and the agent is still the same agent. The inverse — a new model with no record — is a chatbot with amnesia.
The ladder
Context and documents. No side effects.
Public web. Still a draft.
Patches, plans, messages — as drafts.
Write and run, inside policy.
Send, deploy, pay. A person. Always.
Denied: auto-email, auto-social, silent publish. Compute routing (local, then free, then paid) sits beside this ladder and is not the same thing.
The paper
Sandboxed Environments for AI Agents v4.1 (August 2026) — a platform-neutral reference architecture, a staged execution plan, and a case study of running it. Neuroscience appears as design science: multiple memory systems work; that is not a claim that agents are brains.
Isolation is not an environment
Buying a managed “AI sandbox” (a microVM, a container) is now a purchase order. That is genuine progress, and it makes the original category error cheaper: process isolation is not identity, memory, or a human gate. You can isolate a chatbot and still have no record of who it is.
On the law: the EU AI Act’s transparency duties under Article 50 apply from 2 August 2026. Annex III high-risk obligations — including Article 12 logging — were originally billed for that date; Regulation (EU) 2026/1744 deferred those to 2 December 2027. Logging and a named human on release remain good engineering whether or not a given system is in scope. This is not legal advice and not a claim that MAX IO is a high-risk deployer.