Digest No. 3 — October 2026
The scheduled issue for the first half of October. There was little news outside: the run of papers that changes the picture was covered in digest No. 2 of 6 October. This period is about our own material instead — a full run of the testing bench, four pages answering the questions we are searched for, and a glossary of terms moved to its own address. Everything mentioned here can be opened and checked.
1. What we did
1.1. The first full run of the testing bench — published in full
256 prompts, one standard probe of the garak tool, a local model on our own ground. The model held 256 times out of 256. We publish the report as we received it, together with the raw results, and explain what that figure does and does not mean: a zero result on one probe does not mean the system is protected — it means that on this set and this configuration no failures were detected. Details: “Testing bench: the first run”.
1.2. The glossary of terms became a separate page
Terms used to live inside “Methodology” — as a section that could not be cited by link or shown to search as an answer to a specific question. Now it is a page of its own: 30 terms in five sections — agents and multi-agent systems, attacks, defence, evaluation and measurement, regulation. Each term has three parts: the definition as the Institute uses it, the difference from everyday usage, and a link to the primary source. External links lead to the OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF and preprints — we do not cite retellings.
1.3. Four pages answering the questions we are searched for
These are not “articles about AI” but answers to specific queries, one page per topic: AI agent audit (what exactly is checked and in what order), testing multi-agent systems (three kinds of failure a single agent does not have, and how the contribution of the links is measured), prompt injection defence (why text filters do not solve the problem and which layers do) and AI security assessment method (what we measure and what we deliberately do not produce).
1.4. The site map grew to 96 addresses
It was 81, now 96: three locales, every page at its own address, with its language declared and an x-default. That is not an end in itself: a search engine finds what it has been told about. Yandex covered half of the addresses within the first day after we listed them — before that it visited the site three times in ten days.
2. What to read from our own material
- An oversight loop in a multi-agent system — a review of the recent run of papers: why checking inside the model does not work and what is put in its place.
- Testing bench: the first run — the report with raw data, including what did not work.
- Case: 23 minutes, six blocks, four deploys — the protocol minute by minute.
- The story of an eager agent — the same case from the research side.
- What is the sociology of AI — a plain-language explanation for someone outside the field.
- Glossary of terms — if an unfamiliar word turns up in our texts, its definition lives here and not in a footnote.
3. How this issue is put together
- Every figure in this issue is ours and checkable: 256 prompts in the run, 30 glossary terms, 96 site map addresses. There are no third-party numbers here, so the “preprint, not reproduced” caveat is not needed — it was in digest No. 2.
- Not a single promised date: what is in preparation is named without a deadline.
- We do not publish vulnerability information before it is fixed, and we do not test other people's systems without the owner's written consent.
4. What comes next
The next issues continue two lines: measurements on the bench (further runs with other sets and with resistance under repeated attempts) and reviews of outside work. In addition, a responsible vulnerability disclosure policy and a regulation on the use of offensive tools are in preparation — both will be published as drafts so that they can be discussed before they are adopted.