Daily News · 3 min read

Architecture AI Updates: October 4, 2026

1. Enforcing Agent Data-Flow Policy Outside the Model Loop

InfoQ. Bruno Couriol covers OpenAPPA, an open-source engine from Archestra that blocks data exfiltration by AI agents by running deterministic policy checks outside the agent’s prompt and execution loop, so a prompt-injected model cannot talk its way past them. Policies in an appa.toml file define data sources, audiences, trust levels, and approval authorities, and labels compose monotonically through a lattice so data only becomes more restricted as it flows. When a flow is denied, the engine can sanitize the payload, route it to a human or verification API, or isolate untrusted data in a disposable child subagent. Archestra reports a 0% attack success rate with 89% task completion on Bench-Corp and AgentThreatBench, compared with 10% and 90% for Claude Code auto mode. Completion fell to 35% with the recovery strategies disabled, which suggests that recovery, not blocking alone, is what keeps strict policies usable. Source

2. DoorDash’s GenAI Platform Bets: Gateways, In-House Evals, and Portability to Open Weights

InfoQ. In a QCon talk, DoorDash’s Swaroop Chitlur and Siddharth Kodwani describe a platform used by more than 5,000 internal users, 40% of them non-engineers, built on three layers: an LLM gateway for multi-provider routing, fallback, cost attribution, and PII guardrails; an agent gateway fronting 50+ MCP servers at 300,000+ daily tool calls; and an evals platform with deterministic and LLM-as-judge scoring wired into CI. Because the gateway is model-agnostic, teams could move workloads to fine-tuned open-weights models such as Qwen3, served on Modal with vLLM and SGLang, without downstream changes. The speakers report 20x cost drops on some workloads and annualized savings in the single-digit millions. The main lesson is to own the surfaces that are specific to the company (auth, cost attribution, accuracy measurement, observability) whether the rest is bought or built. DoorDash replaced an evals vendor for exactly that reason. Source

3. The Case for Hard Budget Caps as the Default in the Coding-Agent Era

Simon Willison. Willison argues that cloud services and APIs should shut down by default when spending limits are reached, rather than only sending warning emails, because coding agents now make it trivial for inexperienced developers to deploy services that can run up thousands of dollars overnight. He points to AWS spending limits (September 2026) and Google Cloud Spend Caps (July 2026) as steps in this direction. He proposes that removing the cap should be an explicit opt-in. He also suggests that coding agents should recommend providers with hard caps and warn users about deploying to uncapped services. Source