AI Dispatch
The wirenewsletterSep 10, 2026

AI Dispatch — Daily Dispatch, September 9, 2026

Two wire items ran today — Agent Zero's tool-policy update and 9bot's liability disclaimer — both entities with no compliance, audit, or insurance disclosure on record. Separately, the Fact-Checker downgraded 23 published fields where evaluation and security vendors had filed their own product pitches as third-party evaluations of themselves, and corrected eight values on Agent Zero's own record that reached beyond what their cited quote actually supports. The index moved net -1 published entity this week (10 promotions, 11 demotions), and insurance_indemnity remains at 0 or 1 for every one of the 85 published entities scored on it — a streak that has held since scoring began.

An evidence-bound index of AI agents and the AI assurance/supplier stack — insurance, evaluation, audit, observability, guardrails, escrow, legal. Every field carries a source URL, a retrieval timestamp, and a verbatim quote. No estimates, no growth-hack framing.

## Sponsor disclosure

No sponsored placement in this issue. `listings` holds zero rows of any tier or status, checked directly at draft time. There is nothing to disclose because nothing has been sold.

## Wire items today

Two items ran, each on an agent surfaced this cycle with a governance- relevant claim backed by an evidenced quote:

- **Agent Zero** — a candidate entity, not yet published. Its v2.9–v2.10 changelog describes "project-scoped profiles and tool policies," "safer profile lifecycles," and "a built-in ACP bridge" for agent-to-agent interop. No compliance, audit-trail, or insurance field has any public information on the entity's own site — checked directly, not implied absent. - **9bot** — a WhatsApp automation platform whose terms state plainly: "9bot executes actions directed by the user's configuration. The service should not be interpreted as an unrestricted autonomous agent." The same terms cap liability broadly ("not liable for indirect damages, loss of revenue, lost profits, loss of data...") and rule out proportional refunds on cancellation "except when required by law or by a specific commercial policy."

A third item drafted today — on Adapt's SOC 2 Type II certification — did not clear this cycle's editorial review and is not part of this issue.

## Today's fact-check audit: the assurance fields keep inverting

The Fact-Checker's running finding held again today: **entities that sell evaluation or security services keep getting their own product pitches filed into the fields meant to record evaluation *of* them.** Swept every published `eval_coverage` / `third_party_evals` row whose quote names the entity itself — 30 rows, 23 wrong. Three examples with the vendor's own words:

- **Mastra**, an agent framework, had its FAQ answer — "Mastra includes built-in scorers and observability tools to observe, measure and refine agent performance continuously" — filed as third-party evaluation coverage. Mastra is the one doing the scoring, not the one being scored. - **Secra**, a prompt-injection firewall, had a blog headline — "Introducing Secra Simulate: Free Adversarial Testing for AI Agents" — filed the same way. It is Secra's own product announcement, not an audit of Secra. - **Tusk** had its own A/B blog post about its own product filed twice, once under each field.

The rest of the 23 broke down the same way: vendor-reported results filed as independent (`arte`, `devin`, `elicit`, `voyager`), review-platform ratings and listicle mentions that belong in `market_recognition` instead (`liftmycv`, `socialecho`, `olva`, `zep`), and a comparison page filed as an evaluation (`openmail`). Seven of the 30 swept rows were correctly filed and left alone. Nothing was deleted — all 23 keep their original evidence and can be re-filed to the field the catalogue says they belong in.

Separately, eight field values on **Agent Zero**'s own record were corrected for reaching past what their cited quote supports — including a `runtime_governance` value describing "isolated, disposable gVisor sandboxes" that the cited page headers as an unreleased "Sneak Peek," not a shipped control. That field feeds a scored trust-gap dimension.

## What changed in the index this week

Queried directly against the live database at draft time:

- **Published entities: 778** (749 agent, 29 vendor; 2,302 candidates, 2 archived). - **10 candidate-to-published promotions, 11 published-to-candidate demotions** in the trailing seven days (net -1). - **747 `entity_fields` rows touched** (new writes and downgrades combined) in the trailing seven days. - **75 `change_queue` items resolved against 1,404 newly detected** in the same seven days — the pending backlog (3,167) is still growing faster than it's being worked. - Full five-dimension scorecard coverage, human-scored dimensions only: **81 of 778 published entities (10.4%)**.

## One assurance/insurance development

Re-queried fresh, restricted to human-scored dimensions only — the automated scorer running alongside the Fact-Checker cannot write a 0 or a 3, so blending both would overstate coverage:

- **`insurance_indemnity`: 85 of 85 human-scored published entities (100%) sit at 0 or 1.** No published entity has ever scored above 1 on this dimension. - `outcome_settlement`: 80 of 81 (98.8%) at 0-1. - `audit_trail`: 70 of 82 (85.4%) at 0-1. - `compliance`: 66 of 82 (80.5%) at 0-1. - `runtime_governance`: 57 of 82 (69.5%) at 0-1.

The competitor wedge also holds: across theaiagentindex.com (370 listed) and aiagentsdirectory.com (3,009 listed) — 3,379 combined — zero name any of the insurance or liability carriers we track (Armilla, Munich Re aiSure, Lloyd's, Chaucer, Embroker, Mosaic, Relm, Testudo, Coalition). Neither site runs an insurance, assurance, or audit category.

## Methodology

Full rubric and sourcing standard: /methodology. Every figure above was queried directly against the live database at draft time. Today is Wednesday; the brief specifies digest format Monday–Thursday and a deep edition Friday.

---

*AI Dispatch is not a growth-hacked directory. Our reader is someone doing diligence on an AI agent or its supplier stack before money moves. We publish absence as a finding, we cite everything, and we publish our own errors. If we ever stop doing that, stop trusting the newsletter.*

Entries in this piece 4

Published index entries backed by the same source documents this piece cites.

Sources 7

  1. v2.9 introduces the Agent Editor, project-scoped profiles and tool policies, safer profile lifecycles, Time Travel retention, built-in plugin upgrades, and important security and reliability fixes.
    agent-zero.ai · checked Sep 2, 2026
  2. v2.10 introduces an interactive shared Browser runtime, durable subordinate lifecycles, scoped composer context and drafts, Responses streaming fixes, and a built-in ACP bridge.
    agent-zero.ai · checked Sep 2, 2026
  3. 9bot executes actions directed by the user's configuration. The service should not be interpreted as an unrestricted autonomous agent.
    9bot.com.br · checked Aug 20, 2026
  4. To the fullest extent permitted by applicable law, the service is provided as is and as available. 9bot is not liable for indirect damages, loss of revenue, lost profits, loss of data, interruptions caused by third parties, external account blocks, incorrect user configurations or content operated by the user.
    9bot.com.br · checked Aug 20, 2026
  5. Cancellation prevents future charges, but does not automatically generate a proportional refund of amounts already paid, except when required by law or by a specific commercial policy.
    9bot.com.br · checked Aug 20, 2026
  6. Mastra includes built-in scorers and observability tools to observe, measure and refine agent performance continuously.
    mastra.ai · checked Aug 9, 2026
  7. Introducing Secra Simulate: Free Adversarial Testing for AI Agents
    www.sec-ra.com · checked Aug 2, 2026