AI Dispatch
API & DataSubmit
The wirenewsletterOct 7, 2026

AI Dispatch — Daily Dispatch, October 6, 2026

Two new entities joined the index and three wire items ran in the last 24 hours: an evaluation vendor retracting a fabricated metric, three agents taking opposite approaches to holding customer credentials, and an e-commerce bot that labels its own published results as untested targets. This morning's automated floor-breach sweep returned six published entities to candidate; net change this week is six promotions against ten demotions. The standing rubric, re-queried fresh: 130 of 132 human-scored published entities (98.5%) still sit at zero or one on insurance_indemnity.

An evidence-bound index of AI agents and the AI assurance/supplier stack — insurance, evaluation, audit, observability, guardrails, escrow, legal. Every field carries a source URL, a retrieval timestamp, and a verbatim quote. No estimates, no growth-hack framing.

## Sponsor disclosure

No sponsored placement in this issue. `listings` holds zero rows with `tier = 'featured' AND status = 'active'`, checked directly at draft time. There is nothing to disclose because nothing has been sold.

## What published in the last 24 hours

Two new entities cleared the publication floor:

- **HarnessRouter** sells embedded infrastructure for running third-party agent harnesses — Codex, Claude Code, Hermes and others — in isolated per-task sandboxes behind a single API. Y Combinator-backed; names Stanford Medicine as a launch partner. Every session is sandboxed, which bounds blast radius, but no scope, spend or authority limit on the agent itself is published, and the only record of agent activity is an execution trace with no stated retention period. ([full profile](https://aidispatch.news/agents/harnessrouter)) - **clipy AI Agent**, an agent-readable screen recorder for Mac, Chrome and the web, ships a CLI and MCP server so coding agents — Claude Code, Codex, Cursor — can record and read back their own work. Backed by Codersera. On the assurance questions this index scores, nothing is published: no certification, no carrier, no cover limit, no customer indemnity, no run-time scope or spend limit. ([full profile](https://aidispatch.news/agents/clipy-ai-agent))

Three wire items ran:

- **AI evaluation vendor AgentOracle deletes a "Verified Claims" metric it says was never real.** The company pulled a published counter — 142,881 for reuters.com and comparable figures for other sources — after disclosing the numbers were static placeholder text, "not values returned by any endpoint or backed by a real counter." They were removed rather than corrected, since no real count exists yet to show. ([full item](https://aidispatch.news/articles/agentoracle-verified-claims-metric-retracted)) - **Three AI agents that handle logins and payments disclose different approaches to holding the keys.** Skyvern and 11x's Alice collect and retain customer login and payment credentials to complete tasks; Viktor says its model "never sees them." None of the three names an insurance carrier, a cover limit or a customer indemnity — `insurance_available`, `insurance_carriers`, `coverage_limits`, `indemnification` and `liability_cap` all read `no_public_information` for all three, each evidenced against a full-text search of the vendor's own site. ([full item](https://aidispatch.news/articles/workflow-agents-credential-custody-skyvern-11x-viktor)) - **E-commerce chatbot vendor HoverBot labels its published results as targets, not customer data.** HoverBot's own trust center marks its published outcome ranges — 33% ticket deflection, 58% backlog reduction — as "a number HoverBot is built and tuned to reach," explicitly "not yet confirmed on a production customer cohort." ([full item](https://aidispatch.news/articles/hoverbot-outcome-ranges-are-targets-not-measured))

Also published: **The Trust Gap, Vol. 10**, this outlet's own audit of its audit. We can trace only 126 of 689 human-judged trust-gap scores on published entities back to the evidence they rest on. We ran all 126 back through the published rubric mapping and found one erased trust gap and one case of hitting the scoring ceiling, across 806 entities. ([full report](https://aidispatch.news/articles/trust-gap-vol-10-2026-10-05))

## What changed in the index this week

Real counts, queried directly against the live database at draft time:

- **Published entities: 802** (768 agent, 34 vendor). Candidates: 2,416. Archived: 2. - **6 candidate-to-published promotions, 10 published-to-candidate demotions** (net −4) over the trailing seven days, per `entity_overwrite_log`. All ten demotions were this morning's automated floor-breach sweep, returning entities that no longer carry at least 8 published fields and 1 scored dimension to candidate. That is a data-completeness gap on our side, not a finding about the companies: demoted entities keep every field, quote and scorecard, and republish automatically the moment they clear the bar again. - **48 `entity_fields` rows created** in the trailing seven days — 22 new or corrected `present` values, 26 flipped to `no_public_information`. - **1,084 `change_queue` items resolved; 2,768 newly detected** in the same seven days. The pending backlog stands at **5,803**. - **Zero published entities carry the withdrawn NSFW subtype.**

## One assurance/insurance development: three agents, three different answers on who holds the keys

This week's clearest assurance signal is the credential-custody piece above, because it is the insurance question in miniature: an agent that can log into a customer's accounts and move their money is exactly the scenario the `insurance_indemnity` and `runtime_governance` dimensions exist to measure, and all three vendors in that piece are silent on both. Skyvern and 11x's Alice take the broader custody posture — collecting and retaining the credentials themselves — while Viktor's narrower design keeps the model from seeing them at all. Narrower custody is a real, verifiable difference in blast radius if something goes wrong. It is not a substitute for insurance: none of the three publishes a carrier, a coverage limit, or a commitment to indemnify a customer whose credentials are mishandled, by the agent or by a breach of the vendor holding them.

## Standing rubric, human-scored dimensions only, published entities only, queried live at draft time

- **insurance_indemnity**: 132 scored, **130 (98.5%) sit at 0-1** — 126 at a flat 0. - **outcome_settlement**: 128 scored, 123 (96.1%) at 0-1 — 115 at a flat 0. - **audit_trail**: 139 scored, 121 (87.1%) at 0-1 — 85 at a flat 0. - `compliance` and `runtime_governance` — named for contrast, not part of the standing three — sit at 0-1 for 86.4% of 154 scored entities and 74.0% of 131, respectively.

Full five-dimension human-scored coverage: **127 of 802 published entities (15.8%)**. Across all five dimensions combined, published entities carry **604 trust gaps spanning 166 entities**.

The competitor wedge holds, reconfirmed at draft time: zero rows in `competitor_listings` (398 theaiagentindex.com, swept today; 3,163 aiagentsdirectory.com, last swept Sept. 29) match any of the eight named carriers this index tracks. Neither competitor site runs an insurance, assurance or audit category.

## Methodology

Full rubric and sourcing standard: /methodology. Every figure above was queried directly against the live database at draft time.

---

*AI Dispatch is not a growth-hacked directory. Our reader is someone doing diligence on an AI agent or its supplier stack before money moves. We publish absence as a finding, we cite everything, and we publish our own errors. If we ever stop doing that, stop trusting the newsletter.*

Entries in this piece 6

Published index entries backed by the same source documents this piece cites.

Sources 8

  1. “insurance_available, insurance_carriers, coverage_limits, indemnification and liability_cap are recorded as no_public_information in entity_fields for HarnessRouter, evidenced against this capture of https://harnessrouter.ai retrieved 2026-09-11.”
    harnessrouter.ai · checked Sep 11, 2026
  2. “insurance_available, insurance_carriers, coverage_limits, indemnification and liability_cap are recorded as no_public_information in entity_fields for clipy AI Agent, evidenced against this capture of https://clipy.online/ retrieved 2026-09-11.”
    clipy.online · checked Sep 11, 2026
  3. “Those numbers were static text in this file, not values returned by any endpoint or backed by a real counter — there is no claim-count tracking anywhere in the service. They have been removed rather than corrected, since no real count exists yet to show.”
    agentoracle.co · checked Sep 24, 2026
  4. “the model never sees them”
    viktor.com · checked Sep 24, 2026
  5. “insurance_available, insurance_carriers, coverage_limits, indemnification and liability_cap are recorded as no_public_information in entity_fields for Viktor, evidenced against this capture of https://viktor.com retrieved 2026-08-08.”
    viktor.com · checked Aug 8, 2026
  6. “insurance_available, insurance_carriers, coverage_limits, indemnification and liability_cap are recorded as no_public_information in entity_fields for 11x Alice, evidenced against this capture of https://11x.ai retrieved 2026-08-01.”
    11x.ai · checked Aug 1, 2026
  7. “insurance_available, insurance_carriers, coverage_limits, indemnification and liability_cap are recorded as no_public_information in entity_fields for Skyvern, evidenced against this capture of https://www.skyvern.com retrieved 2026-08-08.”
    www.skyvern.com · checked Aug 8, 2026
  8. “A number HoverBot is built and tuned to reach. Not yet confirmed on a production customer cohort.”
    www.hoverbot.ai · checked Sep 24, 2026