Everything Old Is New Again Field Notes on Startups

Fine-tuning is not a company anymore

ai-startupsdefensibilityagent-infraharnessai-infradiligencepatterns

The defensibility surface for agent-shaped AI startups is migrating to the harness layer, the runtime that owns state, policy, authorization, retry, and model-swap. Most teams ship glue code instead, and pay a re-architecture cost on every model release.

Supply-chain guardrails for coding agents

securitysupply-chaincoding-agentsgovernancepatterns

Publish-age staging plus disabling postinstall scripts closes the pre-CVE window on most recent supply-chain attacks — the window coding agents make newly dangerous. One config line per package manager; ship it today.