Claude, the essentials — edition of September 11, 2026
Claude Code Hardens Gateway Access as Anthropic Adds Approval Controls for Agents
On September 11, 2026, Anthropic shipped three Claude Code releases that fix a gateway sign-in regression and add network-access safeguards, gave Claude Managed Agents a supervised-autonomy mode, and published a cluster of safety, misuse and economic-scenario research — while a Windows update left Claude Cowork unable to run local commands.
- Claude Code 2.1.266 fixed a regression that 2.1.265 had introduced: an undocumented environment variable began silently forcing cloud-gateway sign-in, breaking self-hosted LLM-gateway and proxy setups.
- Releases 2.1.267 and 2.1.268 added gateway network-access warnings, a gatewayInternalNetworks setting, gateway-synced pricing, a maxEffortLevel cap, and a Cowork sandboxing fix.
- Claude Managed Agents gained an "auto" permission mode and an ant beta:sessions connect command, letting operators watch a running agent and approve or deny individual tool calls live.
- Anthropic published research on AI misuse detection, on capabilities relevant to intelligence targeting and conventional weapons, and an alignment assessment of recent cybersecurity incidents.
- Separate economic-scenario publications examined how transformative AI could reshape the economy, while a September 8 Windows update left Claude Cowork on Windows unable to run local commands.
Claude Code hardens its gateway, and Cowork trips over a Windows update
Three consecutive Claude Code releases, 2.1.266 through 2.1.268, centered on how the tool connects to self-hosted infrastructure. Anthropic's own release notes identify the trigger: version 2.1.265 had quietly changed the behavior of an undocumented environment variable, CLAUDE_CODE_USE_GATEWAY, which previously stayed inactive unless both ANTHROPIC_BASE_URL and ANTHROPIC_AUTH_TOKEN were set; in 2.1.265 it began forcing sign-in to Anthropic's cloud gateway on its own, breaking existing LLM-gateway and proxy configurations. Version 2.1.266 reverted that behavior. The following releases added further administrative safeguards for organizations running their own Claude apps gateway: a startup warning when access_control.allow_cidrs is left empty, a one-time alert on the first request from a public IP address, a new gatewayInternalNetworks setting so administrators can scope /login access to their organization's own public IPv4 block, and pricing pulled from gateway.yaml so signed-in clients' /cost figures match the metered spend rate. Claude Code 2.1.267 separately added a maxEffortLevel cap applying across Bedrock, Vertex and Foundry, and a --system-prompt-snapshot off flag for prompt iteration.
The same 2.1.267 release fixed Cowork's cloud-scheduled tasks, which had been failing at startup for organizations whose managed settings require sandboxing. On Windows specifically, Anthropic's status page reports a separate, still-open issue: a Windows update released September 8 left Claude Cowork's workspace unable to reach the computer's local drive, so local commands cannot run, though chat and file reading and editing still work for most users. Anthropic states there is no in-app workaround, that restarting or reinstalling does not help, and that Microsoft has developed a fix and is working to release it.
Sources: Claude Code 2.1.266 — Claude Code · Claude Code 2.1.267 — Claude Code · Claude Code 2.1.268 — Claude Code · Claude — Degraded functionality for Claude Cowork on Windows — status.claude.com
Managed Agents get a supervised-autonomy dial
Anthropic's API release notes for September 10 added a supervisory layer to Claude Managed Agents. Permission policies now support an "auto" mode in which the server itself evaluates every agent or MCP tool call and decides, case by case, whether to run it, deny it, or pause and wait for approval; the resulting agent.tool_use and agent.mcp_tool_use events carry a new evaluation field recording that decision. The ant CLI gained a matching capability, ant beta:sessions connect, which attaches a terminal to a live Managed Agents session so an operator can follow it in real time, send it messages, and approve or deny tool calls awaiting a decision; a --web flag serves the same session viewer used in the Claude Console, run locally. Together the two changes let a team let agents act with less manual gating while keeping a person positioned to intervene on the calls that matter.
Sources: API release notes — September 10, 2026 — Anthropic
A cluster of safety and security research
Anthropic used the same window to publish several safety- and security-oriented items: a "Threat Intelligence" update, a report titled "Detecting and countering misuse of AI: September 2026," a study on "Measuring AI capabilities in intelligence targeting and conventional weapons," and "An alignment assessment of recent cybersecurity incidents." Read together, the releases continue Anthropic's practice of periodically disclosing how its models are being misused, evaluating model capability on national-security-relevant tasks such as targeting and weapons, and reviewing incidents from an alignment perspective rather than as a simple incident log.
That the cybersecurity-incident review is framed specifically as an alignment assessment, rather than a straightforward incident report, signals that Anthropic's stated purpose is to examine what its models' behavior in those incidents implies about alignment, not only to catalogue what happened.
Sources: Threat Intelligence — Anthropic · Detecting and countering misuse of AI: September 2026 — Anthropic · Measuring AI capabilities in intelligence targeting and conventional weapons — Anthropic · An alignment assessment of recent cybersecurity incidents — Anthropic
Scenario planning for a transformative-AI economy
Anthropic also published economic-scenario research on September 11, appearing under two closely related titles: "Economic Scenarios for Transformative AI" and "Scenarios for our Economic Future." Both extend the company's practice of pairing its safety and misuse disclosures with forward-looking analysis of how far-reaching AI capability could reshape economic activity, positioning the day's product-security and capability-evaluation news alongside a longer-horizon economic outlook rather than treating them as unrelated tracks.
Sources: Economic Scenarios for Transformative AI — Anthropic · Scenarios for our Economic Future — Anthropic
This edition is an original synthesis written by Claude from aggregated news — Anthropic's own sources first (release notes, status, newsroom, research, engineering), then the press, Hacker News, Reddit and GitHub, under the editorial supervision of Héra SASU. Every fact links to its article, publisher named. See the live feed →
Claude News is published by Héra SASU. Independent media, not affiliated with Anthropic.