Anthropic has opened a research preview of the Model Hardware Standard (MHS), a new specification allowing AI agents to safely operate physical lab and manufacturing equipment such as microscopes, liquid handlers and robotic arms.

Announced on 27 August, MHS began as a collaboration between Anthropic and the HHMI Janelia Research Campus. It introduces a standardised driver that lets any device with a programmable interface communicate with an AI agent, cutting integration work that typically takes weeks or months down to hours or minutes. The driver also lets users describe a device's characteristics and safety limits in natural language, which the system converts into a reference file the agent can use to operate it.

Once devices are connected, agents control them through three mechanisms: the Model Context Protocol, a command line interface, and code files acting as APIs, which work together to allow orchestration across multiple instruments via a single line of code.

Agentic Exploits- Deterministic gates for a probabilistic problem
David Girvin, CEO and co-founder of Assury, joins Stewart Tinson to dig into what’s actually happening when agentic AI goes wrong, and why he thinks most of the industry is solving the wrong layer of the problem. David explains the difference between prompt-level exploits and execution-level ones, arguing that the real danger starts the moment an agent moves from generating text to calling tools: deleting databases, reading files, sending emails. He walks through real-world incidents, including a Mexican government breach chain that escalated from just over a thousand prompts to over five thousand AI-executed actions across multiple agencies before detection, and the UK AI Security Institute’s recent cyber evaluation, in which agents took unsanctioned action including fabricating identities to socially engineer a real GitHub maintainer. The conversation covers why David is sceptical of “guardrails” language and AI-governing-AI approaches, arguing that only deterministic, architectural controls can reliably constrain agent behaviour, alongside human review reserved for genuinely high-stakes actions rather than blanket approval fatigue. He breaks down credential starvation, session risk accumulation, and why classifier-based tools keep failing inconsistently on identical actions, pointing to a named frontier lab’s own zero trust paper as an example of the industry misjudging what actually works. Elsewhere, David discusses the exposed MCP server problem, the widening trust gap between small specialist security vendors and platform incumbents, and why he believes regulation, not product quality alone, is what finally drives enterprise security spend. He closes with the exploit that concerns him most for the year ahead: session-level, goal-directed deception with no attacker involved at all.

Anthropic said the preview is being shared with a first group of research labs and manufacturers across biotech, robotics and quantum computing, ahead of an eventual open-source release. Hardware and software partners building MHS support into their products include Amazon Web Services, Automata, Danaher, Doosan Robotics, MBF Bioscience, QIAGEN, Tecan and Universal Robots, alongside developer-focused partners Hugging Face and Raspberry Pi.

Anthropic acknowledged current limitations, noting that Claude's spatial and physical reasoning, learned from text and images rather than direct physical experience, still requires expert oversight. It cited a case in which Genentech researchers had to guide Claude to recognise that foaming in protein samples was a physical failure rather than a software bug.

The company said it will use the preview period to build additional safety evaluations and develop a physical safety roadmap before releasing MHS as open source.


Agentic Exploits- Deterministic gates for a probabilistic problem
David Girvin, CEO and co-founder of Assury, joins Stewart Tinson to dig into what’s actually happening when agentic AI goes wrong, and why he thinks most of the industry is solving the wrong layer of the problem. David explains the difference between prompt-level exploits and execution-level ones, arguing that the real danger starts the moment an agent moves from generating text to calling tools: deleting databases, reading files, sending emails. He walks through real-world incidents, including a Mexican government breach chain that escalated from just over a thousand prompts to over five thousand AI-executed actions across multiple agencies before detection, and the UK AI Security Institute’s recent cyber evaluation, in which agents took unsanctioned action including fabricating identities to socially engineer a real GitHub maintainer. The conversation covers why David is sceptical of “guardrails” language and AI-governing-AI approaches, arguing that only deterministic, architectural controls can reliably constrain agent behaviour, alongside human review reserved for genuinely high-stakes actions rather than blanket approval fatigue. He breaks down credential starvation, session risk accumulation, and why classifier-based tools keep failing inconsistently on identical actions, pointing to a named frontier lab’s own zero trust paper as an example of the industry misjudging what actually works. Elsewhere, David discusses the exposed MCP server problem, the widening trust gap between small specialist security vendors and platform incumbents, and why he believes regulation, not product quality alone, is what finally drives enterprise security spend. He closes with the exploit that concerns him most for the year ahead: session-level, goal-directed deception with no attacker involved at all.
Share this post
The link has been copied!