HashiCorp, Expo and Appsmith all concede generation and keep the part that verifies it
The lead
HashiCorp put the day's concession in writing: generating configuration is no longer defensible on its own. HCP Terraform was positioned outright as the control plane for AI agents that author and apply infrastructure themselves — provenance, policy, identity, isolation and audit sold as the product — and a week later Packer v1.16.0 shipped native SLSA provenance generation and verification for machine images. Consul Enterprise 2.0 made the same move on trust, taking CyberArk Workload Identity Manager as an external mesh CA rather than remaining its own. Terraform now sells enforcement rather than authoring.
Two vendors went further and withdrew from generation outright. Expo wound down its Expo Agent closed beta in July, two months after making its MCP server free on every plan, and has now shipped a connection from the Claude desktop app — conceding the assistant layer and defending the build, test and deploy pipeline underneath it. Appsmith ended Appsmith AI datasources with a September 30 kill date and moved the assistant up into the authoring surface instead. Neither is retreating from AI. Both stopped trying to be the thing that produces the output.
What moved
- Judgment shipped as the deliverable. Prowler 5.39.0 attaches a Skills menu to every individual finding, including one that decides whether a finding is real and closes it out — with every write path bound to the asking user's RBAC rather than a service identity. DocsBot paired Operator with an Admin MCP server so an outside agent can administer DocsBot itself, then published a launch-readiness checklist to make that delegation auditable. Wagepoint put an AI reviewer on the payroll screen where mistakes get expensive, and Eightfold AI is collapsing the interview loop, not just the screening round.
- The gate matters more than the generator. Windmill turned AI sessions on by default in beta but kept them behind its existing draft-and-diff review gate, while dropping BigQuery and Snowflake out of Enterprise and running dbt projects unmodified. Sanity's MCP server took three releases in nine days, each either exposing more project administration or closing a way an agent could silently corrupt state. Tracecat moved agents into comment threads while tightening the sandbox around them, and Aha! handed customers the controls over how Elle behaves.
- The model became rotating inventory. GitHub Copilot's picker turned over three times in a week — MAI-Code-1.1-Flash in, MAI-Code-1-Flash out on a September 10 date, Gemini 3.7 Flash rolling in — while Agent Plugins 1.0, shipped by GitHub, is the part meant to last. Baseten deprecated four catalog models as three arrived, and began selling its serving stack to the labs themselves. OpenRouter is making the routing decision the product.
- Callable beat openable. Frill put a ten-tool MCP server on every plan rather than gating it; Canny replaced its Slack slash commands with an @Canny mention that files ideas from any thread; Resend added the Agent Plugins Standard beside its Codex plugin and Claude connector; Surfer shipped the MCP server its May API rebuild promised.
- The R libraries gave work away and kept the interface. ggeffects handed its contrast engine to modelbased; discrim became a thin engine shim after passing its model definitions to parsnip; tidyclust handed finalization back to tune; feasts is splitting in two, moving every plot into ggtime. Underneath them knitr, callr and promises all added OpenTelemetry tracing, turning document builds and R subprocesses into observable pipelines.
Sectors today
Analytics led on volume alone — 93 products, almost all the R and tidymodels back catalogue arriving at once, with dbt Core and OpenMetadata the live exceptions. Devtools held the strategy: Windmill, Prowler, Expo, plus Depot absorbing its own git host and Cursor industrialising cloud agents. Development split between HashiCorp, Appwrite's latency quarter and SvelteKit 3's release candidate. AI-assistants was all control plane: DataRobot and AWS both sell the layer under someone else's agents. Collaboration ran on Double and AFFiNE; customer-support on Canny, Frill and respond.io billing AI by consumption; design on Kittl making AI the entry point. HR-recruiting moved AI to the moment of capture (Spark Hire); project-management sat with RentRedi and Aha!, marketing with Surfer and LaunchNotes. Twilio carried communication-messaging by migrating every account off Functions Classic itself; SRS carried video-conferencing with a 7.0 line on a Go proxy tier. The quiet five shipped increments and no directional move: finance (CloudZero), CRM (Twenty), ecommerce (Canix), lms-edtech (Tutor LMS) and marketing-automation (Sender).
Watch tomorrow
Three dated commitments make this week checkable: Expo's EAS Observe goes GA on August 20, Copilot retires MAI-Code-1-Flash on September 10, and Appsmith's AI datasources stop working on September 30. The open question under the lead is whether verification holds as a position — Prowler's roadmap points at applying skills in bulk across finding groups, which is where a per-finding judgment call first gets tested at scale. Watch too whether Merge pushes Gateway's per-project guardrails across its remaining controls. Crawl caveats unchanged — Metricool, Neil Patel, Process Street, BigTime, Celoxis, Bullhorn and Knowmax published content programs, not releases, and Firefly III keeps emitting nightly builds that state no changelog is included.