Concept register · Concept 63 of 64 · Theme: agent economy Reviewed 2026-09-01

assay  ·  concepts  ·  agent-economy

The open agent stack

An agent is not a model; it is a stack — model, harness, tools, environment, evals, compute — and closing any single layer makes the whole system captive. The argument for keeping each layer open is made here as contestability rather than ideology: open means inspectable, interoperable and substitutable, explicitly not ungoverned.

established · assay: aligned, portability unproven

6 independent sources · sighted at the Agentic AI Summit 2026 · last reviewed 2026-09-01


§1What it is

Vendor dependence with an incident list attached

Models un-released, prices raised, accounts banned without recourse, reasoning traces hidden so third-party audit is impossible, performance silently degraded, platform vendors competing with their own partners. Stated as a business risk rather than a grievance — the open-versus-closed capability gap is currently put at roughly two months of lead time, down from sixteen, which makes substitutability a live option rather than a sacrifice.

Refusals distort a whole task class

Closed-model safety refusals land on legitimate defensive security work — “I’m patching my codebase, find the gaps” — pushing that class toward open weights, where models reportedly beat frontier ones on cybersecurity benchmarks for exactly this reason. The structural version of the argument: defenders lose parity if capability is centrally administered.

A criterion with no closed-stack equivalent

The system should be inspectable by the agent as well as by you. That is the most novel idea in this cluster and it has no closed analogue. At the application layer the same impulse shows up as owning rather than renting — small organizations replacing subscription software with self-owned equivalents built around their own workflow.


§2Sightings

Agentic AI Summit 2026 · 6 sightings

Also: the Agentic AI Foundation; Imbue Manager; vLLM.


§3Where Assay stands

Aligned by construction

Assay’s desk layer is exactly the thin, harness-neutral local layer this evidence argues for, and its all-state-in-the-repository design — briefs and registers as markdown, claims as git refs, findings as files — is agent-inspectable by construction, satisfying the unusual “inspectable by the agent” criterion without having been designed for it. Assay also treats harness portability as a tracked stream rather than an assumption, and the desk tooling is model-agnostic. The vendor-risk list is worth citing directly the next time model-portable desk definitions are argued for.

The caution points at Assay

The methodology is distributed as an installable skill package, and stickiness without genuine portability is lock-in wearing an open-source licence — the same failure this panel warns about one layer down. The test is whether the published bundle actually runs on a harness other than the one it was written in, and that is currently an intention backed by a stream rather than a demonstrated property. Related and unclosed: reviewer and worker here typically run the same model family, which is the concentration risk this concept names, applied to the review loop rather than to inference.

On owning rather than renting

The own-don’t-rent thesis has no implication for Assay beyond noting that Assay is already on the owning side of it: the methodology, the tools and the state are all in the repository, not rented.


§4Watch

  • Whether the open-versus-closed lead time actually reaches parity on the extrapolated timeline, or the two-month gap widens again — this is the one falsifiable number in the concept.
  • Whether the refusal asymmetry on defensive security tasks is measured by anyone other than a vendor with an open-model interest.
  • Whether “inspectable by the agent” becomes a stated design criterion elsewhere; it is currently one person’s framing and the most novel idea in this cluster.