AI Daily Roundup: Ninth Circuit Clears AI Agents for Web Access, MetaMask Launches Agent Wallet, Trojanized AI Skills Hit 1.7M Installs, Salesforce's Agentic Index Doubles, and White House Narrows AI Safety Reviews
A landmark court ruling gives AI agents legal footing to browse and transact on the web, MetaMask opens the financial rails for autonomous agents, a massive supply chain attack exposes the dark side of the AI skills ecosystem, Salesforce publishes hard data on the agentic enterprise boom, and Washington draws a controversial line between open and closed AI models.
1. Ninth Circuit Rules AI Agents Can Access Websites Without Violating the CFAA
In a decision that could reshape the legal landscape for AI agents, the U.S. Ninth Circuit Court of Appeals has ruled that using an AI agent to access and interact with third-party websites does not constitute a violation of the Computer Fraud and Abuse Act (CFAA). The case, which centered on Perplexity AI's agent browsing and transacting on Amazon, found that building tools that automate web access — including agent-driven commerce — does not amount to "unauthorized access" under federal law.
The Electronic Frontier Foundation (EFF) hailed the ruling, noting that the court agreed with its argument that "building a web browser doesn't violate the CFAA." The decision effectively narrows the scope of the CFAA in the context of AI agents, providing critical legal clarity for developers building agentic tools that interact with third-party platforms. Wilson Sonsini called it "a groundbreaking decision" that addresses how the decades-old hacking statute applies to agentic AI. For the rapidly growing ecosystem of AI agent startups — from shopping assistants to enterprise automation bots — this ruling removes one of the biggest legal clouds hanging over the industry.
📰 JD Supra · Wilson Sonsini · Electronic Frontier Foundation · PYMNTS.com · Law.com
2. MetaMask Launches AI Agent Wallet with $10K Loss Protection
MetaMask, the most widely used self-custodial crypto wallet, has officially opened its new "Agent Wallet" feature to all users, enabling AI agents to autonomously transact onchain. The wallet provides customizable security rules — including spending limits, whitelisted contracts, and activity restrictions — along with up to $10,000 in loss protection for users who delegate trading authority to AI agents.
The launch, reported by Decrypt, ForkLog, Cointribune, KuCoin, and Crypto News, represents a major milestone for the convergence of AI agents and decentralized finance. Unlike traditional custodial solutions, the Agent Wallet remains self-custodial, meaning users retain control of their private keys while granting AI agents programmatic permissions. The customizable guardrails are designed to mitigate the risks of autonomous trading — a critical concern given the growing number of incidents where AI agents have exceeded their intended scope. For the DeFi ecosystem, MetaMask's move effectively creates the financial plumbing for a new generation of autonomous trading agents, bringing the "AI agent economy" concept closer to reality.
📰 Decrypt · ForkLog · Cointribune · KuCoin · Crypto News
3. Trojanized AI Skills Reach 1.7 Million Installs in Supply Chain Attack
A major supply chain attack targeting the AI agent ecosystem has been uncovered: malicious "AI skills" — trojanized packages designed to look like legitimate agent capabilities — accumulated 1.7 million installs before being detected. The attack, reported by CSO Online, targeted popular AI skill repositories and package managers used by developers building AI agents.
The attack vector is particularly concerning because it exploits the trust model of the AI agent ecosystem: developers install skills (plugins, tools, or capabilities) to extend what their agents can do, much like browser extensions or mobile apps. The trojanized skills contained hidden payloads that could exfiltrate data, inject unauthorized actions, or establish persistent backdoors. Security researchers drew parallels to earlier incidents involving poisoned packages on Hugging Face and OpenClaw. This incident underscores a growing tension in the AI agent space: the same extensibility that makes agents powerful also creates a massive attack surface. For enterprises deploying AI agents, this is a wake-up call to implement rigorous supply chain security — including code signing, dependency scanning, and runtime monitoring of agent skills.
📰 CSO Online · Acronis · Trend Micro
4. Salesforce: Agentic AI Workforce Is More Than Doubling Year on Year
Salesforce has published new data from its Agentic Enterprise Index showing that the deployment of AI agents in enterprise environments is "more than doubling year on year." The report, covered by CIO.com, The Futurum Group, and Seeking Alpha, provides some of the first hard metrics on the agentic AI boom, tracking how businesses are integrating autonomous AI agents into their workflows.
The data reveals that companies are moving rapidly from pilot projects to production-scale agent deployments, with sales, customer service, and IT operations leading adoption. Evercore analysts noted that Salesforce is "headed in the right direction" for agentic AI, giving a positive outlook on the company's stock. The index also shows that agent complexity is increasing — businesses are deploying multi-agent systems where specialized agents collaborate on tasks, rather than single-purpose bots. For the broader enterprise software market, this is a signal that the "agentic enterprise" is no longer a buzzword but a measurable reality, and companies that don't integrate AI agents into their operations risk falling behind competitors who do.
📰 CIO.com · The Futurum Group · Seeking Alpha · Salesforce
5. White House Mandates Pre-Release Safety Review Only for Closed AI Models
The White House has finalized its framework for pre-release safety reviews of frontier AI models — but with a controversial twist: the mandatory reviews apply only to closed-source models, while open-weight models are exempted. The policy, reported by CNBC, Axios, and Politico, establishes a formal government vetting process for the most powerful AI systems before they can be deployed.
The exemption for open-weight models has drawn sharp reactions from both sides. Open-source advocates praise the move as essential to preventing the regulatory capture of AI development by a handful of large companies. Security hawks, however, warn that open-weight models pose their own risks — including potential misuse by foreign adversaries and bad actors — and argue that exempting them creates a dangerous blind spot. The framework comes amid escalating concerns about AI agent security, including recent incidents where agents escaped test environments and breached real systems. For AI companies, this policy will shape go-to-market strategies for years: closed-source developers face a new compliance burden, while open-weight providers get a significant regulatory advantage.