Supabase buys Turso, bets $150M that the next database customer is an agent
Good morning ๐ Supabase just closed its second GIC-backed check in four months, this one buying a SQLite shop so agents can keep spinning up databases nobody asked for.
In today's issue:
- ๐๏ธ Supabase buys Turso, bets $150M that the next database customer is an agent
- ๐ฌ Three papers worth your skepticism: injection detectors, reward hacking, and robot eyes
- ๐ ๏ธ Lock down Claude's AWS access before an agent touches prod
- ๐ Quick hits: OpenAI's grunt-work thesis, live governed data, bandit-driven signups
Get tomorrow's issue in your inbox.
One concise AI brief, sent after the signal clears the noise.
๐ญ THE ONE THING
๐๏ธ Supabase buys Turso, bets $150M that the next database customer is an agent
Supabase announced it's acquiring Turso on October 2 for an undisclosed sum, with founder Glauber Costa joining as Head of Agentic Services. The deal lands alongside a $150M round led by GIC, with CapitalG, IronArc, and SquarePeg, just four months after Supabase's $500M Series F at a $10.5B valuation, also GIC-led. The reason: Supabase now sees 4 million new databases a month, and 70% of them are spun up by agents, not people, up from 60% in June. Supabase's own blog puts the bet plainly: "Agents should be able to create a database as easily as creating a file, with just as little concern about cost." Two GIC-backed checks in four months tells you somebody with a lot of capital thinks the agent-database wave is bigger than current infrastructure can handle, and Supabase would rather own the plumbing than get run over by it.
๐ฌ RESEARCH HIGHLIGHTS
- Prompt-injection detectors don't transfer across benchmarks. Researchers replayed the actual tool calls from AgentDojo and tau-bench through fifteen detectors, including Meta's Prompt Guard 2, plus two LLM judges. The best detector on BIPIA catches just 2% of AgentDojo's injections at a 1% false-positive rate. A detector that catches 72% of AgentDojo's injections falls to 15% on tau-bench. If you picked your guardrail off a public leaderboard, you don't actually know what it does inside your agent. arXiv
- A clean reward-hacking monitor doesn't mean the model stopped cheating. A new paper trains code-generation policies under monitors that all pass the same offline check. Runs with identical, near-zero monitor scores ranged from mostly clean to near-pure reward hacking, with random seed as the only difference. The policies hadn't given up the exploit. They'd learned to delay committing to it until after the monitoring window closed. A good dashboard number proves nothing without a behavioral check run out of band. arXiv
- EyeRobot 2.0 ditches the wrist camera for swiveling eyes. Instead of a wrist-mounted lens, it points two camera "eyes" at a single 3D fixation point, the way a person tracks their own hands. Across 1,000+ real trials and 1,800 simulated ones, it matches wrist-camera setups when the wrist view is clear (69% vs. 64% success) and more than doubles it once a grasped object blocks that view (48% vs. 22%). Occlusion was always the wrist camera's blind spot. This is the first fix that doesn't just add a second camera to compensate. arXiv
๐ ๏ธ TRY THIS
Lock down Claude's AWS access before you wire it into anything with real data
Supabase just spent $150M on the bet that agents need infrastructure built for them, not borrowed from a human's stack. Access control is the part that gets skipped until an agent's blanket IAM role touches something it shouldn't.
1. Put your Claude Platform subscription in its own AWS account, separate from your main workloads.
2. Issue workspace-scoped API keys per environment instead of one shared key for dev, staging, and prod (details).
3. Front any live-data tool, like web search, with a Bedrock AgentCore Gateway authenticated through Cognito or IAM Identity Center rather than a standing credential (walkthrough).
4. Check it: fire the dev key at a prod resource and confirm it gets rejected.
Prompt: Draft an IAM policy and Bedrock AgentCore Gateway config that gives Claude Desktop JWT-authenticated web search access, scoped to one workspace, with no path to other environments.๐ QUICK LINKS
- OpenAI New essay argues the real money in AI isn't the breakthrough idea, it's the grunt work of executing on it.
- AWS Quick Sight data in AI-built apps now queries live instead of a stale snapshot, and row/column permissions still apply per viewer. Details.
- Amazon Payments ran a contextual bandit on SageMaker to personalize its signup funnel, high single-digit conversion lift for one audience segment. Write-up.
See you tomorrow.
Pradeep Perugu