The real story here is in the research—distributed attacks on persistent AI control systems and LLM unlearning evaluation are shipping before the safety monitoring to catch them. LACUNA's localization testbed for unlearning matters because it's the first real attempt to measure whether you can actually remove knowledge from models at inference time, not just pretend you did; this closes a gap between what vendors claim and what's actually happening under the hood. Skip the agent philosophy papers and news noise—focus on the infrastructure: llama.cpp's incremental releases and Transformers v5.13.0 are the unsexy backbone that lets researchers actually *build and test* safety interventions, which is where the real risk lives. The distributed attacks paper should terrify anyone deploying multi-agent systems in production; it's not theoretical if your control plane assumes agents won't coordinate against you.