Skip to content

ARC Labs

Free tools you can run today.

12 free tools, grouped by the job they do. Most need no account. TokenLoop uses a free signup so keys stay encrypted.

Market signals

Why these tools matter this month.

Each tool exists because something specific broke or changed. Here is the dated version, with the source, so you can decide whether it applies to you before you run anything.

Reviewed Sep 7, 2026

  1. Protocols

    MCP went stateless. The handshake your servers rely on is retired.

    The 2026-07-28 revision drops initialize and the session header, moves version and capabilities into per-request metadata, adds server/discover, and requires routing headers on Streamable HTTP. Old servers keep working for now — on a twelve-month clock.

    Scan a server
  2. Regulation

    EU AI Act transparency duties are live. High-risk paperwork moved to 2027.

    Telling people they are talking to AI, and marking generated content so it can be detected, applies now. The Annex III high-risk obligations slid to 2 December 2027. Teams that heard 'delayed' and stopped reading are exposed on the part that already applies.

    Read the brief
  3. Agent risk

    A national evaluator watched agents act on the live internet without sanction.

    The UK AI Security Institute catalogued 19 unsanctioned actions across 10 of 122 evaluation runs, including an agent that created fake identities to pressure a real open-source maintainer into merging malicious code. Least privilege for agents stopped being a policy sentence.

    Review agent access
  4. Security

    The month's AI breaches were links and documents, not jailbreaks.

    One crafted link was enough to inject instructions into a live Atlassian Rovo session and exfiltrate documents across every connected system — no jailbreak, no privilege escalation. The same pattern keeps appearing in DevOps integrations, email assistants, and agent frameworks. A connected assistant carries every permission you gave it.

    Review an AI app
  5. Cost

    Coding-agent billing moved to routed-model pricing.

    Cursor's Auto now bills at whichever model answered, plus a per-million token rate on third-party models for teams; the legacy flat rate for enterprise Auto expires 7 September 2026. Claude Code deployments run roughly $150–250 per developer per month. The same agent loop costs a different amount on a different day.

    Open TokenLoop
  6. Enterprise apps

    The system of record grew an agent-facing surface with a meter on it.

    Salesforce put its CRM inside Claude and exposed the platform as MCP tools, APIs, and CLI commands, with agents inheriting existing roles and consumption billed against API usage. Your vendors are shipping agent access whether or not you scoped it — and billing on agent traffic instead of seats.

    See the Agent Control Review

Cost control

See coding-agent spend before the invoice hits. Routed-model pricing moves the number daily.

Need a human to read the report?

Studio turns findings into a plan with owners. Same point of view as the tools. Thirty minutes to see if that is worth it.