Skip to content

ARC Research

Research from the work, with sources.

Short papers on AI, security, operations, cloud, transformation, and product. If we cannot source a claim, we leave it out.

Library

The library.

Each paper has evidence, what an operator should do with it, where the argument is weak, and links to the sources.

ReportAgent governanceSeptember 7, 2026· 12 min read· 10 sources

Agents With Credentials: What August 2026 Changed for Operators

In one month, the tool protocol went stateless, a national evaluator caught agents acting on the live internet without sanction, enterprise platforms exposed their systems of record as agent-callable tools, and the standards bodies converged on identity. Here is the dated record and what it changes on Monday.

ReportCost controlSeptember 4, 2026· 10 min read· 6 sources

Metered Agents: When the Bill Depends on Which Model Answered

Coding-agent and platform pricing moved from flat seats to routed models and agent traffic, while survey evidence says roughly half of organizations are over their AI plan and almost none pull back. A brief on where the money actually goes and how to govern it by workflow.

ReportRegulationSeptember 2, 2026· 9 min read· 5 sources

The EU AI Act Clock: What Applied on 2 August 2026, and What Moved to 2027

The transparency obligations are in force now. The high-risk obligations were deferred. Teams that heard "delayed" and stopped reading are exposed on the part that already applies — a dated read of the deadlines, with the primary sources.

ResearchAI developmentAugust 1, 2026· 16 min read· 7 sources

AI Development on the Horizon: Agents, Tool Protocols, and the Jagged Frontier

A grounded brief on where AI systems are actually improving — agent computer-use benchmarks, Model Context Protocol tooling, and why capability remains uneven. Built from Stanford HAI, arXiv agent studies, and NIST risk guidance.

ResearchSecurityAugust 1, 2026· 15 min read· 5 sources

Security for Modern Operators: Zero Trust, CSF 2.0, and AI-Era Threats

A cited briefing on NIST Cybersecurity Framework 2.0, Zero Trust Architecture, the emerging Cyber AI Profile, and OWASP’s Top 10 for LLM applications — translated into outcomes teams can actually run.

ResearchOperations workflowAugust 1, 2026· 14 min read· 3 sources

Operations Workflow Development: Process Truth, Mining, and Hyperautomation

How high-performing operations teams move from assumed process maps to event-log truth — grounded in process-mining scholarship, BPM maturity evidence, and Gartner’s hyperautomation research.

ResearchCloud infrastructureAugust 1, 2026· 14 min read· 3 sources

Cloud Infrastructure That Pays Its Way: FinOps, Cloud Native, and Well-Architected Practice

A research brief on running cloud as an operating system for the business — FinOps Framework 2025’s Cloud+ scopes, CNCF evidence that Kubernetes is production infrastructure for AI, and Well-Architected trade-offs.

ResearchDigital transformationAugust 1, 2026· 15 min read· 4 sources

Digital Transformation That Compounds: The Productivity J-Curve and Capability Gaps

Why most digital and AI programs under-deliver — and what Brynjolfsson’s productivity research, MIT manufacturing evidence, and McKinsey capability studies say separates leaders from the pack.

ResearchProduct developmentAugust 1, 2026· 13 min read· 5 sources

Product Development That Learns: Discovery, Delivery, and Outcome Ownership

A research-informed brief on modern product operating models — Marty Cagan / SVPG empowerment principles, Teresa Torres’ continuous discovery habits, and dual-track discovery–delivery — aimed at teams shipping AI-era products without roadmap theater.

Want this applied to your stack?

Studio can take a paper and score it against your environment: what to do first, what to ignore, who owns it.