Reading view
Call for speakers: TechCrunch Founder Summit 2026
Quantifying Individual Health Status from Multi-omics Data by Health State Manifold
Phenomics. 2025 Dec 15;5(5):469-486. doi: 10.1007/s43657-024-00188-4. eCollection 2025 Oct.
ABSTRACT
Quantifying individual health status from increasingly accumulated omics data is essential for both early prevention and intervention of diseases, which attracts great attention from communities of biology and medicine. Most of the existing approaches mainly classify individuals into different catalogues or classes based on phenotypes and biomarkers. However, an individual's health status from a dynamical systems viewpoint can be viewed as a non-equilibrium steady state, which can generally be characterized by two key features, i.e. (1) homeostatic potential that represents the ability of homeostatic resilience to withstand perturbations or maintain functions at the current state/phenotype of this individual and (2) phenotypic potential that represents the state/phenotype of the individual on the whole process from health to disease. Here, we proposed a health state manifold (HSM) method derived from dynamic network biomarker method and diffusion map theory to quantify individual health status with the characterization of such two features in a robust and accurate manner based on multi-omics data. To verify our method, HSM method was applied to the quantification of diabetes mellitus (rat subjects) and the Roux-en-Y Gastric Bypass (human subjects) for both disease progression process and recovery process, which demonstrated its effectiveness and potential for personalized medicine and preventive medicine.
SUPPLEMENTARY INFORMATION: The online version contains supplementary material available at 10.1007/s43657-024-00188-4.
PMID:41659741 | PMC:PMC12881232 | DOI:10.1007/s43657-024-00188-4
Spatial Multi-omics Analyses Reveal Diabetes Promotes Pancreatic Cancer Progression by Stimulating Cholesterol-Induced Neutrophil Extracellular Trap Formation
Cancer Res. 2026 Feb 9. doi: 10.1158/0008-5472.CAN-25-2854. Online ahead of print.
ABSTRACT
Pancreatic ductal adenocarcinoma (PDAC) patients with diabetes mellitus (DM) exhibit poor clinical outcomes. Metabolic reprogramming of both cancer cells and immune compartments plays a crucial role in shaping the anti-tumor immune response in PDAC. DM-induced metabolic alteration may disrupt the intricate crosstalk between immune cells and tumor-associated immune factors, profoundly influencing PDAC progression. Here, we performed an integrated, spatially resolved multi-omics study to investigate DM-associated, cell-specific metabolic remodeling within the PDAC tumor microenvironment. DM influenced interactions between tumor cells and immune cells, which accelerated PDAC growth in both humans and mice. PDAC patients with DM exhibited higher tumor-stage, poorer differentiation, and worse outcomes. Spatial metabolic and transcriptional profiling revealed that SREBP2-dependent cholesterol biosynthesis exacerbated PDAC progression. Increased cholesterol biosynthesis promoted neutrophil recruitment and accelerated formation of neutrophil extracellular traps (NETs) by stimulating the CXCL1-CXCR1/CXCR2 signaling axis, ultimately promoting PDAC growth. Inhibition of SREBP2, pharmacological blockade of CXCL1, or perturbation of NETs markedly reduced PDAC growth in diabetic mouse models. Together, these multi-omics analyses and follow-up mechanistic studies constitute an integrated approach that elucidates a metabolic mechanism by which diabetes promotes PDAC development by remodeling the tumor immune microenvironment and highlights a potential therapeutic strategy for PDAC with DM.
PMID:41661642 | DOI:10.1158/0008-5472.CAN-25-2854
Generating High-quality Privacy-preserving Synthetic Data
Yunjue Agent Tech Report: A Fully Reproducible, Zero-Start In-Situ Self-Evolving Agent System for Open-Ended Tasks
Data-Centric Interpretability for LLM-based Multi-Agent Reinforcement Learning
Exploring AI-Augmented Sensemaking of Patient-Generated Health Data: A Mixed-Method Study with Healthcare Professionals in Cardiac Risk Reduction
Reliability of LLMs as medical assistants for the general public: a randomized preregistered study
Nature Medicine, Published online: 09 February 2026; doi:10.1038/s41591-025-04074-y
In a randomized controlled study involving 1,298 participants from a general sample, performance of humans when assisted by a large language model (LLM) was sensibly inferior to that of the LLM alone when assessing ten medical scenarios leading to disease identification and recommendations for treatment.Sensitive detection of cancer antigens enabled by user-defined peptide libraries
Nature Biotechnology, Published online: 09 February 2026; doi:10.1038/s41587-026-03003-9
Insights into regulatory T cell biology are accelerating therapeutic innovation in cancer immunotherapy, autoimmune diseases and transplant rejection.The Feasibility of Smartwatch Micro–Ecological Momentary Assessment for Tracking Eating Patterns of Malaysian Children and Adolescents in the South-East Asian Community Observatory Child Health Update 2020: Cross-Sectional Study
Tumor microbiome differences in early-onset versus average-onset pancreatic adenocarcinoma
ESMO Gastrointest Oncol. 2025 Jul 7;9:100194. doi: 10.1016/j.esmogo.2025.100194. eCollection 2025 Sep.
ABSTRACT
BACKGROUND: Compelling evidence supports the biomarker potential of microbiome in pancreatic adenocarcinoma. Given the knowledge gap on the characteristics and significance of microbiome in early-onset pancreatic ductal adenocarcinoma (eoPDAC, age <50 years), we aimed to evaluate microbiome profiles in resected specimens from individuals with eoPDAC and average-onset PDAC (aoPDAC, age >50 years).
MATERIALS AND METHODS: We carried out shotgun metagenomic sequencing in resected specimens from individuals with eoPDAC (n = 24) and aoPDAC (n = 20). Statistical tests included Wilcoxon test, permutational analysis of variance, multiomic classifier modeling, differential abundance analysis, and linear regression. All P values were adjusted for multiple testing and P < 0.05 was considered statistically significant.
RESULTS: We successfully sequenced several bacteria and fungi in the tumor specimens from 44 individuals with resected PDAC (24 eoPDAC and 20 aoPDAC). The alpha diversity of the bacterial microbiome was higher in eoPDAC tumor tissue compared with aoPDAC (P = 0.04). In contrast, the fungal mycobiome's alpha diversity was higher for aoPDAC tumor tissue (P = 0.02). Key organisms with differential abundance between tumor tissue from individuals with eoPDAC and aoPDAC included Bacillus, Candida, Collimonas, Cupriavidus, Enterobacter, Escherichia, Klebsiella, Malasseiza, Mucilaginibacter, Neisseria, and Sphingomonas. Higher bacterial diversity in tumor tissue was associated with better overall survival for individuals with eoPDAC (R = 0.26, P = 0.02).
CONCLUSIONS: Shotgun metagenomic sequencing identified bacterial microbiome and fungal mycobiome in tumors from individuals with eoPDAC and aoPDAC. We observed significant differences in alpha and beta diversity and relative abundances of organisms suggesting distinct microbiome signatures. Microbiome associations with survival were observed in eoPDAC indicating unique potential as prognostic biomarker.
PMID:41647993 | PMC:PMC12836659 | DOI:10.1016/j.esmogo.2025.100194
Cheap AI chatbots transform medical diagnoses in places with limited care
Nature, Published online: 06 February 2026; doi:10.1038/d41586-026-00345-x
Studies in Rwanda and Pakistan reveal real-world utility of chatbots in underfunded clinics, and not just in benchmark tests.EcDNA-borne structural variants drive oncogenic fusion transcript amplification
From Data to Behavior: Predicting Unintended Model Behaviors Before Training
Contrastive Continual Learning for Model Adaptability in Internet of Things
DISCOVER: Identifying Patterns of Daily Living in Human Activities from Smart Home Data
From guardrails to governance: A CEO’s guide for securing agentic systems
The previous article in this series, “Rules fail at the prompt, succeed at the boundary,” focused on the first AI-orchestrated espionage campaign and the failure of prompt-level control. This article is the prescription. The question every CEO is now getting from their board is some version of: What do we do about agent risk?

Across recent AI security guidance from standards bodies, regulators, and major providers, a simple idea keeps repeating: treat agents like powerful, semi-autonomous users, and enforce rules at the boundaries where they touch identity, tools, data, and outputs.
The following is an actionable eight-step plan one can ask teams to implement and report against:

Constrain capabilities
These steps help define identity and limit capabilities.
1. Identity and scope: Make agents real users with narrow jobs
Today, agents run under vague, over-privileged service identities. The fix is straightforward: treat each agent as a non-human principal with the same discipline applied to employees.
Every agent should run as the requesting user in the correct tenant, with permissions constrained to that user’s role and geography. Prohibit cross-tenant on-behalf-of shortcuts. Anything high-impact should require explicit human approval with a recorded rationale. That is how Google’s Secure AI Framework (SAIF) and NIST AI’s access-control guidance are meant to be applied in practice.
The CEO question: Can we show, today, a list of our agents and exactly what each is allowed to do?
2. Tooling control: Pin, approve, and bound what agents can use
The Anthropic espionage framework worked because the attackers could wire Claude into a flexible suite of tools (e.g., scanners, exploit frameworks, data parsers) through Model Context Protocol, and those tools weren’t pinned or policy-gated.
The defense is to treat toolchains like a supply chain:
- Pin versions of remote tool servers.
- Require approvals for adding new tools, scopes, or data sources.
- Forbid automatic tool-chaining unless a policy explicitly allows it.
This is exactly what OWASP flags under excessive agency and what it recommends protecting against. Under the EU AI Act, designing for such cyber-resilience and misuse resistance is part of the Article 15 obligation to ensure robustness and cybersecurity.
The CEO question: Who signs off when an agent gains a new tool or a broader scope? How does one know?
3. Permissions by design: Bind tools to tasks, not to models
A common anti-pattern is to give the model a long-lived credential and hope prompts keep it polite. SAIF and NIST argue the opposite: credentials and scopes should be bound to tools and tasks, rotated regularly, and auditable. Agents then request narrowly scoped capabilities through those tools.
In practice, that looks like: “finance-ops-agent may read, but not write, certain ledgers without CFO approval.”
The CEO question: Can we revoke a specific capability from an agent without re-architecting the whole system?
Control data and behavior
These steps gate inputs, outputs, and constrain behavior.
4. Inputs, memory, and RAG: Treat external content as hostile until proven otherwise
Most agent incidents start with sneaky data: a poisoned web page, PDF, email, or repository that smuggles adversarial instructions into the system. OWASP’s prompt-injection cheat sheet and OpenAI’s own guidance both insist on strict separation of system instructions from user content and on treating unvetted retrieval sources as untrusted.
Operationally, gate before anything enters retrieval or long-term memory: new sources are reviewed, tagged, and onboarded; persistent memory is disabled when untrusted context is present; provenance is attached to each chunk.
The CEO question: Can we enumerate every external content source our agents learn from, and who approved them?
5. Output handling and rendering: Nothing executes “just because the model said so”
In the Anthropic case, AI-generated exploit code and credential dumps flowed straight into action. Any output that can cause a side effect needs a validator between the agent and the real world. OWASP’s insecure output handling category is explicit on this point, as are browser security best practices around origin boundaries.
The CEO question: Where, in our architecture, are agent outputs assessed before they run or ship to customers?
6. Data privacy at runtime: Protect the data first, then the model
Protect the data such that there is nothing dangerous to reveal by default. NIST and SAIF both lean toward “secure-by-default” designs where sensitive values are tokenized or masked and only re-hydrated for authorized users and use cases.
In agentic systems, that means policy-controlled detokenization at the output boundary and logging every reveal. If an agent is fully compromised, the blast radius is bounded by what the policy lets it see.
This is where the AI stack intersects not just with the EU AI Act but with GDPR and sector-specific regimes. The EU AI Act expects providers and deployers to manage AI-specific risk; runtime tokenization and policy-gated reveal are strong evidence that one is actively controlling those risks in production.
The CEO question: When our agents touch regulated data, is that protection enforced by architecture or by promises?
Prove governance and resilience
For the final steps, it’s important to show controls work and keep working.
7. Continuous evaluation: Don’t ship a one-time test, ship a test harness
Anthropic’s research about sleeper agents should eliminate all fantasies about single test dreams and show how critical continuous evaluation is. This means instrumenting agents with deep observability, regularly red teaming with adversarial test suites, and backing everything with robust logging and evidence, so failures become both regression tests and enforceable policy updates.
The CEO question: Who works to break our agents every week, and how do their findings change policy?
8. Governance, inventory, and audit: Keep score in one place
AI security frameworks emphasize inventory and evidence: enterprises must know which models, prompts, tools, datasets, and vector stores they have, who owns them, and what decisions were taken about risk.
For agents, that means a living catalog and unified logs:
- Which agents exist, on which platforms
- What scopes, tools, and data each is allowed
- Every approval, detokenization, and high-impact action, with who approved it and when
The CEO question: If asked how an agent made a specific decision, could we reconstruct the chain?
And don’t forget the system-level threat model: assume the threat actor GTG-1002 is already in your enterprise. To complete enterprise preparedness, zoom out and consider the MITRE ATLAS product, which exists precisely because adversaries attack systems, not models. Anthropic provides a case study of a state-based threat actor (GTG-1002) doing exactly that with an agentic framework.
Taken together, these controls do not make agents magically safe. They do something more familiar and more reliable: they put AI, its access, and actions back inside the same security frame used for any powerful user or system.
For boards and CEOs, the question is no longer “Do we have good AI guardrails?” It’s: Can we answer the CEO questions above with evidence, not assurances?
This content was produced by Protegrity. It was not written by MIT Technology Review’s editorial staff.
Phenome-wide analysis of copy number variants in 470,727 UK Biobank genomes
Nature, Published online: 04 February 2026; doi:10.1038/s41586-025-10087-x
A multiancestry phenome-wide analysis of copy number variants in the UK Biobank genomes increases power to detect genetic associations with complex traits across human populations.‘It means I can sleep at night’: how sensors are helping to solve scientists’ problems
Nature, Published online: 04 February 2026; doi:10.1038/d41586-026-00212-9
Continual automated data collection was once possible only for the world’s richest labs. Now, sensor systems are commonplace and can be accessed from an app.