Enterprise AI Radar — Friday, August 7, 2026
noticias radar ia agentes ia seguridad ia automatizacion

Enterprise AI Radar — Friday, August 7, 2026

· CompaniesAutomation

AI agents take a leap: from talking to actually operating—and paying on their own. HappyRobot, a company with Spanish founders, reaches a 1.2 billion valuation automating voice calls and paperwork for Repsol, Naturgy, DHL, or Uber. Cloudflare debuts wallets for agents to buy services autonomously with spending caps. Meanwhile, CISA warns of a critical flaw being exploited in Langflow, and Mistral releases Shieldstral, a European AI for content moderation that keeps your data in-house. Takeaway: agentic automation is doing real work, but it's time to set budget limits, patch the plumbing, and choose data-respectful tools.

Yesterday's AI radar was about reining in your agents; today, agents take a step further and move from talking to operating—and paying. A company with Spanish founders has reached a 1.2 billion valuation by voice-automating paperwork for Repsol, Naturgy, or DHL; Cloudflare launches wallets so an agent can buy services on its own, with a spending cap; a widely used tool for building AI flows (Langflow) has a critical hole that is already being exploited; and Mistral releases a European AI that filters content without your data ever leaving home. Today's takeaway: agentic automation is already doing real work, but it requires setting financial limits, patching the plumbing, and choosing tools that respect your data.

An AI by Spanish founders already handles calls and paperwork for Repsol, Naturgy, and DHL

HappyRobot, a Spanish-American company born in 2022, announced on August 4th a $150 million round—led by Prysm Capital and co-led by Eurazeo, with a16z, Base10, and Y Combinator behind it—valuing it at 1.2 billion. The interesting part isn't the figure, but what it does: its agents automate operational work—confirming loads, calling suppliers, processing paperwork—via voice, email, and documents within the systems of over 150 large clients, including DHL, Kuehne+Nagel, Uber, and the Spanish companies Repsol and Naturgy. For your company: the repetitive phone and email tasks that drown your team—order confirmations, appointment reminders, chasing missing documents—are already being handled by a voice agent in production, and the team leading it is Spanish, not an unreachable Silicon Valley lab. Choose a single high-volume flow, run a pilot with a voice or chat agent, and measure the hours it saves you before scaling up. Source

Your agents can now pay on their own: set a cap before giving them the card

Cloudflare introduced Cloudflare Wallets and cloudflare.pay identifiers on August 4th: programmable wallets that give an AI agent a stable identity and the ability to buy services on the internet on its own, but only within limits set by its human owner—total spending cap, list of allowed merchants, and maximum transaction size—with support for stablecoins. For now, you can reserve your identifier; the full functionality (adding funds, issuing a wallet to each agent, and actual payment) will arrive in the coming months. For your company: agents buying APIs, data, or compute is no longer just theory, and with it comes a new risk: uncontrolled spending or spending induced by an attack. Before letting any automation touch money, demand those three brakes—hard monthly cap, whitelist of who it can pay, and maximum per operation—plus human approval for anything beyond that. Source

If you built your AI flows with Langflow, update today: it's already being exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical flaw in Langflow to its list of actively exploited vulnerabilities on August 5th. Langflow is a popular open-source tool for building AI flows that connect models, APIs, databases, and business systems. The hole (CVE-2026-9198, severity 9.8 out of 10) allows an attacker without a password to execute code and take control of the server in default installations; it affects versions 1.0.0 to 1.10.0 and is fixed by updating to 1.10.1. For your company: many "no-code" automations are built on components like this, and if yours (or your provider's) runs Langflow, someone can enter without credentials and access everything that flow is connected to. Ask whoever set it up for you today two things: if you are on 1.10.1 or higher and if that server is exposed to the internet; if the answer isn't clear, have them patch it or isolate it immediately. Source

You can now filter content with a European AI without your data leaving home

Mistral, the French company, released Shieldstral on August 4th, an open model (Apache 2.0 license) with 3 billion parameters that moderates text and images according to a safety policy you write in plain language, without retraining anything, and returns a risk score. It runs on a single 16 GB GPU—modest hardware—and Mistral claims it matches guardrail models up to seven times larger. For your company: if your chatbot, your community, or the content your users upload needs filtering, until now that usually meant sending everything to a cloud API in the US; this runs on your own machine, with your rules, and without the data leaving your control, which is exactly what the AI Act and any privacy concerns demand. Even if you don't install it yourself, it's an argument to demand a local, European alternative from your provider. Source

What to watch tomorrow?

With agents beginning to move money, the next step will be seeing the first real spending limits—and scares—and more providers copying Cloudflare's capped wallet. And a question for today: of the tools your automations run on, do you know which ones are up to date on patches and which one would take down the rest if it falls?

Watch the 1-minute video