HookBus® Light is live. Every autonomous agent now has somewhere to plug in.
Uber blew $3.4 billion of Claude Code spend in four months. The EU AI Act's high-risk obligations take effect on 2 August 2026, fifteen weeks from today. Today we ship the open-source runtime that sits between your autonomous AI agent and the action it's about to take, and decides whether to let it happen, what it cost, and how to prove to the auditor that it did exactly what you told it to.
Correction. The opening line originally said Uber spent $3.4 billion on Claude Code in four months. $3.4 billion was Uber's total 2025 research and development spend. What was reported is that Uber used its entire 2026 AI budget within four months (Fortune). We also withdraw the claim that AgentAuditor exports SOC 2, ISO 27001, ISO 42001 and EU AI Act Article 12 compliance bundles; it keeps a hash-chained event record with verification and reports, and is not yet published as open source.
The problem is no longer hypothetical
On 15 April 2026, Uber's Chief Technology Officer Praveen Neppalli Naga admitted the company had exhausted its entire 2026 AI budget in four months. The cause: 5,000 engineers running Claude Code as an autonomous agent.
I'm back to the drawing board, because the budget I thought I would need is blown away already. Praveen Neppalli Naga, CTO, Uber · 15 April 2026
Uber is not the outlier. Individual engineers are reporting $500–$2,000 monthly Claude Code bills. One documented case turned a $0.50 bug fix into a $30 bill via 47 autonomous iterations. Cursor issued a public apology on 4 July 2025 after its new credit model drained user subscriptions in a single day.
This is not a tooling failure. It is the inevitable consequence of autonomous agents doing exactly what we asked them to, run for hours, retry on failure, iterate until the goal is met, without a runtime layer that can see, decide, and stop.
HookBus® is that layer.
Three products. One bus. Sixty seconds to install.
HookBus® bus core
The vendor-neutral, on-premise event router. Bearer-token authenticated. Hot-reloadable subscriber config. One container, HTTP and Unix-socket transport. Works with any lifecycle event any AI agent emits.
AgentProtect Light
A HookBus subscriber that brings Microsoft's Agent Governance Toolkit (AGT, MIT) to every autonomous agent in your fleet. Stops a dangerous tool call before it runs by classifying it against Microsoft's destructive · exfiltration · privilege-escalation · system-modification taxonomy in sub-10 ms. Our adapter is MIT, matching the AGT upstream.
AgentSpend
Tells you the second an autonomous agent starts burning money. Real-time token-cost monitor, per-agent, per-model, per-session. Built-in dashboard. SQLite-persisted. Price tables for Claude, GPT, Gemini, MiniMax, DeepSeek, GLM, and ten more. Drops in with zero agent-code changes.
Two MIT publisher shims are public today, Hermes (Nous Research runtime) and OpenClaw. Anthropic Agent SDK, OpenAI Agents SDK, and Sourcegraph Amp shims are in private beta. Install via the runtime's native plugin mechanism. No central registry lock-in.
git clone https://github.com/agentic-thinking/hookbus.git && cd hookbus export HOOKBUS_TOKEN=$(openssl rand -base64 32 | tr -d '/+=') docker compose up -d echo "Dashboard: http://localhost:18800/?token=$HOOKBUS_TOKEN"
Images pull from ghcr.io/agentic-thinking/*. No build step, no registry login. First boot in ~15 seconds.
Fifteen seconds. Bus + AgentProtect Light + AgentSpend, wired and authenticated. Install the shim for your runtime and events start flowing.
Built on Microsoft's Agent Governance Toolkit
AgentProtect Light is not a fork, not a competitor, not a reinvention. It is a HookBus subscriber that adapts Microsoft's Agent Governance Toolkit (MIT-licensed, maintained by Microsoft Corporation) to the HookBus envelope. Microsoft defines the threat taxonomy. HookBus distributes that classification across every agent runtime your company runs, Claude Code, OpenAI Agents SDK, Anthropic Agent SDK, Hermes, OpenClaw, and Amp, in one layer instead of one integration per runtime. We build on Microsoft's work. We do not claim any part of it.
Why we open-sourced it
The enterprise-infrastructure companies that defined the last decade, Red Hat, HashiCorp, Elastic, MongoDB, Sentry, all did the same thing. They gave the core away, let developers adopt it bottom-up, then sold the support, SLA, and closed-source advanced features to the enterprise above. Mitchell Hashimoto framed it this way:
Open source is the key driver around the adoption of enterprise infrastructure software. The new battleground is the hearts and minds of developers and architects who experiment with and ultimately select the winning technologies. Mitchell Hashimoto, co-founder, HashiCorp
80% of organisations now regard open source as strategically valuable to their future. Autonomous-agent use is already happening at scale inside enterprises running Claude Code today. HookBus® Light is what those developers can install on a Tuesday afternoon.
Sections of this post describing a commercial HookBus Enterprise tier were removed on 25 September 2026. That tier is no longer offered; Agentic Thinking is now an independent research lab. AgentProtect, AgenticStudio and HookBus Agent are not currently offered.
Agentic Thinking. We test what AI agents really do, and investigate when it goes wrong.