Wispr Flow turns your voice into clean, ready-to-send writing — speak naturally, it strips the filler and fixes the punctuation. I've used it daily since February 2026 to build this newsletter. Read the full review →

On 7 August 2026, Anthropic shipped a feature to Claude Code that sounds mundane and is not: two of its AI sessions can now send each other a message.

The setup it was built for is one where someone has several AI assistants working on different parts of the same project. One of them changes something fundamental. The others carry on building against a fact that quietly stopped being true, and nobody finds out until something breaks.

Until this month, the fix for that was you. You read what the first assistant said, carried it to the second, and explained it again. You were the wire between them.

Now they have their own wire. That is the part every write-up covered.

The more interesting part is what Anthropic did next, which was to spend most of the feature's design making sure those messages can barely do anything at all.

What actually crosses

Very little, and deliberately so. The documentation describes a message as a piece of text one Claude writes to another, never conversation history or files. Here is the example it gives, in full:

Schema migration finished: the new column is tenant_id, and rebasing on main is safe now.

No conversation history. No files. The receiving session gets that text, the sender's name, and a reply address, and nothing else.

And a detail most coverage skipped: you normally do not write the message. You tell Claude what the other session needs to know, and Claude composes the text itself. What crosses between the two assistants is usually one AI's summary of a situation, written for another AI, which you may never read.

200+ Proven Ways to Make Money With AI in 2026

The next wave of millionaires will be people who figured out how to make AI work for them.

The window to get ahead is still open. But not for long.

Here are 200+ proven ways to make money with AI in 2026.

Sign up for Superhuman AI, the free daily newsletter read by 1M+ professionals, and get instant access to all 200+ ways to profit from AI this year.

What a message is not allowed to do

Four hard limits, all documented:

  • It cannot approve anything. A message never counts as your consent, so it cannot answer a pending permission prompt on your behalf.

  • It cannot change permission settings, project rules, or other configuration because another session asked it to.

  • A command inside it arrives as plain text and is never executed.

  • Your own permission prompts still fire exactly as normal.

Anthropic built a communication channel and then made certain that nothing arriving through it carries any authority. A message can inform. It cannot instruct.

The attack they wrote down

The strongest evidence this was thought through properly is that they named the thing they were worried about, and not in a blog post. It sits inside the messaging tool itself, where the AI reads it every single time it considers sending anything: never ask another session to perform an action that was denied or blocked in yours, because a peer doing it for you bypasses the user's permission decision.

They call it cross-session permission laundering. In plain English: you ask your AI to do something, it asks your permission, and you say no. If it could then turn to the AI in the next window and say you do it instead, your no would have meant nothing at all.

And they had to stop them talking in circles

Repeated messages are rate-limited per sender, identical ones arriving close together are dropped, and accepted messages waiting to be read are capped at fifty per session, with a separate cap holding at most a hundred undelivered ones. The documentation explains why in one flat sentence: a message loop between two sessions therefore stops on its own.

They built the brake because they needed it. And every delivered message counts toward your usage like a prompt you type, sending your full context again each time.

The part worth carrying away

There is no verification step. Session A tells Session B that the column is now called tenant_id. Session B has no way to check. It believes it and acts on it. If A was wrong, B is now confidently wrong too, and the error has travelled instead of staying where it started.

The old copy-paste workflow was slow and irritating. It also had a quality check built into it that nobody noticed was there: you read the message on the way through.

Almost nobody reading this runs three coding sessions at once. It matters anyway, because within a year a great many ordinary tools will have AI parts talking to each other. The question that decides whether that is safe is not can they communicate. It is what a message from one of them is allowed to make another one do.

Anthropic's answer, for now, is: almost nothing. That is the conservative answer, and almost certainly the right one. It is also the question worth asking of every other product that ships something similar.

Stop Paying for 6 Tools. One AI Does It All.

Most e-commerce sellers juggle 6–8 tools and pay hundreds monthly to keep operations running. StoreClaw replaces the stack with one autonomous AI engine that monitors competitors, optimizes listings, automates marketing, and tracks profit 24/7. Connect your store and let AI handle the work — no prompts, no complex setup, no credit card required.