The post has been translated automatically. Original language: Russian
First of all, how does this post differ from the monthly radar that I published in the next article? Radar Trends to Watch is a feed of events with links, namely what came out, what broke, what was announced, and such a stream of news month after month.
And Signals (Signals for 2026) is a different genre, here is the annual forecast, which O'Reilly rolls out in January and lays out not by news, but by roles: developer, architect, infra, data, and so on. They themselves formulate it this way: we do not predict the future, but the signs of the future are already visible in the present.
Well, since the forecast was released in January, and it's June, it's a sin not to check. Let's go!
P.S. according to the classics, the link is after the post. Read it, colleagues, it's really very interesting!
The main bet was a year of responsibility
The biggest thesis of the article was about the mood, namely that 2026 will be the year of accountability. Enough experimentation, it's time to count the money and the real benefits, because the ROI of all the billions poured into the industry is still questionable (Deloitte also nods to this). In six months, we have seen this vividly — the burning of tokens has ceased to be confused with productivity, payment has gone to actual consumption, and in sales, evals have come out on top, without which a beautiful model on paper falls apart in battle. As for me, the guys from O'Reilly guessed the mood of the year.
Finetune as a path to niche models
In the article, the author put train and finance on the post as a way to sculpt specialized domain models. The signal is essentially correct and the specialization has really arrived. Only the mechanism went slightly sideways, namely, OpenAI is rolling out its own finetune API (they say our models are already good enough), and specialization came not through the completion of closed models, but through narrow models out of the box (voice, conversation timing, PII filter right on the phone) and open weights. That is, the result is guessed, but the path, alas, is not. For open models, finetune, by the way, has not gone anywhere.
The developer no longer writes, he conducts
The article also explicitly states that the engineer is moving from "conducting AI" to "orchestrating AI", and the assistant is no longer a programmer couple, but a whole team of agents. And so it turned out, the team of agents will not surprise anyone anymore. But the second half of the same signal holds no worse than the first, and which tools you use is less important than how you work with them. Code review, debug, tests, patterns, and context engineering (how to manage what the model knows about the project) that's what separates sane AI code from garbage.
Architect and MCP
Here, in short, the article advised architects to keep their hand on the MCP and look towards event-driven patterns, where the agent reacts to triggers, and not to a hardwired prompt. MCP has really matured in six months, it is being made stateless and authorization is being adjusted for OAuth/OpenID, the release candidate is scheduled for July 28. The advice was spot on.
Safety. Zero trust is now available for cars as well
Well, agents inflate the attack surface, so zero trust should be extended to machine identities, and systems should be hardened against prompt injection. In January, it sounded like an ordinary horror story (there was also a figure that about 59% of experts (according to an ISACA survey) called AI threats the main fear for 2026). Six months later, a graphic illustration arrived, an example where an agent with a wallet was taken away through a message in Morse code, because he had more rights than he needed. And the industry's response is exactly the same as in the forecast — a sandbox for each agent and an external gateway for access (the same NVIDIA OpenShell). The principle of least privilege for agents has turned from a council into an obligation.
InfraOps or standalone SRE
That's where the prediction was the boldest, self-healing infra, predictive observability, and "agent-based SRE," which hypothesizes the cause of the incident and repairs it itself. It's beautiful, but honestly, it hasn't reached the masses in six months, and there are reservations in the post that fully autonomous systems are still on the horizon. AIOps platforms are growing, the direction is right, but there is no way for the SRE agent to handle the prod himself without a human. In fact, these are demos and pilots, not the norm.
Data and product or slow turnaround
There are a couple of signals that are quieter in the news, but Signals has highlighted them. that agents form their own data layer (vector databases, Postgres "for agents" like Agentic Postgres and Lakebase from Databricks), and the product plays the role of product builder (universal at the intersection of product, design and development, plus the demand for conversational interface designers). The trends are alive, but for me, this is a story for years, not six months, and even O'Reilly himself noted that they are already hiring for this role, but there are almost no people with such a full set.
The verdict
Unlike the monthly radar, which catches events, Signals shows the vector of development more honestly. And the vector for six months is mostly confirmed by facts, and the year really turned towards responsibility, the developer became the conductor, security went to zero-trust-for-machines. What has stalled is the most ambitious autonomous things, namely the SRE agent and the data layer for agents.
And here's a thought that the creators of the research are trying to convey to everyone, and I'll subscribe to it — it's not about whether AI will take the job. The point is how specific people decide to implement it. The tools will change, the forecasts will become outdated, and the foundation (your understanding of your subject area) will remain something on which all this can be safely built.
Source-base: O'Reilly, "Signals for 2026"
https://www.oreilly.com/radar/signals-for-2026/
Сначала главное чем этот пост отличается от того ежемесячного радара который я опубликовал в соседней статье? Радар(Radar Trends to Watch) это лента событий со ссылками а именно что вышло, что сломалось, что объявили и такой поток новостей месяц за месяцем.
А Signals(Signals for 2026) это другой жанр тут годовой прогноз, который O'Reilly выкатывает в январе и раскладывает не по новостям, а по ролям: разработчик, архитектор, инфра, данныеи так далее. Они и сами формулируют так будущее мы не предсказываем, но знаки будущего видны уже в настоящем.
Ну чтоже, раз прогноз вышел в январе, а на дворе июнь грех не свериться. Погнали!
P.s по классике ссылка после поста. Почитайте коллеги это правда очень интересно!
Главная ставка была год ответственности
Самый крупный тезис статьи был про настроение а именно то что 2026 станет годом ответственности(accountability). Хватит экспериментов, пора считать деньги и реальную пользу, потому как ROI от всех влитых в индустрию миллиардов до сих пор под вопросом (на это же кивает и Deloitte). За полгода мы это видим ярко — сжигание токенов перестали путать с продуктивностью, оплата поехала к фактическому потреблению, а в проде на первое место вышли eval'ы, без которых красивая на бумаге модель в бою разваливается. Настроение года как по мне ребята из O'Reilly угадали.
Файнтюн как путь к нишевым моделям
В статье автор ставил на пост трейн и файнтюн как способ лепить специализированные доменные модели. Сигнал по сути верный и специализация реально пришла. Только механизм поехал слегка вбок а именно OpenAI сворачивает собственный API файнтюна (говорят наши модели и так достаточно хороши), и специализация прилетела не через дообучение закрытых моделей, а через узкие модели из коробки (голос, тайминг разговора, фильтр PII прямо на телефоне) и открытые веса. То есть итог угадан, а путь увы нет. Для открытых моделей файнтюн, к слову сказать, никуда не делся.
Разработчик больше не пишет, он дирижирует
Также в статье прямым текстом указано что инженер переходит от «conducting AI» к «orchestrating AI», и ассистент это давно не пара-программист, а целая команда агентов. Так и вышло, командой агентов уже никого не удивишь. Но вторая половина того же сигнала держится не хуже первой и какими инструментами ты пользуешься, важно меньше, чем как ты с ними работаешь. Code review, дебаг, тесты, паттерны и context engineering(как управлять тем, что модель знает о проекте) вот что отделяет вменяемый AI-код от мусора.
Архитектор и MCP
Тут коротко в статье советовали архитекторам держать руку на MCP и смотреть в сторону событийных(event-driven) паттернов, где агент реагирует на триггеры, а не на зашитый промпт. MCP за полгода реально повзрослел его делают stateless и подгоняют авторизацию под OAuth/OpenID, релиз-кандидат назначен на 28 июля. Совет был в точку.
Безопасность. zero trust теперь и для машин
Ну что же агенты раздувают поверхность атаки, поэтому zero trust надо распространять на машинные идентичности, а системы закалять против prompt injection. В январе это звучало как обычная страшилка (там и цифра была чтото около 59% спецов(по опросу ISACA) назвали AI-угрозы главным страхом на 2026). За полгода прилетела наглядная иллюстрация пример где агента с кошельком увели через сообщение азбукой Морзе, потому что прав у него оказалось больше, чем нужно. И ответ индустрии ровно такой, как в прогнозе — песочница на каждого агента и внешний шлюз для доступов (та же NVIDIA OpenShell). Принцип наименьших привилегий для агентов из совета превратился в обязаловку.
InfraOps или автономный SRE
Вот где прогноз был самым смелым, self-healing инфра, предиктивная observability и «агентный SRE», который сам ставит гипотезы о причине инцидента и сам чинит. Красиво, но честно за полгода это в массы не приехало, да и в посте есть оговарки, что полностью автономные системы пока на горизонте. AIOps-платформы растут, направление верное, но чтобы SRE-агент сам разрулил прод без человека пока нет по факту это пока демки и пилоты, а не норма.
Данные и продукт или медленный разворот
Пара сигналов, которые в новостях гремят тише, но Signals их выделил что под агентов формируется свой слой данных (векторные базы, Postgres «для агентов» вроде Agentic Postgres и Lakebase от Databricks), а в продукте проклёвывается роль аля product builder (универсал на стыке продукта, дизайна и разработки, плюс спрос на дизайнеров разговорных интерфейсов). Тренды живые, но как по мне это история на годы, а не на полгода и даже сам O'Reilly отметил, что под эту роль уже нанимают, а людей с таким полным набором почти нет.
Вердикт
В отличие от ежемесячного радара, который ловит события, Signals честнее показывает вектор развития. И вектор за полгода в основном подтверждается фактами и год и правда повернул в сторону ответственности, разработчик стал дирижёром, безопасность поехала в zero-trust-для-машин. Что забуксовало так это самые амбициозные автономные штуки, а именно SRE-агент и слой данных под агентов.
И тут есть мысль, которую создатели ресерча пытаются донести до всех, а я под ней подпишусь — дело не в том, заберёт ли AI работу. Дело в том, как решат его внедрять конкретные люди. Инструменты поменяются, прогнозы устареют, а фундамент(твоё понимание своей предметной области) останется тем, на чём всё это можно безопасно строить.
Источник-основа: O'Reilly, «Signals for 2026»
https://www.oreilly.com/radar/signals-for-2026/