
AI Agent Permissions: Designing Action Boundaries Before Automation
An agent with legitimate access to a folder can still write four thousand files somewhere it should not, and every access check will pass.
Read reportThreats and protective controls for AI systems, models, data, tools, and their surrounding supply chains.
Tagged articles
12 articles in this tag.

An agent with legitimate access to a folder can still write four thousand files somewhere it should not, and every access check will pass.
Read report
That is the uncomfortable lesson from AutoJack, a chain Microsoft's security team disclosed in June 2026. The individual bugs were ordinary — the kind of…
Read report
The attacker's cost curve is falling faster than the defender's learning curve. That single asymmetry explains most of what is actually changing.
Read report
The demo passed. The patch was clean. Three weeks later, your team spends more time reviewing agent output than it would have spent writing the code by…
Read report
A customer asks you to delete their data. You delete the row. You have not deleted the data.
Read report
Your pager fires at 2:14 a.m. A customer has posted a screenshot: your assistant told someone to adjust a medication dose. You open the trace, find the…
Read report
Your application code can be perfect and your AI system can still be compromised before it ever runs. The model weights, the fine-tuning dataset, the MCP…
Read report
A coding agent is not a smarter autocomplete. It is a shell with your credentials, your network, and your filesystem — and it runs all three before you…
Read report
A computer-use agent is a model that reads a screen and drives a mouse and keyboard. The demo looks like magic. The second run looks like a different…
Read report
The demo proves what a model can do. Deployment proves what a system will let it do. An autonomous agent can plan, call tools, and act toward a goal on its…
Read report
The attacker never talks to your model. They leave a sentence in a document it will read later.
Read report
A demo runs on a clean prompt, a tidy retrieval index, and a cooperative user who types exactly what the script expects. Then the system ships, and inputs…
Read report