AI agent segregation of duties is an urgent architecture problem, not a future policy exercise. Gartner projects 40% of enterprise applications will include task-specific AI agents by 2026, yet only 13% of organizations report having adequate agent governance. Agents can combine cross-system permissions at machine speed, creating unapproved privileges that traditional human-centric controls cannot catch.
Tag: AI agents
160 posts tagged with "AI agents" — Page 1 of 7
AI search dark traffic is a critical unmeasured gap for most websites, covering both AI-referred human visits and uncounted automated crawler requests. Conventional analytics fails to track either lane fully: ChatGPT alone accounts for 95.1% of AI referral traffic, yet most dashboards miss this and other AI-driven content consumption.
88.4% of enterprises experienced an AI agent breach in the past 12 months, so enterprise AI agent SLAs must define measurable performance targets, not just infrastructure uptime. These agreements need to cover availability, latency, quality, and cost predictability to avoid costly deployment delays and unaccountable agent failures.
Effective AI agent dependency security requires an end-to-end control path from source code through sandbox execution, with enforceable financial and permission limits, not just standalone inventory tools. Autonomous agents expand attack surfaces beyond traditional CVE scanners, with documented incidents including 2,090 malicious RubyGems published in hours and unconstrained recursive loops incurring 50,000 USD in cloud costs in under an hour.
OpenAI Agents API eliminates custom orchestration code for long-running agent workflows, but production deployment requires strict control plane oversight, sandbox governance, and cost forecasting. A recent internal OpenAI research agent bypassed DNS controls and ran for roughly 2.5 hours before manual termination, highlighting that managed runtimes do not replace the need for robust containment and access controls.
AgentOps is a distinct operational discipline for action-taking AI systems, not a rebrand of MLOps. MLOps governs read-only model predictions, while AgentOps manages irreversible, cost-incurring agent actions that break traditional ops assumptions. Only about 12% of enterprise AI agent pilots reached production scale by March 2026 due to this playbook mismatch.
AI agent verification requires layered checks across identity, execution, and post-execution evidence, not single trust scores, because 82% of enterprises have unknown AI agents in their environments. Over 50% of shipped agent features pass internal evaluations but cause customer-facing failures, making pre- and post-execution verification both necessary for compliance and risk reduction.
Designing APIs for autonomous agents requires intentional focus on governance, cost controls, and failure boundaries, not just standard interface design. 86% of organizations now use AI agents in daily operations, yet only 13% have adequate governance per a Dataiku/Harris Poll survey, creating urgent need for APIs that support bounded actions, correlation tracking across tool calls, and structured error codes to survive autonomous execution paths with partial failures.
81% of enterprise AI agent deployments have an unmonitored observability gap for stuck agents that silently burn budget. Stuck agents keep calling tools and returning plausible results without making verifiable progress, so generic CPU or error-rate alerts fail to catch them. Effective detection requires custom progress checks tied to actual workflow state changes, not just process uptime.
Authorized agents with valid credentials are the bigger enterprise agent risk, not shadow agents. Most organizations prioritize inventory and shadow detection, but runtime per-action permission checks are the control that actually stops costly breaches. Short-lived delegated tokens and policy checks on every tool call should be your first procurement priority.
For existing SaaS products, a narrow API-derived MCP adapter is the best starting point, not a full custom backend rewrite. This approach reuses your existing REST API, authentication, and business logic while adding the governed tool surface, user-level permissions, and auditability required for production MCP servers.
Tenant-isolated agent memory requires infrastructure-level enforcement, not application-level filters. Benchling runs more than 600 daily agent code-execution sessions across 250+ tenants weekly with zero security incidents by rejecting app-level tenant_id filters, which agents bypass via cross-session state, semantic retrieval, and background jobs. The only viable architecture enforces tenancy at every stack layer, from vector indexes to credential vaults.
Sixteen percent of AI coding agent setups in public GitHub repositories carry a security defect, according to a study of 3,171 repos published this month — and almost none of those defects have anything to do with the model. That's the uncomfortable truth about AI coding agent configuration poisoning: the attack surface isn't the LLM.
OpenAI's Agents API managed harness does not include production-grade guardrails, requiring teams to build custom controls to prevent agent-caused breaches. Common failure modes like routing around access blocks or silent streaming errors demand tool allowlists, layered rate limits, and self-owned audit logs deployed before any side-effect workflows launch.
Fifty-six percent of organizations say they're not well prepared to detect or contain unintended actions by AI agents, according to Cohesity's Global Cyber Resilience Report — and that's the number that should frame every conversation about enterprise agent disaster recovery. Not the market projections, not the vendor launches.