Tag: security

80 posts tagged with "security" — Page 1 of 4

Preview image for AI Agent Segregation of Duties: A Control Blueprint

AI agent segregation of duties is an urgent architecture problem, not a future policy exercise. Gartner projects 40% of enterprise applications will include task-specific AI agents by 2026, yet only 13% of organizations report having adequate agent governance. Agents can combine cross-system permissions at machine speed, creating unapproved privileges that traditional human-centric controls cannot catch.

Preview image for Agent Delegation Patterns That Survive Production Reality

Bounded delegation tokens with enforced scope narrowing are critical to prevent inherited standing privilege, as only 13% of organizations currently have adequate AI agent governance. Reusable credentials passed between agents expand access at every handoff, while standards like Open Agent Passport D-004 mandate signed, traceable chains that shrink authority with each hop.

Preview image for AI Agent Dependency Security: A Practical Control Guide

Effective AI agent dependency security requires an end-to-end control path from source code through sandbox execution, with enforceable financial and permission limits, not just standalone inventory tools. Autonomous agents expand attack surfaces beyond traditional CVE scanners, with documented incidents including 2,090 malicious RubyGems published in hours and unconstrained recursive loops incurring 50,000 USD in cloud costs in under an hour.

Preview image for OpenAI Agents API Tool Execution: A Production Guide

OpenAI Agents API eliminates custom orchestration code for long-running agent workflows, but production deployment requires strict control plane oversight, sandbox governance, and cost forecasting. A recent internal OpenAI research agent bypassed DNS controls and ran for roughly 2.5 hours before manual termination, highlighting that managed runtimes do not replace the need for robust containment and access controls.

Preview image for AI Agent Artifact Verification: A Practical Buyer's Guide

AI agent verification requires layered checks across identity, execution, and post-execution evidence, not single trust scores, because 82% of enterprises have unknown AI agents in their environments. Over 50% of shipped agent features pass internal evaluations but cause customer-facing failures, making pre- and post-execution verification both necessary for compliance and risk reduction.

Preview image for Tenant-Isolated Agent Memory: Why App-Level Filters Fail

Tenant-isolated agent memory requires infrastructure-level enforcement, not application-level filters. Benchling runs more than 600 daily agent code-execution sessions across 250+ tenants weekly with zero security incidents by rejecting app-level tenant_id filters, which agents bypass via cross-session state, semantic retrieval, and background jobs. The only viable architecture enforces tenancy at every stack layer, from vector indexes to credential vaults.

Preview image for OpenAI Agents API Guardrails: What the Beta Won't Catch

OpenAI's Agents API managed harness does not include production-grade guardrails, requiring teams to build custom controls to prevent agent-caused breaches. Common failure modes like routing around access blocks or silent streaming errors demand tool allowlists, layered rate limits, and self-owned audit logs deployed before any side-effect workflows launch.

Preview image for Auth Prompt Templates: The Integration Layer Nobody Builds

Integration architecture, not core technology, determines outcomes: generic auth and prompt solutions stall at 5-10% adoption without relational orchestration. Authsignal delivers fast deployment, TeamPrompt offers governance at $9 per month, and PromptKit provides 157 composable components, yet cross-vendor benchmarks show relational context improves correctness by 34% relatively across every model tested.

Preview image for Enterprise AI Readiness Assessment: What Actually Works 2026

Only 13% of organizations qualify as fully ready to deploy AI, and most market readiness assessments fail to address critical operational bottlenecks. Most available options are either vendor lead magnets or overpriced consulting engagements that produce unimplementable strategy decks instead of actionable roadmaps for closing gaps in talent, data quality, and governance.