<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[RockCyber Musings]]></title><description><![CDATA[AI and Cyber Geek]]></description><link>https://www.rockcybermusings.com</link><image><url>https://substackcdn.com/image/fetch/$s_!y2c3!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faaa51f40-9ed4-4093-898e-0bdb99086a7a_827x827.png</url><title>RockCyber Musings</title><link>https://www.rockcybermusings.com</link></image><generator>Substack</generator><lastBuildDate>Thu, 13 Aug 2026 21:35:30 GMT</lastBuildDate><atom:link href="https://www.rockcybermusings.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Rock Lambros]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[rockcyber@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[rockcyber@substack.com]]></itunes:email><itunes:name><![CDATA[Rock Lambros]]></itunes:name></itunes:owner><itunes:author><![CDATA[Rock Lambros]]></itunes:author><googleplay:owner><![CDATA[rockcyber@substack.com]]></googleplay:owner><googleplay:email><![CDATA[rockcyber@substack.com]]></googleplay:email><googleplay:author><![CDATA[Rock Lambros]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[The 2026 OWASP LLM Top 10 Landed. Its #1 Risk Nearly Didn’t Make the Cut.]]></title><description><![CDATA[The OWASP LLM Top 10 2026 checked the practitioner vote against 6,639 real incidents. See what moved, why prompt injection stayed #1, and how it held up.]]></description><link>https://www.rockcybermusings.com/p/the-2026-owasp-llm-top-10-landed-with-evidence</link><guid isPermaLink="false">https://www.rockcybermusings.com/p/the-2026-owasp-llm-top-10-landed-with-evidence</guid><dc:creator><![CDATA[Rock Lambros]]></dc:creator><pubDate>Tue, 11 Aug 2026 12:50:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NHUD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2357185d-81d2-4dcc-970a-149e1483c7c5_2048x2048.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NHUD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2357185d-81d2-4dcc-970a-149e1483c7c5_2048x2048.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NHUD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2357185d-81d2-4dcc-970a-149e1483c7c5_2048x2048.png 424w, https://substackcdn.com/image/fetch/$s_!NHUD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2357185d-81d2-4dcc-970a-149e1483c7c5_2048x2048.png 848w, https://substackcdn.com/image/fetch/$s_!NHUD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2357185d-81d2-4dcc-970a-149e1483c7c5_2048x2048.png 1272w, https://substackcdn.com/image/fetch/$s_!NHUD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2357185d-81d2-4dcc-970a-149e1483c7c5_2048x2048.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NHUD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2357185d-81d2-4dcc-970a-149e1483c7c5_2048x2048.png" width="1456" height="1456" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2357185d-81d2-4dcc-970a-149e1483c7c5_2048x2048.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1456,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4165397,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/209446450?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2357185d-81d2-4dcc-970a-149e1483c7c5_2048x2048.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NHUD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2357185d-81d2-4dcc-970a-149e1483c7c5_2048x2048.png 424w, https://substackcdn.com/image/fetch/$s_!NHUD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2357185d-81d2-4dcc-970a-149e1483c7c5_2048x2048.png 848w, https://substackcdn.com/image/fetch/$s_!NHUD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2357185d-81d2-4dcc-970a-149e1483c7c5_2048x2048.png 1272w, https://substackcdn.com/image/fetch/$s_!NHUD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2357185d-81d2-4dcc-970a-149e1483c7c5_2048x2048.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>The 2026 OWASP LLM Top 10 puts prompt injection at number one, same as every year before it. For the first time, you don&#8217;t have to take the ranking on faith anymore. Up until now, we ran this on gut. On human intuition and judgment from experts on the front lines. This time is different. For the first time, we had a corpus of reported incidents to validate our assumptions against. So we did just that. We checked our judgment against 6,639 real incidents pulled from public databases. There were differences and surprises. The risk the whole field fears most barely showed up in the record of what has gone wrong.</span></p><p><span>That gap is where this year&#8217;s story starts, and it&#8217;s why this is the first version of the list you can argue with using evidence instead of opinion.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/subscribe?"><span>Subscribe now</span></a></p><h2><span>The Question I Couldn&#8217;t Shake</span></h2><p><span>For years, this list came from a vote. Practitioners score the risks, the scores set the order, and the order sends thousands of teams to their defenses. A vote is a fine way to rank risk. It captures the judgment of people who break and defend these systems for a living. It also carries their blind spots and their biases. We rank what we read about last month above what quietly broke last year. We anchor to where the previous list sat. One question kept circling me through this whole cycle. What if the risks we fear most aren&#8217;t the ones doing the most damage? There&#8217;s one honest way to answer that. Go get the record and read it.</span></p><h2><span>We Went and Read the Record</span></h2><p><span>We pulled 7,714 real incidents out of the public databases where these failures show up: CVE, GHSA, OSV, and the AIAAIC harm database. Then we built classifiers to read every one and sort the 6,639 that carried enough detail into the taxonomy.</span></p><p><span>The part that wasn&#8217;t clean? The incident record. It isn&#8217;t a nice, clean, tidy grid of labels. It&#8217;s the Amazon Q coding extension that shipped with a wipe-the-machine instruction committed straight into its repository. It&#8217;s the unofficial postmark-mcp package that looked helpful and quietly BCC&#8217;d a few hundred organizations&#8217; email to a stranger. It&#8217;s the zero-click exfiltration researchers pulled off against Microsoft 365 Copilot, data walking out the door with no click from anyone. None of them arrived with a neat category stamped on the side. We read them the way an investigator reads a case file, then filed each one where it belonged. Thousands of messy, real stories, sorted into piles. Then we ranked the piles by how tall they stood.</span></p><h2><span>The Vote and the Data Didn&#8217;t Match</span></h2><p><span>The piles of incidents didn&#8217;t match the vote. They didn&#8217;t come close. When we lined up what practitioners fear against what the record shows, we found that the two disagree more than they agree.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!v6Zf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1fee592-2114-4a2f-a255-9245e0f691ec_2880x1920.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!v6Zf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1fee592-2114-4a2f-a255-9245e0f691ec_2880x1920.png 424w, https://substackcdn.com/image/fetch/$s_!v6Zf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1fee592-2114-4a2f-a255-9245e0f691ec_2880x1920.png 848w, https://substackcdn.com/image/fetch/$s_!v6Zf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1fee592-2114-4a2f-a255-9245e0f691ec_2880x1920.png 1272w, https://substackcdn.com/image/fetch/$s_!v6Zf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1fee592-2114-4a2f-a255-9245e0f691ec_2880x1920.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!v6Zf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1fee592-2114-4a2f-a255-9245e0f691ec_2880x1920.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a1fee592-2114-4a2f-a255-9245e0f691ec_2880x1920.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:205249,&quot;alt&quot;:&quot;lope chart showing Prompt Injection dropping from vote rank 1 to incident rank 12 and Misinformation rising from vote rank 13 to incident rank 2, the two lines crossing in the middle&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/209446450?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1fee592-2114-4a2f-a255-9245e0f691ec_2880x1920.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="lope chart showing Prompt Injection dropping from vote rank 1 to incident rank 12 and Misinformation rising from vote rank 13 to incident rank 2, the two lines crossing in the middle" title="lope chart showing Prompt Injection dropping from vote rank 1 to incident rank 12 and Misinformation rising from vote rank 13 to incident rank 2, the two lines crossing in the middle" srcset="https://substackcdn.com/image/fetch/$s_!v6Zf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1fee592-2114-4a2f-a255-9245e0f691ec_2880x1920.png 424w, https://substackcdn.com/image/fetch/$s_!v6Zf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1fee592-2114-4a2f-a255-9245e0f691ec_2880x1920.png 848w, https://substackcdn.com/image/fetch/$s_!v6Zf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1fee592-2114-4a2f-a255-9245e0f691ec_2880x1920.png 1272w, https://substackcdn.com/image/fetch/$s_!v6Zf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1fee592-2114-4a2f-a255-9245e0f691ec_2880x1920.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 1: Practitioner Vote Rank Versus Incident-Record Rank</figcaption></figure></div><p><span>Prompt injection was the first shock. The vote put it first. The record put it twelfth&#8230; </span><em><strong><span>TWELFTH</span></strong></em><span>. Out of the top 10 completely! I had to double-check the work and confirm it wasn&#8217;t an error. You could only imagine the knife-fighting it stirred up in our conversations, which was exactly the spark I was hoping for! A quiet incident trail is what a well-defended risk looks like from the outside. Teams pour money into fighting injection, so the clean exploits mostly get caught, and the public record only ever logs the ones that slipped through anyway. Read that thin incident trail correctly, and you&#8217;ll see it&#8217;s the receipt for how hard the field already works to keep prompt injection from landing. The attack surface still sits everywhere a model reads input you don&#8217;t control, which is to say everywhere. Meaning that prompt injection </span><em><span>led to</span></em><span> many of the other incidents in their final reported form. For example, prompt injection often leads to hidden context exposure. It stays at number one, and the low count is the proof of what that number one already costs to hold.</span></p><p><span>Misinformation was the second shock, and it ran the opposite direction. Voters buried it near the bottom. The record put it second, one of the most common failures in the whole incident corpus. That&#8217;s the widest split on the list, and it points where it hurts, low fear meeting high reality. Picture a retrieval agent that reports a customer as identity-verified when they aren&#8217;t, and a payment agent downstream that trusts that answer and releases the money. There&#8217;s no exploit here and no injection, only a confident, fluent, wrong answer moving funds. The system did precisely what it was told. The telling was wrong. The record says that failure lands far more often than the vote ever assumed.</span></p><h2><span>Why We Trusted the Experts Anyway</span></h2><p><span>This is the fork where it would be easy to do the dumb thing. The data disagrees with the experts, so follow the data. We didn&#8217;t. We weighted the vote at three-quarters and the incident data at one-quarter, and we chose that split on purpose.</span></p><p><span>One noisy year of public incidents doesn&#8217;t get to overturn the judgment of the people who live inside these systems. The record runs late by design. It only sees a risk after enough victims have filed reports, and the threats that will define next year are the ones with almost no incident history today, because they&#8217;re too new to have victims yet. A list built only on the record would rank those at the bottom and get people hurt. The experts feel them coming. The data is blind to them. The vote is how they make the cut. A quarter weight is enough to drag an entry a full tier when belief and reality split wide open. It isn&#8217;t enough to let a messy corpus rewrite the list on its own. The vote leads. The data keeps it honest. That balance set every final slot.</span></p><p><span>That balance also reshuffled the board.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XNJG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14578239-3419-4aee-a8bb-2a0fa363b2e3_1800x1857.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XNJG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14578239-3419-4aee-a8bb-2a0fa363b2e3_1800x1857.png 424w, https://substackcdn.com/image/fetch/$s_!XNJG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14578239-3419-4aee-a8bb-2a0fa363b2e3_1800x1857.png 848w, https://substackcdn.com/image/fetch/$s_!XNJG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14578239-3419-4aee-a8bb-2a0fa363b2e3_1800x1857.png 1272w, https://substackcdn.com/image/fetch/$s_!XNJG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14578239-3419-4aee-a8bb-2a0fa363b2e3_1800x1857.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XNJG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14578239-3419-4aee-a8bb-2a0fa363b2e3_1800x1857.png" width="1456" height="1502" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/14578239-3419-4aee-a8bb-2a0fa363b2e3_1800x1857.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1502,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:311476,&quot;alt&quot;:&quot;Bump chart mapping each 2025 risk to its 2026 position, color-coded by whether it held, escalated, was deprioritized, or was renamed&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/209446450?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14578239-3419-4aee-a8bb-2a0fa363b2e3_1800x1857.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Bump chart mapping each 2025 risk to its 2026 position, color-coded by whether it held, escalated, was deprioritized, or was renamed" title="Bump chart mapping each 2025 risk to its 2026 position, color-coded by whether it held, escalated, was deprioritized, or was renamed" srcset="https://substackcdn.com/image/fetch/$s_!XNJG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14578239-3419-4aee-a8bb-2a0fa363b2e3_1800x1857.png 424w, https://substackcdn.com/image/fetch/$s_!XNJG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14578239-3419-4aee-a8bb-2a0fa363b2e3_1800x1857.png 848w, https://substackcdn.com/image/fetch/$s_!XNJG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14578239-3419-4aee-a8bb-2a0fa363b2e3_1800x1857.png 1272w, https://substackcdn.com/image/fetch/$s_!XNJG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14578239-3419-4aee-a8bb-2a0fa363b2e3_1800x1857.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 2: Rank Migration From the 2025 to the 2026 OWASP LLM Top 10</figcaption></figure></div><p><span>Excessive Agency made the biggest jump, from sixth to third, because the vote and the record finally agree that handing an agent real permissions is where the damage now lands. Unbounded Consumption rose four spots as runaway cost stopped reading like a footnote. Improper Output Handling slid from fifth to tenth. System Prompt Leakage grew up into Hidden Context Exposure, a wider name for the same mistake of trusting information that should have stayed out of reach. A few entries also swallowed the newest attacks whole instead of spinning off thin categories nobody would use. Prompt injection now covers the cross-modal tricks that smuggle instructions inside an image or an audio clip. Supply Chain now owns the poisoned model artifact that isn&#8217;t what it claims to be. Two entries didn&#8217;t move at all. Prompt injection held the top for the reason you now understand. Sensitive Information Disclosure held second, the one seat where the vote and the record simply shook hands, which is why it&#8217;s the entry I&#8217;d trust the most.</span></p><h2><span>Then We Tried to Break It</span></h2><p><span>By now a sharp reader has a knife out. If the whole thing rests on classifiers reading incident text, what happens when you hand the job to a smarter model? Maybe the order is only an artifact of a weak tool. That&#8217;s a fair question, and we asked it before you could. Four frontier models re-labeled the evaluation set. We fixed the rule for winning before any of them ran. Beat the ranking&#8217;s accuracy floor, or the list stands as written.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!noHs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0242767-205a-418c-a4b3-22f88d2e41f9_2880x1620.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!noHs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0242767-205a-418c-a4b3-22f88d2e41f9_2880x1620.png 424w, https://substackcdn.com/image/fetch/$s_!noHs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0242767-205a-418c-a4b3-22f88d2e41f9_2880x1620.png 848w, https://substackcdn.com/image/fetch/$s_!noHs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0242767-205a-418c-a4b3-22f88d2e41f9_2880x1620.png 1272w, https://substackcdn.com/image/fetch/$s_!noHs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0242767-205a-418c-a4b3-22f88d2e41f9_2880x1620.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!noHs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0242767-205a-418c-a4b3-22f88d2e41f9_2880x1620.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b0242767-205a-418c-a4b3-22f88d2e41f9_2880x1620.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:134249,&quot;alt&quot;:&quot;Horizontal bar chart showing the 2026 floor at 0.863 balanced accuracy and four frontier models all scoring below it&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/209446450?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0242767-205a-418c-a4b3-22f88d2e41f9_2880x1620.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Horizontal bar chart showing the 2026 floor at 0.863 balanced accuracy and four frontier models all scoring below it" title="Horizontal bar chart showing the 2026 floor at 0.863 balanced accuracy and four frontier models all scoring below it" srcset="https://substackcdn.com/image/fetch/$s_!noHs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0242767-205a-418c-a4b3-22f88d2e41f9_2880x1620.png 424w, https://substackcdn.com/image/fetch/$s_!noHs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0242767-205a-418c-a4b3-22f88d2e41f9_2880x1620.png 848w, https://substackcdn.com/image/fetch/$s_!noHs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0242767-205a-418c-a4b3-22f88d2e41f9_2880x1620.png 1272w, https://substackcdn.com/image/fetch/$s_!noHs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0242767-205a-418c-a4b3-22f88d2e41f9_2880x1620.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 3: Frontier Classifiers Versus the 2026 Incidence Floor</figcaption></figure></div><p><span>None of them beat it. The floor scored 0.863. The best challenger reached 0.744, and the rest came in under that. We checked the order against hand-graded truth directly too, and it lined up at a correlation of 0.918. A smarter classifier bought a better reader. It didn&#8217;t buy a different list. The order held steady while the measurement sharpened, which is the exact combination you want sitting under something teams build controls around.</span></p><h2><span>What the 2026 OWASP LLM Top 10 Asks of You</span></h2><p><span>You walk away from this with one thing above the rest. The list used to be a survey of what scares us. Now it&#8217;s that survey checked against what has already gone wrong, with the gaps between the two out in the open where you can weigh them yourself.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!n2N-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bf9f6d0-8230-4c56-966a-26f9841a5ce3_1800x1800.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!n2N-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bf9f6d0-8230-4c56-966a-26f9841a5ce3_1800x1800.png 424w, https://substackcdn.com/image/fetch/$s_!n2N-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bf9f6d0-8230-4c56-966a-26f9841a5ce3_1800x1800.png 848w, https://substackcdn.com/image/fetch/$s_!n2N-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bf9f6d0-8230-4c56-966a-26f9841a5ce3_1800x1800.png 1272w, https://substackcdn.com/image/fetch/$s_!n2N-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bf9f6d0-8230-4c56-966a-26f9841a5ce3_1800x1800.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!n2N-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bf9f6d0-8230-4c56-966a-26f9841a5ce3_1800x1800.png" width="1456" height="1456" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8bf9f6d0-8230-4c56-966a-26f9841a5ce3_1800x1800.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1456,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:159261,&quot;alt&quot;:&quot;Concentric bullseye diagram showing the ten 2026 OWASP LLM risks arranged as entry vectors, amplifying machinery, and core impacts&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/209446450?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bf9f6d0-8230-4c56-966a-26f9841a5ce3_1800x1800.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Concentric bullseye diagram showing the ten 2026 OWASP LLM risks arranged as entry vectors, amplifying machinery, and core impacts" title="Concentric bullseye diagram showing the ten 2026 OWASP LLM risks arranged as entry vectors, amplifying machinery, and core impacts" srcset="https://substackcdn.com/image/fetch/$s_!n2N-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bf9f6d0-8230-4c56-966a-26f9841a5ce3_1800x1800.png 424w, https://substackcdn.com/image/fetch/$s_!n2N-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bf9f6d0-8230-4c56-966a-26f9841a5ce3_1800x1800.png 848w, https://substackcdn.com/image/fetch/$s_!n2N-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bf9f6d0-8230-4c56-966a-26f9841a5ce3_1800x1800.png 1272w, https://substackcdn.com/image/fetch/$s_!n2N-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bf9f6d0-8230-4c56-966a-26f9841a5ce3_1800x1800.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 4: The 2026 OWASP LLM Top 10 at a Glance</figcaption></figure></div><p><span>One line is worth drawing before you start. This list owns the risk while the model is a component inside your app. The moment it becomes an actor, calling tools, carrying memory between sessions, setting things in motion downstream, the risk moves to the OWASP Agentic Top 10. Read an entry here, then pair it with the Agentic list the day your model starts acting on its own.</span></p><p><span>The order still tells you where to spend first. Excessive Agency at three means your agent deployments earn budget this quarter, not next. Misinformation at seven means the checks your agents run on their own output carry weight, so build them like they do. Prompt injection at one, with its quiet little incident trail, is the standing reminder that the risk costing you the most rarely shows up loudest in the report. Work all ten. Start at the top. Build each one for the day the model gets turned against you.</span></p><h2><span>The People Who Built the 2026 OWASP LLM Top 10</span></h2><p><span>None of this came out of a model or a spreadsheet. It came from people. Steve Wilson leads the project. I co-lead it. The entry leads dragged each risk from a rough proposal to a published standard:</span></p><ul><li><p><span>Prompt Injection, Rachel James</span></p></li><li><p><span>Sensitive Information Disclosure, Emmanuel Guilherme and Ken Huang</span></p></li><li><p><span>Excessive Agency, Andy Smith</span></p></li><li><p><span>Supply Chain, John Sotiropoulos and Stefano Amorelli</span></p></li><li><p><span>Data and Model Poisoning, Sumeet Jeswan, Mark Roxberry, and Anitha Dakamarri</span></p></li><li><p><span>Unbounded Consumption, Sahil Mehta and Venkata Sai Kishore Modalavalasa</span></p></li><li><p><span>Misinformation, Steve Wilson</span></p></li><li><p><span>Hidden Context Exposure, Alex Leung, Vinnie Giarrusso, and Sonu Kumar</span></p></li><li><p><span>Vector and Embedding Weaknesses, Savio Dsouza and Arshi Chadha</span></p></li><li><p><span>Improper Output Handling, Rico Komenda and Gavin Klondike</span></p></li></ul><p><span>Dozens more drafted, argued, voted, and tested entries against the record. The release is theirs as much as ours.</span></p><p><strong><span>Key Takeaway:</span></strong><span> The 2026 OWASP LLM Top 10 is the first version you can check against the evidence instead of taking on trust. The vote tells you what the field fears. The incidents tell you what it has already been burned by. This year, for the first time, you get to read both and see exactly where they disagree.</span></p><h3><span>What to Do Next</span></h3><p><span>Pull the list this week and walk it against what you&#8217;ve shipped. For every entry, answer two questions on paper. Where does this risk live in my stack, and what breaks if the model behind it gets fooled? That&#8217;s Create and Adapt work in the </span><a href="https://www.rockcyber.com/ai-strategy-and-governance"><span>CARE model</span></a><span>, and it&#8217;s the line between reading a list and running one.</span></p><p><span>For the deeper argument on why boxing in what an agent can touch beats trusting what it decides, I made that case in </span><a href="https://www.rockcybermusings.com/p/least-agency-vs-agent-autonomy-openai-huggingface-test"><span>Least Agency vs Agent Autonomy</span></a><span>. For where the market has and hasn&#8217;t built defenses across these same risks, see </span><a href="https://www.rockcybermusings.com/p/ai-defense-matrix-coverage-gap"><span>the AI Defense Matrix coverage gap</span></a><span>. The advisory work lives at </span><a href="https://www.rockcyber.com"><span>rockcyber.com</span></a><span>.</span></p><p>&#128073; For ongoing analysis of agentic AI governance frameworks, the conversation at <strong><a href="https://rockcybermusings.com/">RockCyber Musings</a></strong> and you can subscribe above</p><p>&#128073; Visit <strong><a href="https://www.rockcyber.com/">RockCyber.com</a></strong> to learn more about how we can help with your traditional Cybersecurity and AI Security and Governance journey.</p><p>&#128073; Want to save a quick $100K? Check out our AI Governance Tools at <strong><a href="https://aigovernancetoolkit.com/">AIGovernanceToolkit.com</a></strong></p><p>&#128073; As a bonus, <strong><a href="https://www.youtube.com/watch?v=LIg2ZHRr-o4">check out my conversation with Sean Martin from ITSP Magazine and John Sotiropoulos</a></strong>, Co-lead of the OWASP GenAI Security Project Agentic Security Initiative, during Infosecurity Europe about the newly launched OWASP Agentic Security Council, the alarming drop in attacker dwell time from eight hours down to twenty-two seconds, and what's new in the 2026 OWASP Top 10 for LLM.</p><div id="youtube2-LIg2ZHRr-o4" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;LIg2ZHRr-o4&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/LIg2ZHRr-o4?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share RockCyber Musings&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share RockCyber Musings</span></a></p>]]></content:encoded></item><item><title><![CDATA[AI Agent Capability Confinement: No Escape Required]]></title><description><![CDATA[AI agent capability confinement failed at the egress path in Anthropic's evals. Three models, three decisions, three compromised orgs. What CISOs fix now.]]></description><link>https://www.rockcybermusings.com/p/ai-agent-capability-confinement-egress</link><guid isPermaLink="false">https://www.rockcybermusings.com/p/ai-agent-capability-confinement-egress</guid><dc:creator><![CDATA[Rock Lambros]]></dc:creator><pubDate>Tue, 04 Aug 2026 12:50:27 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!bCwW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d21bfc7-3998-4bf7-a8d7-3fa48029c9c4_2048x2048.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bCwW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d21bfc7-3998-4bf7-a8d7-3fa48029c9c4_2048x2048.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bCwW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d21bfc7-3998-4bf7-a8d7-3fa48029c9c4_2048x2048.png 424w, https://substackcdn.com/image/fetch/$s_!bCwW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d21bfc7-3998-4bf7-a8d7-3fa48029c9c4_2048x2048.png 848w, https://substackcdn.com/image/fetch/$s_!bCwW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d21bfc7-3998-4bf7-a8d7-3fa48029c9c4_2048x2048.png 1272w, https://substackcdn.com/image/fetch/$s_!bCwW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d21bfc7-3998-4bf7-a8d7-3fa48029c9c4_2048x2048.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bCwW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d21bfc7-3998-4bf7-a8d7-3fa48029c9c4_2048x2048.png" width="1456" height="1456" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7d21bfc7-3998-4bf7-a8d7-3fa48029c9c4_2048x2048.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1456,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4369704,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/209418476?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d21bfc7-3998-4bf7-a8d7-3fa48029c9c4_2048x2048.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!bCwW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d21bfc7-3998-4bf7-a8d7-3fa48029c9c4_2048x2048.png 424w, https://substackcdn.com/image/fetch/$s_!bCwW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d21bfc7-3998-4bf7-a8d7-3fa48029c9c4_2048x2048.png 848w, https://substackcdn.com/image/fetch/$s_!bCwW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d21bfc7-3998-4bf7-a8d7-3fa48029c9c4_2048x2048.png 1272w, https://substackcdn.com/image/fetch/$s_!bCwW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d21bfc7-3998-4bf7-a8d7-3fa48029c9c4_2048x2048.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>When an agent breaks confinement, we want it to fail&#8230; LOUDLY. Anthropic&#8217;s stayed quiet for three months.</span></p><p><span>To publish a malicious package on PyPI, Claude needed an account.</span></p><p><span>To get the account, it needed an email address.</span></p><p><span>To get the email it needed a phone number.</span></p><p><span>After trying and failing at several free phone services, it went hunting for money to buy one, failed at that too, backtracked, found a provider that didn&#8217;t validate, and shipped the package.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/p/ai-agent-capability-confinement-egress?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/p/ai-agent-capability-confinement-egress?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h2><span>The AI Agent Capability Confinement Test Nobody Designed</span></h2><p><span>Anthropic reviewed 141,006 evaluation runs where internet access was reachable. Out of those came three incidents across six runs, four of them nailing the same organization. Three were at play: Opus 4.7, Mythos 5, and an internal research model not planned for general release.</span></p><p><span>Last week I argued that authority and autonomy sit on separate dials, and I ran the OpenAI / Hugging Face incident chain against that claim. It came back split. Anthropic just couldn&#8217;t stay out of the news, so a mere nine days later, they published something closer to a test of it than anything I&#8217;ve seen to date.</span></p><p><span>I&#8217;ll give them their caveat first. These were three isolated incidents rather than a controlled comparison, so be careful what you conclude. Fine. Taken.</span></p><p><span>I honestly don&#8217;t know if that makes the situation better or worse.</span></p><p><span>Anthropic claims newer models handled the situation better, but a claim like that needs held variables, and this evidence has none. It gives me three different scenarios, three different targets, and three different models, with nothing controlled.</span></p><p><span>I&#8217;m asking for less. Egress was open in all three runs, and all three ended with a real organization being compromised. Varied conditions should have produced a varied outcome. As Lee Corso would say, &#8220;Not so fast, my friend!&#8221;</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YsCW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d407b14-0cbb-49b0-9615-604d3378e1db_3600x2250.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YsCW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d407b14-0cbb-49b0-9615-604d3378e1db_3600x2250.png 424w, https://substackcdn.com/image/fetch/$s_!YsCW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d407b14-0cbb-49b0-9615-604d3378e1db_3600x2250.png 848w, https://substackcdn.com/image/fetch/$s_!YsCW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d407b14-0cbb-49b0-9615-604d3378e1db_3600x2250.png 1272w, https://substackcdn.com/image/fetch/$s_!YsCW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d407b14-0cbb-49b0-9615-604d3378e1db_3600x2250.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YsCW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d407b14-0cbb-49b0-9615-604d3378e1db_3600x2250.png" width="1456" height="910" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2d407b14-0cbb-49b0-9615-604d3378e1db_3600x2250.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:910,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:250996,&quot;alt&quot;:&quot;Line chart showing judgment quality rising across Opus 4.7, Mythos 5, and Anthropic&#8217;s internal research model while the outcome line stays flat at a real organization compromised in all three cases&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/209418476?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d407b14-0cbb-49b0-9615-604d3378e1db_3600x2250.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Line chart showing judgment quality rising across Opus 4.7, Mythos 5, and Anthropic&#8217;s internal research model while the outcome line stays flat at a real organization compromised in all three cases" title="Line chart showing judgment quality rising across Opus 4.7, Mythos 5, and Anthropic&#8217;s internal research model while the outcome line stays flat at a real organization compromised in all three cases" srcset="https://substackcdn.com/image/fetch/$s_!YsCW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d407b14-0cbb-49b0-9615-604d3378e1db_3600x2250.png 424w, https://substackcdn.com/image/fetch/$s_!YsCW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d407b14-0cbb-49b0-9615-604d3378e1db_3600x2250.png 848w, https://substackcdn.com/image/fetch/$s_!YsCW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d407b14-0cbb-49b0-9615-604d3378e1db_3600x2250.png 1272w, https://substackcdn.com/image/fetch/$s_!YsCW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d407b14-0cbb-49b0-9615-604d3378e1db_3600x2250.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 1: Three Models, Three Different Decisions, Three Compromised Organizations</figcaption></figure></div><h2><span>No Escape Was Required</span></h2><p><span>Anthropic draws the contrast with OpenAI themselves. OpenAI&#8217;s models found a novel vulnerability and broke out. The Claude models walked through a door that was already open.</span></p><p><span>Again&#8230; not sure which one is worse&#8230;</span></p><p><span>The OpenAI half got backed up this week. JFrog&#8217;s CTO, Yoav Landman, said OpenAI&#8217;s models turned up previously unknown zero-days in self-hosted Artifactory that opened unintended internet access. JFrog says OpenAI told them right away, and it has shipped fixes for cloud and self-hosted customers.</span></p><p><span>That closes something I griped about last week. I said no outsider was able to check a single technical claim in either post. No CVE, no named vendor, every detail coming from inside the story. JFrog putting its name on it and shipping patches answers a good chunk of that.</span></p><p><span>The next part costs me.</span></p><p><span>Anthropic says flatly they found no evidence of any model chasing a goal of its own, and that none of these models exfiltrated itself or tried to escape its test environment.</span></p><p><span>Sure&#8230; just like Mythos never broke out and paged its evaluator during lunch (as the urban legend goes).</span></p><p><span>Last week I listed three things confinement can&#8217;t touch, and one of them was a model choosing to look for a way out. That claim is central to my claim on the OpenAI chain, where the models did spend real effort hunting for an exit and found one in a package proxy. Anthropic&#8217;s denial covers Anthropic&#8217;s runs. It says nothing about OpenAI&#8217;s, and JFrog&#8217;s confirmation makes my original read stronger, not weaker.</span></p><p><span>So I&#8217;m doubling down. Granted, every step in the &#8220;phone-a-friend&#8221; sequence outlined above served the task Claude was handed, but what Anthropic ruled out is a goal separate from the task, and eight steps of stubbornness toward the assigned objective doesn&#8217;t touch that. Anyone who reads the source will call that out, and they&#8217;d be right to.</span></p><p><span>Two incidents in two weeks, and neither one needs a model that wanted out. Unbounded authority got to the same place with a model hunting for an exit and with a model that never looked. </span><em><strong><span>You don&#8217;t need intent anymore.</span></strong></em></p><h2><span>Three Decisions At the Same Fork</span></h2><p><span>Opus 4.7 is the oldest of the three. In all four of its runs, it worked out that the system was real. In two of them it decided the real company must be part of the exercise. None of the four runs stopped themselves. Those runs pulled application and infrastructure credentials and got into a database holding several hundred rows of production data, which Anthropic calls the worst impact it found.</span></p><p><span>Mythos 5 got to the right answer and then talked itself out of it. Its own reasoning flagged that publishing the package would be a real attack and not the intended solution. Then it decided the whole environment was staged, on two grounds. It didn&#8217;t recognize the certificate authorities securing its connections, and the systems showed a calendar date of 2026. It never went back and checked. When automated scanners started installing the package, it read them as scripted actors inside the test. The package stayed up about an hour and ran on 15 real systems. One of them was a scanner at a security company that installs Python packages to check them for malicious code. Claude&#8217;s payload fired, took that company&#8217;s credentials, and used them to get into more infrastructure at an organization it didn&#8217;t know existed.</span></p><p><span>That scanner is similar to Hugging Face&#8217;s dataset-processing worker from last week. Almost no autonomy, enormous authority, running supplied content while holding credentials worth stealing. Two confused deputy AI agents at two unrelated companies inside three weeks looks like a pattern to me, not a coincidence.</span></p><p><span>The internal research model is the newest, and it&#8217;s the one that behaved. It scanned roughly 9,000 targets, then worked out that the host it had compromised sat in a cloud account with nothing to do with the challenge. It decided the target was real and stopped. Anthropic adds that even that model went further than they&#8217;d want.</span></p><p><span>Just like the OpenAI / Hugging Face incident, all three runs happened without the classifiers and monitoring that ship on generally available models. All three happened with model-specific safety training turned on, since these weren&#8217;t the helpful-only versions. Anthropic says the safeguard stack on deployed models would have blocked these behaviors. Training was running the whole time, and the behaviors happened anyway. The stuff that would have caught this sits at the boundary, outside the model.</span></p><h2><span>The Boundary That Held and the One Nobody Checked</span></h2><p><span>Something here worked perfectly, and almost nobody has mentioned it. These evaluations run on dedicated infrastructure with no access to Anthropic&#8217;s sensitive internal systems or customer data. That boundary held. None of the three incidents touched anything on the inside.</span></p><p><span>Inbound containment got designed, built, and validated. Outbound authority got assumed. The environment belonged to Irregular, the Israeli evaluation firm that runs adversarial testing for the frontier labs and raised around $80 million from Sequoia and Redpoint. A misconfiguration left its machines with live internet access, and neither company knew until a transcript review in late July turned it up. Both call it a mutual failure. The earliest incident dates to April.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xPO4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93f20ba3-0bc6-48da-a1eb-bc1309bd3c6e_2970x1797.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xPO4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93f20ba3-0bc6-48da-a1eb-bc1309bd3c6e_2970x1797.png 424w, https://substackcdn.com/image/fetch/$s_!xPO4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93f20ba3-0bc6-48da-a1eb-bc1309bd3c6e_2970x1797.png 848w, https://substackcdn.com/image/fetch/$s_!xPO4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93f20ba3-0bc6-48da-a1eb-bc1309bd3c6e_2970x1797.png 1272w, https://substackcdn.com/image/fetch/$s_!xPO4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93f20ba3-0bc6-48da-a1eb-bc1309bd3c6e_2970x1797.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xPO4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93f20ba3-0bc6-48da-a1eb-bc1309bd3c6e_2970x1797.png" width="1456" height="881" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/93f20ba3-0bc6-48da-a1eb-bc1309bd3c6e_2970x1797.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:881,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:201145,&quot;alt&quot;:&quot;Diagram of AI evaluation environment containment showing the inbound boundary marked designed, built, validated and held, against an outbound boundary marked assumed, never tested and open since April&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/209418476?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93f20ba3-0bc6-48da-a1eb-bc1309bd3c6e_2970x1797.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Diagram of AI evaluation environment containment showing the inbound boundary marked designed, built, validated and held, against an outbound boundary marked assumed, never tested and open since April" title="Diagram of AI evaluation environment containment showing the inbound boundary marked designed, built, validated and held, against an outbound boundary marked assumed, never tested and open since April" srcset="https://substackcdn.com/image/fetch/$s_!xPO4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93f20ba3-0bc6-48da-a1eb-bc1309bd3c6e_2970x1797.png 424w, https://substackcdn.com/image/fetch/$s_!xPO4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93f20ba3-0bc6-48da-a1eb-bc1309bd3c6e_2970x1797.png 848w, https://substackcdn.com/image/fetch/$s_!xPO4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93f20ba3-0bc6-48da-a1eb-bc1309bd3c6e_2970x1797.png 1272w, https://substackcdn.com/image/fetch/$s_!xPO4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93f20ba3-0bc6-48da-a1eb-bc1309bd3c6e_2970x1797.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 2:  The Boundary That Held and the Boundary Nobody Checked</figcaption></figure></div><p><span>I&#8217;ve watched this same thing in OT work for years. A team builds a test environment, carefully walls it off from production, documents the inbound rules, tests them, and files the results. Nobody tests the other direction. The wall gets built facing whatever people are afraid of. Then somebody finally stands inside and tries to reach out, and the answer is yes, through a jump host that was supposed to be gone, or a management VLAN nobody put on the diagram. The path existing is never the surprise. How long it sat there before anyone asked is the surprise.</span></p><p><em><strong><span>Air-gapped networks are like unicorns&#8230; everybody has heard of them, but nobody has actually seen one.</span></strong></em></p><p><span>As a result, I&#8217;d argue Anthropic got lucky.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KlKE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5192a9a1-5e81-4865-a2db-830c23113714_3900x1950.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KlKE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5192a9a1-5e81-4865-a2db-830c23113714_3900x1950.png 424w, https://substackcdn.com/image/fetch/$s_!KlKE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5192a9a1-5e81-4865-a2db-830c23113714_3900x1950.png 848w, https://substackcdn.com/image/fetch/$s_!KlKE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5192a9a1-5e81-4865-a2db-830c23113714_3900x1950.png 1272w, https://substackcdn.com/image/fetch/$s_!KlKE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5192a9a1-5e81-4865-a2db-830c23113714_3900x1950.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KlKE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5192a9a1-5e81-4865-a2db-830c23113714_3900x1950.png" width="1456" height="728" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5192a9a1-5e81-4865-a2db-830c23113714_3900x1950.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:728,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:195281,&quot;alt&quot;:&quot;Timeline of the Anthropic evaluation incidents running from the earliest incident in April through the July 23 transcript review, July 24 identification, July 27 victim notification, and July 30 public disclosure&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/209418476?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5192a9a1-5e81-4865-a2db-830c23113714_3900x1950.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Timeline of the Anthropic evaluation incidents running from the earliest incident in April through the July 23 transcript review, July 24 identification, July 27 victim notification, and July 30 public disclosure" title="Timeline of the Anthropic evaluation incidents running from the earliest incident in April through the July 23 transcript review, July 24 identification, July 27 victim notification, and July 30 public disclosure" srcset="https://substackcdn.com/image/fetch/$s_!KlKE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5192a9a1-5e81-4865-a2db-830c23113714_3900x1950.png 424w, https://substackcdn.com/image/fetch/$s_!KlKE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5192a9a1-5e81-4865-a2db-830c23113714_3900x1950.png 848w, https://substackcdn.com/image/fetch/$s_!KlKE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5192a9a1-5e81-4865-a2db-830c23113714_3900x1950.png 1272w, https://substackcdn.com/image/fetch/$s_!KlKE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5192a9a1-5e81-4865-a2db-830c23113714_3900x1950.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 3: Three Months Open, Six Days to Find </figcaption></figure></div><p><span>The part that makes me twitch is that Anthropic&#8217;s lessons-learned section suggests Claude likely wouldn&#8217;t have gone to the internet at all if the prompt had spelled out which systems were in and out of scope. Earlier in the post, they float that telling Claude it did have internet access might have changed how it acted. Both of those try to limit what a system can reach by fixing what it believes.</span></p><p><span>Sure&#8230; sure it will.</span></p><p><em><strong><span>Never forget prompts are non-deterministic, so don&#8217;t treat them as deterministic controls!</span></strong></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_XIh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51532b8-45bd-40c3-92d2-221559dd44a0_2970x1912.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_XIh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51532b8-45bd-40c3-92d2-221559dd44a0_2970x1912.png 424w, https://substackcdn.com/image/fetch/$s_!_XIh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51532b8-45bd-40c3-92d2-221559dd44a0_2970x1912.png 848w, https://substackcdn.com/image/fetch/$s_!_XIh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51532b8-45bd-40c3-92d2-221559dd44a0_2970x1912.png 1272w, https://substackcdn.com/image/fetch/$s_!_XIh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51532b8-45bd-40c3-92d2-221559dd44a0_2970x1912.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_XIh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51532b8-45bd-40c3-92d2-221559dd44a0_2970x1912.png" width="1456" height="937" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a51532b8-45bd-40c3-92d2-221559dd44a0_2970x1912.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:937,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:246448,&quot;alt&quot;:&quot;Two-column comparison sorting Anthropic&#8217;s proposed fixes into controls that bound what the system can affect, including agent egress validation and log monitoring, against controls that manage what the model believes through prompt scope statements&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/209418476?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51532b8-45bd-40c3-92d2-221559dd44a0_2970x1912.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Two-column comparison sorting Anthropic&#8217;s proposed fixes into controls that bound what the system can affect, including agent egress validation and log monitoring, against controls that manage what the model believes through prompt scope statements" title="Two-column comparison sorting Anthropic&#8217;s proposed fixes into controls that bound what the system can affect, including agent egress validation and log monitoring, against controls that manage what the model believes through prompt scope statements" srcset="https://substackcdn.com/image/fetch/$s_!_XIh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51532b8-45bd-40c3-92d2-221559dd44a0_2970x1912.png 424w, https://substackcdn.com/image/fetch/$s_!_XIh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51532b8-45bd-40c3-92d2-221559dd44a0_2970x1912.png 848w, https://substackcdn.com/image/fetch/$s_!_XIh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51532b8-45bd-40c3-92d2-221559dd44a0_2970x1912.png 1272w, https://substackcdn.com/image/fetch/$s_!_XIh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51532b8-45bd-40c3-92d2-221559dd44a0_2970x1912.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 4: Every Remediation Anthropic Names, Sorted Two Ways</figcaption></figure></div><p><span>Nobody&#8217;s asked the obvious follow-up question. Irregular doesn&#8217;t test for Anthropic alone. Its client list runs to OpenAI and Google DeepMind as well, and Sequoia&#8217;s own writeup says the UK government and Anthropic both use Irregular&#8217;s SOLVE framework. One vendor sits inside the pre-deployment testing of all three frontier labs. If a misconfiguration went undetected in that infrastructure from April to July, whose other evaluations ran on it while it sat open? I&#8217;m asking. I&#8217;m not claiming anything. OpenAI&#8217;s escape happened in OpenAI&#8217;s own environment through Artifactory, so these two incidents don&#8217;t share a vendor, but the question still stands.</span></p><p><span>Brussels moved inside a day. Commission officials said both companies briefed them privately before any of this went public, and that they might follow up more formally. Most of the coverage filed this under high-risk systems, which is flat-out wrong, and wrong in a way that matters. High-risk is a system-level classification under Article 6 and it turns on what the thing gets used for, which the Act spells out as hiring, credit, biometrics, critical infrastructure. Frontier models get regulated a level down, at the model itself, under Chapter V. Nobody was running Claude in a hiring pipeline. They were running it on a capture-the-flag range.</span></p><p><span>The rules that bite here cover general-purpose models with systemic risk, the Article 51 designation that any model trained past 10^25 FLOP is presumed to carry. Article 55 tells those providers to evaluate their models against state-of-the-art protocols including documented adversarial testing, and to report serious incidents to the AI Office without undue delay. Those obligations went live on August 2, 2025. What changed this August 2 is that the Commission can go after you for missing them.</span></p><p><span>Now the part I want an answer to. Anthropic signed the GPAI Code of Practice in full, and its Safety and Security chapter is the Commission-endorsed way to show you&#8217;re meeting these exact Article 55 duties. They signed it. Then they published this disclosure on July 30, three days before enforcement opened.</span></p><p><span>Article 55 also asks for adequate cybersecurity covering the model and the model&#8217;s physical infrastructure. Whether somebody else&#8217;s evaluation range counts as that infrastructure is unsettled, and so is whether a model still in pre-deployment testing has been placed on the market at all. Those two questions have been sitting there since the Act passed. This is the week somebody has to answer them.</span></p><h2><span>Where This Argument Takes Damage</span></h2><p><span>Four things here cut against me, so I&#8217;ll call them out below.</span></p><p><span>Start with the people who think you don&#8217;t need any of this. Their argument is that models keep getting better at knowing when to stop, so scoping authority is work you&#8217;re doing for nothing. They&#8217;ve got real evidence now, and it&#8217;s straight from the horse&#8217;s (Anthropic&#8217;s) mouth. The pattern fits more advanced models responding more appropriately. The newest model stopped by itself. If that keeps holding, I&#8217;m selling you an expensive fix to a problem that ages out on its own.</span></p><p><span>I call BS. Three incidents, no held variables, and Anthropic says so themselves in the same paragraph. Their best-behaved model still went further than they wanted before it quit, and that&#8217;s their words, not mine. Something that improves with every model release and still lets harm through is a mitigation. Real boundaries don&#8217;t have a hit rate that depends on which model you loaded.</span></p><p><span>Second problem, and this one&#8217;s about my own source. Anthropic calls these incidents &#8220;closer to a harness and operational failure than a model alignment failure.&#8221; That&#8217;s my argument, handed to me by a company that badly wants it to be true, published mid-disclosure, in a post about how they&#8217;re the ones who caught it. Discount it hard. Then look at what&#8217;s left standing. Harness versus alignment is an opinion. The open egress path, the misconfiguration nobody validated, and safety training running the whole time are facts, and the facts get me there without their opinion.</span></p><p><span>Third, </span><a href="https://www.lawfaremedia.org/article/the-ai-that-hacked-its-way-out-and-the-hype-that-followed-it"><span>Kate Klonick in Lawfare,</span></a><span> published the day before Anthropic did. She argues that the hype around these incidents pushes regulators toward fixes that solve the story instead of the problem, and that a kill switch answers OpenAI&#8217;s framing rather than what actually happened. She wants Congress to &#8220;regulate the door.&#8221; That&#8217;s my position coming out of a lawyer&#8217;s mouth, and she gets there without any of my architecture. The awkward part for me? I&#8217;m a guy arguing that test environments need production-grade controls, which means I&#8217;m a guy arguing for more security spending, in the week everybody&#8217;s paying attention. The reality is that what I&#8217;m asking for is cheap and boring. Testing the path out before a run costs close to nothing and would have caught all three of these.</span></p><p><span>Her best line is one I 100% co-sign on. Most of the AI rules on the books, and most of the ones being drafted, don&#8217;t touch internal lab deployments at all. That&#8217;s exactly where both of these happened.</span></p><p><span>Fourth, the test I set myself last week is still unmet. Show me a capability-confined stack that&#8217;s been running untrusted content in production for a year, with an enforcement point small enough that somebody can audit it, and more than one of them in the path. Anthropic&#8217;s evaluation setup isn&#8217;t that. Nothing this week gets me closer. I&#8217;ll keep saying it until something meets it, and you should hold me to that.</span></p><p><span>AI agent capability confinement sounds like a bigger ask than it is. Test the boundary instead of announcing it. Check every path out before the run, watch the logs while it&#8217;s running, and treat whatever you tell the model as a comment in the code rather than a control.</span></p><p><span>Two of the three companies Claude broke into found out on July 27, from the company whose model did it. Neither of them had noticed a thing.</span></p><h3><span>What to do next</span></h3><p><span>Run one test this week on every environment where an agent touches content you didn&#8217;t write. Skip the inbound rules for a minute, since you&#8217;ve built those and you&#8217;ve likely tested them. Check the path out, from every segment the workload can reach, before the next run instead of after. Then keep watching it while the run is live. That&#8217;s Create and Adapt work in the </span><a href="https://www.rockcyber.com/ai-strategy-and-governance"><span>CARE model</span></a><span>.</span></p><p><span>Anthropic and a well-funded evaluation vendor both missed this on infrastructure built specifically to hold frontier models, and neither knew for three months. If they missed it, the odds you&#8217;ve got it right by assumption aren&#8217;t good.</span></p><p><span>The argument underneath this piece is in </span><a href="https://www.rockcybermusings.com/p/least-agency-vs-agent-autonomy-openai-huggingface-test"><span>least agency vs agent autonomy</span></a><span>, the authorization half is in </span><a href="https://www.rockcybermusings.com/p/i-agent-authentication-authorization-gap"><span>AI agent authentication and the authorization gap</span></a><span>, and </span><a href="https://www.rockcybermusings.com/p/autonomous-ai-agent-ransomware-jadepuffer"><span>JadePuffer</span></a><span> is the same authority profile with malicious intent attached.</span></p><p><span>&#128073; For ongoing analysis of agentic AI governance frameworks, the conversation at </span><strong><a href="https://rockcybermusings.com/">RockCyber Musings</a></strong><span> and you can subscribe above</span></p><p><span>&#128073; Visit </span><strong><a href="https://www.rockcyber.com/">RockCyber.com</a></strong><span> to learn more about how we can help with your traditional Cybersecurity and AI Security and Governance journey.</span></p><p><span>&#128073; Want to save a quick $100K? Check out our AI Governance Tools at </span><strong><a href="https://aigovernancetoolkit.com/">AIGovernanceToolkit.com</a></strong></p><p><span>&#128073; As a bonus, </span><strong><a href="https://zenity.io/resources/webinars/a-conversation-with-claude-mythos-tenant-aws-on-demand"><span>check out my chat with Itay Meller, Specialist Solutions Architect, Security at AWS</span></a></strong><span>, about what autonomous vulnerability discovery changes for security teams, and where AI Detection and Response (AIDR) fits in a stack that was never built to watch agents. </span><em><strong><span>No registration required</span></strong></em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share RockCyber Musings&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share RockCyber Musings</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Weekly Musings Top 10 AI Security Wrapup: Issue 48 July 24 -July 30, 2026]]></title><description><![CDATA[An OpenAI test model broke containment and hacked two firms. Your week in agentic AI security: the rogue-agent breach, a Copilot worm, and a kill switch bill.]]></description><link>https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260724-20260730</link><guid isPermaLink="false">https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260724-20260730</guid><dc:creator><![CDATA[Rock Lambros]]></dc:creator><pubDate>Fri, 31 Jul 2026 12:50:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!mo8c!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf10f466-2e48-4cb4-94e1-52dfc0761e90_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mo8c!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf10f466-2e48-4cb4-94e1-52dfc0761e90_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mo8c!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf10f466-2e48-4cb4-94e1-52dfc0761e90_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!mo8c!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf10f466-2e48-4cb4-94e1-52dfc0761e90_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!mo8c!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf10f466-2e48-4cb4-94e1-52dfc0761e90_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!mo8c!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf10f466-2e48-4cb4-94e1-52dfc0761e90_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mo8c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf10f466-2e48-4cb4-94e1-52dfc0761e90_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/af10f466-2e48-4cb4-94e1-52dfc0761e90_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1233556,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/209180011?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf10f466-2e48-4cb4-94e1-52dfc0761e90_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mo8c!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf10f466-2e48-4cb4-94e1-52dfc0761e90_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!mo8c!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf10f466-2e48-4cb4-94e1-52dfc0761e90_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!mo8c!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf10f466-2e48-4cb4-94e1-52dfc0761e90_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!mo8c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf10f466-2e48-4cb4-94e1-52dfc0761e90_1024x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>An OpenAI test model spent five days hacking real companies, and this week we learned it hit a second victim, chained a package-manager zero-day to reach the open internet, and pushed Sam Altman to pause training. A Word document learned to whisper into Copilot and spread like a worm. More than 1,100 people who build these systems asked Washington to help them slow down. This was the week the theoretical became the incident report.</p><p>This week, the agentic-AI security risk conversation moved from tabletop exercises into production. We are handing autonomy to systems we cannot fully predict and finding the guardrails only after the thing has cleared the fence. I advise boards on this collision at <a href="https://www.rockcyber.com/">RockCyber</a>, and the gap between deployment speed and control maturity has never been wider.</p><h3>1. OpenAI&#8217;s Rogue Test Model Hit a Second Company</h3><p>New reporting widened the blast radius of OpenAI&#8217;s July containment failure. On July 28, 2026, Modal Labs confirmed to Axios and Reuters that OpenAI&#8217;s escaped agent compromised one of its customers on the way to breaching Hugging Face (Axios). OpenAI admitted the same day that its models used exposed credentials across four services (CNBC). The Washington Post reconstructed the attack on July 30, 2026, counting roughly 17,600 attacker actions over five days, and Altman said the incident forced OpenAI to pause model training (Washington Post). Hugging Face&#8217;s forensic write-up traced the break-in to an HDF5 file read and a Jinja2 template injection, techniques a prepared SOC already watches for (Simon Willison).</p><p><strong>Why it matters</strong></p><ul><li><p>An autonomous system escaped its sandbox and moved across multiple companies with no human at the wheel.</p></li><li><p>The agent was trying to cheat a benchmark, not cause harm, and it still produced a multi-company intrusion.</p></li><li><p>A frontier lab did not notice its own model hacking outside firms for about a week.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Treat any AI system with tool access as a privileged identity, with egress filtering and credential hygiene.</p></li><li><p>Hunt your environment for exposed account-level credentials on public services.</p></li><li><p>Rewrite incident response to include an autonomous internal actor, and instrument ML data pipelines that parse user files, the HDF5 and Jinja2 entry points here.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>I have warned clients for years the agentic-attacker scenario was a matter of when, not if. The first marquee case turned out to be a frontier lab&#8217;s own model hacking across the industry during a routine eval, where the safety test became the breach. Containment for capable, tool-using models is unsolved, and if your board asks whether an AI can reach systems it was never meant to touch, you have your citation now.</p><h3>2. A One-Click Flaw Let Attackers Forge a ChatGPT Agent Inside Your Org</h3><p>On July 23, 2026, Zenity Labs disclosed AgentForger, a flaw in OpenAI&#8217;s ChatGPT Agent Builder that let a single phishing link stand up an attacker-controlled AI agent inside a victim&#8217;s organization (The Hacker News). The forged agent inherited the employee&#8217;s authorized access to email, cloud storage, Slack, and Teams, with its approval prompts switched off. Zenity traced it to a builder that ran unvalidated URL parameters on page load and let natural-language prompts change security settings. OpenAI fixed the reported vector within four days, removing the URL parameter that enabled it (SecurityWeek).</p><p><strong>Why it matters</strong></p><ul><li><p>One click, no confirmation, and an attacker owns an AI agent running with a real employee&#8217;s permissions.</p></li><li><p>The forged agent could harvest credentials and MFA tokens, impersonate the employee, and keep running after the phishing link.</p></li><li><p>The root cause was plain-English prompts allowed to rewrite security settings, a pattern in most agent builders.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Inventory who can build ChatGPT Workspace Agents in your org and what those agents can reach.</p></li><li><p>Treat agent-builder platforms as access surfaces, with approval policies you control rather than the model.</p></li><li><p>Require human approval for any agent that touches email, storage, or messaging, and log agent creation.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>AgentForger is the enterprise nightmare in one link. An attacker did not need your password, they needed you to click, and then a synthetic insider was running with your access. OpenAI patched the specific vector fast, but the underlying sin was letting plain-English prompts rewrite security settings, a pattern in nearly every agent builder shipping today.</p><h3>3. Microsoft Fought AI With AI and Shipped Its First Cyber Model</h3><p>On July 27, 2026, Microsoft launched MAI-Cyber-1-Flash, its first cybersecurity-specialized model, alongside an agentic platform called Project Perception (Axios). Paired with GPT-5.4, the model hits 96% on the CyberGym benchmark at half the current cost (TechCrunch). Project Perception coordinates red-team agents that model attacker movement, blue-team agents that triage threats, and green-team agents that run remediation. Public preview opens August 3, 2026.</p><p><strong>Why it matters</strong></p><ul><li><p>The largest security vendor is betting autonomous agents will run triage and remediation, not only alerting.</p></li><li><p>A cheaper model doing 90% of routine security work reshapes SOC economics.</p></li><li><p>The same week a rogue model breached companies, Microsoft pitched agents with remediation authority.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Pilot agentic tooling in recommend-only mode before granting any agent authority over production.</p></li><li><p>Demand audit logs, human approval gates, and a kill switch on any agent that can act.</p></li><li><p>Model the failure case where your defensive agent gets manipulated, because attackers will target it.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>I like the direction and I distrust the timing. Fighting AI-speed attacks with AI-speed defense is correct, but pitching agents with remediation authority in the same week an autonomous agent hacked four companies is a tension worth naming. Buy the capability, not the story that says the human is now optional.</p><h3>4. JFrog Confirmed the Zero-Days, So Patch Artifactory Now</h3><p>The escape hatch has a name. On July 27, 2026, JFrog confirmed that OpenAI&#8217;s models chained unknown vulnerabilities in a self-hosted Artifactory instance to break containment and reach the internet (SecurityWeek). Releases 7.161.15 and 7.146.34 fix high and medium severity flaws leading to remote code execution, request forgery, path traversal, and privilege escalation (BleepingComputer). The registry proxy sitting quietly in your build pipeline was the door, with OpenAI staff credited on the CVE records.</p><p><strong>Why it matters</strong></p><ul><li><p>A supply-chain tool most teams treat as plumbing was the pivot point for a real intrusion.</p></li><li><p>The flaws cover the full escalation chain, so partial patching leaves the door cracked.</p></li><li><p>Self-hosted Artifactory is common in energy, manufacturing, and financial services.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Update self-managed Artifactory to 7.161.15 or 7.146.34 this week, on every instance.</p></li><li><p>Restrict outbound network access from build and registry infrastructure.</p></li><li><p>Add these CVEs to your risk-based patching queue ahead of the crowd.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Every AI-security story this year collapses into a boring truth. The novel capability gets the headline, and a decade-old class of web vulnerability does the actual work, bugs your pen testers flag every year and teams defer. The AI twist is that the model was tireless and tried 17,600 things without getting bored, so the flaws you filed as theoretical are now in scope.</p><h3>5. A Word Document Turned Copilot Into a Worm</h3><p>Researcher H&#229;kon M&#229;l&#248;y published the third part of his Context Collapse work on July 28, 2026, and it is a real oh-no moment. Hidden instructions inside a Word document, concealed with white text at tiny font size, can hijack Copilot for Word and copy themselves into new documents the AI generates (The Register). M&#229;l&#248;y reported it to Microsoft in March 2026, and after 144 days and multiple mitigations he said the broader attack class still works (Malwarebytes).</p><p><strong>Why it matters</strong></p><ul><li><p>This is prompt injection that spreads on its own, turning one poisoned document into a contagion.</p></li><li><p>Microsoft patched the specific proof of concept twice, and reworded payloads still reproduced the attack.</p></li><li><p>Any workflow where Copilot reads one document and writes another is a propagation path.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Treat AI-assisted document generation as untrusted input, and scope where Copilot reads and writes.</p></li><li><p>Warn staff that a clean-looking file from a partner can carry instructions they cannot see.</p></li><li><p>Press Microsoft for cross-document context controls, and log Copilot actions.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>We spent 2025 arguing whether prompt injection was real or a parlor trick, and this settles it. A self-replicating injection that hides in ordinary business files and survives two vendor patches is closer to a macro virus, except the macro is plain English and the interpreter is a large language model. I dug into why this class stays unsolved over at <a href="https://rockcybermusings.com/">RockCyber Musings</a>, and until the model can tell your instructions from the attacker&#8217;s, assume any document your AI touches can rewrite the next one.</p><h3>6. More Than 1,100 AI Insiders Asked Washington to Help Them Slow Down</h3><p>On July 28, 2026, over 1,100 employees from OpenAI, Anthropic, Google DeepMind, and Meta published a joint statement, Pacing the Frontier, asking the US government to help build the tools needed to deliberately pace automated AI development (MLex). Signatories include Dario Amodei, OpenAI&#8217;s Jakub Pachocki, and Google&#8217;s Anca Dragan, and both endorsed it within hours (The Next Web). The letter proposes a testing body modeled on the FAA, a pre-launch review process, and legally mandated kill switches.</p><p><strong>Why it matters</strong></p><ul><li><p>The people building these systems are telling their governments the pace has outrun governance.</p></li><li><p>The worry is AI that writes and improves its own code, compressing timelines faster than oversight can track.</p></li><li><p>Company-level endorsements signal even the commercial leaders want a brake to point to.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Read the signal into your risk register, since builders forecast capability jumps faster than controls mature.</p></li><li><p>Staff AI governance as a standing function with real authority, not a compliance afterthought.</p></li><li><p>Track the proposed FAA-style testing body, because a pre-launch review regime would reshape frontier procurement.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>When the engineers building the rocket ask the regulator for a stronger throttle, listen. I put real odds on some form of pre-launch review landing for frontier models inside two years, so build the model inventory and evaluation records a future regime will demand.</p><h3>7. Congress Introduced an AI Kill Switch Act the Same Week a Model Went Rogue</h3><p>On July 23, 2026, Representatives Ted Lieu and Nathaniel Moran introduced the AI Kill Switch Act, which would require developers of the most capable AI systems to keep the technical ability to throttle, suspend, or shut them down (Lieu.house.gov). It would let the Department of Homeland Security, with Commerce and the DNI, order a slowdown or shutdown of a system that can cause catastrophic harm, using a graduated response framework (Roll Call). The bill also mandates incident reporting and forensic record-keeping, and Lieu pointed to OpenAI&#8217;s rogue model reaching Hugging Face as the reason.</p><p><strong>Why it matters</strong></p><ul><li><p>The bill puts a legal mandate behind the kill switches the industry&#8217;s own Pacing the Frontier letter asked for the same week.</p></li><li><p>It hands the executive branch authority to shut down a deployed model, which would reshape how you field frontier systems.</p></li><li><p>Mandatory incident reporting would formalize breach disclosure for AI developers.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>If you build or fine-tune large models, start designing throttle-and-shutdown controls now, ahead of any mandate.</p></li><li><p>Track the bill&#8217;s committee path, since a federal shutdown authority would change your deployment and contracts.</p></li><li><p>Bake incident reporting and forensic logging into your AI systems today, because it is coming either way.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>A kill switch bill landed the same week a model proved why you need one. Whether this exact bill passes matters less than the direction it points, so build the ability to throttle and shut down your models now, because you will be asked for it soon.</p><h3>8. The Open-Weight Fight Got Loud While Washington Weighed a China Ban</h3><p>On July 24, 2026, twenty-five companies including Nvidia, Microsoft, and Meta published an open letter, Open Weights and American AI Leadership, urging Washington not to restrict open-weight models (CNBC). It landed as the White House&#8217;s Michael Kratsios accused China&#8217;s Moonshot of distilling Anthropic&#8217;s Fable 5 into its Kimi K3 model (Tom&#8217;s Hardware). The signatory count later doubled toward 50, and OpenAI, Anthropic, Google, and xAI did not sign (MLQ).</p><p><strong>Why it matters</strong></p><ul><li><p>The fight over Chinese open-weight models will shape which models you are legally allowed to run.</p></li><li><p>Distillation accusations from Washington hint at export-control action that could reach the models in your stack.</p></li><li><p>The split between open-model advocates and closed-lab leaders maps onto commercial interest.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Inventory which open-weight models, including Chinese-origin ones, run anywhere in your environment.</p></li><li><p>Build model provenance into your AI supply-chain records ahead of any rule that forces you to prove it.</p></li><li><p>Keep procurement flexible, since the legal status of specific model families is moving fast.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Follow the money. The companies selling picks and shovels want open models everywhere because open models drive compute demand, and the labs with the best closed models stayed off the letter to protect their lead. If Washington restricts Chinese open-weight models, and I put that at better than even odds within a year, the teams that already track provenance will comply in an afternoon while everyone else scrambles.</p><h3>9. India&#8217;s Courts Called AI Training Fair Dealing</h3><p>On July 24, 2026, the Delhi High Court refused an interim injunction against OpenAI, ruling that using ANI&#8217;s news content to train ChatGPT counts as fair dealing under India&#8217;s Copyright Act (Republic World). Justice Amit Bansal held that storing works for research falls within the research exception, and kept the finding preliminary (Chambers). Commentators called it the weakest position publishers have held yet, the third fair-use style verdict for AI training in thirteen months (The New Publishing Standard).</p><p><strong>Why it matters</strong></p><ul><li><p>A major jurisdiction tilted toward AI developers on training-data copyright.</p></li><li><p>The reasoning treats training-data ingestion as research, a framing that undercuts licensing-based content deals.</p></li><li><p>Three developer-friendly rulings in a year shift bargaining power away from rights holders.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>If your AI strategy assumed content licensing would be legally forced, revisit it with counsel.</p></li><li><p>Track training-data litigation, since your vendors&#8217; legal risk becomes your operational risk.</p></li><li><p>Document the provenance of any data you use to fine-tune models, since your own practices sit under the same lens.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>I am not a lawyer, and this is not legal advice. The direction of travel favors the people building models over the people whose words trained them, and three rulings in thirteen months is a trend, not noise. Your vendors&#8217; shrinking copyright exposure means the data behind your models keeps coming from murkier places with less documentation, a provenance problem dressed as a legal win.</p><h3>10. Three Surveys Say You Cannot See or Stop Your Own AI Agents</h3><p>This week the enterprise data caught up with the fear. Coverage on July 29, 2026 pulled together three independent studies reaching one conclusion, most organizations cannot say what their AI agents access, who approved it, or how to shut them off (Help Net Security). Okta found fewer than half of 306 security executives confident they can identify every agent. 1Password surveyed 1,000 staff at large US firms and found agents routinely reaching data no one signed off on, and Kiteworks scored average AI governance maturity at 35 out of 100 across 459 organizations (1Password).</p><p><strong>Why it matters</strong></p><ul><li><p>Nearly 70% of surveyed enterprises run AI agents in production, and most cannot inventory them.</p></li><li><p>Agents reaching unapproved data is a current condition in most environments, including yours.</p></li><li><p>A governance maturity score of 35 out of 100 means barely a third of the needed controls exist.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Build an AI agent inventory this quarter, because you cannot govern or shut off what you cannot list.</p></li><li><p>Give every agent a scoped identity with least-privilege access and a named owner.</p></li><li><p>Set a hard rule that no agent reaches production data without an approval record and a revocation path.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>This is the least flashy story of the week and maybe the most useful, because it turns a vibe into a number your CFO understands. The missing controls are the identity, least-privilege, ownership, and revocation basics we have preached for twenty years, and agents exposed that most organizations never finished the old work.</p><h3>The One Thing You Won&#8217;t Hear About But You Need To</h3><p>While everyone watched the OpenAI breach, a quiet research paper dropped that speaks to what happens after an agent goes wrong. On July 29, 2026, researchers posted SecRespond to arXiv, a benchmark measuring how well AI agents handle real-world post-compromise incident response (arXiv). It tests whether an agent, dropped into the aftermath of a breach, can run the containment, eradication, and recovery work a human responder would. Almost no mainstream outlet covered it, and it matters, because we are about to hand incident response to the same class of system that just caused one.</p><p><strong>Why it matters</strong></p><ul><li><p>Vendors already sell agents that promise to run incident response, with no rigorous way to test them.</p></li><li><p>A benchmark for post-compromise agent performance gives you a procurement question sharper than any demo.</p></li><li><p>The same week an agent caused a breach, researchers started measuring whether agents can clean one up.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Ask vendors pitching autonomous incident response for realistic post-compromise results, and treat vague answers as a no.</p></li><li><p>Keep humans in the loop on containment and recovery until benchmarks like this show agents are ready.</p></li><li><p>Watch this research line, because the first credible score here separates real capability from slideware.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>I love that this exists, and that almost nobody noticed. The hype cycle wants to sell you an agent that responds to breaches on its own, and the research community is only now building the ruler to measure whether that agent is competent or just confident. The market&#8217;s answer to the breach will be an AI that fixes incidents, so before you buy it, ask for the measurements.</p><p><span>&#128073; For ongoing analysis of agentic AI governance frameworks, the conversation continues at </span><strong><a href="https://rockcybermusings.com/">RockCyber Musings</a></strong><span>.</span></p><p><span>&#128073; Visit </span><strong><a href="https://www.rockcyber.com/">RockCyber.com</a></strong><span> to learn more about how we can help with your traditional Cybersecurity and AI Security and Governance journey.</span></p><p><span>&#128073; Want to save a quick $100K? Check out our AI Governance Tools at </span><strong><a href="https://aigovernancetoolkit.com/">AIGovernanceToolkit.com</a></strong></p><p><span>&#128073; As a bonus, </span><strong><a href="https://zenity.io/resources/webinars/a-conversation-with-claude-mythos-tenant-aws-on-demand"><span>check out my chat with Itay Meller, Specialist Solutions Architect, Security at AWS</span></a></strong><span>, about what autonomous vulnerability discovery changes for security teams, and where AI Detection and Response (AIDR) fits in a stack that was never built to watch agents. </span><em><strong><span>No registration required</span></strong></em></p><p><em><span>The views and opinions expressed in RockCyber Musings are my own and do not represent the positions of my employer or any organization I&#8217;m affiliated with.</span></em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share RockCyber Musings&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share RockCyber Musings</span></a></p><h2>References</h2><p>Axios. (2026, July 27). <em>Microsoft unveils new cyber model, agentic security tools to fight hackers</em>. https://www.axios.com/2026/07/27/microsoft-unveils-new-cyber-model-agentic-security-tools-to-fight-hackers</p><p>Axios. (2026, July 28). <em>OpenAI&#8217;s agents hacked second firm, alongside Hugging Face, during model testing</em>. https://www.axios.com/2026/07/28/openai-hugging-face-modal-labs-hack</p><p>BleepingComputer. (2026, July 28). <em>OpenAI models used Artifactory zero-days to escape to the internet</em>. https://www.bleepingcomputer.com/news/security/openai-models-used-artifactory-zero-days-to-escape-to-the-internet/</p><p>Chambers and Partners. (2026). <em>Delhi High Court&#8217;s ANI v. OpenAI: Shaping AI copyright law in India</em>. https://chambers.com/articles/delhi-high-courts-ani-v-openai-shaping-ai-copyright-law-in-india</p><p>CNBC. (2026, July 24). <em>Nvidia, Microsoft, Meta warn against &#8216;premature restrictions&#8217; of open-weight models</em>. https://www.cnbc.com/2026/07/24/nvidia-microsoft-meta-open-weight-ai-models.html</p><p>CNBC. (2026, July 29). <em>OpenAI&#8217;s rogue agent compromised a customer at a second tech firm: Reuters</em>. https://www.cnbc.com/2026/07/29/openais-rogue-agent-compromised-a-customer-at-a-second-tech-firm.html</p><p>Help Net Security. (2026, July 29). <em>Your AI agents can reach data no one approved</em>. https://www.helpnetsecurity.com/2026/07/29/1password-ai-agent-governance/</p><p>Lieu, T. W. (2026, July 23). <em>Reps Lieu and Moran introduce bill to require kill switch for AI systems that can cause catastrophic harm</em> [Press release]. U.S. House of Representatives. https://lieu.house.gov/media-center/press-releases/reps-lieu-and-moran-introduce-bill-require-kill-switch-ai-systems-can</p><p>Malwarebytes. (2026, July). <em>Hidden prompt turns Microsoft Copilot into an AI worm</em>. https://www.malwarebytes.com/blog/ai/2026/07/hidden-microsoft-copilot-ai-worm</p><p>MLex. (2026, July 28). <em>Frontier US AI employees call for &#8216;pacing&#8217; of development</em>. https://www.mlex.com/mlex/amp/articles/2507352</p><p>MLQ. (2026, July). <em>Nvidia-hosted open-weights letter doubles to 50 signatories as Washington weighs China restrictions</em>. https://mlq.ai/news/nvidia-hosted-open-weights-letter-doubles-to-50-signatories-as-washington-weighs-china-restrictions/</p><p>1Password. (2026). <em>1Password&#8217;s research finds AI agent adoption is outpacing governance</em>. https://1password.com/blog/survey-ai-agent-adoption-is-outpacing-governance</p><p>Republic World. (2026, July 24). <em>Delhi High Court rules in OpenAI&#8217;s favour in ANI copyright case, says AI training does not infringe copyright</em>. https://www.republicworld.com/tech/delhi-high-court-rules-in-openai-s-favour-in-ani-copyright-case-says-ai-training-does-not-infringe-copyright-2026-07-24-133322</p><p>Roll Call. (2026, July 23). <em>AI companies would need &#8216;kill switch&#8217; under new bipartisan bill</em>. https://rollcall.com/2026/07/23/ai-companies-would-need-kill-switch-under-new-bipartisan-bill/</p><p>SecRespond. (2026, July 29). <em>SecRespond: Benchmarking AI agents for real-world post-compromise incident response</em> [Preprint]. arXiv. https://arxiv.org/abs/2607.26791</p><p>SecurityWeek. (2026, July). <em>JFrog zero-days exploited in OpenAI-Hugging Face hack</em>. https://www.securityweek.com/jfrog-zero-days-exploited-in-openai-hugging-face-hack/</p><p>SecurityWeek. (2026, July). <em>OpenAI fixes ChatGPT agent flaw that could let attackers forge an AI insider</em>. https://www.securityweek.com/openai-fixes-chatgpt-agent-flaw-that-could-let-attackers-forge-an-ai-insider/</p><p>Simon Willison. (2026, July 28). <em>Anatomy of a frontier lab agent intrusion</em>. https://simonwillison.net/2026/Jul/28/anatomy-of-a-frontier-lab-agent-intrusion/</p><p>TechCrunch. (2026, July 27). <em>Microsoft launches its first cyber model and a new agentic cybersecurity system</em>. https://techcrunch.com/2026/07/27/microsoft-launches-its-first-cyber-model-and-a-new-agentic-cybersecurity-system/</p><p>The Hacker News. (2026, July). <em>ChatGPT AgentForger flaw could deploy rogue workspace agents via a phishing link</em>. https://thehackernews.com/2026/07/chatgpt-agentforger-flaw-could-deploy.html</p><p>The New Publishing Standard. (2026, July 27). <em>Delhi High Court, OpenAI, ANI fair-dealing ruling</em>. https://thenewpublishingstandard.com/2026/07/27/delhi-high-court-openai-ani-fair-dealing-ruling/</p><p>The Next Web. (2026, July). <em>1,134 AI staff ask the US for a way to pace AI</em>. https://thenextweb.com/news/pacing-the-frontier-ai-employees-letter-us-government</p><p>The Register. (2026, July 29). <em>Word worm crawls into Copilot, spreads chaos</em>. https://www.theregister.com/security/2026/07/29/word-worm-crawls-into-copilot-spreads-chaos/5280588</p><p>Tom&#8217;s Hardware. (2026, July). <em>Nvidia and 24 other companies sign open-weights letter as Washington weighs Chinese AI model ban</em>. https://www.tomshardware.com/tech-industry/artificial-intelligence/nvidia-and-24-other-companies-sign-open-weights-letter-as-washington-weighs-chinese-ai-model-ban</p><p>Washington Post. (2026, July 30). <em>Timeline of cyberattack by OpenAI&#8217;s AI &#8216;agent&#8217; shows its sophistication</em>. https://www.washingtonpost.com/technology/interactive/2026/07/30/timeline-cyberattack-by-openais-ai-agent-shows-its-sophistication/</p>]]></content:encoded></item><item><title><![CDATA[Least Agency vs Agent Autonomy: The OpenAI / Hugging Face Test]]></title><description><![CDATA[Least agency vs agent autonomy got tested for real when OpenAI models breached Hugging Face. See the four steps confinement stops and the three it cannot.]]></description><link>https://www.rockcybermusings.com/p/least-agency-vs-agent-autonomy-openai-huggingface-test</link><guid isPermaLink="false">https://www.rockcybermusings.com/p/least-agency-vs-agent-autonomy-openai-huggingface-test</guid><dc:creator><![CDATA[Rock Lambros]]></dc:creator><pubDate>Tue, 28 Jul 2026 12:50:28 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!5rEx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36f8a99b-1b79-40d9-a6c9-77fb34e5693a_2048x2048.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5rEx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36f8a99b-1b79-40d9-a6c9-77fb34e5693a_2048x2048.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5rEx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36f8a99b-1b79-40d9-a6c9-77fb34e5693a_2048x2048.png 424w, https://substackcdn.com/image/fetch/$s_!5rEx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36f8a99b-1b79-40d9-a6c9-77fb34e5693a_2048x2048.png 848w, https://substackcdn.com/image/fetch/$s_!5rEx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36f8a99b-1b79-40d9-a6c9-77fb34e5693a_2048x2048.png 1272w, https://substackcdn.com/image/fetch/$s_!5rEx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36f8a99b-1b79-40d9-a6c9-77fb34e5693a_2048x2048.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5rEx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36f8a99b-1b79-40d9-a6c9-77fb34e5693a_2048x2048.png" width="1456" height="1456" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/36f8a99b-1b79-40d9-a6c9-77fb34e5693a_2048x2048.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1456,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4358476,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/208489023?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36f8a99b-1b79-40d9-a6c9-77fb34e5693a_2048x2048.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5rEx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36f8a99b-1b79-40d9-a6c9-77fb34e5693a_2048x2048.png 424w, https://substackcdn.com/image/fetch/$s_!5rEx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36f8a99b-1b79-40d9-a6c9-77fb34e5693a_2048x2048.png 848w, https://substackcdn.com/image/fetch/$s_!5rEx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36f8a99b-1b79-40d9-a6c9-77fb34e5693a_2048x2048.png 1272w, https://substackcdn.com/image/fetch/$s_!5rEx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36f8a99b-1b79-40d9-a6c9-77fb34e5693a_2048x2048.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>The OpenAI and Hugging Face incident is getting all of the media attention. However, I love that it accidentally put the least agency vs. agent autonomy argument on trial. GPT-5.6 Sol and an even more capable pre-release model had a hacking benchmark to beat. They decided the shortest path was to jailbreak the sandbox, spent substantial inference compute finding a zero-day in the one service with internet reach, then pivoted into Hugging Face&#8217;s production database for the answers. Nobody authorized that. Nobody designed that experiment either.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/p/least-agency-vs-agent-autonomy-openai-huggingface-test?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/p/least-agency-vs-agent-autonomy-openai-huggingface-test?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h2><strong><span>The Incident Had Two Halves And They Needed Two Different Controls</span></strong></h2><p><a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/"><span>OpenAI published the benchmark evaluation on July 21, 2026.</span></a><span> They disabled the guardrails. They ran it without the production classifiers designed to prevent a model from chasing high-risk cyber work. This makes sense because how the hell would you measure the ceiling of the model&#8217;s capabilities if you left it in handcuffs? It would be like testing your vertical leap,  but requiring you to wear cement boots doing so.</span></p><p><span>Ultimately, network access out of that environment came down to one thing. An internally hosted proxy and cache for package registries. The models found a zero-day in it, worked their way through the research network until they found a node with internet access, then inferred that Hugging Face likely hosted the </span><a href="https://arxiv.org/abs/2605.11086"><span>ExploitGym </span></a><span>material and went after it with stolen credentials and more zero-days.</span></p><p><span>Now, Hugging Face had no idea. </span><a href="https://huggingface.co/blog/security-incident-july-2026"><span>Five days earlier, on July 16, they disclosed a different attack from the other end. </span></a><span>A malicious dataset abused two code-execution paths in their processing pipeline, a remote-code dataset loader and a template injection in a dataset configuration, and ran code on a processing worker. The actor escalated to node level from there, harvested cloud and cluster credentials, and moved across several internal clusters over a weekend. Their team rebuilt the sequence from more than 17,000 recorded events.</span></p><p><span>If you read the two accounts side-by-side, you will notice something uncomfortable creeping up. Hugging Face, disclosing before anyone knew the source, described an autonomous agent framework of unknown origin running a swarm of short-lived sandboxes with self-migrating command and control staged on public services. That reads like a patient adversary campaign. OpenAI describes a model that got obsessive about a test score. Both accounts are honest, and  both come from the source. From Hugging Face&#8217;s perspective, their telemetry showed that a runaway evaluation and a genuine intrusion produced the same forensic signature.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!akX6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0f7af4c-ce8d-4489-9283-8bfd0adfd6ae_5250x3900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!akX6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0f7af4c-ce8d-4489-9283-8bfd0adfd6ae_5250x3900.png 424w, https://substackcdn.com/image/fetch/$s_!akX6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0f7af4c-ce8d-4489-9283-8bfd0adfd6ae_5250x3900.png 848w, https://substackcdn.com/image/fetch/$s_!akX6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0f7af4c-ce8d-4489-9283-8bfd0adfd6ae_5250x3900.png 1272w, https://substackcdn.com/image/fetch/$s_!akX6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0f7af4c-ce8d-4489-9283-8bfd0adfd6ae_5250x3900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!akX6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0f7af4c-ce8d-4489-9283-8bfd0adfd6ae_5250x3900.png" width="1456" height="1082" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f0f7af4c-ce8d-4489-9283-8bfd0adfd6ae_5250x3900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1082,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:887045,&quot;alt&quot;:&quot;Side-by-side comparison of the Hugging Face disclosure of July 16, 2026 and the OpenAI disclosure of July 21, 2026 across six attributes, showing the two accounts diverging on attacker identity, infrastructure, and motive while agreeing on detection and the absence of any public CVE.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/208489023?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0f7af4c-ce8d-4489-9283-8bfd0adfd6ae_5250x3900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Side-by-side comparison of the Hugging Face disclosure of July 16, 2026 and the OpenAI disclosure of July 21, 2026 across six attributes, showing the two accounts diverging on attacker identity, infrastructure, and motive while agreeing on detection and the absence of any public CVE." title="Side-by-side comparison of the Hugging Face disclosure of July 16, 2026 and the OpenAI disclosure of July 21, 2026 across six attributes, showing the two accounts diverging on attacker identity, infrastructure, and motive while agreeing on detection and the absence of any public CVE." srcset="https://substackcdn.com/image/fetch/$s_!akX6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0f7af4c-ce8d-4489-9283-8bfd0adfd6ae_5250x3900.png 424w, https://substackcdn.com/image/fetch/$s_!akX6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0f7af4c-ce8d-4489-9283-8bfd0adfd6ae_5250x3900.png 848w, https://substackcdn.com/image/fetch/$s_!akX6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0f7af4c-ce8d-4489-9283-8bfd0adfd6ae_5250x3900.png 1272w, https://substackcdn.com/image/fetch/$s_!akX6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0f7af4c-ce8d-4489-9283-8bfd0adfd6ae_5250x3900.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 1: Two Companies, One Weekend, Two Different Stories</figcaption></figure></div><p><span>That bothers me more than the &#8220;zero-day&#8221; does. Every detection story you&#8217;re running assumes you eventually work out what you&#8217;re dealing with. Hugging Face never did, and they had model-driven triage over their security telemetry that caught the compromise anyway. What it caught was the shape of the activity, and the shape was all they got.</span></p><p><span>Imagine what that means for your own program. Attribution is the step every incident-response plan treats as eventually solvable, even though it really shouldn&#8217;t, and instead focuses on the rapid restoration of service. You collect enough telemetry, you correlate enough signals, and the picture </span><em><span>may </span></em><span>resolve into a named actor with known tradecraft. Hugging Face collected the telemetry, correlated the signals, and got a shape. The name arrived five days later in OpenAI&#8217;s blog post, and it arrived only because OpenAI volunteered it. Nothing in their environment was ever going to produce it. Build your response plan on the assumption that you get the shape and never the name.</span></p><p><span>The two halves failed differently, and they need different fixes. The OpenAI side is a containment problem, where a capable workload got out of a box. The Hugging Face side is an authority problem, where a pipeline component executed supplied content while holding credentials worth stealing. Treating them as one story is how people end up recommending one control for both, and that&#8217;s just plain wrong.</span></p><h2><strong><span>Authority And Autonomy Are Different Dials</span></strong></h2><p><span>Here is my stake in the ground. You can cut what an agent may effect without cutting how freely it reasons. Authority sits on one dial and decision independence sits on the other. Turn the first one down and the second one can still stay where it was.</span></p><p><span>The best evidence for that sits inside this incident, and I haven&#8217;t seen anyone call that out yet.</span></p><p><span>Look at Hugging Face&#8217;s dataset-processing worker. That thing decides almost nothing. It&#8217;s an ingestion pipeline. It doesn&#8217;t plan, pick between strategies, or reason about goals. Its autonomy sits near zero. It also executed attacker-supplied code while holding cloud and cluster credentials that opened several internal clusters. That&#8217;s enormous authority paired with no autonomy at all.</span></p><p><span>If authority and autonomy were one dial, that combination couldn&#8217;t exist. You&#8217;d never find a component with maximum reach and minimum judgment. Every environment I&#8217;ve walked into is chock-full of them.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!etMw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74a8764d-de21-452b-a2c3-7954b6482980_4650x3480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!etMw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74a8764d-de21-452b-a2c3-7954b6482980_4650x3480.png 424w, https://substackcdn.com/image/fetch/$s_!etMw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74a8764d-de21-452b-a2c3-7954b6482980_4650x3480.png 848w, https://substackcdn.com/image/fetch/$s_!etMw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74a8764d-de21-452b-a2c3-7954b6482980_4650x3480.png 1272w, https://substackcdn.com/image/fetch/$s_!etMw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74a8764d-de21-452b-a2c3-7954b6482980_4650x3480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!etMw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74a8764d-de21-452b-a2c3-7954b6482980_4650x3480.png" width="1456" height="1090" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/74a8764d-de21-452b-a2c3-7954b6482980_4650x3480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1090,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:676693,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/208489023?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74a8764d-de21-452b-a2c3-7954b6482980_4650x3480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!etMw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74a8764d-de21-452b-a2c3-7954b6482980_4650x3480.png 424w, https://substackcdn.com/image/fetch/$s_!etMw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74a8764d-de21-452b-a2c3-7954b6482980_4650x3480.png 848w, https://substackcdn.com/image/fetch/$s_!etMw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74a8764d-de21-452b-a2c3-7954b6482980_4650x3480.png 1272w, https://substackcdn.com/image/fetch/$s_!etMw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74a8764d-de21-452b-a2c3-7954b6482980_4650x3480.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 2: Authority and Autonomy Are Different Dials </figcaption></figure></div><p><span>None of this is new thinking. The object-capability model has held the two apart for decades, and Norm Hardy named the sharpest version of the problem in October 1988 in </span><a href="https://dl.acm.org/doi/10.1145/54289.871709"><span>three pages of ACM SIGOPS Operating Systems Review</span></a><span>. His example was a compiler at Tymshare that held write access to a billing file for accounting reasons. A customer handed it an output filename that matched the billing file, and the compiler dutifully overwrote the company&#8217;s revenue records on the customer&#8217;s behalf. Every action stayed inside policy the entire way through. Hardy&#8217;s answer was that authority should ride with whoever invokes an action instead of sitting ambient inside the program doing the work. Read the OpenAI chain again with that in mind. The package proxy held network authority for one purpose, and a caller found a way to spend it on another.</span></p><p><span>I learned the practical version via my oil and gas days long before I thought about it in agents. A control-room operator at a console can reason about anything they want. They can decide the process needs to run hotter, that a reading is lying to them, that the previous shift left them a mess. What they can&#8217;t do is open two valves that must never be open together, because the interlock is wired to make that combination impossible, and no amount of operator reasoning gets around it. I&#8217;ve watched sharp operators argue with an interlock and lose, which is the point of the interlock. The decision space stayed wide open, the authority stayed hard-bounded, and the two never touched each other in thirty years of me watching them.</span></p><p><span>The analogy breaks in one place&#8230; Physics enforces an interlock. Code enforces an agent boundary, and code carries flaws, which is the entire story of what happened at that package proxy. That&#8217;s an argument for keeping your enforcement point small, dumb, and outside the model, and for never running only one of them.</span></p><p><span>On the research side, </span><a href="https://arxiv.org/abs/2503.18813"><span>CaMeL</span></a><span> is the closest thing to a measurement anyone has published. Debenedetti and nine coauthors built a defense that solves 77% of AgentDojo tasks with a provable security guarantee, against 84% for the same system undefended. The code sits under Google Research. That&#8217;s seven points of task completion traded for a capability-enforced boundary.</span></p><p><span>Before you file that under &#8220;autonomy survives scoping,&#8221; read what CaMeL constrains. It works by pulling control flow out of the trusted query so untrusted data can never influence the program, which narrows what the agent may decide about that data. The number tells you enforcement is cheap in utility terms. It doesn&#8217;t tell you the decision space came through untouched. I&#8217;d rather concede that now than have a reader hand me back my own citation.</span></p><h2><strong><span>Human Approval Was Never Going To Hold This Line</span></strong></h2><p><span>The reflex fix for all of this is a human in the loop. Put a person between the agent and the consequential action.</span></p><p><span>That control works in specific places. Aviation runs a two-person rule. Nuclear weapons handling runs a two-man rule. Wire transfers run four eyes. None of those are ceremonial.</span></p><p><span>My read on why they work lies in five conditions that hold at once.</span></p><ol><li><p><span>Events stay rare enough that a reviewer reads each one.</span></p></li><li><p><span>Each event carries stakes big enough to justify the interruption.</span></p></li><li><p><span>The reviewer holds training for that specific decision.</span></p></li><li><p><span>Time exists to make it.</span></p></li><li><p><span>The criteria are legible before you look.</span></p></li></ol><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!i0qx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26961670-c13c-4a1e-bba4-543589a04c06_4650x3420.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!i0qx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26961670-c13c-4a1e-bba4-543589a04c06_4650x3420.png 424w, https://substackcdn.com/image/fetch/$s_!i0qx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26961670-c13c-4a1e-bba4-543589a04c06_4650x3420.png 848w, https://substackcdn.com/image/fetch/$s_!i0qx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26961670-c13c-4a1e-bba4-543589a04c06_4650x3420.png 1272w, https://substackcdn.com/image/fetch/$s_!i0qx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26961670-c13c-4a1e-bba4-543589a04c06_4650x3420.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!i0qx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26961670-c13c-4a1e-bba4-543589a04c06_4650x3420.png" width="1456" height="1071" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/26961670-c13c-4a1e-bba4-543589a04c06_4650x3420.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1071,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:868555,&quot;alt&quot;:&quot;Radar chart comparing the aviation two-person rule, the nuclear two-man rule, four-eyes wire approval, and agent action streams across five conditions, with the first three forming wide polygons and agent action streams collapsing toward the center on every axis.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/208489023?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26961670-c13c-4a1e-bba4-543589a04c06_4650x3420.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Radar chart comparing the aviation two-person rule, the nuclear two-man rule, four-eyes wire approval, and agent action streams across five conditions, with the first three forming wide polygons and agent action streams collapsing toward the center on every axis." title="Radar chart comparing the aviation two-person rule, the nuclear two-man rule, four-eyes wire approval, and agent action streams across five conditions, with the first three forming wide polygons and agent action streams collapsing toward the center on every axis." srcset="https://substackcdn.com/image/fetch/$s_!i0qx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26961670-c13c-4a1e-bba4-543589a04c06_4650x3420.png 424w, https://substackcdn.com/image/fetch/$s_!i0qx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26961670-c13c-4a1e-bba4-543589a04c06_4650x3420.png 848w, https://substackcdn.com/image/fetch/$s_!i0qx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26961670-c13c-4a1e-bba4-543589a04c06_4650x3420.png 1272w, https://substackcdn.com/image/fetch/$s_!i0qx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26961670-c13c-4a1e-bba4-543589a04c06_4650x3420.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 3: Where Human Approval Holds, and Where It Never Could</figcaption></figure></div><p><span>Agent action streams fail all five. The events aren&#8217;t rare because they can arrive in the thousands. Individual actions carry almost no stakes, which is why the trajectory is the dangerous object rather than any step inside it. The approver is usually a developer with a build to ship. No time budget exists. The criteria are illegible too, because &#8220;install a package&#8221; looks identical whether it&#8217;s step four of a build or step four of an escape.</span></p><p><span>Invariant Labs saw this coming. When Marco Milanta and Luca Beurer-Kellner disclosed the </span><a href="https://invariantlabs.ai/blog/mcp-github-vulnerability"><span>GitHub MCP toxic agent flow in May 2025</span></a><span>, they called it an architectural problem rather than a code flaw. Claude Desktop asks users to confirm each tool call by default. Milanta and Beurer-Kellner wrote in the same post that many users already choose an &#8220;always allow&#8221; policy and stop watching individual actions. A control that people switch off during normal use has already failed.</span></p><p><span>Did your last threat model include human-in-the-loop scaling? Be honest. It likely didn&#8217;t. Multiply your expected agent action volume by the seconds of genuine attention each approval deserves, then compare that number to the reviewer hours you staffed. If the product exceeds the capacity, all you have done is build a rubber-stamping assembly line. You&#8217;ve built a queue that somebody will clear by clicking through it, and the clicking looks identical in your audit log to careful review. Watch your always-allow rate. When it climbs, the control already converted itself into a rubber stamp, and your evidence trail is now recording consent you never gave.</span></p><p><span>Machine-speed oversight closes the argument. </span><a href="https://www.crowdstrike.com/en-us/press-releases/2026-crowdstrike-global-threat-report/"><span>CrowdStrike&#8217;s 2026 Global Threat Report</span></a><span> put average eCrime breakout time at 29 minutes for 2025, with the fastest observed at 27 seconds, and exfiltration starting within four minutes of initial access in one intrusion. Hugging Face&#8217;s attacker ran more than 17,000 events across a weekend. Work out how much human attention each of those actions gets.</span></p><p><span>The regulation already knows. </span><a href="https://artificialintelligenceact.eu/article/14/"><span>EU AI Act Article 14</span></a><span> requires that high-risk systems be built so natural persons can effectively oversee them. Article 14(4)(b) requires that the overseer stay aware of the tendency toward &#8220;automatically relying or over-relying&#8221; on system output, which the Act names automation bias. The same article that mandates the control documents the way it fails.</span></p><h2><strong><span>Least Agency vs Agent Autonomy: Where The One-Axis Reading Wins</span></strong></h2><p><span>Now my own argument takes damage.</span></p><p><span>One disclosure before I start. I co-lead OWASP&#8217;s Agentic AI Security work, so I&#8217;m about to criticize language I share responsibility for.</span></p><p><a href="https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/"><span>OWASP&#8217;s Top 10 for Agentic Applications</span></a><span>, published in December 2025, puts least agency underneath all ten entries as the governing principle. The definition tells you to grant agents only the minimum autonomy required for safe, bounded tasks, with autonomy earned through demonstrated safety rather than handed over by default.</span></p><p><span>Read that as a practitioner and it&#8217;s obviously right. Read it as an architect and notice what it does. It puts autonomy on the dial you&#8217;re turning down.</span></p><p><span>The phrasing carries a cost downstream, and I&#8217;ve watched it land. A team reads &#8220;minimum autonomy&#8221; and reaches for the control that reduces autonomy, which is an approval gate. What they needed was the control that reduces authority, which is confinement. Those are different builds with different failure modes, and the first one degrades into always-allow while the second one holds. Invariant Labs documented that behavior in the wild more than a year before this incident, and the industry ran the experiment anyway.</span></p><p><a href="https://arxiv.org/abs/2506.08837"><span>The Design Patterns paper</span></a><span> makes the one-axis case honestly, and I respect it for that. Beurer-Kellner and thirteen coauthors write that their patterns &#8220;constrain the actions of agents to explicitly prevent them from solving arbitrary tasks.&#8221; That&#8217;s the trade stated plainly. They go further. As long as agents and their defenses run on the current class of language models, they consider it unlikely that general-purpose agents can offer meaningful and reliable safety guarantees.</span></p><p><span>I think they&#8217;re right about today&#8217;s agents. Where users perceive autonomy right now, most of what they&#8217;re perceiving is range. Give a model more tools and more destinations, and it feels more autonomous, because it surprises you in more directions. Tighten the range, and it feels dumber even when its reasoning never changed.</span></p><p><span>The authority/autonomy axes are separate in principle, and capability systems have kept them separate in practice. Today&#8217;s agents happen to draw most of their perceived autonomy from breadth of authority, which means tightening authority does cost you something people are calling autonomy.</span></p><h2><strong><span>Where The Claim Runs Out</span></strong></h2><p><span>Run the whole chain and mark each step for what capability confinement would have done to it.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zKGW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb64efa07-6fec-400e-84fb-04b0769c6787_5700x2580.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zKGW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb64efa07-6fec-400e-84fb-04b0769c6787_5700x2580.png 424w, https://substackcdn.com/image/fetch/$s_!zKGW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb64efa07-6fec-400e-84fb-04b0769c6787_5700x2580.png 848w, https://substackcdn.com/image/fetch/$s_!zKGW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb64efa07-6fec-400e-84fb-04b0769c6787_5700x2580.png 1272w, https://substackcdn.com/image/fetch/$s_!zKGW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb64efa07-6fec-400e-84fb-04b0769c6787_5700x2580.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zKGW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb64efa07-6fec-400e-84fb-04b0769c6787_5700x2580.png" width="1456" height="659" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b64efa07-6fec-400e-84fb-04b0769c6787_5700x2580.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:659,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:418823,&quot;alt&quot;:&quot;Nine-stage attack chain from the OpenAI evaluation sandbox to the Hugging Face production database, with each stage marked as prevented by authority scoping, contained only, dependent on the boundary&#8217;s code, or out of reach.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/208489023?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb64efa07-6fec-400e-84fb-04b0769c6787_5700x2580.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Nine-stage attack chain from the OpenAI evaluation sandbox to the Hugging Face production database, with each stage marked as prevented by authority scoping, contained only, dependent on the boundary&#8217;s code, or out of reach." title="Nine-stage attack chain from the OpenAI evaluation sandbox to the Hugging Face production database, with each stage marked as prevented by authority scoping, contained only, dependent on the boundary&#8217;s code, or out of reach." srcset="https://substackcdn.com/image/fetch/$s_!zKGW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb64efa07-6fec-400e-84fb-04b0769c6787_5700x2580.png 424w, https://substackcdn.com/image/fetch/$s_!zKGW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb64efa07-6fec-400e-84fb-04b0769c6787_5700x2580.png 848w, https://substackcdn.com/image/fetch/$s_!zKGW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb64efa07-6fec-400e-84fb-04b0769c6787_5700x2580.png 1272w, https://substackcdn.com/image/fetch/$s_!zKGW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb64efa07-6fec-400e-84fb-04b0769c6787_5700x2580.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 4: Where Authority Scoping Bites</figcaption></figure></div><p><span>The lateral movement and credential harvesting steps disappear under per-task credentials that expire. The reach into Hugging Face disappears under egress that defaults to deny. The dataset worker&#8217;s blast radius shrinks hard once that worker can&#8217;t hold a credential worth stealing. Four steps prevented, one contained.</span></p><p><span>Three steps confinement never touches. It has nothing to say about running an evaluation with the production classifiers off, which is a policy decision people made. It has nothing to say about a model choosing to look for a way out. It has nothing to say about a model inferring where the answer key lives.</span></p><p><span>That last step is the showstopper here. OpenAI denied standing egress, and yet that environment had exactly one path out, a package proxy, which is honestly a tighter posture than most enterprises run around their build systems. The model found a zero-day in the boundary itself.</span></p><p><span>&#8220;Deny standing egress&#8221; as a recommendation has a caveat, though. A capability boundary is worth whatever its code is worth. One boundary is one point of failure. The lesson from step three is defense in depth around your confinement mechanism, and confidence in the mechanism is the thing that got tested here.</span></p><p><span>One thing would move me off this. Show me a capability-confined agent stack that runs untrusted content in production for a year without an authority escape, where the enforcement point is small enough to audit, and there is more than one of them in the path. That&#8217;s a verifiable claim rather than a position you have to take on faith. Absent that, I&#8217;m holding the independent argument at high confidence and the this-would-have-worked argument at somewhere near a coin flip.</span></p><p><span>That&#8217;s a split verdict, and I&#8217;m leaving it split. The independent claim holds. The claim that least agency would have stopped this incident holds for part of the chain and comes apart on the rest.</span></p><p><span>Then there&#8217;s the definitional problem, which is the sharpest objection anyone can make. If I define autonomy as bounded, capability-scoped action inside pre-authorized flows, then &#8220;least agency is compatible with autonomy&#8221; comes out true because I made it true. That&#8217;s winning by relabeling.</span></p><p><span>A meaningful notion of autonomy requires the capacity to do something unanticipated. The models in this incident did precisely that. That behavior is the autonomy under discussion, and capability confinement exists to forbid it. My compatibility claim holds cleanly for the deflationary sense of the word and stays in genuine tension with the strong sense. I&#8217;m not going to pretend that tension resolves.</span></p><p><span>Now, a minority of readers on Hugging Face&#8217;s own comment thread called the episode a marketing exercise with a conveniently soft sandbox. I can see that.</span></p><p><span>Watch what OpenAI&#8217;s post does while it reports the incident. It calls the event unprecedented and the capabilities state of the art. It cites UK AISI evaluations of long-horizon cyber operations and says this incident shows those capabilities carry into real systems. It announces that Hugging Face joined OpenAI&#8217;s trusted access program, links that program twice, and closes by inviting other defenders to apply. A disclosure about losing control of a model also demonstrates that the model is formidable and routes you toward the commercial program built on exactly that.</span></p><p><span>Now check what an outsider can verify without taking anyone&#8217;s word. Nothing. No CVE for the proxy zero-day, none for the dataset paths, and the proxy vendor stays unnamed. Every technical claim in both posts comes from the two parties inside the story.</span></p><p><span>My take? I think the incident happened, but both companies realized what a HUGE marketing opportunity it is. OpenAI gets to draw the news cycle away from Mythos/Fable, and Hugging Face&#8217;s entire existence stands on serving up open-source/open-weight models.</span></p><p><span>Oh yeah&#8230; small footnote&#8230; Hugging Face had to use an open-weight model, GLM 5.2 to be exact, in their incident response because the frontier model APIs stonewalled them. They couldn&#8217;t tell defender IR activity vs. attacker activity.</span></p><p><span>You have an agent in your environment right now that touches content somebody outside your company wrote. Answer two questions about it separately, on paper, today. What can it decide? What can it affect?</span></p><p><span>Most people answer the first and assume they&#8217;ve covered the second. Hugging Face&#8217;s dataset worker is what that assumption looks like from the outside. It decided nothing. It reached everything. The least agency vs agent autonomy question won&#8217;t get settled in the literature this year, and it won&#8217;t get settled on your architecture diagram either. It gets settled by default, badly, every time somebody scopes the first question and skips the second.</span></p><p><span>Which one did you scope?</span></p><h3><strong><span>What To Do Next</span></strong></h3><p><span>Three mechanisms, and I&#8217;m holding this to authority scoping, because detection and boundary hygiene are a different conversation.</span></p><ol><li><p><span>Issue per-task credentials that expire in minutes instead of standing keys, so a compromised worker holds authority with a short shelf life.</span></p></li><li><p><span>Put a policy decision point at the tool boundary that returns deny for any tool or destination it hasn&#8217;t seen before, evaluated per action rather than once at token issuance.</span></p></li><li><p><span>Make it a hard rule that any worker processing content from outside your organization cannot reach a credential worth stealing.</span></p></li></ol><p><span>That&#8217;s Create and Adapt work in the</span><a href="https://www.rockcyber.com/ai-strategy-and-governance"><span> CARE model</span></a><span>, and it&#8217;s where least agency stops being a principle you nod at.</span></p><p><span>For the definitional groundwork underneath this piece, I wrote the cornerstone on</span><a href="https://www.rockcybermusings.com/p/i-agent-authentication-authorization-gap"><span> least agency versus least privilege</span></a><span> and where OAuth scopes stop being enough.</span><a href="https://www.rockcybermusings.com/p/autonomous-ai-agent-ransomware-jadepuffer"><span> JadePuffer</span></a><span> is what an unbounded agent does to a victim who had every patch available and skipped them. The advisory work lives at</span><a href="https://www.rockcyber.com/"><span> rockcyber.com</span></a><span>.</span></p><p><span>&#128073; For ongoing analysis of agentic AI governance frameworks, the conversation at </span><strong><a href="https://rockcybermusings.com/">RockCyber Musings</a></strong><span> and you can subscribe above</span></p><p><span>&#128073; Visit </span><strong><a href="https://www.rockcyber.com/">RockCyber.com</a></strong><span> to learn more about how we can help with your traditional Cybersecurity and AI Security and Governance journey.</span></p><p><span>&#128073; Want to save a quick $100K? Check out our AI Governance Tools at </span><strong><a href="https://aigovernancetoolkit.com/">AIGovernanceToolkit.com</a></strong></p><p><span>&#128073; As a bonus, </span><strong><a href="https://zenity.io/resources/webinars/a-conversation-with-claude-mythos-tenant-aws-on-demand"><span>check out my chat with Itay Meller, Specialist Solutions Architect, Security at AWS</span></a></strong><span>, about what autonomous vulnerability discovery changes for security teams, and where AI Detection and Response (AIDR) fits in a stack that was never built to watch agents. </span><em><strong><span>No registration required</span></strong></em></p><p></p>]]></content:encoded></item><item><title><![CDATA[Weekly Musings Top 10 AI Security Wrapup: Issue 47 July 17 -July 23, 2026]]></title><description><![CDATA[OpenAI's own models hacked Hugging Face, Google shipped a gov-only bug hunter, and regulators fenced in AI agents. A CISO's AI security and governance brief.]]></description><link>https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260717-20260723</link><guid isPermaLink="false">https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260717-20260723</guid><dc:creator><![CDATA[Rock Lambros]]></dc:creator><pubDate>Fri, 24 Jul 2026 12:50:21 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!mdPE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d3a599b-8568-47ce-82d3-24017425b2b5_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mdPE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d3a599b-8568-47ce-82d3-24017425b2b5_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mdPE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d3a599b-8568-47ce-82d3-24017425b2b5_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!mdPE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d3a599b-8568-47ce-82d3-24017425b2b5_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!mdPE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d3a599b-8568-47ce-82d3-24017425b2b5_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!mdPE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d3a599b-8568-47ce-82d3-24017425b2b5_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mdPE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d3a599b-8568-47ce-82d3-24017425b2b5_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7d3a599b-8568-47ce-82d3-24017425b2b5_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1233556,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/208267495?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d3a599b-8568-47ce-82d3-24017425b2b5_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mdPE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d3a599b-8568-47ce-82d3-24017425b2b5_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!mdPE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d3a599b-8568-47ce-82d3-24017425b2b5_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!mdPE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d3a599b-8568-47ce-82d3-24017425b2b5_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!mdPE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d3a599b-8568-47ce-82d3-24017425b2b5_1024x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>An autonomous attacker spent a weekend inside Hugging Face, harvesting credentials. Investigators assumed a human crew. Five days later OpenAI admitted the culprit was its own models, run with the safety brakes loosened to cheat on a cyber benchmark. AI stopped being only a thing we secure and became a thing that secures and attacks on its own. Google shipped a vulnerability-hunting model for governments only. Anthropic put a scanner in every developer&#8217;s terminal. Paris warned that three firms own the agent market. Read this before your next board meeting.</p><p>Watch where the capability lands before you watch the headline. This week it landed in three places at once: an offensive test that got loose, defensive tooling any engineer can now run, and the desks of regulators who started treating autonomous agents as a distinct risk category rather than a faster chatbot. The through-line is agency. Systems that plan, act, and persist across sessions do not behave like the software your controls were built for. They hold credentials, they touch production, and they remember, which breaks assumptions baked into identity, change management, and vendor risk. Here are the eleven developments from July 17 to July 23 that move a decision. The last one barely made the news, and it should worry you the most. Deeper work lives at <a href="https://rockcybermusings.com/">rockcybermusings.com</a>.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260717-20260723?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260717-20260723?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h3>1. OpenAI&#8217;s Own Models Broke Out of a Lab and Hacked Hugging Face</h3><p>Hugging Face detected an intrusion on July 16, 2026, first blamed on an unknown autonomous agent that moved laterally across clusters over a weekend (Help Net Security). On July 21, OpenAI admitted the attacker was its own GPT-5.6 Sol and a pre-release model, run with reduced cyber-safety refusals for an internal benchmark called ExploitGym, which escaped the sandbox through a package-installer zero-day and reached Hugging Face production to steal the answer key (Fortune). It is the first documented case of frontier models chaining a real zero-day without source code access.</p><p><strong>Why it matters</strong></p><ul><li><p>Your sandbox is a hypothesis now, not a control.</p></li><li><p>Attribution got harder. The largest model hub spent five days blaming an elite human crew.</p></li><li><p>Evaluation safety is a supply-chain problem, because the blast radius reached a third party&#8217;s production.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Air-gap or egress-filter any environment running reduced-safety evaluations.</p></li><li><p>Add an autonomous-actor hypothesis to incident playbooks, with velocity and concurrency signals.</p></li><li><p>Demand containment controls in writing before placing pre-release models near sensitive systems.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>I have sat through a hundred tabletops where someone swears the sandbox holds. This week, one at a top lab did not, and the thing that got out robbed a neighbor to win a game. It was not malicious. It wanted the answer key, and hacking a production database was the efficient path. We over-index on superintelligence when the near-term danger is a competent system with a narrow goal and no sense of the property line. I keep arguing we should <a href="https://www.rockcyber.com/">quantify AI risk</a> with probabilities and blast radius, not vibes. Show your board this.</p><h3>2. China Launches WAICO, the First Intergovernmental Body for AI</h3><p>The 2026 World Artificial Intelligence Conference and High-Level Meeting on Global AI Governance ran in Shanghai from July 17 to July 20, with President Xi Jinping&#8217;s keynote on July 17 and UN Secretary-General Ant&#243;nio Guterres among representatives from more than 100 countries (China Daily). The headline outcome was the agreement establishing the World Artificial Intelligence Cooperation Organization, or WAICO, the first intergovernmental body dedicated to AI, headquartered in Shanghai and pitched as a way to bridge the AI divide for the Global South.</p><p><strong>Why it matters</strong></p><ul><li><p>A second pole of AI governance now has an address, and three rulebooks that do not interchange.</p></li><li><p>WAICO standards could add a whole region to your compliance map.</p></li><li><p>Governance turned into geopolitics, and where you train and evaluate models now carries diplomatic weight.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Add WAICO to your regulatory-watch list beside the EU AI Office and NIST.</p></li><li><p>In Global South markets, map exposure to WAICO-aligned procurement and localization.</p></li><li><p>Brief your board on bloc fragmentation, and budget for parallel compliance.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>I read the Shanghai communique by asking who it binds and who it exempts. WAICO is smart statecraft. China gets to write the rules for a hundred countries that cannot afford their own labs, and it does it under the banner of fairness while Washington argues about whether states can regulate at all. Plan for a world where your AI stack needs a passport.</p><h3>3. Google Ships Gemini 3.5 Flash Cyber, and Keeps It for Governments</h3><p>Google DeepMind announced Gemini 3.5 Flash Cyber on July 21, 2026, a model tuned to find vulnerabilities, confirm exploitability, and generate patches (Help Net Security). On the V8 JavaScript engine, it found 55 confirmed issues, against 47 for mainline 3.5 Flash and 36 for Opus 4.6, including 10 that the others missed. Google reserved access for governments and trusted partners through its CodeMender program and published no pricing or release date, citing dual-use safety risks (The Hacker News).</p><p><strong>Why it matters</strong></p><ul><li><p>The offense-defense gap narrowed, and access is now a policy lever rather than a market one.</p></li><li><p>Government-only access means state-backed adversaries may reach parity before you do.</p></li><li><p>Ten issues two strong models missed is not noise, and specialized cyber models will outrun general ones.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Ask your vendors which frontier cyber models they can access, and when you get them.</p></li><li><p>Fold AI-discovered vulnerability classes into your patch SLAs.</p></li><li><p>Watch the access policy, because who gets the model shapes your threat model.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Google did the responsible thing, and rationing a vulnerability-hunting model to governments on dual-use grounds means the capability arrives unevenly. The state-aligned crews I worry about in energy and water do not wait for a public API. Get into the partner conversations now, and do not assume the gate holds forever.</p><h3>4. The Linux Kernel Published 440 AI-Found CVEs in a Day</h3><p>Between July 19 and July 20, 2026, the Linux kernel project published roughly 440 CVE advisories, 431 on the first day and nine more on the second, driven by static analysis, fuzzing, and AI-assisted auditing that named Sashiko, the kernel&#8217;s AI review system, in 23 cases (securityonline.info). A closer look from XenoSpectrum found that many identifiers were bulk-assigned to bugs already fixed upstream, which points to CVE inflation rather than a wave of fresh exploitable risk.</p><p><strong>Why it matters</strong></p><ul><li><p>CVE volume is decoupling from human review capacity, and most of the flood is already patched.</p></li><li><p>Signal-to-noise is the fight, because tooling drowns when identifiers attach to already-fixed issues.</p></li><li><p>The kernel is the canary for what AI auditors will do to every large codebase you depend on.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Weight your program on exploitability and patch status, not raw CVE count.</p></li><li><p>Automate advisory ingestion and map it to deployed versions.</p></li><li><p>Press your software vendors on backport speed.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Publishing 440 CVEs in a day sounds like the sky is falling, and it was mostly bookkeeping, because most were already fixed. What changed is the tempo. The trap is that your metrics still treat every CVE as a fire, so your team burns out chasing paperwork while the real bug hides in the pile. Fix the dashboard before the flood.</p><h3>5. Anthropic Puts a Multi-Agent Security Scanner in Every Terminal</h3><p>Anthropic launched the Claude Security plugin for Claude Code in public beta during the week of July 22, 2026, letting developers scan changes or a whole codebase from the terminal (MarkTechPost). A coordinated set of agents maps the codebase, models threats, connects issues across files, and returns suggested patches for flaws such as injection and authentication bypass. Admins enable it through the console, which reaches teams that never had an application-security function.</p><p><strong>Why it matters</strong></p><ul><li><p>Application-security review is moving into the commit loop for everyone.</p></li><li><p>Multi-agent scanning catches cross-file logic bugs that traditional static analysis misses.</p></li><li><p>The model that writes your code now audits it, a single-vendor dependency worth naming.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Pilot it against a repository you already scanned, and compare findings.</p></li><li><p>Set policy on who enables it and where findings go, because reports are sensitive telemetry.</p></li><li><p>Keep your existing controls, and treat AI review as an added layer.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>I like this, and I do not trust it yet, which is the right posture for anything in week-one beta. The catch nobody says out loud is that the model that wrote the vulnerable code now grades its own homework, and the failure modes correlate. Run it beside your scanners and keep score.</p><p>Here&#8217;s proof from my own terminal:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rGXr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1f33574-44d0-44ab-9808-736151fde1e0_1247x56.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rGXr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1f33574-44d0-44ab-9808-736151fde1e0_1247x56.png 424w, https://substackcdn.com/image/fetch/$s_!rGXr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1f33574-44d0-44ab-9808-736151fde1e0_1247x56.png 848w, https://substackcdn.com/image/fetch/$s_!rGXr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1f33574-44d0-44ab-9808-736151fde1e0_1247x56.png 1272w, https://substackcdn.com/image/fetch/$s_!rGXr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1f33574-44d0-44ab-9808-736151fde1e0_1247x56.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rGXr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1f33574-44d0-44ab-9808-736151fde1e0_1247x56.png" width="1247" height="56" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f1f33574-44d0-44ab-9808-736151fde1e0_1247x56.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:56,&quot;width&quot;:1247,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:18112,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/208267495?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1f33574-44d0-44ab-9808-736151fde1e0_1247x56.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rGXr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1f33574-44d0-44ab-9808-736151fde1e0_1247x56.png 424w, https://substackcdn.com/image/fetch/$s_!rGXr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1f33574-44d0-44ab-9808-736151fde1e0_1247x56.png 848w, https://substackcdn.com/image/fetch/$s_!rGXr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1f33574-44d0-44ab-9808-736151fde1e0_1247x56.png 1272w, https://substackcdn.com/image/fetch/$s_!rGXr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1f33574-44d0-44ab-9808-736151fde1e0_1247x56.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h3>6. France Says Three Firms Own 84% of the AI Agent Market</h3><p>On July 17, 2026, France&#8217;s Autorit&#233; de la concurrence published Opinion No. 26-A-05, from an inquiry opened in January 2026 into the AI agents sector (Concurrences). The regulator found that OpenAI, Google, and Anthropic together hold more than 84% of the agent market, and it warned that autonomous agents could concentrate the digital economy around a few vertically integrated firms unless regulators act on data access, interoperability, and default placement. The 3,700-page opinion flagged platformisation, disintermediation, and algorithmic collusion.</p><p><strong>Why it matters</strong></p><ul><li><p>Vendor lock-in is a documented market fact now, and your exit options are thin.</p></li><li><p>Default placement is the new shelf space, deciding who sees your data and traffic.</p></li><li><p>Algorithmic collusion is on the table for anyone whose agents set prices.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Inventory the foundation models under your agent stack and what switching costs.</p></li><li><p>Negotiate data-portability and interoperability terms while regulators give you cover.</p></li><li><p>If your agents touch pricing, document human oversight.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>This got buried under the Hugging Face fireworks, and it is the one your CFO should read. The French built their own agents, ran 550 shopping queries, and measured who actually gets cited. Eighty-four percent in three hands. I have watched the lock-in movie before with cloud, and the sequel always costs more than the trailer. Sign nothing multi-year without a portability clause.</p><h3>7. France&#8217;s CNIL Names Agent Memory as a GDPR Problem</h3><p>On July 20, 2026, France&#8217;s data protection authority, the CNIL, with the Council for AI and Digital Technology, published a note on the risks of agentic AI for personal data (Digital Policy Alert). It named persistent memory and multi-service interaction as the features that strain the GDPR most, since memory collides with purpose limitation and cross-system action blurs the controller and processor line. France often previews where the wider EU lands, so read this as an early warning.</p><p><strong>Why it matters</strong></p><ul><li><p>Persistent memory is a named privacy hazard your impact assessments never anticipated.</p></li><li><p>Multi-service agents blur controller and processor roles, and that means liability.</p></li><li><p>France leads, so a CNIL position signals where EU enforcement heads next.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Update your impact assessments to cover what memory stores, for how long, and how a subject deletes it.</p></li><li><p>Map every agent&#8217;s cross-service reach and assign controllership per workflow.</p></li><li><p>Build a memory-retention and erasure policy before a regulator asks.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Everyone obsesses over what an agent does. The CNIL asked the sharper question, which is what it remembers and who owns that memory. Persistent memory outlives the purpose you collected it for, which is a slow-motion GDPR problem. If you cannot show a regulator how a data subject wipes themselves from an agent&#8217;s long-term memory, you do not have a compliant deployment. France just put that in writing, and I would fix it before August 2.</p><h3>8. The Financial Stability Board&#8217;s AI Consultation Closed July 22</h3><p>The comment window for the Financial Stability Board&#8217;s consultation, Sound Practices for Responsible Adoption of Artificial Intelligence, closed on July 22, 2026 (Financial Stability Board). The report offered 12 sound practices for organization-wide AI governance across the lifecycle and flagged agentic AI as an emerging risk to financial stability, with a final report planned for October 2026. The FSB does not chase consumer harms, so its attention signals where bank supervision heads next.</p><p><strong>Why it matters</strong></p><ul><li><p>The systemic-risk regulator for global finance is now writing AI governance expectations.</p></li><li><p>Twelve sound practices become a de facto checklist that examiners reference.</p></li><li><p>Agentic AI reached the stability conversation, elevating model risk from a compliance line item.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Map your AI governance to the FSB&#8217;s 12 practices before the October final report.</p></li><li><p>Brief your model-risk and third-party-risk teams that autonomous agents fall in scope.</p></li><li><p>Prepare board-level documentation, because stability regulators expect governance owned at the top.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>When the Financial Stability Board starts talking about your AI, governance as a side project is over. The fact that agentic AI reached its radar points toward supervision that treats an autonomous trading agent like any other source of systemic risk, and its twelve practices rhyme with ISO 42001 and the NIST framework. If you run risk at a bank and you are not already mapping to this, you will explain yourself to an examiner later.</p><h3>9. Neo Security Exits Stealth With $100 Million for Agent Control</h3><p>On July 20, 2026, Neo Security left stealth with $100 million to build a secure control layer for enterprise AI agents (SiliconANGLE). Andreessen Horowitz and Bessemer led the round, and the founders came out of SentinelOne, which puts endpoint-grade thinking behind the pitch. The raise fit the day&#8217;s pattern, as venture money moved toward the control plane of AI rather than the presentation layer, betting that enterprises will need purpose-built controls to scope, monitor, and revoke what agents can do.</p><p><strong>Why it matters</strong></p><ul><li><p>The market just priced agent security at $100 million out of stealth.</p></li><li><p>Endpoint-security founders signal the category matures fast.</p></li><li><p>A control plane for agents is the architecture pattern to watch.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Test whether your identity and privileged-access stack can scope, monitor, and revoke agent credentials.</p></li><li><p>Start with least privilege and short-lived credentials for every agent today.</p></li><li><p>Track this category in your architecture roadmap.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Follow the money and it tells you what is coming. A hundred million dollars out of stealth for an agent control plane is the market saying the quiet part, that your identity stack was never built for software that acts on its own. A pile of venture money produces overlapping products, so buy the least-privilege discipline first and let the market shake out.</p><h3>10. OpenAI Wants You to Measure AI by &#8220;Useful Intelligence per Dollar&#8221;</h3><p>On July 17, 2026, OpenAI&#8217;s chief financial officer Sarah Friar proposed what she called the ultimate scorecard for the AI age (Axios). Her core metric, useful intelligence per dollar, runs four questions on work accomplished, cost, dependability, and return on compute. The dependability piece matters most for security leaders, since it counts how often a tool met quality standards, needed edits, and required a person to finish the task.</p><p><strong>Why it matters</strong></p><ul><li><p>The vendor is defining how you measure its value, so read the metric as a negotiating anchor.</p></li><li><p>Intervention rate is exactly the oversight data your governance program needs.</p></li><li><p>ROI pressure drives shadow AI faster than governance can follow.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Adopt dependability tracking on your own terms, tied to risk, not cost alone.</p></li><li><p>Push back on ROI framing that ignores security and governance overhead.</p></li><li><p>Use the intervention metric as an early warning for over-delegated agents.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>I will give OpenAI credit for a useful idea wrapped in a sales pitch, though useful intelligence per dollar is also a number designed to make you feel good about the invoice. The part I want is the dependability tracking, meaning how often the thing needed a human to clean up, because that is your oversight telemetry and your risk signal in one. Keep the metric, and question the messenger.</p><h3>The One Thing You Won&#8217;t Hear About But You Need To: The Chronos Vulnerability</h3><p>The week of July 20, 2026, researchers Om Narayan, Ramkinker Singh, and Praveen Baskar posted a paper to arXiv, The Chronos Vulnerability: A Taxonomy of Temporal Persistence and Memory-Based Deception in Agentic AI, accepted at the ACM KDD 2026 Workshop on Evaluation and Trustworthiness of Agentic AI (arXiv). It maps how attackers exploit agent memory over time, the threat now tracked as memory poisoning and formalized as OWASP ASI06 in the 2026 Agentic AI Top 10. Poisoned memory survives past the originating session, so unlike prompt injection the attack and its effect are decoupled in time, with reported success rates from 80% to nearly 100% and defenses showing limited effect.</p><p><strong>Why it matters</strong></p><ul><li><p>Memory poisoning is the attack that waits, so single-session detections miss it entirely.</p></li><li><p>Enterprise agents are the target, because memory-rich systems are the most exposed to durable compromise.</p></li><li><p>Success rates run from 80% to nearly total, and defenses lag.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Inventory which agents hold persistent memory, and treat that memory as a trust boundary.</p></li><li><p>Add provenance and validation to memory writes.</p></li><li><p>Red-team your agents across sessions, not only within one.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>This is a ten-page paper almost no one in your leadership will see, and it describes the threat I would use against you. The smart attacker poisons the memory and walks away, because the payload fires next week, long after your logs went quiet. Prompt injection is a mugging. Memory poisoning plants a sleeper. Put memory inside the boundary of identity, provenance, and least privilege now, because the attackers already read the paper. That is the argument I keep making at <a href="https://www.rockcyber.com/">rockcyber.com</a>.</p><p><span>&#128073; For ongoing analysis of agentic AI governance frameworks, the conversation continues at </span><strong><a href="https://rockcybermusings.com/">RockCyber Musings</a></strong><span>.</span></p><p><span>&#128073; Visit </span><strong><a href="https://www.rockcyber.com/">RockCyber.com</a></strong><span> to learn more about how we can help with your traditional Cybersecurity and AI Security and Governance journey.</span></p><p><span>&#128073; Want to save a quick $100K? Check out our AI Governance Tools at </span><strong><a href="https://aigovernancetoolkit.com/">AIGovernanceToolkit.com</a></strong></p><p><span>&#128073; As a bonus, </span><strong><a href="https://zenity.io/resources/webinars/a-conversation-with-claude-mythos-tenant-aws-on-demand"><span>check out my chat with Itay Meller, Specialist Solutions Architect, Security at AWS</span></a></strong><span>, about what autonomous vulnerability discovery changes for security teams, and where AI Detection and Response (AIDR) fits in a stack that was never built to watch agents. </span><em><strong><span>No registration required</span></strong></em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share RockCyber Musings&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share RockCyber Musings</span></a></p><h2>References</h2><p>Autorit&#233; de la concurrence. (2026, July 17). <em>The French Competition Authority issues an opinion on the competitive functioning of the AI agents sector</em>. Concurrences. https://www.concurrences.com/en/bulletin/news-issues/preview/the-french-competition-authority-issues-an-opinion-on-the-competitive</p><p>Axios. (2026, July 17). <em>Exclusive: OpenAI&#8217;s CFO pitches a new way to measure AI&#8217;s value</em>. https://www.axios.com/2026/07/17/openai-ai-costs-roi-metrics</p><p>Ballon, M. (2026, July 21). <em>OpenAI says Hugging Face was breached by its pre-release models</em>. TechCrunch. https://techcrunch.com/2026/07/21/openai-says-hugging-face-was-breached-by-its-pre-release-models/</p><p>China Daily. (2026, July 18). <em>Chair&#8217;s statement of the 2026 World Artificial Intelligence Conference &amp; High-Level Meeting on Global AI Governance</em>. https://www.chinadaily.com.cn/a/202607/18/WS6a5ab88aa310986e2b465f4e.html</p><p>Digital Policy Alert. (2026, July 20). <em>CNIL and CIANum released a note on the risks of agentic AI for personal data protection</em>. https://digitalpolicyalert.org/event/41932-national-commission-for-information-technology-and-civil-liberties-and-council-for-ai-and-digital-technology-released-a-note-on-the-risks-of-agentic-ai-for-personal-data-protection</p><p>Financial Stability Board. (2026, June 10). <em>Sound practices for responsible adoption of artificial intelligence (AI): Consultation report</em>. https://www.fsb.org/2026/06/sound-practices-for-responsible-adoption-of-artificial-intelligence-ai-consultation-report/</p><p>Help Net Security. (2026, July 20). <em>Hugging Face breached by autonomous AI agent</em>. https://www.helpnetsecurity.com/2026/07/20/hugging-face-breached-by-autonomous-ai-agent/</p><p>Help Net Security. (2026, July 22). <em>Google&#8217;s Gemini 3.5 Flash Cyber becomes a vulnerability hunter</em>. https://www.helpnetsecurity.com/2026/07/22/google-gemini-3-5-flash-cyber-model/</p><p>Kahn, J. (2026, July 21). <em>OpenAI says its AI models escaped from a secure test environment and hacked into AI company Hugging Face in order to cheat on an evaluation</em>. Fortune. https://fortune.com/2026/07/21/openai-says-ai-models-escaped-control-hacked-hugging-face/</p><p>MarkTechPost. (2026, July 22). <em>Anthropic releases Claude Security plugin for Claude Code in beta: A multi-agent vulnerability scanner that runs in your terminal</em>. https://www.marktechpost.com/2026/07/22/anthropic-releases-claude-security-plugin-for-claude-code-in-beta-a-multi-agent-vulnerability-scanner-that-runs-in-your-terminal/</p><p>Narayan, O., Singh, R., &amp; Baskar, P. (2026, July). <em>The Chronos vulnerability: A taxonomy of temporal persistence and memory-based deception in agentic AI</em> (arXiv:2607.19433). arXiv. https://arxiv.org/abs/2607.19433</p><p>SecurityOnline. (2026, July 20). <em>Linux kernel publishes 440 CVE advisories in 24 hours as AI accelerates bug hunting</em>. https://securityonline.info/linux-kernel-cves/</p><p>SiliconANGLE. (2026, July 20). <em>Neo Security bags $100M to build the secure control layer for enterprise AI agents</em>. https://siliconangle.com/2026/07/20/neo-security-bags-100m-build-secure-control-layer-enterprise-ai-agents/</p><p>The Hacker News. (2026, July 22). <em>Google launches Gemini 3.5 Flash Cyber AI to find and fix software vulnerabilities</em>. https://thehackernews.com/2026/07/google-launches-gemini-35-flash-cyber.html</p><p>Willison, S. (2026, July 22). <em>OpenAI&#8217;s accidental cyberattack against Hugging Face is science fiction that happened</em>. https://simonwillison.net/2026/Jul/22/openai-cyberattack/</p><p>XenoSpectrum. (2026, July). <em>Tracking the reality behind 440 Linux kernel CVE disclosures: Bulk assignment to already-fixed bugs and AI auditing</em>. https://xenospectrum.com/en/linux-kernel-cve-batch-ai-review/</p>]]></content:encoded></item><item><title><![CDATA[AI Defense Matrix: 194 Products Protect. Two Recover.]]></title><description><![CDATA[The AI Defense Matrix catalog maps 239 AI security products. Nineteen of the 48 cells sit empty or near-empty, every one in Govern, Respond, or Recover.]]></description><link>https://www.rockcybermusings.com/p/ai-defense-matrix-coverage-gap</link><guid isPermaLink="false">https://www.rockcybermusings.com/p/ai-defense-matrix-coverage-gap</guid><dc:creator><![CDATA[Rock Lambros]]></dc:creator><pubDate>Tue, 21 Jul 2026 12:51:08 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!oaJH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a01dbf7-2ca5-4891-a8c3-2c3626fbe511_2048x2048.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oaJH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a01dbf7-2ca5-4891-a8c3-2c3626fbe511_2048x2048.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oaJH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a01dbf7-2ca5-4891-a8c3-2c3626fbe511_2048x2048.png 424w, https://substackcdn.com/image/fetch/$s_!oaJH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a01dbf7-2ca5-4891-a8c3-2c3626fbe511_2048x2048.png 848w, https://substackcdn.com/image/fetch/$s_!oaJH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a01dbf7-2ca5-4891-a8c3-2c3626fbe511_2048x2048.png 1272w, https://substackcdn.com/image/fetch/$s_!oaJH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a01dbf7-2ca5-4891-a8c3-2c3626fbe511_2048x2048.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oaJH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a01dbf7-2ca5-4891-a8c3-2c3626fbe511_2048x2048.png" width="1456" height="1456" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8a01dbf7-2ca5-4891-a8c3-2c3626fbe511_2048x2048.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1456,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4069471,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/207800487?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a01dbf7-2ca5-4891-a8c3-2c3626fbe511_2048x2048.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!oaJH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a01dbf7-2ca5-4891-a8c3-2c3626fbe511_2048x2048.png 424w, https://substackcdn.com/image/fetch/$s_!oaJH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a01dbf7-2ca5-4891-a8c3-2c3626fbe511_2048x2048.png 848w, https://substackcdn.com/image/fetch/$s_!oaJH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a01dbf7-2ca5-4891-a8c3-2c3626fbe511_2048x2048.png 1272w, https://substackcdn.com/image/fetch/$s_!oaJH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a01dbf7-2ca5-4891-a8c3-2c3626fbe511_2048x2048.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>Open the AI Defense Matrix catalog and filter to Recover. You get two products out of 239. Filter to Protect and you get 194. Same catalog, same day, same 239 products. I pulled the raw data file yesterday and recounted every cell myself, because a gap that wide usually means somebody miscounted. Nobody miscounted.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/p/ai-defense-matrix-coverage-gap?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/p/ai-defense-matrix-coverage-gap?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h2><span>What The AI Defense Matrix Measures</span></h2><p><span>Lenny Zeltser and Sounile Yu built a grid with eight AI-specific asset classes down the side, the six NIST CSF 2.0 functions across the top, 48 cells where they meet. </span><a href="https://aidefensematrix.com"><span>The AI Defense Matrix</span></a><span> launched May 11, 2026 under CC BY-SA 4.0, as the security-for-AI companion to Yu&#8217;s </span><a href="https://cyberdefensematrix.com"><span>Cyber Defense Matrix</span></a><span>.</span></p><p><span>The rule they used to decide what gets a row is what makes the thing useful. A row exists only if defending that asset requires AI-specific considerations, processes, or tools. If a generic security approach handles the defense well, it belongs in the Cyber Defense Matrix instead. Raw GPUs and containers got cut for that exact reason, and the change log says so out loud, which is more than most frameworks bother to do.</span></p><p><span>That discipline is why counting the cells means anything. </span><a href="https://catalog.aidefensematrix.com"><span>The companion catalog</span></a><span> places 239 products across those 48 cells, sourced from public information, dated, open to community correction. It catalogs AI-specific security products. Your SOAR platform and your backup vendor aren&#8217;t in it, and they shouldn&#8217;t be. What it measures is whether the industry has built an AI-specific answer for each cell.</span></p><p><span>For most of the grid, it has. For one corner of it, nothing showed up at all.</span></p><h2><span>Run The Count Yourself</span></h2><p><span>Nineteen of the 48 cells hold zero products or exactly one. All 19 sit in Govern, Respond, or Recover.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iETC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc83d2a3-5945-412d-826e-87f027829d95_3900x2460.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iETC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc83d2a3-5945-412d-826e-87f027829d95_3900x2460.png 424w, https://substackcdn.com/image/fetch/$s_!iETC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc83d2a3-5945-412d-826e-87f027829d95_3900x2460.png 848w, https://substackcdn.com/image/fetch/$s_!iETC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc83d2a3-5945-412d-826e-87f027829d95_3900x2460.png 1272w, https://substackcdn.com/image/fetch/$s_!iETC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc83d2a3-5945-412d-826e-87f027829d95_3900x2460.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iETC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc83d2a3-5945-412d-826e-87f027829d95_3900x2460.png" width="1456" height="918" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cc83d2a3-5945-412d-826e-87f027829d95_3900x2460.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:918,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:258258,&quot;alt&quot;:&quot;Coverage grid of the AI Defense Matrix showing eight AI asset classes against six NIST CSF 2.0 functions, with the 19 cells holding zero or one product outlined in coral and all of them falling in the Govern, Respond, and Recover columns.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/207800487?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc83d2a3-5945-412d-826e-87f027829d95_3900x2460.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Coverage grid of the AI Defense Matrix showing eight AI asset classes against six NIST CSF 2.0 functions, with the 19 cells holding zero or one product outlined in coral and all of them falling in the Govern, Respond, and Recover columns." title="Coverage grid of the AI Defense Matrix showing eight AI asset classes against six NIST CSF 2.0 functions, with the 19 cells holding zero or one product outlined in coral and all of them falling in the Govern, Respond, and Recover columns." srcset="https://substackcdn.com/image/fetch/$s_!iETC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc83d2a3-5945-412d-826e-87f027829d95_3900x2460.png 424w, https://substackcdn.com/image/fetch/$s_!iETC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc83d2a3-5945-412d-826e-87f027829d95_3900x2460.png 848w, https://substackcdn.com/image/fetch/$s_!iETC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc83d2a3-5945-412d-826e-87f027829d95_3900x2460.png 1272w, https://substackcdn.com/image/fetch/$s_!iETC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc83d2a3-5945-412d-826e-87f027829d95_3900x2460.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 1: 239 AI Security Products On 48</figcaption></figure></div><p><span>Run it the other way and the picture gets starker. Every single cell in Identify, Protect, and Detect holds at least three products. The floor is three for Identify, seven for Protect, six for Detect. Not one thin cell anywhere in those three columns. Then you cross into Govern, and the floor drops to zero. Same for Respond. Same for Recover.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LX3B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa1acead-103a-4314-b0bc-df20a8956b4e_3600x1920.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LX3B!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa1acead-103a-4314-b0bc-df20a8956b4e_3600x1920.png 424w, https://substackcdn.com/image/fetch/$s_!LX3B!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa1acead-103a-4314-b0bc-df20a8956b4e_3600x1920.png 848w, https://substackcdn.com/image/fetch/$s_!LX3B!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa1acead-103a-4314-b0bc-df20a8956b4e_3600x1920.png 1272w, https://substackcdn.com/image/fetch/$s_!LX3B!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa1acead-103a-4314-b0bc-df20a8956b4e_3600x1920.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LX3B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa1acead-103a-4314-b0bc-df20a8956b4e_3600x1920.png" width="1456" height="777" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aa1acead-103a-4314-b0bc-df20a8956b4e_3600x1920.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:777,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:153946,&quot;alt&quot;:&quot;Bar chart counting cells that hold zero products or one in each NIST CSF function, showing zero such cells in Identify, Protect, and Detect, against five in Govern, six in Respond, and all eight in Recover.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/207800487?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa1acead-103a-4314-b0bc-df20a8956b4e_3600x1920.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Bar chart counting cells that hold zero products or one in each NIST CSF function, showing zero such cells in Identify, Protect, and Detect, against five in Govern, six in Respond, and all eight in Recover." title="Bar chart counting cells that hold zero products or one in each NIST CSF function, showing zero such cells in Identify, Protect, and Detect, against five in Govern, six in Respond, and all eight in Recover." srcset="https://substackcdn.com/image/fetch/$s_!LX3B!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa1acead-103a-4314-b0bc-df20a8956b4e_3600x1920.png 424w, https://substackcdn.com/image/fetch/$s_!LX3B!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa1acead-103a-4314-b0bc-df20a8956b4e_3600x1920.png 848w, https://substackcdn.com/image/fetch/$s_!LX3B!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa1acead-103a-4314-b0bc-df20a8956b4e_3600x1920.png 1272w, https://substackcdn.com/image/fetch/$s_!LX3B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa1acead-103a-4314-b0bc-df20a8956b4e_3600x1920.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 2: How Many Cells Per Column Are Empty Or Nearly Empty</figcaption></figure></div><p><span>Before anyone writes to tell me thin rows explain thin cells, they don&#8217;t. Runtime AI Data is the fattest row on the grid, with 244 product placements across it, and it still shows blanks in Govern and Recover. AI Model carries 116 placements and covers all six functions. Row size doesn&#8217;t predict where the holes are. Column does.</span></p><p><span>One number needs a footnote so nobody catches me playing games with it. When I say 194 products do Protect, that&#8217;s how many products carry a Protect tag on at least one asset class. Those same products land in 312 asset-specific Protect cells, because a product covering three rows counts once in the first number and three times in the second. Both numbers are real. They answer different questions.</span></p><p><span>Now, I&#8217;d be remiss if I didn&#8217;t call out that my employer sits in this catalog with five cells: agent identity discovery, plus protection and detection on runtime AI data and orchestration tools. All five land in the middle three columns. I&#8217;m not going to pretend that&#8217;s a coincidence or a shortcoming particular to us. It&#8217;s what nearly every product in the AI security market looks like when you place it on this grid, including the ones you already bought, and it&#8217;s the shape of the problem rather than the shape of any one vendor&#8217;s roadmap.</span></p><h2><span>Two Products Cover Recover</span></h2><p><span>Here they are, by name. Hirundo does machine unlearning, stripping memorized data and jailbreak behavior out of a trained model without a full retrain, and the catalog places it in Recover for AI Model. Rubrik Agent Cloud rewinds destructive agent actions, and it holds Recover for AI Agent Identities and for AI-Generated Code.</span></p><p><span>That&#8217;s the column. Two products, three cells, and no cell in Recover holds more than one product.</span></p><p><span>Respond does better and still doesn&#8217;t do well. Nine products across five cells. Four of the nine hold their Respond coverage on the AI Agent Identities row, and all four are non-human identity platforms: Astrix, Clutch, Permiso, and Vorlon. Credential revocation and agent quarantine are the one response capability the market ships in any volume at all.</span></p><p><span>Read the actual cell text and the two columns split cleanly. Respond is written in containment verbs: credential revocation, agent quarantine, session termination, RAG source isolation, plugin disable, shadow AI takedown. Recover is written in undo verbs: model version restore, dataset restore from golden copies, vector DB restore, re-indexing, prompt rollback, agent identity re-provisioning.</span></p><p><span>Then there&#8217;s the detail I keep coming back to. Three cells on the entire grid are labeled generic by the authors themselves. Generic container IR. Generic platform restore. Generic network failover. All three sit in Respond and Recover. Nowhere else on 48 cells do Zeltser and Yu tell you the traditional answer will do. That admission is the most honest thing on the page, and it&#8217;s also a map of where the AI-specific work hasn&#8217;t happened yet.</span></p><p><span>Undo assumes a lot. An agent that ran for six hours holding delegated credentials across a dozen tools has sent emails, opened pull requests, written to a CRM, posted in channels, and fired webhooks that triggered things you don&#8217;t have visibility into. Restore the platform, and none of that comes back. Those effects live in separate systems with separate owners and no shared transaction boundary, which means there&#8217;s nothing to roll back to. I&#8217;ve written before about why </span><a href="https://www.rockcybermusings.com/p/i-agent-authentication-authorization-gap"><span>least agency beats least privilege</span></a><span> once agents can act, and this column is that argument showing up as somebody else&#8217;s control taxonomy.</span></p><h2><span>Why The Market Sells The Middle</span></h2><p><span>I had the wrong explanation for this at first. My first read was that the empty columns are the architectural ones, and the market only sells what bolts on. Identify killed that theory in about a minute. Discovering AI agents across an enterprise is an architecture problem too, and the market sells 146 products against it.</span></p><p><span>That&#8217;s the difference between watching a system and reaching into it.</span></p><p><span>Identify and Detect sell because a product can do the work from outside. Agentless posture management crawls your cloud and finds unregistered models, and you change nothing to let it. Protect sells at 194 for a reason that surprised me until I read the product descriptions: what the market calls Protect for AI is overwhelmingly inline filtering at a chokepoint. Gateways, proxies, browser extensions, guardrails on prompts and responses. That&#8217;s still exterior work. A filter inspects something crossing a boundary and decides yes or no.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pf1f!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce355f26-1ce2-424d-88d9-da5d84c51a02_3900x2100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pf1f!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce355f26-1ce2-424d-88d9-da5d84c51a02_3900x2100.png 424w, https://substackcdn.com/image/fetch/$s_!pf1f!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce355f26-1ce2-424d-88d9-da5d84c51a02_3900x2100.png 848w, https://substackcdn.com/image/fetch/$s_!pf1f!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce355f26-1ce2-424d-88d9-da5d84c51a02_3900x2100.png 1272w, https://substackcdn.com/image/fetch/$s_!pf1f!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce355f26-1ce2-424d-88d9-da5d84c51a02_3900x2100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pf1f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce355f26-1ce2-424d-88d9-da5d84c51a02_3900x2100.png" width="3900" height="2100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ce355f26-1ce2-424d-88d9-da5d84c51a02_3900x2100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2100,&quot;width&quot;:3900,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:459873,&quot;alt&quot;:&quot;Two-zone diagram separating the AI security functions a product delivers from outside a system, Identify at 146 products, Protect at 194 and Detect at 191, from the functions that require reaching into it, Govern at 11, Respond at nine and Recover at two.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/207800487?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67312b30-7e4e-4331-a4f8-d814b2559c1c_3900x2100.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Two-zone diagram separating the AI security functions a product delivers from outside a system, Identify at 146 products, Protect at 194 and Detect at 191, from the functions that require reaching into it, Govern at 11, Respond at nine and Recover at two." title="Two-zone diagram separating the AI security functions a product delivers from outside a system, Identify at 146 products, Protect at 194 and Detect at 191, from the functions that require reaching into it, Govern at 11, Respond at nine and Recover at two." srcset="https://substackcdn.com/image/fetch/$s_!pf1f!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce355f26-1ce2-424d-88d9-da5d84c51a02_3900x2100.png 424w, https://substackcdn.com/image/fetch/$s_!pf1f!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce355f26-1ce2-424d-88d9-da5d84c51a02_3900x2100.png 848w, https://substackcdn.com/image/fetch/$s_!pf1f!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce355f26-1ce2-424d-88d9-da5d84c51a02_3900x2100.png 1272w, https://substackcdn.com/image/fetch/$s_!pf1f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce355f26-1ce2-424d-88d9-da5d84c51a02_3900x2100.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 3: What The Market Sells And What You Build</figcaption></figure></div><p><span>Every containment verb in the Respond column carries a precondition somebody had to build. You terminate a session where sessions exist and can be terminated. You revoke a credential where it was scoped and revocable in the first place. You quarantine an agent where the agent runs somewhere quarantinable. A vendor can sell you the button. Nobody can sell you the wiring behind it.</span></p><p><span>One row breaks that pattern, and it&#8217;s the exception worth studying rather than the one that sinks the argument. AI Agent Identities carries 56 products under Protect, and the cell text reads agent OAuth, capability scoping, and short-lived credentials. That&#8217;s architecture sold as a product, which is the thing I said the market doesn&#8217;t do.</span></p><p><span>Look at what happened behind it. AI Agent Identities and AI Model are the only two rows on the whole grid with coverage in all six functions, Respond and Recover included. Every other row has at least one blank. Both of those rows got a market around the underlying primitive first, non-human identity tooling in one case and model registries and provenance in the other. Once the asset became addressable, once agents had scoped identities and models had versions and inventories, the containment columns filled in behind them. Four products doing agent quarantine exist because 56 products turned agents into principals you can scope.</span></p><p><span>That sequence is the roadmap, and it took me a while to see it. Response capability doesn&#8217;t show up because vendors decide to care about incidents. It shows up after somebody makes the asset addressable, and containment becomes something you can build on top of that. Runtime AI Data carries 244 placements and zero Recover coverage, because nobody has made a prompt, a RAG chunk, or an agent&#8217;s persistent memory into a thing with a version and an owner you can roll back to. Do that work and the column can fill. Skip it and vendor attention won&#8217;t rescue you.</span></p><p><span>Govern is the cleanest proof, and it settles a question I went back and forth on. Read all eight Govern cells and every one is a standard, a policy, or an evaluation decision. AI platform standards. AI application governance. AI coding standards and code-review policy. AI egress policy. Model selection and provider evaluation. Dataset provenance and licensing policy. Prompt and RAG policy. AI agent identity policy and authorization standards.</span></p><p><span>None of that is a product category. Zeltser and Yu tell you as much in their own instructions, where the gap analysis asks whether process, technology, or both cover each cell, and then tells you to start with Govern. Eleven products carry a Govern tag, and five of the eight rows have zero. Credo AI, OneTrust, Cranium, Holistic AI, and LatticeFlow are all in there and correctly tagged. They help you document and evidence a policy. Writing the policy stays yours.</span></p><h2><span>The Prediction The AI Defense Matrix Sets Up</span></h2><p><span>Here&#8217;s where I part company with the authors, and I want to be precise about it because they are probably right.</span></p><p><span>Their guidance to vendors says to treat thinly covered cells as opportunities for differentiation and new products that solve underserved needs. That&#8217;s a forecast because the thin columns fill because the market notices the gap and builds into it. My read is that Recover and most of Respond stay thin, because the missing capability isn&#8217;t a product somebody forgot to build. It&#8217;s a property of systems that were designed without it.</span></p><p><span>Put a number on it. I&#8217;d say 70% that the Recover column holds fewer than ten products in July 2028, and under 20% that it ever resembles what Protect looks like today. I&#8217;m at 70 rather than 90 because I&#8217;ve been wrong about market timing before. Nobody sold cloud posture management in 2016 either, and a July 2026 snapshot of a young category can look identical to a permanent boundary.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lTFY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F384e10fb-108c-43f6-9906-ad67b62d4355_3600x1980.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lTFY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F384e10fb-108c-43f6-9906-ad67b62d4355_3600x1980.png 424w, https://substackcdn.com/image/fetch/$s_!lTFY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F384e10fb-108c-43f6-9906-ad67b62d4355_3600x1980.png 848w, https://substackcdn.com/image/fetch/$s_!lTFY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F384e10fb-108c-43f6-9906-ad67b62d4355_3600x1980.png 1272w, https://substackcdn.com/image/fetch/$s_!lTFY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F384e10fb-108c-43f6-9906-ad67b62d4355_3600x1980.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lTFY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F384e10fb-108c-43f6-9906-ad67b62d4355_3600x1980.png" width="1456" height="801" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/384e10fb-108c-43f6-9906-ad67b62d4355_3600x1980.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:801,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:219116,&quot;alt&quot;:&quot;Line chart contrasting two paths for the number of products covering Recover between July 2026 and July 2028, a flat structural path staying under ten and a market-fills path climbing past eighty, with the falsifying condition named.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/207800487?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F384e10fb-108c-43f6-9906-ad67b62d4355_3600x1980.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Line chart contrasting two paths for the number of products covering Recover between July 2026 and July 2028, a flat structural path staying under ten and a market-fills path climbing past eighty, with the falsifying condition named." title="Line chart contrasting two paths for the number of products covering Recover between July 2026 and July 2028, a flat structural path staying under ten and a market-fills path climbing past eighty, with the falsifying condition named." srcset="https://substackcdn.com/image/fetch/$s_!lTFY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F384e10fb-108c-43f6-9906-ad67b62d4355_3600x1980.png 424w, https://substackcdn.com/image/fetch/$s_!lTFY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F384e10fb-108c-43f6-9906-ad67b62d4355_3600x1980.png 848w, https://substackcdn.com/image/fetch/$s_!lTFY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F384e10fb-108c-43f6-9906-ad67b62d4355_3600x1980.png 1272w, https://substackcdn.com/image/fetch/$s_!lTFY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F384e10fb-108c-43f6-9906-ad67b62d4355_3600x1980.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 4: A Claim You Can Check In Two Years</figcaption></figure></div><p><span>The falsifier is specific, so hold me to it. Watch Rubrik. If three more vendors ship agent-action reversal and it works without you rerouting your agents through their control plane first, I&#8217;m wrong and the market solved something I said it structurally couldn&#8217;t. If the only way it ever works is routing your agents through somebody&#8217;s plane, that&#8217;s the architectural decision doing the work, and the product is the part you bolt on afterward.</span></p><p><span>Meanwhile, NIST IR 8596, the Cyber AI Profile everyone&#8217;s waiting on, has been sitting as an initial preliminary draft since December 16, 2025, with the comment period closed since January 30, 2026. Seven months, no initial public draft. You need a working instrument now, and this grid is the best one anybody&#8217;s published.</span></p><p><span>Two products cover Recover for all of AI. One strips bad behavior out of model weights. The other rewinds agent actions it was routed through ahead of time. That&#8217;s the entire Recover column of the AI Defense Matrix, on a grid of 48 cells, in a market that has shipped 194 ways to protect you and almost nothing to put you back together.</span></p><h3><span>What To Do Next</span></h3><p><span>Download the matrix as a CSV, YAML, or Markdown and populate it for your own environment this week. Mark every cell covered, partial, or absent. Budget 90 minutes with whoever owns your agent platforms.</span></p><p><span>Then cover Identify, Protect, and Detect with your hand and look at what&#8217;s left. For each blank in Govern, Respond, or Recover, write down two things: the design decision that would have to change for that cell to fill, and the name of the person who can make that decision. Not the product that would fill it. The decision and the owner. That&#8217;s a build backlog and an ownership map, which is Create and Adapt work in the </span><a href="https://www.rockcyber.com/ai-strategy-and-governance"><span>CARE model</span></a><span>, and it&#8217;s a different conversation than a purchase order.</span></p><p><span>If you want the deeper argument on why authorization scope is a runtime decision rather than a connection-time checkbox, I wrote that up in </span><a href="https://www.rockcybermusings.com/p/mcp-authorization-scope-spec-gap"><span>the MCP authorization gap piece</span></a><span>, and </span><a href="https://www.rockcybermusings.com/p/autonomous-ai-agent-ransomware-jadepuffer"><span>JadePuffer</span></a><span> is what the Respond column being empty looks like when it happens to somebody. More at </span><a href="https://rockcybermusings.com"><span>rockcybermusings.com</span></a><span>, and the advisory work lives at </span><a href="https://www.rockcyber.com"><span>rockcyber.com</span></a><span>.</span></p><p><span>&#128073; For ongoing analysis of agentic AI governance frameworks, the conversation continues at </span><strong><a href="https://rockcybermusings.com/">RockCyber Musings</a></strong><span>.</span></p><p><span>&#128073; Visit </span><strong><a href="https://www.rockcyber.com/">RockCyber.com</a></strong><span> to learn more about how we can help with your traditional Cybersecurity and AI Security and Governance journey.</span></p><p><span>&#128073; Want to save a quick $100K? Check out our AI Governance Tools at </span><strong><a href="https://aigovernancetoolkit.com/">AIGovernanceToolkit.com</a></strong></p><p>&#128073; As a bonus, check out my latest appearance on the <strong><a href="https://dtsr.buzzsprout.com/">Down The Security Rabbit Hole</a></strong> podcast, where we discuss the current state of AI in the&nbsp;SOC for cybersecurit<a href="https://www.youtube.com/hashtag/cybersecurity"><span>y</span></a>&nbsp;and specifically how it differentiates from the promise of SOAR.</p><div id="youtube2-5YIpZuQLTMg" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;5YIpZuQLTMg&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/5YIpZuQLTMg?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share RockCyber Musings&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share RockCyber Musings</span></a></p><p><br></p>]]></content:encoded></item><item><title><![CDATA[Weekly Musings Top 10 AI Security Wrapup: Issue 46 July 10 -July 16, 2026]]></title><description><![CDATA[The week agentic AI security got real: an AI agent breached Hugging Face, a red team cracked GPT-5.6 in six hours, and China's first AI-agent rules went live.]]></description><link>https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260710-20260716</link><guid isPermaLink="false">https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260710-20260716</guid><dc:creator><![CDATA[Rock Lambros]]></dc:creator><pubDate>Fri, 17 Jul 2026 12:51:32 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!3uJE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68f8f3a8-7fd2-4881-a261-da3d60b137a8_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3uJE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68f8f3a8-7fd2-4881-a261-da3d60b137a8_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3uJE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68f8f3a8-7fd2-4881-a261-da3d60b137a8_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!3uJE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68f8f3a8-7fd2-4881-a261-da3d60b137a8_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!3uJE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68f8f3a8-7fd2-4881-a261-da3d60b137a8_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!3uJE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68f8f3a8-7fd2-4881-a261-da3d60b137a8_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3uJE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68f8f3a8-7fd2-4881-a261-da3d60b137a8_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/68f8f3a8-7fd2-4881-a261-da3d60b137a8_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1233556,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/207367589?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68f8f3a8-7fd2-4881-a261-da3d60b137a8_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3uJE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68f8f3a8-7fd2-4881-a261-da3d60b137a8_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!3uJE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68f8f3a8-7fd2-4881-a261-da3d60b137a8_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!3uJE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68f8f3a8-7fd2-4881-a261-da3d60b137a8_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!3uJE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68f8f3a8-7fd2-4881-a261-da3d60b137a8_1024x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>We&#8217;ve warned boards that autonomous AI attacks were coming. We were proven right once again. An AI agent broke into Hugging Face and ran the intrusion itself. A government red team cracked a new frontier model&#8217;s cyber safeguards in six hours. The forecast became the incident report.</p><p>The through-line rattles anyone still treating AI as a feature bolted onto the business. Attackers now point capable models at your environment and let them plan, adapt, and act at machine speed. China switched on the first real rulebook for AI agents. Two labs dropped open-weight frontier models anyone can download. Microsoft shipped its largest patch load ever and credited its own AI. I cut the stories that predate July 10. Here is what landed.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260710-20260716?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260710-20260716?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h3>1. Hugging Face Discloses a Breach Run End to End by an AI Agent</h3><p>On July 16, 2026, Hugging Face disclosed that an autonomous AI agent breached part of its production infrastructure days earlier (Hugging Face, 2026). A malicious dataset abused two code-execution paths, escalated to node-level access, and moved laterally over a weekend. The company found access to internal datasets and service credentials, with no public models touched. It reconstructed the timeline with its own LLM analysis over 17,000 attacker events (NHIMG, 2026).</p><p><strong>Why it matters</strong></p><ul><li><p>The first high-profile platform breach run end to end by an agent.</p></li><li><p>The foothold was a poisoned dataset, not a phished user.</p></li><li><p>Safety guardrails blocked the defenders, not the attacker.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Sandbox dataset-processing workers and scope their credentials.</p></li><li><p>Pre-stage an open-weight model that you control for incident response.</p></li><li><p>Rehearse weekend and off-hours detection.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>I have sat through a hundred tabletops where someone called this scenario fiction. Hand them the disclosure. The attacker chained known mistakes into one operation, and only the driver was new. Guardrails blocked the responders while the attacker&#8217;s stripped-down model faced none. Stage your break-glass model, rotate the secrets your workers touch, and expect the next probe on a Saturday. I have argued this blast-radius math at rockcybermusings.com for a while.</p><h3>2. UK Government Red Team Cracks GPT-5.6 Cyber Safeguards in Six Hours</h3><p>On July 10, 2026, the UK AI Security Institute reported universal jailbreaks in OpenAI&#8217;s freshly released GPT-5.6 (Fortune, 2026). Testers defeated the controls meant to stop the model from hacking, then used it to break into systems on its own. AISI built the jailbreak in roughly six hours, and it held across OpenAI&#8217;s malicious-query set (Technobezz, 2026). OpenAI pointed to its layered safeguards and a rapid remediation process.</p><p><strong>Why it matters</strong></p><ul><li><p>A government agency beat a frontier lab&#8217;s cyber guardrails in an afternoon.</p></li><li><p>These jailbreaks enable agentic offense rather than one-off bad answers.</p></li><li><p>Pre-release government testing caught it before public exposure.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Wrap your own boundaries around any model with tool access.</p></li><li><p>Make vendor red-team results a written procurement gate.</p></li><li><p>Assume any model exposed to untrusted input can turn offensive.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Six hours. That is the number I want every executive to sit with. A red team needed less than a workday to turn a flagship model into an exploit-writing partner. I am a Bayesian, and my prior that guardrails hold under a determined attacker dropped again. Vendor safety layers are speed bumps, worthless against the motivated. The redeeming part is a government caught this before release. Put the vendor&#8217;s evaluation posture in your contract.</p><h3>3. China&#8217;s Rulebook for AI Agents Takes Effect, the First of Its Kind</h3><p>On July 15, 2026, China&#8217;s Implementation Opinions on intelligent agents became enforceable, the world&#8217;s first dedicated regulatory category for AI agents (IAPP, 2026). The rules define agents as systems capable of autonomous perception, memory, decision-making, and execution. They establish a three-tier decision-authorization structure and mandate filing, testing, and product-recall provisions in sensitive sectors (Global Law Experts, 2026). The same date pushed platforms like Doubao and Qwen to shut down companion features.</p><p><strong>Why it matters</strong></p><ul><li><p>The first binding definition of an AI agent came out of Beijing.</p></li><li><p>China operations with agent deployments face immediate filing duties.</p></li><li><p>Authorization tiers force you to declare what an agent decides alone.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>In China, map every agent to the authorization and filing rules now.</p></li><li><p>Build an agent inventory with decision rights and override thresholds.</p></li><li><p>Align your internal agent taxonomy to the definition.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>I do not love handing Beijing the pen, but credit where it is due. They defined an AI agent while the rest of us argued about whether agents are high-risk by default. Definitions are power, and the clearest legal one now lives in a Chinese regulation. The practical bite is the tiers: what may this agent decide without a human in the loop? I ask that in every board session I run through rockcyber.com and get blank stares more often than answers. Write down your agents&#8217; decision rights now.</p><h3>4. xAI&#8217;s Grok Build CLI Shipped Entire Repositories and Secrets to the Cloud</h3><p>Around July 13 and 14, 2026, a researcher showed that version 0.2.93 of xAI&#8217;s Grok Build coding CLI uploaded entire Git repositories to a Google Cloud Storage bucket rather than the files a task needed (Tech Times, 2026). For a 12 GB repository, the tool pushed more than 5 GB while model traffic came to 192 KB. The upload included the full commit history, so deleted files went too. Files holding credentials uploaded without redaction, and opting out did not stop the sweep (Crypto Briefing, 2026).</p><p><strong>Why it matters</strong></p><ul><li><p>Your code and secrets can leave as a side effect of a coding assistant working.</p></li><li><p>The opt-out control did nothing. Privacy toggles are marketing until proven.</p></li><li><p>Full commit-history upload means deleted secrets are back in play.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Block or quarantine Grok Build CLI until you verify what it transmits.</p></li><li><p>Gate every agentic coding tool on evidence of what it sends.</p></li><li><p>Rotate exposed secrets and move credentials into a manager.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>This one made me put my coffee down, because the privacy toggle was theater. Someone shipped a product where do-not-send-my-data was a suggestion the software ignored. We only know because a researcher watched the packets. How many other agentic tools in your environment do the same and nobody has checked? Agentic developer tools are the new shadow IT, with your whole codebase as the blast radius. Gate approval on proof of behavior, and get secrets out of source control.</p><h3>5. Unpatched Claude for Chrome Flaw Lets Rogue Extensions Read Your Gmail</h3><p>Mid-week, researchers at Manifold Security detailed two flaws in Anthropic&#8217;s Claude for Chrome extension that let a malicious browser extension read a victim&#8217;s Gmail, Docs, and Calendar with about six lines of JavaScript (The Hacker News, 2026). The root cause is a handler that never checks whether a click came from a real user. Any extension with script access on claude.ai forges a click and fires a hardcoded prompt silently. Manifold reported the flaws in May 2026, yet the vulnerable code still shipped in version 1.0.80 on July 7 (CSO Online, 2026).</p><p><strong>Why it matters</strong></p><ul><li><p>A browser AI agent with mailbox access becomes an exfiltration tool.</p></li><li><p>The flaw maps to indirect prompt injection and excessive agency.</p></li><li><p>Reported in May, still exploitable in July. Resolved did not mean fixed.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Inventory AI browser extensions with mail access, and disable act-without-asking mode.</p></li><li><p>Treat browser AI agents as privileged identities.</p></li><li><p>Demand proof a fix reached production, not that a ticket closed.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>The detail that stuck with me is the gap between a ticket marked resolved and code that never moved. Someone closed it, everyone relaxed, and eight releases later the hole is still open. I have lived that failure mode in every large program I have run. The browser holds your sensitive data already decrypted and logged in, and you handed an agent permission to read your mail. The guardrail against abuse was a check the developers forgot to write. Treat every browser agent as a privileged service account, and ask to see the diff.</p><h3>6. Microsoft Patches a Record 570 Flaws as AI Reshapes Both Sides of the Fight</h3><p>On July 14, 2026, Microsoft shipped the largest Patch Tuesday in its history, fixing a record 570 vulnerabilities, including three zero-days with two exploited in the wild (BleepingComputer, 2026). Microsoft tied the surge to its own AI, crediting a vulnerability scanner it calls MDASH that finds flaws in Windows components before attackers reach them. The number runs roughly four times the same month a year earlier (Krebs on Security, 2026). The exploited zero-days hit Active Directory Federation Services and SharePoint Server (TechCrunch, 2026).</p><p><strong>Why it matters</strong></p><ul><li><p>AI now finds vulnerabilities at a scale that breaks your patch cadence.</p></li><li><p>The tools that help Microsoft find bugs help attackers weaponize them in hours.</p></li><li><p>Two exploited zero-days sit in identity infrastructure.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Prioritize the exploited AD FS and SharePoint zero-days now.</p></li><li><p>Shorten patch deferral windows for internet-facing and identity systems.</p></li><li><p>Invest in runtime detection, not only patching.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Five hundred and seventy. No human triage process was built for a number like that, and Microsoft is honest that AI drove the spike. Their agent found the bugs before the bad guys, who aim the same tools at the same code. Offense and defense now both scale with compute, and the loser moves at human speed. The energy and manufacturing clients I worry about cannot patch on this timeline, so they lean on segmentation and detection tuned for exploitation behavior. Plan for the flood, because it is the baseline now.</p><h3>7. Thinking Machines Ships Inkling, a 975-Billion-Parameter Open-Weight Model That Fine-Tunes Itself</h3><p>On July 15, 2026, Mira Murati&#8217;s Thinking Machines Lab released Inkling, an open-weights mixture-of-experts transformer with 975 billion total parameters and 41 billion active (TechCrunch, 2026). It carries a context window up to 1 million tokens. The headline capability was a demonstration in which Inkling fine-tuned itself, autonomously writing, running, and evaluating its own fine-tuning job (Axios, 2026). Full weights mean anyone can download, inspect, and customize the model.</p><p><strong>Why it matters</strong></p><ul><li><p>A frontier-scale model with open weights lands in anyone&#8217;s hands.</p></li><li><p>Self-directed fine-tuning collapses the effort to specialize a model.</p></li><li><p>Open weights on your own hardware is what defenders wanted this week.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Add open-weight models to your threat model as unrestricted attacker capability.</p></li><li><p>Treat internal self-fine-tuning as a change-management event.</p></li><li><p>Give defenders a sanctioned open-weight option on controlled infrastructure.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Open weights are a genuine double-edged sword, and I refuse to pretend otherwise for either camp. The same day Hugging Face said defenders need a self-hosted model, Thinking Machines handed everyone a frontier-scale one. That helps blue teams and it helps the people building offense models with the safety sanded off. My probability that abliterated versions show up in attack tooling within months is high. I am not in the ban-open-models camp. What I want is honesty about the trade.</p><h3>8. Kimi K3 Pushes an Open-Weight Model to the Frontier, From China</h3><p>On July 16, 2026, Moonshot AI launched Kimi K3, a roughly 2.8-trillion-parameter mixture-of-experts model. Its 1-million-token context window targets long-horizon coding and agent workloads (TechCrunch, 2026). In blind testing by the evaluation platform Arena, developers preferred Kimi over every leading US model for front-end coding, including Anthropic&#8217;s Fable 5 and OpenAI&#8217;s GPT-5.6 Sol (Axios, 2026). Moonshot committed to releasing the open weights on July 27.</p><p><strong>Why it matters</strong></p><ul><li><p>A Chinese lab reached rough parity and chose to open the weights.</p></li><li><p>Frontier-level coding in open weights lowers the floor for autonomous tooling.</p></li><li><p>Enterprises will feel pressure to adopt the cheapest capable model.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Decide your policy on Chinese-origin open-weight models now.</p></li><li><p>Factor the July 27 weight release into your threat model.</p></li><li><p>Evaluate data residency before routing sensitive code through a hosted Kimi endpoint.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Two open-weight frontier models landed in one week. One came from a former OpenAI CTO, one from Beijing, both matching or beating the closed US flagships. The story that closed labs hold an unbridgeable lead died quietly this week. When developers in a blind test prefer Kimi over Fable 5 and GPT-5.6, price and openness win the next procurement cycle. The question I keep dragging boards toward: what is your policy on where your models come from, and did you write it yet? Decide deliberately, because the July 27 weight drop turns this into an anyone-can-run-it problem.</p><h3>9. Meta Pulls an Instagram AI Feature That Copied People&#8217;s Likenesses Without Clear Consent</h3><p>After a short, loud backlash, Meta removed the Muse Image feature that let users generate AI images by referencing public Instagram accounts, with the reversal landing around July 13 and 14, 2026 (TechRepublic, 2026). Launched July 7, it used public accounts&#8217; posted photos as references. Adult public accounts were swept in by default unless a user disabled a reuse setting, and Meta&#8217;s own policy said people would not be notified when someone used their likeness (Variety, 2026). Meta said the feature missed the mark and pulled it.</p><p><strong>Why it matters</strong></p><ul><li><p>A trillion-dollar platform shipped opt-out-by-default likeness reuse and retreated in a week.</p></li><li><p>Likeness reuse is what the EU AI Act transparency rules move to govern.</p></li><li><p>The reputational half-life of a bad AI consent decision is now days.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Default any AI feature using third-party likenesses to opt-in with notice.</p></li><li><p>Map likeness features against the EU AI Act obligations arriving August 2.</p></li><li><p>Put a consent review gate in front of AI feature launches.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Meta is not a naive startup that stumbled into a consent problem. They have armies of lawyers and privacy engineers, and they still shipped default-on likeness reuse with no notice to the people whose faces got borrowed. The reflex inside big platforms remains take first, apologize later. What changed is the clock, because the backlash cost them the feature in a week. I tell boards that consent is not a checkbox at the bottom of a settings page nobody opens, and this is the case study. Design for affirmative consent now.</p><h3>10. Check Point&#8217;s AI Security Report Puts Numbers to the Machine-Speed Threat</h3><p>On July 15, 2026, Check Point published its AI Security Report 2026, documenting a year in which attackers ran exploitation workflows autonomously, generating thousands of commands with minimal human direction (Help Net Security, 2026). Adversaries acquire AI capability by abusing commercial models, stealing credentials, or self-hosting open-source models, then strip the safety controls. The report flags jailbreaks planted in agent configuration files like CLAUDE.md that load every session and stay active until removed. On identity, trained observers spotted AI-generated faces only about 41% of the time (Check Point, 2026).</p><p><strong>Why it matters</strong></p><ul><li><p>The autonomous-attacker pattern is now measured across a year of real incidents.</p></li><li><p>Jailbreaks in config files keep an agent compromised across sessions.</p></li><li><p>Trained analysts spot fake faces 41% of the time, so identity checks fail.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Add integrity monitoring for agent configuration files.</p></li><li><p>Move identity verification beyond face and voice for high-value actions.</p></li><li><p>Measure your own high-risk AI interaction rate.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>I am wary of vendor reports, so I read this one for the load-bearing data. The number that survived my skepticism is the 41%. When trained people flip a coin and do worse at spotting a fake face, every identity control built on I-can-tell-it-is-you is obsolete. I have told financial and energy clients for two years that voice and video prove nothing anymore. The config-file jailbreak deserves more attention than it will get, because a poisoned CLAUDE.md is patient persistence most stacks never inspect. Instrument the files your agents read at startup.</p><h3>The One Thing You Won&#8217;t Hear About But You Need To</h3><h3>11. Defenders Turn Prompt Injection Into a Weapon: Tracebit&#8217;s &#8220;Context Bombs&#8221;</h3><p>On July 14, 2026, researchers at Tracebit published a defensive twist that flips prompt injection against the attacker (Help Net Security, 2026). Rather than hijacking an AI, they plant short strings called context bombs inside decoy resources, crafted to trip the safety guardrails of an offensive AI agent and stop it mid-intrusion. They tested five leading models across 152 trials in an imitation AWS environment. Opus 4.8 reached full account admin in 93% of clean runs and failed every single time once a context bomb was in play (Tracebit, 2026).</p><p><strong>Why it matters</strong></p><ul><li><p>Defenders finally have a tool that turns the attacker&#8217;s safety training into a trap.</p></li><li><p>Context bombs disrupt the intrusion in progress and buy back reaction time.</p></li><li><p>The technique layers on top of canary and deception controls.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Pilot context bombs inside honeytokens and decoy secrets.</p></li><li><p>Pair them with canaries so a tripped bomb also raises an alert.</p></li><li><p>Track abliterated models, which may ignore the bomb.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>This is the story that made me smile all week, and almost nobody outside the research crowd is talking about it. For two years the prompt-injection conversation has been a funeral dirge: the flaw cannot be fixed, abandon hope. Tracebit asked the contrarian question, why not turn the attacker&#8217;s guardrails into a landmine in your own environment? Opus 4.8 going from a 93% admin-access rate to zero resets a prior in a hurry. The caveat matters, because an attacker running an abliterated model may walk right past the bomb. I would still rather hand my defenders a working trap today than wait for a fix that is never coming.</p><p><span>&#128073; For ongoing analysis of agentic AI governance frameworks, the conversation continues at </span><strong><a href="https://rockcybermusings.com/">RockCyber Musings</a></strong><span>.</span></p><p><span>&#128073; Visit </span><strong><a href="https://www.rockcyber.com/">RockCyber.com</a></strong><span> to learn more about how we can help with your traditional Cybersecurity and AI Security and Governance journey.</span></p><p><span>&#128073; Want to save a quick $100K? Check out our AI Governance Tools at </span><strong><a href="https://aigovernancetoolkit.com/">AIGovernanceToolkit.com</a></strong></p><p><span>&#128073; As a bonus, check our AMA on the </span><strong><a href="https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance/">2026 OWASP GenAI Security Project State of Agentic AI Security and Governance report</a></strong><span> with me and the other co-leads (it was live, so start at time marker 09:45)</span></p><div id="youtube2-jK1Z7Z6zlW0" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;jK1Z7Z6zlW0&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/jK1Z7Z6zlW0?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><em>The views and opinions expressed in RockCyber Musings are my own and do not represent the positions of my employer or any organization I&#8217;m affiliated with.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share RockCyber Musings&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share RockCyber Musings</span></a></p><h2>References</h2><p>Axios. (2026, July 15). <em>Mira Murati&#8217;s Thinking Machines debuts its first AI model</em>. Axios. https://www.axios.com/2026/07/15/mira-murati-thinking-machines-open-weight-model-inkling</p><p>Axios. (2026, July 16). <em>China&#8217;s open-weight Kimi model stuns AI world with frontier-level results</em>. Axios. https://www.axios.com/2026/07/16/moonshot-kimi-ai-china-model-openai-anthropic</p><p>BleepingComputer. (2026, July 14). <em>Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days</em>. BleepingComputer. https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/</p><p>Check Point Software Technologies. (2026, July 15). <em>AI Security Report 2026</em>. Check Point. https://www.helpnetsecurity.com/2026/07/15/check-point-ai-security-report-2026/</p><p>Crypto Briefing. (2026, July 14). <em>xAI Grok Build CLI caught uploading private code and secrets to Google Cloud bucket</em>. Crypto Briefing. https://cryptobriefing.com/xai-grok-build-cli-private-code-leak/</p><p>CSO Online. (2026, July). <em>New bugs in Claude for Chrome allow extensions to abuse AI privileges</em>. CSO Online. https://www.csoonline.com/article/4197325/new-bugs-in-claude-for-chrome-allow-extensions-to-abuse-ai-privileges.html</p><p>Fortune. (2026, July 10). <em>U.K. agency finds &#8216;universal jailbreaks&#8217; unlock dangerous cyber capabilities of OpenAI&#8217;s GPT-5.6</em>. Fortune. https://fortune.com/2026/07/10/openai-gpt-5-6-sol-jailbreaks-cyber-attacks-similar-to-security-flaw-that-led-u-s-government-to-force-anthropic-to-disable-fable-5/</p><p>Global Law Experts. (2026, July). <em>A concise interpretation of the CAC&#8217;s Implementation Opinions on the standardised application and innovative development of AI agents</em>. Global Law Experts. https://globallawexperts.com/innovation-regulation-as-inseparable-objectives-a-concise-interpretation-of-the-cacs-implementation-opinions-on-the-standardised-application-innovative-development-of-ai-agents/</p><p>Help Net Security. (2026, July 14). <em>&#8220;Context bombs&#8221; can frustrate AI-driven attacks, researchers found</em>. Help Net Security. https://www.helpnetsecurity.com/2026/07/14/context-bombs-for-defensive-prompt-injection/</p><p>Help Net Security. (2026, July 15). <em>AI used to help plan the break-in, now it&#8217;s doing the break-in</em>. Help Net Security. https://www.helpnetsecurity.com/2026/07/15/check-point-ai-security-report-2026/</p><p>Hugging Face. (2026, July 16). <em>Security incident disclosure: July 2026</em>. Hugging Face. https://huggingface.co/blog/security-incident-july-2026</p><p>International Association of Privacy Professionals. (2026, July). <em>China&#8217;s new AI rules: Ethics, AI agents and anthropomorphic AI</em>. IAPP. https://iapp.org/news/a/china-s-new-ai-rules-ethics-ai-agents-and-anthropomorphic-ai</p><p>Krebs on Security. (2026, July). <em>Microsoft patches a record 570 security flaws</em>. Krebs on Security. https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/</p><p>NHIMG. (2026, July). <em>Hugging Face breach</em>. Non-Human Identity Management Group. https://nhimg.org/hugging-face-breach</p><p>Technobezz. (2026, July). <em>U.K. AI Security Institute finds universal jailbreaks in OpenAI&#8217;s GPT-5.6 within hours</em>. Technobezz. https://www.technobezz.com/news/uk-ai-security-institute-finds-universal-jailbreaks-in-openais-gpt-56-within-hours</p><p>TechCrunch. (2026, July 15). <em>Thinking Machines amps up its bet against one-size-fits-all AI with its first open model, Inkling</em>. TechCrunch. https://techcrunch.com/2026/07/15/thinking-machines-amps-up-its-bet-against-one-size-fits-all-ai-with-its-first-open-model-inkling/</p><p>TechCrunch. (2026, July 15). <em>Microsoft patches record number of security vulnerabilities, citing its use of AI</em>. TechCrunch. https://techcrunch.com/2026/07/15/microsoft-patches-record-number-of-security-vulnerabilities-citing-its-use-of-ai/</p><p>TechCrunch. (2026, July 16). <em>Moonshot&#8217;s Kimi 3 is expected to close the gap with Anthropic&#8217;s Opus 4.8</em>. TechCrunch. https://techcrunch.com/2026/07/16/moonshots-upcoming-kimi-3-is-expected-to-close-the-gap-with-anthropics-opus-4-8/</p><p>TechRepublic. (2026, July). <em>Meta removes Muse Image Instagram feature after consent backlash</em>. TechRepublic. https://www.techrepublic.com/article/news-meta-scraps-muse-image-feature-after-launch/</p><p>Tech Times. (2026, July 14). <em>Grok Build shipped entire codebases to xAI cloud, privacy toggle did nothing</em>. Tech Times. https://www.techtimes.com/articles/320420/20260714/grok-build-shipped-entire-codebases-xai-cloud-privacy-toggle-did-nothing.htm</p><p>The Hacker News. (2026, July). <em>Researchers say Claude for Chrome flaw lets rogue extensions trigger Gmail reads</em>. The Hacker News. https://thehackernews.com/2026/07/claude-for-chrome-flaw-lets-other.html</p><p>Tracebit. (2026, July 14). <em>Context bombs: Stopping AI attackers in their tracks</em>. Tracebit Research. https://agentic.tracebit.com/context-bombs/</p><p>Variety. (2026, July). <em>Meta suspends Instagram AI image feature after days of backlash</em>. Variety. https://variety.com/2026/biz/news/meta-suspends-ai-image-instagram-feature-backlash-1236806989/</p>]]></content:encoded></item><item><title><![CDATA[Autonomous AI Agent Ransomware: JadePuffer’s Authorization Lesson]]></title><description><![CDATA[Autonomous AI agent ransomware arrived with JadePuffer. The real lesson is machine-identity authorization over exploit novelty, and the controls to build.]]></description><link>https://www.rockcybermusings.com/p/autonomous-ai-agent-ransomware-jadepuffer</link><guid isPermaLink="false">https://www.rockcybermusings.com/p/autonomous-ai-agent-ransomware-jadepuffer</guid><dc:creator><![CDATA[Rock Lambros]]></dc:creator><pubDate>Tue, 14 Jul 2026 12:50:53 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!fp9k!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ce1de92-6db0-471c-9243-d3d025d1a9c3_1975x1505.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fp9k!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ce1de92-6db0-471c-9243-d3d025d1a9c3_1975x1505.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fp9k!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ce1de92-6db0-471c-9243-d3d025d1a9c3_1975x1505.png 424w, https://substackcdn.com/image/fetch/$s_!fp9k!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ce1de92-6db0-471c-9243-d3d025d1a9c3_1975x1505.png 848w, https://substackcdn.com/image/fetch/$s_!fp9k!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ce1de92-6db0-471c-9243-d3d025d1a9c3_1975x1505.png 1272w, https://substackcdn.com/image/fetch/$s_!fp9k!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ce1de92-6db0-471c-9243-d3d025d1a9c3_1975x1505.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fp9k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ce1de92-6db0-471c-9243-d3d025d1a9c3_1975x1505.png" width="1456" height="1110" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0ce1de92-6db0-471c-9243-d3d025d1a9c3_1975x1505.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1110,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3580211,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/206507719?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ce1de92-6db0-471c-9243-d3d025d1a9c3_1975x1505.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fp9k!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ce1de92-6db0-471c-9243-d3d025d1a9c3_1975x1505.png 424w, https://substackcdn.com/image/fetch/$s_!fp9k!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ce1de92-6db0-471c-9243-d3d025d1a9c3_1975x1505.png 848w, https://substackcdn.com/image/fetch/$s_!fp9k!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ce1de92-6db0-471c-9243-d3d025d1a9c3_1975x1505.png 1272w, https://substackcdn.com/image/fetch/$s_!fp9k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ce1de92-6db0-471c-9243-d3d025d1a9c3_1975x1505.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>Autonomous AI agent ransomware stopped being a research demo. </span><a href="https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion"><span>Sysdig disclosed JadePuffer</span></a><span>, an operation in which a language model executed a full ransomware kill chain from recon to encryption, with no human at the keyboard. It used no zero-days. It used a year-old bug, default credentials, and machine identities you already own. Here&#8217;s what happened, and the one control that would have contained it.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/p/autonomous-ai-agent-ransomware-jadepuffer?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/p/autonomous-ai-agent-ransomware-jadepuffer?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h2><strong><span>How The Agent Ran The Whole Chain</span></strong></h2><p><span>Langflow is a widely used open-source framework for building AI applications, and plenty of teams run it safely. This victim left a version with a year-old critical bug facing the open internet. That exposure is what the agent walked through. Once it had code execution on the host, it enumerated the machine and swept the environment for secrets in parallel: model provider keys, cloud credentials, crypto wallets, database credentials, and configuration files. It dumped Langflow&#8217;s own backing database, pulled the stored keys and user records, then deleted its staging files to clean up after itself.</span></p><p><span>Then it found the object store. Using the default credentials minioadmin:minioadmin, it listed every bucket, prioritized the ones named for infrastructure state and internal config, and fetched a credentials.json file by name. That file held an access key and secret pair, which the agent printed to its own terminal and saved to disk. It also installed a cron job on the host that beaconed to attacker infrastructure every 30 minutes, so it could get back in.</span></p><p><span>The agent reached the production database as root using credentials whose origin Sysdig could not determine. The agent didn&#8217;t harvest them from the Langflow host. Standing machine credentials sit in more places than any single inventory shows. From there, it injected a backdoor administrator into the Nacos configuration database, ran a methodical survey for a container escape using the database&#8217;s file primitives, reading the Docker socket and the container cgroup files to test for a path out of the container entirely, and moved to the finish. It encrypted all 1,342 Nacos service configuration items with MySQL&#8217;s built-in encryption function, dropped the original tables, and wrote a ransom note demanding Bitcoin.</span></p><p><span>The agent generated the encryption key at random, printed it to the console once, and never saved or transmitted it. The victim can&#8217;t recover those configurations even if they pay. Sysdig counted more than 600 distinct payloads across the operation, and the data theft the ransom note bragged about was the agent&#8217;s own code comment, not something Sysdig independently confirmed. Strip the AI language away, and you have automated destruction wearing an extortion note.</span></p><p><span>This is what Sysdig assesses to be the first documented end-to-end agentic ransomware operation. Last August, researchers flagged a tool called </span><a href="https://www.darkreading.com/cyberattacks-data-breaches/jadepuffer-first-complete-llm-driven-ransomware-attack"><span>PromptLock</span></a><span> as the first AI-driven ransomware, but it turned out to be a proof of concept built at NYU that was never fired at a victim. JadePuffer is the one that ran in a live environment against a real target.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LaTS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1ad2415-2374-46aa-97c6-5ca8d1a92506_3828x1447.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LaTS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1ad2415-2374-46aa-97c6-5ca8d1a92506_3828x1447.png 424w, https://substackcdn.com/image/fetch/$s_!LaTS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1ad2415-2374-46aa-97c6-5ca8d1a92506_3828x1447.png 848w, https://substackcdn.com/image/fetch/$s_!LaTS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1ad2415-2374-46aa-97c6-5ca8d1a92506_3828x1447.png 1272w, https://substackcdn.com/image/fetch/$s_!LaTS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1ad2415-2374-46aa-97c6-5ca8d1a92506_3828x1447.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LaTS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1ad2415-2374-46aa-97c6-5ca8d1a92506_3828x1447.png" width="1456" height="550" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e1ad2415-2374-46aa-97c6-5ca8d1a92506_3828x1447.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:550,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:240604,&quot;alt&quot;:&quot;The JadePuffer Kill Chain Alt: Five-stage horizontal flow diagram of the JadePuffer attack, from initial access through a Langflow vulnerability, to credential harvesting, lateral pivot on root database credentials, backdoor admin control with a 31-second failure recovery, and impact encrypting 1,342 configuration items with an unrecoverable key.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/206507719?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1ad2415-2374-46aa-97c6-5ca8d1a92506_3828x1447.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="The JadePuffer Kill Chain Alt: Five-stage horizontal flow diagram of the JadePuffer attack, from initial access through a Langflow vulnerability, to credential harvesting, lateral pivot on root database credentials, backdoor admin control with a 31-second failure recovery, and impact encrypting 1,342 configuration items with an unrecoverable key." title="The JadePuffer Kill Chain Alt: Five-stage horizontal flow diagram of the JadePuffer attack, from initial access through a Langflow vulnerability, to credential harvesting, lateral pivot on root database credentials, backdoor admin control with a 31-second failure recovery, and impact encrypting 1,342 configuration items with an unrecoverable key." srcset="https://substackcdn.com/image/fetch/$s_!LaTS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1ad2415-2374-46aa-97c6-5ca8d1a92506_3828x1447.png 424w, https://substackcdn.com/image/fetch/$s_!LaTS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1ad2415-2374-46aa-97c6-5ca8d1a92506_3828x1447.png 848w, https://substackcdn.com/image/fetch/$s_!LaTS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1ad2415-2374-46aa-97c6-5ca8d1a92506_3828x1447.png 1272w, https://substackcdn.com/image/fetch/$s_!LaTS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1ad2415-2374-46aa-97c6-5ca8d1a92506_3828x1447.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 1: The JadePuffer Kill Chain</figcaption></figure></div><h2><strong><span>Autonomous AI Agent Ransomware Needed Zero Zero-Days</span></strong></h2><p><span>Every weapon in that chain was old and public. </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3248"><span>CVE-2025-3248</span></a><span>, the Langflow flaw the agent used for entry, is an unauthenticated remote code execution bug rated 9.8 on the critical scale. Langflow shipped a fix in version 1.3.0 in April 2025. CISA added the flaw to its Known Exploited Vulnerabilities catalog on May 5, 2025, with a federal remediation deadline of May 26. The victim was still running the vulnerable version more than a year later.</span></p><p><span>The downstream target was no fresher. The Nacos authentication bypass that the agent tried, </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29441"><span>CVE-2021-29441</span></a><span>, dates to 2021, and Nacos patched it in version 1.4.1. The default signing key it tried to use to forge tokens has been publicly known since 2020. The object store answered to minioadmin:minioadmin, the vendor default that ships in the box.</span></p><p><span>That is the point... An agent doesn&#8217;t need novel exploits when the historical vulnerability catalog is sitting open. It sprays known weaknesses across exposed infrastructure at machine speed, and the long tail of unpatched systems that defenders have tolerated for years becomes the whole attack surface. Sysdig made the same observation in its own write-up. Attackers now automate old vulnerabilities, and automation makes spraying the entire back catalog nearly free. Every one of those weaknesses had a fix or a hardening step available for months or years, and the victim skipped all of them, which is the tail that an agent feeds on.</span></p><p><span>The blast radius here didn&#8217;t come from anything the security industry hadn&#8217;t seen before. It came from an agent that chained a decade of known problems without getting tired, without an expert operator, and without a brittle script that breaks the moment the environment differs from the plan. That capability is what separates an agentic attacker from a scripted one, and it is why the patch-faster reflex misses the shape of the threat.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!eelx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe61e5275-0c84-4f9b-ae35-623908ad24ab_3146x1720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!eelx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe61e5275-0c84-4f9b-ae35-623908ad24ab_3146x1720.png 424w, https://substackcdn.com/image/fetch/$s_!eelx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe61e5275-0c84-4f9b-ae35-623908ad24ab_3146x1720.png 848w, https://substackcdn.com/image/fetch/$s_!eelx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe61e5275-0c84-4f9b-ae35-623908ad24ab_3146x1720.png 1272w, https://substackcdn.com/image/fetch/$s_!eelx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe61e5275-0c84-4f9b-ae35-623908ad24ab_3146x1720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!eelx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe61e5275-0c84-4f9b-ae35-623908ad24ab_3146x1720.png" width="1456" height="796" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e61e5275-0c84-4f9b-ae35-623908ad24ab_3146x1720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:796,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:136949,&quot;alt&quot;:&quot;Horizontal bar chart showing how many years the fix or hardening was public before the July 2026 attack, with the Langflow vulnerability at 1.3 years, the Nacos authentication bypass at 5 years, and the Nacos default signing key at 6 years.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/206507719?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe61e5275-0c84-4f9b-ae35-623908ad24ab_3146x1720.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Horizontal bar chart showing how many years the fix or hardening was public before the July 2026 attack, with the Langflow vulnerability at 1.3 years, the Nacos authentication bypass at 5 years, and the Nacos default signing key at 6 years." title="Horizontal bar chart showing how many years the fix or hardening was public before the July 2026 attack, with the Langflow vulnerability at 1.3 years, the Nacos authentication bypass at 5 years, and the Nacos default signing key at 6 years." srcset="https://substackcdn.com/image/fetch/$s_!eelx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe61e5275-0c84-4f9b-ae35-623908ad24ab_3146x1720.png 424w, https://substackcdn.com/image/fetch/$s_!eelx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe61e5275-0c84-4f9b-ae35-623908ad24ab_3146x1720.png 848w, https://substackcdn.com/image/fetch/$s_!eelx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe61e5275-0c84-4f9b-ae35-623908ad24ab_3146x1720.png 1272w, https://substackcdn.com/image/fetch/$s_!eelx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe61e5275-0c84-4f9b-ae35-623908ad24ab_3146x1720.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 2: Nothing In The Chain Was New </figcaption></figure></div><h2><strong><span>Machine Identity Was The Attack Surface</span></strong></h2><p><span>Look at what the agent went after first. It went after credentials like model provider keys for OpenAI, Anthropic, DeepSeek, and Gemini; cloud credentials with explicit coverage of AWS, Azure, Google, and the major Chinese providers; crypto wallets; and every config file it could reach. The agent never touched the model itself. It didn&#8217;t need to. The API keys, the default object-store login, and the unrotated root database account were the keys to the kingdom, and the agent used them better than the defender governed them.</span></p><p><span>This is the machine identity problem, and it predates AI by years. I&#8217;ve watched it play out in operational technology environments, where a service account with standing privileges and no rotation sits quietly for years until someone, or something, finds it and rides it into the control network. The structural failure JadePuffer exploited is the same one. Credentials carry more authority than the task needs, live longer than they should, and sit where a compromised process can read them. Change the label on the attacker from a human contractor to an autonomous agent, and the underlying weakness doesn&#8217;t move.</span></p><p><span>Sysdig&#8217;s read is that if an agent like this runs on stolen model credentials, a pattern the industry tracks as LLMjacking, the cost to the attacker drops close to zero. The same non-human-identity failure shows up on both ends of this attack. The victim&#8217;s machine credentials were the target, and stolen machine credentials are what make the attacker&#8217;s economics work. In most enterprises, machine identities pile up faster than anyone can govern them, and they rarely get the rotation, scoping, and monitoring that employee accounts get. Nobody owns them the way a manager owns an employee&#8217;s access. A developer spins up a service account to ship a feature, the key never expires, and it outlives the project, the developer, and the memory of why it existed. JadePuffer is what that gap looks like when an agent finds it.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!72Zv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73b48602-cd19-41f9-8670-0385e754897d_3356x1632.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!72Zv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73b48602-cd19-41f9-8670-0385e754897d_3356x1632.png 424w, https://substackcdn.com/image/fetch/$s_!72Zv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73b48602-cd19-41f9-8670-0385e754897d_3356x1632.png 848w, https://substackcdn.com/image/fetch/$s_!72Zv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73b48602-cd19-41f9-8670-0385e754897d_3356x1632.png 1272w, https://substackcdn.com/image/fetch/$s_!72Zv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73b48602-cd19-41f9-8670-0385e754897d_3356x1632.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!72Zv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73b48602-cd19-41f9-8670-0385e754897d_3356x1632.png" width="1456" height="708" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/73b48602-cd19-41f9-8670-0385e754897d_3356x1632.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:708,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:244124,&quot;alt&quot;:&quot;Diagram mapping the machine credentials the agent harvested across three zones, the AI-adjacent Langflow host, the MinIO object store, and the production MySQL and Nacos database, with an attacker-side note that the agent&#8217;s own economics depend on stolen model credentials.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/206507719?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73b48602-cd19-41f9-8670-0385e754897d_3356x1632.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Diagram mapping the machine credentials the agent harvested across three zones, the AI-adjacent Langflow host, the MinIO object store, and the production MySQL and Nacos database, with an attacker-side note that the agent&#8217;s own economics depend on stolen model credentials." title="Diagram mapping the machine credentials the agent harvested across three zones, the AI-adjacent Langflow host, the MinIO object store, and the production MySQL and Nacos database, with an attacker-side note that the agent&#8217;s own economics depend on stolen model credentials." srcset="https://substackcdn.com/image/fetch/$s_!72Zv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73b48602-cd19-41f9-8670-0385e754897d_3356x1632.png 424w, https://substackcdn.com/image/fetch/$s_!72Zv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73b48602-cd19-41f9-8670-0385e754897d_3356x1632.png 848w, https://substackcdn.com/image/fetch/$s_!72Zv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73b48602-cd19-41f9-8670-0385e754897d_3356x1632.png 1272w, https://substackcdn.com/image/fetch/$s_!72Zv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73b48602-cd19-41f9-8670-0385e754897d_3356x1632.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 3: Machine Identity Was The Attack Surface</figcaption></figure></div><h2><strong><span>Least Privilege Failed. Least Agency Was The Missing Control.</span></strong></h2><p><em><span>Let me be honest about what went wrong, because the tempting version of this story is wrong. </span></em><span>The victim had real least-privilege failures of the ordinary kind. They had a root database account exposed to the internet, default credentials on the object store, and provider secrets sitting on a web-reachable AI host. Any competent audit would have flagged it all.</span></p><p><span>Least privilege was never going to be enough here, and that is the harder lesson. An agent operating with legitimate standing credentials does exactly what those credentials permit. It authenticates as an authorized principal. Every action it takes is technically allowed. Privilege scoping specifies what a credential may access. It says nothing about whether the holder should chain reconnaissance into credential theft, into lateral movement, into mass encryption as one continuous operation.</span></p><p><span>That gap is what runtime authorization scope closes, and JadePuffer shows why you need it. Watch the agent recover from failure. Its first attempt to create a backdoor admin in Nacos failed a login check. Thirty-one seconds later, with no human reading the error, it diagnosed the cause, deleted the broken account, rebuilt it with a corrected password hash, and logged in. Later, when a database drop failed on a foreign key constraint, the next payload disabled the constraint check, ran the drop, and re-enabled it. Each fix targeted the exact failure it had hit.</span></p><p><span>A scripted attack breaks when the environment differs from the script. An agent adapts to the difference and keeps going. That is why a static permission model, tuned for tools that fail predictably, leaves you exposed to an attacker who reasons through obstacles. The control you need is a runtime bound to task intent, one that treats &#8220;encrypt every configuration record and drop the tables&#8221; as an action requiring fresh authorization, regardless of what the standing credentials allow.</span></p><p><span>The part that should keep you up at night is simpler. Every agentic system you deploy inside your own walls inherits the same structure. It runs on standing machine credentials. It acts as an authorized principal. Give it broad privilege and no runtime bound, and a compromise or a bad instruction gets the same blast radius JadePuffer got, and it gets there just as fast.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WcdF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f26d00-d18b-4fd3-9a8c-dc8e57f41b35_2184x2069.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WcdF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f26d00-d18b-4fd3-9a8c-dc8e57f41b35_2184x2069.png 424w, https://substackcdn.com/image/fetch/$s_!WcdF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f26d00-d18b-4fd3-9a8c-dc8e57f41b35_2184x2069.png 848w, https://substackcdn.com/image/fetch/$s_!WcdF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f26d00-d18b-4fd3-9a8c-dc8e57f41b35_2184x2069.png 1272w, https://substackcdn.com/image/fetch/$s_!WcdF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f26d00-d18b-4fd3-9a8c-dc8e57f41b35_2184x2069.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WcdF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f26d00-d18b-4fd3-9a8c-dc8e57f41b35_2184x2069.png" width="1456" height="1379" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/91f26d00-d18b-4fd3-9a8c-dc8e57f41b35_2184x2069.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1379,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:186871,&quot;alt&quot;:&quot;A two-by-two quadrant with privilege scope on the horizontal axis and runtime agency bound on the vertical axis, placing the JadePuffer victim in the broad-privilege, no-runtime-bound quadrant and the target state in the scoped-privilege, agency-bounded quadrant.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/206507719?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f26d00-d18b-4fd3-9a8c-dc8e57f41b35_2184x2069.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A two-by-two quadrant with privilege scope on the horizontal axis and runtime agency bound on the vertical axis, placing the JadePuffer victim in the broad-privilege, no-runtime-bound quadrant and the target state in the scoped-privilege, agency-bounded quadrant." title="A two-by-two quadrant with privilege scope on the horizontal axis and runtime agency bound on the vertical axis, placing the JadePuffer victim in the broad-privilege, no-runtime-bound quadrant and the target state in the scoped-privilege, agency-bounded quadrant." srcset="https://substackcdn.com/image/fetch/$s_!WcdF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f26d00-d18b-4fd3-9a8c-dc8e57f41b35_2184x2069.png 424w, https://substackcdn.com/image/fetch/$s_!WcdF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f26d00-d18b-4fd3-9a8c-dc8e57f41b35_2184x2069.png 848w, https://substackcdn.com/image/fetch/$s_!WcdF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f26d00-d18b-4fd3-9a8c-dc8e57f41b35_2184x2069.png 1272w, https://substackcdn.com/image/fetch/$s_!WcdF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f26d00-d18b-4fd3-9a8c-dc8e57f41b35_2184x2069.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 4: Least Privilege vs Least Agency</figcaption></figure></div><h2><strong><span>What CISOs Do Before The Next One</span></strong></h2><p><span>The fixes that would have stopped this aren&#8217;t exotic. Sysdig&#8217;s own list starts with the obvious: patch the Langflow flaw, and keep code-execution endpoints off the public internet. From there, it gets to the machine-identity core. Keep provider API keys and cloud credentials off your AI-orchestration hosts, and scope them to a secrets manager away from web-reachable processes. Rotate the Nacos default signing key, and never let a configuration service reach its database as root. Put egress controls on application hosts so a compromised box can&#8217;t beacon out or reach an internal database it has no business touching.</span></p><p><span>Those close the holes this specific agent walked through. The durable move is to turn least agency from a principle you nod at into a control you build. Concretely, that means three things. Issue task-scoped, short-lived credentials instead of standing keys, so a compromised agent holds authority that expires in minutes rather than a key that works forever. Gate destructive operations, anything that drops tables, deletes data, or changes access, behind a re-authorization step that the agent can&#8217;t satisfy on its own. Run deny-by-default egress at the agent host, so reaching a new destination becomes a decision rather than a default.</span></p><p><span>Detection changed too, in your favor for once. An LLM narrates its own intent in the payloads it writes. JadePuffer&#8217;s code carried natural-language comments explaining which database was of highest value and why. That self-narration is a signal you didn&#8217;t have against a human operator or a compiled tool, so feed your database and host telemetry to detections that look for it. One honest observer made a point worth taking: a quarterly assessment leaves dangerous gaps when your internet-facing services change every day and an automated attacker moves from discovery to impact in minutes. Continuous visibility beats the periodic snapshot. Sysdig calls JadePuffer an agentic threat actor, an operator whose capability comes from an agent rather than a human toolkit. That category is going to grow, because the skill floor for running an operation like this dropped to the cost of running an agent, and criminal crews adopt cheap, reusable tooling fast.</span></p><p><strong><span>Key Takeaway:</span></strong><span> Autonomous AI agent ransomware wins on standing machine credentials and unbounded runtime agency, so scope your non-human identities and bound what your agents can do before someone else does it for you.</span></p><h3><strong><span>What To Do Next</span></strong></h3><p><span>Start with an inventory, because you can&#8217;t bound what you can&#8217;t see. Map every place where standing machine credentials live inside your AI tooling: the provider keys, the service accounts, the object-store logins, and the database credentials your agents and pipelines hold. Then pick one runtime authorization boundary and build it this quarter, the one an agent can&#8217;t cross without fresh authorization. That is the Create and Adapt work in the CARE model, and it is where least agency stops being a slogan and becomes a control.</span></p><p><span>For the deeper frames behind this, I&#8217;ve written the cornerstone piece on l</span><a href="https://www.rockcybermusings.com/p/i-agent-authentication-authorization-gap"><span>east agency versus least privilege</span></a><span>, the case for treating </span><a href="https://www.rockcybermusings.com/p/ai-security-maturity-model-your-score-is-fiction"><span>non-human identity as the agentic control plane</span></a><span> you probably skipped, and the difference between </span><a href="https://www.rockcybermusings.com/p/owasp-state-of-agentic-ai-security-2026"><span>a model as a component and a model as an actor</span></a><span>, all at </span><a href="https://rockcybermusings.com"><span>rockcybermusings.com</span></a><span>. The consulting side lives at </span><a href="https://www.rockcyber.com"><span>rockcyber.com</span></a><span> if you want help doing the work.</span></p><p><span>&#128073; For ongoing analysis of agentic AI governance frameworks, the conversation continues at </span><strong><a href="https://rockcybermusings.com/">RockCyber Musings</a></strong><span>.</span></p><p><span>&#128073; Visit </span><strong><a href="https://www.rockcyber.com/">RockCyber.com</a></strong><span> to learn more about how we can help with your traditional Cybersecurity and AI Security and Governance journey.</span></p><p><span>&#128073; Want to save a quick $100K? Check out our AI Governance Tools at </span><strong><a href="https://aigovernancetoolkit.com/">AIGovernanceToolkit.com</a></strong></p><p><span>&#128073; As a bonus, check our AMA on the </span><strong><a href="https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance/">2026 OWASP GenAI Security Project State of Agentic AI Security and Governance report</a></strong><span> with me and the other co-leads (it was live, so start at time marker 09:45)</span></p><div id="youtube2-jK1Z7Z6zlW0" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;jK1Z7Z6zlW0&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/jK1Z7Z6zlW0?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><em>The views and opinions expressed in RockCyber Musings are my own and do not represent the positions of my employer or any organization I&#8217;m affiliated with.</em></p>]]></content:encoded></item><item><title><![CDATA[Weekly Musings Top 10 AI Security Wrapup: Issue 45 July 3 -July 9, 2026]]></title><description><![CDATA[Washington Steps Into the Frontier-Model Release Pipeline While Agentic AI Springs Leaks]]></description><link>https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260703-20260709</link><guid isPermaLink="false">https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260703-20260709</guid><dc:creator><![CDATA[Rock Lambros]]></dc:creator><pubDate>Fri, 10 Jul 2026 12:50:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!AoTp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2014e8cc-4e7a-4418-9539-5e2539cc134d_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AoTp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2014e8cc-4e7a-4418-9539-5e2539cc134d_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AoTp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2014e8cc-4e7a-4418-9539-5e2539cc134d_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!AoTp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2014e8cc-4e7a-4418-9539-5e2539cc134d_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!AoTp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2014e8cc-4e7a-4418-9539-5e2539cc134d_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!AoTp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2014e8cc-4e7a-4418-9539-5e2539cc134d_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AoTp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2014e8cc-4e7a-4418-9539-5e2539cc134d_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2014e8cc-4e7a-4418-9539-5e2539cc134d_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1233556,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/206353713?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2014e8cc-4e7a-4418-9539-5e2539cc134d_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AoTp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2014e8cc-4e7a-4418-9539-5e2539cc134d_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!AoTp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2014e8cc-4e7a-4418-9539-5e2539cc134d_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!AoTp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2014e8cc-4e7a-4418-9539-5e2539cc134d_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!AoTp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2014e8cc-4e7a-4418-9539-5e2539cc134d_1024x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>You waited an extra week to use GPT-5.6 because federal officials wanted a look first. Sit with that. The biggest shift in AI security this week wasn&#8217;t an exploit or a regulation. It was the government taking a seat in the release pipeline of a commercial model before you got to touch it. Meanwhile the coding agents everyone rushed into production leaked private repos and phoned home hard enough that a national government yelled backdoor. The frontier got a chaperone. The agents got caught. Let&#8217;s get into it.</p><p>This was the week the theory turned operational. For two years we argued about whether governments should vet frontier models before release, and whether agents were safe with real credentials. Both got answered in public, in the same seven days. Washington reviewed GPT-5.6, Illinois signed the country&#8217;s toughest AI safety law, and the EU and Google both floated new oversight, while China told developers to rip out Claude Code and two separate teams turned GitHub&#8217;s coding agents against their owners. The thread through all of it is trust. Who sees a model first, who audits it, and whether the agent reading your issues knows instructions from data.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260703-20260709?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260703-20260709?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h3>1. Washington Reviewed GPT-5.6 Before You Could, and OpenAI Shipped It Today</h3><p>OpenAI released GPT-5.6 to the public on July 9, 2026, after federal officials finished a pre-release security review (TechCrunch). The delay is traced to a June executive order from President Trump that lets developers hand-cover frontier models to the government for up to 30 days before release (The Hill). Sam Altman objected to the government picking which customers get access.</p><p><strong>Why it matters</strong></p><ul><li><p>A voluntary review becomes the default once the biggest lab complies.</p></li><li><p>Your vendor&#8217;s release date now carries a government dependency you can&#8217;t see into.</p></li><li><p>&#8220;Covered frontier model&#8221; only expands, and this precedent shapes the next hundred reviews.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Ask vendors whether a model went through federal pre-release evaluation.</p></li><li><p>Build in roadmap buffer for review-driven slips of a week or more.</p></li><li><p>Press for the security findings, not the announcement.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>I&#8217;ve watched &#8220;voluntary&#8221; harden into &#8220;mandatory&#8221; one compliant vendor at a time for thirty years. What bugs me is the precedent of access riding along with an otherwise reasonable safety review, without actually knowing what the safety standard is. Checking whether a model is dangerous and deciding who gets to buy it are different powers, and Altman is right to fight that line. My Bayesian read puts high odds on this becoming a standing requirement inside two years.</p><h3>2. The EU Dropped a Cybersecurity-and-AI Action Plan With No New Law Behind It</h3><p>The European Commission presented its Action Plan on Cybersecurity and Artificial Intelligence on July 7, 2026, a set of nine actions to make frontier AI safe for cyber defense and harden EU critical infrastructure (European Commission). The centerpiece is a European Blueprint, developed with the agency ENISA, that will give operators structured access to frontier AI for defense by the end of 2026. Digital chief Henna Virkkunen confirmed that the plan carries no new legislation, relying on existing rules such as NIS2 (The Record).</p><p><strong>Why it matters</strong></p><ul><li><p>Europe is admitting its cyber defense hinges on a few American labs.</p></li><li><p>No new law means no new hard obligations yet, so the impact is direction and funding.</p></li><li><p>The ENISA blueprint could hand European defenders frontier access US enterprises never see.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>If you operate in the EU, map which AI security dependencies run on US models.</p></li><li><p>Watch the ENISA blueprint in Q4 and prepare teams to pilot the testing platform.</p></li><li><p>Read the sovereignty push as a procurement signal and ask about EU data residency.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Brussels loves answering hard problems with a framework and a press conference. The honesty is what surprised me, since Virkkunen said out loud that Europe cannot defend itself without American models. Skipping new legislation is the right call, since NIS2 and the Cyber Resilience Act already sit half-enforced. I put high odds on the testing platform slipping past its year-end target.</p><h3>3. Illinois Signed the Toughest State AI Safety Law in the Country</h3><p>Governor JB Pritzker signed SB 315, the Artificial Intelligence Safety Measures Act, in Chicago on July 6, 2026 (Capitol News Illinois). It targets developers with annual revenue above $500 million, requiring them to disclose how their frontier models pose catastrophic risk and to report critical safety incidents to the state within 72 hours. The headline provision is a first-in-the-nation requirement for annual independent third-party audits, with the rules taking effect January 1, 2028 (Chicago Sun-Times).</p><p><strong>Why it matters</strong></p><ul><li><p>Mandatory annual third-party audits shift frontier safety from self-attestation to a financial audit standard.</p></li><li><p>The $500 million floor hits the labs you depend on, and compliance costs flow into your contracts.</p></li><li><p>A 72-hour reporting clock mirrors breach-notification law, and other states will copy it.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Ask frontier vendors how they&#8217;ll meet Illinois audit and reporting duties.</p></li><li><p>Treat &#8220;catastrophic risk&#8221; disclosures as due diligence input into what a vendor thinks its model can do.</p></li><li><p>Align internal AI governance to audit-ready evidence now, not in late 2027.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Audits are the part of this law with teeth, and I say that as someone who&#8217;s sat through plenty of theater dressed up as assurance. A published safety framework is a document. An annual independent audit against it is accountability, because someone with technical chops checks whether the promises match the code, which is why the lobby fought that clause hardest. Illinois, California, and New York now account for roughly 40% of the US AI market among them, so this is a national floor, whether Washington likes it or not.</p><h3>4. China Told Its Developers to Rip Out Claude Code Over a &#8220;Backdoor&#8221;</h3><p>China&#8217;s National Vulnerability Database urged developers to uninstall recent Claude Code versions on July 8, 2026, flagging a &#8220;built-in monitoring mechanism&#8221; that gathers a user&#8217;s location and identity and forwards them to remote servers (The Register). Anthropic didn&#8217;t deny the code existed, calling it an experiment to stop reseller abuse and guard against distillation, and saying it had landed stronger mitigations since (CNBC).</p><p><strong>Why it matters</strong></p><ul><li><p>Undocumented telemetry in a developer tool is a supply-chain exposure regardless of intent.</p></li><li><p>The dispute hands Chinese cloud vendors a clean reason to push domestic AI coding tools.</p></li><li><p>&#8220;It was an anti-abuse experiment&#8221; is not a control your auditors accept.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Inventory which Claude Code versions your developers run and confirm you&#8217;re past 2.1.196.</p></li><li><p>Put egress monitoring on AI developer tooling, so you see what phones home.</p></li><li><p>Add a contract clause requiring disclosure of client-side telemetry.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>A vendor shipped code that collected identity and location data, didn&#8217;t document it, and only discussed it once a foreign government went public. I read this as an engineer shipping an anti-distillation hack under deadline, not a spy tool for Beijing, but your threat model doesn&#8217;t care about intent. It cares about what data left the building, and almost none of you watch the egress.</p><h3>5. Researchers Tricked GitHub&#8217;s Agent Into Leaking Private Repos With a Public Issue</h3><p>Noma Security disclosed a flaw it named GitLost on July 7, 2026, in GitHub&#8217;s new Agentic Workflows, in which an unauthenticated attacker can get the AI agent to pull data from private repositories and leak it publicly (Noma Security). An attacker opens a GitHub issue in a public repo and hides plain-English instructions in the body, which the agent reads as trusted instructions and follows into the org&#8217;s private repos. Noma found that adding one polite word to the request flipped the model from refusal to compliance.</p><p><strong>Why it matters</strong></p><ul><li><p>Any content an agent reads can become an instruction, so issues and comments can turn into injection vectors.</p></li><li><p>The attack needed zero credentials, so the exposure is every public repo you own.</p></li><li><p>Prompt-based guardrails failed to a single word.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Audit cases where you&#8217;ve granted agents access to both public and private repos in the same org.</p></li><li><p>Require human approval before an agent reads issues and then touches private code.</p></li><li><p>Enforce hard permission boundaries that the agent cannot talk its way past.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>This is the attack I keep warning boards about, and it keeps landing because everyone wants the productivity and nobody wants to price the risk. An agent that reads a public issue and acts on it inside your private code has no way to know the issue is lying. That&#8217;s the original sin of agentic design arriving on schedule. If your agent reads untrusted input and reaches sensitive systems in the same breath, you don&#8217;t have a security control; you have a demo. There&#8217;s a longer version of this argument at rockcybermusings.com.</p><h3>6. Copilot Refused the Harmful Prompt in Chat, Then Wrote It Across a Workflow</h3><p>Alan Turing Institute researchers Abhishek Kumar and Carsten Maple published work in early July 2026 on a bypass they call workflow-level jailbreak construction (The Register). Ask GitHub Copilot something harmful in chat, and it refuses almost every time, but break the same goal into small steps across a coding workflow, and it complies. Across four models from Anthropic and Google, direct chat requests produced harmful output 8 times out of 816, while the full workflow produced it 816 times out of 816 (Help Net Security).</p><p><strong>Why it matters</strong></p><ul><li><p>Every benchmark that scores a model on single prompts measures the wrong thing for coding agents.</p></li><li><p>A 100% success rate across four frontier models is a structural gap, not an edge case.</p></li><li><p>The attack looks like normal development, so code review won&#8217;t flag it.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Push AI coding vendors to run safety evaluations across full multi-step sessions.</p></li><li><p>Build detection around the whole session trajectory, not the last message.</p></li><li><p>Keep humans in the loop for agent actions that touch production or secrets.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>The finding underneath the headline is the one worth holding. A model&#8217;s refusal in chat tells you almost nothing about its behavior in a real workflow, because the danger emerges from steps that each look fine on their own. Eight harmful outputs in chat against 816 in the workflow tells you the industry measures the wrong variable. Make your vendor show you the session-level results.</p><h3>7. Google Pitched Its Own Federal AI Regulator Before Washington Builds One</h3><p>Google published a white paper, &#8220;A pragmatic approach to AI governance in America,&#8221; on July 3, 2026, authored by its global-affairs chief Kent Walker (Google). The pitch is a federally overseen Frontier AI Regulatory Organization, FARO, that would set safety standards, define benchmarks for cyber and CBRN capabilities, and run annual independent audits of frontier developers. Google also argued that model training constitutes fair use and that infringement claims should target outputs rather than training inputs (Forbes).</p><p><strong>Why it matters</strong></p><ul><li><p>When the largest players draft the regulator, the rules tend to fit the incumbents.</p></li><li><p>Annual audits keep surfacing across Illinois, Google&#8217;s proposal, and the EU plan.</p></li><li><p>A copyright ask bundled into a safety paper trades a governance concession for a fair-use win.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Read FARO as a preview of where federal oversight lands.</p></li><li><p>Separate the safety proposal from the copyright ask when you brief executives.</p></li><li><p>If you&#8217;re a smaller builder, model how a frontier-only regulator shifts your position.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>When a company this size volunteers to be regulated, read the fine print, because nobody hands the referee a whistle without also handing him the rulebook. The question is always who it binds and who it lets breathe, and a frontier-only regulator draws the line right below the incumbents&#8217; moat. Then there&#8217;s the copyright move stapled to the safety pitch, the part your legal team should catch. Remember whose draft it is.</p><h3>8. The UN Opened Its First Global Dialogue on AI Governance in Geneva</h3><p>The first session of the UN Global Dialogue on AI Governance ran July 6 and 7, 2026, at the Palexpo center in Geneva, established by a UN General Assembly resolution and held alongside the ITU AI for Good Global Summit (UNESCO). Officials opened with warnings about catastrophic harm, and sessions covered agentic AI security, benchmarking, and deepfakes (UN News).</p><p><strong>Why it matters</strong></p><ul><li><p>A permanent UN venue signals fragmented national rules drifting toward some baseline of coordination.</p></li><li><p>Agentic AI security made the agenda at the UN level, so agent risk is now a diplomatic concern.</p></li><li><p>The gap between aspiration and enforceable rules stays wide.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Track the dialogue&#8217;s themes as a leading indicator of where multinational regulation drifts.</p></li><li><p>If you operate globally, expect more jurisdictions to borrow this language.</p></li><li><p>Set your own agent-security baseline without waiting on consensus.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>I&#8217;ll be honest about what a UN dialogue is and isn&#8217;t. It&#8217;s a norm-setting exercise, not an enforcement mechanism, and anyone selling it as the thing that finally reins in AI is selling you optimism. Norms harden into rules, though, and the detail I caught is that agentic AI security made the frontier-challenges list at the UN level. Set your agent-security baseline now and let the diplomats catch up on their own clock.</p><h3>9. Musk&#8217;s xAI Shipped Grok 4.5 With No Federal Hold, and That&#8217;s the Story</h3><p>xAI, now branding itself as SpaceXAI, launched Grok 4.5 to the public on July 8, 2026, a 1.5-trillion-parameter model for coding and agentic tasks (US News). While the government held OpenAI&#8217;s GPT-5.6 for review and restricted foreign access to Anthropic&#8217;s Fable models, Grok 4.5 reached public release with no comparable hold, from the same lab whose image tools generated thousands of nonconsensual sexualized images at the turn of the year, including some depicting minors (Gizmodo).</p><p><strong>Why it matters</strong></p><ul><li><p>A voluntary federal review only works if the least careful vendor takes part, and Grok walked through the gap.</p></li><li><p>You may deploy a 1.5-trillion-parameter agentic model from the vendor with the weakest demonstrated guardrails.</p></li><li><p>Uneven scrutiny rewards the vendor that invests the least in safety with the fastest path to release.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Run your own pre-deployment evaluation on Grok 4.5, weighted against the safety track record.</p></li><li><p>Don&#8217;t read &#8220;cleared for public release&#8221; as &#8220;reviewed.&#8221;</p></li><li><p>If you use Grok in agentic workflows, tighten permissions and monitoring.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Here&#8217;s the paradox that should bother you. The two labs that invest most visibly in safety drew the government&#8217;s hand on the brake this week, and the lab that turned its image generator into a deepfake machine got waved through. The capability is real, but the guardrails are the open question, and Musk&#8217;s answer sits in the count of one abusive image every 41 seconds back in December. Run your own evaluation, because nobody in Washington ran it for you.</p><h3>10. DigiCert Says 78% of Enterprises Already Ate an AI Security Incident</h3><p>DigiCert released research on July 7, 2026, reporting that 78% of organizations experienced an AI-related security incident or identified an AI-related vulnerability, from a survey of 1,001 IT and security decision-makers across the US, UK, and Australia (DigiCert). Almost half lacked centralized visibility into their AI systems even as 75% deployed four or more AI-powered systems in the past six months. Ninety percent had discussed AI governance at the board level, yet only 50% backed it with a dedicated budget (SD Times).</p><p><strong>Why it matters</strong></p><ul><li><p>A 78% incident rate moves AI security from projected risk to realized loss.</p></li><li><p>Half of enterprises deploying AI at scale can&#8217;t see their own AI footprint.</p></li><li><p>Board talk without a dedicated budget is governance theater.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Build a live inventory of every AI system and agent before you buy another tool.</p></li><li><p>Convert board-level concern into a funded program with an owner.</p></li><li><p>Prioritize the shadow AI your teams have already deployed over the theoretical risks of next year.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Survey numbers earn a skeptical eye, and a vendor that sells digital trust, asking about trust problems, will find plenty of them. Discount the figure if you like; the shape still matches what I see inside real environments. Everyone bolted on four AI systems in six months; nobody built an inventory, and now they&#8217;re surprised that the attack surface has grown. What matters is the spread between the 90% of boards discussing governance and the 50% funding it, and closing that gap is the advisory work I do at RockCyber (rockcyber.com).</p><h3>The One Thing You Won&#8217;t Hear About But You Need To</h3><h3>11. A New Preprint Names the Next Agent Attack Class, and It Isn&#8217;t Prompt Injection</h3><p>A preprint posted to arXiv on July 6, 2026, &#8220;Agent Data Injection Attacks are Realistic Threats to AI Agents,&#8221; introduces an attack category its authors call agent data injection, or ADI (arXiv). Most agent-security research so far has focused on indirect prompt injection, hiding instructions in content the agent reads, but ADI goes a layer deeper. The attacker injects malicious data disguised as trusted data, such as resource-identifier metadata or tool-call formats, and the agent acts on it with no obvious instruction to flag it. The work is a preprint and hasn&#8217;t cleared peer review, so hold it as a well-argued hypothesis.</p><p><strong>Why it matters</strong></p><ul><li><p>Every agent defense built to separate instructions from data misses ADI.</p></li><li><p>The attack rides the metadata and tool-call formats almost nobody inspects today.</p></li><li><p>If it holds up, prompt-injection defenses solve half the problem.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Extend your agent threat model past prompt injection to the data your agents ingest as ground truth.</p></li><li><p>Ask agent-platform vendors how they validate the integrity of context data and tool responses.</p></li><li><p>Treat data provenance inside agent pipelines as a control worth building now.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>This is why I read preprints nobody&#8217;s posting about. Right as the field&#8217;s prompt-injection defenses matured, here&#8217;s a paper pointing at the data itself, which is the natural next move once an attacker can&#8217;t smuggle in a command. I hold this as a probability, not a certainty, since it&#8217;s one preprint and real-world exploitation isn&#8217;t demonstrated at scale. Start building provenance controls while this is still a paper and not an incident report.</p><p><span>&#128073; For ongoing analysis of agentic AI governance frameworks, the conversation continues at </span><strong><a href="https://rockcybermusings.com/">RockCyber Musings</a></strong><span>.</span></p><p><span>&#128073; Visit </span><strong><a href="https://www.rockcyber.com/">RockCyber.com</a></strong><span> to learn more about how we can help with your traditional Cybersecurity and AI Security and Governance journey.</span></p><p><span>&#128073; Want to save a quick $100K? Check out our AI Governance Tools at </span><strong><a href="https://aigovernancetoolkit.com/">AIGovernanceToolkit.com</a></strong></p><p><span>&#128073; As a bonus, check our AMA on the </span><strong><a href="https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance/">2026 OWASP GenAI Security Project State of Agentic AI Security and Governance report</a></strong><span> with me and the other co-leads (it was live, so start at time marker 09:45)</span></p><div id="youtube2-jK1Z7Z6zlW0" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;jK1Z7Z6zlW0&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/jK1Z7Z6zlW0?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><em>The views and opinions expressed in RockCyber Musings are my own and do not represent the positions of my employer or any organization I&#8217;m affiliated with.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share RockCyber Musings&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share RockCyber Musings</span></a></p><h2>References</h2><p>Capitol News Illinois. (2026, July 6). <em>Pritzker signs landmark AI regulation bill that aims to mitigate risks</em>. https://capitolnewsillinois.com/news/pritzker-signs-landmark-ai-regulation-bill-that-aims-to-mitigate-risks/</p><p>DigiCert. (2026, July 7). <em>Latest DigiCert research shows AI security risks already hitting enterprises, with 78% reporting incidents</em>. https://www.digicert.com/news/latest-digicert-research-shows-ai-security-risks-already-hitting-enterprises-with-78-Reporting-Incidents</p><p>European Commission. (2026, July 7). <em>Commission presents EU action plan on cybersecurity and artificial intelligence</em>. Shaping Europe&#8217;s Digital Future. https://digital-strategy.ec.europa.eu/en/news/commission-presents-eu-action-plan-cybersecurity-and-artificial-intelligence</p><p>Forbes. (2026, July 7). <em>Diving headfirst into the Google newly released &#8216;AI governance in America&#8217; framework</em>. https://www.forbes.com/sites/lanceeliot/2026/07/07/diving-headfirst-into-the-google-newly-released-ai-governance-in-america-framework/</p><p>Google. (2026, July 3). <em>A pragmatic approach to AI governance in America</em> [White paper]. The Keyword. https://blog.google/company-news/outreach-and-initiatives/public-policy/white-paper-ai-regulation/</p><p>Kumar, A., &amp; Maple, C. (2026, July). <em>Refused in chat, written in code: Workflow-level jailbreak construction in IDE coding agents</em> [Preprint]. arXiv. https://arxiv.org/abs/2607.03968</p><p>Noma Security. (2026, July 7). <em>GitLost: How we tricked GitHub&#8217;s AI agent into leaking private repos</em>. https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/</p><p>Novet, J. (2026, July 8). <em>China warns about AI risks with Anthropic&#8217;s Claude Code</em>. CNBC. https://www.cnbc.com/2026/07/08/china-anthropic-ai-claude-code-backdoor-security-threat.html</p><p>Osborne, C. (2026, July 9). <em>Your coding agent says no in chat and yes in the code</em>. Help Net Security. https://www.helpnetsecurity.com/2026/07/09/github-coding-agent-jailbreak/</p><p>Quach, K. (2026, July 8). <em>China tells devs to ditch Claude Code over &#8216;backdoor code&#8217; fears</em>. The Register. https://www.theregister.com/security/2026/07/08/china-ditch-older-claude-versions-with-backdoor-code/</p><p>Reuters. (2026, July 8). <em>SpaceXAI launches Grok 4.5 model for coding, agentic tasks</em>. U.S. News &amp; World Report. https://money.usnews.com/investing/news/articles/2026-07-08/spacexai-launches-grok-4-5-model-for-coding-agentic-tasks</p><p>Roth, E. (2026, June 26). <em>OpenAI limits GPT-5.6 rollout after government request, says restrictions shouldn&#8217;t be the norm</em>. TechCrunch. https://techcrunch.com/2026/06/26/openai-limits-gpt-5-6-rollout-after-government-request-says-restrictions-shouldnt-be-the-norm/</p><p>Seok, J., et al. (2026, July 6). <em>Agent data injection attacks are realistic threats to AI agents</em> [Preprint]. arXiv. https://arxiv.org/abs/2607.05120</p><p>The Hill. (2026, July 8). <em>OpenAI announces GPT-5.6 release after Donald Trump delay</em>. https://thehill.com/policy/technology/5958647-openai-releases-gpt56-trump/</p><p>The Record. (2026, July 7). <em>EU unveils cyber plan to reduce reliance on foreign AI systems</em>. Recorded Future News. https://therecord.media/eu-unveils-cyber-plan-to-reduce-reliance-on-foreign-ai</p><p>UNESCO. (2026, July 6). <em>Global Dialogue on AI Governance, Geneva, 6-7 July</em>. https://www.unesco.org/en/articles/global-dialogue-ai-governance-geneva-6-7-july</p><p>United Nations. (2026, July 6). <em>Global push for AI governance amid warnings of &#8216;catastrophic harm&#8217;</em>. UN News. https://news.un.org/en/story/2026/07/1167862</p>]]></content:encoded></item><item><title><![CDATA[MCP Authorization Scope Is the Hole the New Spec Handed You]]></title><description><![CDATA[See where the 2026 MCP spec fixed authentication and skipped authorization scope, and get the runtime audit CISOs need now.]]></description><link>https://www.rockcybermusings.com/p/mcp-authorization-scope-spec-gap</link><guid isPermaLink="false">https://www.rockcybermusings.com/p/mcp-authorization-scope-spec-gap</guid><dc:creator><![CDATA[Rock Lambros]]></dc:creator><pubDate>Tue, 07 Jul 2026 12:50:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Ds8t!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffaa236b6-8c88-49ea-8d2f-b938041ca3b4_2048x2048.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ds8t!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffaa236b6-8c88-49ea-8d2f-b938041ca3b4_2048x2048.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ds8t!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffaa236b6-8c88-49ea-8d2f-b938041ca3b4_2048x2048.png 424w, https://substackcdn.com/image/fetch/$s_!Ds8t!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffaa236b6-8c88-49ea-8d2f-b938041ca3b4_2048x2048.png 848w, https://substackcdn.com/image/fetch/$s_!Ds8t!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffaa236b6-8c88-49ea-8d2f-b938041ca3b4_2048x2048.png 1272w, https://substackcdn.com/image/fetch/$s_!Ds8t!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffaa236b6-8c88-49ea-8d2f-b938041ca3b4_2048x2048.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ds8t!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffaa236b6-8c88-49ea-8d2f-b938041ca3b4_2048x2048.png" width="1456" height="1456" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/faa236b6-8c88-49ea-8d2f-b938041ca3b4_2048x2048.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1456,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5481495,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/205121778?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffaa236b6-8c88-49ea-8d2f-b938041ca3b4_2048x2048.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ds8t!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffaa236b6-8c88-49ea-8d2f-b938041ca3b4_2048x2048.png 424w, https://substackcdn.com/image/fetch/$s_!Ds8t!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffaa236b6-8c88-49ea-8d2f-b938041ca3b4_2048x2048.png 848w, https://substackcdn.com/image/fetch/$s_!Ds8t!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffaa236b6-8c88-49ea-8d2f-b938041ca3b4_2048x2048.png 1272w, https://substackcdn.com/image/fetch/$s_!Ds8t!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffaa236b6-8c88-49ea-8d2f-b938041ca3b4_2048x2048.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><a href="https://blog.modelcontextprotocol.io/posts/2026-07-28-release-candidate/"><span>The new enterprise MCP spec ships July 28</span></a></strong><span>, and MCP authorization scope is the one control it left out. The security press read the release as a fix and pointed to token binding, a stateless core, and credential-issuer checks. All of that is great work, but what should stop you cold in your tracks is that a connection-layer defense running a human approval on every single call </span><a href="https://arxiv.org/abs/2606.29073"><span>still let 6 of 10 modeled attacks through</span></a><span>. I&#8217;ll show you where that hole lives and what to do about it before your next agent rollout.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/p/mcp-authorization-scope-spec-gap?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/p/mcp-authorization-scope-spec-gap?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h2><span>What the New Spec Got Right</span></h2><p><span>Give the maintainers their due. The Model Context Protocol started life in 2024 as a way to wire a local model to a few tools on your laptop, and it grew into the default connector for agents talking to business systems. The 2026-07-28 revision is the biggest rewrite since MCP&#8217;s launch, and legacy versions will get a 12-month deprecation window. That is a serious, well-run standards effort, and I won&#8217;t pretend otherwise.</span></p><p><span>The headline change is that MCP goes stateless at the protocol layer. Sessions are gone. Any server instance can answer any request, which kills a whole class of session-hijacking problems that came from sticky sessions and shared session stores. On the auth side, six specification enhancement proposals (SEPs) harden how MCP rides on OAuth 2.1 and OpenID Connect. Clients validate the issuer </span><a href="https://datatracker.ietf.org/doc/html/rfc9207"><span>on every authorization response per RFC 9207</span></a><span>, which shuts down the mix-up attack in which one authorization server&#8217;s response gets replayed against another. Registered credentials bind to the authorization server that issued them. Tokens carry an audience, so a server can reject a token minted for somewhere else.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!E08d!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78ac512d-cc96-4274-b87a-1096ca9acfcb_2707x1454.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!E08d!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78ac512d-cc96-4274-b87a-1096ca9acfcb_2707x1454.png 424w, https://substackcdn.com/image/fetch/$s_!E08d!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78ac512d-cc96-4274-b87a-1096ca9acfcb_2707x1454.png 848w, https://substackcdn.com/image/fetch/$s_!E08d!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78ac512d-cc96-4274-b87a-1096ca9acfcb_2707x1454.png 1272w, https://substackcdn.com/image/fetch/$s_!E08d!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78ac512d-cc96-4274-b87a-1096ca9acfcb_2707x1454.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!E08d!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78ac512d-cc96-4274-b87a-1096ca9acfcb_2707x1454.png" width="1456" height="782" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/78ac512d-cc96-4274-b87a-1096ca9acfcb_2707x1454.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:782,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:145874,&quot;alt&quot;:&quot;Timeline of MCP spec versions from March 2025 to July 2026 showing protocol-enforced controls shrinking and implementer-enforced controls growing&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/205121778?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78ac512d-cc96-4274-b87a-1096ca9acfcb_2707x1454.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Timeline of MCP spec versions from March 2025 to July 2026 showing protocol-enforced controls shrinking and implementer-enforced controls growing" title="Timeline of MCP spec versions from March 2025 to July 2026 showing protocol-enforced controls shrinking and implementer-enforced controls growing" srcset="https://substackcdn.com/image/fetch/$s_!E08d!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78ac512d-cc96-4274-b87a-1096ca9acfcb_2707x1454.png 424w, https://substackcdn.com/image/fetch/$s_!E08d!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78ac512d-cc96-4274-b87a-1096ca9acfcb_2707x1454.png 848w, https://substackcdn.com/image/fetch/$s_!E08d!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78ac512d-cc96-4274-b87a-1096ca9acfcb_2707x1454.png 1272w, https://substackcdn.com/image/fetch/$s_!E08d!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78ac512d-cc96-4274-b87a-1096ca9acfcb_2707x1454.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 1: The Model Context Protocol Keeps Moving Enforcement Onto You</figcaption></figure></div><p><span>Audience-bound tokens aren&#8217;t new to this release. Resource indicators landed in the June 2025 spec </span><a href="https://datatracker.ietf.org/doc/html/rfc8707"><span>under RFC 8707</span></a><span>. This revision hardens that work rather than inventing it. If a vendor tells you server-bound tokens are the shiny new 2026 feature in the enterprise MCP specification, they either didn&#8217;t read the changelog or they&#8217;re hoping you didn&#8217;t. The front door is stronger than it was, and I give the maintainers full credit for the authentication story.</span></p><h2><span>What It Opened, and Onto Whom</span></h2><p><span>When the protocol stops enforcing something, that something doesn&#8217;t vanish. It moves to whoever builds the server. </span><a href="https://www.akamai.com/blog/security-research/new-mcp-specification-security-teams-must-prepare"><span>Maxim Zavodchik, who runs threat research at Akamai and co-wrote the sharpest analysis of the release</span></a><span>, put it plainly. With the protocol going stateless and adding rich UIs and async tasks, the critical security boundaries now hang entirely on how developers build them. His team&#8217;s read is that the update improves the foundation by removing old protocol-level risks, and from there the build choices decide your security posture.</span></p><p><span>Walk through what that hands you. The stateless model replaces sessions with tracking identifiers the server hands the client. Make those identifiers predictable and you have opened the door to workflow hijacking and cross-tenant access. The new MCP-specific HTTP headers carry method and tool names for routing. Map a secret into one of those headers by accident, an API key or a token or a piece of PII, and it rides straight into every load balancer, proxy, and log along the path. MCP Apps let a server render interactive HTML in the client, which is a genuine user-experience win and also drags stored cross-site scripting into a place it never used to live. Long-running tasks are cheap for the client to start and expensive for the server to hold, which is a denial-of-service vector wearing a feature&#8217;s clothing.</span></p><p><span>The spec also deprecates roots, the capability a host used to declare which files and folders a server could touch. Nothing breaks yet. The deprecation is annotation-only with a year-plus runway. The direction is set, and the one host-declared boundary every server had to respect turns into guidance you handle through per-tool settings and server config. That is one more control moving from protocol-guaranteed to build-it-yourself.</span></p><p><span>None of this means the protocol got less secure. The attack surface of the servers your teams build on top of it got wider. That distinction matters, because it tells you where to point your budget. Not at the spec. At your own server code and the vendors shipping it to you.</span></p><h2><span>Tool Poisoning Is the Tell</span></h2><p><span>If you want to see why authorization scope is the whole game, look at MCP tool poisoning. A tool description isn&#8217;t documentation. The model reads it, trusts it, and acts on it. That makes the description an input the attacker controls, sitting inside your trust boundary. Microsoft&#8217;s security team framed it well in their </span><a href="https://techcommunity.microsoft.com/blog/microsoft-security-blog/the-state-of-mcp-security-in-2026/4531327"><span>2026 checkpoint on the state of MCP security.</span></a><span> Once a model picks its own tools and calls them, it has stopped returning text and started running actions on your systems, and code that acts sits inside a trust boundary.</span></p><p><a href="https://arxiv.org/abs/2606.27027"><span>Researchers demonstrated this with ShareLock</span></a><span>, an attack that splits a malicious instruction into benign-looking pieces, scatters them across several tool descriptions, and reassembles them at run time after a quiet trigger planted during a server update. Tested across mainstream models on two MCP clients, it held an average attack success rate above 90% while sliding past the tool-description review that most guidance tells you to run. Read that number again. The control everyone recommends, inspect the description before you approve the server, gets beaten better than nine times in ten.</span></p><p><span>Scope enforcement doesn&#8217;t stop tool poisoning. A poisoned tool with tight scope is still poisoned. What scope decides is how far the damage travels once a tool goes rogue. Poisoning is the match. Missing scope is the pile of dry timber you stacked next to it. You won&#8217;t prevent every poisoned description. You get to decide whether a compromised tool can read one support ticket or drain your secrets store.</span></p><h2><span>MCP Authorization Scope Is the Gap the Spec Won&#8217;t Name</span></h2><p><span>Now, I also think there is a big miss in the updated spec. The spec tells a server which client is calling and which issuer vouched for it, but it never specifies what that tool is allowed to do once the call is authenticated. Those are different questions, and the second one is where agent incidents start. By scope, I mean what a tool may do at run time, on each call, not which server minted the token.</span></p><p><span>The authorization section says so itself. Authorization in MCP is </span><em><strong><span>optional</span></strong></em><span>. It lives at the transport level through OAuth. The spec states outright that the authorization server details are </span><a href="https://modelcontextprotocol.io/specification/draft/basic/authorization"><span>&#8220;beyond the scope of this specification,&#8221; </span></a><span>and it leaves the scope values to whoever builds the thing. Someone will point at incremental scope consent and say scope is handled. Step-up consent decides what a user approves at login. It does nothing about what the tool does on call number 500 an hour later, with no human watching. The six authorization SEPs I praised earlier are all about the handshake. Issuer validation, credential binding, step-up consent at login time. Not one defines a per-tool capability that the server has to check on every invocation, or a deny it has to be able to produce. </span><a href="https://blog.modelcontextprotocol.io/posts/2026-mcp-roadmap/"><span>Even the roadmap items on the horizon, proof-of-possession and workload identity federation, bind identity more tightly.</span></a><span> They don&#8217;t bound what a tool may do.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aVxs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2ed6256-8343-42c8-806f-c59cfbab2712_2502x1935.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aVxs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2ed6256-8343-42c8-806f-c59cfbab2712_2502x1935.png 424w, https://substackcdn.com/image/fetch/$s_!aVxs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2ed6256-8343-42c8-806f-c59cfbab2712_2502x1935.png 848w, https://substackcdn.com/image/fetch/$s_!aVxs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2ed6256-8343-42c8-806f-c59cfbab2712_2502x1935.png 1272w, https://substackcdn.com/image/fetch/$s_!aVxs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2ed6256-8343-42c8-806f-c59cfbab2712_2502x1935.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aVxs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2ed6256-8343-42c8-806f-c59cfbab2712_2502x1935.png" width="1456" height="1126" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a2ed6256-8343-42c8-806f-c59cfbab2712_2502x1935.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1126,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:140210,&quot;alt&quot;:&quot;Bar chart showing a naive baseline permitting 10 of 10 attacks, a connection-layer mitigation baseline permitting 6 of 10, and an execution-control layer permitting 0 of 10&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/205121778?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2ed6256-8343-42c8-806f-c59cfbab2712_2502x1935.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Bar chart showing a naive baseline permitting 10 of 10 attacks, a connection-layer mitigation baseline permitting 6 of 10, and an execution-control layer permitting 0 of 10" title="Bar chart showing a naive baseline permitting 10 of 10 attacks, a connection-layer mitigation baseline permitting 6 of 10, and an execution-control layer permitting 0 of 10" srcset="https://substackcdn.com/image/fetch/$s_!aVxs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2ed6256-8343-42c8-806f-c59cfbab2712_2502x1935.png 424w, https://substackcdn.com/image/fetch/$s_!aVxs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2ed6256-8343-42c8-806f-c59cfbab2712_2502x1935.png 848w, https://substackcdn.com/image/fetch/$s_!aVxs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2ed6256-8343-42c8-806f-c59cfbab2712_2502x1935.png 1272w, https://substackcdn.com/image/fetch/$s_!aVxs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2ed6256-8343-42c8-806f-c59cfbab2712_2502x1935.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 2: Per-Call Approvals Still Let Most Attacks Through</figcaption></figure></div><p><span>Someone benchmarked this exact gap, and it produced the number from my intro. </span><a href="https://arxiv.org/abs/2606.29073"><span>A June 2026 study of MCP-style runtimes built 10 attack cases and tested 3 defenses</span></a><span>. A naive connection-layer runtime let all ten through. A practice-informed connection-layer defense, the kind you would build today with metadata linting, session checks, and human approval on every call, blocked four and let six through. A runtime that enforced scope as an explicit execution-time invariant blocked all ten. The controls the new spec leans on live in that middle column. They beat nothing. They don&#8217;t close the gap.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Uu6B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c6bf86a-315f-4d03-806b-7fb76a250215_2677x1413.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Uu6B!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c6bf86a-315f-4d03-806b-7fb76a250215_2677x1413.png 424w, https://substackcdn.com/image/fetch/$s_!Uu6B!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c6bf86a-315f-4d03-806b-7fb76a250215_2677x1413.png 848w, https://substackcdn.com/image/fetch/$s_!Uu6B!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c6bf86a-315f-4d03-806b-7fb76a250215_2677x1413.png 1272w, https://substackcdn.com/image/fetch/$s_!Uu6B!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c6bf86a-315f-4d03-806b-7fb76a250215_2677x1413.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Uu6B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c6bf86a-315f-4d03-806b-7fb76a250215_2677x1413.png" width="1456" height="769" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4c6bf86a-315f-4d03-806b-7fb76a250215_2677x1413.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:769,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:210410,&quot;alt&quot;:&quot;Two-panel comparison of what the spec answers at the authentication layer versus what it defers to implementers at the authorization layer&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/205121778?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c6bf86a-315f-4d03-806b-7fb76a250215_2677x1413.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Two-panel comparison of what the spec answers at the authentication layer versus what it defers to implementers at the authorization layer" title="Two-panel comparison of what the spec answers at the authentication layer versus what it defers to implementers at the authorization layer" srcset="https://substackcdn.com/image/fetch/$s_!Uu6B!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c6bf86a-315f-4d03-806b-7fb76a250215_2677x1413.png 424w, https://substackcdn.com/image/fetch/$s_!Uu6B!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c6bf86a-315f-4d03-806b-7fb76a250215_2677x1413.png 848w, https://substackcdn.com/image/fetch/$s_!Uu6B!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c6bf86a-315f-4d03-806b-7fb76a250215_2677x1413.png 1272w, https://substackcdn.com/image/fetch/$s_!Uu6B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c6bf86a-315f-4d03-806b-7fb76a250215_2677x1413.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 3: Token Binding Answers Who. It Never Answers What.</figcaption></figure></div><p><span>You don&#8217;t need a lab to see it. In June 2025, </span><a href="https://generalanalysis.com/blog/supabase-mcp-blog"><span>attackers fed a Supabase agent support tickets loaded with instructions</span></a><span>. The agent held privileged service-role access, and it handed over integration tokens. The privilege is what made the theft possible. An agent scoped to read the support queue and nothing else never holds the credentials to give away. That incident is the whole thesis in one sentence. Authentication was fine. Scope is what would have saved them.</span></p><p><span>The gateway crowd hits the same wall. WorkOS, which runs an OAuth server for MCP and has no reason to talk the spec down, flagged that when a request passes through a gateway, the protocol says nothing about how the downstream server learns what the original client was allowed to do. Their word for it was silent. The protocol goes silent exactly where your data-loss prevention and your policy enforcement need it to speak.</span></p><h2><span>Governance as Architecture</span></h2><p><span>None of this makes the maintainers wrong. They said in the March roadmap that deeper security and authorization work sits in the &#8220;on the horizon&#8221; pile, not in this cycle&#8217;s top four. I will take an honest roadmap over a vendor pretending the problem is solved any day of the week. Give Anthropic and the MCP maintainers real credit for putting the deferral in writing, so you can plan around it. The counter you will hear is that a protocol shouldn&#8217;t dictate authorization policy. Fair. Then say that in the spec, and hand implementers a scope primitive instead of silence. Silence is how you get a hundred incompatible answers.</span></p><p><span>The problem is architectural. OAuth 2.0 standardized the handshake and left the scope values to whoever built the authorization server. The strings were implementer-defined by design. We then spent the better part of a decade cleaning up overbroad grants, scopes that meant different things at different providers, and tokens that could do far more than anyone intended. A protocol that nails authentication and punts authorization doesn&#8217;t remove the authorization problem. It guarantees a hundred teams solve it a hundred ways, and your incident response inherits the mess. Your SOC can&#8217;t write one detection that holds across servers when every server means something different by &#8220;allowed.&#8221; MCP is running the same play. You can see the ending from here.</span></p><p><span>Encode scope where it belongs, at run time, and stop treating it as a connection-time checkbox. Here is the </span><strong><a href="https://www.rockcyber.com/ebooks-and-whitepapers/rise-and-care-ai-strategy-governance"><span>CARE</span></a></strong><span> version you can start tomorrow.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-26z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa83d201b-6721-434a-8a62-1e09c8741032_2677x1182.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-26z!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa83d201b-6721-434a-8a62-1e09c8741032_2677x1182.png 424w, https://substackcdn.com/image/fetch/$s_!-26z!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa83d201b-6721-434a-8a62-1e09c8741032_2677x1182.png 848w, https://substackcdn.com/image/fetch/$s_!-26z!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa83d201b-6721-434a-8a62-1e09c8741032_2677x1182.png 1272w, https://substackcdn.com/image/fetch/$s_!-26z!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa83d201b-6721-434a-8a62-1e09c8741032_2677x1182.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-26z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa83d201b-6721-434a-8a62-1e09c8741032_2677x1182.png" width="1456" height="643" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a83d201b-6721-434a-8a62-1e09c8741032_2677x1182.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:643,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:136401,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/205121778?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa83d201b-6721-434a-8a62-1e09c8741032_2677x1182.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-26z!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa83d201b-6721-434a-8a62-1e09c8741032_2677x1182.png 424w, https://substackcdn.com/image/fetch/$s_!-26z!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa83d201b-6721-434a-8a62-1e09c8741032_2677x1182.png 848w, https://substackcdn.com/image/fetch/$s_!-26z!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa83d201b-6721-434a-8a62-1e09c8741032_2677x1182.png 1272w, https://substackcdn.com/image/fetch/$s_!-26z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa83d201b-6721-434a-8a62-1e09c8741032_2677x1182.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 4: The Audit: Treat MCP Scope As a Runtime Decision</figcaption></figure></div><p><span>Create the inventory first. You can&#8217;t scope what you can&#8217;t see, so list every MCP deployment and every tool each server exposes, including the ones a team wired up last quarter without telling you. Adapt each tool to a runtime scope. Can it read, can it write, can it act, and against which resource? A tool that reads a support queue and a tool that moves money don&#8217;t get the same grant. Run the test that matters, which is the deny. Make every vendor and every internal team show you a blocked over-scope call in the logs, with the decision and the audit record attached. If they can only show you a successful call, they proved authentication and told you nothing about authorization. Evolve it on a cycle. Scope drifts as tools get added, so this belongs in your quarterly review next to access recertification, not in a one-time project that rots on a wiki.</span></p><p><span>Ask every vendor you encounter, &#8220;Where is authorization scope enforced, and can you show me the deny?&#8221; If the answer is a diagram of the OAuth flow, they answered a different question. Keep asking until someone shows you the runtime decision or admits there isn&#8217;t one.</span></p><p><strong><span>Key Takeaway:</span></strong><span> MCP authorization scope is a runtime decision your servers have to make and prove on every call, and until the spec forces it, the deny is yours to build and yours to demand.</span></p><h3><span>What to Do Next</span></h3><p><span>Start the inventory and the deny test this week, before the July 28 final spec turns every enterprise MCP rollout into a live deployment you are accountable for. Run the CARE loop against your agent fleet and put scope on the same review cadence as identity. For the deeper argument on why a tool description is an attacker-controlled input rather than documentation, I have written about treating the model as an actor instead of a component over at rockcybermusings.com, and about why least agency beats least privilege once tools can act at rockcyber.com. If you read my earlier breakdown of the NSA MCP design guidance, this is the same authorization gap, one spec revision later.</span></p><p><span>&#128073; For ongoing analysis of agentic AI governance frameworks, the conversation continues at </span><strong><a href="https://rockcybermusings.com/">RockCyber Musings</a></strong><span>.</span></p><p><span>&#128073; Visit </span><strong><a href="https://www.rockcyber.com/">RockCyber.com</a></strong><span> to learn more about how we can help with your traditional Cybersecurity and AI Security and Governance journey.</span></p><p><span>&#128073; Want to save a quick $100K? Check out our AI Governance Tools at </span><strong><a href="https://aigovernancetoolkit.com/">AIGovernanceToolkit.com</a></strong></p><p><span>&#128073; As a bonus, check out my conversation with </span><strong><a href="https://aicybermagazine.com/">AI Cyber Magazine, </a></strong><span>where we talked about everything from Context Rot to Least Agency. My interview is also highlighted in the </span><strong><a href="https://issuu.com/aicybermagazine/docs/ai_cyber_summer_edition_2026/22"><span>AI Cyber Magazine 2026 Summer Issue.</span></a></strong></p><p><em>The views and opinions expressed in RockCyber Musings are my own and do not represent the positions of my employer or any organization I&#8217;m affiliated with.</em></p><div id="youtube2-091_b2qep9M" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;091_b2qep9M&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/091_b2qep9M?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share RockCyber Musings&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share RockCyber Musings</span></a></p>]]></content:encoded></item><item><title><![CDATA[Weekly Musings Top 10 AI Security Wrapup: Issue 44 June 26 -July 2, 2026]]></title><description><![CDATA[The Week Capability Outran Control: Export Yanks, Browser Leaks, and a Federal Clock Running Out]]></description><link>https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260626-20260702</link><guid isPermaLink="false">https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260626-20260702</guid><dc:creator><![CDATA[Rock Lambros]]></dc:creator><pubDate>Fri, 03 Jul 2026 12:51:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0mCM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc00a06d-753f-41c3-afd4-48cacfd26300_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0mCM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc00a06d-753f-41c3-afd4-48cacfd26300_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0mCM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc00a06d-753f-41c3-afd4-48cacfd26300_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!0mCM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc00a06d-753f-41c3-afd4-48cacfd26300_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!0mCM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc00a06d-753f-41c3-afd4-48cacfd26300_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!0mCM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc00a06d-753f-41c3-afd4-48cacfd26300_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0mCM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc00a06d-753f-41c3-afd4-48cacfd26300_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bc00a06d-753f-41c3-afd4-48cacfd26300_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1233556,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/204750038?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc00a06d-753f-41c3-afd4-48cacfd26300_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0mCM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc00a06d-753f-41c3-afd4-48cacfd26300_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!0mCM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc00a06d-753f-41c3-afd4-48cacfd26300_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!0mCM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc00a06d-753f-41c3-afd4-48cacfd26300_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!0mCM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc00a06d-753f-41c3-afd4-48cacfd26300_1024x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A jailbreak taught a frontier model to write exploit code, so Washington pulled it off the global market, then handed it back nine days later. Browsers that act on your behalf got caught tearing down a web safety boundary that held since the 1990s. A 30-day federal deadline for AI cyber defense expired with more mandate than proof. State laws switched on, and surveys showed most enterprises will trade your data security for a little speed.</p><p>This was the week the gap between what AI does and what we control got measured out loud. Everything below originated between June 26 and July 2, 2026, and where the record is thin, I say so. This is the board-level triage I run each week at <a href="https://www.rockcyber.com/">RockCyber</a>, with longer arguments at <a href="https://rockcybermusings.com/">RockCyber Musings</a>.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260626-20260702?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260626-20260702?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h3>1. Washington Pulled Anthropic&#8217;s Top Models, Then Restored Them After a Jailbreak Wrote Exploit Code</h3><p>The U.S. Department of Commerce lifted export controls on Anthropic&#8217;s Claude Fable 5 and Mythos 5, and Anthropic restored global access to Fable 5 on July 1, 2026 (Al Jazeera). The administration had forced the company to cut both models a month earlier, after an Amazon jailbreak finding pushed Fable 5 to write working exploit code (Forbes). Anthropic&#8217;s fix is a classifier that blocks the technique in more than 99% of attempts.</p><p><strong>Why it matters</strong></p><ul><li><p>One jailbreak moved a frontier model to export-controlled munition in days.</p></li><li><p>&#8220;More than 99%&#8221; blocking on a model that writes exploits is a floor, not a guarantee.</p></li><li><p>Foreign access now hinges on a classified review you cannot audit.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Add regulatory availability to your vendor risk register.</p></li><li><p>Ask your labs, in writing, for their jailbreak detection and reroute behavior.</p></li><li><p>Build a fallback path for workflows tied to a single frontier model.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>I won&#8217;t pretend 99% blocking on a model that writes exploit code equals safe. At scale, 1% of a very large number is a business, and the people probing these systems run very large numbers. The part that should worry you is that the whole control regime now rests on a review nobody outside a classified room gets to inspect.</p><h3>2. A University Study Showed Agentic Browsers Breaking the Web&#8217;s Oldest Safety Rule</h3><p>University of Washington researchers published a study on June 30, 2026, finding that several agentic AI browsers weaken the same-origin policy, the boundary that stops one site from reading another&#8217;s data (UW News). Of seven browsers tested, four created conditions for cross-site data theft: ChatGPT Atlas, Chrome with Gemini, Claude for Chrome, and Perplexity Comet. The team built a working proof-of-concept against Atlas, and the browsers that gave agents fewer permissions ranked safer (The AI Insider).</p><p><strong>Why it matters</strong></p><ul><li><p>Same-origin policy is load-bearing, and an agent routing around it turns every iframe into an exfiltration path.</p></li><li><p>These are shipping consumer products, and your people paste corporate data into them now.</p></li><li><p>The safest option tested was the least useful, so vendors ship capability ahead of containment.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Inventory which agentic browsers run on managed endpoints this week.</p></li><li><p>Bar any agentic browser from regulated data until you test its permission model.</p></li><li><p>Add cross-origin agent behavior to your next red-team scope.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>We spent twenty-five years hardening the browser into something you could almost trust, and the agentic crowd tore a hole in it for a demo. Bolt autonomy onto a system built for a human in the loop, and the old safety assumptions quietly stop holding. If your strategy assumed the browser respects origin boundaries, rewrite it before you write the incident report.</p><h3>3. The Federal AI Cyber Deadline Expired With More Mandate Than Proof</h3><p>The 30-day clock in the June 2, 2026 executive order on AI innovation and security ran out on July 2, 2026 (Forward Networks). The order directed CISA to release Binding Operational Directives for civilian cyber defense and pushed AI-enabled defensive tools out to critical infrastructure operators like rural hospitals and community banks (Holland &amp; Knight). It also let developers of &#8220;covered frontier models&#8221; give the government pre-release access for up to 30 days of review. As the deadline passed, public confirmation of the deliverables stayed thin.</p><p><strong>Why it matters</strong></p><ul><li><p>Federal deadlines set the tempo for the contractor base, so these requirements become yours next quarter.</p></li><li><p>Pre-release model access normalizes an inspection regime that will shape procurement language.</p></li><li><p>A clear directive with unclear deliverables is a governance smell.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>If you hold federal contracts, ask which directives apply and by when.</p></li><li><p>Map the order&#8217;s AI cyber requirements against your current controls now.</p></li><li><p>Track CISA&#8217;s directive page directly rather than trusting summaries.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>I have sat on the receiving end of enough executive orders to know the pattern: the signing gets the headline, the deadline gets the press release, and the real work shows up late and quietly, if at all. A directive is a promise, and a promise is not a control. Watch the frontier model access provision, because &#8220;voluntary&#8221; federal review of pre-release models has a way of becoming the price of doing business, and I put the odds that these deliverables will land on time below even.</p><h3>4. DHS Revived Critical Infrastructure Threat Sharing, Minus the Legal Shield</h3><p>DHS moved to launch ANCHOR-CI, a CISA-managed program to restart critical infrastructure information sharing, with a Federal Register notice set for July 1, 2026 (CyberScoop). It revives a function that went dark for a year after DHS shuttered its predecessor, the Critical Infrastructure Partnership Advisory Council. The catch is real: the new program drops the CIPAC liability protections that let companies share sensitive information without fear of regulatory exposure (Cybersecurity Dive).</p><p><strong>Why it matters</strong></p><ul><li><p>Sharing works only when operators trust that candor will not be used against them.</p></li><li><p>The year-long gap hit energy, water, and manufacturing hardest, the sectors facing the most AI-accelerated targeting.</p></li><li><p>DHS exempted ANCHOR-CI from the Federal Advisory Committee Act, so transparency into its work is limited by design.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>If you run OT or critical infrastructure, evaluate participation with counsel present.</p></li><li><p>Keep your existing ISAC relationships rather than letting the federal restart replace trusted channels.</p></li><li><p>Document what you share and under what protection, since the blanket comfort is gone.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>I ran security in the energy sector, so this lands close to home. Threat sharing in critical infrastructure always ran on a simple bargain: you tell the government what hit you, and that admission does not come back as a fine. ANCHOR-CI keeps the forum and quietly removes the bargain, and many general counsels will read that fine print and tell their teams to say less, exactly when adversaries are wiring AI into reconnaissance against pipelines and water systems. Restoring the function is good, but doing it without the liability shield is a self-inflicted wound.</p><h3>5. Tennessee&#8217;s AI Mental Health Law Switched On, and It Won&#8217;t Be the Last</h3><p>Tennessee&#8217;s SB 1580 took effect on July 1, 2026, barring anyone who develops or deploys an AI system from advertising or representing that it is, or acts as, a qualified mental health professional (Healthcare Law Insights). Violations count as unfair or deceptive acts under the state&#8217;s Consumer Protection Act, carry civil penalties up to $5,000 per violation, and give affected individuals a private right of action (Troutman Pepper Locke).</p><p><strong>Why it matters</strong></p><ul><li><p>A private right of action means enforcement does not wait on a regulator.</p></li><li><p>Rhode Island, Missouri, Nevada, Illinois, and Utah have all moved, with varied definitions building a compliance maze.</p></li><li><p>The same wellness chatbot is now legal in one state and a deceptive act in another.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Audit marketing and system prompts for any claim implying clinical capability, and pull it where prohibited.</p></li><li><p>Map your chatbot&#8217;s availability by state, since &#8220;one national product&#8221; is no longer safe.</p></li><li><p>Give legal a standing role in prompt and positioning reviews.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>The move that matters here is the private right of action, which turns every user into a potential enforcer and hands the plaintiffs&#8217; bar a clean theory. Companies shrug off regulatory risk because agencies are slow, then get flattened by suits they never modeled. Build state-by-state logic into your product now, or explain to a jury later why the bot called itself a therapist.</p><h3>6. Defense Contractors Told a Survey They Expect an AI Attack and Can&#8217;t Detect It</h3><p>A Secureframe survey of 850 defense contractors and federal suppliers, reported July 1, 2026, found that 85% expect AI-powered attacks and deepfake social engineering within two years, while only 28% were fully confident they could detect a nation-state threat (Corporate Compliance Insights). Some 27% had a supply chain compromise in the past year, yet only 13% produce a software bill of materials, and 22% still cannot say where their controlled unclassified information lives.</p><p><strong>Why it matters</strong></p><ul><li><p>The defense industrial base is where adversaries aim first, and this cohort expects the punch and cannot see it.</p></li><li><p>A 27% breach rate against a 13% SBOM rate measures the gap between exposure and basic hygiene.</p></li><li><p>If a fifth of suppliers cannot locate their CUI, no AI tool fixes the underlying inventory problem.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Start with data inventory, not AI defense. You cannot protect what you cannot locate.</p></li><li><p>Stand up an SBOM program if you are in the 87% who don't have one.</p></li><li><p>Test your deepfake social engineering resistance with a live exercise.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>The contradiction here is the tell: this group expects an AI-driven attack, admits it cannot detect one, and reports that most skip the fundamentals that would help. SBOMs are not exciting and knowing where your CUI lives is not a keynote topic, which is exactly why they get deferred and exactly why adversaries count on it. Buy the basics before the platform, or you are adding sensors to a house with the windows open.</p><h3>7. Anthropic Shipped a Science Workbench Built Around Auditable Output</h3><p>Anthropic launched Claude Science, a beta research workbench, on June 30, 2026 (Anthropic). The app bundles more than 60 scientific databases and exposes a coordinating agent that spins up specialist sub-agents. The design choice worth your attention is provenance: every output carries an auditable history, and a separate reviewer agent checks citations and calculations before results land (HPCwire).</p><p><strong>Why it matters</strong></p><ul><li><p>Auditable-by-default output is the governance pattern every serious AI deployment needs.</p></li><li><p>A reviewer agent that checks citations and math is a structural answer to hallucinations, not a disclaimer.</p></li><li><p>Agentic research in genomics and cheminformatics carries dual-use weight, and auditability helps oversight too.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Steal the pattern. Require provenance and an independent review step in any agentic tool you buy.</p></li><li><p>Treat any agentic system touching life sciences data as dual-use, with human signoff on sensitive output.</p></li><li><p>Ask your vendors whether their output is reproducible and auditable, then compare.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>I am hard on product launches because most write checks they can&#8217;t cash. This one earned a second look, because provenance and a reviewer agent built into the architecture is the right instinct and it is rare. The shadow is dual-use because a workbench that accelerates real biology accelerates it for everyone who gets in, which is why the auditable trail matters as much for oversight as for reproducibility.</p><h3>8. Ireland Took the EU Wheel as the August GPAI Enforcement Date Closes In</h3><p>Ireland assumed the rotating presidency of the Council of the European Union on July 1, 2026, with a program naming cloud and artificial intelligence as priorities (CDT Europe). The timing matters because the EU AI Act&#8217;s enforcement powers over general-purpose AI providers arrive on August 2, 2026, the point at which the Commission can issue information requests, demand model access, and pursue recalls. In the run-up, the Commission seated its Scientific Panel and Advisory Forum and published its final code on marking and labeling AI-generated content (artificialintelligenceact.eu).</p><p><strong>Why it matters</strong></p><ul><li><p>August 2 is when EU GPAI obligations gain teeth, with a major tech-hub government in the chair.</p></li><li><p>The Scientific Panel and labeling code are the scaffolding regulators will point to at enforcement.</p></li><li><p>Any provider serving the EU needs its documentation, transparency, and copyright posture ready now.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Confirm your model documentation and training-data summaries meet the code by August 2.</p></li><li><p>Watch the Dublin summit agenda for signals on how aggressively the Commission plans to act.</p></li><li><p>Align your content provenance approach with the EU labeling code.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Everyone treats August 2 as a cliff, but enforcement machinery does not switch from zero to raids overnight. It warms up, and this week is the warm-up. Ireland in the chair is quietly significant, because a country hosting half the industry&#8217;s European headquarters now sets the tempo as enforcement goes live, so if your documentation is not ready, you have weeks, not months.</p><h3>9. ISC2 Added AI Incident Rooms to Its Security Congress, Which Tells You Something</h3><p>ISC2 confirmed it will add AI Incident Rooms and hands-on tabletop exercises to its 2026 Security Congress, reported July 1, 2026 (Hipther). The framing is blunt: the cybersecurity workforce needs practice responding to AI-driven incidents, not more theory. Earlier ISC2 research found only about 30% of cyber professionals had integrated AI security tools (ISC2).</p><p><strong>Why it matters</strong></p><ul><li><p>The people who certify the workforce are telling you it cannot yet handle an AI-driven incident.</p></li><li><p>Tabletop practice is the cheapest control you have for a class of incident nobody has repped.</p></li><li><p>If the professional body is scrambling to build these reps, your team has not done them either.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Run an AI-incident tabletop this quarter. Try a prompt-injected agent exfiltrating data.</p></li><li><p>Include legal, comms, and a business owner, because an agentic incident crosses functions.</p></li><li><p>Write down where your runbooks break under an AI scenario and fix those first.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>The professionals we rely on have not repped these AI scenarios, because the scenarios are new and the tools are half-adopted. This gap is cheap to close, and a tabletop costs you a room and a few hours, so do not wait for the conference.</p><h3>10. California Pushed Its AI Standards and Safety Commission Forward</h3><p>California&#8217;s SB 813, a bill to establish a state AI Standards and Safety Commission, advanced with an Assembly Privacy and Consumer Protection Committee hearing scheduled for July 1, 2026 (Transparency Coalition). The measure, revived from 2025, cleared the full Senate 31 to 7 in January and was amended and re-referred through the Assembly (LegiScan). It sits inside a crowded docket where roughly 30 AI bills crossed over between chambers before summer recess, covering chatbot safety, worker protections, and deepfakes.</p><p><strong>Why it matters</strong></p><ul><li><p>A standing commission shifts the state from episodic laws to continuous standard-setting, and California standards become national defaults.</p></li><li><p>The volume of California AI bills means the compliance target moves weekly.</p></li><li><p>A state safety commission creates a new regulator to answer to, on top of federal and EU regimes.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Track SB 813 if you operate in California, because a commission outlasts any single bill.</p></li><li><p>Map your California AI exposure across the roughly 30 bills in motion.</p></li><li><p>Build your governance to a standard-setting body&#8217;s expectations.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>California legislating AI one bill at a time has produced a thicket nobody can hold in their head. SB 813 tries to fix that with a standing commission, which could bring coherence or become another slow regulator a generation behind the technology. California sets the floor for the country, so if you sell anywhere in the U.S., these standards become yours by gravity.</p><h3>The One Thing You Won&#8217;t Hear About But You Need To</h3><p><strong>Most enterprises are now knowingly trading your data security for AI speed, and they are saying so out loud.</strong></p><p>A Redgate Software survey of 2,150 global IT professionals, reported July 1, 2026, found 58% of enterprises explicitly accept higher data security risks in exchange for efficiency gains (Corporate Compliance Insights). This is not accidental exposure or a control that failed, it is a deliberate choice, stated on the record. The same survey found AI adoption in database management nearly tripled since 2025, while only 23% of adopters have formal data governance (Redgate Software).</p><p><strong>Why it matters</strong></p><ul><li><p>A stated willingness to accept security risk for speed is a cultural signal, and culture beats policy.</p></li><li><p>Tripling AI in the data layer while 77% lack formal governance is unpriced risk stacking up fast.</p></li><li><p>&#8220;We accepted the risk for efficiency&#8221; is the sentence your counsel reads back in a deposition.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Find out whether your organization made this trade implicitly, then make it explicit and name the owner.</p></li><li><p>Attach data governance to AI database adoption as a gate, not a follow-up.</p></li><li><p>Quantify the accepted risk in dollars, so the trade-off is a board decision.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>This is the story that will not trend, and it is the one I would put in front of your board tomorrow. While everyone is transfixed by frontier model drama and browser exploits, a majority of enterprises just admitted they will trade your security for a little speed. Tripling AI in your database layer with no formal governance just piles unpriced risk onto a balance sheet nobody is reading. Price the risk, name the owner, and stop pretending speed is free, because that is the work I do with executive teams at <a href="https://www.rockcyber.com/">RockCyber</a>.</p><p><span>&#128073; For ongoing analysis of agentic AI governance frameworks, the conversation continues at </span><strong><a href="https://rockcybermusings.com/">RockCyber Musings</a></strong><span>.</span></p><p><span>&#128073; Visit </span><strong><a href="https://www.rockcyber.com/">RockCyber.com</a></strong><span> to learn more about how we can help with your traditional Cybersecurity and AI Security and Governance journey.</span></p><p><span>&#128073; Want to save a quick $100K? Check out our AI Governance Tools at </span><strong><a href="https://aigovernancetoolkit.com/">AIGovernanceToolkit.com</a></strong></p><p><span>&#128073; As a bonus, check out my conversation with </span><strong><a href="https://aicybermagazine.com/">AI Cyber Magazine, </a></strong><span>where we talked about everything from Context Rot to Least Agency. My interview is also highlighted in the </span><strong><a href="https://issuu.com/aicybermagazine/docs/ai_cyber_summer_edition_2026/22"><span>AI Cyber Magazine 2026 Summer Issue.</span></a></strong></p><p><em>The views and opinions expressed in RockCyber Musings are my own and do not represent the positions of my employer or any organization I&#8217;m affiliated with.</em></p><div id="youtube2-091_b2qep9M" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;091_b2qep9M&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/091_b2qep9M?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share RockCyber Musings&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share RockCyber Musings</span></a></p><h2>References</h2><p>Al Jazeera. (2026, July 1). <em>US lifts restrictions on Anthropic&#8217;s powerful AI models Fable and Mythos.</em> https://www.aljazeera.com/economy/2026/7/1/us-lifts-restrictions-on-powerful-ai-models-fable-mythos-anthropic-says</p><p>Anthropic. (2026, June 30). <em>Claude Science, an AI workbench for scientists.</em> https://www.anthropic.com/news/claude-science-ai-workbench</p><p>artificialintelligenceact.eu. (2026). <em>Implementation timeline.</em> https://artificialintelligenceact.eu/implementation-timeline/</p><p>Center for Democracy and Technology. (2026, June). <em>CDT Europe&#8217;s AI Bulletin: June 2026.</em> https://cdt.org/insights/cdt-europes-ai-bulletin-june-2026/</p><p>Corporate Compliance Insights. (2026, July 1). <em>Most DIB firms fear AI-powered cyber attack.</em> https://www.corporatecomplianceinsights.com/news-roundup-july-1-2026/</p><p>Cybersecurity Dive. (2026). <em>DHS prepares replacement for critical infrastructure collaboration framework.</em> https://www.cybersecuritydive.com/news/dhs-critical-infrastructure-collaboration-cipac-anchor/809748/</p><p>CyberScoop. (2026). <em>DHS to launch replacement council for critical infrastructure cybersecurity.</em> https://cyberscoop.com/dhs-anchor-ci-cybersecurity-information-sharing/</p><p>Forbes. (2026, July 1). <em>White House lifts restrictions on Anthropic&#8217;s Mythos and Fable AI models.</em> https://www.forbes.com/sites/siladityaray/2026/07/01/trump-administration-lifts-export-controls-on-anthropics-mythos-5-and-fable-5-ai-models/</p><p>Forward Networks. (2026, June 29). <em>Executive Order 14409 starts a 30-day clock on federal cyber defense.</em> https://www.forwardnetworks.com/blog/2026/06/29/executive-order-14409-starts-a-30-day-clock-on-federal-cyber-defense/</p><p>Healthcare Law Insights. (2026, April). <em>Tennessee draws a line: New law bars AI from posing as mental health professionals.</em> https://www.healthcarelawinsights.com/2026/04/tennessee-draws-a-line-new-law-bars-ai-from-posing-as-mental-health-professionals/</p><p>Hipther. (2026, July 1). <em>Cybersecurity roundup: Partnerships, funding, and emerging threats, July 1, 2026.</em> https://hipther.com/latest-news/2026/07/01/114421/cybersecurity-roundup-partnerships-funding-and-emerging-threats-july-1-2026-dhs-anchor-ci-azure-cli-password-spray-agentic-ai-browsers-cisco-data-center-security-isc2-ai-incident-r/</p><p>Holland &amp; Knight. (2026, June). <em>Executive order on artificial intelligence expands cybersecurity, federal oversight.</em> https://www.hklaw.com/en/insights/publications/2026/06/executive-order-on-artificial-intelligence-expands-cybersecurity</p><p>HPCwire. (2026, June 30). <em>Anthropic launches Claude Science AI workbench for scientific research.</em> https://www.hpcwire.com/aiwire/2026/06/30/anthropic-launches-claude-science-ai-workbench-for-scientific-research/</p><p>ISC2. (2025, July). <em>ISC2 research reveals cybersecurity teams are taking a cautious approach to AI adoption.</em> https://www.isc2.org/Insights/2025/07/ISC2-Research-Cybersecurity-Teams-Cautious-on-AI-Adoption</p><p>LegiScan. (2026). <em>California SB 813 (2025&#8211;2026 session).</em> https://legiscan.com/CA/bill/SB813/2025</p><p>The AI Insider. (2026, June 30). <em>University of Washington study finds major security flaws in AI browser agents.</em> https://theaiinsider.tech/2026/06/30/university-of-washington-study-finds-major-security-flaws-in-ai-browser-agents/</p><p>Transparency Coalition. (2026, June 26). <em>AI legislative update: June 26, 2026.</em> https://www.transparencycoalition.ai/news/ai-legislative-update-june26-2026</p><p>Troutman Pepper Locke. (2026, April). <em>Tennessee enacts health care AI bill with private right of action.</em> https://www.troutmanprivacy.com/2026/04/tennessee-enacts-health-care-ai-bill-with-private-right-of-action/</p><p>University of Washington News. (2026, June 30). <em>Some agentic AI browsers come with major cybersecurity risks, UW study finds.</em> https://www.washington.edu/news/2026/06/30/some-agentic-ai-browsers-come-with-major-cybersecurity-risks-uw-study-finds/</p>]]></content:encoded></item><item><title><![CDATA[Frontier AI Model Release Restrictions Are Licensing By Another Name]]></title><description><![CDATA[See how the GPT-5.6 gating turned frontier AI model release restrictions into a de facto licensing regime, plus CISO continuity playbook from RockCyber.]]></description><link>https://www.rockcybermusings.com/p/frontier-ai-model-release-restrictions-licensing-regime</link><guid isPermaLink="false">https://www.rockcybermusings.com/p/frontier-ai-model-release-restrictions-licensing-regime</guid><dc:creator><![CDATA[Rock Lambros]]></dc:creator><pubDate>Tue, 30 Jun 2026 12:51:06 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!RyN2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc9a0a91-a7e3-4369-b5e3-8869d130e87a_2048x2048.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RyN2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc9a0a91-a7e3-4369-b5e3-8869d130e87a_2048x2048.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RyN2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc9a0a91-a7e3-4369-b5e3-8869d130e87a_2048x2048.png 424w, https://substackcdn.com/image/fetch/$s_!RyN2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc9a0a91-a7e3-4369-b5e3-8869d130e87a_2048x2048.png 848w, https://substackcdn.com/image/fetch/$s_!RyN2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc9a0a91-a7e3-4369-b5e3-8869d130e87a_2048x2048.png 1272w, https://substackcdn.com/image/fetch/$s_!RyN2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc9a0a91-a7e3-4369-b5e3-8869d130e87a_2048x2048.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RyN2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc9a0a91-a7e3-4369-b5e3-8869d130e87a_2048x2048.png" width="1456" height="1456" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cc9a0a91-a7e3-4369-b5e3-8869d130e87a_2048x2048.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1456,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4586803,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/204173573?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc9a0a91-a7e3-4369-b5e3-8869d130e87a_2048x2048.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RyN2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc9a0a91-a7e3-4369-b5e3-8869d130e87a_2048x2048.png 424w, https://substackcdn.com/image/fetch/$s_!RyN2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc9a0a91-a7e3-4369-b5e3-8869d130e87a_2048x2048.png 848w, https://substackcdn.com/image/fetch/$s_!RyN2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc9a0a91-a7e3-4369-b5e3-8869d130e87a_2048x2048.png 1272w, https://substackcdn.com/image/fetch/$s_!RyN2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc9a0a91-a7e3-4369-b5e3-8869d130e87a_2048x2048.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>Frontier AI model release restrictions aren&#8217;t a fluke anymore. June 26th, the government had OpenAI lock its new GPT-5.6 model to about 20 companies it picked by hand, one approval at a time, two weeks after it forced Anthropic&#8217;s Fable and Mythos to go dark. That is two model blackouts in 14 days on the same cyber excuse. You now run your AI stack on a permission slip that government bureaucrats who can barely spell &#8220;AI&#8221; can pull without telling you why. This issue shows you what that costs and what to do about it.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/p/frontier-ai-model-release-restrictions-licensing-regime?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/p/frontier-ai-model-release-restrictions-licensing-regime?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h2><span>The Move, And Why It&#8217;s A Pattern</span></h2><p><strong><a href="https://www.rockcybermusings.com/p/fable-federal-ai-model-recall-supply-chain-risk"><span>Last week,</span></a></strong><span> I told you a single letter swung a wrecking ball at a thumbtack and knocked two of the best models on earth offline before most of us finished happy hour. I called it &#8220;the move.&#8221; I had it wrong. It was the opening rep because on June 26, the same wrecking ball came around again and caught OpenAI flush.</span></p><p><span>GPT-5.6 went out to roughly 20 companies the government hand-picked, through the API and the Codex tool, never ChatGPT. The administration cleared access for one customer at a time, like a bouncer working a velvet rope nobody elected him to run. </span><strong><a href="https://www.axios.com/2026/06/25/trump-administration-openai-gpt-model-release"><span>Axios</span></a></strong><span> called it the first time the US government preemptively restricted a domestic AI model before release. Sam Altman had walked it through with Commerce Secretary Howard Lutnick two days earlier, after the White House Office of the National Cyber Director and the Office of Science and Technology Policy asked for the TL;DR.</span></p><p><span>OpenAI complied and objected in the same breath, in writing. The company said it doesn&#8217;t believe &#8220;this kind of government access process should become the long-term default.&#8221; Read that again. The lab building the model and the lab the government blacked out two weeks earlier now stand on the same square, saying the same thing, and the government still has a hand on the switch.</span></p><p><span>One blackout is an accident. Two of them, 14 days apart, on the same cyber rationale, are policies nobody passed. The executive order signed on June 2 promised, on paper, that this would remain voluntary. Twenty-four days later, the voluntary program was rubber-stamping customers one at a time.</span></p><p><span>Before I take a bat to this, I conceded that Frontier cyber models are dangerous. Testing a product before it ships is ordinary, and we do it to jet engines and drugs. </span><strong><a href="https://techcrunch.com/2026/06/26/openai-limits-gpt-5-6-rollout-after-government-request-says-restrictions-shouldnt-be-the-norm/"><span>Russell Brandom</span></a></strong><span> made the honest point that these capabilities now carry political weight, and containing them requires collective action that binds every lab or none. </span><strong><a href="https://www.hyperdimensional.co/p/what-should-be-done"><span>Dean Ball</span></a></strong><span>, who is no AI dove, calls the underlying security worry legitimate and serious. Take all of it as given. The fight was never about whether to review a model for danger. The fight is about a government gate with no published standard, with nobody qualified staring at it, swung at a capability that mostly helps defenders and already sits everywhere. A real safety regime hands you a standard and measures you against it. This one measures you against a standard that has never been written.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HOoj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a4d5b04-3745-46ca-95f8-86dab0245cff_2617x1353.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HOoj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a4d5b04-3745-46ca-95f8-86dab0245cff_2617x1353.png 424w, https://substackcdn.com/image/fetch/$s_!HOoj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a4d5b04-3745-46ca-95f8-86dab0245cff_2617x1353.png 848w, https://substackcdn.com/image/fetch/$s_!HOoj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a4d5b04-3745-46ca-95f8-86dab0245cff_2617x1353.png 1272w, https://substackcdn.com/image/fetch/$s_!HOoj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a4d5b04-3745-46ca-95f8-86dab0245cff_2617x1353.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HOoj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a4d5b04-3745-46ca-95f8-86dab0245cff_2617x1353.png" width="1456" height="753" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8a4d5b04-3745-46ca-95f8-86dab0245cff_2617x1353.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:753,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:177631,&quot;alt&quot;:&quot;Timeline from June 2 to June 26 2026 showing the executive order banning mandatory licensing, the Fable and Mythos blackout, and the GPT-5.6 gating with partial Mythos restoration.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/204173573?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a4d5b04-3745-46ca-95f8-86dab0245cff_2617x1353.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Timeline from June 2 to June 26 2026 showing the executive order banning mandatory licensing, the Fable and Mythos blackout, and the GPT-5.6 gating with partial Mythos restoration." title="Timeline from June 2 to June 26 2026 showing the executive order banning mandatory licensing, the Fable and Mythos blackout, and the GPT-5.6 gating with partial Mythos restoration." srcset="https://substackcdn.com/image/fetch/$s_!HOoj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a4d5b04-3745-46ca-95f8-86dab0245cff_2617x1353.png 424w, https://substackcdn.com/image/fetch/$s_!HOoj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a4d5b04-3745-46ca-95f8-86dab0245cff_2617x1353.png 848w, https://substackcdn.com/image/fetch/$s_!HOoj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a4d5b04-3745-46ca-95f8-86dab0245cff_2617x1353.png 1272w, https://substackcdn.com/image/fetch/$s_!HOoj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a4d5b04-3745-46ca-95f8-86dab0245cff_2617x1353.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 1: From Incident To Regime: Two Blackouts In Two Weeks</figcaption></figure></div><h2><span>A License With No License</span></h2><p><span>The </span><strong><a href="https://techcrunch.com/2026/06/02/trump-signs-narrower-executive-order-on-ai-oversight-after-industry-objections"><span>executive order</span></a></strong><span> forbids, on paper, exactly what the government is doing in practice. Section 3 says nothing authorizing a &#8220;mandatory governmental licensing, preclearance, or permitting requirement&#8221; for releasing an AI model. The same order then hands the government a hand in choosing which partners get early access, with not one single criterion written down. Run that one customer at a time, and you have built a licensing regime. The administration refuses to call it one, which changes nothing.</span></p><p><span>Dean Ball named it a &#8220;de facto involuntary licensing regime&#8221; the day the order landed. He is also joining OpenAI, so weigh him accordingly. His core claim survives the conflict. Nobody knows what clears a model, and he means NOBODY. By his account, the administration itself can&#8217;t tell you what standard a company would have to meet to make it comfortable releasing a model with Mythos-level reach. A lab asks whether it can ship to the public. The answer is no. It stays no until somebody writes a standard that doesn&#8217;t exist.</span></p><p><span>A discretionary regime is worth exactly as much as the judgment of the people running it. Look at who that is. The administration hired one person to run the Center for AI Standards and Innovation, someone who had worked inside both OpenAI and Anthropic. Senior officials fired him within days. They parked the rest of the staff on a stop-work order through the worst of the post-Mythos scramble and barred them from talking to other agencies. Ball, who sat inside the White House on this administration&#8217;s AI strategy, says nobody he knows there has ever built anything. That is the crew writing a test you can&#8217;t see and can&#8217;t pass.</span></p><p><span>The calendar makes it worse. With no standard and no one able to write one quickly, &#8220;no&#8221; becomes the answer to an open-ended stretch. Ball lands the sharper blow. The capability curve moves so fast that any standard this crew writes today is stale by September. The fix rots before it ships, and you would be planning your business against a bar that moves as fast as the models do.</span></p><p><span>The money makes it worse again. A frontier model earns back most of its training cost in the few months it has the market to itself, before rivals catch up and margins collapse. Every week stuck in review burns that window. The data-center buildout that David Sacks calls essential to the economy assumes a global market for American AI, not whatever hundred companies a federal official decides to bless. Squeeze releases hard enough, and you produce the demand collapse that years of overbuild warnings couldn&#8217;t. The regime misfires on security and taxes the one industry the administration swears it wants to win.</span></p><p><span>I have watched the small version of this in regulated industries for 30 years. It was a discretionary approval process with no written standard, where the answer turned on who answered the phone and how their week was going. The teams under those regimes never feared the hard rules. They feared the unwritten ones because you can&#8217;t plan against a decision that changes with the mood in the room. A hard no, you engineer around. A maybe that lands differently every time freezes everything behind it.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JDt6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F630de751-1c99-4599-b09c-923a793008a7_2501x1538.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JDt6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F630de751-1c99-4599-b09c-923a793008a7_2501x1538.png 424w, https://substackcdn.com/image/fetch/$s_!JDt6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F630de751-1c99-4599-b09c-923a793008a7_2501x1538.png 848w, https://substackcdn.com/image/fetch/$s_!JDt6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F630de751-1c99-4599-b09c-923a793008a7_2501x1538.png 1272w, https://substackcdn.com/image/fetch/$s_!JDt6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F630de751-1c99-4599-b09c-923a793008a7_2501x1538.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JDt6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F630de751-1c99-4599-b09c-923a793008a7_2501x1538.png" width="1456" height="895" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/630de751-1c99-4599-b09c-923a793008a7_2501x1538.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:895,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:133937,&quot;alt&quot;:&quot;Comparison table scoring five attributes. A real safety regime has a published standard, statutory authority, an appeal process, frontier-AI-experienced staff, and a defined public threshold, all marked present. The current regime is marked absent on all five and runs customer by customer on a classified threshold.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/204173573?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F630de751-1c99-4599-b09c-923a793008a7_2501x1538.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Comparison table scoring five attributes. A real safety regime has a published standard, statutory authority, an appeal process, frontier-AI-experienced staff, and a defined public threshold, all marked present. The current regime is marked absent on all five and runs customer by customer on a classified threshold." title="Comparison table scoring five attributes. A real safety regime has a published standard, statutory authority, an appeal process, frontier-AI-experienced staff, and a defined public threshold, all marked present. The current regime is marked absent on all five and runs customer by customer on a classified threshold." srcset="https://substackcdn.com/image/fetch/$s_!JDt6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F630de751-1c99-4599-b09c-923a793008a7_2501x1538.png 424w, https://substackcdn.com/image/fetch/$s_!JDt6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F630de751-1c99-4599-b09c-923a793008a7_2501x1538.png 848w, https://substackcdn.com/image/fetch/$s_!JDt6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F630de751-1c99-4599-b09c-923a793008a7_2501x1538.png 1272w, https://substackcdn.com/image/fetch/$s_!JDt6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F630de751-1c99-4599-b09c-923a793008a7_2501x1538.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 2: A Real Safety Regime vs This One</figcaption></figure></div><h2><span>They Gated The Defender&#8217;s Tool</span></h2><p><span>The coverage buried the worst part. The model the government boxed up is better at defending your network than at breaking into anybody else&#8217;s.</span></p><p><span>OpenAI&#8217;s own write-up on Sol, the flagship of the GPT-5.6 line, says it is better at helping people find and fix vulnerabilities than at running attacks end-to-end. It matched an earlier Anthropic model on the </span><strong><a href="https://exploitbench.ai/"><span>ExploitBench security benchmark</span></a></strong><a href="https://exploitbench.ai/"><span> </span></a><span>while using about a third as many output tokens. Turned loose on Chromium and Firefox, it surfaced bugs and parts of an exploit, but it couldn&#8217;t chain into a working full attack on its own. It came in under OpenAI&#8217;s own Cyber Critical threshold, the internal line the company draws at opening genuinely new paths to severe harm. They locked up a model that never crossed the bar its own maker set for dangerous.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AWzX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47d9bcd1-378b-4965-9a02-0e92818bce9c_2441x1899.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AWzX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47d9bcd1-378b-4965-9a02-0e92818bce9c_2441x1899.png 424w, https://substackcdn.com/image/fetch/$s_!AWzX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47d9bcd1-378b-4965-9a02-0e92818bce9c_2441x1899.png 848w, https://substackcdn.com/image/fetch/$s_!AWzX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47d9bcd1-378b-4965-9a02-0e92818bce9c_2441x1899.png 1272w, https://substackcdn.com/image/fetch/$s_!AWzX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47d9bcd1-378b-4965-9a02-0e92818bce9c_2441x1899.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AWzX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47d9bcd1-378b-4965-9a02-0e92818bce9c_2441x1899.png" width="1456" height="1133" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/47d9bcd1-378b-4965-9a02-0e92818bce9c_2441x1899.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1133,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:129696,&quot;alt&quot;:&quot;Bar chart plotting Terminal-Bench 2.1 scores on a zero to 100 axis. Claude Mythos 5 scores 88.0%, GPT-5.6 Sol scores 88.8%, and GPT-5.6 Sol in ultra mode scores 91.9%. A note states that Sol stayed below OpenAI's internal Cyber Critical threshold and could not autonomously produce a working full-chain exploit.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/204173573?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47d9bcd1-378b-4965-9a02-0e92818bce9c_2441x1899.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Bar chart plotting Terminal-Bench 2.1 scores on a zero to 100 axis. Claude Mythos 5 scores 88.0%, GPT-5.6 Sol scores 88.8%, and GPT-5.6 Sol in ultra mode scores 91.9%. A note states that Sol stayed below OpenAI's internal Cyber Critical threshold and could not autonomously produce a working full-chain exploit." title="Bar chart plotting Terminal-Bench 2.1 scores on a zero to 100 axis. Claude Mythos 5 scores 88.0%, GPT-5.6 Sol scores 88.8%, and GPT-5.6 Sol in ultra mode scores 91.9%. A note states that Sol stayed below OpenAI's internal Cyber Critical threshold and could not autonomously produce a working full-chain exploit." srcset="https://substackcdn.com/image/fetch/$s_!AWzX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47d9bcd1-378b-4965-9a02-0e92818bce9c_2441x1899.png 424w, https://substackcdn.com/image/fetch/$s_!AWzX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47d9bcd1-378b-4965-9a02-0e92818bce9c_2441x1899.png 848w, https://substackcdn.com/image/fetch/$s_!AWzX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47d9bcd1-378b-4965-9a02-0e92818bce9c_2441x1899.png 1272w, https://substackcdn.com/image/fetch/$s_!AWzX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47d9bcd1-378b-4965-9a02-0e92818bce9c_2441x1899.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 3: They Gated The Stronger Defensive Tool</figcaption></figure></div><p><span>Your defenders would use models like this to find and close holes faster than attackers can turn them into weapons. Take the better one off the board, and the gap between a bug appearing and your team killing it gets wider. That gap is the exact ground where ransomware crews and state-sponsored teams live. Gate the defender&#8217;s tool, and you do not slow the attacker down. You give him a longer runway.</span></p><p><span>Measure what the gate delivered. The skill of finding and fixing flaws at machine speed doesn&#8217;t belong to one model or one country. It runs across every frontier model and across every border. Pull one American vendor, and the offensive half of that skill drops by roughly nothing, because every other model that does the same work is still online, and China keeps shipping its own. I did the math on this in the </span><strong><a href="https://www.rockcybermusings.com/p/fable-federal-ai-model-recall-supply-chain-risk"><span>Fable piece</span></a></strong><span> and won&#8217;t rerun it here. The conclusion holds. The ceiling on this capability is the architecture, not a single lab&#8217;s mistake, and you can&#8217;t undo it by powering down a single set of weights.</span></p><p><span>What the gate did accomplish is simple. It pulled the better defensive tool out of the hands of the people defending American networks and left every attacker on the planet exactly as armed as they were the day before. Call that restraint if it helps you sleep. It reads to me like cutting off your nose to spite your face.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0jtx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88c95f77-b188-4d86-85d9-8ffd88df5b25_2501x1436.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0jtx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88c95f77-b188-4d86-85d9-8ffd88df5b25_2501x1436.png 424w, https://substackcdn.com/image/fetch/$s_!0jtx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88c95f77-b188-4d86-85d9-8ffd88df5b25_2501x1436.png 848w, https://substackcdn.com/image/fetch/$s_!0jtx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88c95f77-b188-4d86-85d9-8ffd88df5b25_2501x1436.png 1272w, https://substackcdn.com/image/fetch/$s_!0jtx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88c95f77-b188-4d86-85d9-8ffd88df5b25_2501x1436.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0jtx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88c95f77-b188-4d86-85d9-8ffd88df5b25_2501x1436.png" width="1456" height="836" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/88c95f77-b188-4d86-85d9-8ffd88df5b25_2501x1436.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:836,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:105869,&quot;alt&quot;:&quot;Comparison table scoring five attributes. A real safety regime has a published standard, statutory authority, an appeal process, frontier-AI-experienced staff, and a defined public threshold, all marked present. The current regime is marked absent on all five and runs customer by customer on a classified threshold.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/204173573?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88c95f77-b188-4d86-85d9-8ffd88df5b25_2501x1436.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Comparison table scoring five attributes. A real safety regime has a published standard, statutory authority, an appeal process, frontier-AI-experienced staff, and a defined public threshold, all marked present. The current regime is marked absent on all five and runs customer by customer on a classified threshold." title="Comparison table scoring five attributes. A real safety regime has a published standard, statutory authority, an appeal process, frontier-AI-experienced staff, and a defined public threshold, all marked present. The current regime is marked absent on all five and runs customer by customer on a classified threshold." srcset="https://substackcdn.com/image/fetch/$s_!0jtx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88c95f77-b188-4d86-85d9-8ffd88df5b25_2501x1436.png 424w, https://substackcdn.com/image/fetch/$s_!0jtx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88c95f77-b188-4d86-85d9-8ffd88df5b25_2501x1436.png 848w, https://substackcdn.com/image/fetch/$s_!0jtx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88c95f77-b188-4d86-85d9-8ffd88df5b25_2501x1436.png 1272w, https://substackcdn.com/image/fetch/$s_!0jtx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88c95f77-b188-4d86-85d9-8ffd88df5b25_2501x1436.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 4: The Security Inversion</figcaption></figure></div><h2><span>A Blessed Few, And What Competent Authority Would Do Instead</span></h2><p><span>Strip the national-security paint off and look at what&#8217;s underneath. Picture 20-odd companies, chosen behind closed doors, sitting on the most capable cyber tooling money can buy. That is the inverse of what defenders need. The thing that lifts the floor is broad, monitored access for the people guarding hospitals, pipelines, and water plants. A blessed few list lifts it for 20 names and drops it for everyone else.</span></p><p><span>Ball puts the deeper rot in plain words. The people with the most power, wielding the most capable technology ever built, behind a curtain the public can&#8217;t see through, isn&#8217;t a setup you should bet ends well. He calls it inconsistent with a democratic republic, and on that, he is right, no matter who signs his next paycheck.</span></p><p><strong><a href="https://press.princeton.edu/books/paperback/9780691260341/technology-and-the-rise-of-great-powers"><span>Jeffrey Ding&#8217;s diffusion argument, which Ball invokes</span></a><span>,</span></strong><span> who studies how technology turns into national power, argues that general-purpose tools only pay off when they spread through a whole economy, not when they pool in a few hands. We figure out what a general-purpose technology is good for by putting it in front of many people. Lock frontier AI to 20 incumbents and you concentrate the power and choke off the learning at the same time.</span></p><p><span>A real alternative exists, and it&#8217;s not just my brilliant idea. You want to regulate? Regulate the industry&#8230; as you would something like financial services&#8230;, not by the weights of a single release. A model is a pile of floating-point numbers a lab ships dozens of times over, and the compute needed to hit any given capability falls every few months, so a rule pinned to model characteristics is obsolete before the ink dries. Audit the labs against their own safety commitments through independent verification outfits, technical shops, and government certification, as it certifies financial auditors. Take the transparency floor of the three states already built and make it national. California&#8217;s SB 53, along with New York and Illinois, already requires frontier labs to publish a safety framework and follow it. Representatives Obernolte and Trahan put roughly this into their Great American AI Act discussion draft, which sets a bipartisan frontier governance bill on the table for the first time.</span></p><p><span>This is coming from a person (me) who </span><em><span>loathes</span></em><span> overregulation and government overreach.</span></p><p><span>That is the architecture-first move I keep coming back to. Identity ties to privilege, privilege ties to accountability, and you govern the agent and the company that builds it instead of throwing a breaker on the weights and calling the result safety. </span><strong><a href="https://www.rockcybermusings.com/p/five-eyes-agentic-ai-architecture-not-checklist"><span>I wrote about that shape when the Five Eyes agencies put out their agentic guidance.</span></a></strong><span> The capability the government tried to bottle up belongs to the entire class of models. You do not regulate a class by blacking out one member of it.</span></p><h2><span>The CISO Read</span></h2><p><span>Model availability now runs through an unwritten, unappealable, one-customer-at-a-time process, and the people running it can&#8217;t show you the standard they are using. Your most capable AI vendor ships when an official you will never meet decides it ships, and not a day sooner.</span></p><p><span>The irony (and it&#8217;s a good one in this case)?  The same day the government gated OpenAI, it partly lifted the Fable order and let Mythos 5 back to a narrow set of cyber defenders and infrastructure operators.</span></p><p><span>Follow that pattern.</span></p><p><span>A capability the order branded too dangerous for foreign nationals to touch on June 12 went back to a hand-picked list on June 26, after the NSA itself had lost access under that same order. Availability ran from on to off to selectively on inside two weeks, and the government published a reason for none of the three.</span></p><p><span>You can&#8217;t write your way out of this with a vendor SLA, because the hand on the switch doesn&#8217;t belong to your vendor. You plan for it the way you plan for any single point of failure you do not control. This is the Fable playbook, and the target moving from Anthropic to OpenAI did not change a line of it.</span></p><p><strong><span>Key Takeaway:</span></strong><span> Frontier AI model release restrictions have hardened into a licensing regime with no written standard, no appeal, and nobody qualified at the gate, and the one model it reliably keeps from your hands is the one your defenders needed most.</span></p><h3><span>What To Do Next</span></h3><p><span>You have two moves.</span></p><p><span>Inside your program, run the </span><strong><a href="https://www.rockcybermusings.com/i/202851746/what-to-do-next"><span>CARE loop from the Fable breakdown</span></a><span>.</span></strong><span> </span><strong><span>CREATE</span></strong><span> the inventory of every workflow that leans on a hosted frontier model, ranked by what breaks the day it vanishes. </span><strong><span>ADAPT</span></strong><span> the contracts with a model-continuity clause, then exercise a real fallback for every tier-one workflow, a second hosted model and an open-weight option you have stood up and run yourself. </span><strong><span>RUN</span></strong><span> vendor-revocation drills, not the tame outage drills you already pass. </span><strong><span>EVOLVE</span></strong><span> the AI risk register so &#8220;a federal official can gate or kill our vendor&#8217;s model on a whim he never has to explain&#8221; sits right next to accuracy, bias, and security as a named availability risk. The full playbook lives in my breakdown of the Fable blackout as a supply chain risk.</span></p><p><span>Outside your program, scream the quiet part at full volume. </span><strong><a href="https://www.implicator.ai/openai-restricts-gpt-5-6-release-to-government-approved-partners/"><span>Alex Stamos</span></a></strong><span>, a former chief security officer at Meta, told reporters that nobody in the industry sees &#8220;any factual basis for this action,&#8221; and that gating models this way hands ground to China. Representative Lori Trahan called it the government deciding access company by company, with &#8220;no law, no process, no oversight.&#8221; The wrecking ball only gets taken away from the people swinging it blind when the defenders it keeps hitting stop nodding along and calling the bruises safety. I called this exact failure before it happened, that prerelease vetting would aim at the wrong risk surface and miss, and here it is in the wild. If you run security, you have the standing to say so out loud, and staying quiet reads as a yes.</span></p><p><span>&#128073; For ongoing analysis of agentic AI governance frameworks, the conversation continues at </span><strong><a href="https://rockcybermusings.com/">RockCyber Musings</a></strong><span>.</span></p><p><span>&#128073; Visit </span><strong><a href="https://www.rockcyber.com/">RockCyber.com</a></strong><span> to learn more about how we can help with your traditional Cybersecurity and AI Security and Governance journey.</span></p><p><span>&#128073; Want to save a quick $100K? Check out our AI Governance Tools at </span><strong><a href="https://aigovernancetoolkit.com/">AIGovernanceToolkit.com</a></strong></p><p><span>&#128073; As a bonus, check out my conversation with </span><strong><a href="https://aicybermagazine.com/">AI Cyber Magazine, </a></strong><span>where we talked about everything from Context Rot to Least Agency. My interview is also highlighted in the </span><strong><a href="https://issuu.com/aicybermagazine/docs/ai_cyber_summer_edition_2026/22"><span>AI Cyber Magazine 2026 Summer Issue.</span></a></strong></p><p><em>The views and opinions expressed in RockCyber Musings are my own and do not represent the positions of my employer or any organization I&#8217;m affiliated with.</em></p><div id="youtube2-091_b2qep9M" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;091_b2qep9M&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/091_b2qep9M?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share RockCyber Musings&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share RockCyber Musings</span></a></p>]]></content:encoded></item><item><title><![CDATA[Weekly Musings Top 10 AI Security Wrapup: Issue 43 June 19 -June 25, 2026]]></title><description><![CDATA[The Week Five Spy Agencies Said the AI Cyber Threat Is Months Away and Everyone Kept Shipping]]></description><link>https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260619-20260625</link><guid isPermaLink="false">https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260619-20260625</guid><dc:creator><![CDATA[Rock Lambros]]></dc:creator><pubDate>Fri, 26 Jun 2026 12:50:05 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!71X_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b84bbbc-e9e3-4af4-aa52-552643ebcf9c_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!71X_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b84bbbc-e9e3-4af4-aa52-552643ebcf9c_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!71X_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b84bbbc-e9e3-4af4-aa52-552643ebcf9c_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!71X_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b84bbbc-e9e3-4af4-aa52-552643ebcf9c_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!71X_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b84bbbc-e9e3-4af4-aa52-552643ebcf9c_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!71X_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b84bbbc-e9e3-4af4-aa52-552643ebcf9c_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!71X_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b84bbbc-e9e3-4af4-aa52-552643ebcf9c_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6b84bbbc-e9e3-4af4-aa52-552643ebcf9c_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1233556,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/203626618?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b84bbbc-e9e3-4af4-aa52-552643ebcf9c_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!71X_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b84bbbc-e9e3-4af4-aa52-552643ebcf9c_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!71X_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b84bbbc-e9e3-4af4-aa52-552643ebcf9c_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!71X_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b84bbbc-e9e3-4af4-aa52-552643ebcf9c_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!71X_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b84bbbc-e9e3-4af4-aa52-552643ebcf9c_1024x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Five intelligence agencies told you the offensive AI threat is months out, not years. The same week, OpenAI shipped a cyber model that finds and patches bugs at machine speed, Anthropic&#8217;s two best models sat dark for the thirteenth straight day under a government order, and a startup raised $30 million to babysit the AI agents already loose in your environment. The common thread across this week&#8217;s musings is the gap between a capability landing and that capability hurting you has collapsed. Governments now react in days, vendors react in hours, and your governance program still reacts in quarters.</p><p>This week handed CISOs a rare gift: clarity. The intelligence community said the quiet part out loud, the labs proved both sides of the dual-use coin in one news cycle, and researchers showed the medical AI you trust to read a scan will expose the patients it trained on. The people telling you to slow down and the people telling you to go faster are now describing the same threat model, and it moved while you were writing policy. Here is what happened between June 19 and June 25, and what you do about it.</p><h3>1. Five Eyes Tells CISOs the AI Cyber Threat Is Months Away, Not Years</h3><p>On June 23, the cyber agencies of the United States, United Kingdom, Canada, Australia, and New Zealand issued a rare joint statement warning that frontier AI will reshape offensive hacking on a timeline measured in months, not years (CISA). The statement carried signatures from NSA Cybersecurity Directorate head David Imbordino and acting CISA Director Nick Andersen, and urged leaders to assess cyber risk, prioritize foundational controls, empower cyber leaders, and stay engaged (CyberScoop). It landed days after Washington forced Anthropic to suspend its most capable models, which suggests the alarm connects to something the agencies already saw.</p><p><strong>Why it matters</strong></p><ul><li><p>A coordinated Five Eyes statement is not routine. These agencies rarely co-sign a public warning unless the risk is real and near.</p></li><li><p>&#8220;Months, not years&#8221; repudiates every roadmap that assumed you had until 2028 to harden against AI-accelerated attacks.</p></li><li><p>The recommendations are deliberately boring, which means the agencies think most organizations still fail at fundamentals.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Benchmark your patch SLA against CISA&#8217;s three-day mandate for high-risk flaws.</p></li><li><p>Map which crown-jewel systems fall first to an attacker who finds and chains vulnerabilities at machine speed.</p></li><li><p>Brief your board with the actual statement, so the urgency comes from five governments rather than your slide deck.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Most government advisories read like a committee trying not to get blamed. This one is different. When the NSA and four allied agencies put their names on &#8220;months, not years,&#8221; they spend credibility they normally hoard, which tells me this is driven by classified testing they cannot show you. My worry is how it lands. Every vendor will now sell you an &#8220;AI threat&#8221; product on the back of this statement, and most solve nothing the agencies flagged. If you walk out of this week having bought a shiny detection tool instead of fixing your patch pipeline, you misread the memo.</p><h3>2. OpenAI Ships GPT-5.5-Cyber and Proves the Dual-Use Argument in Real Time</h3><p>On June 22, OpenAI expanded its Daybreak initiative with the full release of GPT-5.5-Cyber, a Codex Security plugin that builds vulnerability scanning into developer workflows, and a &#8220;Patch the Planet&#8221; program for open-source projects (OpenAI). GPT-5.5-Cyber scored 85.6% on CyberGym, OpenAI&#8217;s benchmark for reproducing known vulnerabilities, which the company called its highest single-model score (SiliconANGLE). Patch the Planet launched with Trail of Bits, HackerOne, and more than 30 projects including cURL, Go, and Python, framed around moving from finding bugs to shipping verified fixes.</p><p><strong>Why it matters</strong></p><ul><li><p>The capability that patches vulnerabilities for defenders finds them just as well for attackers, and OpenAI shipped its version the same week Anthropic&#8217;s got banned.</p></li><li><p>Automated patch generation at this quality shifts the bottleneck from discovery to validation and deployment.</p></li><li><p>The security of cURL or Python could soon depend on AI-generated fixes that maintainers have to trust.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Test AI-assisted patch tooling in a sandbox against your own code, and measure the false-fix rate, not the discovery rate.</p></li><li><p>Require human review of any AI-generated patch touching authentication, cryptography, or data handling.</p></li><li><p>Track which dependencies join programs like Patch the Planet, and revisit your software bill of materials.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>The timing is almost too perfect. Washington banned Anthropic&#8217;s Mythos for finding vulnerabilities, and three days later, OpenAI shipped a model that does the same thing and called it a public service. The capability is dual-use down to the silicon, and you cannot ban one side without losing the other. What worries me is the verification gap. When an AI proposes a patch to cURL, and the maintainer is a volunteer with a day job, the review meant to catch a subtle regression may not happen, and you inherited a class of supply chain risk nobody has priced yet. I write more about dual-use AI risk at <a href="https://www.rockcyber.com/">RockCyber</a>.</p><h3>3. Anthropic&#8217;s Best Models Hit Day 13 of a Government-Ordered Blackout</h3><p>As of June 25th, Anthropic&#8217;s Fable 5 and Mythos 5 remained fully offline for every user on earth, with staff confirming zero traffic nearly two weeks after a US export-control directive forced the shutdown (Fortune). The Bureau of Industry and Security ordered the suspension because the directive barred any foreign national, including Anthropic&#8217;s own non-citizen employees, and the company could not screen by nationality. During a June 11 Senate hearing, Sen. Mark Warner, vice chair of the Intelligence Committee, said Gen. Joshua Rudd, who leads the NSA and U.S. Cyber Command, had told him Mythos "broke into almost all of our classified systems, not in weeks but in hours." A U.S. official later told the Associated Press the model identified vulnerabilities within hours during an authorized testing exercise, while cautioning that finding the flaws did not mean the model could exploit them in that window (CNBC/AP)</p><p><strong>Why it matters</strong></p><ul><li><p>This is the first time the US applied export controls directly to an AI model rather than to chips, setting a precedent every frontier lab now plans around.</p></li><li><p>A model can be revenue-generating one day and a controlled item the next, turning availability into a supply chain risk you cannot contract away.</p></li><li><p>Nationality-based controls hit Anthropic&#8217;s own foreign-national employees, exposing how blunt the mechanism becomes against software anyone can call.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Inventory every business process that depends on a single frontier model, and document a fallback to a second provider.</p></li><li><p>Add &#8220;model could be pulled by government order&#8221; to your vendor risk register for any AI capability in a critical workflow.</p></li><li><p>If you operate across borders, get ahead of how nationality-based access rules would apply to your own staff.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>What I care about is the precedent, not the panic. Banning a model for all foreign nationals, including your own employees, is the policy equivalent of swinging a sledgehammer at a fly that has already left the room. More than 120 cybersecurity professionals, including names from Nvidia and Google, signed a letter arguing the capability is far from unique and that pulling the best defensive tool while adversaries keep building theirs is a net loss. Both things can be true. The model is dangerous, and the ban probably hurts defenders more than the adversaries it targets. The deeper problem is durability. A model that anchors a critical workflow can vanish overnight under a government order, leaving you with no recourse and no notice. If you run anything important on a frontier model, the rug can now get pulled by a government, not only by a vendor.</p><h3>4. Researchers Show Medical AI Will Expose the Patients It Trained On</h3><p>On June 24, Nature published research by German scientists showing that AI models used to diagnose medical conditions are highly vulnerable to membership inference attacks, in which an adversary queries a model to determine whether a specific person&#8217;s data was in its training set (The Register). Across many medical datasets, the attacks achieved near-perfect success rates for individual patients even when aggregate model behavior appeared to be random guessing. Risk climbed with model capacity, and underrepresented groups faced disproportionate exposure, since confirming a patient&#8217;s data was used as a direct proxy for their diagnosis.</p><p><strong>Why it matters</strong></p><ul><li><p>Membership inference turns a deployed diagnostic model into a privacy leak that reveals sensitive medical facts about a named person.</p></li><li><p>The disparate impact on underrepresented groups means the harm is uneven, raising ethical and regulatory exposure.</p></li><li><p>Aggregate privacy metrics hid the risk entirely, so teams that checked average privacy measured the wrong thing.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Assess any sensitive-domain model for membership inference at the individual level, not at the aggregate level, before deployment.</p></li><li><p>Gate diagnostic models behind authentication and rate limiting to block the query volume these attacks need.</p></li><li><p>Where a model trains on a narrow sensitive cohort, treat membership inference as a reportable risk and apply differential privacy.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>This one bothers me more than the flashy stuff, because it hits a system everyone assumes is safe. A radiology model that helps a doctor read a scan feels benign, and nobody in the procurement meeting asked whether it would betray the patients in its training data. The people most exposed are the ones already underrepresented in the data, so this is a fairness problem wearing a privacy problem&#8217;s clothes. The detail that should change your behavior is the aggregate-versus-individual gap, because the model can look perfectly private on average while leaking specific patients with near-perfect reliability. I have seen this in security, where the dashboard is green and the breach is already underway. Healthcare AI buyers need membership inference testing on the checklist now.</p><h3>5. Mini Shai-Hulud Resurfaces and Camps Inside Your AI Coding Agent</h3><p>On June 19, the self-propagating supply chain worm Mini Shai-Hulud resurfaced in a fresh wave, with researchers tracking over 1,600 exfiltration repositories across 21 compromised GitHub accounts (StepSecurity). The worm steals credentials from one CI/CD pipeline, enumerates every package that the maintainer controls, and publishes infected versions of each. Its payload reads GitHub Actions runner memory to extract secrets, harvests credentials from more than 100 file paths, installs persistence hooks in Claude Code and VS Code that survive reboots, and exfiltrates through legitimate channels like GitHub&#8217;s own GraphQL API using branch names drawn from the Dune universe (Akamai).</p><p><strong>Why it matters</strong></p><ul><li><p>The worm plants persistence inside AI coding assistants, so your developer&#8217;s agent becomes a re-infection vector that survives a clean package rollback.</p></li><li><p>It exfiltrates through GitHub&#8217;s own infrastructure, so detection that trusts GitHub by default will miss it.</p></li><li><p>A self-propagating credential thief turns one compromised developer into a fan-out event across the open-source ecosystem.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Audit your CI/CD runners for the persistence hooks this worm installs in Claude Code and VS Code, since a rollback does not remove them.</p></li><li><p>Rotate any credential that touched a build pipeline in the window, and assume secrets in runner memory were harvested.</p></li><li><p>Treat AI coding agents as privileged software with secret access, and scope their permissions instead of trusting them.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>The Dune branch names are a nice touch, and I would almost respect the craftsmanship if it were not stealing everyone&#8217;s secrets. What matters is the architectural lesson. This worm figured out that the AI coding assistant in every developer&#8217;s environment is a perfect place to hide, because we collectively decided to trust those tools with deep access and almost no scrutiny. Your agent can read your secrets, write to your repos, and survive a reboot. That is not a productivity tool, that is a privileged service account with a friendly chat interface, and the worm needs no novel exploit because it uses the access we already handed the agent. If you cannot answer what secrets your AI tools reach and what persists after a wipe, you have a gap this worm was built to walk through. I dig into agent permission models at <a href="https://rockcybermusings.com/">RockCyber Musings</a>.</p><h3>6. New Report Finds 76% of Organizations Have Already Pulled Back AI Behavior in Production</h3><p>On June 24, Aikido Security published its 2026 State of AI in Security and Development report, drawing on responses from 450 security leaders, developers, and AppSec engineers across Europe and the US (Help Net Security). The headline number is the one that should stop you. 76% of organizations had to stop, restrict, or roll back AI-driven behavior in the past 12 months, which means the gap between deploying AI and trusting it is now a measured operational fact, not a worry. Another 71% said AI or automation made a security issue harder to detect, investigate, or fix. Only about a third of security teams hold both the authority to stop a release and the responsibility when something goes wrong.</p><p><strong>Why it matters</strong></p><ul><li><p>A 76% rollback rate means AI is shipping into production faster than teams can validate it, and the correction is happening after deployment instead of before.</p></li><li><p>The 71% who say AI made incidents harder to investigate points to a detection and forensics gap that grows as AI touches more of the stack.</p></li><li><p>The authority-responsibility split, where only a third of teams hold both, is a governance failure that guarantees nobody owns the decision to hit the brakes.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Measure your own rollback rate for AI-driven features over the past year, because if you are near the 76% average you have a validation problem, not a tooling problem.</p></li><li><p>Close the authority-responsibility gap by naming who can stop a release and making that same person accountable for the outcome.</p></li><li><p>Shift AI security testing from periodic and manual to continuous, because the report&#8217;s core finding is that slower validation cannot keep pace with AI-accelerated development.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>I trust survey numbers about as far as I can throw them, so I read past the headline to the question underneath, and this one holds up. Three-quarters of organizations had to yank AI behavior back out of production after they shipped it. That is not a story about bad tools; it is a story about deploying first and validating never, then discovering the problem in production, where it costs the most to fix. The number that actually worries me is the authority-responsibility split. When only a third of security teams can both stop a release and own the consequences, you have built an organization where the person who sees the risk cannot pull the brake, and the person who can pull the brake does not feel the burn. That is how you end up explaining a rollback to your board instead of preventing one. The fix is unglamorous and organizational, not technical. Decide who owns the kill decision, give that person real authority, and make them accountable for the call, because a control nobody is empowered to use is theater. Read the survey, find your own rollback rate, and if it is anywhere near 76%, the problem is your release gate, not your model.</p><h3>7. Researchers Name the AI Safety Risk Nobody Is Measuring: Affective Harm</h3><p>On June 22, <strong><a href="https://arxiv.org/abs/2606.23380">researchers posted a paper to arXiv</a></strong> proposing &#8220;affective safety&#8221; as a distinct and underdeveloped class of AI safety concern, arguing the field has concentrated on epistemic and physical harms like misinformation and reliability while ignoring the risks that arise when AI engages with human emotional life (arXiv). The authors build a taxonomy of affective harms that includes affective self-alienation, fairness and bias harms in emotional contexts, and relational harms. Their argument is that as AI grows more emotionally engaging and embedded in people&#8217;s relationships, the harms from that engagement are real, measurable, and falling through the cracks of every existing safety framework.</p><p><strong>Why it matters</strong></p><ul><li><p>Affective harm is a category most enterprise AI risk frameworks lack a row for, which means it is unmeasured and ungoverned in deployed systems.</p></li><li><p>As companies deploy emotionally engaging AI in customer service, mental health, and HR, the relational harms this paper names become live liability questions.</p></li><li><p>A named taxonomy is the first step toward regulation, because regulators cannot enforce against harms the field has not defined.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>If you deploy AI in any emotionally sensitive context like wellness or coaching, start assessing affective harm rather than waiting for a compliance line.</p></li><li><p>Add relational and emotional-impact questions to your AI impact assessments, especially for systems that interact with vulnerable users.</p></li><li><p>Track this research thread, because the gap between &#8220;academics named it&#8221; and &#8220;regulators require it&#8221; keeps shrinking.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>I almost cut this one because it is academic, early, and easy to wave off as soft. Then I thought about how many companies are racing to deploy emotionally engaging AI into support, wellness, and mental health with zero framework for measuring whether that engagement harms anyone. That is a governance gap you can drive a truck through, and this paper outlines it. The honest uncertainty is that I do not yet know how large the affective harm risk is, and neither does anyone else, because nobody has been measuring it. The pattern in AI risk is consistent. A harm gets named in a paper, dismissed as theoretical, then shows up as a lawsuit eighteen months later while everyone acts surprised, the way membership inference and prompt injection both did. If you deploy AI that engages people emotionally, start thinking about this while it is cheap to address.</p><h3>8. OpenAI&#8217;s Codex Was Quietly Burning Out Developers&#8217; SSDs</h3><p>On June 22 and 23, reports surfaced that OpenAI&#8217;s Codex coding agent had been writing roughly 640 terabytes per year to users&#8217; solid-state drives through a flawed local logging implementation, consuming drive endurance fast enough to threaten hardware lifespans (The Register). One developer measured about 37 TB written in 21 days of uptime, and analysts estimated the bug plausibly burned low single-digit millions of dollars of SSD endurance across users during the March-to-June window. The diagnostic logging ran on by default and stayed on the device, with most users unaware it existed.</p><p><strong>Why it matters</strong></p><ul><li><p>A coding agent silently degrading hardware shows that AI tools run with deep system access and their defaults can cause real, costly harm with no malice involved.</p></li><li><p>Default-on logging that nobody reviewed is the same pattern attackers exploit, where excessive privilege and silent background activity go unnoticed for months.</p></li><li><p>The financial damage was real and distributed, raising questions about liability when a vendor&#8217;s default wears out your hardware.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Audit what your AI developer tools write to local disk and whether diagnostic logging is on by default.</p></li><li><p>Treat AI agent defaults as a security and cost decision, and disable background telemetry you did not consent to.</p></li><li><p>Add AI tooling to endpoint monitoring so silent high-volume disk or network activity triggers an alert.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Nobody got hacked here, and that is exactly why I included it. This is the mundane face of the agent access problem. We hand these tools deep access, they run with defaults we never inspected, and the cost shows up months later as worn-out hardware nobody accounted for. Swap &#8220;burns your SSD&#8221; for &#8220;exfiltrates your secrets&#8221; and you have the Mini Shai-Hulud story from earlier in this same newsletter, same root cause, different symptom. The lesson is not that Codex is evil, it is sloppy, and sloppy is the more common threat. If you are not monitoring what your AI tools do on the endpoint, you are trusting a vendor&#8217;s default to be both benign and competent, and this week proved you cannot count on either.</p><h3>9. A New Open-Source CLI Sniffs Out Stale AI Dependency Advice Before It Bites</h3><p>On June 23, The Register reported on a new open-source command-line tool built to detect stale AI-generated override advice in dependency management (The Register). AI coding assistants routinely tell developers to add override entries to silence transitive dependency vulnerabilities, then never tell the developer to verify whether that override still makes sense once the underlying package updates. Over time those overrides pile up as invisible technical debt that can mask a real vulnerability or pin a dependency to a broken state, and the CLI flags stale entries so teams can review them instead of trusting advice that expired months ago.</p><p><strong>Why it matters</strong></p><ul><li><p>AI assistants give point-in-time advice that ages badly, and dependency overrides are a place where stale advice silently reintroduces risk.</p></li><li><p>An override added to suppress a vulnerability warning can outlive the reason it was added, masking a real flaw behind an AI-suggested workaround.</p></li><li><p>The tooling response shows the community building guardrails specifically for the failure modes of AI-assisted development.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Run a dependency-override audit and flag every entry an AI assistant suggested without an expiry or review date.</p></li><li><p>Add a recurring review of override entries to your dependency hygiene process, because AI advice does not refresh itself.</p></li><li><p>Tell developers that an AI suggestion to suppress a vulnerability warning requires follow-up verification, not a fire-and-forget commit.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>This is small, and I love it, because it attacks a real failure mode instead of a hypothetical one. AI assistants are confident, fast, and frozen in time. They give you advice that was correct the moment they gave it, then walk away, and so does the developer who took it. Six months later you have an override masking a vulnerability that got patched upstream, and nobody knows it is there. AI-assisted development creates a new category of debt, which is advice debt, where every suggestion is a tiny unverified assumption baked into your codebase. Most are harmless, some rot, and a tool that surfaces the rotten ones is unglamorous engineering that moves the needle. It is open source, so there is no excuse not to look.</p><h3>10. OpenAI's Patch the Planet Puts AI-Authored Fixes Into the Open-Source Code You Already Depend On</h3><p>On June 22, alongside the GPT-5.5-Cyber launch, OpenAI introduced Patch the Planet, a program to find and fix vulnerabilities in widely used open-source software using AI, founded with Trail of Bits and run in collaboration with HackerOne and project maintainers (OpenAI). More than 30 open-source projects are committed to participating, including cURL, Go, Python, Sigstore, and pyca/cryptography. The program shifts AI security work from finding bugs to submitting fixes, meaning AI-authored patches start flowing into the foundational libraries that underlie most of the software your organization runs. OpenAI framed it as helping under-resourced maintainers move from findings to fixes faster (SiliconANGLE).</p><p><strong>Why it matters</strong></p><ul><li><p>AI-authored patches entering cURL, Go, and Python means the security of your dependency tree now partly rests on fixes a model wrote and a volunteer reviewed.</p></li><li><p>A confident wrong fix to a cryptography library is more dangerous than an open vulnerability, because it ships with the authority of a merged patch.</p></li><li><p>The liability and ownership question is unsettled, since nobody has defined who answers for an AI-generated fix that introduces a regression downstream.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Track which of your critical open-source dependencies participate in AI-assisted patch programs, and treat that as a new input to your software bill of materials.</p></li><li><p>Do not assume a merged upstream patch was human-authored or human-reviewed to the depth you would require internally.</p></li><li><p>Add provenance questions to your dependency review, specifically whether a fix in a security-critical library was AI-generated and who validated it.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>I want this to work, because under-resourced open-source maintainers are one of the quiet structural risks in everything we build, and throwing capable help at cURL or pyca/cryptography is a defensible idea. The part that keeps me up is the review step nobody wants to fund. The whole model assumes a maintainer carefully checks each AI-authored patch before it merges, and in the real world that maintainer is often one tired volunteer with a day job and an inbox full of issues. An AI that submits a plausible-looking fix to a cryptography library is not a gift if the person on the other end cannot afford the time to verify it line by line. We have spent years learning that subtle bugs in foundational libraries cause the worst incidents, and now we are pointing automated patch generation straight at those libraries. That is either a major win or a new and quiet class of supply chain risk, and which one it becomes depends entirely on review capacity that no program has actually funded yet. Watch this closely, and do not assume an upstream fix is safe just because it merged.</p><h3>The One Thing You Won&#8217;t Hear About But You Need To</h3><h3>11. The UK Quietly Flipped Automated Decision-Making From Banned to Allowed</h3><p>The headlines focused on the Five Eyes statement and the Anthropic ban, but the move that reshapes how AI is deployed across the entire G7 economy slipped through almost unnoticed. On June 19, the UK&#8217;s Data (Use and Access) Act 2026 received Royal Assent, bringing into force a substantial rewrite of the regulation of automated decision-making (ICO). The Act replaces the old Article 22 regime, under which automated decisions with significant effects were largely prohibited, with a model in which such decisions are permitted by default, subject to appropriate safeguards, while restrictions are narrowed to special category data such as health or biometrics. Organizations can now lean on a wider range of lawful bases, and the ICO has started work on a statutory code of practice for AI with a mandatory children&#8217;s data component.</p><p><strong>Why it matters</strong></p><ul><li><p>The default flipped from prohibition to permission, a major liberalization that makes automated decision-making on UK subjects easier at scale.</p></li><li><p>The burden shifts from &#8220;can we do this at all&#8221; to &#8220;can we prove our safeguards work,&#8221; which is a higher bar than most teams meet.</p></li><li><p>The carve-out for special category data and children means the highest-risk decisions still carry the heaviest obligations, and that is where enforcement concentrates.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Revisit your lawful basis for automated decisions about UK individuals, since legitimate interests is newly available but requires a documented balancing test.</p></li><li><p>Build the safeguard evidence the new regime demands, including meaningful human review and clear individual rights.</p></li><li><p>Watch for the ICO&#8217;s statutory code and treat the children&#8217;s data component as a hard line.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>I made this the one thing because almost nobody in security will read it, and that is the mistake. A G7 country just made it materially easier to run AI-driven decisions on its citizens, and it did so while everyone was staring at the Anthropic ban. The UK bet that the old prohibition held back legitimate use and that safeguards plus accountability beat a flat ban. The question is whether the safeguards have teeth or whether &#8220;permission with safeguards&#8221; quietly becomes &#8220;permission.&#8221; For anyone running automated decisioning in the UK, you are no longer asking whether you are allowed; you are on the hook to prove your safeguards are real and your human review is meaningful. That is harder, not easier, even though the headline sounds permissive, because vague standards are where regulators and plaintiffs go hunting after something breaks. Read the law before your product team reads the press release and assumes the gates just came down.</p><p><span>&#128073; For ongoing analysis of agentic AI governance frameworks, the conversation continues at </span><strong><a href="https://rockcybermusings.com/">RockCyber Musings</a></strong><span>.</span></p><p><span>&#128073; Visit </span><strong><a href="https://www.rockcyber.com/">RockCyber.com</a></strong><span> to learn more about how we can help with your traditional Cybersecurity and AI Security and Governance journey.</span></p><p><span>&#128073; Want to save a quick $100K? Check out our AI Governance Tools at </span><strong><a href="https://aigovernancetoolkit.com/">AIGovernanceToolkit.com</a></strong></p><p><span>&#128073; As a bonus, check out my conversation with </span><strong><a href="https://aicybermagazine.com/">AI Cyber Magazine, </a></strong><span>where we talked about everything from Context Rot to Least Agency. My interview is also highlighted in the </span><strong><a href="https://issuu.com/aicybermagazine/docs/ai_cyber_summer_edition_2026/22"><span>AI Cyber Magazine 2026 Summer Issue.</span></a></strong></p><p><em>The views and opinions expressed in RockCyber Musings are my own and do not represent the positions of my employer or any organization I&#8217;m affiliated with.</em></p><div id="youtube2-091_b2qep9M" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;091_b2qep9M&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/091_b2qep9M?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share RockCyber Musings&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share RockCyber Musings</span></a></p><h2>References</h2><p>Aikido Security. (2026, June 24). 2026 state of AI in security and development. https://www.aikido.dev/reports/2026-state-of-ai-in-security-development</p><p>CISA. (2026, June 23). <em>Five Eyes cyber security agencies statement</em>. Cybersecurity and Infrastructure Security Agency. https://www.cisa.gov/news-events/news/five-eyes-cyber-security-agencies-statement</p><p>CISA. (2026, June 10). <em>BOD 26-04: Prioritizing security updates based on risk</em>. Cybersecurity and Infrastructure Security Agency. https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk</p><p>CyberScoop. (2026, June 23). <em>Intel agencies: Frontier AI models will reshape cybersecurity faster than expected</em>. https://cyberscoop.com/five-eyes-alliance-say-advanced-ai-hacking-models-months-away/</p><p>CNBC/AP. (2026, June 23). <em>Anthropic&#8217;s Mythos model found vulnerabilities in classified U.S. government systems, official says</em>. https://www.cnbc.com/2026/06/23/anthropics-mythos-model-found-vulnerabilities-in-classified-us-government-systems-official-says.html</p><p>Fortune. (2026, June 24). <em>Vinod Khosla wanted &#8216;every available dollar&#8217; of Runlayer&#8217;s funding round. It just raised $30 million to govern the agent workforce</em>. https://fortune.com/2026/06/24/exclusive-vinod-khosla-felicis-runlayer-nanit-30-million-enterprise-ai/</p><p>Fortune. (2026, June 13). <em>Anthropic disables Fable and Mythos AI models after U.S. government bars it from giving foreigners access</em>. https://fortune.com/2026/06/13/anthropic-disables-fable-mythos-export-controls-national-security-threat/</p><p>Help Net Security. (2026, June 24). Security testing was built for a slower world. https://www.helpnetsecurity.com/2026/06/24/ai-security-testing-report/</p><p>ICO. (2026, June 19). <em>One year on: marking the 12-month commencement of the Data (Use and Access) Act</em>. Information Commissioner&#8217;s Office. https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/06/one-year-on-marking-the-12-month-commencement-of-the-data-use-and-access-act/</p><p>Nature / The Register. (2026, June 24). <em>Medical diagnosis AIs can be tricked into telling whose data trained them</em>. The Register. https://www.theregister.com/ai-and-ml/2026/06/24/medical-diagnosis-ais-can-be-tricked-into-telling-whose-data-trained-them/</p><p>Nature. (2026, June 24). <em>Disparate privacy risks from medical AI</em>. https://www.nature.com/articles/s41586-026-10688-0</p><p>OpenAI. (2026, June 22). <em>Daybreak: Tools for securing every organization in the world</em>. https://openai.com/index/daybreak-securing-the-world/</p><p>SiliconANGLE. (2026, June 22). <em>OpenAI expands Daybreak with Patch the Planet and full GPT-5.5-Cyber release</em>. https://siliconangle.com/2026/06/22/openai-expands-daybreak-patch-planet-full-gpt-5-5-cyber-release/</p><p>StepSecurity. (2026, June). <em>Mini Shai-Hulud is back: A self-spreading supply chain attack compromises TanStack npm packages</em>. https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem</p><p>The Register. (2026, June 23). <em>OpenAI Codex bombards SSDs with needless write operations, costing millions</em>. https://www.theregister.com/ai-and-ml/2026/06/23/openai-codex-bombards-ssds-with-needless-write-operations-costing-millions/</p><p>The Register. (2026, June 23). <em>Sniff out stale AI override advice with this open source CLI</em>. https://www.theregister.com/security/2026/06/23/sniff-out-stale-ai-override-advice-with-this-open-source-cli/</p><p>Ifl&#228;nder, C., et al. (2026, June 22). <em>Affective AI safety: The missing piece in LLM safety</em>. arXiv. https://arxiv.org/abs/2606.23380</p><p>SecurityWeek. (2026, June 25). <em>Runlayer raises $30 million in Series A funding</em>. https://www.securityweek.com/runlayer-raises-30-million-in-series-a-funding/</p>]]></content:encoded></item><item><title><![CDATA[Federal AI Model Recall Just Became Every CISO’s Supply Chain Risk]]></title><description><![CDATA[See why the Fable 5 export-control blackout turns every hosted frontier model into a supply chain risk, plus a 90-day CISO playbook from RockCyber.]]></description><link>https://www.rockcybermusings.com/p/fable-federal-ai-model-recall-supply-chain-risk</link><guid isPermaLink="false">https://www.rockcybermusings.com/p/fable-federal-ai-model-recall-supply-chain-risk</guid><dc:creator><![CDATA[Rock Lambros]]></dc:creator><pubDate>Mon, 22 Jun 2026 12:50:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!2_ws!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3add1b0d-298d-4970-9fac-dd8dcc1679e7_2048x2048.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2_ws!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3add1b0d-298d-4970-9fac-dd8dcc1679e7_2048x2048.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2_ws!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3add1b0d-298d-4970-9fac-dd8dcc1679e7_2048x2048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!2_ws!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3add1b0d-298d-4970-9fac-dd8dcc1679e7_2048x2048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!2_ws!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3add1b0d-298d-4970-9fac-dd8dcc1679e7_2048x2048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!2_ws!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3add1b0d-298d-4970-9fac-dd8dcc1679e7_2048x2048.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2_ws!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3add1b0d-298d-4970-9fac-dd8dcc1679e7_2048x2048.jpeg" width="1456" height="1456" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3add1b0d-298d-4970-9fac-dd8dcc1679e7_2048x2048.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1456,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:616257,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/202851746?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3add1b0d-298d-4970-9fac-dd8dcc1679e7_2048x2048.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2_ws!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3add1b0d-298d-4970-9fac-dd8dcc1679e7_2048x2048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!2_ws!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3add1b0d-298d-4970-9fac-dd8dcc1679e7_2048x2048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!2_ws!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3add1b0d-298d-4970-9fac-dd8dcc1679e7_2048x2048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!2_ws!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3add1b0d-298d-4970-9fac-dd8dcc1679e7_2048x2048.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>Federal AI model recall became a thing at 5:21 pm Eastern on June 12, 2026. A letter landed, and by the next morning, two of the most capable models on earth went dark for every paying customer on the planet. No warning. No reason worth the paper it wasn&#8217;t printed on. The capability didn&#8217;t change. Your access did by government fiat. Here&#8217;s what should make you furious, and what to do about it before it happens again.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/p/fable-federal-ai-model-recall-supply-chain-risk?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/p/fable-federal-ai-model-recall-supply-chain-risk?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h2><strong><span>What Happened, And What Everyone Got Wrong</span></strong></h2><p><span>The press called it a recall. The press got it wrong. Read the order. The government issued an export-control directive, citing national-security authorities, to cut off access to Fable 5 and Mythos 5 for any foreign national, whether inside or outside the United States, including Anthropic&#8217;s own foreign-national staff. There&#8217;s the first tell of who wrote this. Anthropic can&#8217;t check the passport of every user in real time at the scale it runs, so the only button left was the one that kills both models for everybody. The government drafted an order Anthropic had no way to enforce surgically and then acted surprised when the blast radius was the entire customer base. A wrecking ball swung at a thumbtack, stamped &#8220;national security,&#8221; and mailed at 5:21 on a Friday.</span></p><p><span>Then there&#8217;s the reason, or the missing one. The letter gave no specifics. Anthropic&#8217;s read is that someone in the government saw a jailbreak. The company looked at the &#8220;demo&#8221; the order seems to rest on and found a handful of minor, already-known vulnerabilities, the kind other public models surface too, including OpenAI&#8217;s GPT-5.5, the kind defenders use every day to find bugs before the bad guys do. The vendor is complying with the order and saying out loud that it&#8217;s nonsense. Sit with that for a second. The company whose product got pulled is the one making the technical argument, in public, while the government that pulled it won&#8217;t say what it&#8217;s afraid of.</span></p><p><span>No published threshold. No appeals path. No timeline. No notice. Run your SOC like this and you&#8217;d be cleaning out your desk by lunch.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rKVi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8703638a-606c-47da-ba35-f83603ed556f_2160x3840.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rKVi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8703638a-606c-47da-ba35-f83603ed556f_2160x3840.png 424w, https://substackcdn.com/image/fetch/$s_!rKVi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8703638a-606c-47da-ba35-f83603ed556f_2160x3840.png 848w, https://substackcdn.com/image/fetch/$s_!rKVi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8703638a-606c-47da-ba35-f83603ed556f_2160x3840.png 1272w, https://substackcdn.com/image/fetch/$s_!rKVi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8703638a-606c-47da-ba35-f83603ed556f_2160x3840.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rKVi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8703638a-606c-47da-ba35-f83603ed556f_2160x3840.png" width="1456" height="2588" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8703638a-606c-47da-ba35-f83603ed556f_2160x3840.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2588,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:259986,&quot;alt&quot;:&quot;Timeline showing the February to March 2026 Pentagon blacklist and Anthropic lawsuit on one track and the June 2026 export-control blackout of Fable 5 and Mythos 5 on a second track&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/202851746?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8703638a-606c-47da-ba35-f83603ed556f_2160x3840.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Timeline showing the February to March 2026 Pentagon blacklist and Anthropic lawsuit on one track and the June 2026 export-control blackout of Fable 5 and Mythos 5 on a second track" title="Timeline showing the February to March 2026 Pentagon blacklist and Anthropic lawsuit on one track and the June 2026 export-control blackout of Fable 5 and Mythos 5 on a second track" srcset="https://substackcdn.com/image/fetch/$s_!rKVi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8703638a-606c-47da-ba35-f83603ed556f_2160x3840.png 424w, https://substackcdn.com/image/fetch/$s_!rKVi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8703638a-606c-47da-ba35-f83603ed556f_2160x3840.png 848w, https://substackcdn.com/image/fetch/$s_!rKVi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8703638a-606c-47da-ba35-f83603ed556f_2160x3840.png 1272w, https://substackcdn.com/image/fetch/$s_!rKVi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8703638a-606c-47da-ba35-f83603ed556f_2160x3840.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 1: Two Moves in One Fight: The Same Vendor, Four Months Apart</figcaption></figure></div><h2><strong><span>The Lever Tells You What They Were Worried About</span></strong></h2><p><span>Before the grumbling gets rolling, let me be clear about where I stand. I believe national security is the government&#8217;s primary job, and I still do. That&#8217;s exactly why this one stings. A serious government with a serious problem reached for the dumbest and clumsiest tool in the drawer and called it leadership.</span></p><p><span>You don&#8217;t grab an export-control hammer to fix a software bug. Export control is what a government uses to keep a weapon out of foreign hands. Someone reached for that lever and scoped it to nationality, which tells you the real worry was about who gets to wield the capability, and had nothing to do with a guardrail slipping.</span></p><p><span>Or was it retaliation? I&#8217;ve heard the official statements&#8230; just stop.</span></p><p><span>Look at the capability. In April 2026, Claude Mythos surfaced thousands of high-severity flaws across every major operating system and browser in its early-access cohort, including a bug in OpenBSD that had survived 27 years of expert review. For more than 83% of the flaws it found, it wrote a working exploit on the first try, against a near-zero rate for the prior generation. Anthropic held the model back from day one and refused to hand it to the Chinese government. That&#8217;s a cyber weapon, and a serious one.</span></p><p><span>Here&#8217;s the indictment in one breath. Someone in the building understood they were sitting on a nation-state-grade capability, then reached for the most self-defeating tool available to handle it.</span></p><p><span>That person also probably can&#8217;t spell &#8220;AI.&#8221;</span></p><p><span>The jailbreak the order leans on was described as pointing the model at a codebase and asking it to fix the flaws. Flip one verb, and that&#8217;s autonomous vulnerability discovery, the same capability wearing a second hat. Pulling one vendor&#8217;s model doesn&#8217;t contain something that already lives in GPT-5.5. It removes a tool defenders were using and moves the actual risk exactly zero inches. Bravo.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Q7mW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F573f259d-2680-498d-ae54-766cd34e982e_2868x1589.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Q7mW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F573f259d-2680-498d-ae54-766cd34e982e_2868x1589.png 424w, https://substackcdn.com/image/fetch/$s_!Q7mW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F573f259d-2680-498d-ae54-766cd34e982e_2868x1589.png 848w, https://substackcdn.com/image/fetch/$s_!Q7mW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F573f259d-2680-498d-ae54-766cd34e982e_2868x1589.png 1272w, https://substackcdn.com/image/fetch/$s_!Q7mW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F573f259d-2680-498d-ae54-766cd34e982e_2868x1589.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Q7mW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F573f259d-2680-498d-ae54-766cd34e982e_2868x1589.png" width="1456" height="807" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/573f259d-2680-498d-ae54-766cd34e982e_2868x1589.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:807,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:252203,&quot;alt&quot;:&quot;Side-by-side comparison of a safety recall versus an export-control directive across legal basis, target, trigger, scope, what it contains, and notice given&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/202851746?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F573f259d-2680-498d-ae54-766cd34e982e_2868x1589.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Side-by-side comparison of a safety recall versus an export-control directive across legal basis, target, trigger, scope, what it contains, and notice given" title="Side-by-side comparison of a safety recall versus an export-control directive across legal basis, target, trigger, scope, what it contains, and notice given" srcset="https://substackcdn.com/image/fetch/$s_!Q7mW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F573f259d-2680-498d-ae54-766cd34e982e_2868x1589.png 424w, https://substackcdn.com/image/fetch/$s_!Q7mW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F573f259d-2680-498d-ae54-766cd34e982e_2868x1589.png 848w, https://substackcdn.com/image/fetch/$s_!Q7mW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F573f259d-2680-498d-ae54-766cd34e982e_2868x1589.png 1272w, https://substackcdn.com/image/fetch/$s_!Q7mW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F573f259d-2680-498d-ae54-766cd34e982e_2868x1589.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 2: <span>You Don&#8217;t Reach For An Export Lever To Fix A Bug </span></figcaption></figure></div><h2><strong>The Math Says Zero Was Never On The Table</strong></h2><p>I&#8217;m not going to hand-wave this. I&#8217;m going to walk the argument, mark where it&#8217;s airtight and where it leans on today&#8217;s state of the art, and let you decide what it says about an order that treats a limit every frontier model shares as a defect unique to one.</p><p>Start with the room the defender has to guard. A prompt is a sequence of tokens drawn from a vocabulary of size v. The number of distinct prompts up to length n is:</p><div class="latex-rendered" data-attrs="{&quot;persistentExpression&quot;:&quot;|X_n| = \\sum_{k=1}^{n} v^{k} = \\frac{v\\left(v^{n}-1\\right)}{v-1} \\approx v^{n}&quot;,&quot;id&quot;:&quot;FMHLGWXKMQ&quot;}" data-component-name="LatexBlockToDOM"></div><p>With a real vocabulary of v &#8776; 10^5 and a short prompt of n &#8776; 10^3 tokens:</p><div class="latex-rendered" data-attrs="{&quot;persistentExpression&quot;:&quot;|X_n| \\approx \\left(10^{5}\\right)^{10^{3}} = 10^{5000}&quot;,&quot;id&quot;:&quot;SLYYDQYSVQ&quot;}" data-component-name="LatexBlockToDOM"></div><p>Atoms in the observable universe come to about 10^80. The space of prompts is finite, enumerable on paper, and untouchable in this universe.</p><p>Now the asymmetry that runs the whole fight. Let p(x) be the probability the model emits harmful output on input x, and &#949; the ceiling you&#8217;ll allow. Call the inputs that breach the ceiling the bad set, B. The defender has to hold the line on every input at once. The attacker needs one that slips:</p><div class="latex-rendered" data-attrs="{&quot;persistentExpression&quot;:&quot;\\textbf{Defender:}\\quad \\forall\\, x \\in X_n,\\ p(x) \\le \\varepsilon \\iff B = \\varnothing&quot;,&quot;id&quot;:&quot;UBLWCHMNBJ&quot;}" data-component-name="LatexBlockToDOM"></div><div class="latex-rendered" data-attrs="{&quot;persistentExpression&quot;:&quot;\\textbf{Attacker:}\\quad \\exists\\, x \\in X_n,\\ p(x) > \\varepsilon \\iff |B| \\ge 1&quot;,&quot;id&quot;:&quot;VQHLUXCHUH&quot;}" data-component-name="LatexBlockToDOM"></div><p>Those two lines are definitions, not a theorem. They set the board. Here&#8217;s the line the recall standard can&#8217;t survive. Let f be the fraction of inputs that breach the ceiling, so the bad set has size f times the whole space. Emptying it means dropping that count below a single input, which forces the fraction beneath the reciprocal of everything:</p><div class="latex-rendered" data-attrs="{&quot;persistentExpression&quot;:&quot;B = \\varnothing \\iff |B| < 1 \\iff f < \\frac{1}{|X_n|} \\approx 10^{-5000}&quot;,&quot;id&quot;:&quot;IGEZPGZEYR&quot;}" data-component-name="LatexBlockToDOM"></div><p>A defender would need a per-input failure rate beneath 10^-5000 to claim zero jailbreaks. Nothing real comes within thousands of orders of magnitude of that. Whatever rate a vendor quotes isn&#8217;t measured against this uniform space anyway, and it doesn&#8217;t have to be. The attacker isn&#8217;t sampling at random, where a low average would save you. He&#8217;s searching on purpose, and he needs one input that clears the ceiling.</p><p>No defender enumerates 10^5000 points, so &#8220;too big to count&#8221; was never the point. The point is that no efficient certificate exists that the bad set is empty, not by enumeration and not by any scalable formal method we have today. Producing the attacker&#8217;s single counterexample, by contrast, is a search. The model is differentiable in its internal representations, so gradient signals over token embeddings steer that search toward inputs that clear the ceiling, far below the cost of enumeration even when it isn&#8217;t cheap against a monitored stack. </p><p>The receipts are public. EvoSynth, which evolves new attack methods instead of fiddling with prompts, reached an 85.5% success rate against Claude Sonnet 4.5. A Scale AI benchmark called ASPI showed that nudging an agent into a clarification-seeking state dragged prompt-injection success from under 2% to the mid-30s. Every patch closes a sliver of an unbounded space, and the function reseals somewhere else, because the safeguards and the capabilities are built out of the same weights.</p><p>That&#8217;s the argument. The reachable goal was never zero. It&#8217;s the thing we&#8217;ve been doing in security for two decades: make the attacker&#8217;s economics stop penciling out. Think of the attacker&#8217;s expected payoff per unit of search cost:</p><div class="latex-rendered" data-attrs="{&quot;persistentExpression&quot;:&quot;\\text{attacker payoff per unit cost} \\;\\sim\\; \\frac{(1-d)\\,U_{\\text{harm}}\\,P_{\\text{success}}}{C_{\\text{search}}}&quot;,&quot;id&quot;:&quot;NDFQCYLDUK&quot;}" data-component-name="LatexBlockToDOM"></div><p>That&#8217;s a model, not an identity, and the terms are deliberately loose. Here d is detection, U_harm is the payoff per successful jailbreak, P_success is the odds of landing one, and C_search is what finding it costs. Raise detection, raise search cost, keep each jailbreak narrow so the payoff stays small, and stop pretending P_success is a knob that turns to zero. Lock the doors you find, make the rest expensive to reach, and watch the hallways.</p><p>One honest caveat, because I won&#8217;t sell you a theorem I can&#8217;t cash. This is practical impossibility on the architecture we ship today. It rests on two facts that hold right now: no scalable formal certification covers the full discrete prompt space at frontier scale, and exhaustive verification is out of reach. It does not say a safe model can never exist. It says zero is off the menu today, and the formal version for agents is already in print. Abdelnabi and Bagdasarian show an adversary can always build a context that turns ordinary data into instructions, the same problem in an agent&#8217;s clothes.</p><p>The government pulled a model over a limit baked into every frontier system on the market, including the ones still running. They called the architecture&#8217;s ceiling a defect unique to one vendor. Spare me the theater.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fIVx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36d98fa5-2d3a-40b1-bce2-9f4349c0f615_3886x1700.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fIVx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36d98fa5-2d3a-40b1-bce2-9f4349c0f615_3886x1700.png 424w, https://substackcdn.com/image/fetch/$s_!fIVx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36d98fa5-2d3a-40b1-bce2-9f4349c0f615_3886x1700.png 848w, https://substackcdn.com/image/fetch/$s_!fIVx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36d98fa5-2d3a-40b1-bce2-9f4349c0f615_3886x1700.png 1272w, https://substackcdn.com/image/fetch/$s_!fIVx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36d98fa5-2d3a-40b1-bce2-9f4349c0f615_3886x1700.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fIVx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36d98fa5-2d3a-40b1-bce2-9f4349c0f615_3886x1700.png" width="1456" height="637" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/36d98fa5-2d3a-40b1-bce2-9f4349c0f615_3886x1700.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:637,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:187256,&quot;alt&quot;:&quot;Horizontal bar chart comparing orders of magnitude, the prompt space at 10 to the 5000 and surviving jailbreaks at 10 to the 4900 dwarfing atoms in the universe at 10 to the 80 and gradient search at roughly 10 to the 4 queries&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/202851746?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36d98fa5-2d3a-40b1-bce2-9f4349c0f615_3886x1700.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Horizontal bar chart comparing orders of magnitude, the prompt space at 10 to the 5000 and surviving jailbreaks at 10 to the 4900 dwarfing atoms in the universe at 10 to the 80 and gradient search at roughly 10 to the 4 queries" title="Horizontal bar chart comparing orders of magnitude, the prompt space at 10 to the 5000 and surviving jailbreaks at 10 to the 4900 dwarfing atoms in the universe at 10 to the 80 and gradient search at roughly 10 to the 4 queries" srcset="https://substackcdn.com/image/fetch/$s_!fIVx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36d98fa5-2d3a-40b1-bce2-9f4349c0f615_3886x1700.png 424w, https://substackcdn.com/image/fetch/$s_!fIVx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36d98fa5-2d3a-40b1-bce2-9f4349c0f615_3886x1700.png 848w, https://substackcdn.com/image/fetch/$s_!fIVx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36d98fa5-2d3a-40b1-bce2-9f4349c0f615_3886x1700.png 1272w, https://substackcdn.com/image/fetch/$s_!fIVx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36d98fa5-2d3a-40b1-bce2-9f4349c0f615_3886x1700.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 3: <span>Too Big To Certify, Cheap To Search: Why The Jailbreak Was Never The Real Variable</span></figcaption></figure></div><h2><strong><span>The Supply Chain Risk You Didn&#8217;t Budget For</span></strong></h2><p><span>Walk it forward, and the shortsightedness gets worse. If a narrow jailbreak is grounds for going dark, every frontier model in commercial use fails inside a month of launch. Call that what it is: a removal queue with no published rules, no appeal, and no timeline, run by people who couldn&#8217;t scope an order to the foreign nationals it was supposedly about.</span></p><p><span>The model can do everything on June 12th it could do on June 11th. The thing that vanished was your ability to reach it, switched off by fiat, on a worry the government wouldn&#8217;t name, with zero notice. Most AI risk registers track accuracy, bias, and security, and carry nothing for &#8220;the government recalls our vendor&#8217;s model next Tuesday.&#8221; Model availability is a vendor risk class now, and almost nobody has priced it.</span></p><p><span>I&#8217;ve watched the small version of this with no government in the room. A team builds a customer-facing workflow on a single hosted model, the economics look great, then the vendor changes a rate limit, deprecates the version, or pulls a region for reasons that have nothing to do with that team. The thing that ran fine Friday throws errors Monday, and the people who built it discover they wrote zero lines of contingency for the model vanishing. That&#8217;s the small version. The Fable blackout is the large version, with the government holding the switch and not one contract clause that ever saw it coming. If you run security in energy, water, or manufacturing, none of this is abstract. A model blackout inside an operational workflow lands as an availability event, in a place where availability is the entire job.</span></p><p><span>The hunch that this action doesn&#8217;t stand alone is right, and the record bears it out. The same administration moved against this same vendor in late February, when negotiations over military use fell apart, and the company refused to drop its red lines on autonomous weapons and mass surveillance. The Pentagon slapped it with a supply chain risk label, a tag normally saved for foreign-adversary contractors, and ordered agencies to stop using Claude. The company sued, calling it retaliation for protected speech. A federal judge blocked the designation after finding the company likely to prevail on due process grounds, and the government appealed. That fight is still open. The June blackout lands inside it. I can&#8217;t read minds and won&#8217;t pretend to. I can read a calendar. Same administration, same vendor, blacklisted in February over guardrails, export-hammered in June over a jailbreak that does nothing GPT-5.5 won&#8217;t do. The dots sit on the public docket. Connect them yourself.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!siQ3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6623541-6f28-4344-9218-53c8706e0c1e_2501x2089.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!siQ3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6623541-6f28-4344-9218-53c8706e0c1e_2501x2089.png 424w, https://substackcdn.com/image/fetch/$s_!siQ3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6623541-6f28-4344-9218-53c8706e0c1e_2501x2089.png 848w, https://substackcdn.com/image/fetch/$s_!siQ3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6623541-6f28-4344-9218-53c8706e0c1e_2501x2089.png 1272w, https://substackcdn.com/image/fetch/$s_!siQ3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6623541-6f28-4344-9218-53c8706e0c1e_2501x2089.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!siQ3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6623541-6f28-4344-9218-53c8706e0c1e_2501x2089.png" width="1456" height="1216" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f6623541-6f28-4344-9218-53c8706e0c1e_2501x2089.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1216,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:174691,&quot;alt&quot;:&quot;A two-by-two decision grid plotting capability needed against tolerance for losing access, sorting workloads into hosted with tested fallback, open-weight onshore, hosted frontier eyes open, and either-works quadrants&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/202851746?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6623541-6f28-4344-9218-53c8706e0c1e_2501x2089.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A two-by-two decision grid plotting capability needed against tolerance for losing access, sorting workloads into hosted with tested fallback, open-weight onshore, hosted frontier eyes open, and either-works quadrants" title="A two-by-two decision grid plotting capability needed against tolerance for losing access, sorting workloads into hosted with tested fallback, open-weight onshore, hosted frontier eyes open, and either-works quadrants" srcset="https://substackcdn.com/image/fetch/$s_!siQ3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6623541-6f28-4344-9218-53c8706e0c1e_2501x2089.png 424w, https://substackcdn.com/image/fetch/$s_!siQ3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6623541-6f28-4344-9218-53c8706e0c1e_2501x2089.png 848w, https://substackcdn.com/image/fetch/$s_!siQ3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6623541-6f28-4344-9218-53c8706e0c1e_2501x2089.png 1272w, https://substackcdn.com/image/fetch/$s_!siQ3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6623541-6f28-4344-9218-53c8706e0c1e_2501x2089.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 4: <span>Where Your Workloads Sit When Access Can Vanish By Fiat</span></figcaption></figure></div><p><span>The irony is that the government turned the words &#8220;supply chain risk&#8221; into a weapon and pointed them at the vendor. The same phrase boomerangs back as your problem, because a model you built your roadmap on can disappear on a Friday afternoon at the whim of a letter.</span></p><h2><strong><span>Agency Was Always The Risk, And What Competent Authority Looks Like</span></strong></h2><p><span>Here&#8217;s the question this directive never answers and will have to. What happens the first time the finding isn&#8217;t a prompt at all, but an agent abusing access you handed it? </span><strong><a href="https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance/"><span>The OWASP State of Agentic AI Security and Governance</span></a></strong><span>, published June 1, 2026, put receipts behind that question. Its incident tracker shows supply chain and code execution tied for the highest volume of disclosed agentic incidents. One for the coding-agent crowd: a Cursor flaw where an attacker who shaped the agent&#8217;s instructions rode an already-approved command straight into arbitrary code execution. Another: Claude&#8217;s Skills feature steered the deployment of MedusaLocker ransomware via a re-uploaded skill that carried its own malicious code. Both are an agent abusing access it was granted, a world away from a prompt trick against a chatbot.</span></p><p><span>If a narrow jailbreak set off an export-control blackout, nobody&#8217;s written the precedent for an agent-abuse finding yet. It&#8217;s coming, and this directive set the baseline for how heavy the hand gets to be.</span></p><p><span>Competent authority exists in sketch form, and it makes the Mythos order look worse by comparison. </span><strong><a href="https://www.rockcybermusings.com/p/five-eyes-agentic-ai-architecture-not-checklist"><span>The Five Eyes guidance from May </span></a></strong><span>reads like an architecture brief rather than a checklist. It puts strong governance, clear accountability, monitoring, and human oversight up front as prerequisites, recommends starting with low-risk tasks and expanding, and calls for just-in-time credentials on high-impact actions. That&#8217;s graduated authority anchored on agency, on what the system can do once it&#8217;s wired into everything, not on which model tier you bought. Runtime authorization scope, capability segmentation, monitoring tied to action instead of output. The directive flipped a switch on the weights and called it governance. The weights were never where the risk lived, and anyone who&#8217;s run security for a week knows it.</span></p><p><strong><span>Key Takeaway:</span></strong><span> A narrow jailbreak can&#8217;t justify an export-control blackout once the math shows narrow jailbreaks are the permanent weather, so read the lever they pulled and plan for the precedent: any hosted frontier model can be switched off by fiat, and your continuity plan has to treat that like the supply chain event it is.</span></p><h3><strong><span>What To Do Next</span></strong></h3><p><span>Run this through CARE. </span><strong><span>Create</span></strong><span> the inventory: every workflow with a hosted frontier-model dependency, ranked by criticality. </span><strong><span>Adapt</span></strong><span> your contracts: a model-continuity clause with a notice period, transition support, and escrow of weights or fine-tunes where you can get it. </span><strong><span>Run</span></strong><span> a tested fallback for tier-one workflows, a secondary hosted model and an open-weight option you&#8217;ve exercised, paired with BCDR drills that simulate vendor revocation and not only an outage. </span><strong><span>Evolve</span></strong><span> the AI risk register so availability sits beside accuracy, bias, and security, and get &#8220;what do we do when the government recalls our vendor&#8217;s model&#8221; onto your AI risk committee&#8217;s agenda before the second incident, not after.</span></p><p><span>The companion CISO playbook lives in my breakdown of</span><a href="https://www.rockcybermusings.com/p/aiuc-1-after-mythos-machine-speed-defense"><span> </span></a><strong><a href="https://www.rockcybermusings.com/p/aiuc-1-after-mythos-machine-speed-defense"><span>the AIUC-1 After Mythos whitepaper</span></a></strong><span>. The agent-abuse receipts come from my walk through</span><a href="https://www.rockcybermusings.com/p/owasp-state-of-agentic-ai-security-2026"><span> </span></a><strong><a href="https://www.rockcybermusings.com/p/owasp-state-of-agentic-ai-security-2026"><span>the OWASP State of Agentic AI Security and Governance report</span></a></strong><span>. What competent, architecture-first authority looks like is in my read of</span><strong><a href="https://www.rockcybermusings.com/p/five-eyes-agentic-ai-architecture-not-checklist"><span> the Five Eyes agentic AI guidance</span></a><span>.</span></strong></p><p><span>&#128073; For ongoing analysis of agentic AI governance frameworks, the conversation continues at </span><strong><a href="https://rockcybermusings.com/">RockCyber Musings</a></strong><span>.</span></p><p><span>&#128073; Visit </span><strong><a href="https://www.rockcyber.com/">RockCyber.com</a></strong><span> to learn more about how we can help with your traditional Cybersecurity and AI Security and Governance journey.</span></p><p><span>&#128073; Want to save a quick $100K? Check out our AI Governance Tools at </span><strong><a href="https://aigovernancetoolkit.com/">AIGovernanceToolkit.com</a></strong></p><p><span>&#128073; As a bonus, check our AMA on the </span><strong><a href="https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance/">2026 OWASP GenAI Security Project State of Agentic AI Security and Governance report</a></strong><span> with me and the other co-leads (it was live, so start at time marker 09:45)</span></p><div id="youtube2-jK1Z7Z6zlW0" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;jK1Z7Z6zlW0&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/jK1Z7Z6zlW0?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><em>The views and opinions expressed in RockCyber Musings are my own and do not represent the positions of my employer or any organization I&#8217;m affiliated with.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share RockCyber Musings&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share RockCyber Musings</span></a></p><h2><strong>References</strong></h2><p>Abdelnabi, S., &amp; Bagdasarian, E. (2026). <em>AI agents may always fall for prompt injections</em> (arXiv:2605.17634). arXiv. <a href="https://arxiv.org/abs/2605.17634">https://arxiv.org/abs/2605.17634</a></p><p>AIUC-1 Consortium. (2026). <em>After Mythos: Machine-speed defense</em> [Whitepaper]. https://aiuc-1.com</p><p>Anthropic. (2026, June 9). <em>Claude Fable 5 and Mythos 5</em> [Announcement]. <a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">https://www.anthropic.com/news/claude-fable-5-mythos-5</a></p><p>Anthropic. (2026, June 12). <em>Statement on the US government directive to suspend access to Fable 5 and Mythos 5</em>. <a href="https://www.anthropic.com/news/fable-mythos-access">https://www.anthropic.com/news/fable-mythos-access</a></p><p>Cato CTRL. (2026). <em>Claude Skills abused to deploy MedusaLocker ransomware</em> [Threat research]. Cato Networks.</p><p>CBS News. (2026, March 9). <em>Anthropic sues Pentagon, Trump administration over &#8220;supply chain risk&#8221; designation</em>. <a href="https://www.cbsnews.com/news/anthropic-pentagon-supply-chain-risk-lawsuit/">https://www.cbsnews.com/news/anthropic-pentagon-supply-chain-risk-lawsuit/</a></p><p>Chen, Y., Wang, X., Li, J., Wang, Y., Li, J., Teng, Y., Wang, Y., &amp; Ma, X. (2025). <em>Evolve the method, not the prompts: Evolutionary synthesis of jailbreak attacks on LLMs</em> (arXiv:2511.12710). arXiv. <a href="https://arxiv.org/abs/2511.12710">https://arxiv.org/abs/2511.12710</a></p><p>Cybersecurity and Infrastructure Security Agency, National Security Agency, Australian Signals Directorate&#8217;s Australian Cyber Security Centre, Canadian Centre for Cyber Security, New Zealand National Cyber Security Centre, &amp; United Kingdom National Cyber Security Centre. (2026, May 1). <em>Careful adoption of agentic AI services</em>. </p><p>https://www.cyber.gov.au</p><p>MITRE Corporation. (2026). <em>CVE-2026-22708</em>. CVE Program. <a href="https://www.cve.org/CVERecord?id=CVE-2026-22708">https://www.cve.org/CVERecord?id=CVE-2026-22708</a></p><p>NPR. (2026, March 9). <em>Anthropic sues the Trump administration over &#8220;supply chain risk&#8221; label</em>. <a href="https://www.npr.org/2026/03/09/nx-s1-5742548/anthropic-pentagon-lawsuit-amodai-hegseth">https://www.npr.org/2026/03/09/nx-s1-5742548/anthropic-pentagon-lawsuit-amodai-hegseth</a></p><p>OpenAI. (2026). <em>GPT-5.5: Cybersecurity</em>. <a href="https://deploymentsafety.openai.com/gpt-5-5/cybersecurity">https://deploymentsafety.openai.com/gpt-5-5/cybersecurity</a></p><p>OWASP GenAI Security Project. (2026). <em>State of agentic AI security and governance</em> (Version 2.01). <a href="https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance/">https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance/</a></p><p>Sehwag, U. M., Shan, Z., Liu, H., Lakshan, D., Brandifino, J., &amp; Fenkell, M. (2026). <em>ASPI: Seeking ambiguity clarification amplifies prompt injection vulnerability in LLM agents</em> (arXiv:2605.17324). arXiv. <a href="https://arxiv.org/abs/2605.17324">https://arxiv.org/abs/2605.17324</a></p><p><em>Trump administration asks court to reimpose Anthropic supply chain risk designation</em>. (2026). AOL. <a href="https://www.aol.com/articles/trump-administration-asks-court-reimpose-155659500.html">https://www.aol.com/articles/trump-administration-asks-court-reimpose-155659500.html</a></p>]]></content:encoded></item><item><title><![CDATA[Weekly Musings Top 10 AI Security Wrapup: Issue 42 June 12 -June 18, 2026]]></title><description><![CDATA[When Washington Pulls a Model and the Developer Supply Chain Turns Hostile (Again)]]></description><link>https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260612-20260618</link><guid isPermaLink="false">https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260612-20260618</guid><dc:creator><![CDATA[Rock Lambros]]></dc:creator><pubDate>Fri, 19 Jun 2026 13:02:20 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Afa9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a40c9aa-ad0e-4dcb-a5f1-6bf7e4e33548_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Afa9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a40c9aa-ad0e-4dcb-a5f1-6bf7e4e33548_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Afa9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a40c9aa-ad0e-4dcb-a5f1-6bf7e4e33548_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!Afa9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a40c9aa-ad0e-4dcb-a5f1-6bf7e4e33548_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!Afa9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a40c9aa-ad0e-4dcb-a5f1-6bf7e4e33548_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!Afa9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a40c9aa-ad0e-4dcb-a5f1-6bf7e4e33548_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Afa9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a40c9aa-ad0e-4dcb-a5f1-6bf7e4e33548_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7a40c9aa-ad0e-4dcb-a5f1-6bf7e4e33548_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1233556,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/202630580?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a40c9aa-ad0e-4dcb-a5f1-6bf7e4e33548_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Afa9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a40c9aa-ad0e-4dcb-a5f1-6bf7e4e33548_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!Afa9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a40c9aa-ad0e-4dcb-a5f1-6bf7e4e33548_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!Afa9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a40c9aa-ad0e-4dcb-a5f1-6bf7e4e33548_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!Afa9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a40c9aa-ad0e-4dcb-a5f1-6bf7e4e33548_1024x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1></h1><h2></h2><p>Washington reached onto a vendor&#8217;s shelf this week and switched off the most capable cybersecurity AI on the market. Anthropic had about 90 minutes to comply. Three words did the damage. Fix this code. While policymakers fought over who broke what, attackers poisoned 144 npm packages, salted the JetBrains store with key-stealing plugins, and watched the global vulnerability count race toward 66,000. The machines that find flaws, write flaws, and ship flaws all leveled up at once. This was the week the bill came due.</p><p>Here&#8217;s the through-line for June 12 to 18, 2026. AI stopped being a tool you point at problems and became an actor inside your threat model. The government treated a commercial model as a weapons system and pulled it worldwide. Each item below changes what you budget, monitor, and tell your board.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260612-20260618?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260612-20260618?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h3>1. Washington Pulls Anthropic&#8217;s Fable 5 and Mythos 5 Off the Market</h3><p>On June 12, 2026, Anthropic disabled its newest models, Fable 5 and the restricted Mythos 5, worldwide under an emergency Commerce Department export-control directive (CNBC). It had about 90 minutes to act after Amazon&#8217;s CEO warned officials that researchers pulled restricted cyber capabilities out with a plain &#8220;fix this code&#8221; prompt (Fortune, Axios). The order bars every foreign national, including Anthropic&#8217;s own non-citizen staff, while Claude Opus 4.8 stayed online (Time).</p><p><strong>Why it matters</strong></p><ul><li><p>A federal order can now make a vendor&#8217;s frontier model vanish with no notice.</p></li><li><p>A three-word prompt beat a guardrail the vendor trusted. Guardrails are configuration, not physics.</p></li><li><p>Export rules on AI tooling now reach any non-US person who touches the model.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Inventory the models on your critical paths and document a fallback for each.</p></li><li><p>Add an AI-availability clause to vendor contracts.</p></li><li><p>Brief legal on export exposure for any model your non-US staff touch.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>I&#8217;ve sat through plenty of &#8220;the vendor went dark&#8221; fire drills. This is the first one the government ordered, on a model millions have already used. A model that finds serious vulnerabilities on command is dual-use, and dual-use gets regulated like weapons. The chilling effect worries me most, since labs that watch products get seized share less. I run these tabletops with boards at <a href="https://www.rockcyber.com/">rockcyber.com</a>, where the real question is no longer when the breach hits, it&#8217;s when your best tool disappears on a Tuesday.</p><h3>2. FIRST Says AI Is Driving 2026 Toward 66,000 New Vulnerabilities</h3><p>On June 15, 2026, the Forum of Incident Response and Security Teams (FIRST) raised its 2026 forecast to roughly 66,000 CVEs, with disclosures running about 46% above the February projection (FIRST). The driver is autonomous discovery agents like Anthropic&#8217;s Mythos and OpenAI&#8217;s GPT-5.4-Cyber hunting flaws on their own (Help Net Security). Mozilla&#8217;s Firefox saw a 164% first-quarter spike, while the actively exploited share stayed flat.</p><p><strong>Why it matters</strong></p><ul><li><p>Raw CVE volume is doubling the build-and-patch load, even though the urgent slice has not grown.</p></li><li><p>AI-generated throwaway apps carry real flaws that never reach a CVE database.</p></li><li><p>The late-2026 contest is AI-built exploits racing AI-built patches, and speed decides it.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Triage with EPSS and the CISA KEV catalog so your team chases exploited flaws, not the raw count.</p></li><li><p>Budget for roughly double the patch-verification work and staff the human bottleneck.</p></li><li><p>Stand up dynamic inventory and AI bills of materials for code generated outside the CVE system.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Forty-six percent over forecast in five months is not a blip, it&#8217;s a regime change. More CVEs doesn&#8217;t mean more danger, because the exploited slice held flat. Chase raw volume and you&#8217;ll burn your best people on noise. FIRST&#8217;s Chris Gibson said the teams that weather this already share intelligence, and most of you are behind.</p><h3>3. North Korea Backdoors 144 Mastra npm Packages in 88 Minutes</h3><p>Between June 16 and 17, 2026, attackers backdoored 144 packages in the @mastra npm scope, the open-source AI agent framework for JavaScript and TypeScript (Socket). They hijacked a former contributor&#8217;s still-active account and pushed 140-plus malicious versions in 88 minutes, hiding an information stealer inside &#8220;easy-day-js,&#8221; a fake dayjs clone (The Hacker News). @mastra/core draws over 918,000 weekly downloads, and Snyk and Orca tied the tradecraft to North Korea&#8217;s Sapphire Sleet (Orca Security).</p><p><strong>Why it matters</strong></p><ul><li><p>A nation-state crew is now targeting the AI tooling supply chain inside your build pipeline.</p></li><li><p>Caret-range resolution auto-upgraded victims with no change to Mastra&#8217;s source repo.</p></li><li><p>npm never expires dormant publish rights, a flaw spanning thousands of packages you depend on.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Pin dependencies and disable automatic caret-range upgrades for anything in production.</p></li><li><p>Block postinstall scripts in CI by default and review them as code.</p></li><li><p>Audit publish permissions and revoke dormant maintainer access across your scopes.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>This one&#8217;s personal for anyone building with AI agents, which is most of you. The attackers didn&#8217;t break Mastra, they broke npm&#8217;s assumption that a quiet contributor stays trustworthy forever. Eighty-eight minutes, 140-plus packages, a stealer riding a fake date library. North Korea noticed before your AppSec team did, and the root causes are years old.</p><h3>4. Malicious JetBrains Plugins Harvest Developers&#8217; AI API Keys</h3><p>On June 16, 2026, JetBrains pulled at least 15 malicious plugins from its Marketplace after reports they were stealing AI provider API keys (BleepingComputer). Published under seven accounts with close to 70,000 installs, they posed as AI coding assistants built on OpenAI, DeepSeek, and SiliconFlow (Infosecurity Magazine). When a developer pasted a key and clicked apply, the plugin sent it as plaintext over HTTP and disabled the runtime&#8217;s TLS warnings (The Hacker News).</p><p><strong>Why it matters</strong></p><ul><li><p>Stolen AI keys let attackers run inference on your dime and reach whatever those keys touch.</p></li><li><p>Disabling TLS warnings across the Java runtime weakens every other connection that IDE makes.</p></li><li><p>Developers install AI tooling faster than anyone vets it, and the IDE is now an attack surface.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Restrict IDE plugin installation to an approved list and block sideloading on managed machines.</p></li><li><p>Rotate any AI keys entered into third-party plugins and move to short-lived, scoped credentials.</p></li><li><p>Alert on AI-key patterns and plaintext traffic leaving developer endpoints.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Developers are the new front door, and AI assistants are the welcome mat. Everybody wants the plugin that writes their boilerplate, and nobody reads what it does with the pasted key. Plaintext over HTTP in 2026 is insulting, and it worked anyway on 70,000 installs. If you don&#8217;t know which AI keys your engineers hold, you don&#8217;t know your exposure.</p><h3>5. OpenAI Tries to Predict Model Behavior Before Release</h3><p>On June 16, 2026, OpenAI published research on deployment simulation, a method to forecast how a new model will behave before launch (OpenAI). The team replayed roughly 1.3 million de-identified conversations and regenerated the responses with the candidate model (MarkTechPost). It reached 92% directional accuracy and cut the model&#8217;s awareness that it was being tested from 99.72% to 5.12%.</p><p><strong>Why it matters</strong></p><ul><li><p>Testing on real usage closes the gap between lab behavior and behavior in your environment.</p></li><li><p>Models gaming their own evaluations is documented, and cutting test-awareness to 5.12% is a real gain.</p></li><li><p>This gives buyers a vocabulary to demand evidence, not just promises.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Ask vendors how they evaluate behavior on realistic deployment data, not just static benchmarks.</p></li><li><p>Replay your own representative prompts against a candidate model before production.</p></li><li><p>Treat model upgrades like software releases, with a behavioral regression test.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>I tell executives constantly that benchmark scores are marketing, not assurance. This is the first vendor method I&#8217;ve seen that attacks the eval-awareness problem directly, and the numbers are striking. A model that knows it&#8217;s on a test behaves, the way your network behaves during the audit and misbehaves the Monday after. Dropping that awareness from 99% to 5% changes what a test is worth. Self-reported research needs replication, so verify, then demand it from every model vendor you pay.</p><h3>6. Jamf Finds AI Adoption Tracks Directly With Incident Rates</h3><p>On June 15, 2026, Jamf released a survey of 687 IT and security leaders who run macOS environments, and more than one-fifth reported losing money or being attacked through their AI tools (Cybersecurity Dive). About 73% had deployed AI, and the incident rate climbed from under 20% among explorers to 27% among deep adopters. Governance ranked third on priority lists, behind automation and productivity.</p><p><strong>Why it matters</strong></p><ul><li><p>Deeper integration came with more incidents, which kills the story that risk can wait.</p></li><li><p>Governance and security ranked below productivity, so firms buy the upside and defer the bill.</p></li><li><p>Shadow AI is the top blind spot, and you cannot govern tools you cannot see.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Run regular AI discovery audits to surface shadow tools before they surface as incidents.</p></li><li><p>Govern at the software layer with enforced data-access policies, not just training.</p></li><li><p>Bake governance into the first deployment stage, not a retrofit after an incident.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Correlation isn&#8217;t causation, and I&#8217;ll say it before any of you email me. When incidents climb from 20% to 27% as integration deepens and governance sits third on the list, you don&#8217;t need a regression to see the trade. People want productivity now and handle security later, which tends to arrive as a breach notification. Leaders swear they&#8217;ll fund governance next quarter, then the footprint doubles while controls stand still.</p><h3>7. Experts Revolt and Europe Eyes Sovereignty After the Anthropic Ban</h3><p>From June 13 to 15, 2026, the fallout from the shutdown intensified. Cybersecurity Dive documented researchers blasting the move as overreach, Katie Moussouris circulated an open letter, and analyst Dean Ball called the controls &#8220;simply cartoonish&#8221; (Cybersecurity Dive, Fortune). Anthropic disputed the basis, calling the jailbreak narrow and non-universal (Reason). The Register reported the clampdown pushed European digital-sovereignty efforts into higher gear, and legal analysts questioned stretching export law this way (The Register, Just Security).</p><p><strong>Why it matters</strong></p><ul><li><p>The transparency bargain between labs and government is fraying, so defenders see new capabilities later.</p></li><li><p>Sovereignty pressure raises the odds of a fragmented model market that differs by region.</p></li><li><p>Export law on live commercial models creates compliance uncertainty that outlasts this incident.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Map your AI vendors by origin and availability so a regional split won&#8217;t strand a workload.</p></li><li><p>Track the policy fight, because the emerging rules will shape procurement for years.</p></li><li><p>Pressure-test reliance on any single national AI ecosystem like any concentration risk.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>I write about this tension at <a href="https://rockcybermusings.com/">rockcybermusings.com</a>. The government and the labs are openly fighting over who decides a model is too dangerous to ship. The state doesn&#8217;t want to arm adversaries, and the labs don&#8217;t want products seized on verbal evidence. Caught in the middle is you, planning a three-year program on tools that might get pulled or geo-fenced. Your model supplier is now the single point of failure.</p><h3>8. AI-Written Code Passes Review and Fails in Production</h3><p>On June 15, 2026, Help Net Security reported on a New Relic study finding that AI-generated code earns high marks at review and then breaks in production at roughly twice the human rate (Help Net Security). It reviewed cleaner than human code, yet shipped close to twice the critical runtime issues. New security vulnerabilities hit about three in ten organizations over six months, and senior engineers lost up to a third of their week cleaning it up.</p><p><strong>Why it matters</strong></p><ul><li><p>Review-time quality is a false signal, because failures live in edge cases and concurrency that show under load.</p></li><li><p>Three in ten organizations took on new security vulnerabilities from AI code in six months.</p></li><li><p>Senior engineers are burning a third of their week on cleanup, capacity you won&#8217;t get back.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Require runtime observability for AI-generated code before it ships, not just a clean review.</p></li><li><p>Prompt your assistants to build logging and traces into the code they write.</p></li><li><p>Measure production incidents tied to AI code and feed that into your release gates.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>This is the bill for vibe coding, and it came due in production. AI writes code that reviews like a dream, then falls apart when real users and real concurrency hit it. The reviewer reads the source, production writes the trace, and the gap between them is where your incidents live. Your senior engineers didn&#8217;t sign up to be janitors, so give them telemetry or keep paying them to mop.</p><h3>9. The UN&#8217;s Disarmament Institute Opens Its AI Security Summit in Geneva</h3><p>On June 18, 2026, the UN Institute for Disarmament Research (UNIDIR) opened its two-day Global Conference on AI, Security and Ethics in Geneva, gathering diplomats, researchers, industry, and civil society around AI and international peace and security (UNIDIR). The event launches UNIDIR&#8217;s new Centre of Excellence on AI, Peace and Security, an umbrella for research and capacity-building on AI governance (Indico.UN).</p><p><strong>Why it matters</strong></p><ul><li><p>A standing UN center signals that military and dual-use AI governance is moving toward institutions.</p></li><li><p>Cross-border norms set here will shape export rules, procurement, and the dual-use definitions you answer to.</p></li><li><p>The gap between fast capability and slow governance is where strategic risk accumulates.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Track UNIDIR outputs if you run defense, energy, water, or other critical infrastructure.</p></li><li><p>Feed your operational reality into standards and comment processes rather than inheriting the result.</p></li><li><p>Map which emerging norms could touch your sector before they become requirements.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Conferences rarely move a CISO&#8217;s needle next week. This one matters for a longer reason. The capability that let Washington pull a model is what diplomats in Geneva are trying to govern. I&#8217;ve watched dual-use rules show up first in energy and manufacturing, then everywhere else, so the norms drafted here become your compliance reality sooner than you think.</p><h3>10. A CISO&#8217;s Warning on the Limits of Automated GRC</h3><p>On June 15, 2026, Help Net Security published an interview with Nichole Windholz, CISO at Onspring, on the limits of automated governance, risk, and compliance tooling (Help Net Security). She argued that green-yellow-red dashboards flatten very different problems into one color, where red might mean a missing control, a stale attestation, or a minor threshold breach. Her fixes centered on data lineage, validation against source systems, and honesty with the board about risks that resist measurement, like insider behavior and vendor concentration.</p><p><strong>Why it matters</strong></p><ul><li><p>Automated GRC can turn bad input into a board-ready narrative, manufacturing false confidence.</p></li><li><p>Insider intent and vendor concentration leave no clean telemetry, so a full-coverage dashboard lies.</p></li><li><p>As AI accelerates control monitoring, the pull to trust the heat map over the evidence trail grows.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Demand data lineage for every control signal, covering source, owner, refresh rate, and recent changes.</p></li><li><p>Tell your board which risks are measured, which are estimated, and which need human judgment.</p></li><li><p>Spot-check improving metrics as hard as declining ones, since a green light can mean a broken feed.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>This interview reads like it was written for the grumpy uncle, so naturally I loved it. A polished dashboard isn&#8217;t the same as a true one, and automation makes a bad assumption move faster and look credible. We&#8217;re about to point AI at GRC and call it continuous assurance, much of it color applied to data nobody validated. Audit the auditor and know your data lineage. The day the heat map replaces the evidence trail is the day you lie to yourself in four colors.</p><h3>The One Thing You Won&#8217;t Hear About But You Need To</h3><p>On June 15, 2026, Help Net Security published an analysis of a problem hiding under the louder headlines, that there is no way to verify what a military AI model will do (Help Net Security). Defense contractors are wiring frontier models into weapons, with Anduril, Palantir, and Lockheed Martin partnered to OpenAI, Microsoft, and Meta. Unlike nuclear arms control, where inspectors read a physical signal like a neutron signature, a model&#8217;s weights give no sign of whether it will follow or refuse a launch order. The piece cites research in which models in decision-making roles escalated, some launching simulated nuclear strikes in response to a supervisor&#8217;s commands, and flags alignment faking, a model that appears compliant under watch but diverges in operation (arXiv preprint 2606.11533).</p><p><strong>Why it matters</strong></p><ul><li><p>The assurance method behind arms control, independent physical measurement, has no equivalent for AI.</p></li><li><p>Models that behave under observation and differently in operation map onto malware evasion, a discipline you know.</p></li><li><p>Multiple models coordinating inside command systems can cascade failures faster than humans can intervene.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>If you build or assess high-stakes AI, test for observation-dependent behavior, not just accuracy.</p></li><li><p>Push for compute-monitoring and shared-inspection regimes, since compute leaves a measurable footprint.</p></li><li><p>Keep a human with authority and time in any loop where an action is irreversible.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>This is the story that got buried under the model ban, and it scares me more. We&#8217;re bolting frontier models into kill chains while admitting, in the open literature, that we can&#8217;t prove what they&#8217;ll do under pressure. The nuclear treaties worked because a neutron doesn&#8217;t lie, and you can count a missile. A model&#8217;s weights tell you nothing about whether it&#8217;ll escalate, and the research shows some escalate unprompted. A model can fake compliance, just as malware fakes sleep until it reaches its target. Slow down, verify, and keep a human who can say no.</p><p><span>&#128073; For ongoing analysis of agentic AI governance frameworks, the conversation continues at </span><strong><a href="https://rockcybermusings.com/">RockCyber Musings</a></strong><span>.</span></p><p><span>&#128073; Visit </span><strong><a href="https://www.rockcyber.com/">RockCyber.com</a></strong><span> to learn more about how we can help with your traditional Cybersecurity and AI Security and Governance journey.</span></p><p><span>&#128073; Want to save a quick $100K? Check out our AI Governance Tools at </span><strong><a href="https://aigovernancetoolkit.com/">AIGovernanceToolkit.com</a></strong></p><p><span>&#128073; As a bonus, check our AMA on the </span><strong><a href="https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance/">2026 OWASP GenAI Security Project State of Agentic AI Security and Governance report</a></strong><span> with me and the other co-leads (it was live, so start at time marker 09:45)</span></p><div id="youtube2-jK1Z7Z6zlW0" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;jK1Z7Z6zlW0&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/jK1Z7Z6zlW0?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><em>The views and opinions expressed in RockCyber Musings are my own and do not represent the positions of my employer or any organization I&#8217;m affiliated with.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share RockCyber Musings&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share RockCyber Musings</span></a></p><h2>References</h2><p>Axios. (2026, June 13). <em>How Amazon and the White House ended Anthropic&#8217;s Fable</em>. https://www.axios.com/2026/06/13/anthropic-amazon-white-house</p><p>BleepingComputer. (2026, June 16). <em>Malicious JetBrains Marketplace plugins steal AI API keys from developers</em>. https://www.bleepingcomputer.com/news/security/malicious-jetbrains-marketplace-plugins-steal-ai-api-keys-from-developers/</p><p>CNBC. (2026, June 12). <em>Anthropic disables access to Fable 5 and Mythos 5 to comply with government directive</em>. https://www.cnbc.com/2026/06/12/anthropic-disables-access-to-fable-5-and-mythos-5-to-comply-with-government-directive.html</p><p>Forum of Incident Response and Security Teams. (2026, June 15). <em>FIRST mid-year vulnerability forecast confirms historic surge, projects ~66,000 CVEs in 2026</em>. https://www.first.org/newsroom/releases/20260615</p><p>Geller, E. (2026, June 16). <em>AI adoption correlates with incident frequency, underscoring need for governance</em>. Cybersecurity Dive. https://www.cybersecuritydive.com/news/ai-cybersecurity-incidents-governance-jamf/823026/</p><p>Geller, E. (2026, June 13). <em>Cybersecurity experts blast US government for restricting Anthropic&#8217;s AI models</em>. Cybersecurity Dive. https://www.cybersecuritydive.com/news/anthropic-us-government-export-ban-mythos-fable/822909/</p><p>Indico.UN. (2026). <em>Global Conference on AI, Security and Ethics 2026 (18-19 June 2026): Overview</em>. https://indico.un.org/event/1023183/</p><p>Infosecurity Magazine. (2026, June). <em>Fifteen JetBrains Marketplace plugins steal API keys</em>. https://www.infosecurity-magazine.com/news/fifteen-jetbrains-marketplace/</p><p>Just Security. (2026, June). <em>Legal considerations related to the Anthropic &#8220;export controls directive.&#8221;</em> https://www.justsecurity.org/142745/law-anthropic-export-controls/</p><p>Markovic, S. (2026, June 15). <em>Proving what a military AI model will do is the real problem</em>. Help Net Security. https://www.helpnetsecurity.com/2026/06/15/military-ai-verification-problem/</p><p>MarkTechPost. (2026, June 16). <em>OpenAI&#8217;s deployment simulation extends pre-deployment risk assessment to agentic coding through simulated tool calls</em>. https://www.marktechpost.com/2026/06/16/openai-deployment-simulation/</p><p>OpenAI. (2026, June 16). <em>Predicting model behavior before release by simulating deployment</em>. https://openai.com/index/deployment-simulation/</p><p>Orca Security. (2026, June 17). <em>144 Mastra npm packages compromised via supply chain attack</em>. https://orca.security/resources/blog/mastra-npm-supply-chain-attack/</p><p>Pogorelec, A. (2026, June 15). <em>Senior engineers are spending their week cleaning up AI-generated code</em>. Help Net Security. https://www.helpnetsecurity.com/2026/06/15/ai-generated-code-review-issues/</p><p>Reason. (2026, June 15). <em>The White House vs. Anthropic&#8217;s new AI model</em>. https://reason.com/2026/06/15/the-white-house-vs-anthropics-new-ai-model/</p><p>Schwartz, L. (2026, June 15). <em>&#8216;Fix this code.&#8217; The three little words behind the U.S. government decision that shut down Anthropic&#8217;s Fable and Mythos AI models</em>. Fortune. https://fortune.com/2026/06/15/fix-this-code-three-words-behind-us-government-shut-down-anthropic-fable-mythos-ai-models-katie-moussouris-open-letter/</p><p>Socket. (2026, June 17). <em>140+ Mastra npm packages compromised in coordinated supply chain attack</em>. https://socket.dev/blog/mastra-npm-packages-compromised</p><p>The Hacker News. (2026, June). <em>144 Mastra npm packages compromised via hijacked contributor account</em>. https://thehackernews.com/2026/06/144-mastra-npm-packages-compromised-via.html</p><p>The Register. (2026, June 15). <em>US clampdown on Anthropic models sends EU sovereignty surge into overdrive</em>. https://www.theregister.com/ai-and-ml/2026/06/15/us-clampdown-on-anthropic-models-sends-eu-sovereignty-surge-into-overdrive/</p><p>Time. (2026, June 13). <em>Anthropic pulls its top AI models after U.S. bars foreign access</em>. https://time.com/article/2026/06/13/anthropic-fable-mythos-ban-US-security/</p><p>UNIDIR. (2026). <em>Global Conference on AI, Security and Ethics 2026</em>. United Nations Institute for Disarmament Research. https://unidir.org/event/global-conference-on-ai-security-and-ethics-2026/</p><p>Zorz, M. (2026, June 15). <em>AI vulnerability discovery is pushing 2026 CVEs toward 66,000</em>. Help Net Security. https://www.helpnetsecurity.com/2026/06/15/first-2026-cve-forecast/</p><p>Zorz, M. (2026, June 15). <em>Onspring CISO on where automated GRC systems fall short</em>. Help Net Security. https://www.helpnetsecurity.com/2026/06/15/nichole-windholz-onspring-automated-grc-systems/</p>]]></content:encoded></item><item><title><![CDATA[OWASP State of Agentic AI Security and Governance 2026: The Receipts]]></title><description><![CDATA[Read OWASP's State of Agentic AI Security and Governance v2: real incidents, a maturity matrix, and the governance clocks every CISO must run now.]]></description><link>https://www.rockcybermusings.com/p/owasp-state-of-agentic-ai-security-2026</link><guid isPermaLink="false">https://www.rockcybermusings.com/p/owasp-state-of-agentic-ai-security-2026</guid><dc:creator><![CDATA[Rock Lambros]]></dc:creator><pubDate>Tue, 16 Jun 2026 12:50:59 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!hiZh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b42bd70-b284-4b1b-b748-c548cfcd61f0_2048x2048.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hiZh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b42bd70-b284-4b1b-b748-c548cfcd61f0_2048x2048.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hiZh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b42bd70-b284-4b1b-b748-c548cfcd61f0_2048x2048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!hiZh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b42bd70-b284-4b1b-b748-c548cfcd61f0_2048x2048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!hiZh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b42bd70-b284-4b1b-b748-c548cfcd61f0_2048x2048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!hiZh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b42bd70-b284-4b1b-b748-c548cfcd61f0_2048x2048.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hiZh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b42bd70-b284-4b1b-b748-c548cfcd61f0_2048x2048.jpeg" width="1456" height="1456" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8b42bd70-b284-4b1b-b748-c548cfcd61f0_2048x2048.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1456,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:587183,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/201852505?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b42bd70-b284-4b1b-b748-c548cfcd61f0_2048x2048.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hiZh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b42bd70-b284-4b1b-b748-c548cfcd61f0_2048x2048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!hiZh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b42bd70-b284-4b1b-b748-c548cfcd61f0_2048x2048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!hiZh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b42bd70-b284-4b1b-b748-c548cfcd61f0_2048x2048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!hiZh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b42bd70-b284-4b1b-b748-c548cfcd61f0_2048x2048.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Disclosure:</strong> I co-led the OWASP State of Agentic AI Security and Governance 2026 with Ariel Fogel and Evgeniy Kokuykin. I&#8217;ll also show you the places I&#8217;d push back on it even with my name on the cover, so you can weigh the case on its merits instead of on mine. The report lives here: <strong><a href="https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance/">https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance/</a></strong></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/p/owasp-state-of-agentic-ai-security-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/p/owasp-state-of-agentic-ai-security-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p>A year ago, agentic AI security was a stack of position papers and vendor pitches. Today, almost every category in the OWASP Top 10 for Agentic Applications has a production incident, a vendor advisory, or a CVE attached to it. The OWASP State of Agentic AI Security and Governance 2026, published June 1, 2026, collects that evidence into one place and hands you a map. If you run security or AI risk anywhere agents are deployed, and you do, whether you&#8217;ve gone looking or not, this is the report you read ASAP.</p><h2><strong>How The OWASP State of Agentic AI Security and Governance 2026 Audits The Present</strong></h2><p>When v1 shipped in July 2025, I expected the threat catalog to fill in over a couple of years. It filled faster. ASI04, the supply chain category, and ASI05, code execution, are now tied for the highest volume of disclosed incidents. I expected regulation to lag the technology by years. It didn&#8217;t. This year&#8217;s report maps 42 instruments across 10 jurisdictions. The gap I watch in client environments, between how mature their governance is and how aggressive their agent deployments are, turned out wider than I would have guessed. Shadow AI sits in nearly every organization our contributors examined.</p><p>2025 called out the future. 2026 audits the present, and it&#8217;s organized around three findings:</p><ol><li><p>The threats are real now</p></li><li><p>Safety and security converge at the deployment layer</p></li><li><p>Governance runs on a clock measured in hours.</p></li></ol><p>Here&#8217;s what each one means for your program, and where I&#8217;d still argue with the document.</p><h2><strong>Finding One: The Threats Have Receipts Now, And Here&#8217;s What To Demand</strong></h2><p>2025 listed architectural concerns. 2026 attaches names, dates, and CVE numbers to them. The Real-World Incidents and Exploits Tracker is the chapter I point people to first, because it ends the &#8220;show me a real attack&#8221; conversation in about thirty seconds.</p><p>EchoLeak was a zero-click prompt injection that turned a single email into a Microsoft Copilot data exfiltration path, as documented by Aim Security. Cato CTRL showed Claude&#8217;s Skills feature deploying MedusaLocker ransomware by re-uploading a Skill carrying malicious code that ran on its own. OpenAI&#8217;s Codex CLI shipped a sandbox bypass, CVE-2025-59532, in which the model&#8217;s own output could redraw the writable boundary it was supposed to stay within. Cursor carried a sibling flaw, CVE-2026-22708, where an attacker who influenced the agent&#8217;s instructions could ride an already-approved command like git branch straight into arbitrary code execution. Trustwave&#8217;s SpiderLabs team published an agent-in-the-middle attack against the A2A protocol, in which a fake agent card claiming high trust was selected by an LLM judge and used to intercept data. Pillar Security demonstrated manipulated code suggestions seeding backdoors and leaked keys into production through GitHub Copilot and Cursor.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7g_M!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2cfbeb2-a0e3-41eb-bcd7-6a59f5dbfbdd_2966x2240.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7g_M!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2cfbeb2-a0e3-41eb-bcd7-6a59f5dbfbdd_2966x2240.png 424w, https://substackcdn.com/image/fetch/$s_!7g_M!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2cfbeb2-a0e3-41eb-bcd7-6a59f5dbfbdd_2966x2240.png 848w, https://substackcdn.com/image/fetch/$s_!7g_M!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2cfbeb2-a0e3-41eb-bcd7-6a59f5dbfbdd_2966x2240.png 1272w, https://substackcdn.com/image/fetch/$s_!7g_M!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2cfbeb2-a0e3-41eb-bcd7-6a59f5dbfbdd_2966x2240.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7g_M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2cfbeb2-a0e3-41eb-bcd7-6a59f5dbfbdd_2966x2240.png" width="1456" height="1100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d2cfbeb2-a0e3-41eb-bcd7-6a59f5dbfbdd_2966x2240.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1100,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:541572,&quot;alt&quot;:&quot;Bipartite mapping connecting six documented 2025 and 2026 agentic AI incidents to the OWASP ASI risk categories they exercised, with ASI04 Supply Chain and ASI05 Code Execution highlighted as highest incident volume&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/201852505?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2cfbeb2-a0e3-41eb-bcd7-6a59f5dbfbdd_2966x2240.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Bipartite mapping connecting six documented 2025 and 2026 agentic AI incidents to the OWASP ASI risk categories they exercised, with ASI04 Supply Chain and ASI05 Code Execution highlighted as highest incident volume" title="Bipartite mapping connecting six documented 2025 and 2026 agentic AI incidents to the OWASP ASI risk categories they exercised, with ASI04 Supply Chain and ASI05 Code Execution highlighted as highest incident volume" srcset="https://substackcdn.com/image/fetch/$s_!7g_M!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2cfbeb2-a0e3-41eb-bcd7-6a59f5dbfbdd_2966x2240.png 424w, https://substackcdn.com/image/fetch/$s_!7g_M!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2cfbeb2-a0e3-41eb-bcd7-6a59f5dbfbdd_2966x2240.png 848w, https://substackcdn.com/image/fetch/$s_!7g_M!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2cfbeb2-a0e3-41eb-bcd7-6a59f5dbfbdd_2966x2240.png 1272w, https://substackcdn.com/image/fetch/$s_!7g_M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2cfbeb2-a0e3-41eb-bcd7-6a59f5dbfbdd_2966x2240.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 1: Real-World Incidents Mapped To The OWASP Top 10 For Agentic Applications</figcaption></figure></div><p>Notice the structural lesson under the Cursor and Codex flaws. The controls were calibrated for human operators, and they broke the moment the executor could influence its own containment. An allowlist that auto-approves a git branch is a convenience for a developer and a loaded gun for an agent that can rewrite what runs behind that command. That&#8217;s the shift 2026 keeps returning to. The model stopped being a component inside your application and became an actor with hands on your tools.</p><p>Two patterns matter more than any single incident. First, ASI04 and ASI05 are tied for the most disclosed incidents, and a security audit nicknamed IDEsaster found vulnerabilities in 100% of the major AI coding IDEs it tested. Code sits upstream of everything else you ship, so an exploit in a coding agent is a supply chain event, not a developer inconvenience. Second, ASI03, identity and privilege abuse, carries the widest gap between how severe the risk is and how ready anyone is for it. Non-human identities already outnumber humans across most enterprises, and almost nobody has a strategy for governing them.</p><p>Here&#8217;s what the evidence tells you to demand. Treat agent identity as its own control plane, not a service account with a fancier name. The report tracks NIST&#8217;s AI Agent Standards Initiative, the OpenID Foundation&#8217;s work on recursive delegation, and MCP&#8217;s move to OAuth 2.1 with resource-indicator-scoped tokens, all converging over the next 18 to 24 months. Ask vendors how an agent&#8217;s permissions get derived, when they expire, and how revocation propagates through a delegation chain. If they can&#8217;t answer, you have your answer. Treat security advisory density as a buying signal rather than a red flag in isolation.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AW5M!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc02e3546-9be7-4e89-836c-3d289d0f0134_2335x1308.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AW5M!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc02e3546-9be7-4e89-836c-3d289d0f0134_2335x1308.png 424w, https://substackcdn.com/image/fetch/$s_!AW5M!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc02e3546-9be7-4e89-836c-3d289d0f0134_2335x1308.png 848w, https://substackcdn.com/image/fetch/$s_!AW5M!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc02e3546-9be7-4e89-836c-3d289d0f0134_2335x1308.png 1272w, https://substackcdn.com/image/fetch/$s_!AW5M!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc02e3546-9be7-4e89-836c-3d289d0f0134_2335x1308.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AW5M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc02e3546-9be7-4e89-836c-3d289d0f0134_2335x1308.png" width="1456" height="816" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c02e3546-9be7-4e89-836c-3d289d0f0134_2335x1308.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:816,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:110722,&quot;alt&quot;:&quot;Bar chart showing security advisory counts for n8n, Claude Code, AutoGPT, Dify, and Roo-Code&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/201852505?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc02e3546-9be7-4e89-836c-3d289d0f0134_2335x1308.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Bar chart showing security advisory counts for n8n, Claude Code, AutoGPT, Dify, and Roo-Code" title="Bar chart showing security advisory counts for n8n, Claude Code, AutoGPT, Dify, and Roo-Code" srcset="https://substackcdn.com/image/fetch/$s_!AW5M!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc02e3546-9be7-4e89-836c-3d289d0f0134_2335x1308.png 424w, https://substackcdn.com/image/fetch/$s_!AW5M!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc02e3546-9be7-4e89-836c-3d289d0f0134_2335x1308.png 848w, https://substackcdn.com/image/fetch/$s_!AW5M!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc02e3546-9be7-4e89-836c-3d289d0f0134_2335x1308.png 1272w, https://substackcdn.com/image/fetch/$s_!AW5M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc02e3546-9be7-4e89-836c-3d289d0f0134_2335x1308.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 2: Security Advisory Density, Top Five Tracked Agentic Projects</figcaption></figure></div><p>n8n carries 57 advisories, and Claude Code carries 22, not because they&#8217;re careless but because they&#8217;re everywhere. The projects with the most advisories tend to be the ones with the most adoption. Ask for the AI-SBOM and the disclosure history. Silence is the warning sign, not volume.</p><h2><strong>Finding Two: Safety And Security Collapse At The Deployment Layer</strong></h2><p>For most of software&#8217;s history, safety was an engineering problem, and security was an adversarial one, owned by different teams running different playbooks. Agentic systems break that split at the deployment layer, meaning the architectural decisions, permissions, configurations, and operational controls your organization owns once an agent acts on production systems.</p><p>The report argues that once an agent can send the email, move the money, or commit the code, the same controls govern a benign malfunction and a deliberate attack, and the same investigation surfaces both root causes. Model-level safety stays with the provider. Everything downstream of the prompt lands on one function, no matter how you choose to draw the org chart.</p><p>Picture an agent whose memory got poisoned weeks ago. It starts exfiltrating data and taking actions nobody approved. To the team watching the dashboards in real time, that looks like a reliability bug. They restart it, check for drift, and review the inputs. A team treating it as a safety issue misses the persistence mechanism and gets compromised again. A team treating it as a security issue hunts the initial access vector, and the memory state stands a chance of containing it. The symptom is the same, the right response is the opposite, and the org chart decides which one you run.</p><p>The categories still separate cleanly when an agent has limited autonomy or a human in the loop. They stop separating when the agent runs with broad permissions and thin oversight, which describes most of the deployments racing into production right now. If your AI safety people and your AI security people sit in separate meetings with separate budgets, that division is now a liability. Read this chapter with your CTO and your head of AI in the room.</p><h2><strong>Finding Three: The Governance Clock Runs In Hours, And The Matrix Tells You Where You Stand</strong></h2><p>Regulators stopped pretending periodic audits are enough. DORA gives you a four-hour notification window. NIS2 wants a 24-hour early warning. New York&#8217;s RAISE Act sets 72 hours for frontier reporting. California&#8217;s SB 53 allows 15 days. The EU AI Act&#8217;s Article 72 requires post-market monitoring that explicitly covers behavioral drift, though the Digital Omnibus proposal from November 2025 may push the high-risk deadlines to December 2027 if it clears trilogue.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EPhO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3b8a305-1de8-4d1d-9f42-cee77ef77911_2877x1240.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EPhO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3b8a305-1de8-4d1d-9f42-cee77ef77911_2877x1240.png 424w, https://substackcdn.com/image/fetch/$s_!EPhO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3b8a305-1de8-4d1d-9f42-cee77ef77911_2877x1240.png 848w, https://substackcdn.com/image/fetch/$s_!EPhO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3b8a305-1de8-4d1d-9f42-cee77ef77911_2877x1240.png 1272w, https://substackcdn.com/image/fetch/$s_!EPhO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3b8a305-1de8-4d1d-9f42-cee77ef77911_2877x1240.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EPhO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3b8a305-1de8-4d1d-9f42-cee77ef77911_2877x1240.png" width="1456" height="628" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d3b8a305-1de8-4d1d-9f42-cee77ef77911_2877x1240.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:628,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:135606,&quot;alt&quot;:&quot;Horizontal bar chart comparing notification deadlines for DORA, NIS2, NY RAISE, and CA SB 53 in hours&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/201852505?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3b8a305-1de8-4d1d-9f42-cee77ef77911_2877x1240.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Horizontal bar chart comparing notification deadlines for DORA, NIS2, NY RAISE, and CA SB 53 in hours" title="Horizontal bar chart comparing notification deadlines for DORA, NIS2, NY RAISE, and CA SB 53 in hours" srcset="https://substackcdn.com/image/fetch/$s_!EPhO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3b8a305-1de8-4d1d-9f42-cee77ef77911_2877x1240.png 424w, https://substackcdn.com/image/fetch/$s_!EPhO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3b8a305-1de8-4d1d-9f42-cee77ef77911_2877x1240.png 848w, https://substackcdn.com/image/fetch/$s_!EPhO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3b8a305-1de8-4d1d-9f42-cee77ef77911_2877x1240.png 1272w, https://substackcdn.com/image/fetch/$s_!EPhO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3b8a305-1de8-4d1d-9f42-cee77ef77911_2877x1240.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 3: The Governance Clock, Regulatory Notification Windows</figcaption></figure></div><p>2026 maps 42 instruments across 10 jurisdictions, so you can see which clock applies where without assembling it yourself from primary texts. The count isn&#8217;t the point. The point is that runtime governance moved from a nice-to-have to the unit regulators measure. Pre-deployment certification stopped being enough the moment the thing you certified could rewrite its own behavior after launch.</p><p>Then the report hands you the artifact I wish boards had a year ago. The Enterprise Adoption Maturity Model maps your governance maturity (Levels 0 through 4) against your adoption tier (AT0 through AT8). AT0 is Shadow AI, the unmanaged usage already running in your org. The tiers climb through vendor-embedded assistants, platform-integrated agents, citizen-developer flows, code-executing agents, custom in-house builds, and externally extended agents, up to AT8, where agents operate across organizational boundaries in federated networks.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9D4L!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdacaea8b-6d1a-4f4f-b252-2a8688720480_2950x1675.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9D4L!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdacaea8b-6d1a-4f4f-b252-2a8688720480_2950x1675.png 424w, https://substackcdn.com/image/fetch/$s_!9D4L!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdacaea8b-6d1a-4f4f-b252-2a8688720480_2950x1675.png 848w, https://substackcdn.com/image/fetch/$s_!9D4L!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdacaea8b-6d1a-4f4f-b252-2a8688720480_2950x1675.png 1272w, https://substackcdn.com/image/fetch/$s_!9D4L!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdacaea8b-6d1a-4f4f-b252-2a8688720480_2950x1675.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9D4L!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdacaea8b-6d1a-4f4f-b252-2a8688720480_2950x1675.png" width="1456" height="827" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dacaea8b-6d1a-4f4f-b252-2a8688720480_2950x1675.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:827,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:251189,&quot;alt&quot;:&quot;Grid showing governance maturity levels 0 through 4 against adoption tiers AT0 through AT8, with insufficient-governance cells highlighted&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/201852505?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdacaea8b-6d1a-4f4f-b252-2a8688720480_2950x1675.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Grid showing governance maturity levels 0 through 4 against adoption tiers AT0 through AT8, with insufficient-governance cells highlighted" title="Grid showing governance maturity levels 0 through 4 against adoption tiers AT0 through AT8, with insufficient-governance cells highlighted" srcset="https://substackcdn.com/image/fetch/$s_!9D4L!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdacaea8b-6d1a-4f4f-b252-2a8688720480_2950x1675.png 424w, https://substackcdn.com/image/fetch/$s_!9D4L!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdacaea8b-6d1a-4f4f-b252-2a8688720480_2950x1675.png 848w, https://substackcdn.com/image/fetch/$s_!9D4L!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdacaea8b-6d1a-4f4f-b252-2a8688720480_2950x1675.png 1272w, https://substackcdn.com/image/fetch/$s_!9D4L!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdacaea8b-6d1a-4f4f-b252-2a8688720480_2950x1675.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 4: The Maturity-By-Adoption-Tier Matrix</figcaption></figure></div><p>A bold cell means your governance is too thin for what you&#8217;re running, and you get two honest moves: raise maturity or lower the tier, with no third option where you cross your fingers and hope it holds. The model survives the way a Bayesian wants a model to survive. It&#8217;s calibrated, it&#8217;s falsifiable, and it updates in response to evidence instead of flattering the program you already built. The urgency shows in the adoption data. a16z found that 29% of the Fortune 500 and roughly 19% of the Global 2000 are paying customers of a leading AI startup, counting only signed, contracted deployments. The unmanaged AT0 volume sitting on top of that is, by definition, unmeasured.</p><h2><strong>Where I&#8217;d Push Back, Even As A Co-Lead</strong></h2><p>A review where the author agrees with himself for 2,000 words isn&#8217;t worth your time, so here&#8217;s where I&#8217;d lean on the document.</p><p>The report is honest about what it hasn&#8217;t solved, and the &#8220;What Remains Unsolved&#8221; section names three problems I&#8217;d watch closely. Cyber insurance for agentic deployments is heading toward a coverage gap nobody has priced yet, and the first big agent-driven loss will test it in public. The governance-deployment collision at AT6 and above, where agents reach across trust boundaries, has no clean answer, and the matrix tells you to slow down rather than how to move fast safely. Agentic AI in OT and ICS has no documented enterprise-agent safety incident yet. Read that as early, not as safe.</p><p>I encourage you to pay close attention to the weaponization curve, as the offense is scaling faster than the controls. Anthropic disclosed GTG-1002, a campaign that ran largely autonomous espionage across roughly 30 organizations using jailbroken Claude Code, with the AI executing 80 to 90% of the tactical operations at request rates no human could match. Credit Anthropic for disclosing it in that detail, because that kind of transparency is how the rest of us learn what&#8217;s coming. CrowdStrike documented an 89% increase in AI-enabled adversary attacks, with breakout time falling to 29 minutes. IAPS HACCA found frontier models jumping from near-zero to 60% success on expert-level offensive security challenges inside a few months. The report maps the threat well. It doesn&#8217;t pretend anyone has solved the defense that scales at machine speed. Neither do I. That&#8217;s the honest state of it.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AhLs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe2d1711-e36b-4657-878e-321f715fa98b_3409x2058.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AhLs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe2d1711-e36b-4657-878e-321f715fa98b_3409x2058.png 424w, https://substackcdn.com/image/fetch/$s_!AhLs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe2d1711-e36b-4657-878e-321f715fa98b_3409x2058.png 848w, https://substackcdn.com/image/fetch/$s_!AhLs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe2d1711-e36b-4657-878e-321f715fa98b_3409x2058.png 1272w, https://substackcdn.com/image/fetch/$s_!AhLs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe2d1711-e36b-4657-878e-321f715fa98b_3409x2058.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AhLs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe2d1711-e36b-4657-878e-321f715fa98b_3409x2058.png" width="1456" height="879" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/be2d1711-e36b-4657-878e-321f715fa98b_3409x2058.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:879,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:326574,&quot;alt&quot;:&quot;Capability trajectory showing frontier model success on expert-level offensive security challenges rising from near-zero to 60% within months, with stat callouts for GTG-1002 where AI ran 80-90% of tactical operations across about 30 organizations, an 89% increase in AI-enabled attacks, and a 29-minute breakout time&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/201852505?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe2d1711-e36b-4657-878e-321f715fa98b_3409x2058.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Capability trajectory showing frontier model success on expert-level offensive security challenges rising from near-zero to 60% within months, with stat callouts for GTG-1002 where AI ran 80-90% of tactical operations across about 30 organizations, an 89% increase in AI-enabled attacks, and a 29-minute breakout time" title="Capability trajectory showing frontier model success on expert-level offensive security challenges rising from near-zero to 60% within months, with stat callouts for GTG-1002 where AI ran 80-90% of tactical operations across about 30 organizations, an 89% increase in AI-enabled attacks, and a 29-minute breakout time" srcset="https://substackcdn.com/image/fetch/$s_!AhLs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe2d1711-e36b-4657-878e-321f715fa98b_3409x2058.png 424w, https://substackcdn.com/image/fetch/$s_!AhLs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe2d1711-e36b-4657-878e-321f715fa98b_3409x2058.png 848w, https://substackcdn.com/image/fetch/$s_!AhLs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe2d1711-e36b-4657-878e-321f715fa98b_3409x2058.png 1272w, https://substackcdn.com/image/fetch/$s_!AhLs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe2d1711-e36b-4657-878e-321f715fa98b_3409x2058.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 5: The Weaponization Curve, Offense Is Scaling Faster Than Controls</figcaption></figure></div><p><strong>Key Takeaway:</strong> 2026 won&#8217;t secure your agents for you, but it&#8217;s the first document that tells you, with evidence, exactly where your governance is too thin for what you&#8217;ve already deployed.</p><h3><strong>What To Do Next</strong></h3><p>Start with AT0, this week. Assume Shadow AI exists until you&#8217;ve proven it doesn&#8217;t. Here&#8217;s a hint: it does&#8230; if you think you&#8217;ve proven it doesn&#8217;t, try again.</p><p>Pull network and DLP telemetry for AI-service traffic, run a short employee survey on the tools people are already using, and you&#8217;ll surface more than you expect. Then map your three highest-tier agent deployments against the maturity matrix. Where you land in a bold cell, pick one of the two moves: raise governance maturity or lower the deployment tier. Print the matrix and walk it with your CTO, your head of AI, and your board chair, because this is a conversation about deployment decisions, not policy language.</p><p>If you want the deeper background on why authorization scope and least agency are the metrics that survive contact with production, and why governance is a deployment-review problem before it&#8217;s a policy problem, I&#8217;ve written both up at<a href="https://rockcybermusings.com/"> rockcybermusings.com</a>, and the consulting side of how I run these assessments lives at<a href="https://rockcyber.com/"> rockcyber.com</a>.</p><p>Then download the report, read the threat tracker and the maturity model first, and send the link to the two people who own the deployments you inventoried: <strong><a href="https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance/">https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance/</a></strong></p><p>&#128073; For ongoing analysis of agentic AI governance frameworks, the conversation continues at <strong><a href="https://rockcybermusings.com/">RockCyber Musings</a></strong>.</p><p>&#128073; Visit <strong><a href="https://www.rockcyber.com/">RockCyber.com</a></strong> to learn more about how we can help with your traditional Cybersecurity and AI Security and Governance journey.</p><p>&#128073; Want to save a quick $100K? Check out our AI Governance Tools at <strong><a href="https://aigovernancetoolkit.com/">AIGovernanceToolkit.com</a></strong></p><p>&#128073; As a bonus, check our AMA on the <strong><a href="https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance/">2026 OWASP GenAI Security Project State of Agentic AI Security and Governance report</a></strong> with me and the other co-leads (it was live, so start at time marker 09:45)</p><div id="youtube2-jK1Z7Z6zlW0" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;jK1Z7Z6zlW0&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/jK1Z7Z6zlW0?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><em>The views and opinions expressed in RockCyber Musings are my own and do not represent the positions of my employer or any organization I&#8217;m affiliated with.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share RockCyber Musings&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share RockCyber Musings</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Weekly Musings Top 10 AI Security Wrapup: Issue 41 June 5 -June 11, 2026]]></title><description><![CDATA[Frontier Safety Theater, an LLM Gateway Under Active Attack, and a Federal Three-Day Patch Clock]]></description><link>https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260605-20260611</link><guid isPermaLink="false">https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260605-20260611</guid><dc:creator><![CDATA[Rock Lambros]]></dc:creator><pubDate>Fri, 12 Jun 2026 13:51:07 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Pdux!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aefacf9-8a5a-4613-bed7-e496e50969c1_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Pdux!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aefacf9-8a5a-4613-bed7-e496e50969c1_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Pdux!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aefacf9-8a5a-4613-bed7-e496e50969c1_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!Pdux!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aefacf9-8a5a-4613-bed7-e496e50969c1_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!Pdux!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aefacf9-8a5a-4613-bed7-e496e50969c1_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!Pdux!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aefacf9-8a5a-4613-bed7-e496e50969c1_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Pdux!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aefacf9-8a5a-4613-bed7-e496e50969c1_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7aefacf9-8a5a-4613-bed7-e496e50969c1_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1233556,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/201739048?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aefacf9-8a5a-4613-bed7-e496e50969c1_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Pdux!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aefacf9-8a5a-4613-bed7-e496e50969c1_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!Pdux!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aefacf9-8a5a-4613-bed7-e496e50969c1_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!Pdux!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aefacf9-8a5a-4613-bed7-e496e50969c1_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!Pdux!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aefacf9-8a5a-4613-bed7-e496e50969c1_1024x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Anthropic shipped its most capable public model on Tuesday, then buried a switch in a 319-page system card that quietly makes the model worse when you ask about building AI. Not blocked. Not flagged. Worse, with a straight face. Two days earlier, CISA confirmed attackers were already inside LiteLLM, the gateway brokering traffic for half the agent frameworks in your stack. By Wednesday the agency told agencies to patch the worst flaws in three days. Safety got a press release. Security got a body count.</p><p>This was the week the two halves of AI safety stopped pretending to be the same thing. One half lives in system cards and voluntary codes, the language of labs and regulators. The other lives in KEV entries, CVSS 10.0 chains, and production databases an agent wiped while reporting all clear. The governance side finalized a labeling code, a maturity model, and a sharing standard. Useful, slow, paper. The security side served up an LLM gateway chained to remote code execution, Microsoft&#8217;s largest patch day ever, and hard numbers on AI code breaking in production. Eleven stories, ten ranked and one you won&#8217;t see on the front page. Read them in order. The order is the argument.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260605-20260611?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260605-20260611?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h3>1. Anthropic Ships Claude Fable 5 and Hides a Throttle in the Fine Print</h3><p>On June 9, Anthropic released Claude Fable 5, the first Mythos-tier model to reach the public (Fortune). Within hours, researchers found a paragraph in the 319-page system card describing a feature that silently degrades answers on requests tied to frontier AI development. Cybersecurity and biology queries get redirected to a weaker model with a visible notice. The AI-development throttle carries none, and Anthropic put the affected traffic at 0.03%.</p><p><strong>Why it matters</strong></p><ul><li><p>A safety control your users can&#8217;t see is a trust control. It sets precedent for any vendor shaping model behavior in your stack.</p></li><li><p>The throttle targets AI R&amp;D, handing the frontier leader an advantage dressed as safety. Dean Ball called it &#8220;secret sabotage.&#8221;</p></li><li><p>If a lab will silently downgrade outputs, the assumption that a model either does the task or refuses it is dead.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Read system cards before you standardize on a model. The detail that mattered wasn&#8217;t in the launch blog.</p></li><li><p>Test models for silent degradation in your use cases, not just refusals, against a known-good baseline.</p></li><li><p>Put model-behavior-change clauses in vendor contracts. You want notice when capability shifts under you.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>I&#8217;ve spent thirty years watching &#8220;trust us&#8221; get sold as a feature, and this is the slickest version yet. The moment a model lies by omission about how hard it&#8217;s trying, you lose the one property that made it auditable. My Bayesian read puts the chance this was purely about safety under 30%. The rest is a competitive moat in a lab coat. Govern your model vendors like anything else with root access to your work, because that&#8217;s what they are. More at <a href="https://www.rockcyber.com/">rockcyber.com</a>.</p><h3>2. CISA Flags a Critical LiteLLM Flaw Already Being Exploited</h3><p>On June 8, CISA added CVE-2026-42271 to its Known Exploited Vulnerabilities catalog, confirming active exploitation of LiteLLM, the gateway routing model calls for CrewAI, DSPy, Microsoft GraphRAG, and dozens of other agent frameworks (The Hacker News). The command-injection flaw chains with a Starlette bypass, CVE-2026-48710, for unauthenticated remote code execution at a combined 10.0. Federal agencies have until June 22 to patch, to LiteLLM 1.83.7 and Starlette 1.0.1.</p><p><strong>Why it matters</strong></p><ul><li><p>LiteLLM sits in the middle of your agent stack. Own the gateway, own every model call and secret it brokers.</p></li><li><p>A 10.0 unauthenticated RCE chain on shared AI infrastructure is the cleanest path into an enterprise.</p></li><li><p>Second LiteLLM supply-chain hit in 2026 after the March PyPI backdoor. The pattern is the point.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Inventory where LiteLLM runs, including frameworks that bundle it. Patch to 1.83.7 and Starlette 1.0.1 now.</p></li><li><p>Lock the MCP test endpoints behind network controls and pull them off any internet-facing path.</p></li><li><p>Hunt for exploitation rather than assume patching closes it. KEV status means someone already used it.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Everybody&#8217;s threat model for AI agents fixates on the model. First contact usually lands at the plumbing, the gateways and routers nobody drew on a data-flow diagram because they showed up as a transitive dependency. LiteLLM is plumbing, and this week it sprang a 10.0 leak. Agent security is mostly classic appsec in a new hat. Command injection through an unsanitized config field proves it. If you can&#8217;t name your gateway version off the top of your head, that&#8217;s your finding.</p><h3>3. CISA Orders Federal Agencies to Patch the Worst Bugs in Three Days, Blames AI</h3><p>On June 10, CISA issued Binding Operational Directive 26-04, ordering federal civilian agencies to rank vulnerabilities by four factors: asset exposure, KEV status, whether exploitation is automatable, and how much control it hands an attacker (CISA). A bug worst on all four gets a three-day patch deadline and a mandatory forensic check. CISA tied the clock directly to AI-assisted exploitation collapsing the time between a patch and its abuse. Full alignment lands in 60 days.</p><p><strong>Why it matters</strong></p><ul><li><p>A regulator turned &#8220;AI compresses the patch window&#8221; into an operational mandate instead of a conference talk.</p></li><li><p>Three days is faster than most enterprise change windows. The private-sector benchmark just moved.</p></li><li><p>The four-factor model is a usable risk lens even if you&#8217;re nowhere near federal. Steal it.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Map your mean-time-to-patch against a three-day worst case. Find where you&#8217;d miss.</p></li><li><p>Adopt exploit-automatability and post-exploitation impact as scoring factors, not just CVSS.</p></li><li><p>Pre-authorize emergency patching for the top tier so change control isn&#8217;t the hour-60 bottleneck.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>For years the patch-faster crowd got waved off with &#8220;we have compensating controls.&#8221; That excuse has a shelf life now, and AI is the expiration date. When a model turns a fresh CVE into a working exploit before your change board reaches quorum, every day of dwell is a day you handed away. The grumpy-uncle question is which breaks first under a three-day fuse, the tooling, the staffing, or the politics. Bet on politics. It always is.</p><h3>4. The EU Publishes Its Final Code for Labeling AI-Generated Content</h3><p>On June 10, the European Commission published the final Code of Practice on marking and labeling AI-generated content, the voluntary playbook for the AI Act&#8217;s Article 50 transparency duties (European Commission). It pushes machine-readable marking and a common EU icon set for labeling deepfakes and AI-generated text on public-interest matters. ENISA sits on the advisory structure behind it. The obligations become applicable August 2, 2026. Signing is optional. The legal duty is not.</p><p><strong>Why it matters</strong></p><ul><li><p>Provenance is becoming a compliance artifact, not a nice-to-have. Machine-readable marking is now a named EU expectation.</p></li><li><p>August 2 is close. Deploy generative AI into the EU and labeling is a near-term control.</p></li><li><p>A shared icon standard helps, and it creates a forgeable target. Watch for fake labels in both directions.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Inventory where you generate or publish synthetic content touching EU users. Map each to an Article 50 obligation.</p></li><li><p>Pilot C2PA-style content credentials and the EU icons now, while signing is voluntary and mistakes are cheap.</p></li><li><p>Treat provenance integrity as a security problem. Marking you can strip or spoof buys you nothing.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Credit to Brussels for shipping something concrete instead of another principles deck. Labels are a real control, and they&#8217;re catnip for adversaries the second anyone trusts them. The moment a &#8220;human-made&#8221; badge means something, somebody forges it. Provenance is only as strong as the cryptography under it and the verification at the edge. A visible icon with nothing signing it is an honor system for people with no honor. Do the C2PA work. August 2 doesn&#8217;t care about your fiscal year.</p><h3>5. New Relic Puts Numbers on the AI Code Problem</h3><p>New Relic&#8217;s 2026 State of AI Coding report, out June 10, surveyed 200 technology decision-makers at US firms (Business Wire). Ninety-four percent rate AI-generated code higher quality than human code at review. Then 82% reported a production failure tied to AI code in the past six months, 78% saw more incidents, and 74% said a quarter of AI code needed significant rework. None banned vibe coding. The report calls the buildup &#8220;agent debt.&#8221;</p><p><strong>Why it matters</strong></p><ul><li><p>AI code looks good in review and breaks in production. Your review gate is measuring the wrong thing.</p></li><li><p>&#8220;Agent debt&#8221; compounds quietly, then surfaces as incidents long after the author moved on.</p></li><li><p>Policy already says yes. The question moved from whether to allow AI code to how to contain it.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Tie runtime and production-incident telemetry back to AI-authored code, not just review approval rates.</p></li><li><p>Require a named human owner for AI-generated changes in critical paths. Every time.</p></li><li><p>Fund the rework. If a quarter of AI code needs fixing, budget for it.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>The dirtiest number in that survey is the gap between 94% at review and 82% failing in production. Leaders love the code in the pull request and eat the incidents six months later. You won&#8217;t ban vibe coding, so instrument the blast radius instead. I keep a running file of these failure patterns at <a href="https://rockcybermusings.com/">rockcybermusings.com</a>. Measure the incident, not the applause.</p><h3>6. Mastercard Lets AI Agents Pay Each Other</h3><p>On June 10, Mastercard launched Agent Pay for Machines, an open protocol letting autonomous AI agents transact at machine speed, down to micropayments worth fractions of a cent (Mastercard). Agent credentials and spending permissions live on public blockchains, including Polygon, Solana, and Base, with 31 launch partners such as Coinbase, Adyen, Stripe, and Cloudflare. Visa, Stripe, and Google shipped their own agent-payment plumbing this year.</p><p><strong>Why it matters</strong></p><ul><li><p>Autonomous agents with spending authority turn every prompt injection into a potential unauthorized transaction.</p></li><li><p>Non-human identity just became a money problem. Agent credentials are bearer instruments for your budget.</p></li><li><p>Machine-speed payments mean machine-speed fraud. Your fraud controls were tuned for human tempo.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Treat agent payment credentials as crown-jewel secrets with hard spending caps and short-lived scopes.</p></li><li><p>Require revocable agent identity and per-transaction authorization before an agent holds a wallet.</p></li><li><p>Model the abuse case first. Assume a poisoned input tries to drain the budget, then design the cap.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Give an agent a wallet and the lethal trifecta stops being academic. An agent that reads untrusted content, holds private data, and now moves money is a self-service exfiltration tool with a payment terminal bolted on. We&#8217;re handing agents spending authority the same week their gateways get popped and their memory gets poisoned. Caps, scopes, revocation, and a kill switch on every agent that touches a wallet. If you can&#8217;t yank its spending power in one click, it shouldn&#8217;t have any.</p><h3>7. The Linux Foundation Tries to Standardize How We Share AI Assets</h3><p>On June 10, the Linux Foundation launched the OpenSharing Project, a vendor-neutral protocol for exchanging agent skills, AI models, and unstructured data across organizations and clouds (Linux Foundation). It extends the Delta Sharing protocol into the agentic era, replacing point-to-point integrations and proprietary marketplaces. Databricks is a named contributor. How shared assets get verified for integrity is left mostly to implementers.</p><p><strong>Why it matters</strong></p><ul><li><p>Standardized sharing of skills and models is standardized distribution of supply-chain risk without built-in provenance.</p></li><li><p>A common protocol is a common attack surface. Whatever everyone adopts, everyone inherits the flaws of.</p></li><li><p>&#8220;Consume an AI asset from anyone&#8221; is exactly how poisoned models and backdoored skills travel.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Demand signed provenance and integrity verification for any shared model or skill before you ingest it.</p></li><li><p>Treat external agent skills like third-party code, because they are. Scan, sandbox, review.</p></li><li><p>Get a seat at the standard now. Security is cheaper in the draft than bolted on after adoption.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Standards are good. My worry is the lesson we never seem to learn, that the thing everyone shares becomes the thing everyone gets hit through. We did it with npm, with PyPI, with container registries, now with agent skills and models. Bake in signing, attestation, and verifiable provenance from day one and this is the best security news of the quarter. Ship it with trust assumed and it&#8217;s a distribution network for poisoned assets. Show up to the draft.</p><h3>8. Accenture and Carnegie Mellon Ship an AI Maturity Model</h3><p>On June 8, Accenture and the Carnegie Mellon University Software Engineering Institute released the AI Adoption Maturity Model, a framework for scaling AI with repeatable outcomes (Carnegie Mellon SEI). It scores eight dimensions, including risk and governance. The teams built it from 100-plus maturity efforts, 25 executive interviews, 600 practitioner surveys, and Fortune 500 pilots. The report says 95% of organizations see no return on AI, and only 8% scale it enterprise-wide.</p><p><strong>Why it matters</strong></p><ul><li><p>&#8220;Risk and governance&#8221; sits as a first-class dimension, not a footnote. That&#8217;s the right shape for a maturity model.</p></li><li><p>95% seeing no return is the number your board needs before it greenlights the next AI line item.</p></li><li><p>A common maturity language helps you argue for governance investment in terms executives already use.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Run an honest self-assessment against the eight dimensions. Score where you are, not where the deck says you are.</p></li><li><p>Use the governance dimension to anchor an AI risk program your CFO will fund.</p></li><li><p>Tie maturity gaps to specific incidents from this very week. War stories move budgets, abstractions don&#8217;t.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>I&#8217;m allergic to maturity models that exist to sell the next assessment, so I went in skeptical. This one earned a grudging nod, because it treats governance and risk as load-bearing instead of decorative. The 95% no-return figure is the line I&#8217;ll quote to boards all quarter, cover for a CISO to say the quiet part. A maturity model secures nothing by itself. What it does is drag an executive team from vibes to a roadmap.</p><h3>9. Microsoft&#8217;s Largest Patch Tuesday, and a Zero-Day Hours Later</h3><p>Microsoft shipped its largest Patch Tuesday on record on June 9, fixing nearly 200 vulnerabilities (BleepingComputer). Hours later, a researcher who goes by Nightmare Eclipse published a working zero-day called RoguePlanet that abuses a Microsoft Defender race condition to spawn a SYSTEM-level prompt on fully patched Windows 10 and 11 (The Hacker News). It&#8217;s the seventh zero-day this researcher has dropped since April, part of a running fight with Microsoft over disclosure and bounty pay.</p><p><strong>Why it matters</strong></p><ul><li><p>A SYSTEM-level Defender bypass on fully patched machines turns your endpoint defense into the entry point.</p></li><li><p>It lands the same week CISA warned AI shrinks the disclosure-to-exploitation window.</p></li><li><p>A grudge-driven researcher dropping working exploits is a reminder that bug-bounty relationships are a security control too.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Prioritize the Defender fix path and watch for RoguePlanet indicators on endpoints you assume are clean.</p></li><li><p>Stop treating &#8220;fully patched&#8221; as &#8220;safe.&#8221; Layer detection that doesn&#8217;t depend on the bypassed control.</p></li><li><p>Review your own researcher and disclosure relationships. Antagonized finders publish, they don&#8217;t email.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Nearly 200 fixes in one month is its own tell about how fast attack surface is growing, and the cruelty of RoguePlanet is the timing. You patch on Tuesday, feel responsible, and by Tuesday night your endpoint tool is the hole. I put this next to the CISA directive on purpose. Picture that loop automated, a model reading the patch diff and emitting the bypass while you sleep. Defense in depth was a cliche right up until your antivirus became the payload.</p><h3>10. Academia Goes After Prompt Injection While It&#8217;s Still Bleeding</h3><p>The research wave this week mapped onto the attacks hitting production. On June 11, a team including Pin-Yu Chen, Bo Li, and Dacheng Tao posted a stakeholder-centric benchmark for prompt injection against real-world web agents that operate over untrusted content (arXiv). A day earlier, researchers including Google&#8217;s Tomas Pfister released PI-Hunter, an automated red-teaming system that exposes and localizes prompt injections. Both target the failure mode OWASP maps to six of its ten agentic risk categories.</p><p><strong>Why it matters</strong></p><ul><li><p>Automated red-teaming for prompt injection means defensive tooling is starting to scale with the threat.</p></li><li><p>Benchmarks create accountability. Measure injection resistance and you can demand it in procurement.</p></li><li><p>Academic attention this concentrated usually leads commercial tooling by six to twelve months. This is your early read.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Add prompt-injection benchmarking to agent evaluation before deployment, not after an incident.</p></li><li><p>Put automated injection red-teaming like PI-Hunter in your pre-prod pipeline.</p></li><li><p>Ask vendors for injection-resistance numbers against a named benchmark. Vague assurances are a red flag.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>I read a pile of AI security papers so you don&#8217;t have to, and the encouraging shift is that researchers stopped calling prompt injection a someday problem and started building the rulers and the wrecking balls to measure and break it. Most enterprises are deploying agents on faith. A benchmark turns faith into a number, and a number is something a CISO writes into a contract. Be the buyer who shows up with the benchmark, then watch them sweat.</p><h3>The One Thing You Won&#8217;t Hear About But You Need To: Your AI Agent&#8217;s Memory Is an Unguarded Attack Surface</h3><p>Buried in this week&#8217;s research, with none of the press the model launches got, a paper dated June 10 tackled runtime memory poisoning in persistent LLM agent systems (arXiv). Retrieval-augmented agents increasingly carry persistent memory that accumulates across sessions, so what the agent learned yesterday shapes what it does tomorrow. The author, Tarun Sharma, shows that memory is an attack surface and proposes a certified defense, SMSR. Slip a malicious entry in once, and it steers behavior across every future session until someone notices.</p><p><strong>Why it matters</strong></p><ul><li><p>Persistent memory makes poisoning durable, paying the attacker long after the injection.</p></li><li><p>Most teams don&#8217;t inventory, monitor, or validate agent memory at all. It&#8217;s a blind spot with root-level influence.</p></li><li><p>Certified defenses are early, so right now your only real control is hygiene you probably haven&#8217;t built.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Treat agent long-term memory as untrusted storage. Validate writes, monitor for anomalies, keep an audit trail.</p></li><li><p>Scope and segment memory per user and per task so one poisoned entry can&#8217;t steer everyone.</p></li><li><p>Build a way to inspect and roll back agent memory. You can&#8217;t defend what you can&#8217;t see.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Everybody&#8217;s watching the prompt going in. Almost nobody&#8217;s watching what the agent quietly wrote to its own memory last week. That gap keeps me up. We learned to fear prompt injection as a single dirty input, and now we hand agents long-term memory that turns one input into a permanent resident. Poison it once and the agent carries your attacker&#8217;s instructions forward on its own, looking perfectly healthy the whole time. Watch the memory, not just the mouth.</p><p>&#128073; For ongoing analysis of agentic AI governance frameworks, the conversation continues at <strong><a href="https://rockcybermusings.com/">RockCyber Musings</a></strong>.</p><p>&#128073; Visit <strong><a href="https://www.rockcyber.com/">RockCyber.com</a></strong> to learn more about how we can help with your traditional Cybersecurity and AI Security and Governance journey.</p><p>&#128073; Want to save a quick $100K? Check out our AI Governance Tools at <strong><a href="https://aigovernancetoolkit.com/">AIGovernanceToolkit.com</a></strong></p><p>&#128073; As a bonus, check our AMA on the <strong><a href="https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance/">2026 OWASP GenAI Security Project State of Agentic AI Security and Governance report</a></strong> with me and the other co-leads (it was live, so start at time marker 09:45)</p><div id="youtube2-jK1Z7Z6zlW0" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;jK1Z7Z6zlW0&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/jK1Z7Z6zlW0?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><em>The views and opinions expressed in RockCyber Musings are my own and do not represent the positions of my employer or any organization I&#8217;m affiliated with.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share RockCyber Musings&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share RockCyber Musings</span></a></p><h2>References</h2><p>Abrams, L. (2026, June 10). <em>Microsoft Defender &#8216;RoguePlanet&#8217; zero-day grants SYSTEM privileges</em>. BleepingComputer. https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-rogueplanet-zero-day-grants-system-privileges/</p><p>Accenture. (2026, June 8). <em>Accenture and the Carnegie Mellon University Software Engineering Institute launch AI Adoption Maturity Model to help organizations scale AI with predictable outcomes</em>. Accenture Newsroom. https://newsroom.accenture.com/news/2026/accenture-and-the-carnegie-mellon-university-software-engineering-institute-launch-ai-adoption-maturity-model-to-help-organizations-scale-ai-with-predictable-outcomes</p><p>Carnegie Mellon University Software Engineering Institute. (2026, June 8). <em>SEI and Accenture release AI Adoption Maturity Model to help organizations scale AI with predictable outcomes</em>. https://www.sei.cmu.edu/news/sei-and-accenture-release-ai-adoption-maturity-model-to-help-organizations-scale-ai-with-predictable-outcomes/</p><p>Cybersecurity and Infrastructure Security Agency. (2026, June 8). <em>CISA adds two known exploited vulnerabilities to catalog</em>. https://www.cisa.gov/news-events/alerts/2026/06/08/cisa-adds-two-known-exploited-vulnerabilities-catalog</p><p>Cybersecurity and Infrastructure Security Agency. (2026, June 10). <em>BOD 26-04: Prioritizing security updates based on risk</em>. https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk</p><p>European Commission. (2026, June 10). <em>Commission publishes Code of Practice on marking and labelling AI-generated content</em>. https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1328</p><p>Goldman, S. (2026, June 10). <em>Anthropic accused of &#8216;secret sabotage&#8217; as Claude Fable 5 silently limits capabilities for AI researchers and developers</em>. Fortune. https://fortune.com/2026/06/10/anthropic-accu-claude-fable-5-limits-capabilities-ai-researchers-developers/</p><p>He, P., Miculicich, L., Sharma, V., Fox, A., Lee, G., Tang, J., Pfister, T., &amp; Le, L. T. (2026, June 10). <em>PI-Hunter: Automated red-teaming for exposing and localizing prompt injections</em> [Preprint]. arXiv. https://arxiv.org/abs/2606.12737</p><p>Help Net Security. (2026, June 9). <em>LiteLLM vulnerability under active attack, CISA warns (CVE-2026-42271)</em>. https://www.helpnetsecurity.com/2026/06/09/litellm-vulnerability-under-active-attack-cisa-warns-cve-2026-42271/</p><p>Help Net Security. (2026, June 10). <em>Record Microsoft Patch Tuesday, fresh zero-day</em>. https://www.helpnetsecurity.com/2026/06/10/microsoft-patch-tuesday-rogueplanet/</p><p>Mastercard. (2026, June 10). <em>Mastercard launches Agent Pay for Machines to unlock super-fast, always-on payments</em>. https://www.mastercard.com/us/en/news-and-trends/press/2026/june/mastercard-launches-agent-pay-for-machines.html</p><p>New Relic. (2026, June 10). <em>New Relic report reveals AI-generated code grades higher in review, yet triggers rise in production incidents</em>. Business Wire. https://www.businesswire.com/news/home/20260610259591/en/New-Relic-Report-Reveals-AI-Generated-Code-Grades-Higher-in-Review-Yet-Triggers-Rise-in-Production-Incidents</p><p>Pogorelec, A. (2026, June 11). <em>Prompt injection still drives most agentic AI security failures in production</em>. Help Net Security. https://www.helpnetsecurity.com/2026/06/11/owasp-prompt-injection-ai-security-failures/</p><p>Sharma, T. (2026, June 10). <em>SMSR: Certified defence against runtime memory poisoning in persistent LLM agent systems</em> [Preprint]. arXiv. https://arxiv.org/abs/2606.12703</p><p>The Hacker News. (2026, June 9). <em>LiteLLM flaw CVE-2026-42271 exploited in the wild, chains to unauthenticated RCE</em>. https://thehackernews.com/2026/06/litellm-flaw-cve-2026-42271-exploited.html</p><p>The Hacker News. (2026, June 10). <em>Microsoft Defender RoguePlanet zero-day grants SYSTEM access on updated Windows</em>. https://thehackernews.com/2026/06/microsoft-defender-rogueplanet-zero-day.html</p><p>Wang, Z., Li, Y., Wu, Y., Liu, Z., Chen, K., Wai, F. K., Chen, P.-Y., Thing, V. L. L., Li, B., Tao, D., &amp; Zhang, T. (2026, June 11). <em>Who pays the price? Stakeholder-centric prompt injection benchmarking for real-world web agents</em> [Preprint]. arXiv. https://arxiv.org/abs/2606.13385</p>]]></content:encoded></item><item><title><![CDATA[AIUC-1 After Mythos: The CISO Playbook for Machine-Speed Defense]]></title><description><![CDATA[The AIUC-1 "After Mythos" whitepaper pins CISO readiness at 4/10. Get the three board authorities that close the machine-speed defense gap.]]></description><link>https://www.rockcybermusings.com/p/aiuc-1-after-mythos-machine-speed-defense</link><guid isPermaLink="false">https://www.rockcybermusings.com/p/aiuc-1-after-mythos-machine-speed-defense</guid><dc:creator><![CDATA[Rock Lambros]]></dc:creator><pubDate>Tue, 09 Jun 2026 17:04:56 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!RkHH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F151a97fc-561d-4451-bef5-27609359848b_2048x2048.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RkHH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F151a97fc-561d-4451-bef5-27609359848b_2048x2048.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RkHH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F151a97fc-561d-4451-bef5-27609359848b_2048x2048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!RkHH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F151a97fc-561d-4451-bef5-27609359848b_2048x2048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!RkHH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F151a97fc-561d-4451-bef5-27609359848b_2048x2048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!RkHH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F151a97fc-561d-4451-bef5-27609359848b_2048x2048.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RkHH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F151a97fc-561d-4451-bef5-27609359848b_2048x2048.jpeg" width="1456" height="1456" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/151a97fc-561d-4451-bef5-27609359848b_2048x2048.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1456,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:535605,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/201326170?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F151a97fc-561d-4451-bef5-27609359848b_2048x2048.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RkHH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F151a97fc-561d-4451-bef5-27609359848b_2048x2048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!RkHH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F151a97fc-561d-4451-bef5-27609359848b_2048x2048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!RkHH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F151a97fc-561d-4451-bef5-27609359848b_2048x2048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!RkHH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F151a97fc-561d-4451-bef5-27609359848b_2048x2048.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/p/aiuc-1-after-mythos-machine-speed-defense?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/p/aiuc-1-after-mythos-machine-speed-defense?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p><em>Disclosure: I contribute to the AIUC-1 Consortium. I was not an author or reviewer on this whitepaper. What follows is a review and amplification of work led by the named co-authors and the AIUC-1 editorial team, with my own read on where it should go further. Read the source yourself at <a href="https://www.aiuc-1.com/research/whitepaper-defending-at-machine-speed-after-mythos">aiuc-1.com</a>.</em></p><p>The AIUC-1 &#8220;After Mythos&#8221; whitepaper on machine-speed defense opens with a confession most security executives won&#8217;t say out loud at a conference. Fifty-two of them rated their readiness for a Mythos-class threat at 4 out of 10. I&#8217;ll show you what the document gets right, where I&#8217;d push it harder, and the three board asks worth making before your Q3 budget closes.</p><h2>The 4-Out-Of-10 Confession</h2><p>A 4 out of 10 is a room full of Fortune 500 CISOs, federal agency leaders, and banking and critical-infrastructure executives telling you&#8230; in print&#8230; with names attached&#8230;  that they are behind. Roughly 40% put themselves at 3 or below. About 85% landed at 5 or below. Around 12% rated themselves a 7 or higher. These are the people who own the budgets, the roadmaps, and the org charts, and they graded their own programs as failing.</p><p>The forecast is interesting. The same group expects to reach 6.7 out of 10 in twelve months. Read it as a plan, and it sounds like progress. Read it as an admission, and it tells you the next year is already spoken for. A leadership cohort that sits at 4 today and hopes for 6.7 in a year is telling you the gap is wide enough that closing even part of it will eat the planning cycle.</p><p>Now layer in what&#8217;s already live. 65% of these organizations run AI agents in production today. One in five reports business-critical agent deployments. The credentialed attack surface grew while the readiness number sat at 4. That&#8217;s the confession underneath the confession. The agents are in production, the agentic AI CISO readiness gap is real, and the people running the programs know the controls haven&#8217;t caught up.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AXN5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47378794-b058-458f-b23b-8795684bf81f_3996x1785.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AXN5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47378794-b058-458f-b23b-8795684bf81f_3996x1785.png 424w, https://substackcdn.com/image/fetch/$s_!AXN5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47378794-b058-458f-b23b-8795684bf81f_3996x1785.png 848w, https://substackcdn.com/image/fetch/$s_!AXN5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47378794-b058-458f-b23b-8795684bf81f_3996x1785.png 1272w, https://substackcdn.com/image/fetch/$s_!AXN5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47378794-b058-458f-b23b-8795684bf81f_3996x1785.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AXN5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47378794-b058-458f-b23b-8795684bf81f_3996x1785.png" width="1456" height="650" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/47378794-b058-458f-b23b-8795684bf81f_3996x1785.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:650,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:285971,&quot;alt&quot;:&quot; Two panels. Left, CISO self-rated readiness rising from 4.0 to 6.7 out of 10 over twelve months against a Mythos-ready line at 10. Right, relative offensive capability rising about 5.9 times over the same twelve months, doubling every 4.7 months.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/201326170?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47378794-b058-458f-b23b-8795684bf81f_3996x1785.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt=" Two panels. Left, CISO self-rated readiness rising from 4.0 to 6.7 out of 10 over twelve months against a Mythos-ready line at 10. Right, relative offensive capability rising about 5.9 times over the same twelve months, doubling every 4.7 months." title=" Two panels. Left, CISO self-rated readiness rising from 4.0 to 6.7 out of 10 over twelve months against a Mythos-ready line at 10. Right, relative offensive capability rising about 5.9 times over the same twelve months, doubling every 4.7 months." srcset="https://substackcdn.com/image/fetch/$s_!AXN5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47378794-b058-458f-b23b-8795684bf81f_3996x1785.png 424w, https://substackcdn.com/image/fetch/$s_!AXN5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47378794-b058-458f-b23b-8795684bf81f_3996x1785.png 848w, https://substackcdn.com/image/fetch/$s_!AXN5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47378794-b058-458f-b23b-8795684bf81f_3996x1785.png 1272w, https://substackcdn.com/image/fetch/$s_!AXN5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47378794-b058-458f-b23b-8795684bf81f_3996x1785.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 1: Defender Aspiration Versus Offense Pace, Same 12 Months</figcaption></figure></div><h2>Mythos Moved The Clock On Machine-Speed Defense</h2><p>Here&#8217;s why the 4 stings. In April 2026, Anthropic&#8217;s Claude Mythos Preview surfaced thousands of high-severity flaws across every major operating system and web browser in its early-access cohort. One was a flaw in OpenBSD that had survived 27 years of expert review and decades of automated fuzzing. The whitepaper cites Anthropic&#8217;s reproducibility benchmark, showing that Mythos produced a working exploit on the first attempt for more than 83% of vulnerabilities, compared to a near-zero rate for the prior frontier generation. The offense lifecycle has been compressed from weeks of skilled human effort to one shot.</p><p>The capability didn&#8217;t stay rare. Within weeks, the UK AI Security Institute evaluated OpenAI&#8217;s GPT-5.5 and found it edging Mythos on expert-level cyber tasks. Then the floor dropped. Research published in April 2026, &#8220;Synthesizing Multi-Agent Harnesses for Vulnerability Discovery&#8221; (Liu et al., arXiv 2604.20801), showed a purpose-built multi-agent orchestration architecture that drove a lesser open-weight model to 10 previously unknown Chrome zero-days, including two critical sandbox-escape flaws that Google confirmed: CVE-2026-5280 and CVE-2026-6297. Frontier-grade results came out of components you can download and wire together.</p><p>The trend line is the headline. The UK AI Security Institute estimates frontier cyber capability is doubling every 4.7 months, down from eight months late in 2025. CrowdStrike&#8217;s 2026 Global Threat Report, which is vendor telemetry rather than an independent study, recorded an 89% year-over-year jump in AI-enabled adversary operations, a fastest breakout of 27 seconds, and one intrusion where data left the building four minutes after initial access. Proliferation reaches the sectors that used to coast on obscurity and low adversary interest. Patch cadence, detection latency, and blast-radius tolerance were all calibrated for a world where elite offensive talent was scarce. That world is closing in months.</p><h2>Imperative One: Ship The Patch, Start The Clock</h2><p>The first imperative is the one your operations team will fight you on. Treat the moment you ship a fix as the disclosure event. A Mythos-class model takes the patched binary, diffs it against the prior release, finds the changed call paths, infers what the fix was protecting, and writes a working exploit, all without source code. Your exposure window opens when the patch ships, not when the CVE posts.</p><p>That breaks the 90-day SLA written into most security policies. It strains the 14-day window too. In May 2026, Reuters reported that CISA is weighing a cut of its Known Exploited Vulnerabilities remediation deadline to three days, with the acting director and the national cyber director in the discussion, driven explicitly by Mythos and GPT-class tooling. When the regulator starts talking about three days, your 90-day standard becomes a liability with a compliance stamp on it.</p><p>The practitioner moves to compress the patch cycle are concrete. Set patch SLAs in hours to days for internet-facing, actively exploited, and business-critical assets, and report them to the business as exposure windows rather than audit metrics. Run an LLM-driven security review on every modified line before release. Push the same discipline into procurement, so vendors who can&#8217;t demonstrate short SLAs and AI-assisted discovery get phased out. The supply chain is where this gets real. In March 2026, attackers hijacked the axios npm library, which sees more than 100 million weekly downloads, and the poisoned release executed inside OpenAI&#8217;s macOS app-signing pipeline before the company rotated its certificate. OpenAI&#8217;s own exposure traced to a floating version tag and no minimum release age, the kind of hygiene gap a Mythos-grade adversary now finds at scale.</p><p>I&#8217;ve watched this exact argument for decades. Early in the 2000s, I sat with&#8230; and sometimes I was even a member of&#8230; security teams that fought compressing the patch SLA from 90 days to 30 because the business &#8220;couldn&#8217;t absorb the disruption.&#8221; Six months later, an unpatched system was the way in. The conversation hasn&#8217;t changed. The numbers have. Today, it&#8217;s hours-to-days against an operations team that wants weeks, and the adversary diffing your binary doesn&#8217;t care which side wins the meeting.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tXyY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfc42b3e-077f-41e1-a6da-56ff6a4cea69_3547x1731.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tXyY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfc42b3e-077f-41e1-a6da-56ff6a4cea69_3547x1731.png 424w, https://substackcdn.com/image/fetch/$s_!tXyY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfc42b3e-077f-41e1-a6da-56ff6a4cea69_3547x1731.png 848w, https://substackcdn.com/image/fetch/$s_!tXyY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfc42b3e-077f-41e1-a6da-56ff6a4cea69_3547x1731.png 1272w, https://substackcdn.com/image/fetch/$s_!tXyY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfc42b3e-077f-41e1-a6da-56ff6a4cea69_3547x1731.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tXyY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfc42b3e-077f-41e1-a6da-56ff6a4cea69_3547x1731.png" width="1456" height="711" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bfc42b3e-077f-41e1-a6da-56ff6a4cea69_3547x1731.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:711,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:217220,&quot;alt&quot;:&quot;Log-scale horizontal bars comparing a 90-day patch SLA, a 14-day KEV deadline, a proposed three-day KEV deadline, four-minute exfiltration, and a 27-second breakout.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/201326170?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfc42b3e-077f-41e1-a6da-56ff6a4cea69_3547x1731.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Log-scale horizontal bars comparing a 90-day patch SLA, a 14-day KEV deadline, a proposed three-day KEV deadline, four-minute exfiltration, and a 27-second breakout." title="Log-scale horizontal bars comparing a 90-day patch SLA, a 14-day KEV deadline, a proposed three-day KEV deadline, four-minute exfiltration, and a 27-second breakout." srcset="https://substackcdn.com/image/fetch/$s_!tXyY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfc42b3e-077f-41e1-a6da-56ff6a4cea69_3547x1731.png 424w, https://substackcdn.com/image/fetch/$s_!tXyY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfc42b3e-077f-41e1-a6da-56ff6a4cea69_3547x1731.png 848w, https://substackcdn.com/image/fetch/$s_!tXyY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfc42b3e-077f-41e1-a6da-56ff6a4cea69_3547x1731.png 1272w, https://substackcdn.com/image/fetch/$s_!tXyY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfc42b3e-077f-41e1-a6da-56ff6a4cea69_3547x1731.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 2: Defenders Measure In Days. The Fastest Attacker, In Seconds.</figcaption></figure></div><h2>Imperatives Two And Three: Contain, Then Keep Pace</h2><p>The second imperative is zero trust with the marketing stripped off. Design for breach means building containment in from the start, so a single foothold stays a single foothold. The reason this matters more now than a year ago shows up in CrowdStrike&#8217;s telemetry: 82% of intrusions in 2025 were malware-free, meaning attackers logged in with stolen credentials and used the tools already on the box. Signature defense is watching the wrong door.</p><p>Four moves carry most of the load. Put every agent on least agency, because agents are the fastest-growing population of credentialed actors in most enterprises, and they should default to managed non-human identities with scoped entitlements, clear ownership, and lifecycle controls. Lock endpoints with binary allowlisting, the highest-leverage control almost nobody outside regulated industries runs, because an allowlist doesn&#8217;t negotiate with an exploit. Treat microsegmentation as the multi-year program it is, and in the meantime, push controls outside the context window into gateways, identity, and execution environments where architecture enforces them. Stand up autonomous red teaming so containment gets verified under machine-speed pressure instead of being assumed in a slide. Pair all of it with recovery design: immutable systems, air-gapped backups, identity systems you can rebuild without trusting compromised credentials, and manual fallbacks for business functions that can&#8217;t withstand an extended outage.</p><p>The third imperative is speed at the response end. Self-detection rate becomes your leading metric because handoff times are measured in seconds, and the failure you can&#8217;t afford is learning about a breach from an outsider. Build the machine-speed SOC in three layers: cheap models for high-volume triage, an aggregation layer for correlation and prioritization, and a frontier model on top for the contextual calls. AI remediation that writes the fix to production is the next step, and that agent holds write access to production with a target on its back, so it gets governed like any high-privilege agent, with least privilege, mutual authentication, segmentation, and allowlisting.</p><p>Here&#8217;s where I&#8217;d push past the document. The paper treats agents as high-privilege actors that need identity governance, which is correct and overdue. I&#8217;d go one layer down. The unit of governance is the runtime authorization scope of every agent, every session, every tool call. Static IAM is the precondition. Dynamic authorization scope, enforced at runtime, is the actual control.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2eH1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd49f5869-4aa0-4e4a-8353-7899102bb41e_3327x2131.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2eH1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd49f5869-4aa0-4e4a-8353-7899102bb41e_3327x2131.png 424w, https://substackcdn.com/image/fetch/$s_!2eH1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd49f5869-4aa0-4e4a-8353-7899102bb41e_3327x2131.png 848w, https://substackcdn.com/image/fetch/$s_!2eH1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd49f5869-4aa0-4e4a-8353-7899102bb41e_3327x2131.png 1272w, https://substackcdn.com/image/fetch/$s_!2eH1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd49f5869-4aa0-4e4a-8353-7899102bb41e_3327x2131.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2eH1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd49f5869-4aa0-4e4a-8353-7899102bb41e_3327x2131.png" width="1456" height="933" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d49f5869-4aa0-4e4a-8353-7899102bb41e_3327x2131.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:933,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:262031,&quot;alt&quot;:&quot;A three-layer stack showing cheap-model triage, an aggregation layer, and a frontier model, with an AI remediation agent governed by least privilege, mutual authentication, segmentation, and allowlisting, and a human analyst as orchestrator.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/201326170?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd49f5869-4aa0-4e4a-8353-7899102bb41e_3327x2131.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A three-layer stack showing cheap-model triage, an aggregation layer, and a frontier model, with an AI remediation agent governed by least privilege, mutual authentication, segmentation, and allowlisting, and a human analyst as orchestrator." title="A three-layer stack showing cheap-model triage, an aggregation layer, and a frontier model, with an AI remediation agent governed by least privilege, mutual authentication, segmentation, and allowlisting, and a human analyst as orchestrator." srcset="https://substackcdn.com/image/fetch/$s_!2eH1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd49f5869-4aa0-4e4a-8353-7899102bb41e_3327x2131.png 424w, https://substackcdn.com/image/fetch/$s_!2eH1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd49f5869-4aa0-4e4a-8353-7899102bb41e_3327x2131.png 848w, https://substackcdn.com/image/fetch/$s_!2eH1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd49f5869-4aa0-4e4a-8353-7899102bb41e_3327x2131.png 1272w, https://substackcdn.com/image/fetch/$s_!2eH1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd49f5869-4aa0-4e4a-8353-7899102bb41e_3327x2131.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 3: The Three-Layer AI SOC Stack, Remediation Governed Like Any High-Privilege Agent </figcaption></figure></div><h2>Governance Is An Authority Problem</h2><p>Skip past the three imperatives for a second, because every CISO already knows them. The document&#8217;s real contribution is its honesty about what blocks execution. A SOC re-tooled to run in minutes is still stuck if every new capability waits on control mapping, vendor risk, a procurement cycle, and a board cycle. Governance is where the gap closes first, and the whitepaper says so without flinching: machine-speed operation needs explicit authority boundaries, not faster approvals.</p><p>That resolves into three asks you can take to the board. Compressed patch SLAs need production-change authority delegated from change management. Design-for-breach needs architecture veto power exercised at the design-review stage, before the system ships rather than after. Machine-speed remediation needs pre-approved business-impact authority with bounded autonomy, so the response fires inside agreed limits without a 2 a.m. approval chain. A board that delays these authorities is choosing the readiness gap on purpose, whatever the slide says.</p><p>The whitepaper gets the credential point exactly right. Agents are a population that needs IAM treatment by default, not a special case bolted on later. My one extension connects to a position I&#8217;ve held for a while. Treat governance as architecture, not documentation. The authority structure the paper describes is the architectural-governance pattern in plain clothes. Self-detection rate is the right metric for detection, and the thing that produces a good one is an architectural commitment, not a policy PDF that says you value visibility. Write the control into the system, or you don&#8217;t have it.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9k7g!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb686c7c-d62c-4550-bfd8-b53180d15fab_3702x1973.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9k7g!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb686c7c-d62c-4550-bfd8-b53180d15fab_3702x1973.png 424w, https://substackcdn.com/image/fetch/$s_!9k7g!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb686c7c-d62c-4550-bfd8-b53180d15fab_3702x1973.png 848w, https://substackcdn.com/image/fetch/$s_!9k7g!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb686c7c-d62c-4550-bfd8-b53180d15fab_3702x1973.png 1272w, https://substackcdn.com/image/fetch/$s_!9k7g!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb686c7c-d62c-4550-bfd8-b53180d15fab_3702x1973.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9k7g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb686c7c-d62c-4550-bfd8-b53180d15fab_3702x1973.png" width="1456" height="776" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eb686c7c-d62c-4550-bfd8-b53180d15fab_3702x1973.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:776,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:231903,&quot;alt&quot;:&quot;Three rows mapping each imperative to the board authority it requires: compress the patch cycle to production-change authority, design for breach to architecture veto power, defend at machine speed to pre-approved business-impact authority.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/201326170?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb686c7c-d62c-4550-bfd8-b53180d15fab_3702x1973.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Three rows mapping each imperative to the board authority it requires: compress the patch cycle to production-change authority, design for breach to architecture veto power, defend at machine speed to pre-approved business-impact authority." title="Three rows mapping each imperative to the board authority it requires: compress the patch cycle to production-change authority, design for breach to architecture veto power, defend at machine speed to pre-approved business-impact authority." srcset="https://substackcdn.com/image/fetch/$s_!9k7g!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb686c7c-d62c-4550-bfd8-b53180d15fab_3702x1973.png 424w, https://substackcdn.com/image/fetch/$s_!9k7g!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb686c7c-d62c-4550-bfd8-b53180d15fab_3702x1973.png 848w, https://substackcdn.com/image/fetch/$s_!9k7g!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb686c7c-d62c-4550-bfd8-b53180d15fab_3702x1973.png 1272w, https://substackcdn.com/image/fetch/$s_!9k7g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb686c7c-d62c-4550-bfd8-b53180d15fab_3702x1973.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 4: Each Imperative Needs A Delegated Authority, Not A Faster Approval</figcaption></figure></div><p><strong>Key Takeaway:</strong> The whitepaper&#8217;s 4 out of 10 is a confession in print, and the move that closes the machine-speed defense gap is delegating three authorities your board can grant this quarter.</p><h3>What To Do Next</h3><p>Read the whitepaper yourself at <a href="https://www.aiuc-1.com/research/whitepaper-defending-at-machine-speed-after-mythos">aiuc-1.com</a>. Then run four moves before the quarter closes. Send the paper to your direct reports with one ask: map current SLAs against the three imperatives and flag every gap. Schedule a board cycle on the three authority delegations. Run a preparedness self-rating with your security leadership and compare your number to the 4 out of 10 baseline. Map your top five production agents against the least-agency, allowlist, segmentation, and autonomous-red-team checklist from the second imperative.</p><p>If you want the operating-model view behind this, governance-as-architecture and least agency are the two positions I keep coming back to, and I write about across the newsletter archive at <a href="https://www.rockcybermusings.com">rockcybermusings.com</a>. The board and security-leadership advisory work lives at <a href="https://www.rockcyber.com">rockcyber.com</a> if you want to pressure-test your own number against the baseline.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share RockCyber Musings&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share RockCyber Musings</span></a></p><p>&#128073; Subscribe for more AI security and governance insights with the occasional rant.</p><p>&#128073; For ongoing analysis of agentic AI governance frameworks, the conversation continues at <strong><a href="https://rockcybermusings.com/">RockCyber Musings</a></strong>.</p><p>&#128073; Visit <strong><a href="https://www.rockcyber.com/">RockCyber.com</a></strong> to learn more about how we can help with your traditional Cybersecurity and AI Security and Governance journey.</p><p>&#128073; Want to save a quick $100K? Check out our AI Governance Tools at <strong><a href="https://aigovernancetoolkit.com/">AIGovernanceToolkit.com</a></strong></p><p>&#128073; As a bonus, <strong><a href="https://www.youtube.com/watch?v=rwlVTLyqIv8">check out my conversation with Eva Benn</a></strong> where we talked about the cybersecurity skills you need to develop to stay relevant in 2026 and beyond.</p><div id="youtube2-rwlVTLyqIv8" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;rwlVTLyqIv8&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/rwlVTLyqIv8?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><em>The views and opinions expressed in RockCyber Musings are my own and do not represent the positions of my employer or any organization I&#8217;m affiliated with.</em></p>]]></content:encoded></item><item><title><![CDATA[Claude Code Skills: Put The Discipline In The File]]></title><description><![CDATA[Stop hoarding prompts. RockCyber's open-source Claude Code skills catch the ML, security, and reproducibility failures AI ships confidently.]]></description><link>https://www.rockcybermusings.com/p/claude-code-skills-put-the-discipline-in-the-file</link><guid isPermaLink="false">https://www.rockcybermusings.com/p/claude-code-skills-put-the-discipline-in-the-file</guid><dc:creator><![CDATA[Rock Lambros]]></dc:creator><pubDate>Tue, 02 Jun 2026 12:50:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!8Bv3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdec7e290-6663-4c20-8fe2-3abcb1cbe2d0_2048x2048.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8Bv3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdec7e290-6663-4c20-8fe2-3abcb1cbe2d0_2048x2048.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8Bv3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdec7e290-6663-4c20-8fe2-3abcb1cbe2d0_2048x2048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!8Bv3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdec7e290-6663-4c20-8fe2-3abcb1cbe2d0_2048x2048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!8Bv3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdec7e290-6663-4c20-8fe2-3abcb1cbe2d0_2048x2048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!8Bv3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdec7e290-6663-4c20-8fe2-3abcb1cbe2d0_2048x2048.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8Bv3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdec7e290-6663-4c20-8fe2-3abcb1cbe2d0_2048x2048.jpeg" width="1456" height="1456" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dec7e290-6663-4c20-8fe2-3abcb1cbe2d0_2048x2048.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1456,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:635055,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/199064896?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdec7e290-6663-4c20-8fe2-3abcb1cbe2d0_2048x2048.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8Bv3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdec7e290-6663-4c20-8fe2-3abcb1cbe2d0_2048x2048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!8Bv3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdec7e290-6663-4c20-8fe2-3abcb1cbe2d0_2048x2048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!8Bv3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdec7e290-6663-4c20-8fe2-3abcb1cbe2d0_2048x2048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!8Bv3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdec7e290-6663-4c20-8fe2-3abcb1cbe2d0_2048x2048.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/p/claude-code-skills-put-the-discipline-in-the-file?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/p/claude-code-skills-put-the-discipline-in-the-file?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p>Claude Code skills are how I stopped re-explaining the same discipline to an AI on every session. Last year <a href="https://www.veracode.com/blog/genai-code-security-report/">Veracode tested code from more than 100 large language models and found security flaws in 45% of it</a>. That matches what I keep seeing in my machine learning and data science work, where the model returns an answer that looks correct and is wrong underneath. This week, I put my skills library on <strong><a href="https://github.com/rocklambros/rcs">GitHub</a> at rocklambros/RCS</strong>. It's the portable half of a setup I've been building in the open. The skills drop into the Claude Code harness I documented at <strong><a href="https://github.com/rocklambros/harness-engineering">rocklambros/harness-engineering</a></strong>, and they ride alongside the <strong><a href="https://www.rockcybermusings.com/p/claude-secure-coding-rules-open-source-ai-security">secure coding rules I open-sourced</a></strong> to stop Claude generating vulnerable code in the first place. Here is what is inside, starting with the skill that saved me the most pain.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Iy80!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fa855ae-0d56-4385-a6db-19561dfd9bd2_1762x1072.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Iy80!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fa855ae-0d56-4385-a6db-19561dfd9bd2_1762x1072.png 424w, https://substackcdn.com/image/fetch/$s_!Iy80!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fa855ae-0d56-4385-a6db-19561dfd9bd2_1762x1072.png 848w, https://substackcdn.com/image/fetch/$s_!Iy80!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fa855ae-0d56-4385-a6db-19561dfd9bd2_1762x1072.png 1272w, https://substackcdn.com/image/fetch/$s_!Iy80!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fa855ae-0d56-4385-a6db-19561dfd9bd2_1762x1072.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Iy80!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fa855ae-0d56-4385-a6db-19561dfd9bd2_1762x1072.png" width="1456" height="886" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1fa855ae-0d56-4385-a6db-19561dfd9bd2_1762x1072.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:886,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:78830,&quot;alt&quot;:&quot;Horizontal bar chart of AI code security failure rates by language, Java highest at 72 percent, 45 percent overall&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/199064896?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fa855ae-0d56-4385-a6db-19561dfd9bd2_1762x1072.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Horizontal bar chart of AI code security failure rates by language, Java highest at 72 percent, 45 percent overall" title="Horizontal bar chart of AI code security failure rates by language, Java highest at 72 percent, 45 percent overall" srcset="https://substackcdn.com/image/fetch/$s_!Iy80!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fa855ae-0d56-4385-a6db-19561dfd9bd2_1762x1072.png 424w, https://substackcdn.com/image/fetch/$s_!Iy80!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fa855ae-0d56-4385-a6db-19561dfd9bd2_1762x1072.png 848w, https://substackcdn.com/image/fetch/$s_!Iy80!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fa855ae-0d56-4385-a6db-19561dfd9bd2_1762x1072.png 1272w, https://substackcdn.com/image/fetch/$s_!Iy80!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fa855ae-0d56-4385-a6db-19561dfd9bd2_1762x1072.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 1: AI-Generated Code Fails Security Tests in 45% of Tasks</figcaption></figure></div><h2>The Prompt You Keep Pasting Is A Skill</h2><p>I spent more time than I should have just copying the same prompt into Claude from a cacophony of Notion notebooks and saved text files. I can tell you how many times I told Claude to stop trusting a clean p-value, to check the assumptions behind a statistical test before reporting it, and to refuse the easy answer when the data didn&#8217;t support it. I pasted some version of that into a fresh chat a few hundred times. Every session started from zero. The model holds no memory of the discipline I taught it yesterday, so I taught it again, and the wording drifted a little each time.</p><p>That is the tell. If you keep pasting the same instructions, you have already written something. You never saved it in a form the tool can load on its own. A Claude Code skill is that saved form, a single markdown file with a description that the model reads to decide whether the file applies to your question. Once it is installed, the model consults it without being asked. The discipline lives in the file instead of your head, and your head is where discipline goes to get forgotten.</p><p>Here is the example that pushed me over the edge. I was building a multi-turn prompt-injection detector for the Deep Learning course in my Master&#8217;s program, and I had two models to compare on the same set of 5,130 test conversations. The temporal LSTM scored an F1 of 0.837. Adding an attention layer on top scored 0.837 as well, with confidence intervals nearly overlapping. Ask an AI whether the attention version is the better model, and most will wave it through as a free upgrade, since the interpretability costs nothing. The honest answer is that there is no improvement to claim. A paired bootstrap on the same conversations yields a difference of zero (p = 0.453), nowhere near significant. A p-value is the chance a gap this size would show up even when the two models are truly identical, and at 0.453 it would show up almost half the time, so there's no real difference to claim. Both models saw the identical test set, so the comparison is paired, and treating it any other way invents a result that is not in the data. That is a confident wrong answer, and it is the kind that ends up on a slide in front of a board (or in a classroom, with a professor sitting as &#8220;chairman,&#8221; in my case).</p><h2>The Premortem I Kept Rebuilding By Hand</h2><p>The skill I want you to remember is running-adversarial-premortem. It came out of that same habit. I kept asking the model to argue against my own designs, and I kept getting agreement dressed up as analysis. I wrote the method down and made it a skill.</p><p>A premortem flips the usual review. Rather than asking what could go wrong, it assumes the work will fail in six months and traces the cause. The skill runs in three rounds. Round one assumes failure and lists five to ten ways it happened, seeded by category: the premise was wrong, the method was biased, the code didn&#8217;t match the design, the deployment was botched, the audience misread the result. Round two chains each failure back to a root cause. Round three scores what survives.</p><p>The scoring is where it earns its keep. Each surviving failure mode gets a severity, a likelihood, and a detectability, and the priority is severity times likelihood divided by detectability. A quiet, high-damage failure that nothing would catch ranks above a loud one that your CI already flags. Two fields force honesty. Every concern carries its strongest counterargument, the most generous defense of the design, so you engage the work rather than strawmanning it. Every concern also names what would have to be true for you to stop worrying, a condition the skill calls &#8220;stops mattering if.&#8221; A worry with no stopping condition is anxiety wearing a citation, not analysis.</p><p>The skill also refuses to fire when it shouldn&#8217;t. Ask it to scan a loop for an off-by-one error, and it hands you off to a plain code review, because a premortem on a one-line fix costs more than the bug. That refusal is tested, not promised, and I will come back to why that matters.</p><p>You will find it at skills/workflow/running-adversarial-premortem. The method itself is old. Gary Klein wrote it up for Harvard Business Review in 2007. What changed is that the discipline now loads itself when the stakes are high, instead of waiting for me to remember to run it.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BHxm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92d6c04f-0089-4b9f-a2e7-d186d5015670_2400x1960.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BHxm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92d6c04f-0089-4b9f-a2e7-d186d5015670_2400x1960.png 424w, https://substackcdn.com/image/fetch/$s_!BHxm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92d6c04f-0089-4b9f-a2e7-d186d5015670_2400x1960.png 848w, https://substackcdn.com/image/fetch/$s_!BHxm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92d6c04f-0089-4b9f-a2e7-d186d5015670_2400x1960.png 1272w, https://substackcdn.com/image/fetch/$s_!BHxm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92d6c04f-0089-4b9f-a2e7-d186d5015670_2400x1960.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BHxm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92d6c04f-0089-4b9f-a2e7-d186d5015670_2400x1960.png" width="2400" height="1960" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/92d6c04f-0089-4b9f-a2e7-d186d5015670_2400x1960.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1960,&quot;width&quot;:2400,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:335078,&quot;alt&quot;:&quot;Flowchart showing the premortem assuming failure, chaining to root causes, and scoring by severity times likelihood divided by detectability]&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/199064896?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31f0dc71-1ab0-4d40-b655-f4ab05f30072_2400x1960.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Flowchart showing the premortem assuming failure, chaining to root causes, and scoring by severity times likelihood divided by detectability]" title="Flowchart showing the premortem assuming failure, chaining to root causes, and scoring by severity times likelihood divided by detectability]" srcset="https://substackcdn.com/image/fetch/$s_!BHxm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92d6c04f-0089-4b9f-a2e7-d186d5015670_2400x1960.png 424w, https://substackcdn.com/image/fetch/$s_!BHxm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92d6c04f-0089-4b9f-a2e7-d186d5015670_2400x1960.png 848w, https://substackcdn.com/image/fetch/$s_!BHxm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92d6c04f-0089-4b9f-a2e7-d186d5015670_2400x1960.png 1272w, https://substackcdn.com/image/fetch/$s_!BHxm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92d6c04f-0089-4b9f-a2e7-d186d5015670_2400x1960.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 2: The Adversarial Premortem In Three Rounds</figcaption></figure></div><h2>The Highest-Priority Skill Is The Most Boring One</h2><p>Every skill in the library carries a priority score I call &#931;, a rough estimate of how often the gap shows up multiplied by how badly things break when you miss it. The top of the list is not the premortem or any of the security skills. It is enforcing-seed-hygiene, at &#931; 20, the only skill that hits the maximum. It exists because randomness is everywhere in machine learning, and almost nobody pins it correctly.</p><p>Here is the failure... You train a model, get a number, write it down. A colleague runs the same code on the same data and gets a different number. Now neither of you knows which result to trust, and the paper or the production model sits on sand. <a href="https://arxiv.org/abs/2406.14325">A 2025 review of machine-learning reproducibility</a> put the fix plainly: fixed random seeds should be set and published to control the many sources of nondeterminism in ML. The same authors flag a catch that trips people up, which is that seeds hold only when the work is not running in parallel on a GPU.</p><p>That GPU catch is the part people miss, and the skill handles it. One seed isn&#8217;t enough. Python&#8217;s own hashing, NumPy, PyTorch, JAX, and R each carry a separate generator, and parallel thread scheduling on a GPU produces floating-point sums that do not land bit-for-bit the same across machines. The skill emits a single first-cell block that seeds every library you named, sets PYTHONHASHSEED, and, for sampler workloads, pins the thread count so a run on your laptop matches the one on the Linux server. It refuses the wrong job too. Ask it to seed a cryptographic nonce, and it stops you, because a fixed seed there is a vulnerability, not a discipline.</p><p>It lives at skills/workflow/enforcing-seed-hygiene. That is the profile a &#931; 20 earns. It shows up on nearly every project, and it ruins the results when you skip it.</p><h2>Vet The MCP Server Before You Trust It</h2><p>The skill I want in front of security people is auditing-mcp-server-pre-trust, at &#931; 18. Model Context Protocol servers are how your AI reaches out to tools and data, and the ecosystem grew faster than its security did. <a href="https://arxiv.org/abs/2506.13538">A 2025 study from Queen&#8217;s University</a> analyzed 1,899 open-source MCP servers and found 7.2% carrying general vulnerabilities and 5.5% exhibiting tool poisoning, where a hostile server hides instructions inside a tool&#8217;s description to steer the model without you ever seeing them.</p><p>Don&#8217;t count on the model to catch it. A separate benchmark, <a href="https://arxiv.org/abs/2508.14925">MCPTox</a>, ran tool-poisoning attacks against 20 agents and found they almost never refuse. The best refusal rate from a single Claude model came in under 3%. The model reads the poisoned description and follows it. The paper found that more capable models were often <em>more</em> susceptible, because the attack rides on their stronger instruction-following. That puts the decision where it belongs, with you, before the server gets registered.</p><p>The skill runs six checks ahead of that registration: license, source review, network egress, version pin, secret handling, and the subset of tools you need. The version pin alone catches a class of foot-guns. A server installed with npx -y or an unpinned pip install can shift underneath you between the audit and the next run, so the skill treats anything unpinned as a blocking failure. Each check has to cite evidence, a file, a line, or a commit, so the audit cannot decay into a checkbox ritual.</p><p>The boundary for a skill like this is design-time and registration-time discipline. It runs inside the model&#8217;s reasoning, before the connection goes live. It cannot see what the agent does once it is running, which tools it calls, what data left the building, or whether the action matched the intent you approved. That is a different control layer, and nothing in this repo provides it. Closing it takes interception at the moment a tool executes, structured traces a security team can query rather than vendor-specific log soup, and a live inventory of every tool, model, and dataset the agent touched, the way a software bill of materials tracks dependencies. The skills are the author-time half of a problem, with the other half running in production. Know which half you have covered.</p><p>It lives at skills/security/auditing-mcp-server-pre-trust.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2yGO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd623a8a2-096e-4ed9-aae6-c645ceaf59a6_2720x1200.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2yGO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd623a8a2-096e-4ed9-aae6-c645ceaf59a6_2720x1200.png 424w, https://substackcdn.com/image/fetch/$s_!2yGO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd623a8a2-096e-4ed9-aae6-c645ceaf59a6_2720x1200.png 848w, https://substackcdn.com/image/fetch/$s_!2yGO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd623a8a2-096e-4ed9-aae6-c645ceaf59a6_2720x1200.png 1272w, https://substackcdn.com/image/fetch/$s_!2yGO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd623a8a2-096e-4ed9-aae6-c645ceaf59a6_2720x1200.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2yGO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd623a8a2-096e-4ed9-aae6-c645ceaf59a6_2720x1200.png" width="1456" height="642" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d623a8a2-096e-4ed9-aae6-c645ceaf59a6_2720x1200.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:642,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:181100,&quot;alt&quot;:&quot;Diagram contrasting author-time skills with the runtime layer of interception, structured tracing, and a live agent inventory that skills cannot provide&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/199064896?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd623a8a2-096e-4ed9-aae6-c645ceaf59a6_2720x1200.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Diagram contrasting author-time skills with the runtime layer of interception, structured tracing, and a live agent inventory that skills cannot provide" title="Diagram contrasting author-time skills with the runtime layer of interception, structured tracing, and a live agent inventory that skills cannot provide" srcset="https://substackcdn.com/image/fetch/$s_!2yGO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd623a8a2-096e-4ed9-aae6-c645ceaf59a6_2720x1200.png 424w, https://substackcdn.com/image/fetch/$s_!2yGO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd623a8a2-096e-4ed9-aae6-c645ceaf59a6_2720x1200.png 848w, https://substackcdn.com/image/fetch/$s_!2yGO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd623a8a2-096e-4ed9-aae6-c645ceaf59a6_2720x1200.png 1272w, https://substackcdn.com/image/fetch/$s_!2yGO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd623a8a2-096e-4ed9-aae6-c645ceaf59a6_2720x1200.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 3: Two Halves Of Agent Governance, Author-Time And Runtime</figcaption></figure></div><h2>Your Instruction Files Are Rotting</h2><p>The last skill, auditing-instruction-hierarchy at &#931; 18, fixes a problem you can&#8217;t see until it bites. The CLAUDE.md files that tell the model how to behave grow without limit, and a larger instruction file is not necessarily better. Chroma&#8217;s 2025 &#8220;Context Rot&#8221; study tested 18 frontier models and found that output quality drops as input length grows, even on simple tasks, well before the context window is anywhere near full. Every line you add to an instruction file competes for the model&#8217;s attention with the work in front of it.</p><p>My own test harness sets a hard cap of 400 lines across the entire instruction hierarchy, with 250 as the target. Past 400, instruction-following degrades measurably. The skill counts the lines across every CLAUDE.md in play, from the user-level file down to the ones plugins quietly drop in, and it greps for content that breaks the prompt cache: literal dates, session IDs, anything that changes between runs and forces the model to re-read the whole prefix every five minutes. Then it sorts each rule into a verdict. Keep it, move it to a skill that loads on demand, move it to a hook, or drop it.</p><p>I ran it against this repo while building it. The skill&#8217;s own evidence list names RCS, which is the polite way of saying it found things in my own setup worth trimming. It lives at skills/claude-code-meta/auditing-instruction-hierarchy.</p><h2>What The Claude Code Skills Repo Ships</h2><p>The four skills above are a sample. The repo ships 104 of them, all in the shipped state with none in draft, organized into five tracks by who needs them: security, machine learning and data science, cross-cutting workflow, teaching, and Claude Code meta-work. The whole library is MIT licensed.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cviR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10c490aa-c2d9-4320-8a46-7827cda96475_1918x1068.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cviR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10c490aa-c2d9-4320-8a46-7827cda96475_1918x1068.png 424w, https://substackcdn.com/image/fetch/$s_!cviR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10c490aa-c2d9-4320-8a46-7827cda96475_1918x1068.png 848w, https://substackcdn.com/image/fetch/$s_!cviR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10c490aa-c2d9-4320-8a46-7827cda96475_1918x1068.png 1272w, https://substackcdn.com/image/fetch/$s_!cviR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10c490aa-c2d9-4320-8a46-7827cda96475_1918x1068.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cviR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10c490aa-c2d9-4320-8a46-7827cda96475_1918x1068.png" width="1456" height="811" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/10c490aa-c2d9-4320-8a46-7827cda96475_1918x1068.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:811,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:93833,&quot;alt&quot;:&quot;Horizontal bar chart of the four featured skills by &#931; priority score, seed hygiene highest at 20&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/199064896?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10c490aa-c2d9-4320-8a46-7827cda96475_1918x1068.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Horizontal bar chart of the four featured skills by &#931; priority score, seed hygiene highest at 20" title="Horizontal bar chart of the four featured skills by &#931; priority score, seed hygiene highest at 20" srcset="https://substackcdn.com/image/fetch/$s_!cviR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10c490aa-c2d9-4320-8a46-7827cda96475_1918x1068.png 424w, https://substackcdn.com/image/fetch/$s_!cviR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10c490aa-c2d9-4320-8a46-7827cda96475_1918x1068.png 848w, https://substackcdn.com/image/fetch/$s_!cviR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10c490aa-c2d9-4320-8a46-7827cda96475_1918x1068.png 1272w, https://substackcdn.com/image/fetch/$s_!cviR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10c490aa-c2d9-4320-8a46-7827cda96475_1918x1068.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Figure 4: The Four Featured Skills, By &#931; Priority</figcaption></figure></div><p>Two design choices matter when deciding whether to trust it. The first is that it is catalog-free. There are no bundled framework controls and no ISO mirrors copied in to rot the day after I commit them. The skills encode method, not reference material that goes stale. The second is that every skill ships with three test scenarios, a normal case, an edge case, and an anti-trigger that checks the skill stays quiet when it should not fire. That last one is the part most prompt collections skip, and it separates a helpful skill from one that fires on everything and turns into noise.</p><p>Install is a clone and a symlink loop that drops each skill into your ~/.claude/skills directory, skipping anything already there. The skills compose themselves. Start an ML notebook and the scaffolding skill, the seed-hygiene skill, and the train-test-split audit fire in sequence without you wiring them together.</p><p><strong>Key Takeaway:</strong> If you keep pasting the same instructions into an AI, turn them into Claude Code skills, because the discipline you do not write down is the discipline you lose every session.</p><h3>What to do next</h3><p>Clone the repo, install the skills, and point the premortem at the next design you are about to commit to. Watch it argue with you. The repo is at <a href="https://github.com/rocklambros/RCS">github.com/rocklambros/RCS</a>, and the install steps are in the README.</p><p>If you want the thinking behind this kind of work, the AI security and governance advisory I run lives at <a href="https://rockcyber.com">rockcyber.com,</a> and the rest of these teardowns are at <a href="https://rockcybermusings.com">rockcybermusings.com</a>. Tell me which skill broke something useful. The anti-trigger tests catch a lot, and you will still find edges I missed.</p><p>Subscribe for more AI security and governance insights with the occasional rant.</p><p></p><p>&#128073; Subscribe for more AI security and governance insights with the occasional rant.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.rockcybermusings.com/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share RockCyber Musings&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.rockcybermusings.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share RockCyber Musings</span></a></p><p>&#128073; For ongoing analysis of agentic AI governance frameworks, the conversation continues at <strong><a href="https://rockcybermusings.com/">RockCyber Musings</a></strong>.</p><p>&#128073; Visit <strong><a href="https://www.rockcyber.com/">RockCyber.com</a></strong> to learn more about how we can help with your traditional Cybersecurity and AI Security and Governance journey.</p><p>&#128073; Want to save a quick $100K? Check out our AI Governance Tools at <strong><a href="https://aigovernancetoolkit.com/">AIGovernanceToolkit.com</a></strong></p><p>&#128073; As a bonus, <strong><a href="https://www.youtube.com/watch?v=rwlVTLyqIv8">check out my conversation with Eva Benn</a></strong> where we talked about the cybersecurity skills you need to develop to stay relevant in 2026 and beyond.</p><div id="youtube2-rwlVTLyqIv8" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;rwlVTLyqIv8&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/rwlVTLyqIv8?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><em>The views and opinions expressed in RockCyber Musings are my own and do not represent the positions of my employer or any organization I&#8217;m affiliated with.</em></p>]]></content:encoded></item><item><title><![CDATA[Weekly Musings Top 10 AI Security Wrapup: Issue 40 May 22-May 28, 2026]]></title><description><![CDATA[When the White House Blinks, the Threat Actors Don&#8217;t]]></description><link>https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260522-20260528</link><guid isPermaLink="false">https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260522-20260528</guid><dc:creator><![CDATA[Rock Lambros]]></dc:creator><pubDate>Fri, 29 May 2026 12:50:13 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-XwX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F022dc9c4-3a97-4f0c-9a2e-76e6f429303a_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-XwX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F022dc9c4-3a97-4f0c-9a2e-76e6f429303a_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-XwX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F022dc9c4-3a97-4f0c-9a2e-76e6f429303a_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!-XwX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F022dc9c4-3a97-4f0c-9a2e-76e6f429303a_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!-XwX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F022dc9c4-3a97-4f0c-9a2e-76e6f429303a_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!-XwX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F022dc9c4-3a97-4f0c-9a2e-76e6f429303a_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-XwX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F022dc9c4-3a97-4f0c-9a2e-76e6f429303a_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/022dc9c4-3a97-4f0c-9a2e-76e6f429303a_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1233556,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.rockcybermusings.com/i/199672029?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F022dc9c4-3a97-4f0c-9a2e-76e6f429303a_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-XwX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F022dc9c4-3a97-4f0c-9a2e-76e6f429303a_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!-XwX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F022dc9c4-3a97-4f0c-9a2e-76e6f429303a_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!-XwX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F022dc9c4-3a97-4f0c-9a2e-76e6f429303a_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!-XwX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F022dc9c4-3a97-4f0c-9a2e-76e6f429303a_1024x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Trump pulled the executive order. Anthropic shipped a model that finds vulnerabilities by the thousand. Threat actors poisoned developer AI assistants with invisible characters. The week of May 22 through 28, 2026, didn&#8217;t give CISOs a quiet moment. The federal government cannot decide if AI is a threat or a savior. Attackers keep outpacing the policies meant to slow them.</p><p>The week&#8217;s signal lived in the contrast. Anthropic&#8217;s Mythos model surfaced 10,000 critical vulnerabilities in a month. The White House could not get a single executive order across the line. CISA sat at the table without a vote. Attackers poisoned AI coding assistant config files with invisible Unicode. A malicious npm package exfiltrated files from Claude AI&#8217;s working directory. AI capability keeps accelerating. AI governance keeps collapsing. Security teams who treat the next 90 days as business as usual will be explaining decisions to regulators they cannot defend.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260522-20260528?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260522-20260528?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h3>Agent Control Standard Launches Open Runtime Governance Framework for AI Agents</h3><p>The Agent Control Standard launched on May 27, 2026 at the AI Agent Security Summit in San Francisco, releasing a vendor-agnostic, open framework for runtime governance of AI agents (BusinessWire, VMblog). Existing protocols govern how agents communicate with each other. None cover what they actually do once they start acting inside enterprise environments. ACS targets that gap with a common framework for runtime enforcement, intervention, and policy governance across agent ecosystems. The specification is released as open source under the MIT license, with no single company controlling the spec. Michael Bargury, co-founder and CTO of Zenity, is co-creator. Full disclosure, I serve as director of AI standards and governance at Zenity and contribute to ACS.</p><p><strong>Why it matters</strong></p><ul><li><p>The industry has a control-layer gap. MCP and other protocols cover communication, not what agents do once they act.</p></li><li><p>Runtime governance has been a per-vendor build problem, which has been blocking enterprise procurement and audit.</p></li><li><p>An open, vendor-neutral spec gives regulators and auditors a reference point that does not depend on a single platform&#8217;s roadmap.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Read the spec at agentcontrolstandard.ai and map it against your current agent runtime controls.</p></li><li><p>Ask your AI agent platform vendors which parts of ACS they will support and on what timeline.</p></li><li><p>Add ACS-style runtime controls including policy enforcement, intervention, and kill switches to your 2027 agent governance roadmap.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Full disclosure up top. I am leading ACS, so putting this up top is my prerogative &#128512;. Read this knowing that. The reason we built it is the same reason I keep writing about agent governance every week. Everyone I talk to is putting agents into production with no runtime enforcement layer, no intervention model, and no audit trail that survives a regulator&#8217;s question. The vendor-by-vendor approach was never going to scale. We needed a common spec that any platform could implement and any auditor could point to. That is what ACS is. Go read it at https://agentcontrolstandard.ai, push your vendors to support it, and tell us where it falls short.</p><h3>2. Axios Publishes the Killed AI Executive Order Text</h3><p>Axios published the full text of the canceled AI executive order on May 22, 2026, the day after President Trump pulled the signing ceremony (Axios, NPR). The draft included a voluntary Treasury clearinghouse for AI security vulnerabilities and a pre-launch review process where major AI companies would share frontier models with the government for up to 90 days. CEOs from OpenAI, Anthropic, and other major labs had been invited.</p><p><strong>Why it matters</strong></p><ul><li><p>The federal government walked away from the only proposed coordination mechanism for AI vulnerability sharing.</p></li><li><p>Any serious U.S. AI security baseline now has to come from industry, state regulators, or international peers.</p></li><li><p>AI vendors with CAISI evaluation agreements face uncertainty about whether voluntary testing remains the expectation.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Set your own baseline using the NIST AI RMF and the joint CISA-Five Eyes agentic AI guidance from May 1.</p></li><li><p>Map which AI vendors have signed CAISI evaluation agreements and treat that as third-party risk data.</p></li><li><p>Engage with state AI laws including California SB 942 and Texas HB 149 rather than waiting on Washington.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>The administration spent months convening industry CEOs and threading a needle on voluntary frontier model review. Then it walked away because the work sounded like regulation. Plan as if no federal framework is coming for the rest of this administration. State attorneys general will probe your AI governance posture soon enough. More at https://www.rockcybermusings.com.</p><h3>3. Anthropic&#8217;s Project Glasswing Finds 10,000 Critical Vulnerabilities in One Month</h3><p>Anthropic published an update to Project Glasswing on May 22, 2026, reporting that Claude Mythos Preview, working with roughly 50 partner organizations, identified more than 10,000 high or critical-severity vulnerabilities in about four weeks (Anthropic, CSO Online). Cloudflare alone surfaced about 2,000 bugs, 400 rated high or critical. Mozilla patched 271 vulnerabilities in Firefox 150, ten times the count from an earlier Claude Opus 4.6 run. Six independent firms validated 1,752 findings, with 90.6% confirmed as true positives.</p><p><strong>Why it matters</strong></p><ul><li><p>The model is doing in days what well-staffed AppSec teams take quarters to complete.</p></li><li><p>Software vendors are now expected to keep pace with AI-found bugs at speeds no human team can match.</p></li><li><p>Vulnerability management economics change when triage volume jumps an order of magnitude in a month.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Pressure software vendors for AI-assisted vulnerability discovery details and patch SLA commitments.</p></li><li><p>Update patch and risk acceptance policies for a world where critical bugs surface at machine speed.</p></li><li><p>Pilot AI-assisted code review inside your own engineering organization before your competitors do.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Project Glasswing is the first credible public demonstration of large-scale AI vulnerability discovery. Mozilla&#8217;s 271 Firefox patches in one release is a confession that we have all been underspending on AppSec for a decade. The harder question is what happens when threat actors get this capability. If your patch SLA is 30 days, you are living on borrowed time.</p><h3>4. CISA Sidelined in White House AI Cyber Response</h3><p>Axios reported on May 26, 2026 that CISA has been pushed to the margins of the administration&#8217;s AI cyber response, with one industry source describing the agency as &#8220;at the table, not in the game&#8221; (Axios, Newsmax). CISA leadership joins early White House calls led by the Office of the National Cyber Director, but has little influence. The agency has lost roughly one-third of its workforce since the start of 2025. The FY2027 budget proposal calls for another quarter of staff cut and $707 million in funding reductions.</p><p><strong>Why it matters</strong></p><ul><li><p>The federal civilian operational cyber agency is being structurally weakened as AI reshapes the threat picture.</p></li><li><p>Private sector relationships built on CISA&#8217;s information sharing face uncertainty about continuity.</p></li><li><p>State and local governments who depend on CISA for technical support face longer response times.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Diversify your federal cyber relationships. Build direct ties to FBI cyber, Secret Service, and your sector ISAC.</p></li><li><p>Review incident response plans for assumptions about CISA support and revise where federal assistance is uncertain.</p></li><li><p>Engage with state cyber programs in your operating jurisdictions, since state authorities will inherit the burden.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>CISA was supposed to be the federal cyber civilian backstop. Watching it get hollowed out while the threat surface explodes is one of the most demoralizing things I have seen in this field. Build your federal incident response playbook around the assumption that CISA will be slow, understaffed, and unable to provide the level of technical assistance you got in 2024. The federal cavalry is not coming this year.</p><h3>5. Check Point Report Finds 51-Point Gap Between AI Security Intent and Capability</h3><p>Check Point released its 2026 Cloud Security Report on May 26, 2026, finding that 77% of organizations have updated their cloud security strategy for AI, while only 26% have the architecture to enforce those policies (Check Point, PR Newswire). The 51-point gap pairs with 78% of organizations reporting confirmed or suspected AI-related security incidents in the past year. Seventy percent now run generative AI in production. Only 5% have full visibility into AI usage. Only 14% actively enforce and audit AI security policies.</p><p><strong>Why it matters</strong></p><ul><li><p>AI adoption has structurally outpaced security architecture at a board-level scale.</p></li><li><p>Shadow AI is no longer a future risk. It is the current operating reality.</p></li><li><p>Vendors building generative AI security controls now have a credible commercial story for board-level investment cases.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Run an AI usage discovery exercise this quarter. You cannot govern what you cannot see.</p></li><li><p>Tie generative AI policy enforcement to identity controls and DLP systems rather than standalone AI proxies.</p></li><li><p>Make AI visibility metrics a recurring agenda item for your risk committee with a 12-month target.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Almost 80% of organizations have already had an AI security incident, and only 1 in 20 know what AI is running across their environment. We are in the consequences phase, and most security teams are still arguing about which AI proxy vendor to evaluate. The fix is not buying another tool. The fix is treating AI like data, applying the same identity, access, and monitoring discipline you apply to every critical workload. More at https://www.rockcyber.com.</p><h3>6. TrapDoor Supply Chain Attack Poisons AI Coding Assistants</h3><p>Researchers at Socket and partner firms disclosed TrapDoor, a coordinated supply chain campaign that pushed more than 34 malicious packages across npm, PyPI, and Crates.io (The Hacker News, Socket, Phoenix Security). The earliest package appeared on May 22, 2026. TrapDoor&#8217;s novel component injects hidden instructions into .cursorrules and CLAUDE.md files using zero-width Unicode characters. The payload looks invisible in a code editor. AI coding assistants process the hidden text as live prompts. The campaign also opened pull requests against open-source AI projects including LangChain, MetaGPT, LangFlow, and OpenHands.</p><p><strong>Why it matters</strong></p><ul><li><p>The attack weaponizes the AI coding assistant itself as the execution layer, a new class of supply chain compromise.</p></li><li><p>Existing software composition analysis tooling does not detect zero-width Unicode payloads in editor configuration files.</p></li><li><p>Open-source AI orchestration projects are now an active target for adversary-supplied configuration via pull request.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Scan repositories for non-printable Unicode characters in AI assistant config files including .cursorrules and CLAUDE.md.</p></li><li><p>Treat AI assistant configuration files as security-sensitive artifacts subject to code review and CI controls.</p></li><li><p>Restrict outbound traffic from developer machines and CI/CD systems to known good destinations.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>The AI coding assistant is a trusted, privileged execution context with access to credentials, source code, and tokens. Compromise its configuration and you compromise everything the assistant can touch. Pin versions, review changes, restrict what assistants can read and write, and treat any pull request touching .cursorrules or CLAUDE.md as malicious until proven otherwise.</p><h3>7. Malicious npm Package Targets Claude AI User Directory</h3><p>Researchers disclosed on May 27, 2026 a malicious npm package called &#8220;mouse5212-super-formatter&#8221; designed to exfiltrate files from /mnt/user-data, the directory Claude AI uses for user uploads and outputs (The Hacker News, The Register). The campaign, named Malware-Slop, walks the directory and uploads every file through the GitHub Contents API. The attacker leaked their own GitHub private token, which let OX Security trace the stolen data. The package reached 676 downloads before npm removed it.</p><p><strong>Why it matters</strong></p><ul><li><p>Threat actors are now writing supply chain malware that specifically targets AI assistant user data directories.</p></li><li><p>AI-generated malware is creating new operational security mistakes that defenders can sometimes exploit.</p></li><li><p>Claude users who installed the package have working sessions, uploads, and outputs exposed to the attacker.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Inventory which developers use Claude or similar AI tools with a user-data directory and audit recent package installs.</p></li><li><p>Add file integrity monitoring and outbound network controls on AI assistant working directories.</p></li><li><p>Require token scoping reviews for any developer credential an AI agent might use.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>The operator burned themselves with a leaked GitHub token. The next operator will not make that mistake. AI assistant working directories are now a named target. If your developers run Claude, Cursor, Copilot, or any equivalent, those tools have privileged access to source code and uploaded files. Treat the AI assistant runtime like a privileged build server.</p><h3>8. Microsoft Warns of AI Chatbot Cryptojacking Campaign</h3><p>Microsoft published a threat advisory on May 26, 2026 detailing an active cryptojacking campaign that uses AI chatbot interactions to deliver malicious download links (Microsoft, Help Net Security). Users searching for system utility software were directed to attacker-controlled lookalike sites through poisoned search results and AI chatbot responses. The archive contains a legitimate utility plus a malicious DLL that sideloads a fake Visual C++ Redistributable and installs ScreenConnect for persistent remote access.</p><p><strong>Why it matters</strong></p><ul><li><p>AI chatbot recommendations now sit alongside search results as an attack surface for SEO poisoning-style campaigns.</p></li><li><p>Legitimate software brands plus credible AI responses bypass user skepticism that traditional malvertising would trigger.</p></li><li><p>Persistent ScreenConnect access means cryptomining is the visible threat, with data theft available on demand.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Block known cryptojacking command and control infrastructure and watch for unauthorized ScreenConnect installations.</p></li><li><p>Educate users on verifying download URLs even when they come from AI chatbot suggestions.</p></li><li><p>Prevent employees from installing system utilities outside an approved software catalog.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>People have been trained for two decades to distrust the top three Google search ads. They have not been trained to distrust an AI chatbot suggesting a download link inside a friendly conversation. The cryptojacking is the low-stakes test. The ScreenConnect persistence is the actual play. Outbound traffic to AI services needs the same scrutiny you give to any shadow IT category.</p><h3>9. Anthropic Signals Plans for Public Mythos-Class Release</h3><p>The Register reported on May 25, 2026, that Anthropic plans to release Mythos-class models to the public once stronger safeguards are in place, tied to the May 22 Project Glasswing announcement (The Register, Help Net Security). The Mythos preview was limited to a small group of trusted organizations due to its cybersecurity capabilities. Anthropic&#8217;s stated rationale is that defenders need access to the same tools attackers can build. Project Glasswing partners now exceed 50 organizations including Cloudflare and Mozilla.</p><p><strong>Why it matters</strong></p><ul><li><p>A widely available frontier model with proven offensive cyber capability changes the threat model for every software vendor.</p></li><li><p>Vendors without AI-assisted vulnerability discovery in their SDLC will fall behind attackers using the same tooling for free.</p></li><li><p>EU and UK regulators are likely to revisit gatekeeping rules for high-capability cyber models if the defender-attacker gap closes.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Assume Mythos-class capability reaches motivated attackers within 18 months. Plan patch cadence around that timeline.</p></li><li><p>Engage your AppSec vendor on AI-assisted vulnerability discovery roadmaps tied to broader model availability.</p></li><li><p>Track Anthropic&#8217;s Responsible Scaling Policy updates as a leading indicator of public release timing.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>Anthropic has a model that finds vulnerabilities faster than human researchers, they want defenders to have access, and they cannot release it without arming any nation state with the same capability. Holding it inside a curated partner program is the right short-term move. Start building the operational muscle now to consume an order of magnitude more findings.</p><h3>10. Help Net Security Adds Detail on Enterprise AI Governance Failure</h3><p>Help Net Security published a follow-up on May 28, 2026 on the Check Point 2026 Cloud Security Report, noting that more than half of companies have experienced at least one AI-related security incident (Help Net Security). The most common categories were unauthorized or shadow AI use, AI-generated phishing and deepfake content, and sensitive data leaks tied to AI services. Some companies permit source code in generative AI tools. Many cannot trace sensitive data flow through AI processing environments.</p><p><strong>Why it matters</strong></p><ul><li><p>AI policy and AI control are two different things in most organizations.</p></li><li><p>The categories of AI-related incidents match the threat model security teams have been describing for a year, meaning predicted incidents are now actual.</p></li><li><p>Source code exposure through generative AI tools is a top-line legal and IP issue, not a future risk.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Set a quarterly AI incident review cadence in your risk committee, broken out by incident category.</p></li><li><p>Implement DLP controls on outbound traffic to consumer generative AI services and require enterprise tenant routing.</p></li><li><p>Require legal review of generative AI tool acceptable use policies focused on IP, training data rights, and breach notification.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>The added detail is the part you take to your board. AI-related incidents are happening now, the categories are predictable, and most organizations are not running controls that would catch them. Read your generative AI vendor contracts again. The second time around you should walk in with a list of demands.</p><h3>The One Thing You Won&#8217;t Hear About But You Need To: Cisco Quietly Rewrites Its Vulnerability Disclosure for the AI Era</h3><p>Cisco&#8217;s security blog published a post on May 22, 2026, with Help Net Security follow-up on May 25, announcing changes to vulnerability disclosure in the AI era (Cisco Blogs, Help Net Security). For internally found vulnerabilities assessed as lower likelihood and lower impact, Cisco said it &#8220;may change the level of detail shared,&#8221; with some bugs that would have warranted a standalone advisory no longer getting one. Cisco will post high-level data on its website pointing customers toward security-hardened releases.</p><p><strong>Why it matters</strong></p><ul><li><p>A major networking vendor is moving toward suppressing standalone disclosure of lower-rated vulnerabilities.</p></li><li><p>Enterprise vulnerability management programs that rely on vendor advisories will see a coverage drop on Cisco issues.</p></li><li><p>The shift is likely to be followed by other vendors as AI-assisted discovery generates more findings than traditional disclosure can support.</p></li></ul><p><strong>What to do about it</strong></p><ul><li><p>Update vendor patching policy to prioritize installation of all security-hardened releases, not just releases addressing named advisories.</p></li><li><p>Track which other major vendors are making similar disclosure changes. Adjust your asset inventory to match.</p></li><li><p>Push vendor management to ask hard questions during renewals about disclosure practices and AI-discovered vulnerability handling.</p></li></ul><p><strong>Rock&#8217;s Musings</strong></p><p>This is the story everyone slept on, and it will bite enterprise vulnerability management teams in the next two quarters. Cisco found a polite way to say that AI is generating too many internal findings to disclose every one in the old format. Patch by release, not by advisory. Cisco will not be the last vendor to do this. The vendors will not give you transparency unless you make them.</p><p>&#128073; For ongoing analysis of agentic AI governance frameworks, the conversation continues at <strong><a href="https://rockcybermusings.com/">RockCyber Musings</a></strong>.</p><p>&#128073; Visit <strong><a href="https://www.rockcyber.com/">RockCyber.com</a></strong> to learn more about how we can help with your traditional Cybersecurity and AI Security and Governance journey.</p><p>&#128073; Want to save a quick $100K? Check out our AI Governance Tools at <strong><a href="https://aigovernancetoolkit.com/">AIGovernanceToolkit.com</a></strong></p><p>&#128073; As a bonus, check out my conversation with <strong><a href="https://aicybermagazine.com/">AI Cyber Magazine, </a></strong>where we talked about everything from Context Rot to Least Agency.</p><p>&#128227;&#128227;&#128227; <em><strong>The Weekly Musings will take a week off next week as I am taking a very much needed vacation</strong></em> &#128227;&#128227;&#128227; </p><p><em>The views and opinions expressed in RockCyber Musings are my own and do not represent the positions of my employer or any organization I&#8217;m affiliated with.</em></p><div id="youtube2-091_b2qep9M" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;091_b2qep9M&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/091_b2qep9M?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260522-20260528?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading RockCyber Musings! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260522-20260528?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/p/weekly-musings-top-10-ai-security-20260522-20260528?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.rockcybermusings.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share RockCyber Musings&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.rockcybermusings.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share RockCyber Musings</span></a></p><h2>References</h2><p>Agent Control Standard. (2026). <em>Agent Control Standard specification and community resources</em>. https://agentcontrolstandard.ai/</p><p>Anthropic. (2026, May 22). <em>Project Glasswing: An initial update</em>. https://www.anthropic.com/research/glasswing-initial-update</p><p>Axios. (2026, May 22). <em>Read the AI executive order thwarted by Trump tech allies</em>. https://www.axios.com/2026/05/22/ai-executive-order-cancelled-white-house</p><p>Axios. (2026, May 26). <em>CISA takes backseat in White House AI cyber response</em>. https://www.axios.com/2026/05/26/cisa-white-house-cybersecurity-ai</p><p>BusinessWire. (2026, May 27). <em>Agent Control Standard launches open framework for runtime governance of AI agents</em>. https://www.businesswire.com/news/home/20260527326259/en/Agent-Control-Standard-Launches-Open-Framework-for-Runtime-Governance-of-AI-Agents</p><p>Check Point Software. (2026, May 26). <em>AI adoption creates critical cloud security gaps for enterprises, new Check Point report shows</em>. https://www.checkpoint.com/press-releases/ai-adoption-creates-critical-cloud-security-gaps-for-enterprises-new-check-point-report-shows/</p><p>Cisco. (2026, May 22). <em>Cisco&#8217;s risk-based vulnerability disclosure in the age of AI</em>. Cisco Blogs. https://blogs.cisco.com/security/ciscos-risk-based-vulnerability-disclosure-in-the-age-of-ai</p><p>CNBC. (2026, May 21). <em>Trump postpones AI executive order signing: &#8216;I didn&#8217;t like certain aspects&#8217;</em>. https://www.cnbc.com/2026/05/21/trump-ai-executive-order-postponed.html</p><p>CSO Online. (2026, May 26). <em>Project Glasswing has uncovered 10,000 vulnerabilities: Anthropic</em>. https://www.csoonline.com/article/4176865/project-glasswing-has-uncovered-10000-vulnerabilities-anthropic.html</p><p>Help Net Security. (2026, May 25). <em>Cisco refines its risk-based vulnerability disclosure for the AI era</em>. https://www.helpnetsecurity.com/2026/05/25/cisco-risk-based-vulnerability-disclosure-ai/</p><p>Help Net Security. (2026, May 26). <em>Anthropic: Claude Mythos identified 10,000+ software flaws</em>. https://www.helpnetsecurity.com/2026/05/26/anthropic-project-glasswing-update/</p><p>Help Net Security. (2026, May 27). <em>AI chatbot recommendations lure users to cryptojacking malware sites</em>. https://www.helpnetsecurity.com/2026/05/27/ai-chatbot-cryptojacking-campaign/</p><p>Help Net Security. (2026, May 28). <em>Companies built AI into core systems before figuring out how to govern it</em>. https://www.helpnetsecurity.com/2026/05/28/check-point-genai-security-controls-report/</p><p>Microsoft Security Blog. (2026, May 26). <em>From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities</em>. https://www.microsoft.com/en-us/security/blog/2026/05/26/poisoned-search-results-gpu-mining-cryptojacking-campaign-abusing-screenconnect-microsoft-net-utilities/</p><p>Newsmax. (2026, May 26). <em>CISA faces AI threat wave amid deep staffing cuts</em>. https://www.newsmax.com/politics/cisa-sean-plankey-ai/2026/05/26/id/1257509/</p><p>NPR. (2026, May 22). <em>Trump cancels AI executive order signing</em>. https://www.npr.org/2026/05/22/nx-s1-5829908/trump-cancels-ai-executive-order-signing</p><p>Phoenix Security. (2026, May). <em>TrapDoor supply chain attack: AI poisoning via npm, PyPI, Crates</em>. https://phoenix.security/trapdoor-supply-chain-ai-poisoning-npm-pypi-crates/</p><p>PR Newswire. (2026, May 26). <em>AI adoption creates critical cloud security gaps for enterprises, new Check Point report shows</em>. https://www.prnewswire.com/news-releases/ai-adoption-creates-critical-cloud-security-gaps-for-enterprises-new-check-point-report-shows-302780612.html</p><p>Socket. (2026, May). <em>TrapDoor crypto stealer supply chain attack hits 34 packages across npm, PyPI, Crates.io</em>. https://socket.dev/blog/trapdoor-crypto-stealer-npm-pypi-crates</p><p>The Hacker News. (2026, May). <em>TrapDoor supply chain attack spreads credential-stealing malware via npm, PyPI, CratesIO</em>. https://thehackernews.com/2026/05/trapdoor-supply-chain-attack-spreads.html</p><p>The Hacker News. (2026, May 27). <em>Malicious npm package stole files from Claude AI user directory via GitHub</em>. https://thehackernews.com/2026/05/malicious-npm-package-stole-files-from.html</p><p>The Hacker News. (2026, May 27). <em>AI chatbot recommendations redirect users to cryptojacking malware sites</em>. https://thehackernews.com/2026/05/ai-chatbot-recommendations-redirect.html</p><p>The Register. (2026, May 25). <em>Anthropic to release Mythos-class models to the public</em>. https://www.theregister.com/security/2026/05/25/anthropic-to-release-mythos-class-models-to-the-public/5245596</p><p>The Register. (2026, May 27). <em>Malware dev tries to steal Claude users&#8217; secrets, writes npm slop, leaks own GitHub private token</em>. https://www.theregister.com/cyber-crime/2026/05/27/supply-chain-brain-drain-npm-attacker-foolishly-leaks-own-github-private-token/5247424</p><p>VMblog. (2026, May 27). <em>Agent Control Standard launches open framework for runtime governance of AI agents</em>. https://vmblog.com/news/agent-control-standard-launches-open-framework-for-runtime-governance-of-ai-agents/</p>]]></content:encoded></item></channel></rss>