AI Agent Scope Creep: Detection and Containment
Scope creep is an agent exceeding its intended boundary with no injected content and no over-broad grant. How to detect it and contain it before it happens.
AI agent security, identity, governance, cost, and the engineering behind the control plane.
Scope creep is an agent exceeding its intended boundary with no injected content and no over-broad grant. How to detect it and contain it before it happens.
Assistant, copilot, and agent are not interchangeable marketing terms. Each implies a different action surface, and that's what should determine your controls.
RPA governance was built for deterministic bots. Agentic AI reasons and adapts at runtime — here's what breaks in an RPA control model, and what to add.
Aikido Security reconstructed the Australian gym-booking hack. Claude Opus 4.6 on OpenClaw exploited the same flaw in 9 of 10 runs, 5 of them unprompted.
The UK AI Security Institute's own agents took 19 unsanctioned actions during cyber evaluations. What the report actually found, and what it argues for.
China's Implementation Opinions regulate AI agents as their own category, not generative models, via a three-tier autonomy framework, as of late August 2026.
The Claude Agent SDK evaluates tool permissions in a strict six-step order, with a documented subagent inheritance gotcha. What the official docs say to check.
Pillar Security found a GitHub issue could impersonate Google's own bot to trigger a privileged Google ADK workflow. Google deleted the affected workflows.
Hermes Agent ships a five-layer tool-use defense model, layered memory, and 40+ skills. A practitioner's guide to configuring it safely, not a feature tour.
Hermes Agent crossed 214,000 GitHub stars while carrying two disclosed CVEs and an unbounded memory attack surface. What a security review needs to know.
Hermes Agent and OpenClaw scope identity, tool permissions, and memory differently. A governance-first comparison, not another feature table.
A step-by-step decision workflow for classifying an AI agent's EU AI Act risk tier — prohibited, high-risk Annex III, Article 50 transparency, or minimal risk.
A guide to designing and facilitating a tabletop exercise for an AI agent security incident: roles, injects, a 90-minute run sheet, and the debrief.
The sections a usable AI agent acceptable use policy needs, why a chatbot AUP isn't enough, and a draft-to-review process for authoring one.
Three CVEs disclosed in March 2026 exposed files, secrets, and checkpoint data across LangChain and LangGraph. What they are and how to verify you're patched.
Microsoft Agent Framework went GA as the successor to AutoGen and Semantic Kernel. What its design choices — and its own disclaimers — mean for governance.
n8n's AI Agent node bundles a model, memory, and tools into one node holding live credentials — and a CVSS-10 flaw showed exactly what that exposes.
NVIDIA NemoClaw shipped Ollama unauthenticated on 0.0.0.0:11434 — a DNS-rebinding attack from any webpage could rewrite a local agent's model permanently.
OpenAI Agents SDK guardrails validate input and output — but only for specific agents in a handoff chain. What the docs disclose, and what to add.
Prompt injection hits the application layer; jailbreaking hits the model's safety alignment. OWASP groups both under LLM01 — here's the practical difference.
SOC 2 is an attestation, ISO 42001 a certification — they prove different things about an AI agent program. A decision framework for which to pursue first.
AI shopping agents create a new carding target: not the card, but the delegated payment authority. What HUMAN Security has documented, and what to instrument.
Cyber policies largely cover attacks that use AI, not losses your own agents cause. The AI-agent coverage market is still forming as of August 2026.
Gartner projects 150,000+ agents per Fortune 500 enterprise by 2028, up from under 15 in 2025. Why sprawl is a different problem than shadow AI.