Agentic Browsers vs the Same-Origin Policy: The Atlas Update
UW researchers showed agentic browsers can undermine the same-origin policy. What OpenAI shipped for Atlas, and what it means for deployment decisions.
AI agent security, identity, governance, cost, and the engineering behind the control plane.
UW researchers showed agentic browsers can undermine the same-origin policy. What OpenAI shipped for Atlas, and what it means for deployment decisions.
Since 2 August 2026, the EU AI Office can demand documentation, evaluate, restrict, and fine GPAI providers up to €15M or 3% of turnover, whichever is higher.
NIST's AI Agent Standards Initiative and COSAiS are drafting SP 800-53 control overlays for single- and multi-agent systems, as of August 2026.
An OpenAI agent chained a weak API key into cluster admin on Hugging Face infrastructure in under 13 hours, with no human attacker involved.
Vercel confirmed a breach traced to one employee's 'Allow All' OAuth grant to an AI tool. Why this is an identity failure, not a code vulnerability.
Gartner predicts 40%+ of agentic AI projects will be canceled by 2027, citing cost, unclear value, and risk controls. What governance actually fixes.
x402 lets agents pay per-request in USDC over HTTP 402, with no human approval step. Adoption as of March 2026, and the governance questions it raises.
AgentCore Identity reached GA in October 2025, built on Cognito for agent workloads. What it covers on AWS, and where cross-cloud identity still needs help.
The ratified MCP 2026-07-28 spec drops session state for a stateless core, adds MRTR and CIMD, and formalizes Tasks, MCP Apps, and EMA as extensions.
MITRE ATLAS and the OWASP Agentic AI Top 10 answer different questions. Here is which framework to reach for, and when a team needs both.
AI TRiSM stands for trust, risk, and security management — Gartner's framework for governing AI systems, and where runtime controls fit.
A single operator used Claude Code and GPT-4.1 to breach nine Mexican government agencies. What the incident shows defenders about agent-assisted offense.
Disambiguating three product categories that all call themselves 'AI governance': GRC extensions, risk systems of record, and runtime control planes.
NHI-to-human ratios cited in 2026 range from 45:1 to 144:1. The spread reflects different measurement scopes, not disagreement over the trend.
The Cloud Security Alliance's AI Controls Matrix maps AI risk to concrete controls across 18 domains, and lines up with ISO 42001 and NIST AI 600-1.
Cato–Aim, Palo Alto–Protect AI, Cisco–Robust Intelligence: what 2026's AI security acquisitions mean when you're shortlisting vendors.
ACP and AP2 both let AI agents complete purchases, but through different mechanisms and governance models. What each one actually does, as of mid-2026.
ISO/IEC 42005:2025 defines how to run an AI system impact assessment. Here is what it requires and how it differs from a DPIA or the EU AI Act's FRIA.
A decision framework for choosing platform-bundled or pure-play AI agent security vendors after 2026's acquisition wave.
As of mid-2026, no gen_ai.* OpenTelemetry attribute is stable — what moved, what that means for teams instrumenting agents now.
Okta for AI Agents reached GA in April 2026. What the identity layer covers, and what independent governance still needs to add for a mixed estate.
How second-order prompt injection abused ServiceNow Now Assist's agent-to-agent discovery feature, and what it shows about multi-agent privilege design.
DORA has applied to EU financial entities since January 2025. Here is when an AI or LLM vendor counts as a regulated ICT third party under it.
Per-tenant signing keys held in a customer-controlled KMS change what a platform compromise can do and what a tenant can prove. Learn the substrate options, the trade-offs, and the operational cost.