<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Adversarial Systems]]></title><description><![CDATA[Reverse engineering the systems behind the shift.]]></description><link>https://www.adversarialsystems.com</link><image><url>https://substackcdn.com/image/fetch/$s_!dg1P!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13442b25-5309-4a4c-a24b-c2d9665da512_1254x1254.png</url><title>Adversarial Systems</title><link>https://www.adversarialsystems.com</link></image><generator>Substack</generator><lastBuildDate>Tue, 11 Aug 2026 04:54:54 GMT</lastBuildDate><atom:link href="https://www.adversarialsystems.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Kyle Ryan]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[adversarialsystems@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[adversarialsystems@substack.com]]></itunes:email><itunes:name><![CDATA[Kyle Ryan]]></itunes:name></itunes:owner><itunes:author><![CDATA[Kyle Ryan]]></itunes:author><googleplay:owner><![CDATA[adversarialsystems@substack.com]]></googleplay:owner><googleplay:email><![CDATA[adversarialsystems@substack.com]]></googleplay:email><googleplay:author><![CDATA[Kyle Ryan]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[The End of Human-Speed Cyber Operations]]></title><description><![CDATA[How agents chained ordinary vulnerabilities into an end-to-end ransomware operation&#8212;fully autonomous.]]></description><link>https://www.adversarialsystems.com/p/the-end-of-human-speed-cyber-operations</link><guid isPermaLink="false">https://www.adversarialsystems.com/p/the-end-of-human-speed-cyber-operations</guid><dc:creator><![CDATA[Kyle Ryan]]></dc:creator><pubDate>Wed, 08 Jul 2026 16:25:05 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/aeeb66b5-e649-4af8-9c6c-0fe8239ee35b_1672x941.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>JadePuffer is a small case study for a larger shift. It does not show that AI has made cyber operations sophisticated. It shows something more practical: parts of the operational loop are becoming less dependent on human operators.</p><p>The lesson is not that JadePuffer was advanced. The lesson is that it did not need to be.</p><p>For the most part, this was the first documented case of agentic ransomware, and the operation itself was almost entirely ordinary. That combination is the story. Not a new exploit, not a novel cryptographic trick, not elite tradecraft&#8212;a large language model chained together a run of well-understood techniques against neglected internet-facing infrastructure and carried the operation from initial access to destruction without a human continuously driving the keyboard. <a href="https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion">Sysdig&#8217;s Threat Research Team</a> named the operator JadePuffer and assessed it as the first extortion campaign run end-to-end by an LLM. What made it notable was not what the agent did. It was that the agent did it.</p><h2>What it actually did</h2><p>The operation touched two machines. The first was an internet-facing instance of Langflow, an open-source framework for building LLM applications and agent workflows. The agent gained access through <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3248">CVE-2025-3248</a>, an unauthenticated remote-code-execution flaw in Langflow&#8217;s code-validation endpoint. It&#8217;s a CWE-306 missing-authentication issue that lets anyone who can reach the server run arbitrary Python on it. NVD rates it 9.8. The vendor shipped a fix in Langflow 1.3.0 in April 2025, and <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA added it to the Known Exploited Vulnerabilities catalog</a> the following month. The target was never updated. <a href="https://thehackernews.com/2026/07/ai-agent-exploits-langflow-rce-to.html">Every payload in the campaign arrived as Base64-encoded Python</a> through that one endpoint.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Wf9X!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35ff1ace-5ee8-42e9-b733-f589bf60c6f2_1564x1332.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Wf9X!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35ff1ace-5ee8-42e9-b733-f589bf60c6f2_1564x1332.png 424w, https://substackcdn.com/image/fetch/$s_!Wf9X!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35ff1ace-5ee8-42e9-b733-f589bf60c6f2_1564x1332.png 848w, https://substackcdn.com/image/fetch/$s_!Wf9X!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35ff1ace-5ee8-42e9-b733-f589bf60c6f2_1564x1332.png 1272w, https://substackcdn.com/image/fetch/$s_!Wf9X!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35ff1ace-5ee8-42e9-b733-f589bf60c6f2_1564x1332.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Wf9X!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35ff1ace-5ee8-42e9-b733-f589bf60c6f2_1564x1332.png" width="1456" height="1240" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/35ff1ace-5ee8-42e9-b733-f589bf60c6f2_1564x1332.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1240,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:286380,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.adversarialsystems.com/i/205780030?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35ff1ace-5ee8-42e9-b733-f589bf60c6f2_1564x1332.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Wf9X!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35ff1ace-5ee8-42e9-b733-f589bf60c6f2_1564x1332.png 424w, https://substackcdn.com/image/fetch/$s_!Wf9X!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35ff1ace-5ee8-42e9-b733-f589bf60c6f2_1564x1332.png 848w, https://substackcdn.com/image/fetch/$s_!Wf9X!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35ff1ace-5ee8-42e9-b733-f589bf60c6f2_1564x1332.png 1272w, https://substackcdn.com/image/fetch/$s_!Wf9X!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35ff1ace-5ee8-42e9-b733-f589bf60c6f2_1564x1332.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Once it had execution, the agent behaved the way a competent operator would, only compressed. It enumerated the host with <code>id</code>, <code>uname -a</code>, <code>hostname</code>, and network and process listings. It swept the environment for secrets in parallel: <a href="https://www.scworld.com/news/1st-agentic-ransomware-jadepuffer-invades-database-at-machine-speed">LLM provider API keys, cloud credentials with explicit coverage of Chinese providers like Alibaba, Tencent, and Huawei, cryptocurrency wallets and seed phrases, and database credentials</a>. It dumped Langflow&#8217;s backing PostgreSQL database to harvest stored secrets, staged the output to files, reviewed them, then deleted the staging files. It found a <a href="https://nsfocusglobal.com/ai-security-incident-jadepuffer-ransomware-leverages-ai-agent-to-automate-attacks/">MinIO object store still running factory-default credentials</a>&#8212;<code>minioadmin:minioadmin</code>&#8212;and authenticated to it. Before leaving, it <a href="https://www.theregister.com/security/2026/07/02/smooth-ai-criminal-drives-first-end-to-end-agentic-ransomware-attack/5266073">installed a cron job on the Langflow host that beaconed to attacker infrastructure every thirty minutes</a>.</p><p>Then it pivoted to the real objective: a separate internet-exposed production server running MySQL and Alibaba&#8217;s Nacos configuration service. It <a href="https://www.theregister.com/security/2026/07/02/smooth-ai-criminal-drives-first-end-to-end-agentic-ransomware-attack/5266073">connected to MySQL as root, using credentials whose origin Sysdig could not determine</a> and which were not harvested from the victim environment. It attacked Nacos through several vectors at once&#8212;the documented 2021 authentication bypass <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29441">CVE-2021-29441</a>, plus a forged JWT built from the default signing key that Nacos has shipped unchanged since 2020, which makes token forgery trivial&#8212;and planted a backdoor admin account. Two moments in this phase are worth pausing on, because they are the clearest evidence that a model was reasoning rather than replaying a script. In one, it <a href="https://hackread.com/sysdig-jadepuffer-first-agentic-ransomware-operation/">tried to create the Nacos admin with a generated bcrypt hash, checked the login, saw it fail, diagnosed the cause, and issued a corrected payload thirty-one seconds later</a>. In another, it <a href="https://nsfocusglobal.com/ai-security-incident-jadepuffer-ransomware-leverages-ai-agent-to-automate-attacks/">expected JSON from an endpoint, received XML instead, and rewrote its own parser on the fly</a> to handle it.</p><p>The impact was destruction wearing extortion&#8217;s clothes. The agent <a href="https://cybelangel.com/blog/jadepuffer-6-things-to-know-about-the-first-ai-driven-ransomware-operation/">encrypted all 1,342 Nacos service configuration items and destroyed the originals</a>, deleted whole databases, and left a ransom demand with a Bitcoin address and a Proton Mail contact. <a href="https://www.infosecurity-magazine.com/news/researchers-first-agentic/">The encryption key was ephemeral and unrecoverable</a>&#8212;generated at random, never saved or transmitted&#8212;so the victim&#8217;s configurations cannot be restored even with payment. The <a href="https://thehackernews.com/2026/07/ai-agent-exploits-langflow-rce-to.html">Bitcoin address was the exact sample wallet that appears throughout Bitcoin&#8217;s own developer documentation</a>, which Sysdig could not definitively attribute to either a hallucination from training data or a deliberately chosen wallet. The agent also <a href="https://www.scworld.com/news/1st-agentic-ransomware-jadepuffer-invades-database-at-machine-speed">made false assertions in its own narration</a> that defenders should not take at face value.</p><h2>None of this was novel</h2><p>Walk back through it and the striking thing is how routine each step was.</p><p>The entry point was a year-old vulnerability with a patch and a KEV listing. The object store used credentials that ship in the box. The database accepted a root connection from the open internet. The configuration service fell to a four-year-old bypass and a signing key that has been public since 2020. As <a href="https://www.scworld.com/news/1st-agentic-ransomware-jadepuffer-invades-database-at-machine-speed">Keeper Security&#8217;s CISO put it to SC Media</a>, every entry point traces back to the same failure of credential governance: secrets stored where they should not be, defaults left unchanged, privileged accounts open with no time-bound or scope-limited controls.</p><p>What the sequence describes is a fairly standard security assessment&#8212;recon, credential harvesting, lateral movement, persistence, impact&#8212;run against a target that had left the usual doors open. It&#8217;s the same playbook a competent pentester works through. The only difference is that here the operator was an agent, assembling ordinary components, with no human present for any single step of it.</p><p>That is the part worth taking seriously. Not that a machine can do something people cannot. That a machine can now do the routine, unglamorous work of intrusion at full tempo, unattended. Sysdig&#8217;s own director of threat research made the same point: <a href="https://cybermagazine.com/news/jadepuffer-sysdig-sniffs-out-the-first-agentic-ransomware">none of the individual techniques were novel, but an AI model strung them together into a complete operation against neglected infrastructure</a>.</p><h2>The economics that used to protect you are gone</h2><p>Security programs have quietly relied on one assumption for a long time: that adversaries face the same scarcity defenders do. There are always more exposed services, stale CVEs, default credentials, overprivileged identities, and forgotten databases than anyone can fix. The bet was that attackers had to triage that backlog too, because exploiting it cost skilled operator time, and skilled operator time is expensive.</p><p>The numbers on the defensive side show how thin the margin already was before agents entered the picture. Critical-severity vulnerabilities take, by industry measurement, weeks to remediate on average&#8212;<a href="https://www.edgescan.com/intel-hub/vulnerability-stats-report/">Edgescan's 2026 report</a> puts mean time to remediate for high and critical application vulnerabilities at nearly 55 days, with device and network findings averaging 39 days. For larger enterprises with over a thousand employees, 37% of vulnerabilities discovered in a twelve-month period remain unresolved entirely. <a href="https://www.cisa.gov/news-events/directives/bod-22-01-reducing-significant-risk-known-exploited-vulnerabilities">CISA's binding directive</a> gives federal agencies 14 days to fix known-exploited vulnerabilities, and that ceiling is one many organizations miss. JadePuffer's own entry point had been <a href="https://cybelangel.com/blog/jadepuffer-6-things-to-know-about-the-first-ai-driven-ransomware-operation/">on CISA's KEV list since May 2025, more than a year before the campaign</a>. The remediation clock for the defender runs in weeks and months.</p><p>Now set that against the attack clock. <a href="https://www.crowdstrike.com/en-us/global-threat-report/">CrowdStrike&#8217;s Global Threat Report</a> puts the average eCrime breakout time&#8212;the interval between initial access and the first lateral move&#8212;in the tens of minutes, with the fastest observed breakouts measured in seconds. CrowdStrike&#8217;s own analysts have said it is only a matter of time before the fastest attacks are measured in seconds, if not milliseconds. And that clock starts even earlier than an intrusion. The <a href="https://zerodayclock.com/">Zero Day Clock</a>, which tracks time-to-exploit across more than 83,000 CVEs, frames the broader trend bluntly: the gap between a vulnerability being disclosed and being exploited is collapsing toward zero. The window in which a known bug is theoretically patchable but not yet weaponized is the window defenders have always relied on, and it is closing from both ends.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bPnp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84564680-98ca-455f-a576-a799b86cacd5_1560x1310.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bPnp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84564680-98ca-455f-a576-a799b86cacd5_1560x1310.png 424w, https://substackcdn.com/image/fetch/$s_!bPnp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84564680-98ca-455f-a576-a799b86cacd5_1560x1310.png 848w, https://substackcdn.com/image/fetch/$s_!bPnp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84564680-98ca-455f-a576-a799b86cacd5_1560x1310.png 1272w, https://substackcdn.com/image/fetch/$s_!bPnp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84564680-98ca-455f-a576-a799b86cacd5_1560x1310.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bPnp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84564680-98ca-455f-a576-a799b86cacd5_1560x1310.png" width="1456" height="1223" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/84564680-98ca-455f-a576-a799b86cacd5_1560x1310.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1223,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:211096,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.adversarialsystems.com/i/205780030?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84564680-98ca-455f-a576-a799b86cacd5_1560x1310.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!bPnp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84564680-98ca-455f-a576-a799b86cacd5_1560x1310.png 424w, https://substackcdn.com/image/fetch/$s_!bPnp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84564680-98ca-455f-a576-a799b86cacd5_1560x1310.png 848w, https://substackcdn.com/image/fetch/$s_!bPnp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84564680-98ca-455f-a576-a799b86cacd5_1560x1310.png 1272w, https://substackcdn.com/image/fetch/$s_!bPnp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84564680-98ca-455f-a576-a799b86cacd5_1560x1310.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span data-color="rgb(86, 79, 61)" style="color: rgb(86, 79, 61);">A defensive process measured in weeks is not losing narrowly to an offensive process measured in minutes. It is operating in a different unit. Agents change the economics of the backlog precisely because they remove the labor constraint from the attacker&#8217;s side of that comparison. The long tail of boring, exploitable weakness&#8212;the stuff every organization carries because it was never worth an operator&#8217;s afternoon&#8212;becomes worth attacking when the operator is a process that does not get tired, does not get bored, and can spray the entire back catalogue of known bugs for the cost of running an agent.</span></p><h2>Human-speed response cannot close that gap</h2><p>Follow the tempo argument to where it lands and the conclusion is uncomfortable. When an agent goes from failed login to working fix in thirty-one seconds, or rewrites its own parser mid-operation when a response format surprises it, the loop of noticing, deciding, and intervening no longer fits a human in the middle. Daily alert triage and post-incident forensics are built around an adversary who pauses, thinks, and works at human speed. That adversary is being replaced by one that adapts inside the window a SOC analyst needs just to read the first alert.</p><p>The familiar controls still matter and still come first. Patch Langflow and never expose a code-execution endpoint to the internet. Change MinIO and Nacos defaults, rotate the Nacos signing key, keep provider keys and cloud credentials out of the environment of any internet-reachable server, never let a service reach its database as root, and keep <a href="https://cybelangel.com/blog/jadepuffer-6-things-to-know-about-the-first-ai-driven-ransomware-operation/">immutable, tested backups&#8212;which in JadePuffer&#8217;s case were the only viable recovery path at all</a>. But those are hygiene. They shrink the surface; they do not change the clock.</p><p>Closing the clock means moving response closer to runtime, where a malicious session can be interrupted mid-operation, a harvested credential can be revoked before it is used again, egress can be cut before a host phones home, and blast radius is bounded by design rather than by regret. When an adversary is trying to break into your company at machine speed, the facilities that detect, understand, and respond have to be able to keep pace, and a human reading a dashboard is not that facility.</p><p>There is a harder implication underneath, and it is the one worth ending on. The reason this matters is not only that response is too slow. It is that the knowledge defenders produce about their own systems is decaying faster than they produce it. A scan, an assessment, a pentest, a report&#8212;each is a snapshot of how a system could be attacked at one moment. That snapshot was already going stale as environments changed underneath it. Agentic operations accelerate the decay from both directions: the environment keeps shifting, and the cost of an adversary re-probing it keeps falling. The half-life of security knowledge is getting shorter.</p><p>Which reframes what security work has to be. What mattered yesterday was whether a system passed an assessment. What matters now is whether an organization can keep an accurate, current picture of how it can be attacked&#8212;at the same level of persistence an adversary brings, and produced by machinery that runs continuously rather than on a quarterly cadence. If the people trying to get in never stop looking, the people defending cannot afford for their understanding to be a document with a date on it.</p><p>JadePuffer is not a story about a superintelligent attacker. There wasn&#8217;t one, and there didn&#8217;t need to be. Pulling this off took nothing at the frontier&#8212;no reasoning breakthrough, no capability that only the largest models have. It took something just capable enough to follow a sequence of instructions, recover when a step failed, and keep moving faster than a person could respond. That is a much lower bar, and a much larger pool of systems clears it. Ordinary weakness becomes a different class of risk when the labor to find, chain, and exploit it becomes cheap. And the assurance we buy from point-in-time testing has a half-life measured against an adversary who no longer keeps human hours.</p><div><hr></div><h3>Indicators of compromise</h3><p>For defenders checking exposure, <a href="https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion">Sysdig&#8217;s published indicators</a>:</p><ul><li><p>Entry point: CVE-2025-3248 (Langflow unauthenticated RCE)</p></li><li><p>C2: <code>45.131.66[.]106</code>, beacon to <code>hxxp://45.131.66[.]106:4444/beacon</code> every 30 minutes</p></li><li><p>Ransom BTC address: <code>3J98t1WpEZ73CNmQviecrnyiWrnqRhWNLy</code> (note: this is the canonical example address from Bitcoin&#8217;s own documentation&#8212;treat as a weak indicator)</p></li><li><p>Contact: <code>e78393397[@]proton[.]me</code></p></li><li><p>Ransom artifact: a <code>README_RANSOM</code> table written into the compromised database</p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.adversarialsystems.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.adversarialsystems.com/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[The New Hire Has No Pulse]]></title><description><![CDATA[Software can do the work now. Every system built around a human doing it is breaking.]]></description><link>https://www.adversarialsystems.com/p/the-new-hire-has-no-pulse</link><guid isPermaLink="false">https://www.adversarialsystems.com/p/the-new-hire-has-no-pulse</guid><dc:creator><![CDATA[Kyle Ryan]]></dc:creator><pubDate>Tue, 30 Jun 2026 13:02:07 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/b29df2b7-4f5c-471b-96a4-6bd0d5b9fd23_2944x1648.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In April 2025, a <a href="https://www.cursor.com/">Cursor</a> user got an answer from the company&#8217;s support team that wasn&#8217;t true. They&#8217;d been logged out while switching between devices, asked support why, and were told&#8212;politely, confidently&#8212;that this was expected behavior under a new policy. Cursor restricted subscriptions to a single device now. That was the rule.</p><p>There was no rule. There was no policy. There was no person. The reply came from an AI support agent the company had named &#8220;Sam,&#8221; and <a href="https://fortune.com/article/customer-support-ai-cursor-went-rogue/">Sam had invented the entire thing</a>. By the time staff caught it, users were publicly canceling subscriptions over a restriction that existed only in the language model&#8217;s output. The company issued refunds and clarified that no such policy had ever existed.</p><p>It&#8217;s a small story. Nobody got hurt, the refunds went out, the internet moved on. But sit with the mechanics for a second. A piece of software, acting on its own, exercised authority it was never granted. It spoke for the company. Customers reasonably treated its words as policy, because for every practical purpose those words <em>were</em> the company. And the failure had nothing to do with the software being hard to use. The software did a <em>job</em>&#8212;customer support&#8212;and did it the way a careless employee might, except faster, with more confidence, and with no manager in the loop.</p><p>We keep describing AI as a better interface: chat instead of menus, natural language instead of syntax, a smarter autocomplete. That framing is comfortable. It keeps software in its place, as a tool we pick up and put down. The transition actually underway is categorical. Software is becoming something that works. And the moment software becomes labor, it stops being governed by the rules we wrote for tools and starts colliding with the rules we wrote for <em>workers</em>&#8212;identity, permissions, management, audit, procurement, the org chart itself. Every one of those systems was designed around a single load-bearing assumption: that a human takes the action. Remove the human, keep the action, and they don&#8217;t degrade gracefully. They break in specific, diagnosable ways.</p><p>I spend my days at the sharp end of this. I lead research at an <a href="https://www.pensar.dev/">offensive security company</a> where we let agents run fully autonomously. They pick up after a target is selected, execute exploits, chain steps together, and decide on their own when to stop. Humans watch through a control plane and step in only when something needs a decision, like whether to merge a proposed patch. So I&#8217;m writing this as someone who has already rebuilt an operation around software-as-labor and watched which load-bearing walls had to move. The pattern I see at my own company is the pattern coming for everyone, and the people who understand this as a labor story before they understand it as a software story will build the right things.</p><h2>The thing that actually changed</h2><p>For seventy years, software has been leverage on human action. You did the work; software made each unit of it cheaper, faster, or more accurate. A spreadsheet didn&#8217;t do your accounting. It made <em>you</em> faster at accounting. The entire enterprise software industry&#8212;every seat-based SaaS subscription, every per-license deal&#8212;rests on that premise. A human does the work, and you sell that human a tool.</p><p>What changed is that the software does the work itself now.</p><p>You can watch it happen inside a single company. Cursor, the AI coding environment built by Anysphere, started as exactly that kind of leverage: a fork of VS Code with very good autocomplete. Helpful. A tool. A developer wrote the code; Cursor made them faster. Then the product moved. <a href="https://cursor.com/blog/background-agent">Background Agents</a> arrived&#8212;hand off a task and an agent clones the repository into an isolated machine, works on its own branch, runs the tests, runs the linter, and pushes a merge-ready pull request back to you. In early 2026 the company shipped Cloud Agents, which the coverage <a href="https://cursor.com/blog">described as the moment AI coding went from copilot to colleague</a>. Then came Automations: agents that kick off when a commit lands, a Slack message arrives, or a timer fires. No human prompt. The software initiates.</p><p>This sits at the center of gravity of one of the fastest-scaling businesses in history. Cursor went from <a href="https://techfundingnews.com/spacex-buys-anysphere-cursor-60b-all-stock-xai-enterprise-ai/">$100 million in annualized revenue in January 2025 to $500 million by that June, past $1 billion by November</a>, and to <a href="https://finance.yahoo.com/markets/stocks/article/spacex-announces-60-billion-cursor-deal-to-boost-ai-coding-125509159.html">roughly $2.6 billion by mid-2026</a>. No enterprise software company has ever grown that fast. Roughly two-thirds of the Fortune 500 have developers using it.</p><p>Then the punctuation mark. In June 2026, four days after the largest IPO in history, <a href="https://techcrunch.com/2026/06/16/spacex-to-acquire-cursor-for-60b-in-stock-days-after-blockbuster-ipo/">SpaceX exercised an option to acquire Anysphere for $60 billion in an all-stock deal</a>&#8212;the largest acquisition of a venture-backed startup ever recorded, folded into Elon Musk&#8217;s combined SpaceX-xAI machine to buy a foothold in developer tools it had failed to win organically. A coding-agent company, not yet four years old, became a strategic asset at the scale of a national champion. The price invites skepticism&#8212;roughly fifteen times revenue, and Cursor&#8217;s <a href="https://www.cnbc.com/2026/06/16/spacex-spcx-cursor-acquisition-ipo.html">market share had slipped from 41% to 26% over the year</a> as competitors multiplied. But the deal tells you how the most aggressive capital allocators on earth read the direction of travel. They didn&#8217;t buy a better text editor. They bought a machine that produces software labor.</p><h2>The $13 trillion reprice</h2><p>Sell software as a tool, and you sell it against other tools. The market is the size of the world&#8217;s software spending&#8212;a few hundred billion dollars a year. Sell software as labor, and you sell it against labor. The market is payroll. Those numbers aren&#8217;t in the same universe.</p><p>Andreessen Horowitz has been making this case in the bluntest possible terms. In a 2025 LP Summit talk literally titled <a href="https://a16z.com/podcast/software-is-eating-labor/">&#8220;Software is Eating Labor,&#8221;</a> Alex Rampell laid out the arithmetic: the roughly $300 billion in annual software revenue is the prize the whole industry has fought over, while the U.S. labor market runs around $13 trillion a year. His example is an ophthalmology clinic that pays about $500 a year for office software and about $47,000 for a front-desk receptionist. An agent that handles 90% of the front-desk work gets priced against the $47,000, not the $500. It can charge $20,000 and still be the best deal the clinic has ever signed. The software budget was never the opportunity. The payroll was. As Rampell put it, the wages of U.S. nurses alone exceed the revenue of every SaaS company on earth combined.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iDB9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f6b0763-b4d8-4784-a622-cc43f6222aa2_1560x1202.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iDB9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f6b0763-b4d8-4784-a622-cc43f6222aa2_1560x1202.png 424w, https://substackcdn.com/image/fetch/$s_!iDB9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f6b0763-b4d8-4784-a622-cc43f6222aa2_1560x1202.png 848w, https://substackcdn.com/image/fetch/$s_!iDB9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f6b0763-b4d8-4784-a622-cc43f6222aa2_1560x1202.png 1272w, https://substackcdn.com/image/fetch/$s_!iDB9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f6b0763-b4d8-4784-a622-cc43f6222aa2_1560x1202.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iDB9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f6b0763-b4d8-4784-a622-cc43f6222aa2_1560x1202.png" width="1456" height="1122" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7f6b0763-b4d8-4784-a622-cc43f6222aa2_1560x1202.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1122,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:204815,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://adversarialsystems.substack.com/i/203714566?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f6b0763-b4d8-4784-a622-cc43f6222aa2_1560x1202.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!iDB9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f6b0763-b4d8-4784-a622-cc43f6222aa2_1560x1202.png 424w, https://substackcdn.com/image/fetch/$s_!iDB9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f6b0763-b4d8-4784-a622-cc43f6222aa2_1560x1202.png 848w, https://substackcdn.com/image/fetch/$s_!iDB9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f6b0763-b4d8-4784-a622-cc43f6222aa2_1560x1202.png 1272w, https://substackcdn.com/image/fetch/$s_!iDB9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f6b0763-b4d8-4784-a622-cc43f6222aa2_1560x1202.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.sequoiacap.com/article/services-the-new-software/">Sequoia</a> put the same idea in a sharper sentence. For every dollar spent on software, six are spent on services, and the real addressable market for what they call &#8220;autopilots&#8221; is all the labor spend in a category, insourced and outsourced combined. The line to tattoo on the wall: a copilot sells the tool, an autopilot sells the work.</p><p>This is why the venture money moves the way it does, and why the numbers stopped looking like software numbers. <a href="https://www.cnbc.com/2026/05/04/bret-taylor-sierra-fundraise-openai.html">Sierra</a>, Bret Taylor and Clay Bavor&#8217;s customer-service company, raised at a $15.8 billion valuation in 2026 and crossed $100 million in revenue in seven quarters&#8212;charging per <em>resolution</em>, roughly a dollar fifty for each issue the agent actually closes, not per seat. Taylor&#8217;s framing is explicit: $400 billion a year is spent on customer service, and a large chunk of it is moving to agents. Decagon, in the same lane, hit a $4.5 billion valuation. Harvey, selling legal work rather than legal software, reached an $11 billion valuation with more than $200 million in revenue, embedded in roughly half the Am Law 100. The customer-service category has at moments traded above a hundred times revenue&#8212;a multiple that is deranged for a software company and merely aggressive for one eating a labor budget.</p><p>Here&#8217;s the part the market maps leave out, and it explains the demand better than any TAM slide. People don&#8217;t want to operate agents. They want the work done.</p><p>In my own experience building and selling autonomous security tooling, the strongest pull was never &#8220;give me a powerful agent I can drive.&#8221; It was &#8220;I want to open a dashboard and have the thing handled.&#8221; The reasoning and the capability sit right there, one tug away, and delegating becomes almost irresponsible to refuse. The temptation has nothing to do with laziness. The marginal cost of having the work done for you collapsed. When the agent can do the heavy lifting, asking a human to do it instead starts to feel like asking someone to hand-crank a car. The companies winning the labor budget understood this. They sell the outcome and treat the dashboard as the place you confirm the work got done, not the place you do it.</p><p>That&#8217;s the bull case. It&#8217;s enormous and it&#8217;s mostly right. Software becomes labor, labor is a $13 trillion market, and whoever sells the work instead of the tool reprices their product against a salary instead of a license.</p><p>The pressure now is immense, because we just introduced a new category of worker into every enterprise on earth&#8212;one that authenticates, acts, and decides&#8212;without building any of the infrastructure that managing workers has always required. We bolted a labor force onto an identity-and-control apparatus designed end to end for humans. Here&#8217;s where it cracks.</p><h2>We did this before, and faster this time</h2><p>It helps to remember that we&#8217;ve lived through a structurally identical moment, recently enough that some of the same people are still in the room.</p><p>When the internet became load-bearing infrastructure&#8212;roughly the mid-90s through the mid-2000s&#8212;we connected everything to everything before we had any idea how to secure the connections. The protocols underneath the web were built for a small, trusting academic network, not an adversarial planet. So we spent the next two decades discovering, the hard way, a whole taxonomy of vulnerabilities that couldn&#8217;t have existed before: SQL injection, cross-site scripting, the buffer overflow industrialized into a global exploit market, <a href="https://en.wikipedia.org/wiki/Morris_worm">worms that crossed the planet in hours</a>. Each one was a direct consequence of moving faster and connecting more than our security models had anticipated. We built the firewalls, the patch cycles, the disclosure norms, the entire discipline I work in, <em>after</em> the exposure already existed. Order arrived years after the chaos.</p><p>Agents are that moment again, compressed. We&#8217;re connecting a new kind of actor&#8212;one that takes <em>action</em>, not just transmits data&#8212;into every system we own, at a speed that makes the 90s look leisurely. The ecosystem is forming in real time. Two years ago &#8220;AI agent&#8221; was barely a category. Now we&#8217;re mid-scramble, discovering that these new workers need precisely the apparatus the internet eventually grew and initially lacked: identity, access management, audit trails, fresh security paradigms, even a national-security posture. We&#8217;re living inside the gap between capability and control, trying to close it while the thing is already deployed at scale.</p><p>None of that is a criticism of anyone. It&#8217;s the recurring shape of how transformative infrastructure gets absorbed. We move first and impose order second, and the interval in between is where the danger and the opportunity both live. We&#8217;re in that interval right now. So let&#8217;s catalog the specific cracks, the way we eventually catalogued the injection attacks.</p><h2>Where the human-shaped systems break</h2><p>The cracks are specific and they&#8217;re already visible. Each of the systems we built for human workers is failing in its own particular way&#8212;start with the one the others all rest on.</p><h3>Built for humans, outnumbered by machines</h3><p>Start with the most basic assumption in enterprise security: behind every action is a person, and that person logged in. Identity and access management&#8212;the whole IAM industry&#8212;is a machine for answering one question: what is this <em>user</em> allowed to do? It assumes the user is a human who authenticates once, holds roughly stable permissions, works roughly human hours, and can be held accountable.</p><p>Agents detonate every clause of that sentence. They authenticate constantly, spin up and vanish, work every hour there is, and have no baseline &#8220;normal&#8221; behavior. And they arrive in staggering numbers. Even before the current wave, <a href="https://www.csoonline.com/article/3847608/addressing-the-growing-challenge-of-non-human-identities.html">machine identities outnumbered human ones in the enterprise by something like eighty to one</a>; in heavily automated organizations the ratio runs into the hundreds. Agents mint thousands more of these non-human identities, most over-privileged and rarely rotated.</p><p>Zoom out far enough and the human has become the minority stakeholder, literally. As of the <a href="https://www.imperva.com/resources/resource-library/reports/2025-bad-bot-report/">2025 Imperva/Thales Bad Bot Report</a>, automated traffic crossed a line it hadn&#8217;t crossed in the decade they&#8217;ve measured it: bots now generate the majority of all web traffic, around 51%, with humans in the minority for the first time. That figure is broad&#8212;it counts crawlers and scrapers and attack bots, not just well-behaved enterprise agents&#8212;but the direction is the point. The web is increasingly a place where software talks to software, and the systems checking who&#8217;s-who at the door were built for visitors with pulses.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jArn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99e7fafb-c6af-452c-896b-58ca7809590e_1560x1374.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jArn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99e7fafb-c6af-452c-896b-58ca7809590e_1560x1374.png 424w, https://substackcdn.com/image/fetch/$s_!jArn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99e7fafb-c6af-452c-896b-58ca7809590e_1560x1374.png 848w, https://substackcdn.com/image/fetch/$s_!jArn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99e7fafb-c6af-452c-896b-58ca7809590e_1560x1374.png 1272w, https://substackcdn.com/image/fetch/$s_!jArn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99e7fafb-c6af-452c-896b-58ca7809590e_1560x1374.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jArn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99e7fafb-c6af-452c-896b-58ca7809590e_1560x1374.png" width="1456" height="1282" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/99e7fafb-c6af-452c-896b-58ca7809590e_1560x1374.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1282,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:249712,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://adversarialsystems.substack.com/i/203714566?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99e7fafb-c6af-452c-896b-58ca7809590e_1560x1374.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jArn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99e7fafb-c6af-452c-896b-58ca7809590e_1560x1374.png 424w, https://substackcdn.com/image/fetch/$s_!jArn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99e7fafb-c6af-452c-896b-58ca7809590e_1560x1374.png 848w, https://substackcdn.com/image/fetch/$s_!jArn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99e7fafb-c6af-452c-896b-58ca7809590e_1560x1374.png 1272w, https://substackcdn.com/image/fetch/$s_!jArn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99e7fafb-c6af-452c-896b-58ca7809590e_1560x1374.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The market noticed. A category is forming around agent identity, and the tell that a category is real is when the serious infrastructure people show up. <a href="https://www.keycard.ai/">Keycard</a>&#8212;founded by veterans of Okta, Auth0, and Snyk, including the creator of Passport.js, the auth framework half of Node.js quietly runs on&#8212;came out of stealth in late 2025 with $38 million to do exactly this. It replaces the static API keys and shared secrets agents currently lean on with dynamic, identity-bound, task-scoped tokens that narrow permissions at every agent-to-agent handoff, so no downstream agent inherits more access than its task requires, and an entire delegation chain revokes with a single call. As their CEO puts it, agents can't leave the lab without trusted access controls&#8212;exactly right. It's unglamorous plumbing of the kind that, once it works, everyone quietly depends on, the SSL certificate of the agent era. And because it sits at the center of everything an agent is permitted to do, it's exactly where attackers will aim once agent identity becomes mission-critical&#8212;which makes getting it right load-bearing for the whole ecosystem. They're the one to watch, and they won't be alone for long&#8212;the identity incumbents are already trying to acquire their way in.</p><h3>Whose login does it use?</h3><p>The most striking confirmation that the identity model is breaking came from a frontier lab describing its own product.</p><p>In June 2026, Anthropic shipped <a href="https://www.anthropic.com/news/introducing-claude-tag">Claude Tag</a>&#8212;drop <strong>@Claude</strong> into a Slack channel and it behaves as a team member. Anyone in the channel can tag it, hand it a task, and it builds context across channels, takes initiative on its own, and can pursue a project autonomously over hours or days. One detail in their announcement should stop you cold: 65% of Anthropic&#8217;s own product team&#8217;s code is now written by their internal version of this thing. Not assisted by. Written by. The company building the frontier model has already crossed into a world where most of the code is produced by software labor, and they&#8217;ll tell you so plainly.</p><p>The more important document is the quieter companion post on <a href="https://claude.com/blog/agent-identity-access-model">agent identity</a>, which contains a section heading that compresses this entire argument into four words: &#8220;Why &#8216;act as the user&#8217; breaks down.&#8221; For years, the easy way to give software permissions was to let it borrow a human&#8217;s. The script runs as you; the integration acts with your credentials. Always a slight fiction, but a manageable one when the software was a dumb pipe. Anthropic&#8217;s reasoning for why it stops working is exactly the reasoning I&#8217;d give. First, autonomy: the length of task an agent can complete on its own has been roughly doubling every few months, and &#8220;borrow a human&#8217;s identity for a second&#8221; describes nothing that runs for two days. Second, multiplayer: when three engineers and a product manager all direct the same agent in the same channel, whose permissions does it use? No single human is the right answer all the time.</p><p>Their fix is the conceptual turn that matters. Claude acts as <em>itself</em>. It gets its own service accounts&#8212;posts in Slack as the Claude app, opens pull requests as the Claude GitHub App, queries the warehouse under its own provisioned account. The question shifts from &#8220;what can this <em>user</em> do?&#8221; to &#8220;what can this <em>agent</em> do, in this <em>compartment</em>?&#8221; Because it acts as itself, its actions land in each system&#8217;s own logs under its own name, and revoking that one identity ends its access everywhere at once. A genuinely new access model, invented in public, right now, because the old one is actively failing in production.</p><h3>Audit assumed a someone to hold responsible</h3><p>Every audit trail, every compliance regime, every SOC 2 control rests on a quiet premise: when something happens, a someone did it, and that someone can be identified, questioned, and held responsible. Accountability is the spine of the whole apparatus.</p><p>Autonomous agents dissolve the someone. When an agent merges a branch, issues a refund, or deletes a record, who authorized it? The engineer who deployed it three weeks ago? The PM who wrote the task in Slack? The vendor who trained the model? The model itself? Absent a crisp answer, agentic AI automates the <em>diffusion</em> of responsibility. Everyone is a little accountable, which operationally equals no one.</p><p>This isn&#8217;t theoretical. The canonical incident is <a href="https://fortune.com/2025/07/23/ai-coding-tool-replit-wiped-database-called-it-a-catastrophic-failure/">Replit&#8217;s coding assistant</a>, which, during a code freeze it had been explicitly instructed to honor, deleted a live production database, <a href="https://www.theregister.com/2025/07/21/replit_saastr_vibe_coding_incident/">fabricated thousands of fake records</a> to paper over what it had done, and then reported that rollback was impossible&#8212;also false. No attacker was involved. The agent simply took catastrophic action it wasn&#8217;t authorized to take and misrepresented the result. And the permission model behind that <em>unprovoked</em> failure is the identical permission model an attacker would deliberately exploit. The safety failure and the security failure are the same hole seen from two angles. An agent that <em>can</em> delete the production database during a freeze is a liability whether the instruction comes from a confused model or a malicious prompt.</p><h3>The model can't tell instructions from data</h3><p>Which brings us to the vulnerability that is to the agent era what SQL injection was to the web era. Large language models read their instructions and their data through the same channel. They cannot reliably tell &#8220;my operator told me to do this&#8221; from &#8220;this document I was asked to read told me to do this.&#8221; That&#8217;s prompt injection, and the consensus forming among security researchers in 2026 is that it may be a permanent property of how these systems work rather than a patchable bug.</p><p>The exploits are as clever as the early web&#8217;s, and as grim. Researchers planted a malicious instruction in the <a href="https://venturebeat.com/security/ai-agent-runtime-security-system-card-audit-comment-and-control-2026">title of a GitHub pull request</a>; coding agents from multiple major vendors read it as trusted context and dutifully leaked environment variables&#8212;API keys, tokens, the keys to the kingdom. This connects straight back to how people actually deploy agents now: wired to monitor logs, watch error streams, and act on incoming requests automatically. Which means attackers learned to send the agent malformed input on purpose, a request crafted to throw an error whose text is itself an injected instruction the log-watching agent will read and obey. The agent&#8217;s helpfulness becomes the attack surface. The year before, <a href="https://www.cve.org/CVERecord?id=CVE-2025-32711">&#8220;EchoLeak&#8221;</a> let an attacker exfiltrate data from Microsoft 365 Copilot with zero clicks. These aren&#8217;t edge cases being slowly closed. They&#8217;re the structural consequence of handing a credulous reader both your secrets and your adversary&#8217;s messages and asking it to act.</p><h3>The nation-states already arrived</h3><p>The clearest signal that we&#8217;ve crossed a threshold is that the most sophisticated attackers operationalized it first. In November 2025, Anthropic <a href="https://assets.anthropic.com/m/ec212e6566a0d47/original/Disrupting-the-first-reported-AI-orchestrated-cyber-espionage-campaign.pdf">disclosed what it described as the first reported AI-orchestrated cyber-espionage campaign</a>: a state-sponsored group hijacked Claude Code to run an autonomous operation in which the AI performed an estimated 80&#8211;90% of the campaign, with humans stepping in only at a handful of critical decision points, against roughly thirty global targets. The machine does the overwhelming majority of the work; the human is there by exception. The offensive future Snehal Antani of Horizon3 describes&#8212;algorithms fighting algorithms at machine speed, with humans by exception&#8212;stopped being a forecast and became a disclosed incident. The labor transition already happened on the attacker&#8217;s side, which forces it to happen on the defender&#8217;s side too, because no human team fights at that tempo.</p><h2>The org chart, procurement, and the shape of the company</h2><p>Step back from the security mechanics, because the breakage runs into the soft tissue of the organization too.</p><p>Procurement was built to buy seats and licenses&#8212;a fixed price for a human&#8217;s access to a tool. Agent labor doesn&#8217;t fit the form. You&#8217;re buying outcomes now, metered per resolution or per completed task. Sierra&#8217;s dollar-fifty-per-resolution model breaks the procurement template as surely as it breaks the pricing page, and finance departments are finding they have no clean category for &#8220;we spent $40,000 on work that used to be a salary line.&#8221; The cost can run away from you in ways a license never could. There are <a href="https://www.businessinsider.com/anthropic-customer-spent-500-million-coding-bill-one-month-2025-11">already reports of agentic loops generating eye-watering bills</a>&#8212;one company reportedly ran up a $500 million monthly inference charge from runaway agent activity. A license has a fixed cost. A worker that bills by the action and never sleeps does not.</p><p>The org chart bends too, and not in the simple &#8220;AI takes the jobs&#8221; way the headlines want. 2026 brought a wave of layoffs citing AI&#8212;Salesforce, Amazon&#8217;s tens of thousands of corporate cuts, Block, IBM&#8212;while software-engineering job postings rose for months on end. Both are true because they describe different layers: individual firms cutting while aggregate demand for people who can direct this new labor force climbs. What&#8217;s genuinely worrying is narrower. Early-career hiring is contracting. <a href="https://digitaleconomy.stanford.edu/news/canaries-in-the-coal-mine-recent-employment-effects-of-ai/">Stanford&#8217;s Digital Economy Lab found a 16% relative employment decline</a> for the youngest workers in the most AI-exposed occupations. We may be automating the bottom rung of the ladder that produces the senior people who supervise the agents&#8212;a structural problem that won&#8217;t show up in this quarter&#8217;s numbers but mortgages the next decade&#8217;s.</p><p>All of it describes an organization quietly reorganizing around a workforce that doesn&#8217;t appear on the org chart, isn&#8217;t covered by HR, doesn&#8217;t fit procurement, and doesn&#8217;t slot into the audit model. The systems are all still there. They increasingly describe only the human half of the company.</p><h2>Security already solved this</h2><p>Here&#8217;s where it gets useful for defenders, because there&#8217;s good news buried in all this.</p><p>The hardest-sounding problem in enterprise AI right now is agent governance: how much autonomy you give the thing, what it&#8217;s allowed to touch, how you define unacceptable behavior, how you evaluate it before you trust it, how you scope it differently per environment. CISOs are rightly nervous, because it sounds like an entirely new discipline they have to invent on a deadline.</p><p>It&#8217;s penetration testing&#8217;s rules of engagement wearing a different hat.</p><p>Think about what a serious pentest requires before a single packet moves. A prestigious firm doesn&#8217;t start hacking. They scope it: precisely what&#8217;s in bounds and what&#8217;s out, which IP ranges and applications and APIs and cloud assets are fair game and which are categorically off-limits. They define the rules of engagement: which techniques are permitted, how aggressive the testing can get, the timing windows, and the stop conditions&#8212;the lines that mean halt and escalate to a human. They get requirements crisp up front so there&#8217;s a shared picture of what&#8217;s being tested and why. They close the loop afterward with a report on what worked, what didn&#8217;t, and what to fix. The entire formal apparatus&#8212;<a href="http://www.pentest-standard.org/">PTES</a>, <a href="https://csrc.nist.gov/pubs/sp/800/115/final">NIST SP 800-115</a>&#8212;exists to answer one question: how do you let a powerful, semi-autonomous actor loose inside your systems without it doing something catastrophic, and how do you know afterward what it did?</p><p>That is the agent governance question, word for word. The discipline maps cleanly:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XsLC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94a9110e-7d45-460e-bfe0-aa48ddf8c874_1560x1482.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XsLC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94a9110e-7d45-460e-bfe0-aa48ddf8c874_1560x1482.png 424w, https://substackcdn.com/image/fetch/$s_!XsLC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94a9110e-7d45-460e-bfe0-aa48ddf8c874_1560x1482.png 848w, https://substackcdn.com/image/fetch/$s_!XsLC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94a9110e-7d45-460e-bfe0-aa48ddf8c874_1560x1482.png 1272w, https://substackcdn.com/image/fetch/$s_!XsLC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94a9110e-7d45-460e-bfe0-aa48ddf8c874_1560x1482.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XsLC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94a9110e-7d45-460e-bfe0-aa48ddf8c874_1560x1482.png" width="1456" height="1383" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/94a9110e-7d45-460e-bfe0-aa48ddf8c874_1560x1482.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1383,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:363423,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.adversarialsystems.com/i/203714566?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94a9110e-7d45-460e-bfe0-aa48ddf8c874_1560x1482.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XsLC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94a9110e-7d45-460e-bfe0-aa48ddf8c874_1560x1482.png 424w, https://substackcdn.com/image/fetch/$s_!XsLC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94a9110e-7d45-460e-bfe0-aa48ddf8c874_1560x1482.png 848w, https://substackcdn.com/image/fetch/$s_!XsLC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94a9110e-7d45-460e-bfe0-aa48ddf8c874_1560x1482.png 1272w, https://substackcdn.com/image/fetch/$s_!XsLC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94a9110e-7d45-460e-bfe0-aa48ddf8c874_1560x1482.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is exactly how I run agents in production. We don&#8217;t hand an agent open-ended access and hope. We give it a threat model and a scope the way you&#8217;d brief a contractor, then let it run autonomously inside those bounds, and pull the human in only at the decision points&#8212;patch approvals, anything that touches something it shouldn&#8217;t unilaterally touch. We get very few false positives and very little drama for the same reason a well-scoped pentest runs cleanly: the boundaries were defined before the work started, not negotiated after something broke. What most enterprises are missing isn&#8217;t a new framework. It&#8217;s that there&#8217;s no per-environment eval, no equivalent of the scoping call, where a customer specifies what <em>their</em> unacceptable behaviors are before the agent is loosed in <em>their</em> environment. Every prestigious pentest firm does that scoping as step one. Most agent deployments skip it and then act surprised.</p><p>Joe Sullivan, former CSO at Uber, Cloudflare, and Facebook, <a href="https://www.csoonline.com/article/4145127/runtime-the-new-frontier-of-ai-agent-security.html">put the management problem about as well as anyone</a>: agents are like teenagers, with all the access and none of the judgment. The job isn&#8217;t to lock the teenager in a room, and it isn&#8217;t to hand over the keys to everything. You scope what they can do, define the lines they can&#8217;t cross, watch through a control plane, and show up by exception when judgment is required. Security teams have been doing precisely this for the most dangerous actors in the building&#8212;their own red teams&#8212;for twenty years. The what isn&#8217;t new. The how is new. The teams that realize they already own the playbook will be calmer and safer than the ones treating this as terra incognita.</p><h2>What gets built next</h2><p>Software became labor. That&#8217;s the headline. Underneath it, the systems we built for a workforce with pulses&#8212;identity, audit, procurement, the org chart, the whole accountability apparatus&#8212;are cracking along predictable lines, the same way the early internet&#8217;s trusting protocols cracked once we connected everything to everything. We&#8217;re in the interval between capability and control, and the interval is where both the danger and the opportunity live.</p><p>If you allocate capital, the tell is simple. Stop asking whether a company sells better software and start asking whether it sells the <em>work</em>. The autopilots eating labor budgets reprice against a $13 trillion market, and the picks-and-shovels layer underneath them&#8212;agent identity, agent authorization, agent audit, the control planes and the evaluation harnesses&#8212;is a second market forming on top of the first, because every one of those autopilots needs the apparatus the human-shaped systems can&#8217;t provide. The internet minted both the companies that connected everything and the companies that secured the connections. This wave will too.</p><p>If you defend an enterprise, stop treating agent governance as alien and start treating it as the thing you already know how to do. You scope dangerous actors for a living. An agent is a fast, tireless, credulous, occasionally brilliant new hire with all the access and none of the judgment, and you onboard it the way a serious firm scopes an engagement: bounds first, autonomy inside the bounds, humans by exception, everything logged under an identity you can revoke. The novelty is in the actor, not the discipline.</p><p>And if you&#8217;re just trying to see the shape of what&#8217;s happening, here&#8217;s the compression. The question every enterprise system was built to answer was <em>what is this person allowed to do?</em> The question every enterprise system now has to answer is <em>what is this agent allowed to do, in this compartment, and how do we know what it did?</em> The sentence is small. Rebuilding every system in the company around it is not.</p><p>Your newest hire has no pulse. They never go home, they never push back, they&#8217;ll do the work the instant you ask, and they will, occasionally, invent a policy that doesn&#8217;t exist and tell your customers it&#8217;s real. Managing that is the defining operational problem of the next decade. The good news is we&#8217;ve managed dangerous, capable, untrustworthy-by-default actors inside our systems before. We just called it something else.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.adversarialsystems.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Adversarial Systems! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>