Discussion about this post

User's avatar
State of Play's avatar

The mapping is the sharpest part of the piece for me: excessive agency to tools and permissions, unbounded consumption to rate limits and circuit breakers, hidden context exposure to what actually gets loaded into the window. Each of those is a distinct engineering surface with a plausible owner, which is different from "harness security" as one undifferentiated blob someone eventually inherits.

So the practical question: of those three, are you seeing any of them get a named owner in production, someone whose job is sign-off on tool permissions or provenance on what enters context, or is it still diffuse by default across AppSec, platform, and ML teams? That seems like the actual tell for whether this Top 10 changes anything operationally versus just describing the problem more precisely.

Amit Spitzer's avatar

This changes what I diligence in an AI security vendor pitch. I've stopped asking which models they support and started asking whether they can produce a diff between what an agent was granted and what it actually invoked over the last 30 days. Almost every vendor logs actions taken; almost none log the unused half of the grant. If excessive agency is the fastest-growing risk, the permissions nobody's using yet are the part of the harness nobody's pricing.

2 more comments...

No posts

Ready for more?