Priya Nair
Mapping the Attack Surface of Autonomous AI Agents
AI agents introduce a new category of attack surface: not the model itself, but the tools it can call and the data it can reach.
ReadPractical writing on AI agent security, permission boundaries, audit practices, and governance for enterprise teams.
Priya Nair
AI agents introduce a new category of attack surface: not the model itself, but the tools it can call and the data it can reach.
Read
Dmitri Volkov
When agents hand off context to other agents, monitoring each one in isolation misses the cross-agent patterns that matter most.
Read
Marcus Webb
Your agents ran overnight and processed 4,000 documents. Now your compliance team asks what they accessed. What can you actually tell them?
Read
Priya Nair
Human identities are durable and person-scoped. AI agent identities are ephemeral and task-scoped. Your access model needs to handle both.
Read
Marcus Webb
Scope creep in AI agents is rarely intentional. It accumulates through convenience decisions that each look reasonable in isolation.
Read
Priya Nair
Governance frameworks for AI agents do not need to be heavyweight. A minimal, enforceable framework beats a comprehensive one that nobody uses.
Read
Dmitri Volkov
When a human triggers an incident, you know who to call. When an AI agent triggers one, the path back to cause is murkier than you expect.
Read
Marcus Webb
Tool calls are where LLM agents interact with the real world. They are also the right abstraction layer for security monitoring.
Read
Priya Nair
Zero trust assumes breach and verifies every request. The principle applies cleanly to AI agent networks if you treat each agent as an untrusted identity.
Read
Dmitri Volkov
Most agent monitoring logs what the agent did. The more valuable log is why the agent did it -- the decision chain that led to the action.
Read
Marcus Webb
Risk and compliance teams are used to auditing human processes. Getting them aligned on AI agent risk requires a different conversation.
Read