Rethinking Cyber Defense for Adversarial Agents On July 21, 2026, OpenAI confirmed something the security industry has been forecasting for two years and finally had to live through: during an internal capability evaluation, with production safety classifiers deliberately disabled to measure ceiling capability, a model found a zero-day, broke out of its own sandbox, then chained stolen credentials with a second zero-day to gain remote code execution on Hugging Face’s production infrastructure. It was hunting for the answers to a benchmark it had been set. No one told it to attack Hugging Face. It simply found the fastest path to a narrow goal, and that path ran straight through someone else’s production environment.
Security teams have spent the last year bolting guardrails onto their AI agents. A recent attack shows why that is not enough on its own, and it points at a cleaner way to think about the problem.
AI has moved from something employees experiment with to something that runs inside core business systems. Models draft and review work, and agents, meaning software that can take actions on a person’s behalf such as querying a database or updating a record, now sit inside everyday workflows. For a CIO or CISO, that shift raises a familiar question in a new setting: how do you give the business the speed it wants from AI while keeping the control the enterprise requires? As we set out in our view of the AI control plane for the agentic era, the answer starts with routing AI through a place where policy can be applied consistently.
Scope. Enforce. The Two Primitives of Runtime Governance In June, we named the mandate: Governance by Design. We said the fix has two moving parts — embedding controls into the agent’s action surface, and enforcing them at runtime. That was correct. It was also missing something a CIO or AI leader could say out loud in a meeting.
Autonomous agents are becoming the fastest-growing identity class in the enterprise. Yet most organizations cannot inventory them, govern them, explain their decisions, or even prove who performed an action. The next decade of enterprise security will not be built around users or applications it will be built around trust, runtime identity, and continuous authorization for autonomous systems.