Moona Intelligence
Live market intelligence for Agent Authority.
No period over period comparison yet
I am not showing a period over period comparison yet, and I want to be direct about why. Moona Intelligence opened on 12 August 2026. A fair comparison needs two full windows collected the same way, and anything in the ledger dated before the desk opened is only there because a recent record cited it. That makes it a biased sample of its own period, not a baseline. The last 3 months comparison becomes available from 7 February 2027.
Audit and evidence is where everyone is building. It is also where things keep breaking.
The market is treating audit and evidence as a control point. But six observed failures still map to this surface, so I am not convinced yet about where the winning implementation lands.
54 gap74 response6 failures32 organizations
How convinced I amHigh that it mattersLow on where it lands
Why I read it that way
54 of the window's artifacts show that gap open in practice and 74 show a deliberate move against it, across 44 distinct developments. 32 separate organizations published on the response side: AWS, Algorand Foundation, AlpacaX, Ant Group, Anthropic and 27 others. High conviction that it matters, low conviction about where it lands.
Last 3 months, 1 June 2026 to 29 August 2026. 374 independent artifacts, 55 showing a gap open and 82 showing a move against one.
Audit and Evidence carries more independent evidence than anything else I track this period, and it reads mixed. 55 of the artifacts in this window show a control gap open in practice, and 82 show somebody deliberately moving against one.
Seven separate real world failures sit inside this window, every one of them a system doing what it had been permitted to do.
What I would do
2 things deserve attention right now- Now
Go harder on approval controls.
- 51 response artifacts against 20 showing the gap open.
- 26 independent organizations have published on it in this window.
- One observed failure maps to this surface.
- High conviction on direction, accelerating.
This is one of the cleanest directional signals on the board. 26 independent organizations behind it, and almost nothing failing under it.
See the evidenceWhy this matters for Moona
What put it here
- High conviction on direction, which is the level where I would build.
- Response outweighs the gap, 51 against 20, so the market is answering this rather than only reporting it.
- 26 independent organizations published on it, and no single publisher holds more than 13 percent of the response.
What held it back
- One observed failure still sits on it.
One failure so far, against 51 response artifacts on the response side.
- Watch
Do not call audit and evidence yet.
- 74 response artifacts against 54 showing the gap open.
- 32 independent organizations have published on it in this window.
- Six observed failures map to this surface.
- Low conviction on direction, accelerating.
This is the surface I am least willing to act on, and not because it is quiet. It carries the largest evidence base on the board with the least resolved direction.
See the evidenceWhat would resolve it
What put it here
- 32 independent organizations published on it, and no single publisher holds more than 13 percent of the response.
- Accelerating inside this window.
What held it back
- Six observed failures against 74 response artifacts, which is a heavier failure burden than the rest of the board carries.
- Low conviction on direction. It clearly matters. I do not yet know where it lands.
six failures sit against 74 response artifacts trying to close them, closer than it looks but still short of caught up.
Why nothing else made the list
- Sequence Integrity. One observed failure still sits on it.
- Agent Identity. Four observed failures against 74 response artifacts, which is a heavier failure burden than the rest of the board carries.
- Delegated Authority. Three observed failures against 66 response artifacts, which is a heavier failure burden than the rest of the board carries.
- Execution Authority. Three observed failures against 53 response artifacts, which is a heavier failure burden than the rest of the board carries.
- Environment Boundaries. Four observed failures against 62 response artifacts, which is a heavier failure burden than the rest of the board carries.
What could change the call
Audit and Evidence keeps breaking while the market builds around it.
Six separate real world failures in this window map to audit and evidence, against 74 artifacts showing a deliberate move against it. The response is running ahead of the failures on this surface, which is the shape of a problem being absorbed rather than solved. I would keep watching it either way. Seven failures sit in the window in total, so this is concentration rather than the whole picture.
For now the response is growing faster than the failures. If that reverses, I change my read.
See what sits behind itControls are arriving on audit and evidence and it still fails
32 organizations published controls for audit and evidence inside this window, and six real world failures still landed on the same surface. Either the controls are not deployed where the failures happen, or they do not cover what breaks.
Another failure on that surface with no matching control published would tell me the response is aimed at the wrong thing.
See what sits behind it
This section exists to find the evidence that proves the call wrong.
Where I stand right now
Open a row for the evidence, the conviction and the records behind it- 20 gap · 51 response · 1 failedHigh mattersHigh direction
The response side on approval controls is already well ahead, 51 artifacts against 20, from 26 organizations that did not coordinate.
Evidence on approval controls did not just pick up, it surged: 24 before 16 July 2026, 240 on or after it.
Conviction it matters264 independent artifacts across 23 distinct developments and 71 organizations, comfortably past the bar for high importance.
Conviction on directionA broad base of 71 graded artifacts, and most of it shows the market building rather than breaking: 51 to 20.
One failure so far, against 51 response artifacts on the response side.
Somebody has to say yes before a consequential action proceeds, and the market is still deciding which actions those are.
Where the gap is open- draft-asor-wimse-agent-delegation-chain-00, IETF Datatracker document recordIETF Datatracker · 27 August 2026
- attenu-guard, PyPI registry metadata and release historyPyPI · 26 August 2026
- The State of Agent Security 2026Reco · 26 August 2026
Where the market is answering- Out-of-band approval: why an agent's own channel can never be the one that approvesAlpacaX · 28 August 2026
- Previewing the Model Hardware StandardAnthropic · 27 August 2026
- Your agent's guardrails have a bypassMicrosoft, Command Line / Responsible AI · 27 August 2026
- 20 gap · 40 response · 1 failedModerate mattersModerate direction
The response side on sequence integrity is already well ahead, 40 artifacts against 20, from 20 organizations that did not coordinate.
Evidence on sequence integrity did not just pick up, it surged: 14 before 16 July 2026, 155 on or after it.
Conviction it matters14 distinct developments and 51 organizations behind 169 artifacts, short of this window's leading surface.
Conviction on directionThe graded evidence leans toward the response side at 40 of 60, though not from enough separate organizations for me to call it firmly.
One failure so far, against 40 response artifacts on the response side.
Each step can be permitted while the sequence they form is not, and almost nothing checks the sequence.
Where the gap is open- Hugging Face Incident Technical ReportOpenAI · 26 August 2026
- OpenAI: Agent behavior that led to Hugging Face intrusion formed in MayCyberScoop · 26 August 2026
- OpenAI, independent firms publish reports into rogue AI agent attack on Hugging Face. Here's what they say, and what they don'tFortune · 26 August 2026
Where the market is answering- Previewing the Model Hardware StandardAnthropic · 27 August 2026
- Your agent's guardrails have a bypassMicrosoft, Command Line / Responsible AI · 27 August 2026
- Visa Expands Support for its Clients and the Industry as Organizations Navigate New AI Era of CybersecurityVisa · 27 August 2026
- 45 gap · 74 response · 4 failedHigh mattersModerate direction
No surface in this window has more organizations publishing against it without coordinating than agent identity: 32 organizations.
Evidence on agent identity did not just pick up, it surged: 40 before 16 July 2026, 298 on or after it.
Conviction it mattersAgent identity trails only this window's most covered surface: 338 independent artifacts across 41 distinct developments and 87 organizations.
Conviction on directionThe graded evidence leans toward the response side at 74 of 119, though not from enough separate organizations for me to call it firmly.
four failures sit against 74 response artifacts trying to close them, closer than it looks but still short of caught up.
Systems need to know which actor is acting, and most agents still act as the human who started them.
Where the gap is open- draft-asor-wimse-agent-delegation-chain-00, IETF Datatracker document recordIETF Datatracker · 27 August 2026
- Hugging Face Incident Technical ReportOpenAI · 26 August 2026
- OpenAI: Agent behavior that led to Hugging Face intrusion formed in MayCyberScoop · 26 August 2026
Where the market is answering- Out-of-band approval: why an agent's own channel can never be the one that approvesAlpacaX · 28 August 2026
- Previewing the Model Hardware StandardAnthropic · 27 August 2026
- Your agent's guardrails have a bypassMicrosoft, Command Line / Responsible AI · 27 August 2026
- 41 gap · 62 response · 4 failedHigh mattersModerate direction
28 separate organizations published against environment boundaries in this window without coordinating.
Evidence on environment boundaries did not just pick up, it surged: 25 before 16 July 2026, 273 on or after it.
Conviction it mattersEnvironment boundaries trails only this window's most covered surface: 298 independent artifacts across 34 distinct developments and 83 organizations.
Conviction on directionThe graded evidence leans toward the response side at 62 of 103, though not from enough separate organizations for me to call it firmly.
four failures sit against 62 response artifacts trying to close them, closer than it looks but still short of caught up.
What the agent can reach decides what a mistake costs, and reachability is set long before the agent misbehaves.
Where the gap is open- draft-asor-wimse-agent-delegation-chain-00, IETF Datatracker document recordIETF Datatracker · 27 August 2026
- Hugging Face Incident Technical ReportOpenAI · 26 August 2026
- OpenAI: Agent behavior that led to Hugging Face intrusion formed in MayCyberScoop · 26 August 2026
Where the market is answering- Previewing the Model Hardware StandardAnthropic · 27 August 2026
- Your agent's guardrails have a bypassMicrosoft, Command Line / Responsible AI · 27 August 2026
- Visa Expands Support for its Clients and the Industry as Organizations Navigate New AI Era of CybersecurityVisa · 27 August 2026
- 54 gap · 74 response · 6 failedHigh mattersLow direction
No surface in this window has more organizations publishing against it without coordinating than audit and evidence: 32 organizations.
Evidence on audit and evidence did not just pick up, it surged: 40 before 16 July 2026, 309 on or after it.
Conviction it mattersAudit and evidence is the most covered surface in this window: 349 independent artifacts across 44 distinct developments and 92 organizations.
Conviction on direction54 against 74, close enough to call it unresolved rather than lopsided. The evidence still clears the bar for mattering, so this is a real open question, not a quiet one.
six failures sit against 74 response artifacts trying to close them, closer than it looks but still short of caught up.
After an agent acts, somebody has to be able to prove what it did and who permitted it.
Where the gap is open- draft-asor-wimse-agent-delegation-chain-00, IETF Datatracker document recordIETF Datatracker · 27 August 2026
- Hugging Face Incident Technical ReportOpenAI · 26 August 2026
- OpenAI: Agent behavior that led to Hugging Face intrusion formed in MayCyberScoop · 26 August 2026
Where the market is answering- Out-of-band approval: why an agent's own channel can never be the one that approvesAlpacaX · 28 August 2026
- Previewing the Model Hardware StandardAnthropic · 27 August 2026
- Your agent's guardrails have a bypassMicrosoft, Command Line / Responsible AI · 27 August 2026
- 37 gap · 53 response · 4 failedHigh mattersLow direction
26 separate organizations published against human oversight in this window without coordinating.
Evidence on human oversight did not just pick up, it surged: 20 before 16 July 2026, 201 on or after it.
Conviction it matters221 independent artifacts across 25 distinct developments and 58 organizations, comfortably past the bar for high importance.
Conviction on direction37 against 53, close enough to call it unresolved rather than lopsided. The evidence still clears the bar for mattering, so this is a real open question, not a quiet one.
four failures sit against 53 response artifacts trying to close them, closer than it looks but still short of caught up.
Oversight is being sold as a control, and watching an action is not the same as being able to stop it.
Where the gap is open- draft-asor-wimse-agent-delegation-chain-00, IETF Datatracker document recordIETF Datatracker · 27 August 2026
- Hugging Face Incident Technical ReportOpenAI · 26 August 2026
- OpenAI: Agent behavior that led to Hugging Face intrusion formed in MayCyberScoop · 26 August 2026
Where the market is answering- Previewing the Model Hardware StandardAnthropic · 27 August 2026
- Your agent's guardrails have a bypassMicrosoft, Command Line / Responsible AI · 27 August 2026
- Visa Expands Support for its Clients and the Industry as Organizations Navigate New AI Era of CybersecurityVisa · 27 August 2026
What would make me change my mind
- Already in play
Failures keep landing on audit and evidence while the controls keep shipping. Two more independent failures on that surface with no matching control published would tell me the response is not touching what actually breaks.
- Not seen yet
The response stops widening. If the 32 organizations currently publishing on audit and evidence stay the only ones, this is a vendor push rather than a market converging, and I would drop the conviction on direction.
- Not seen yet
Another surface takes the lead. Agent Identity is 11 artifacts behind audit and evidence in this window. If that closes and holds, the call moves with it.
What I am watching next
Each trigger above is the same threshold the states themselves are computed from, so a reader can check the call rather than take it.
I could be wrong.
Signals I’m watching
- The response side on approval controls is already well ahead, 51 artifacts against 20, from 26 organizations that did not coordinate.Direction is resolved here, which is rare on this board.
- No surface in this window has more organizations publishing against it without coordinating than agent identity: 32 organizations.One of the largest evidence bases in this window, and the direction still has not resolved with it.
- No surface in this window has more organizations publishing against it without coordinating than audit and evidence: 32 organizations.Six observed failures on one surface, more than any other carries in this window.
Three surfaces out of 8 on the board are carrying something worth elevating.
The evidence behind this
Research in this window 19
- Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident
- Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident
- The State of Agent Security 2026
- PAuth - Precise Task-Scoped Authorization For Agents (arXiv:2603.17170v2)
- Agentic orchestration: Enterprise AI organizations know how to govern agents but still can't meter what they cost
- One Gate Is Not Enough: Composing Stateful Pre Action Controls for Agentic AI
- PACE: Policy-Attested Contract Execution for Safe AI Agents in Decentralized Finance (arXiv:2608.17220v1)
- Wiz Red Agent Finds Its Way Into Snowflake's Internal Jira Through a Flaw in a GitHub Copilot Assisted PR
- Bounded Agents: Delegation Security for Multi-Agent AI Systems
- Convergent Detour Hijacking: Task-Preserving Resource Amplification in Skill-Based LLM Agents
- Mind Viruses: Self-Propagating Ideas in Multi-Agent LLM Systems
- CoreBreak research and Black Hat USA 2026 briefing, Hedi Ingber and Aviyam Ivgi
- The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents (arXiv:2608.05884v1)
- Binding Biometrics with AI Agent Identifiers for Delegation of Authority
- Beyond Single-Use Tokens: Durable Authorization State for Replay-Resistant LLM Agent Actions
- Agent Control Planes Still Need A Robust Standards Stack
- Announcing Our Evaluation Of The Agent Control Plane Market
- Bad Memory: Evaluating Prompt Injection Risks from Memory in Agentic Systems
- The State of GRC in the Age of AI: New Research on the Accountability Gap
Click any card or row to open the evidence behind it.
What arrived since the last update
Evidence dated 29 August 2026One new record arrived, but none changed the thesis, directional conviction or what I would do.
- Nothing materially changed the call.
- Approval controls remains the clearest actionable direction.
- Audit and evidence remains important but unresolved.
See every record and what it did to my conviction
- Contextattenu-io/attenu-guard, CHANGELOG.md, 0.5.0 through 0.6.1 entriesDescribes audit and evidence without taking a side, so it counts as evidence of the surface and moves no direction.
What that did to my conviction
- Audit and Evidence is accelerating inside this windowEvidence on audit and evidence did not just pick up, it surged: 40 before 16 July 2026, 309 on or after it. No surface in this window has more organizations publishing against it without coordinating than audit and evidence: 32 organizations.
- Agent Identity is accelerating inside this windowEvidence on agent identity did not just pick up, it surged: 40 before 16 July 2026, 298 on or after it. No surface in this window has more organizations publishing against it without coordinating than agent identity: 32 organizations.
- Conviction is rising on agent identity32 independent organizations published 64 artifacts against agent identity, with no single one behind more than 13 percent of it, and the response side now outweighs the gap 74 to 45. Read that as consensus forming rather than a launch cycle.
- Conviction is rising on audit and evidence32 independent organizations published 64 artifacts against audit and evidence, with no single one behind more than 13 percent of it, and the response side now outweighs the gap 74 to 54. Read that as consensus forming rather than a launch cycle.
Movement is measured inside the selected window by comparing its earlier half with its later half, on eight surfaces that carry enough evidence to split.
Where organizations are moving together
- Agent IdentityConvergence forming32 organizations · 64 artifacts
32 independent organizations published 64 artifacts against agent identity, with no single one behind more than 13 percent of it, and the response side now outweighs the gap 74 to 45. Read that as consensus forming rather than a launch cycle.
AWS, Algorand Foundation, AlpacaX, Ant Group, Anthropic, Binance, Britive, Cloudflare, Drata, GitHub, Google, IBM, JFrog, Linux Foundation, Mate Security, Microsoft, National Institute of Standards and Technology, Nuggets, Okta, OpenAI, Proof, QuEra Computing, Rain, RebelDot, Reco, Rubrik, Salesforce, Somansa, Token, University of Southern California, Visa, Your Bourse
- Audit and EvidenceConvergence forming32 organizations · 64 artifacts
32 independent organizations published 64 artifacts against audit and evidence, with no single one behind more than 13 percent of it, and the response side now outweighs the gap 74 to 54. Read that as consensus forming rather than a launch cycle.
AWS, Algorand Foundation, AlpacaX, Ant Group, Anthropic, Binance, Britive, Cloudflare, Docker, Drata, Google, IBM, JFrog, Linux Foundation, Mate Security, Microsoft, National Institute of Standards and Technology, Nuggets, Okta, OpenAI, Proof, QuEra Computing, Rain, RebelDot, Reco, Rubrik, Salesforce, Somansa, Token, University of Southern California, Visa, Your Bourse
- Delegated AuthorityConvergence forming29 organizations · 56 artifacts
29 independent organizations published 56 artifacts against delegated authority, with no single one behind more than 13 percent of it, and the response side now outweighs the gap 66 to 43. Read that as consensus forming rather than a launch cycle.
AWS, Algorand Foundation, Ant Group, Anthropic, Binance, Britive, Cloudflare, Docker, GitHub, Google, IBM, JFrog, Mate Security, Microsoft, National Institute of Standards and Technology, Nuggets, Okta, OpenAI, Proof, Rain, Reco, Rubrik, Salesforce, Somansa, Token, University of Southern California, Visa, WRITER, Your Bourse
- Execution AuthorityConvergence forming29 organizations · 50 artifacts
29 independent organizations published 50 artifacts against execution authority, with no single one behind more than 10 percent of it, and the response side now outweighs the gap 53 to 30. Read that as consensus forming rather than a launch cycle.
AWS, Algorand Foundation, Anthropic, Binance, Britive, Cloudflare, DataHub, Docker, Drata, Fortinet, Google, JFrog, Linux Foundation, Microsoft, National Institute of Standards and Technology, Nuggets, OpenAI, QuEra Computing, Rain, RebelDot, Reco, Rubrik, Salesforce, Somansa, Token, TrueFoundry, University of Southern California, Virtue AI, Your Bourse
- Environment BoundariesConvergence forming28 organizations · 54 artifacts
28 independent organizations published 54 artifacts against environment boundaries, with no single one behind more than 13 percent of it, and the response side now outweighs the gap 62 to 41. Read that as consensus forming rather than a launch cycle.
AWS, Algorand Foundation, Ant Group, Anthropic, Binance, Britive, Cloudflare, Docker, Google, IBM, JFrog, Linux Foundation, Lovable, Mate Security, Microsoft, National Institute of Standards and Technology, Okta, OpenAI, QuEra Computing, Rain, RebelDot, Reco, Salesforce, Somansa, Token, University of Southern California, Visa, Your Bourse
- Approval ControlsConvergence forming26 organizations · 45 artifacts
26 independent organizations published 45 artifacts against approval controls, with no single one behind more than 13 percent of it, and the response side now outweighs the gap 51 to 20. Read that as consensus forming rather than a launch cycle.
AWS, Algorand Foundation, AlpacaX, Ant Group, Anthropic, Binance, Britive, Cloudflare, DataHub, Docker, GitHub, Google, JFrog, Microsoft, National Institute of Standards and Technology, Okta, QuEra Computing, Rain, RebelDot, Reco, Salesforce, Somansa, Token, University of Southern California, WRITER, Your Bourse
- Human OversightConvergence forming26 organizations · 46 artifacts
26 independent organizations published 46 artifacts against human oversight, with no single one behind more than 15 percent of it, and the response side now outweighs the gap 53 to 37. Read that as consensus forming rather than a launch cycle.
AWS, Ant Group, Anthropic, Binance, Britive, Cloudflare, Drata, Fortinet, Google, IBM, JFrog, Mate Security, Microsoft, National Institute of Standards and Technology, OpenAI, QuEra Computing, RebelDot, Reco, Rubrik, Salesforce, Somansa, Token, University of Southern California, Virtue AI, Visa, WRITER
- Sequence IntegrityConvergence forming20 organizations · 37 artifacts
20 independent organizations published 37 artifacts against sequence integrity, with no single one behind more than 19 percent of it, and the response side now outweighs the gap 40 to 20. Read that as consensus forming rather than a launch cycle.
AWS, Anthropic, Britive, Cloudflare, Docker, Google, IBM, JFrog, Mate Security, Microsoft, National Institute of Standards and Technology, OpenAI, QuEra Computing, Rain, RebelDot, Reco, Token, University of Southern California, Visa, WRITER
Counted on who published, never on who was written about, and measured against how concentrated the publishing is.
What the evidence is about
- Agent Authority88%
- Incidents8%
- Research & Architecture2%
- Governance & Policy1%
- Enterprise Adoption1%
- Agent Security0%
Most of the evidence in this window sits in one cluster, Agent Authority, at 88 percent.
How the evidence is structured
After an agent acts, somebody has to be able to prove what it did and who permitted it.
349 independent artifacts across 44 distinct developments: 54 showing the gap open in practice, 74 showing a deliberate move against it and 221 documenting what platforms currently permit. Both sides of this are real, which is why I am not calling it a clean open problem. Part of it is being absorbed by the people who own the platform. The artifacts on the response side were published by GitHub, Google and Anthropic.
54 gap open in practice · 74 deliberate move against it · 221 documented platform behaviour
Where the gap is open- draft-asor-wimse-agent-delegation-chain-00, IETF Datatracker document recordIETF Datatracker · 27 August 2026
- Hugging Face Incident Technical ReportOpenAI · 26 August 2026
- OpenAI: Agent behavior that led to Hugging Face intrusion formed in MayCyberScoop · 26 August 2026
Counter evidence- Out-of-band approval: why an agent's own channel can never be the one that approvesAlpacaX · 28 August 2026
- Previewing the Model Hardware StandardAnthropic · 27 August 2026
- Your agent's guardrails have a bypassMicrosoft, Command Line / Responsible AI · 27 August 2026
Systems need to know which actor is acting, and most agents still act as the human who started them.
338 independent artifacts across 41 distinct developments: 45 showing the gap open in practice, 74 showing a deliberate move against it and 219 documenting what platforms currently permit. The evidence is spread across enough separate developments that this is a real surface rather than one story repeated. Most of it is the market building rather than the market breaking, so read this as where the control is going, not where it is failing. The artifacts on the response side were published by GitHub, Anthropic and Google.
45 gap open in practice · 74 deliberate move against it · 219 documented platform behaviour
Where the gap is open- draft-asor-wimse-agent-delegation-chain-00, IETF Datatracker document recordIETF Datatracker · 27 August 2026
- Hugging Face Incident Technical ReportOpenAI · 26 August 2026
- OpenAI: Agent behavior that led to Hugging Face intrusion formed in MayCyberScoop · 26 August 2026
Counter evidence- Out-of-band approval: why an agent's own channel can never be the one that approvesAlpacaX · 28 August 2026
- Previewing the Model Hardware StandardAnthropic · 27 August 2026
- Your agent's guardrails have a bypassMicrosoft, Command Line / Responsible AI · 27 August 2026
What the agent can reach decides what a mistake costs, and reachability is set long before the agent misbehaves.
298 independent artifacts across 34 distinct developments: 41 showing the gap open in practice, 62 showing a deliberate move against it and 195 documenting what platforms currently permit. The evidence is spread across enough separate developments that this is a real surface rather than one story repeated. Most of it is the market building rather than the market breaking, so read this as where the control is going, not where it is failing. The artifacts on the response side were published by GitHub, Google and Anthropic.
41 gap open in practice · 62 deliberate move against it · 195 documented platform behaviour
Where the gap is open- draft-asor-wimse-agent-delegation-chain-00, IETF Datatracker document recordIETF Datatracker · 27 August 2026
- Hugging Face Incident Technical ReportOpenAI · 26 August 2026
- OpenAI: Agent behavior that led to Hugging Face intrusion formed in MayCyberScoop · 26 August 2026
Counter evidence- Previewing the Model Hardware StandardAnthropic · 27 August 2026
- Your agent's guardrails have a bypassMicrosoft, Command Line / Responsible AI · 27 August 2026
- Visa Expands Support for its Clients and the Industry as Organizations Navigate New AI Era of CybersecurityVisa · 27 August 2026
Somebody has to say yes before a consequential action proceeds, and the market is still deciding which actions those are.
264 independent artifacts across 23 distinct developments: 20 showing the gap open in practice, 51 showing a deliberate move against it and 193 documenting what platforms currently permit. The evidence is spread across enough separate developments that this is a real surface rather than one story repeated. Most of it is the market building rather than the market breaking, so read this as where the control is going, not where it is failing. The artifacts on the response side were published by GitHub, Google and Anthropic.
20 gap open in practice · 51 deliberate move against it · 193 documented platform behaviour
Where the gap is open- draft-asor-wimse-agent-delegation-chain-00, IETF Datatracker document recordIETF Datatracker · 27 August 2026
- attenu-guard, PyPI registry metadata and release historyPyPI · 26 August 2026
- The State of Agent Security 2026Reco · 26 August 2026
Counter evidence- Out-of-band approval: why an agent's own channel can never be the one that approvesAlpacaX · 28 August 2026
- Previewing the Model Hardware StandardAnthropic · 27 August 2026
- Your agent's guardrails have a bypassMicrosoft, Command Line / Responsible AI · 27 August 2026
Oversight is being sold as a control, and watching an action is not the same as being able to stop it.
221 independent artifacts across 25 distinct developments: 37 showing the gap open in practice, 53 showing a deliberate move against it and 131 documenting what platforms currently permit. Both sides of this are real, which is why I am not calling it a clean open problem. Part of it is being absorbed by the people who own the platform. The artifacts on the response side were published by GitHub, Anthropic and DeepSeek.
37 gap open in practice · 53 deliberate move against it · 131 documented platform behaviour
Where the gap is open- draft-asor-wimse-agent-delegation-chain-00, IETF Datatracker document recordIETF Datatracker · 27 August 2026
- Hugging Face Incident Technical ReportOpenAI · 26 August 2026
- OpenAI: Agent behavior that led to Hugging Face intrusion formed in MayCyberScoop · 26 August 2026
Counter evidence- Previewing the Model Hardware StandardAnthropic · 27 August 2026
- Your agent's guardrails have a bypassMicrosoft, Command Line / Responsible AI · 27 August 2026
- Visa Expands Support for its Clients and the Industry as Organizations Navigate New AI Era of CybersecurityVisa · 27 August 2026
Each step can be permitted while the sequence they form is not, and almost nothing checks the sequence.
169 independent artifacts across 14 distinct developments: 20 showing the gap open in practice, 40 showing a deliberate move against it and 109 documenting what platforms currently permit. The evidence is spread across enough separate developments that this is a real surface rather than one story repeated. Most of it is the market building rather than the market breaking, so read this as where the control is going, not where it is failing. The artifacts on the response side were published by AWS, GitHub and DeepSeek.
20 gap open in practice · 40 deliberate move against it · 109 documented platform behaviour
Where the gap is open- Hugging Face Incident Technical ReportOpenAI · 26 August 2026
- OpenAI: Agent behavior that led to Hugging Face intrusion formed in MayCyberScoop · 26 August 2026
- OpenAI, independent firms publish reports into rogue AI agent attack on Hugging Face. Here's what they say, and what they don'tFortune · 26 August 2026
Counter evidence- Previewing the Model Hardware StandardAnthropic · 27 August 2026
- Your agent's guardrails have a bypassMicrosoft, Command Line / Responsible AI · 27 August 2026
- Visa Expands Support for its Clients and the Industry as Organizations Navigate New AI Era of CybersecurityVisa · 27 August 2026
Eight control surfaces carry enough independent evidence in this window to characterise.
Where companies are putting the control
54 organizations published separately against the same surface in this window, audit and evidence: AWS, Algorand Foundation, AlpacaX, Ant Group, Anthropic and 49 others.
What keeps breaking in the real world
- The AI Review Missed the Bug. Five Days Later, Another Agent Exploited It.Execution Authority, Agent Identity, Audit and Evidence17 August 2026View
- The Agent Created Another Agent. Which Permissions Came With It?Execution Authority, Delegated Authority, Approval Controls, Agent Identity, Environment Boundaries, Audit and Evidence, Human Oversight14 August 2026View
- When Several AI Agents Act at Once, Who Is Actually in Control?Delegated Authority, Audit and Evidence12 August 2026View
- It Booked the Gym Class. It Also Removed Someone Else From the Waitlist.No tracked control surface yet10 August 2026View
- Meta's AI Hacked Another Company. The Word to Focus on Is Misconfiguration.Execution Authority, Agent Identity, Environment Boundaries, Audit and Evidence, Human Oversight6 August 2026View
Repeating: Audit and Evidence (6), Agent Identity (4), Environment Boundaries (4), Human Oversight (4), Delegated Authority (3), Execution Authority (3).
Explore every incident analysisThe thing I keep coming back to
Everyone wants autonomous agents right up until autonomy touches something that matters. Not one of the failures in this window needed a model to misbehave. The systems did what they had been permitted to do, which means the permission was the defect.
The evidence keeps landing in the same place. Audit and Evidence is where the decision gets made, and prompts are not policy at that boundary. The organizations that will come out of this well are the ones enforcing at that boundary and keeping evidence a reader could check afterwards.
374 artifacts is what this rests on, with no previous window to measure it against. That is not a trend and I am not going to present it as one.
Explore by topic
Browse all topicsLatest Intelligence Records
See all Intelligence Records- Agent AuthorityCEOs Own the AI Budget. Who Owns the Agent's Actions?28 August 2026
- Agent AuthoritySARC Shows Why Remediated Agent Actions Need to Be Re-Evaluated28 August 2026
- Agent AuthorityDrata Used to Help You Prove the Control Existed. Now It Wants to Enforce It Before the Agent Acts.28 August 2026
- Agent AuthorityThe Employee Can Open the File. Somansa Says the Agent Still Might Not Be Allowed To.28 August 2026
- Agent AuthorityAsk DataHub Requires Human Approval. One Setting Decides Whether It Still Does.26 August 2026
