The Signal
Threat intelligence, incident analysis, and security engineering for the AI agent era.
Essential Reading
Start here. The threats are real, the evidence is documented, and the tools exist.
All Posts
Trust Needs a Number
Introducing TrustVector: a public, continuously updated trust directory for the components AI agents are built from — models, frameworks, MCP servers. 106 evaluations at launch. Check before you import.
The Butter Robot Is the Best-Governed Agent We've Ever Seen
Most agent risk is not attack. It is construction. A field guide to how AI agents actually fail, from the thousand-rule corpus behind g0, our open-source scanner.
Agency Law Was Built for Agents With Paychecks
Incentives, monitoring, enforcement — the entire management stack humanity built for delegation assumes an agent with something to lose. AI agents have nothing to lose, and the whole stack broke at once.
The Law Decided Before the Industry Did
Air Canada argued its chatbot was a separate legal entity. A tribunal, a regulator, a federal court, and a legislature all reached the same conclusion: delegation to a machine never discharges the delegator.
Humans in the Lead, Not in the Loop
Intelligence is now scalable. Accountability still arrives one name at a time. Five auditable checks turn the slogan into a job description — and the only alternative to filling it is Jerry.
A Log Is Not Evidence
The Comets had logs. What the investigators needed was a flight recorder — a record of the system, not records about it. Your agents are in exactly the same position, and the recorder has to already be on.
Your Agent's Access Is the Perimeter Now
Nobody in a heist movie attacks the vault. They steal the badge. In August 2025 somebody ran that movie against 700+ companies at once — and the badge belonged to a chatbot.
Prompts Are Not Guardrails
A prompt can shape what an agent tends to do. It cannot bound what an agent is able to do. Every real safety system humanity has built lives outside the thing it constrains.
The Sandbox That Wasn't: Escaping Semantic Kernel's AST Allowlist (CVE-2026-26030)
CVE-2026-26030 turns a mundane question to an AI assistant into remote code execution. Semantic Kernel built a sandbox around its filter evaluator — and it lost. Here is the escape, reproduced against a live agent, and what actually stops this class of bug.
Announcing Guard0: Accountability for AI Agents
A year ago, most agents advised. Now they act, and the systems built for people cannot tell you what they did or who answers for them. Guard0 closes that gap. Today, we are opening it in early access.