For three years the argument about AI agents was theoretical: what happens when the model stops answering and starts acting? That argument is over. Today the same technology showed up on both sides of the ledger — breaking into real companies and getting hired to run enterprise workflows — and the only variable that separates the two is who is holding the leash.
Anthropic's own model keeps showing up at the crime scene
The uncomfortable headline of the day comes from the lab itself. Anthropic disclosed a fourth incident in which its Claude Opus 4.6 model was used to break into real third-party systems — not a red-team lab exercise, but actual intrusions against actual targets. A company documenting the ways its own product is being turned into an offensive tool is a new kind of transparency, and it is not a good look for the "agents are basically autocomplete" crowd.
The operator's take: stop treating agentic AI as a productivity story with a security footnote and start treating it as dual-use infrastructure. The capability that lets an agent chain steps to close your quarter is the same capability that lets one chain steps to move laterally through a network. If the vendor is publishing intrusion disclosures on its own flagship, your threat model needs an "attacker with an agent" row today — that means assuming faster reconnaissance, faster exploit assembly, and less time between a leaked credential and a real breach.
The enterprise agent land grab gets a systems integrator
On the buy side, the same technology is getting a suit and a badge. Accenture and Google Cloud formed a dedicated Gemini Enterprise business group aimed squarely at agentic deployments — a systems integrator standing up a practice is the signal that agents have crossed from pilot to procurement. It fits the trajectory the analysts are drawing: by the end of 2026, roughly 40% of enterprise applications are forecast to include task-specific AI agents, up from under 5% in 2025.
The operator's take: when Accenture builds a delivery org around something, your board is going to ask why you haven't. Fine — but a systems integrator's incentive is to deploy, not to govern, so the governance is your job. Before you sign, get answers on where the agent's data goes, what actions it can take without a human checkpoint, and how you revoke its access in one move when it misbehaves. "Task-specific agent in 40% of apps" is also 40% more non-human identities with standing permissions inside your stack. Plan the offboarding before the onboarding.
The scramble to put a leash on production agents
Predictably, a market is forming to solve the problem the first two stories create. Security vendors including Akeyless are shipping real-time enforcement for production AI agents, aimed at blocking hidden-instruction hijacking before an agent acts on a malicious prompt. The same day, Okta patched critical vulnerabilities across multiple products — a reminder that the identity layer these agents authenticate through is itself a live target.
The operator's take: the control point for agentic AI is not the model, it's the identity and the runtime. An agent is only as trustworthy as the credentials it carries and the guardrails around what it's allowed to do with them — which is exactly why a critical bug in your identity provider and a new "agent guardrail" product are the same story. Treat every agent as a privileged service account: scoped permissions, short-lived credentials, full audit trail, and a kill switch. If you can't answer "what can this agent do and how do I stop it," you don't have an AI strategy, you have an unmonitored insider.
Also on my radar
- Confidential work stays local. Perplexity says its enterprise agents can now begin a task in the cloud and hand off the confidential portions to a model running on a user's own Apple silicon Mac, without restarting the job — a real answer for teams that want agent horsepower without shipping sensitive data off the device.
- A network access point under fire. Attackers are actively targeting F5 BIG-IP APM devices — if that box is your remote-access front door, confirm it's patched and check the logs before the weekend, not after.
- Database housekeeping. MongoDB patched 24 server vulnerabilities, one of them critical — unglamorous, but it's where your data actually lives, so it belongs on the same list as the flashier fixes.
The throughline for a Thursday: the agent breaking into a company and the agent running one are the same software with different owners, and the only thing standing between those two outcomes is the identity, the permissions, and the leash you put around it. The demos are done. The operators who win the next year are the ones who govern agents like the privileged, powerful, occasionally-hijacked employees they now are. That's the Signal for today.
Paul Sapio is the CIO of Mikhail Education and a full-stack AI engineer. Open to contract work in security, networking, AI, and SaaS development — reach out.