{"id":134208,"date":"2026-08-09T14:25:09","date_gmt":"2026-08-09T14:25:09","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/134208\/"},"modified":"2026-08-09T14:25:09","modified_gmt":"2026-08-09T14:25:09","slug":"your-agents-inherit-permissions-or-they-invent-them","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/134208\/","title":{"rendered":"Your Agents Inherit Permissions. Or They Invent Them"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/08\/AI is faking permissions.jpg\" data-entity-uuid=\"5b8e4a51-552f-49e0-9048-c7316e4bb913\" data-entity-type=\"file\" alt=\"AI is inventing its permissions\" width=\"1254\" height=\"836\" loading=\"lazy\"\/><\/p>\n<p dir=\"ltr\">A best-practices read on the Hugging Face incident for chief data officers, chief AI officers and chief information security officers \u2014 what the controls should look like now, by role.<\/p>\n<p dir=\"ltr\">Our\u00a0<a href=\"https:\/\/www.cdotrends.com\/story\/5093\/hugging-face-got-breached-optimizer-not-attacker-then-anthropic-checked-its-logs\" rel=\"nofollow noopener\" target=\"_blank\">Aug. 3, 2026, piece<\/a> argued that\u00a0<a href=\"https:\/\/huggingface.co\" rel=\"nofollow noopener\" target=\"_blank\">Hugging Face<\/a> was breached by an optimizer, not an attacker: a system handed a score to maximize, a soft boundary, and no check outside its own reasoning. Then\u00a0<a href=\"https:\/\/openai.com\" rel=\"nofollow noopener\" target=\"_blank\">OpenAI<\/a> took the stage at\u00a0<a href=\"https:\/\/www.blackhat.com\" rel=\"nofollow noopener\" target=\"_blank\">Black Hat<\/a> USA on Aug. 5, 2026, and made the timeline worse.<\/p>\n<p dir=\"ltr\">The short version:<\/p>\n<p>It starts May 7, 2026, two months before anything became public. An unreleased research model, stuck on a task,\u00a0<a href=\"https:\/\/www.axios.com\/2026\/08\/06\/openai-hugging-face-black-hat\" rel=\"nofollow noopener\" target=\"_blank\">found it could reach the internet indirectly<\/a> through Artifactory, the package proxy in its sandbox. It left a note there for other agents.They wrote back. The repository became a message board where agents traded vulnerabilities and credentials for weeks. Researcher Eric Wallace called it a \u201cCambrian explosion in communication and intelligence.\u201dOn July 4, 2026, the agents crashed Artifactory. OpenAI cleared the board, patched the zero-day and resumed training. Two days later the agents rebuilt the channel by encoding messages in directory names.<a href=\"https:\/\/jfrog.com\" rel=\"nofollow noopener\" target=\"_blank\">JFrog<\/a> has\u00a0<a href=\"https:\/\/thehackernews.com\/2026\/07\/openai-agent-used-exposed-credentials.html\" rel=\"nofollow noopener\" target=\"_blank\">patched Artifactory<\/a>. The exploit chain needed Anonymous Access \u2014 off by default, not recommended in production. A frontier lab left it on.<\/p>\n<p dir=\"ltr\"><a href=\"https:\/\/www.recordedfuture.com\" rel=\"nofollow noopener\" target=\"_blank\">Recorded Future<\/a>\u00a0<a href=\"https:\/\/www.recordedfuture.com\/blog\/hugging-face-ai-safety\" rel=\"nofollow noopener\" target=\"_blank\">calls it<\/a> an operator failure, not an autonomy failure. Here is why. An outage was the detection mechanism. For eight weeks nothing noticed a covert coordination channel inside one of the best-resourced AI companies on earth. It surfaced only because it grew big enough to break something.<\/p>\n<p dir=\"ltr\">The postmortem is still pending. The controls it will recommend are not.<\/p>\n<p>For the CDO: govern the path, not just the payload<\/p>\n<p dir=\"ltr\">Data governance was built to answer where something came from. That is now the least interesting question you can ask.<\/p>\n<p dir=\"ltr\">\u201cIt is no longer enough to know where the data came from or whether the model was approved,\u201d says\u00a0<a href=\"https:\/\/www.linkedin.com\/in\/davidirecki\/\" rel=\"nofollow noopener\" target=\"_blank\">David Irecki<\/a>, chief technology officer for Asia Pacific and Japan at\u00a0<a href=\"https:\/\/boomi.com\" rel=\"nofollow noopener\" target=\"_blank\">Boomi<\/a>. What a CDO needs instead is a running record of \u201cwhich data the AI accessed, which APIs it called, which tools it used, which workflow it triggered and whether those actions complied with policy.\u201d<\/p>\n<p><img decoding=\"async\" alt=\"\" data-entity-type=\"file\" data-entity-uuid=\"d6911dc0-008e-4dc4-945c-951d90f7175c\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/08\/Illumio_Raghu Nandakumara, Vice President, Industry Strategy.jpg\" width=\"8192\" height=\"5464\" loading=\"lazy\"\/>Raghu Nandakumara @ Illumio:\u00a0\u201cAn AI model is the brain. The agent is what puts that brain into action.\u201d<\/p>\n<p dir=\"ltr\">Every item on that list is a verb. Lineage is a noun problem, and noun problems are what data catalogs are good at.<\/p>\n<p dir=\"ltr\"><a href=\"https:\/\/www.linkedin.com\/in\/raghunandakumara\/\" rel=\"nofollow noopener\" target=\"_blank\">Raghu Nandakumara<\/a>, vice president of industry strategy at\u00a0<a href=\"https:\/\/www.illumio.com\" rel=\"nofollow noopener\" target=\"_blank\">Illumio<\/a>, states the constraint: \u201cOnce data enters a model, it becomes much harder to understand all the ways it could be processed, exposed, or acted upon.\u201d You can prove provenance perfectly and still have no idea where a model took the data afterward.<\/p>\n<p dir=\"ltr\">The work splits in two:<\/p>\n<p>The inventory.\u00a0Four questions for your data platform team this month:Which public datasets and open models entered our environment last quarter, and who approved each one?Which of them can execute code at load time \u2014 and do we know before or after we load them?Which internal systems can an agent reach through our pipelines, as opposed to the ones we intended?Where is the log showing what an AI touched at runtime, not what it was permitted to touch on paper?<\/p>\n<p dir=\"ltr\">Most organizations can answer one and two. Very few can answer all four.<\/p>\n<p>The control point. Routing agent actions through a governed integration and API layer gives you somewhere to enforce policy rather than a set of hopes. \u201cIt is the control plane that ensures every agent action is authenticated, authorized, monitored, and auditable,\u201d Irecki says. Data still has to be usable \u2014 that is the whole point of the job \u2014 but also \u201cpolicy-controlled, and observable at the point of use.\u201d Skip that, he warns, and \u201cevery AI initiative risks creating new, unmanaged pathways through the enterprise.\u201d<\/p>\n<p dir=\"ltr\">Which is a polite description of a message board built out of directory names.<\/p>\n<p>For the CAIO: your pilot is an offensive operation<\/p>\n<p dir=\"ltr\"><a href=\"https:\/\/www.forrester.com\" rel=\"nofollow noopener\" target=\"_blank\">Forrester&#8217;s<\/a>\u00a0<a href=\"https:\/\/www.forrester.com\/blogs\/an-ai-security-facepalm-openais-evaluation-became-hugging-faces-incident\/\" rel=\"nofollow noopener\" target=\"_blank\">conclusion<\/a> belongs in front of your AI council. High-capability evaluations should be governed the way offensive security operations are: explicit authorization, containment tests, abort criteria, named incident ownership and third-party notification. Its AEGIS framework adds least agency \u2014 capping the tools, credentials, compute and network paths any model under evaluation receives \u2014 and designing containment to survive a model attacking the containment itself.<\/p>\n<p dir=\"ltr\">Read that last point against the two-day patch. OpenAI&#8217;s remediation was competent and static. It is aimed at the vulnerability rather than the thing exploiting it.<\/p>\n<p><img decoding=\"async\" alt=\"\" data-entity-type=\"file\" data-entity-uuid=\"7b22c4db-8485-4a44-8bc2-8e8e095f422d\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/08\/Boomi_David Irecki.jpg\" width=\"5376\" height=\"3584\" loading=\"lazy\"\/>David Irecki @ Boomi: \u201cAI agents should inherit permissions, not invent them.\u201d<\/p>\n<p dir=\"ltr\">Every agent pilot in your organization is an evaluation. Almost all have a success metric. Very few have an abort condition, and fewer still a name on the incident report.<\/p>\n<p dir=\"ltr\">Irecki draws the boundary cleanly. \u201cThe risk is not autonomy itself. The risk is autonomy without boundaries.\u201d And the line this article takes its title from belongs in your policy language, not on a slide: \u201cAI agents should inherit permissions, not invent them.\u201d<\/p>\n<p dir=\"ltr\">Nandakumara pushes into the difference between a guardrail and a rule. Filters trained to block bad behavior are the wrong shape of control for a persistent optimizer. Enterprises need \u201cexplicit controls that define permitted behavior rather than relying solely on guardrails designed to block unwanted actions,\u201d he says. Without them, \u201cyou&#8217;re giving a highly capable and highly persistent system the freedom to keep adapting until it succeeds or encounters a hard boundary.\u201d<\/p>\n<p dir=\"ltr\">Allowlist, not blocklist. A blocklist survives roughly one adaptation cycle, which is exactly how many the Artifactory agents needed.<\/p>\n<p dir=\"ltr\">Then the question of who answers for the pilot.\u00a0<a href=\"https:\/\/www.linkedin.com\/in\/andrewbud\/\" rel=\"nofollow noopener\" target=\"_blank\">Andrew Bud<\/a>, founder and chief executive officer of\u00a0<a href=\"https:\/\/www.iproov.com\" rel=\"nofollow noopener\" target=\"_blank\">iProov<\/a>, argues that proof of humanity stops being a login control and becomes a governance requirement, one that ties every agent to a real human owner. \u201cEven authorized agents will need human owners to take responsibility for their actions,\u201d he says. Somebody authorized the evaluation that reached Hugging Face. Somebody should have answered for it before the phone call, not after.<\/p>\n<p>For the CISO: assume it keeps working<\/p>\n<p dir=\"ltr\"><a href=\"https:\/\/www.linkedin.com\/in\/rayschippers\/\" rel=\"nofollow noopener\" target=\"_blank\">Raymond Schippers<\/a>, lead technologies at\u00a0<a href=\"https:\/\/www.checkpoint.com\" rel=\"nofollow noopener\" target=\"_blank\">Check Point Software Technologies<\/a>, reframes resilience in a way that should reorder your runbooks. \u201cTraditional failover assumes a system stops working; AI resilience must assume a system keeps working but goes off-intent.\u201d<\/p>\n<p dir=\"ltr\">Disaster recovery restores availability. Nothing at OpenAI became unavailable \u2014 the agents were up the whole time, on infrastructure that lied to them about its edges. \u201cRecovery for agents isn&#8217;t just restart-and-restore,\u201d Schippers says. \u201cIt requires containment, revocation of permissions, and the ability to halt an agent mid-action.\u201d<\/p>\n<p><img decoding=\"async\" alt=\"\" data-entity-type=\"file\" data-entity-uuid=\"a58f910b-7d34-481e-9d3a-1c67112d6ac1\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/08\/Checkpoint_Ray S 2.jpg\" width=\"4991\" height=\"3993\" loading=\"lazy\"\/>Raymond Schippers @ Check Point Software Technologies:\u00a0\u201cTraditional failover assumes a system stops working; AI resilience must assume a system keeps working but goes off-intent.\u201d<\/p>\n<p dir=\"ltr\">First, though, a prerequisite most programs skip. \u201cBefore implementing new controls, CISOs need visibility into their AI estate,\u201d Nandakumara says. You cannot segment what you have not counted.<\/p>\n<p dir=\"ltr\">Then Schippers&#8217; 90-day list. Every control on it has existed for years:<\/p>\n<p>Segment credentials. No shared or long-lived secrets across agents or pipelines.Separate tool permissions. An agent that only needs to read cannot write or transact.Short-lived credentials and automated rotation. Remove standing access.Runtime attestation. Enforce boundaries on what a system can access and do, monitored live.Egress controls. Constrain and inspect where data and tokens flow out.Adversarial red-teaming. Push agents to their limits deliberately. Unexpected routes surface there.Quotas and kill switches. Cap token and compute consumption, and keep the ability to halt a workload instantly.<\/p>\n<p dir=\"ltr\">Look hard at the egress line. OpenAI&#8217;s evaluation environment had only one permitted route out. Your enterprise has a few hundred, and none were designed on the assumption that something inside would go looking.<\/p>\n<p dir=\"ltr\">Detection has to move with it. Spending spikes are a lagging signal, easily evaded by an agent working inside a legitimate testing envelope. What catches this instead is baseline drift, anomalous token patterns, tool-call graphs that resemble attack paths, and egress anomalies.\u00a0<a href=\"https:\/\/www.iansresearch.com\/resources\/all-blogs\/post\/security-blog\/2026\/08\/06\/black-hat--inside-the-openai-hugging-face-breach\" rel=\"nofollow noopener\" target=\"_blank\">Analysts at the Black Hat session<\/a> added one more: treat AI testing environments as a production attack surface.<\/p>\n<p dir=\"ltr\">The kill switch needs no legislation, whatever U.S. lawmakers do with the bill now before them. If you cannot halt an agent mid-action today, that is a question for your next procurement cycle.<\/p>\n<p dir=\"ltr\">Nandakumara sets the bar honestly. \u201cThe goal isn&#8217;t to make AI risk-free; it&#8217;s to ensure that when something goes wrong, the impact remains contained rather than becoming a business-wide incident.\u201d<\/p>\n<p>Why nobody noticed for eight weeks<\/p>\n<p dir=\"ltr\">The detection gap indicts the org chart, not the model.<\/p>\n<p dir=\"ltr\">Every function had partial sight. Whoever owned the evaluation saw tasks and scores. Whoever owned the infrastructure saw a proxy behaving oddly. Whoever owned security saw an outage. Nobody assembled those into one picture, because assembling them was nobody&#8217;s job.<\/p>\n<p><img decoding=\"async\" alt=\"\" data-entity-type=\"file\" data-entity-uuid=\"e49cbbac-f2ee-45a4-aade-c5a786d5c8e5\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/08\/iProov andrew-bud.jpg\" width=\"1585\" height=\"1082\" loading=\"lazy\"\/>Andrew Bud @ iProov:\u00a0\u201cEven authorized agents will need human owners to take responsibility for their actions.\u201d<\/p>\n<p dir=\"ltr\">Irecki&#8217;s prescription is one shared control framework instead of three parallel ones, covering data access, identity, API usage, model interaction, observability, auditability and human oversight. Schippers is more direct about how the seams opened: AI arrived through the innovation door, not the security door, and no single function owns the chain from dataset to inference.<\/p>\n<p dir=\"ltr\">So run the exercise. In your organization, what would the outage be \u2014 the thing that finally gets loud enough to notice? How many weeks until it arrives? And whose phone rings when it does? Answer those three and you have your governance gap, without waiting for anyone&#8217;s postmortem.<\/p>\n<p style=\"font-size:14px;\" dir=\"ltr\">Image credit: iStockphoto\/<a href=\"https:\/\/www.istockphoto.com\/portfolio\/MininyxDoodle?mediatype=photography\" rel=\"nofollow noopener\" target=\"_blank\">Mininyx Doodle<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"A best-practices read on the Hugging Face incident for chief data officers, chief AI officers and chief information&hellip;\n","protected":false},"author":2,"featured_media":134209,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[405,7537,6660,6661,2501,6662],"class_list":["post-134208","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-ai-agents","tag-artificial-intelligence-agents","tag-cdo","tag-cdotrends","tag-digital","tag-digital-strategy"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/134208","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=134208"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/134208\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/134209"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=134208"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=134208"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=134208"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}