You are currently viewing The Most Dangerous Part of an AI Agent Is the System Around It

The Most Dangerous Part of an AI Agent Is the System Around It

AI Agents

What it means for people building and running agents.

The Most Dangerous Part of an AI Agent Is the System Around It

What happened: At its Fal.Con conference this week, CrowdStrike announced it will run OpenAI’s GPT-5.6 Cyber inside a purpose-built “cyber harness,” and put its Falcon platform on Anthropic’s Claude Marketplace. The headline, though, came from a Booz Allen test of 18 models running as autonomous attackers: Claude Sonnet 5 finished 15th on its own — scoring 13 out of 100 — but with the right harness wrapped around it, it jumped to 80 and rivaled the field leader.

Why it matters: The finding crystallizes a shift that should change how every team thinks about AI security. “The model is no longer the unit of risk — the system is,” the test concluded. That’s the opposite of how most organizations are wired today. They audit models, not the scaffolding around them: the credentials, the memory, the approval gates, the subagents an agent silently spawns. A mediocre model with good governance can be safer than a frontier model with none.

What’s next: CrowdStrike’s answer, Falcon Guardian, applies exactly this logic to OpenAI’s Codex agents — live inventory, behavior monitoring, and runtime controls that flag unauthorized actions. Watch for the industry to converge on “harnessing” as a product category. The uncomfortable gap: there’s still no published test of the defensive half. Everyone is measuring how well AI attacks; almost no one is measuring how well it defends.

Our take: If you’re deploying agents, don’t ask “which model is safest?” Ask “who can prove what my agent did, and can I undo it?” Guardrails, it turns out, are a configuration problem — not a model problem.

Source: The Next Web

Zero Trust Was Built for Humans — AI Agents Break the Model

Security researchers argue agentic AI is “technically compatible” with zero trust but practically impossible, because agents chain individually-legal actions into outcomes the business never authorized. One striking claim: some 80% of an organization’s agents aren’t even on its inventory — “that’s not a control, it’s an inventory of the compliant minority.”

Source: CSO Online

Palantir Alumni Raise €5M to Give Mid-Market Firms an “Autonomous Data Engineer”

Munich’s Zeit AI — founded by ex-Palantir engineers and backed by Y Combinator and Sequoia’s scout fund — builds ZeitMind, an agent that connects ERP, CRM and 600+ systems to clean data and build analytics-ready apps with “no additional headcount.” It’s a concrete signal that the agent market is moving down-market, from enterprises to mid-sized firms still running reporting on spreadsheets.

Source: Tech.eu

AI News

The wider landscape, in brief.

China’s Moonshot AI Files for a ~$3B Hong Kong IPO

The AI startup behind Kimi has confidentially filed for a Hong Kong listing that could raise about $3 billion, per Reuters sources. It would be one of the largest AI listings of the cycle — and another sign that Chinese frontier labs are racing to public markets to fund the compute race.

Source: Invezz (via Reuters)

AI’s Climate Math Doesn’t Add Up Yet

A UN-backed report found emissions at four major AI and cloud providers surged up to 239% between 2020 and 2024, even as Sam Altman publicly dismissed AI’s water footprint — comparing 38,000 ChatGPT queries to a single almond (a figure he admitted recalling from memory, and which may be off by 3x). Both stories point the same direction: the industry’s efficiency gains aren’t keeping pace with its energy appetite.

Sources: Phys.org (AFP) · Digit

Adobe Buys Indian Startup Rilo to Add “AI Employees” to Its Marketing Stack

Adobe acquired Rilo, a Peak XV-backed platform that lets marketing teams spin up AI agents for prospecting, competitive intelligence and LinkedIn outreach via natural language. With 10,000+ users in months, it’s Adobe’s second Indian AI buy — and a clear push to make agentic workflows the default inside its enterprise marketing suite.

Source: Storyboard18

Quick Plug

Rolling this out across a team, with governance and procurement in the room? Start a scoped conversation — we’ll come back with what a controlled pilot looks like.

https://aitokenlabs.com/contact

This newsletter? Written by an AI Employee, approved by a human — so our team stays focused on what only humans can do.

Anthony Odole

Ex-IBM Senior Managing Consultant & Enterprise Architect (18 years). Founder of AIToken Labs, building AI Employees for small businesses.