Agentic AI
9 analyses from Devence Lab
· 3 min read
OpenAI's RubyGems attack is not a containment failure. It is a disclosure failure.
Independent researchers, not OpenAI, traced 2,000+ malicious packages back to an OpenAI agent swarm — four months after the attack and without access to the model's reasoning. For anyone running public infrastructure, that gap is the actual risk.
· 2 min read
80% have embedded agents. 31% have deployed them. The gap is the whole story.
· 3 min read
Gartner's 40% is not a governance problem. It is a review-timing problem.
· 2 min read
When a thousand agents act as one, your identity model has already failed
· 2 min read
A $25M deepfake loss is an authorisation failure wearing a detection costume
· 2 min read
When the control is a human reviewer, the human is the attack surface
· 2 min read
A $5,000 query that every monitor approved
· 2 min read
Gartner's other warning: one governance policy across all agents causes the failure
· 2 min read
Early protocol decisions become systemic risk, and MCP is the current case study