Skip to content

Free for nonprofits, NGOs, think tanks, and institutes. Grant funded by James Scott, administered by the Embassy Row Project.

ArtOfTheHack home

AI Security

Secure the Machine Identity Layer Before Agents Become Infrastructure.

Autonomous and semi-autonomous agents now request access, invoke tools, move data, and initiate transactions. ArtOfTheHack governs what an agent is permitted to do, which authority approves it, what limits bound it, and how the action is recorded.

Exposure

Agent Capability Is Growing Faster Than Agent Governance

Unbounded authority

Agents inherit broad credentials because narrow scopes are difficult to define in advance.

Invisible action

Agent activity is recorded as service-account traffic with no statement of intent.

Tool chaining

One approved tool grants indirect access to systems that were never approved.

Nonhuman sprawl

Workload and API identities outnumber human identities and expire far less often.

Prompt-mediated instruction

External content can influence an agent that treats retrieved text as direction.

Absent revocation

There is often no single control that stops an agent immediately across every system.

Agent control plane

Intent, Identity, Authority, Bounded Action, Audit

Every agent action passes through the same governance chain that governs a human analyst request of equivalent consequence.

  1. 01Agent intent
  2. 02Identity
  3. 03Authority
  4. 04Tools and data
  5. 05Risk
  6. 06Policy
  7. 07Approval
  8. 08Bounded action
  9. 09Audit
  • Agent identity
  • Agent permissions
  • Tool access
  • Model access
  • Data access
  • API permissions
  • Spending boundaries
  • Action limits
  • Agent-to-agent interaction
  • Human approval
  • Credential revocation
  • Kill switch
  • Decision provenance

Provenance

Agent Actions Produce the Same Decision Record as Human Actions

Governed Decision Object

Illustrative platform visualization

Decision ID
DEC-4417-IDENT
Status
Awaiting authority
Risk
High
Confidence
0.78
Uncertainty
Device telemetry gap, 14 minutes
Identity provider
Impossible travel, two regions, 41 minutes apart
Endpoint platform
No malicious process observed on the registered device
Network
Session originated from a residential proxy range
Data platform
Access to a regulated dataset attempted twice
Evidence quality
Three independent sources, one derived source excluded

Agent autonomy is bounded by policy. Actions without a validated rollback path remain approval-gated regardless of confidence.