Agent Security as Its Own Product: One Reading, Held Loosely
OpenAI's news page lists \"Codex Security: now in research preview\" with almost no public detail. The headline cannot settle what the product is, so the...
OpenAI's news page lists \"Codex Security: now in research preview\" with almost no public detail. The headline cannot settle what the product is, so the...
Codex Security entered research preview in March 2026, per the announcement. The capability worth examining is triage, not vulnerability discovery.
A reported 27-second lab breakout, from hijacked browser session to shell, sits outside what wall-based defense was built for. Per-action signed identity...
Evals, provenance, and execution controls are merging into the agent runtime. The advantage is shifting from model quality to who owns the deployment surface.
Agent safety is shifting from a bolt-on audit layer into the runtime itself, and that quietly changes where the competitive moat sits.
For higher-risk agent workflows, pause-resume execution changes the trust model: agents can preserve state, request human approval at the risky step, then...
Three supply chain incidents in six weeks expose a pattern: AI deployment velocity is breaking operational security. The risk isn't rogue superintelligence, it's a compromised pip package.
Evals and security controls are being absorbed into the agent runtime. The moat is no longer model quality, it's control of the deployment surface.
Constitutional MCP isn't a security patch. It's an architectural shift that will fracture the MCP ecosystem in two, and eliminate third-party agent firewall services overnight.