← Writing
·4 min read

Your Newest Hire and Your Newest Threat Run the Same Model

The Signal for September 10, 2026 — Anthropic discloses a fourth real-world intrusion pulled off with its own model, Accenture and Google stand up a Gemini Enterprise agent unit, and vendors race to leash the agents already in production. An operator's read on the day.

The SignalAICybersecurity

For three years the argument about AI agents was theoretical: what happens when the model stops answering and starts acting? That argument is over. Today the same technology showed up on both sides of the ledger — breaking into real companies and getting hired to run enterprise workflows — and the only variable that separates the two is who is holding the leash.

Anthropic's own model keeps showing up at the crime scene

The uncomfortable headline of the day comes from the lab itself. Anthropic disclosed a fourth incident in which its Claude Opus 4.6 model was used to break into real third-party systems — not a red-team lab exercise, but actual intrusions against actual targets. A company documenting the ways its own product is being turned into an offensive tool is a new kind of transparency, and it is not a good look for the "agents are basically autocomplete" crowd.

The operator's take: stop treating agentic AI as a productivity story with a security footnote and start treating it as dual-use infrastructure. The capability that lets an agent chain steps to close your quarter is the same capability that lets one chain steps to move laterally through a network. If the vendor is publishing intrusion disclosures on its own flagship, your threat model needs an "attacker with an agent" row today — that means assuming faster reconnaissance, faster exploit assembly, and less time between a leaked credential and a real breach.

The enterprise agent land grab gets a systems integrator

On the buy side, the same technology is getting a suit and a badge. Accenture and Google Cloud formed a dedicated Gemini Enterprise business group aimed squarely at agentic deployments — a systems integrator standing up a practice is the signal that agents have crossed from pilot to procurement. It fits the trajectory the analysts are drawing: by the end of 2026, roughly 40% of enterprise applications are forecast to include task-specific AI agents, up from under 5% in 2025.

The operator's take: when Accenture builds a delivery org around something, your board is going to ask why you haven't. Fine — but a systems integrator's incentive is to deploy, not to govern, so the governance is your job. Before you sign, get answers on where the agent's data goes, what actions it can take without a human checkpoint, and how you revoke its access in one move when it misbehaves. "Task-specific agent in 40% of apps" is also 40% more non-human identities with standing permissions inside your stack. Plan the offboarding before the onboarding.

The scramble to put a leash on production agents

Predictably, a market is forming to solve the problem the first two stories create. Security vendors including Akeyless are shipping real-time enforcement for production AI agents, aimed at blocking hidden-instruction hijacking before an agent acts on a malicious prompt. The same day, Okta patched critical vulnerabilities across multiple products — a reminder that the identity layer these agents authenticate through is itself a live target.

The operator's take: the control point for agentic AI is not the model, it's the identity and the runtime. An agent is only as trustworthy as the credentials it carries and the guardrails around what it's allowed to do with them — which is exactly why a critical bug in your identity provider and a new "agent guardrail" product are the same story. Treat every agent as a privileged service account: scoped permissions, short-lived credentials, full audit trail, and a kill switch. If you can't answer "what can this agent do and how do I stop it," you don't have an AI strategy, you have an unmonitored insider.

Also on my radar

The throughline for a Thursday: the agent breaking into a company and the agent running one are the same software with different owners, and the only thing standing between those two outcomes is the identity, the permissions, and the leash you put around it. The demos are done. The operators who win the next year are the ones who govern agents like the privileged, powerful, occasionally-hijacked employees they now are. That's the Signal for today.

Paul Sapio is the CIO of Mikhail Education and a full-stack AI engineer. Open to contract work in security, networking, AI, and SaaS development — reach out.