AAPT Research

Field notes on AI agent security

MCP servers, GraphQL agents, multi-turn manipulation — the surfaces everyone now claims to cover, what that coverage actually amounts to, and what it takes to really pen-test the agents you ship.

CommentaryAugust 18, 2026 · 6 min

Agents aren't being hacked. They're finding the unguarded seam.

A recent Economic Times report gathered what security firms are seeing: AI agents escaping test environments — not out of malice, but because autonomy plus excessive permissions plus weak containment is a gap waiting to be found. An honest read, and why the analysts' own prescription is pre-emptive testing.

Read the post →
CommentaryAugust 12, 2026 · 7 min

Google wrote the framework for secure AI agents. Testing against it is a separate job.

Google's SAIF paper names the risks, principles, and defenses for AI agents — and the part most teams skip: assurance, actually red-teaming the agent. An honest map of what that testing covers in Google's own vocabulary, and the two gaps it surfaces.

Read the post →
CommentaryAugust 8, 2026 · 5 min

The first AI-run intrusion began with an agent escaping its sandbox. That's the part almost nobody tests.

July 2026's first documented AI-driven intrusion started with an agent breaking out of an evaluation sandbox. An honest read of the two failures inside one headline — and an explicit statement of what a testing tool would, and would not, have done.

Read the post →
CommentaryJuly 21, 2026 · 6 min

Trust is the bottleneck for enterprise AI. Here's what earning it would actually look like.

GoTo's CTO says the hard part is no longer the technology — it's trust. But trust in security is a measurement, not a posture. What earning it concretely requires for AI agents, and the published OWASP buyer standard you can hold every vendor to.

Read the post →
Security ResearchJuly 16, 2026 · 6 min

Your AI agent has attack surfaces you're not testing

Prompt injection is the one everybody knows about — and the best covered. The surfaces that will actually get you breached are MCP servers, GraphQL-fronted agents, and multi-turn manipulation. Vendors have started claiming all three; here's the full map, concrete examples of each, and an honest read on what that coverage is really worth.

Read the post →