AI Agent Security and Governance Crisis
Shadow AI, limited usage visibility, excessive tool scope, poisoned or untrusted retrieved data, identity gaps, unverifiable generated code, and unsafe dependency installation continue exposing enforcement gaps. Controls should emphasize bounded authority, auditable approvals, runtime monitoring, and evidence-based governance; Plugin4Shell remains unverified.
Sources (3)
Updated Oct 11, 2026