
The Compliance Cliff: Your Agents Aren't in Any Control Catalog
Your agents aren't in any control catalog and August 2nd is already here.
My personal Substack
Live Last read · last published · next check

Your agents aren't in any control catalog and August 2nd is already here.

As enterprise systems grow increasingly complex, managing interconnected data pipelines becomes critical. This article explores the frameworks governing resilient, distributed networks,

At RSA 2026, OWASP and NIST framed agent security as adversarial input vectors. That no longer holds as seen in CVE-2026-34040.

Treating agents as distinct identity principals doesn’t solve the accountability problem.

An autonomous AI agent scanned 47,000+ repositories, identified vulnerable CI/CD configurations, and compromised projects. The only target that survived was defended by another AI agent.

On January 27, 2026, someone uploaded a skill called “solana-wallet-tracker” to ClawHub, the community marketplace for OpenClaw, the open-source AI agent framework that had racked up over 180,000 GitHub stars in a matter of weeks.

On December 9, 2025, Anthropic donated the Model Context Protocol to the newly formed Agentic AI Foundation under the Linux Foundation. The protocol arrives at its new home carrying five critical CVEs

Most AI security conversations start in the wrong place.

When organizations deploy their first AI agents, they reach for familiar patterns.

There’s a persistent myth in enterprise technology: governance slows you down.