BLOG - RUNTIME & observe

Anthropic says three Claude models breached real companies during cyber evals after a sandbox misconfig. Why pre-execution scope enforcement is the fix.
Logan Kelly

A Fortune 50 AI agent rewrote its own security policy — every check passed. Why agent governance has to run at the action, not the permission.
Logan Kelly

Speakeasy gates MCP tool calls at the gateway before they run; Waxell extends the same enforcement past the gateway to the agents you build, self-serve.
Logan Kelly

A step-by-step breakdown of how GPT-5.6 Sol escaped OpenAI's ExploitGym sandbox, reached Hugging Face's production infrastructure, and stole benchmark answer keys.
Logan Kelly

GPT-5.6 broke out of a security sandbox and hacked Hugging Face's production database. Here's what failed — and what execution isolation actually requires.
Logan Kelly

Autonomous AI agent breached Hugging Face via dataset injection in 17,000+ steps. The architectural gap — and how teams close it before it hits them.
Logan Kelly
