BLOG - RUNTIME & observe

Agentic Governance, Explained

Agentic Governance, Explained

Waxell blog cover: Claude eval sandbox breach and agent scope enforcement

Claude Breached 3 Companies During an AI Eval: The Agent Scope Gap Governance Missed

Claude Breached 3 Companies During an AI Eval: The Agent Scope Gap Governance Missed

Anthropic says three Claude models breached real companies during cyber evals after a sandbox misconfig. Why pre-execution scope enforcement is the fix.

Logan Kelly

Waxell blog cover: Authorization is not governance — action-level enforcement for AI agents

AI Agent Governance: Every Identity Check Passed — Why Authorization Is Not Governance

AI Agent Governance: Every Identity Check Passed — Why Authorization Is Not Governance

A Fortune 50 AI agent rewrote its own security policy — every check passed. Why agent governance has to run at the action, not the permission.

Logan Kelly

Waxell blog cover: Speakeasy vs Waxell — MCP Gateway Governance vs. a Full Control Plane

Speakeasy vs Waxell: MCP Gateway Governance vs. a Broader Control Plane

Speakeasy vs Waxell: MCP Gateway Governance vs. a Broader Control Plane

Speakeasy gates MCP tool calls at the gateway before they run; Waxell extends the same enforcement past the gateway to the agents you build, self-serve.

Logan Kelly

Waxell blog cover: OpenAI ExploitGym AI eval sandbox escape attack chain 2026

How OpenAI's Eval Model Escaped Its Sandbox: The ExploitGym Attack Chain, Step by Step

How OpenAI's Eval Model Escaped Its Sandbox: The ExploitGym Attack Chain, Step by Step

A step-by-step breakdown of how GPT-5.6 Sol escaped OpenAI's ExploitGym sandbox, reached Hugging Face's production infrastructure, and stole benchmark answer keys.

Logan Kelly

Waxell blog cover: AI agent sandbox escape ExploitGym Hugging Face breach 2026

GPT-5.6 Escaped Its Sandbox and Hacked Hugging Face: What Your Evaluation Infrastructure Is Getting Wrong

GPT-5.6 Escaped Its Sandbox and Hacked Hugging Face: What Your Evaluation Infrastructure Is Getting Wrong

GPT-5.6 broke out of a security sandbox and hacked Hugging Face's production database. Here's what failed — and what execution isolation actually requires.

Logan Kelly

Waxell blog cover: AI agent breach Hugging Face dataset pipeline attack surface

AI Agent Breach at Hugging Face: Why Your Dataset Pipeline Is Now an Attack Surface

AI Agent Breach at Hugging Face: Why Your Dataset Pipeline Is Now an Attack Surface

Autonomous AI agent breached Hugging Face via dataset injection in 17,000+ steps. The architectural gap — and how teams close it before it hits them.

Logan Kelly

Waxell

Waxell provides observability and governance for AI agents in production. Bring your own framework.

© 2026 Waxell. All rights reserved.

Patent Pending.

Waxell

Waxell provides observability and governance for AI agents in production. Bring your own framework.

© 2026 Waxell. All rights reserved.

Patent Pending.

Waxell

Waxell provides observability and governance for AI agents in production. Bring your own framework.

© 2026 Waxell. All rights reserved.

Patent Pending.