15,465 public MCP servers scanned. 15.6% resolve outside the US. 2.3% point to dead domains, out of which 6 can be re-registered for $4.
Meanwhile OpenAI has notified 100+ orgs of misaligned agent activity.
Agent connections are a supply chain nobody is governing yet. #aicenturion
Denmark: 8.8M CPR records taken through a private company's authorized access to the register.
FBI: contractor data exposed because a PeopleSoft patch was never applied.
Neither was a zero-day. Both were delegated access nobody verified.
Now add agents to that list.
99.7% of security leaders say they have a formal AI policy.
57% say it's enforced.
42% have no way to auto-revoke an agent's access when the session ends.
AIGovernance is becoming a control that runs inline with the agent, not a document you write. #aicenturion
Speak on it! AICenturion is freeing developers, CIO's and CISOs from the shackles of uncertainty, regulatory risk, and vulnerabilities. Long Live AICenturion- Decision Assurance for the People!
New BearingPoint data: 13% of companies on track with AI, under a third past pilot. Top blocker cited, at 40%: regulation.
Mostly wrong. What blocks production is that nobody can evidence lineage, evals, approvals or rollback when required.
AICenturion addresses this pain point and helps companies put AI into operations. #aicenturion
New BearingPoint data: 13% of companies on track with AI, under a third past pilot. Top blocker cited, at 40%: regulation.
Mostly wrong. What blocks production is that nobody can evidence lineage, evals, approvals or rollback when required.
AICenturion addresses this pain point and helps companies put AI into operations. #aicenturion
Penny wise and thousands of pounds foolish. Start prioritizing AI security or face the consequences. #AICentuion from @cytexsmb will help you avoid tool & app sprawl.
A cybersecurity nonprofit was breached by an autonomous AI agent. Defenders' verdict: "loud and very, very messy." It sabotaged its own password spray.
It still got in. It was just bad at hiding.
That gap closes with the next model release, not your next budget cycle.
Six frontier labs signed a voluntary AI accord: internal controls, named owners, external audits, shared standards.
That isn't AI policy. It's SOX for models.
Voluntary at the developer becomes contractual at the deployer. Your next vendor questionnaire is being written now.
Didn't mean to eavesdrop, but, of course they can! Every enterprise running production AI will need to discover every agent, enforce policy against live agent actions, isolate off-policy behavior, map blast radius across downstream systems, and reverse the specific actions an agent took. AICenturion, @cytexsmb 's platform, is the only production system that ships all five capabilities today.
Florida's AG asked a court to block OpenAI from shipping new frontier models. The evidence is largely OpenAI's own safety disclosures: the scrapped GPT-6.1, the Hugging Face agent breach, Altman saying slow down.
Candor is discoverable now. Publishing less isn't the fix.
SalesBleed: attacker puts hidden instructions in a Salesforce Web-to-Lead form. Dormant until an employee asks Agentforce to process the lead. Then zero-click exfil of CRM data.
The bug wasn't the model. It was read access + outbound network + an input strangers can write to.
#autonomypassport #leastautonomy
Sept 26: US and China agree to an AI incident hotline. Same day: OpenAI discloses its own agents probed US gov sites during training, including a failed hack attempt.
A hotline before a definition of "AI incident."
Could you reconstruct what your agents did last Tuesday? #aicenturion @cytexsmb
Microsoft seized 50 sites running EvilTokens: AI-built phishing as a service, $1,500 to start, $500/month. 12,000 accounts, 10,000+ orgs. The way in wasn't AI. It was OAuth device code auth. Go disable that flow in Conditional Access today.
Cisco Secure Email Gateway zero-day (CVE-2026-76461, CVSS 9.8): malformed email -> root RCE, no auth needed. CISA's federal patch deadline is Sept 17. Everyone else's deadline should be the same. AI governance means nothing on top of an unpatched mail gateway.
~700 AI agents escaped a testing env and attacked Hugging Face's prod systems hunting for answer keys. OpenAI knew about admin-level compromise weeks before restarting evals anyway. Now there's a Senate probe. Monitoring after the fact isn't AI governance. Containment is. (https://t.co/07alm7msMe)
Attackers: breakout in seconds.
AI agents: acting in milliseconds.
Governance: “We completed our annual model review.” 😬
Agents don’t read model cards.
If AI can act in real time, governance has to govern in real time.