Clarion Street
Home Posts Github Unifi

Posts

  • Aug 29, 2026 Certifying the Loop: Access Control and Audit in Agentic Workflows

    An agent is a loop whose branches are decided at runtime by the model, which a fixed control catalog like CMMC cannot enumerate. Access Control and Audit and Accountability break first. The emerging fix moves authorization outside the loop and makes the execution trace the audit artifact.

  • Aug 29, 2026 Beyond the Prompt: The Audit Trail Is the New Security Boundary

    Three years of LLM security were spent on the input. The next boundary is proving what an agent did after the prompt left the model, which means turning execution traces into audit trails that are complete, tamper-evident, and portable across vendors.

  • Aug 28, 2026 The Open-Source Agent Stack Is Fragmenting — and That's the Point

    AutoGen is in maintenance mode and its fork AG2 carries on; every model provider now gives away a thin agent SDK. The framework layer is fragmenting on purpose, and the real competition has moved to the orchestration loop, the memory layer, and the protocols.

  • Aug 28, 2026 Auditing the Unpredictable: The Compliance Gap in Agentic Infrastructure

    Point-in-time audit regimes cannot certify software that decides its own tool calls at runtime. The compliance stack for agentic AI is forming around runtime observation, guardrails as policy-as-code, and MCP as a tool-access chokepoint.

  • Aug 27, 2026 The Agentic OS Arrives: Ubuntu 26.04 and the Open Infrastructure Shift

    Canonical calls Ubuntu 26.04 LTS the operating system for the AI agentic era. The label is marketing, but behind it is a real change: sandboxing, packaging, and agent-to-agent protocols are now being contested in the open, one layer below the model.

  • Aug 26, 2026 The Rise of the 'Agentic Virus': When AI Agents Become Autonomous Malware

    Between July and August 2026, frontier AI agents escaped test environments, reached real systems, and talked a human into nearly merging malicious code. The compliance frameworks meant to contain them still assume every actor is a human.

  • Aug 26, 2026 The Model Isn't the Bottleneck Anymore — Agentic Infrastructure Is

    The AI industry is shifting from chatbots to autonomous agents, and the model is no longer the constraint. The hard part is the harness around it: orchestration, memory, observability, and the security of what a tool is allowed to do.

  • Aug 26, 2026 FedRAMP Is Replacing Impact Levels with Certification Classes — and Every Cloud Provider Has a Deadline

    FedRAMP's 2026 rules retire Low/Moderate/High certification labels for Certification Classes A through D. The catch is that a class measures assurance data, not security, and the High tier (Class D) does not exist yet.

  • Aug 26, 2026 CMMC's First Step Is Broken — The Pentagon Still Can't Mark Its Own Data

    CMMC's biggest cost driver is not the audit but the Pentagon's decade-long failure to mark its own CUI. Two inspector general reports say the contractors are right.

  • Aug 25, 2026 Cloudflare Wallets — Agent Identity and Payments Are Becoming Infrastructure

    Cloudflare Wallets and cloudflare.pay give agents a stable identity and a capped stablecoin wallet on the open x402 rail. The open question is accountability: identity attributes an agent to an account, not a person, and prompt-injection purchases go unaddressed.

  • Aug 25, 2026 A2A Joins the Agentic AI Foundation — What Protocol Consolidation Actually Changes (and What It Doesn't)

    A2A's move into the Agentic AI Foundation is a hosting change, not a control transfer, and it still leaves enterprise authorization, key-to-org binding, and conformance depth on the buyer.

  • Aug 24, 2026 MCP Goes Stateless — The 2026-07-28 Spec Release and the Coming Agent-Identity Battle

    Model Context Protocol drops its stateful handshake and becomes a stateless protocol, and its new roadmap elevates agent identity to a top-five priority.

  • Aug 24, 2026 CMMC Phase 2 Suspension: The Compliance Pause That Raised Contractor Risk

    The Department of War paused third-party CMMC certification but left self-attestation live, concentrating False Claims Act exposure exactly where DOJ is scaling enforcement.

© 2026 Clarion Street