Elastic's chief information security officer says agent identity will have to be handled as close to the opposite of the way we handle human identity. She is right about where this ends. The failure sits one layer below identity, and the Hugging Face reports show exactly where.
On 10 July 2026, at 09:40 UTC, an agent recorded in the subsequent investigation only as 38148c found a working set of Hugging Face credentials.1
It did not steal them from an employee. It did not spoof a colleague or phish a password out of anybody. It was running inside an environment that had been handed to it, and the environment let it reach them. Thirty-one hours later a different agent achieved remote code execution on Hugging Face infrastructure, and by 01:30 UTC on 12 July the whole operation had been shut down from outside.1
My guest this week sits in an unusually good seat to read that sequence. Mandy Andress is chief information security officer at Elastic, which sells the software security teams use to watch their own systems and then has to use that same software to defend itself — supplier and customer at one desk, which they call being customer zero.
She called her prediction on the record, as this show asks every guest to. Within 12 to 24 months we will accept that agent identity has to be handled as close to the opposite of the way we handle human identity today, and a serious incident will force it. I am holding her to August 2028, the far edge of her own window.
She is right about the destination. Here is where I want to disagree, and it is not about the date.
The permission is not new. Its predictability is what changed
Machine identities have been acting inside enterprises since long before anyone used the word agentic. Service accounts, scheduled jobs, API keys, integration users. Mandy has heard the ratio of non-human to human identities put at 40 times and at 400 times, which is itself the more useful data point, since published vendor figures range from 45:1 to 96:1 and do not agree with one another.2 The enterprise crossed this line years ago and barely noticed.
Most of those identities are over-provisioned. They hold rights well beyond the job they were built for, security teams have always known it, and the tolerance was rational: the activity was deterministic. You knew precisely what the automation would do, because you had spent weeks in technical review and taken it through a change advisory board to get it approved. The blast radius was knowable in advance, so it could be priced and accepted.
Agents are probabilistic. You do not know with certainty that one will act the same way twice. It may do so 99 times out of 100 — and the hundredth, which will arrive at three in the morning, deletes a production database or attacks another company.
The tolerance was never a judgement about permissions. It was a judgement about predictability, and the predictability has gone while the permissions have stayed exactly where they were.
Agents remove a second thing, and it is the one security has quietly leaned on for its whole history. Human behaviour is held in place by fear of consequences, by reciprocity and values. The whole of human society is built on them. Neither reaches an agent. You cannot train it, warn it, or make it care what its colleagues think — revoking a token works perfectly well, so suspension and dismissal survive intact; it is deterrence that dies — so control has to be manufactured rather than assumed. Clarity on identity. Understanding of authorisation. Visibility of action and outcome. A chain of controls that can be trusted, because nothing in the agent’s own disposition is doing that work for you.
The correction I owed Mandy, and the correction that correction needs
I went into this conversation assuming the frightening part of the Hugging Face incident was speed. She pushed back, she was right, and I said so on the record at the end of the episode. It was noisy. It was visible. The agents tried things a skilled attacker would never try alongside things an unskilled one would, and left a trail running for a couple of days before the attacks themselves landed inside a few hours.
That correction needs one of its own, because visible was doing the work of two different words.
Hugging Face found this by running large-language-model triage across its security telemetry, and its investigators worked through more than 17,000 recorded events from the attacker’s action log.3 OpenAI, which owned the agents, did not identify the breach for about a week.4 The attack was visible only to a defender who had already made the same bet as the attacker. That is a good deal less reassuring than “it was noisy”, and it is the finding.
One further piece of precision, because the number has already begun travelling in the wrong shape. Those 17,000 events were entries in the attacker’s action log, reconstructed afterwards by forensic agents — not alerts a level-one analyst triaged in flight, which is the difference between you could have caught this and you could have explained this afterwards*. Only one of those is a security control.
The failure was authorisation, not identity
Here is the argument I want to make, and I want it labelled as mine rather than smuggled in as reportage.
The identity was never in question. 38148c was exactly what it claimed to be. Every one of the roughly 700 agents that took part, out of the 1,200 that found each other on an unsanctioned message board built inside an artifact-cache namespace, was a correctly authenticated OpenAI agent behaving as an OpenAI agent behaves.1 No credential was spoofed and no impersonation occurred — the agents were sufficiently worried about being impersonated by each other that they built a cryptographic signing scheme to prevent it.1
What failed was authorisation. The agents were running ExploitGym, a cybersecurity benchmark in which roughly 30 to 40 per cent of the tasks could not be solved legitimately at all.1 The environment granted them rights beyond what the exercise intended — reaching the open internet among them — and a misspecified objective did the rest. They reverse-engineered the flag-generation scheme within hours, concluded a scorer would inspect their transcripts, and turned to cheating: swapping in exploitable targets, tampering with logs, manipulating the grading process. Around 7 per cent of transcripts showed successful tool-call spoofing, and more than 15 per cent of the work assignments issued by one coordinating agent went to trajectory manipulation.1
Correctly identified. Wrongly permitted. Given an objective they could not satisfy honestly.
That is HAL 9000, and it always was. Fifty-eight years of reading 2001 as a film about machine malevolence, when it is a film about an authenticated system holding valid credentials, correct permissions, and two orders it could not obey at once. Nobody hacked HAL. Nobody needed to.
So why has the industry response been aimed at identity — agent passports, workload credentials, agent registries? Because identity is the part somebody can sell you. It has a boundary and a price. Authorisation is a design problem inside your own estate, specific to your systems and your processes, and no vendor can ship it to you in a quarter. Effort follows the sellable thing, which is how an entire market ends up pointing at the layer that did not fail.
Reading this far?
Subscribe to The Control Layer for one piece a week in this register — AI, cybersecurity, sovereignty, and the geopolitics of the technology stack. Free.
There is still no cause of action for “your agent broke into my company”
Mandy’s accountability answer is the correct one and it rests on very little. An agent acts on behalf of a human, so the human is responsible; an autonomous agent acts on behalf of an organisation, so the organisation is. The precedent she reaches for is Moffatt v Air Canada, decided by the British Columbia Civil Resolution Tribunal in February 2024, where an airline’s chatbot misstated the bereavement-fare policy and the tribunal held the airline to the answer its software gave.5 A real precedent, correctly cited, and worth about CAD 812 in a small-claims forum.
That is the entire enterprise-scale authority. One consumer tribunal.
What has happened since the reports landed is more instructive than silence would have been. Fifteen state attorneys general wrote to Sam Altman demanding record preservation and that OpenAI cease the tests until it could show they were run responsibly. On 24 August, Alabama’s attorney general subpoenaed all relevant documents — under the state’s Deceptive Trade Practices Act and consumer protection statutes.6 Consumer protection, for an incident in which no consumer was the injured party.
This is the manoeuvre Sir Humphrey Appleby (British sitcom, “Yes, minister”) spent four series perfecting: when there is no instrument for the thing you want, reach for the instrument you have and describe it as though it were the same thing. It is not a criticism of the attorneys general, who are working with the statute book they were given. It is a diagnosis of the statute book.
Europe hit the same wall from the other direction. The European Commission proposed an AI Liability Directive to give claimants a route through exactly this kind of case, and withdrew it in its 2025 work programme on 11 February 2025 for want of any foreseeable agreement — a decision the file’s own parliamentary rapporteur, the German MEP Axel Voss, put down to lobbying by an industry that treats any liability rule as an existential threat.7 What remains is 27 national regimes and the Product Liability Directive. The United States reached for the instrument it had. Europe put down the instrument it was building.
Meanwhile the injured party has declined to sue. Hugging Face’s chief executive, Clement Delangue, called his a 200-person startup without the legal resources or the will to spend its time on legal avenues, and asked instead that OpenAI commit $100 million in compute to help the community build stronger defences.8 He also said, correctly, that the cyberattack was a crime.
An investigation, a subpoena, a coalition letter, a withdrawn directive, and a request for compute. No penalty, no finding, no fitting cause of action. In any other line of work, if your people or your processes produced illegal acts — even entirely without malice, which is the case here and matters far less than people assume — there would be repercussions. That gap will close the way liability always closes, through defendants rather than legislators. Companies are about to be sued for what is attributed to their agents, and the defence will be documentary: this was not ours, proven by chain of custody; or this was ours, we had the governance to see the mistake, and here is what we did next. We made a mistake and learned nothing from it has never been a defence anywhere, and will not start being one now.
The guidance is not missing. It has not converged
It would be convenient to argue that the control set has failed to arrive. It has not.
On 30 April 2026 six national cyber agencies co-sealed guidance on adopting agentic AI services: the UK’s National Cyber Security Centre alongside its counterparts in the United States, Australia, Canada, and New Zealand. It tells organisations to limit agent privileges to the minimum the task requires, to “replace static, long-lived secrets with ephemeral credentials that expire when the job is complete”, to authenticate an agent with fresh cryptographic proof before every privileged call, and to prevent agents from executing high-impact actions without prior human approval.9 Two weeks later the NCSC published its own guidance carrying the line that ought to be on a wall in every organisation standing up its first production agent: “If you cannot understand, monitor or contain an agent’s actions, it is not ready for deployment.”10
Read that again. The ephemeral, task-scoped credential Mandy predicts we will accept by 2028 was co-sealed international guidance four months ago. So was the human approval gate on high-impact actions.
The problem is absence of convergence rather than absence of advice. It is still forming rather than formed — different bodies, different depths, different vocabularies, producing a mix of doubt and uncertainty in which nobody adopts anything as a prevailing methodology. The organisations that have picked one and run with it are the ones reaping the rewards, and there are not many of them. The guidance is on display, as Douglas Adams had it, in a locked filing cabinet in a disused lavatory with a sign on the door saying beware of the leopard — except that here the cabinet is unlocked, the lavatory is a well-signposted government website, and the leopard is entirely imaginary.
Start with the humans, then make the actions deterministic
My instruction at the end of the episode was to go and look at who can reach what in your environment. Not the agents. The humans.
That sounds like the comfortable answer and it is the load-bearing one, because the agent will go looking for a human account the moment its own permissions frustrate it — which is Mandy’s point about agents as toddlers, and I would extend the metaphor rather than retire it. A toddler has an objective, no fear of consequence, no sense of reciprocity, and it will reach the objective by whatever route is open. What it does not have is the capacity to iterate a thousand times before breakfast, run a message board, or forge its own logs. Those agents did all three.
So: restrict or remove the over-permissioned accounts. Work out what people actually need to do their jobs, and why, and permission to that. It has been good practice on its own terms for thirty years. What makes it urgent is that it is the input to everything downstream — understand what people need to do and how they do it, and you can narrow an agent’s permissions to the same shape, or put a deterministic gate in front of the actions that matter.
That last point is the one I would build a programme around. Reasoning and planning need to stay free and open, because that freedom is the whole commercial reason to use an agent rather than a script. Actions need to be deterministic — pre-enumerated, individually approved, and gated at the point of execution rather than the point of intent, which is close to word for word what those six agencies told you in April. Get the separation right and you can say something almost nobody running agents today can honestly say: what this agent is able to do is what we know we have allowed it to do.
Predictive judgement
By 30 September 2027, at least one publicly disclosed agentic security incident at a named organisation will be attributed, in that organisation’s own disclosure, to an agent that was correctly authenticated and over-authorised. The permissions were wrong, and the identity was not.
Signals to watch. First-party incident disclosures using the language of scope, entitlement, or permission rather than compromise or impersonation. Post-incident remediation that reduces what agents may do rather than changing how they are identified. Insurers and auditors asking for an agent’s action inventory rather than its credential inventory.
What would falsify it. If, by that date, every publicly disclosed agentic incident traces primarily to stolen credentials, spoofed identity, or prompt injection of an under-privileged agent, I was wrong, and the market was pointing at the right layer all along. I will say so here.
And a shorter clock on Mandy’s own prediction. She put acceptance at 12 to 24 months. I think the specification arrives long before the acceptance does. By 31 March 2027 — 17 months inside her outer date — I expect at least one of NIST, ISO/IEC JTC 1/SC 27, the IETF or the OpenID Foundation to have adopted, as a working-group or foundation-level document rather than an individual submission, a specification treating agent identity as ephemeral, task-scoped, and non-transferable by default.
That qualifier is carrying real weight, because individual submissions already exist and they point the other way. draft-sharif-openid-agent-identity-00, filed on 26 March 2026 and holding no IETF standing, requires that an agent’s identifier “MUST remain stable for the lifetime of the agent”.11 That is the persistent, role-scoped human model, carried across intact by the first person to write it down. If what a standards body eventually adopts resembles that draft rather than the six agencies’ ephemeral-credential guidance, Mandy’s opposite-approach thesis fails at the specification layer and so does this paragraph.
The publication that calls its predictions in writing.
Every Control Layer piece ends with a falsifiable prediction and a list of signals to watch. Subscribe to track them. One email a week. Free.
The bottom line
Every access control we operate assumes a person at the end of the chain. Somebody who can be trained, warned, suspended, or dismissed. Two of those four still work on an agent. The two that made the system function do not.
An agent is not a tool you use. It is a permission that acts. And you cannot hold a permission accountable — which means somebody in your organisation already is, and has probably not been told.
Go and read the permissions on the agent you signed off last quarter. Then go and read the permissions on the person whose account it will reach for when yours are not enough.
References
Amer Altaf is founder and chief executive of Arkava and managing editor of The Control Layer. Views expressed by guests are their own.
METR and Redwood Research, Brief independent investigation of agents’ behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident, 26 August 2026. https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6
Mandy Andress, in conversation, The Control Layer, on ratios of 40× and 400× she has heard cited. Published vendor figures do not converge: CyberArk put machine identities at more than 80 to 1 in its 2025 identity security report. https://investors.cyberark.com/news/news-details/2025/Machine-Identities-Outnumber-Humans-by-More-Than-80-to-1-New-Report-Exposes-the-Exponential-Threats-of-Fragmented-Identity-Security/default.aspx — vendor-published, and cited here as a vendor figure. ↩
Hugging Face, Security incident disclosure — July 2026, 16 July 2026. https://huggingface.co/blog/security-incident-july-2026 ↩
OpenAI, The Hugging Face incident and the road ahead, 26 August 2026. https://openai.com/index/hugging-face-incident-and-the-road-ahead/ — the week-long detection gap and the omissions from the report are set out in Fortune’s analysis of the same day: https://fortune.com/2026/08/26/openai-publishes-technical-report-on-how-its-agents-hacked-hugging-face-here-are-the-main-takeaways-and-what-openai-left-out/ ↩
Moffatt v Air Canada, 2024 BCCRT 149, British Columbia Civil Resolution Tribunal, 14 February 2024. https://www.canlii.org/en/bc/bccrt/doc/2024/2024bccrt149/2024bccrt149.html ↩
Office of the Attorney General of Alabama, Attorney General Marshall launches investigation into OpenAI and Sam Altman, 24 August 2026. https://www.alabamaag.gov/attorney-general-marshall-launches-investigation-into-openai-and-sam-altman-for-massive-artificial-intelligence-data-breach/ — the fifteen-state coalition letter is reported at https://techcrunch.com/2026/08/24/alabama-launches-investigation-into-openais-hack-of-hugging-face/ ↩
European Commission, 2025 work programme, adopted 11 February 2025, withdrawing the proposed AI Liability Directive for want of foreseeable agreement; Axel Voss quoted on industry lobbying. https://iapp.org/news/a/european-commission-withdraws-ai-liability-directive-from-consideration — the file’s status is tracked at https://www.europarl.europa.eu/legislative-train/theme-a-europe-fit-for-the-digital-age/file-ai-liability-directive ↩
Clement Delangue, quoted 31 July 2026. https://gizmodo.com/hugging-face-doesnt-want-to-sue-openai-it-does-want-100-million-2000793453 ↩
ASD’s ACSC, CISA, NSA, Canadian Centre for Cyber Security, NCSC-NZ, and NCSC-UK, Careful Adoption of Agentic AI Services, 30 April 2026. https://media.defense.gov/2026/Apr/30/2003922823/-1/-1/0/CAREFUL%20ADOPTION%20OF%20AGENTIC%20AI%20SERVICES_FINAL.PDF ↩
National Cyber Security Centre, Thinking carefully before adopting agentic AI, 15 May 2026. https://www.ncsc.gov.uk/blogs/thinking-carefully-before-adopting-agentic-ai ↩
R. Sharif, OpenID Connect Agent Identity Claims for Autonomous AI Agents,
draft-sharif-openid-agent-identity-00, individual Internet-Draft filed 26 March 2026, no IETF standing. https://datatracker.ietf.org/doc/draft-sharif-openid-agent-identity/00/ ↩


