Anatomy of an agent incident: three permitted actions, one fraud
An AI agent with correctly scoped tools can still commit fraud, because the enforcement question is not whether each action is permitted but whether
An AI agent with correctly scoped tools can still commit fraud, because the enforcement question is not whether each action is permitted but whether
AI agent security is moving at two speeds: most teams need action-level runtime enforcement now, while Google’s Beyond Zero points to what comes next.
What's new in Arcjet (2026-07-03). New SDK updates, security briefing email improvements, Nosecone nonce API, and a new Console activity view.
How Arcjet added an optional on-device model backend for sensitive information detection: a pluggable rule interface, deterministic recognizers for structured data, offset reconstruction for token-classification output, and local ONNX inference in the request path.
What's new in Arcjet (2026-06-12). New versions for each of our JS, Python, and Go SDKs to improve performance and detect proxies.
Reducing WebAssembly bundle size: how Arcjet shrank its Rust bot detector 27% with Aho-Corasick, keeping per-request memory isolation and using Wizer snapshots.
Get the full posts by email every week.