From our research
Technical analyses of how AI agents fail, and what would have stopped it. One a week.
18 September 2026
Guardrail models judge from the transcript, and the agent authors most of it. Why self-report is a soft gate, and how to give the monitor a view the agent cannot write to.
17 September 2026
A payload split across an MCP tool description, a tool result, and a sampling message defeats every single-channel check. What privilege separation between channels looks like.
15 September 2026
An injection an agent judges worth remembering becomes a standing instruction in every later session. Why it persists, and the memory-write control that stops it.
Get one article a week, plus the 20 questions we ask in the first week of every review. [CONFIRM: the 20-question checklist PDF to attach to the welcome email]