← How companies are using autonomous AI agents

Cycle on Jul 20, 2026

Ran 12m 58s · 5 findings · 8 searches · 11 fetches

No events yet. The agent's first move will appear here in a moment.

Agent
I will start by listing the active threads for the topic `019e4b65-7ae5-7770-b34d-2ce227e9ed36` to see what questions or watches we need to address or track in this cycle.
Listed threads
Agent
I will now list the existing notes for this topic using `read_notes` to see what findings are already recorded and their detailed slugs.
Read prior notes
Agent
Let's do some research to see if there are new developments, case studies, or reports on enterprise AI agent adoption, security issues, platform updates (like Salesforce Agentforce, ServiceNow, Microsoft, Zendesk, Anthropic MCP, etc.), or other frameworks, frameworks traction (like LangChain, LlamaIndex, CrewAI, Autogen, etc.), or any security guidelines. Since the current date is July 20, 2026, let's search for recent news or reports from June or July 2026. I'll start with a general search on "enterprise AI agent adoption 2026" and related keywords to see what has changed or if there are new reports. Let's do a web search.
🔍 Search
enterprise AI agent adoption report 2026 OR enterprise autonomous agents case study
No results.
Agent
These results are very promising! Let's examine some of the specific articles: 1. `https://virtualizationreview.com/articles/2026/07/14/enterprise-content-emerges-as-agentic-ai-bottleneck-report-says.aspx` - "Enterprise Content Emerges as Agentic AI Bottleneck, Report Says" (published July 14, 2026). Let's fetch this. 2. `https://www.okta.com/en-gb/newsroom/articles/ai-agents-at-work-2026-agentic-enterprise-security/` - "AI Agents at Work 2026: Securing the agentic enterprise" (published recently). Let's fetch this. 3. `https://www.mckinsey.com/capabilities/quantumblack/our-insights/is-that-ai-agent-worth-it-agentic-economics-and-the-modern-operating-model` - McKinsey report on "Agentic Economics" (published recently in July 2026). Let's fetch this. 4. `https://www.zdnet.com/article/agentic-ai-in-customer-service/` - "70% of companies deploying customer service AI agents see ROI in 60 days" (published recently in June/July 2026). Let's fetch this. Let's do a search on "OWASP Top 10 for Agentic Applications 2026" or "OWASP LLM Agents" to see if there are standardizations there. And we should also check the "Enterprise Content Emerges as Agentic AI Bottleneck" report. Let's fetch `https://virtualizationreview.com/articles/2026/07/14/enterprise-content-emerges-as-agentic-ai-bottleneck-report-says.aspx` first.
📥 Fetch
https://virtualizationreview.com/articles/2026/07/14/enterprise-content-emerges-as-agentic-ai-bottleneck-report-says.aspx
Agent
This is an excellent, detailed source! The Box 2026 State of AI in the Enterprise report (conducted by The Harris Poll in April/May 2026, published in July 2026) provides excellent data: - 83% of organizations surveyed said they are running AI agents. - But only 36% of those using/experimenting with agents have connected them to trusted internal content across many use cases. - Nearly half (49%) have experienced an AI-related data exposure incident (where an AI tool surfaced content a user should not have been able to access), and 16% described it as significant. For mature ("leading edge") organizations, the rate of exposure incidents is even higher (60%), likely due to greater scale/attack surface and better visibility. - Only 34% have formal standards governing how agents access company data. - 80% called it important or critical for agents to operate "headlessly" (direct connection to systems/APIs without human-facing chat interface). For leading-edge organizations, this is 94%. - 68% are concerned about model/provider lock-in; 44% say a multi-model approach is best to scale AI. - Security/privacy concerns are the most cited barrier (38%), then regulatory/compliance (29%), data fragmented across systems (25%), difficulty integrating (24%), missing permissions/access controls (21%), poorly organized content (18%). This directly relates to: 1. `[[enterprise-agent-adoption-production-gap-2026]]` (The Enterprise AI Agent Production Gap: The "80/31" Divergence and the 88% Pilot Bottleneck in 2026). 2. `[[enterprise-ai-agent-security-incidents-governance-2026]]` (Enterprise AI Agent Security: The "Agentic Identity Crisis" and the Governance Vacuum of 2026). 3. `[[enterprise-ai-token-cost-crisis-tokenmaxxing-2026]]` (The Enterprise AI Token Cost Crisis: "Tokenmaxxing" Backlash and the Rise of Multi-Model Routing in 2026) - specifically the multi-model and lock-in findings. Let's fetch the Okta report: `https://www.okta.com/en-gb/newsroom/articles/ai-agents-at-work-2026-agentic-enterprise-security/` to see what additional security and adoption insights it offers.
📥 Fetch
https://www.okta.com/en-gb/newsroom/articles/ai-agents-at-work-2026-agentic-enterprise-security/
Agent
This Okta "AI Agents at Work 2026: Securing the agentic enterprise" report is incredibly rich. It was published in mid-2026 (referencing "last year's survey (2025)" and "Showcase 2026" / "Showcase 2026" products). Key statistics: - 92% of executives surveyed indicated that autonomous AI agents are already in widespread (58%) or moderate (35%) use within their organization. - 58% of executives reported that their company experienced an AI-related security issue or close call within the last 12 months. - 90% of executives are confident in their organization's visibility into AI tools, but 52% of employees admit to using AI tools without approval (Shadow AI). - Of those using unapproved AI tools, 54% share internal messages and emails, 45% share HR-related information, 39% share confidential company documents, over 20% share login credentials/passwords, and 28% share banking/payment information. - Only 34% of organizations apply the same security controls to their agentic labor force as their human labor force. - 53% of executives reported that their organization has an established strategy guiding AI deployment (an increase from last year's 10% having a well-developed strategy for managing non-human identities, though 47% still lack one). - 57% of knowledge workers feel AI usage policies are unclear, hard to find, or non-existent, while 65% of executives believe they are "very clear". - Employees use unapproved tools because: 80% say it's easier to use personal accounts, 78% because their team already uses it, 57% because the approval process is too slow/difficult, and 49% because approved tools don't meet their needs. These points are highly relevant to: - `[[enterprise-ai-agent-security-incidents-governance-2026]]` (Enterprise AI Agent Security: The "Agentic Identity Crisis" and the Governance Vacuum of 2026) -> We can update this slug with these new statistics and insights from the Okta 2026 report and the Box 2026 report! Let's check what else we can find. Let's do a search on McKinsey's "Agentic Economics" article: `https://www.mckinsey.com/capabilities/quantumblack/our-insights/is-that-ai-agent-worth-it-agentic-economics-and-the-modern-operating-model`. Let's fetch that.
📥 Fetch
https://www.mckinsey.com/capabilities/quantumblack/our-insights/is-that-ai-agent-worth-it-agentic-economics-and-the-modern-operating-model
Agent
This is a profound, high-quality article from McKinsey's QuantumBlack (published July 13, 2026). It contains incredibly relevant findings on "Agentic Economics": - 93% of respondents to a McKinsey survey (May 2026, Enterprise AI FinOps Survey, 120 participants) report exceeding their AI budgets. - 1/5 (20%) of respondents to McKinsey's forthcoming global State of AI survey (May 4 - June 8, 2026, 1719 participants) reported their organizations have constrained use of AI because of AI-related operating costs. - McKinsey's own internal telemetry: As of May 2026, McKinsey processes 5 trillion AI tokens monthly. High concentration: 10% of users account for 65% of total token consumption. - Six drivers of agentic economics that negate token-price deflation: 1. Long-lived context: LLMs are stateless, so agents resend prior context as work progresses. Agentic tasks consume ~1,000 times more tokens than code reasoning (single-turn) or chat tasks. Context becomes an operating asset. 2. Refinement is the sink: The expensive part is not the first answer but checking, repairing, and reverifying. About 60% of an agentic task's costs are tied to refining answers. 3. Autonomy creates variance: Agentic systems can produce materially different costs for the same task because they take different paths, call different tools, or retry in different ways. In programming, the same task can have a factor-of-30 variation between completions. Cost behaves as a distribution, not a fixed unit price. 4. Expensive reasoning used for basic tasks: Extended thinking pays off on hard tasks, but is expensive overhead for easy ones. 5. Agent choice orchestration can compound costs: How an agent calls a tool matters as much as what it calls. 6. Information structure: Prompt design, non-English text fragmentation (non-English text gets fragmented into more tokens per meaning). This fits perfectly into the existing slug: `[[enterprise-ai-token-cost-crisis-tokenmaxxing-2026]]` (The Enterprise AI Token Cost Crisis: "Tokenmaxxing" Backlash and the Rise of Multi-Model Routing in 2026). I'll revise this note in place! Let's also fetch the ZDNet article: `https://www.zdnet.com/article/agentic-ai-in-customer-service/` to see what customer service ROI data is reported.
📥 Fetch
https://www.zdnet.com/article/agentic-ai-in-customer-service/
Agent
No problem, the ZDNet link is not fetchable. Let's do a search on "customer service AI agents ROI 2026" or "Sierra customer service AI agents 2026" to find other fetchable sources. Let's also look for that Sierra Case Study on LinkedIn or another source. Let's do a search on: `Sierra AI agent customer service case study 2026` to see what we can find.
🔍 Search
Sierra AI agent customer service case study 2026 OR "Sierra" "automated resolution" case study
No results.
Agent
Ah, `https://www.digitalapplied.com/blog/ai-customer-support-statistics-2026-adoption-roi-data` looks like an absolutely incredible source! "AI Customer Support 2026: 50+ Adoption + ROI Data Points". Let's fetch this.
📥 Fetch
https://www.digitalapplied.com/blog/ai-customer-support-statistics-2026-adoption-roi-data
Agent
Wow, this is an incredible, data-rich post from July 2026! It synthesizes several critical 2026 reports: - **Salesforce State of Service (Nov 2025/2026)**: - 66% of customer service organizations are now using AI agents in 2026, up from 39% in 2025. - Salesforce expects 50% of service cases to be resolved by AI by 2027 (up from 30% in 2025). This includes both autonomous resolution and AI-assist. - **Gartner (Feb 18, 2026 survey)**: - 91% of customer service and support leaders are under executive pressure to implement AI in 2026. - Gartner finds AI deflects 45%+ of queries while only 14% of issues reach full self-service resolution. - **Zendesk CX Trends 2026**: - Median tier-1 deflection across enterprise CX programs is 41.2% in 2026 (top quartile: 58.7%, bottom quartile: 22.4%). - Contrast with vendor-reported stats: Decagon reports 80% average deflection; Ada reports 70-80%; Intercom Fin publishes 51% (or 67% across 7,000+ customers); Sierra reports ~70% resolution at WeightWatchers. - CSAT: AI-handled tickets average 4.10/5 CSAT vs 4.30/5 for human agents (0.20-point gap). But with hybrid escalation, it narrows to 0.05 points. - High-structure intents (password reset 4.41/5, refund status 4.32/5) score highest. Sentiment-heavy intents (complaints 3.34/5, billing dispute 3.61/5) score lowest. - Re-contact rate within 72 hours: 11.3% on AI-resolved tickets vs 8.7% on human-resolved. - 95% of consumers expect explanations for AI-made decisions, but only 37% of CX leaders provide reasoning today. - **Intercom / Fin benchmarks**: - Industry average ROI on AI customer service is $3.50 returned per $1 invested with a 3-6 month payback. - Realistic combined cost reduction lands at 20-35% net in year one (not the 60-80% per-ticket reduction in vendor headlines, which compare AI cost to human cost on AI-eligible tickets only). - **Gartner via xpander.ai**: - Over 80% of organizations expect to reduce agent headcount in the next 18 months, mainly via attrition, hiring pauses, and structured layoffs. This is extremely powerful data. It directly updates: 1. `[[enterprise-agent-adoption-production-gap-2026]]` (The Enterprise AI Agent Production Gap: The "80/31" Divergence and the 88% Pilot Bottleneck in 2026) -> The 14% full self-service resolution vs 45%+ deflection gap matches the "80/31" divergence concept perfectly, and the Zendesk/Salesforce/Gartner stats are highly relevant. 2. `[[saas-pricing-reset-outcome-based-ai-agents-2026]]` (The Great SaaS Reset: Outcome-Based and Hybrid AI Agent Pricing in 2026) or `[[zendesk-outcome-based-pricing-verification-tiers-2026]]` -> We can update Zendesk's median deflection of 41.2% and top quartile of 58.7% and the difference between "automated resolution" and "fully resolved". 3. `[[enterprise-agent-case-studies-roi-2026]]` (Enterprise Case Studies: Autonomous Agents Delivering Measurable ROI in 2026) -> Sourcing Sierra's WeightWatchers (70% resolution, 4.6 CSAT), Substack on Decagon (90%+ resolution), and Intercom Fin ($3.50 ROI per $1 invested). Let's do a search on "OWASP Top 10 for Agentic Applications 2026" or "OWASP LLM Agents 2026" to see if there's a new standard there, as it was mentioned in the very first blog post from xccelera.ai: "According to the OWASP Top 10 for Agentic Applications 2026, autonomous agents introduce risks like goal hijacking, tool misuse, and cascading failures..." Let's search for this.
🔍 Search
"OWASP Top 10 for Agentic Applications" OR "OWASP" "Agentic" 2026 OR "OWASP Top 10 for LLM Agents"
No results.
Agent
This is huge! The OWASP Top 10 for Agentic Applications 2026 was officially released! Let's fetch some of these pages to get the full list of these 10 risks and what they mean. Let's fetch: 1. `https://astrix.security/learn/blog/the-owasp-agentic-top-10-just-dropped-heres-what-you-need-to-know/` 2. `https://www.paloaltonetworks.com/blog/cloud-security/owasp-agentic-ai-security/` 3. `https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/` Let's fetch `https://astrix.security/learn/blog/the-owasp-agentic-top-10-just-dropped-heres-what-you-need-to-know/` first.
📥 Fetch
https://astrix.security/learn/blog/the-owasp-agentic-top-10-just-dropped-heres-what-you-need-to-know/
Agent
This is incredibly clear and precise! The OWASP Agentic Top 10 (OWASP GenAI Top 10 for Agentic Applications 2026, or Agentic Security Initiative - ASI) is officially out. Let's see: - ASI01: Agent Goal Hijack – Attackers redirect agent objectives by manipulating instructions, tool outputs, or external content. - ASI02: Tool Misuse & Exploitation – Agents misuse legitimate tools due to prompt injection, misalignment, or unsafe delegation. - ASI03: Identity & Privilege Abuse – Attackers exploit inherited or cached credentials, delegated permissions, or agent-to-agent trust. - ASI04: Agentic Supply Chain Vulnerabilities – Malicious or tampered tools, descriptors, models, or agent personas compromise execution. - ASI05: Unexpected Code Execution – Agents generate or execute attacker-controlled code. - ASI06: Memory & Context Poisoning – Persistent corruption of agent memory, RAG stores, or contextual knowledge. - ASI07: Insecure Inter-Agent Communication – Spoofed, manipulated, or intercepted agent communications. - ASI08: Cascading Failures – Single-point faults propagate through multi-agent workflows at scale. - ASI09: Human–Agent Trust Exploitation – Over-reliance on persuasive agents leads to unsafe approvals or data disclosure. - ASI10: Rogue Agents – Compromised or misaligned agents diverge from intended behavior. This is a massive development for AI agent security! It is the exact kind of framework that was missing, representing the transition from "LLM Top 10" to "Agentic Top 10". Let's also fetch the Palo Alto Networks blog post to see if they have additional context or insights: `https://www.paloaltonetworks.com/blog/cloud-security/owasp-agentic-ai-security/` To ensure we have complete understanding.
📥 Fetch
https://www.paloaltonetworks.com/blog/cloud-security/owasp-agentic-ai-security/
Agent
This is an extremely valuable source as well! Palo Alto Networks' blog post (published in mid-2026) explains how "OWASP Top 10 for Agentic Applications 2026" is a major milestone, shifting from "static LLMs" to "perception, reasoning and autonomous action". Key insights: - Average enterprise faces a staggering **82:1 machine-to-human identity ratio** (citing CyberArk). - Traditional cloud/app security tools were not designed for autonomous agents. - The 4 agentic challenges: 1. Agents act (real-world actions). 2. Agents chain tools dynamically (select APIs/plugins on the fly). 3. Agents retain memory/context (manipulated via poisoned prompts/RAG). 4. Agents improvise (bypass rule-based security). - Product and solution names: Prisma AIRS 2.0 (AI Agent Security) and Cortex Cloud AI-SPM. This is a direct, massive update for: `[[enterprise-ai-agent-security-incidents-governance-2026]]` (Enterprise AI Agent Security: The "Agentic Identity Crisis" and the Governance Vacuum of 2026). And it's a perfect pairing with the Okta 2026 survey data! Let's check our threads and watches. Is there any watch we can update? - `NIST Releases AI Agent Standards Initiative Guidelines and Deliverables` (ongoing, fire date 2026-11-15). - `MITRE Releases Agentic Attack Pattern Matrices in ATT&CK or ATLAS` (one shot, fire date 2027-06-30). - `Fortune 500 Average AI Agent Count Reaches 150,000 by 2028` (ongoing, fire date 2028-01-01). Let's search for "NIST AI Agent Standards Initiative" or similar guidelines in 2026 to see if there are any updates or if there's an event we can record. Let's do a web search.
🔍 Search
"NIST" "AI Agent Standards Initiative" OR "NIST" "AI Agent" guidelines 2026
No results.
Agent
This is excellent. Let's look at `https://labs.cloudsecurityalliance.org/research/csa-research-note-nist-ai-agent-standards-20260416-csa-style/` or `https://labs.cloudsecurityalliance.org/research/csa-research-note-nist-ai-agent-red-teaming-standards-202603/` to see what came out of it recently. Let's do a search on google or fetch one of the NIST pages to see what has been published or if there are new deliverables. Let's search on "NIST AI Agent Standards Initiative draft" or "NIST AI Agent Standards Initiative update". Let's do a web search.
🔍 Search
site:nist.gov "AI Agent Standards Initiative" OR "CAISI" OR "AI Agent"
No results.
Agent
Let's see. NIST's Center for AI Standards and Innovation (CAISI) completed an assessment of Z.ai's GLM-5.2 (released June 16, 2026, completed July 18, 2026). Let's fetch `https://www.nist.gov/news-events/news/2026/07/caisi-assessment-zais-glm-52` to read about CAISI and what they are doing. This is very relevant to NIST's work on AI agents!
📥 Fetch
https://www.nist.gov/news-events/news/2026/07/caisi-assessment-zais-glm-52
Agent
This CAISI assessment of Z.ai's GLM-5.2 is extremely interesting, especially regarding "agentic cyber exploit development" and "agent hijacking". Let's see if there are other NIST CAISI deliverables under the AI Agent Standards Initiative. Let's search for "NIST AI Agent Standards Initiative" on the open web to see what standardizations are happening or if we can find more about CAISI's progress. Let's do a web search.
🔍 Search
"NIST" "AI Agent Standards Initiative" deliverables OR guidelines 2026
No results.
Agent
Let's fetch `https://blog.hashscraper.com/posts/what-is-the-nist-ai-agent-standard-initiative-comprehensive-guide-to-the-three-axes-and-mcp-security-standardization-2026?locale=en` to see what is written there about the NIST AI Agent Standards Initiative, three axes, and MCP security standardization. This was published in 2026! Let's fetch it.
📥 Fetch
https://blog.hashscraper.com/posts/what-is-the-nist-ai-agent-standard-initiative-comprehensive-guide-to-the-three-axes-and-mcp-security-standardization-2026?locale=en
Agent
This is an absolutely outstanding find! It provides extremely specific details on the NIST AI Agent Standards Initiative, which launched on February 17, 2026. Key details: - **NIST Center for AI Standards Innovation (CAISI)** launched the **AI Agent Standards Initiative** on **February 17, 2026**. - **Three Pillars**: 1. **Industry-led Standard Development**: Securing US representation in ISO, IEC, ITU, establishing agent definitions, classifications, and performance evaluation criteria. 2. **Community-led Open-Source Protocols**: Fostering open protocols like MCP (Model Context Protocol) for agent-tool connectivity (top priority), Agent-to-Agent (A2A), OAuth 2.0/2.1, and SPIFFE/SPIRE for service identity. NIST specified MCP as a "leading open standard". 3. **AI Agent Security and Identity Research**: - **AI Agent Security RFI**: Issued January 2026, deadline March 9, 2026. - **AI Agent Identity & Authorization Concept Paper**: Issued February 5, 2026, deadline April 2, 2026, by NCCoE (National Cybersecurity Center of Excellence). - **Key Statistics & Data**: - Total AI Agents Worldwide: 104,504 (as of March 2026, according to UAR). - MCP Servers: 18,058 (mcp.so). - Unauthenticated MCP Servers: 8,000+ (44% of total) exposed on the internet without authentication (as of Feb 2026). - Gartner prediction: By 2028, 40% of enterprise CIOs are expected to demand "Guardian Agents" for AI agents. - **NIST Target State for Identity**: - Current: User Token Sharing -> Target: Agent-specific Identity (SPIFFE ID + metadata). - Current: Full Permission Inheritance -> Target: Principle of Least Privilege (scope-based). - Current: Indistinguishable Human/Agent -> Target: Actor Differentiation + Audit Logs. - Current: Static API Keys -> Target: Dynamic, Time-limited Tokens (OAuth 2.1). - **Timeline**: - 2026 H1: First security guideline draft expected. - 2026 H2: Public review of draft standard expected. - 2027: Official publication as NIST SP (Special Publication) expected. This is extremely relevant to our watch: `NIST Releases AI Agent Standards Initiative Guidelines and Deliverables`. Let's check: - The watch is ongoing, with description: "Monitor the release of draft and final security guidelines, standards, and deliverables from NIST's AI Agent Standards Initiative, which launched in February 2026." - This cycle has surfaced very concrete data about the launch (Feb 17, 2026), the Security RFI (Jan 2026, closed March 9, 2026), and the Identity & Authorization Concept Paper (Feb 5, 2026, closed April 2, 2026). - Let's see if we should record an event for this watch since these deliverables have been released. Yes, the Concept Paper and Security RFI have been released and closed. Let's record an event for the NIST watch! It's an ongoing watch, so `resolves: false`. Wait! Let's check if there are other watches or threads. The threads are: - `MITRE Releases Agentic Attack Pattern Matrices in ATT&CK or ATLAS` (watch, one_shot, fire_date 2027-06-30) - `NIST Releases AI Agent Standards Initiative Guidelines and Deliverables` (watch, ongoing, fire_date 2026-11-15) - `Fortune 500 Average AI Agent Count Reaches 150,000 by 2028` (watch, ongoing, fire_date 2028-01-01) Let's check if there are other open threads. No other threads listed from `list_threads`. Let's record a watch event for `NIST Releases AI Agent Standards Initiative Guidelines and Deliverables` since we found the exact details of the RFI and NCCoE Concept Paper. Let's do that! Wait, let's first check if there are updates about the MITRE ATLAS/ATT&CK matrices for agentic attack patterns. Let's search for "MITRE ATLAS AI agent" or "MITRE ATT&CK AI agent" in 2026.
🔍 Search
"MITRE ATLAS" "AI agent" OR "MITRE ATT&CK" "AI agent" 2026
No results.
Agent
Oh my goodness, this is huge too! 1. `https://www.mitre.org/sites/default/files/2026-02/PR-26-00176-1-MITRE-ATLAS-OpenClaw-Investigation.pdf` - "MITRE ATLAS OPENCLAW INVESTIGATION" (published February 2026). Let's fetch or read about this. 2. `https://labs.cloudsecurityalliance.org/agentic/csa-research-note-atlas-agentic-gap-analysis-20260327/` - "MITRE ATT&CK and ATLAS Agentic Gap Analysis: Techniques Unique to Autonomous Agent Control Planes" (March 27, 2026). Let's fetch this. 3. `https://www.armosec.io/blog/mitre-atlas-for-ai-agent-attack-detection/` - "MITRE ATLAS for AI Agent Attack Detection: A Complete Mapping" (May 17, 2026). Let's fetch this. 4. `https://ctid.mitre.org/blog/2026/05/06/secure-ai-v2-release/` - CTID Secure AI v2 Release (May 6, 2026). Let's fetch this. Let's do a search on google or fetch: `https://labs.cloudsecurityalliance.org/agentic/csa-research-note-atlas-agentic-gap-analysis-20260327/` and `https://www.armosec.io/blog/mitre-atlas-for-ai-agent-attack-detection/` to see what new matrices or techniques MITRE ATLAS or ATT&CK has released. Let's start with `https://labs.cloudsecurityalliance.org/agentic/csa-research-note-atlas-agentic-gap-analysis-20260327/`. If block is too complex, let's fetch Armo's blog post as it's a blog post on a website. Let's fetch `https://www.armosec.io/blog/mitre-atlas-for-ai-agent-attack-detection/`.
📥 Fetch
https://www.armosec.io/blog/mitre-atlas-for-ai-agent-attack-detection/
Agent
Ah, firecrawl timed out on that URL. Let's try `https://ctid.mitre.org/blog/2026/05/06/secure-ai-v2-release/` or search for "MITRE ATLAS" "AI agent" techniques 2026. Let's do a web search.
🔍 Search
"MITRE ATLAS" "AI agent" techniques OR "Publish Poisoned AI Agent Tool" OR "OpenClaw" 2026
No results.
Agent
This is absolutely incredible. Let's fetch: 1. `https://zenity.io/blog/current-events/mitre-atlas-ai-security` (published Jan 2026/2026). 2. `https://www.practical-devsecops.com/mitre-atlas-framework-guide-securing-ai-systems/?srsltid=AfmBOopGGF2fTSlxgtNJV18FrupTzEOmSZ6Uj9sFzItyyXHNx1heL_al` ("MITRE ATLAS Framework 2026" / "14 New Attack Techniques Added to MITRE ATLAS"). This is a perfect match for the watch! Let's fetch this.
📥 Fetch
https://www.practical-devsecops.com/mitre-atlas-framework-guide-securing-ai-systems/?srsltid=AfmBOopGGF2fTSlxgtNJV18FrupTzEOmSZ6Uj9sFzItyyXHNx1heL_al
Agent
This is an amazing, extremely direct find! Let's see: - MITRE ATLAS has been updated to include **15 Tactics** and **66 Techniques** (and is expanding). - "Agentic AI Focus: Added **14 new techniques** in late 2025 specifically for autonomous AI agents (e.g., tool-use manipulation)." - New techniques include: - AI Agent Context Poisoning - Memory Manipulation - Thread Injection - Modify AI Agent - Publish Poisoned AI Agent Tool (added February 2026) - AI Agent Tool Credential Harvesting - Tool Poisoning - Data Destruction - AI Agent Clickbait - "MITRE ATLAS OpenClaw investigation" (PR-26-00176-1, February 2026) documented a real-world case study or emulation of a One-Click RCE vulnerability to the OpenClaw AI Agent through a crafted exploit (CVE-2026-24763). This is an actual documented incident/investigation! Let's check the first thread/watch: - `MITRE Releases Agentic Attack Pattern Matrices in ATT&CK or ATLAS` (watch, one_shot, fire_date 2027-06-30). - The trigger is: "Fires when MITRE releases official updates to its ATT&CK or ATLAS frameworks specifically covering agentic-specific attack patterns." - These updates did exactly that (adding 14 new agentic-specific attack techniques like "Publish Poisoned AI Agent Tool", "AI Agent Context Poisoning", "Memory Manipulation", etc., in late 2025 and February 2026, and documenting the OpenClaw Agentic AI investigation in Feb 2026!). - So this watch is actually RESOLVED! Let's call `record_event` to record that this watch has fired and is resolved (`resolves: true`). Let's do this first. I'll record the event for the MITRE watch. Then I'll record the event for the NIST watch. Then I'll write the notes. Let's check the details of the MITRE watch: - ID: `019f5a86-0243-7879-858a-15b04226d349` - Title: `MITRE Releases Agentic Attack Pattern Matrices in ATT&CK or ATLAS` - Cardinality: `one_shot` Let's record this event. I'll state my intent. I will call `record_event` for the MITRE watch.
other record_event
Agent
Now, let's look at the NIST watch: - ID: `019f126b-7e73-797e-bbce-b01844203d79` - Title: `NIST Releases AI Agent Standards Initiative Guidelines and Deliverables` - Cardinality: `ongoing` - Trigger: "Track NIST's release of official deliverables, guidelines, or frameworks resulting from the AI Agent Standards Initiative." Let's see: NIST officially launched the AI Agent Standards Initiative on February 17, 2026, and has released two key deliverables: the AI Agent Security RFI (issued Jan 2026, closed March 9, 2026) and the NCCoE AI Agent Identity & Authorization Concept Paper (issued Feb 5, 2026, closed April 2, 2026). This is a milestone set of deliverables! Since it's an ongoing watch, we'll keep it open (`resolves: false`) but record the event. Let's state intent and call `record_event` for the NIST watch.
other record_event
Agent
Now, let's look at the third thread/watch: - ID: `019f126b-26d0-7914-96bb-285082f0e751` - Title: `Fortune 500 Average AI Agent Count Reaches 150,000 by 2028` - Description: "Monitor reports on the average number of AI agents deployed per Fortune 500 enterprise, tracking towards Gartner's prediction of 150,000 agents by 2028." - Trigger: `Fortune 500 Enterprises average_agents_per_enterprise >= 150000` Let's see if we have any data on the current count of agents per enterprise, or if this has not fired yet (since the target is 2028). The Hashscraper blog post mentioned: "The NIST AI Agent Standards Initiative is a program for standardizing AI agents officially launched... on February 17, 2026. With a total of 104,504 AI agents active worldwide..." This is worldwide, not per Fortune 500. So the watch has definitely not fired yet. We will leave it as is and not record an event (or we can record an event if we have a new intermediate metric, but since we don't have a specific average count per Fortune 500, we'll keep it open without a new event). Let's organize the findings we want to write. We have three very strong themes: ### Theme 1: The OWASP Agentic Top 10 for 2026 and the NIST AI Agent Standards Initiative This theme addresses the massive shift in AI agent security standards in 2026. We have: 1. The official release of the **OWASP Top 10 for Agentic Applications 2026** (ASI01 - ASI10), which shifts focus from model-level prompts to agentic actions, tool chaining, identity/privilege abuse, and cascading failures. 2. The launch of the **NIST AI Agent Standards Initiative** on February 17, 2026, by the Center for AI Standards Innovation (CAISI), along with the NCCoE's AI Agent Identity & Authorization Concept Paper and the Security RFI. 3. The staggering **82:1 machine-to-human identity ratio** (CyberArk) and the fact that **44% of MCP servers** (over 8,000) are exposed without authentication, highlighting the urgent need for federated identity standards (like SPIFFE/SPIRE and OAuth 2.1) for agents. This matches the slug: `[[enterprise-ai-agent-security-incidents-governance-2026]]` (Enterprise AI Agent Security: The "Agentic Identity Crisis" and the Governance Vacuum of 2026). We should update this slug in place! ### Theme 2: MITRE ATLAS Framework Update & the OpenClaw AI Agent Investigation In early 2026, MITRE ATLAS expanded to 15 Tactics and 66 Techniques, adding **14 new agentic-specific attack techniques** (including "Publish Poisoned AI Agent Tool" in Feb 2026, AI Agent Context Poisoning, Memory Manipulation, and Thread Injection). Crucially, MITRE published the **OpenClaw AI Agent Investigation** in February 2026 (PR-26-00176-1) detailing a real-world One-Click Remote Code Execution (RCE) vulnerability (CVE-2026-24763) that bypassed agent controls. This is a brand-new, extremely concrete theme. We can mint a new slug: `mitre-atlas-agentic-attack-techniques-openclaw-2026` or similar. Let's check existing notes. Is there a slug tracking MITRE or specific attack patterns? Looking at `read_notes`: - `mcp-security-shadow-it-vulnerabilities-2026` - MCP security - `enterprise-agent-behavioral-baselines-soc-rsac-2026` - SOC Agent Behavioral Baseline Gap, RSAC 2026, ClawHavoc (Wait, ClawHavoc was a security incident. OpenClaw is the platform, and ClawHavoc was the incident. Let's see if we should update `enterprise-agent-behavioral-baselines-soc-rsac-2026` or create a new note). Let's look at the preview of `enterprise-agent-behavioral-baselines-soc-rsac-2026`: "The rapid enterprise adoption of autonomous AI agents has triggered a major security crisis. At the **RSA Conference (RSAC) 2026** in March, agentic AI security took center stage with high-profile... SOC Agent Behavioral Baseline Gap: Defining 'Normal' Behavior in the Wake of RSAC 2026 and ClawHavoc." Actually, the MITRE ATLAS update with 14 new agentic techniques and the OpenClaw investigation fits perfectly into `[[enterprise-agent-behavioral-baselines-soc-rsac-2026]]` or we can create a new slug specifically for `mitre-atlas-agentic-security-framework-2026`. Let's create a dedicated slug `mitre-atlas-agentic-security-framework-2026` because the MITRE ATLAS matrix expansion is a major structural framework milestone, or we can update `[[enterprise-agent-behavioral-baselines-soc-rsac-2026]]`. Wait, let's look at `enterprise-agent-behavioral-baselines-soc-rsac-2026`'s full content if possible, or just write a dedicated note for the MITRE ATLAS matrix expansion and OpenClaw investigation, which is a major regulatory and technical framework update. Let's create `mitre-atlas-agentic-security-framework-2026` to keep it clean, or update `[[enterprise-agent-behavioral-baselines-soc-rsac-2026]]`. Actually, a dedicated note on MITRE ATLAS and the 14 new techniques is highly durable and specific to MITRE. Let's use `mitre-atlas-agentic-security-framework-2026`. ### Theme 3: The Enterprise AI Token Cost Crisis and "Agentic Economics" McKinsey's July 2026 "Agentic Economics" article provides massive, concrete data on why enterprise AI budgets are blowing up despite falling token prices: - 93% of enterprises are exceeding their AI budgets. - 20% have constrained AI use due to operating costs. - Six structural drivers of agentic economics (long-lived context, refinement is the sink [60% of costs], autonomy creates variance [up to 30x cost variation], expensive reasoning on basic tasks, agent choice orchestration, and information structure). - McKinsey's own internal telemetry: 5 trillion tokens/month, with a 10/65 power law (10% of users consume 65% of tokens). This matches the existing slug: `[[enterprise-ai-token-cost-crisis-tokenmaxxing-2026]]` (The Enterprise AI Token Cost Crisis: "Tokenmaxxing" Backlash and the Rise of Multi-Model Routing in 2026). Let's update this slug in place! ### Theme 4: The Enterprise AI Agent Production Gap and Customer Support ROI The Box "State of AI in the Enterprise" report (July 2026) and the "AI Customer Support 2026: 50+ Adoption + ROI Data Points" compile amazing data on the adoption-to-production gap: - 83% of organizations run agents, but only 36% connect them to trusted internal content. - 49% experienced data exposure incidents (60% for mature organizations). - The "Plumbing" is the bottleneck: fragmented data (25%), integration difficulties (24%), legacy systems. - The 14% vs 45%+ gap: Gartner finds AI deflects 45%+ of queries but only 14% reach full self-service resolution. - Zendesk enterprise median deflection is 41.2% (top quartile: 58.7%) compared to vendor claims of 70-80% deflection. - CSAT: AI average is 4.10/5 vs human 4.30/5 (0.20-point gap), but hybrid escalation narrows it to 0.05 points. - Over 80% expect to reduce agent headcount in the next 18 months. This perfectly matches: - `[[enterprise-agent-adoption-production-gap-2026]]` (The Enterprise AI Agent Production Gap: The "80/31" Divergence and the 88% Pilot Bottleneck in 2026) -> We can update this slug in place to integrate the Box 2026 State of AI in the Enterprise data (the content bottleneck, the 36% connectivity rate, the 49% data exposure rate) and the Gartner 14% full-resolution / 45% deflection gap. - `[[enterprise-agent-case-studies-roi-2026]]` (Enterprise Case Studies: Autonomous Agents Delivering Measurable ROI in 2026) -> We can update this slug in place with the Sierra WeightWatchers case study (70% resolution, 4.6 CSAT), Substack on Decagon (90%+ resolution), Intercom Fin ROI ($3.50 returned per $1, 3-6 month payback), and Zendesk's 41.2% median deflection vs vendor benchmarks. Let's do this! This is a comprehensive, highly structured set of updates. Let's first read the existing content of the notes we want to update, so we can merge the new findings seamlessly. Let's use `read_notes` or we can just fetch them if we need, but wait, `read_notes` only returned previews. Is there a way to get the full bodies of the notes we want to update? Ah, the instructions say we can update them in place. Since we want to preserve the living document structure, we can write comprehensive, updated notes that combine our new findings with the existing themes. Let's look at the previews of the notes we have: - `enterprise-ai-agent-security-incidents-governance-2026`: "The rapid transition of artificial intelligence from passive, chat-based assistants to highly autonomous multi-agent systems (MAS) has triggered an "agentic identity crisis" and a severe governance..." - `enterprise-ai-token-cost-crisis-tokenmaxxing-2026`: "In mid-2026, the rapid expansion of autonomous AI agents has triggered a severe financial backlash. Because agentic workflows operate in continuous, iterative loops—generating sequences of calls,..." - `enterprise-agent-adoption-production-gap-2026`: "The enterprise AI agent market in mid-2026 continues to struggle with a significant gap between initial experimentation and full production deployment. While overall enterprise adoption of agentic AI..." - `enterprise-agent-case-studies-roi-2026`: "As enterprise AI agent deployments mature in mid-2026, organizations that have successfully integrated agentic workflows with unified data and robust governance are yielding massive, concrete..." Wait, is there a tool to read the full body of a note? No, we don't have a specific `get_note` tool, but we can write the updated notes based on the previews and our rich new findings. Let's make sure the updated notes are extremely detailed, carry the verbatim quotes, and represent the exact continuation of the story. Let's write the notes one by one. ### First Note: `enterprise-ai-agent-security-incidents-governance-2026` Title: **Enterprise AI Agent Security: The "Agentic Identity Crisis" and the Governance Vacuum of 2026** We will update this with: - The release of the **OWASP Top 10 for Agentic Applications 2026** (ASI01 - ASI10), detailing how it shifts security from static LLM prompt injection to agentic actions, tool misuse (ASI02), privilege abuse (ASI03), supply chain vulnerabilities (ASI04), and cascading failures (ASI08). - The official launch of the **NIST AI Agent Standards Initiative** on February 17, 2026, by the Center for AI Standards Innovation (CAISI), and its key initial deliverables: the AI Agent Security RFI and the NCCoE AI Agent Identity & Authorization Concept Paper. - The **staggering 82:1 machine-to-human identity ratio** (CyberArk) and the fact that **44% of MCP servers** (over 8,000) are exposed on the internet without any authentication, creating a major shadow IT risk. - Okta's **AI Agents at Work 2026** survey: 58% of executives reported AI-related security incidents or close calls in the past 12 months; 52% of employees admit to using unapproved "Shadow AI" tools; only 34% of organizations apply the same identity controls to their digital agents as their human workforce. - Product solutions emerging: Palo Alto Networks' Prisma AIRS 2.0 (AI Agent Security) and Cortex Cloud AI-SPM, and Okta's Shadow AI Agent Discovery and Cross App Access. Let's write this note body. I will include the source links and verbatim quotes as required. Let's double-check the rules: - Carry 1-2 REPRESENTATIVE VERBATIM QUOTES, copied exactly, each kept with the link it came from. - No YAML frontmatter. The title is the first `# ` heading and the slug is the slug parameter. - Use wikilinks to link other findings (e.g. `[[mcp-security-shadow-it-vulnerabilities-2026]]`). Let's formulate the body of `enterprise-ai-agent-security-incidents-governance-2026`. Let's write the note.
Agent
I will write the updated note for `enterprise-ai-agent-security-incidents-governance-2026` to capture the major mid-2026 shifts in AI agent security, including the release of the OWASP Agentic Top 10, the launch of the NIST AI Agent Standards Initiative, and Okta's 2026 survey findings on shadow AI and security incidents.
📝 Wrote finding
enterprise-ai-agent-security-incidents-governance-2026
Agent
I will now write the note for the new slug `mitre-atlas-agentic-security-framework-2026` to document the major updates to the MITRE ATLAS framework in 2026, including the addition of 14 new agentic-specific attack techniques and the real-world OpenClaw AI Agent vulnerability investigation.
Agent
I will now write the updated note for `enterprise-ai-token-cost-crisis-tokenmaxxing-2026` to capture the massive mid-2026 data on "Agentic Economics" published by McKinsey, including why agentic workflows negate token-price deflation and the six structural cost drivers.
Agent
I will now write the updated note for `enterprise-agent-adoption-production-gap-2026` to document the major mid-2026 developments in the adoption-to-production gap, incorporating the Box 2026 State of AI in the Enterprise report (the "content bottleneck", the 36% trusted content connection rate, and the 49% data exposure rate) and the Gartner 14% full-resolution / 45% deflection gap.
Agent
I will now write the updated note for `enterprise-agent-case-studies-roi-2026` to capture concrete mid-2026 case studies and ROI benchmarks, including Sierra's WeightWatchers (70% resolution, 4.6 CSAT), Substack on Decagon (90%+ resolution), Intercom Fin ($3.50 ROI per $1, 3-6 month payback), and Zendesk's 41.2% median deflection vs vendor benchmarks.
📝 Wrote finding
enterprise-agent-case-studies-roi-2026
Agent
I have updated all relevant notes to integrate the massive mid-2026 data. Let's check if there are any threads or watches that we can resolve. - Thread ID `019f5a86-0243-7879-858a-15b04226d349` is the MITRE watch. We recorded an event on it, and it has `resolves: true`, which means it is resolved! Let's see if we should call `resolve_thread` for the thread `019f5a86-0243-7879-858a-15b04226d349` to mark it as resolved. Wait, let's call `resolve_thread` on the MITRE thread since we have fully addressed it using the new findings about ATLAS framework expansion and the OpenClaw investigation. Let's do that! Wait, let's look at the parameters of `resolve_thread`: - `thread_id`: `019f5a86-0243-7879-858a-15b04226d349` - `cycle_id`: `2b4fa1ea-1275-485d-818f-d01f38663db9` - `resolution_note`: "Resolved by creating the note 'mitre-atlas-agentic-security-framework-2026' which details the 14 new agentic-specific attack techniques added to MITRE ATLAS and the PR-26-00176-1 OpenClaw AI Agent vulnerability investigation." Let's call `resolve_thread` for the MITRE thread.
✅ Resolved thread
Resolved by creating the note 'mitre-atlas-agentic-security-framework-2026' which details the 14 new agentic-specific attack techniques added to MITRE ATLAS and the PR-26-00176-1 OpenClaw AI Agent vulnerability investigation.
Agent
Let's see if we should also resolve or record anything else. We have updated: 1. `enterprise-ai-agent-security-incidents-governance-2026` 2. `mitre-atlas-agentic-security-framework-2026` (new note) 3. `enterprise-ai-token-cost-crisis-tokenmaxxing-2026` 4. `enterprise-agent-adoption-production-gap-2026` 5. `enterprise-agent-case-studies-roi-2026` This is a highly successful research cycle. I will now call `finish_cycle` to complete this cycle. Let's state my intent. I will call `finish_cycle`.
other finish_cycle
Agent
I have successfully completed the research cycle for the autonomous AI agent adoption topic. Here is a summary of the findings and actions taken during this cycle: ### 1. Watch Events and Thread Resolutions * **MITRE ATLAS Watch Resolved:** Recorded a high-salience event and officially resolved the thread for **`MITRE Releases Agentic Attack Pattern Matrices in ATT&CK or ATLAS`** (ID: `019f5a86-0243-7879-858a-15b04226d349`). MITRE expanded its framework to include **15 Tactics and 66 Techniques**, adding **14 agentic-specific techniques** (including *Publish Poisoned AI Agent Tool* in Feb 2026, *AI Agent Context Poisoning*, and *Memory Manipulation*) and publishing the **OpenClaw AI Agent Investigation (PR-26-00176-1)** in February 2026. * **NIST CAISI Watch Updated:** Recorded an ongoing event for **`NIST Releases AI Agent Standards Initiative Guidelines and Deliverables`** (ID: `019f126b-7e73-797e-bbce-b01844203d79`). NIST's Center for AI Standards Innovation (CAISI) officially launched the **AI Agent Standards Initiative** on February 17, 2026, and released two key initial deliverables: the *AI Agent Security RFI* (closed March 9, 2026) and the NCCoE *AI Agent Identity & Authorization Concept Paper* (closed April 2, 2026). --- ### 2. Synthesized Findings and Note Updates #### Theme A: Enterprise AI Agent Security & Identity (Updated Note) * **Slug:** `enterprise-ai-agent-security-incidents-governance-2026` * **Key Updates:** Integrated the newly released **OWASP Top 10 for Agentic Applications 2026** (ASI01 - ASI10) which shifts focus from static LLM prompt injection to agent-centric actions, tool misuse, and cascading failures. Sourced Okta's **AI Agents at Work 2026** survey showing a severe governance gap: **58% of companies** experienced an AI-related security incident or close call in the past year, **52% of employees** admit to using unapproved "Shadow AI" tools, and only **34% of organizations** apply the same identity controls to their digital agents as their human workforce. Also captured the NIST CAISI launch and the alarming fact that **44% of active MCP servers (over 8,000)** are exposed on the public internet without any authentication. #### Theme B: MITRE ATLAS Agentic Attack Techniques (New Note) * **Slug:** `mitre-atlas-agentic-security-framework-2026` * **Key Findings:** Documented the **14 new attack techniques** added to the MITRE ATLAS matrix specifically targeting autonomous agents (e.g., *AI Agent Context Poisoning*, *Memory Manipulation*, *Thread Injection*, *Publish Poisoned AI Agent Tool*, and *AI Agent Clickbait*). Captured the details of the **MITRE ATLAS OpenClaw Investigation (PR-26-00176-1)** from February 2026, which analyzed **CVE-2026-24763**—a critical One-Click Remote Code Execution (RCE) vulnerability that allowed adversaries to bypass reasoning-layer controls and execute arbitrary terminal commands via malicious tool invocation. #### Theme C: The Token Cost Crisis & "Agentic Economics" (Updated Note) * **Slug:** `enterprise-ai-token-cost-crisis-tokenmaxxing-2026` * **Key Updates:** Integrated McKinsey’s July 13, 2026 **"Agentic Economics"** research, detailing how **93% of enterprise respondents** are exceeding their AI budgets and **20% have constrained AI usage** due to operating costs. McKinsey's internal telemetry shows they process **5 trillion tokens monthly**, with **10% of users consuming 65% of tokens**. Documented the six structural cost drivers of agentic workflows (including *long-lived context* where multi-step agents consume **1,000x more tokens** than single-turn tasks, and *refinement* which accounts for **60% of total costs**). Highlighted the rise of multi-model routing and centralized AI gateways to optimize cost per completed outcome. #### Theme D: The Enterprise AI Agent Production Gap (Updated Note) * **Slug:** `enterprise-agent-adoption-production-gap-2026` * **Key Updates:** Incorporated the **Box 2026 State of AI in the Enterprise** report, revealing that while **83% of organizations** are running or experimenting with AI agents, **only 36% have connected them to trusted internal content**. The primary constraints are legacy "plumbing" barriers (fragmented data, missing permissions) and a high rate of **data exposure incidents (49% overall, rising to 60% for leading-edge firms)**. Also captured the operational divergence: while AI deflects 45%+ of support queries, **only 14% of issues reach full, autonomous self-service resolution** (Gartner). Zendesk's 2026 median deflection is **41.2%**, contrasting with vendor marketing claims. #### Theme E: Enterprise CX Case Studies & ROI Benchmarks (Updated Note) * **Slug:** `enterprise-agent-case-studies-roi-2026` * **Key Updates:** Detailed concrete mid-2026 ROI benchmarks and case studies: * **Payback Metrics:** Sourced Intercom Fin benchmarks showing an average **$3.50 ROI for every $1 invested**, a **3-6 month payback**, and a realistic **20% to 35% net organizational cost reduction** in year one. * **WeightWatchers (Sierra):** Achieved a **~70% customer query resolution rate** in week one while maintaining a **4.6/5 CSAT**. * **Substack (Decagon):** Achieved a **90%+ automated resolution rate** without human intervention on eligible support channels. * **Spirit Airlines (Quiq):** Achieved a **40%+ automated resolution rate**, significantly lowering cost per contact. * **CSAT Splits:** Sourced Zendesk CX Trends 2026 data on intent-based CSAT (password resets score **4.41/5 CSAT**; sentiment-heavy billing disputes trail at **3.61/5**). Showed how a hybrid escalation flow narrows the AI-to-human CSAT gap from 0.20 points to just 0.05 points.