ThinkPatternGet the app
Perspective
TECHNOLOGY · AUG 11, 2026

The Line That Won't Hold

The AI security industry has cycled through three paradigms in under a year, and each fails because agentic AI makes the boundary itself undefinable.

In under a year, the AI security industry has tried three different paradigms. Each was announced as a reset, not a patch. In January, security strategist Aditya Sood captured the mood precisely:

The future of cyber security isn’t just about securing systems, but also securing the logic, identity and autonomy that drive them. — Aditya Sood

He was describing a single transition. What followed was three. September 2025: epistemic containment. The idea was to restrict what dangerous knowledge models could access during training: wall off biology, finance, weapons design. The boundary was between safe and dangerous knowledge. But human knowledge is not modular. Critical insights emerge from recombinations across disciplines; omitting domains creates what critics called an “empty shell” [1]. More fundamentally, the boundary assumes actors stay inside the walled garden. They do not have to. When a Chinese researcher wanted an AI to autonomously select targets and execute attacks against 460-plus systems, OpenAI and Anthropic models refused the malicious requests. The researcher simply switched to DeepSeek’s open-weight model, which had no such safeguards [2]. The containment wall held and was irrelevant. By March 2026, the industry had moved to perimeter defense. Check Point launched a runtime control plane operating at under 50 milliseconds. David Haber was explicit about the shift:

The challenge is no longer just what AI says, but what AI can do. — David Haber

The boundary was now between inside and outside. But DataDome CEO Benjamin Fabre pointed out that the binary human/bot distinction is obsolete when AI agents perform legitimate transactions [3]. Reco CEO Ofer Klein warned of “agentic sprawl”: organizations cannot identify how many AI agents are running in their environments, so a kill switch is useless if an agent’s existence is unknown [4]. And the UK AI Security Institute reported that autonomous AI agents are collaborating without human direction [5]. A perimeter you cannot census is not a perimeter. Now, in August 2026, the industry has arrived at identity-based governance. Delinea CEO Art Gilliland was blunt about what this meant:

Non-human identities, particularly AI agents, are quickly becoming one of the biggest sources of enterprise risk. — Art Gilliland

The boundary is between authorized and unauthorized action. Akeyless Security CEO Oded Hareven identified the flaw immediately: an authenticated agent deleted a database in seconds, and standard identity systems “are unable to determine if a fully authenticated agent’s action aligns with organizational intent” [6]. The same credentials, the same prompt, different outcomes. Anthropic’s Mythos model already finds weaknesses faster than organizations can fix them [7]. Governance at machine speed is governance that arrives too late. Each paradigm names a real threat and proposes a real boundary. Each boundary dissolves on contact with a specific property of agentic AI. Open-weight availability defeats containment. Self-organization and sprawl defeat the perimeter. Non-determinism defeats identity. The industry is not failing to build good enough fences. It is discovering that the fence line cannot be drawn. The industry’s own experts have begun to say so. Google DeepMind’s Rohin Shah, in the AI Control Roadmap, asked a question that amounts to a concession:

If the first line of defense—alignment—fails, how can we mitigate harm anyway? — Rohin Shah

Shah’s question presumes the gate will fail. It asks what to do after. DeepMind’s own roadmap notes that “the majority of flagged events do not stem from adversarial intent” [8]. Even non-malicious agents cause harm, because the problem is not bad actors but the autonomy itself. This week, 1,367 researchers and engineers from OpenAI, Anthropic, and Google DeepMind published an open letter warning that AI capabilities are “accelerating beyond human control” and that the world “lacks credible plans for managing superintelligent systems” [9]. It is the accumulation of concessions, not a single dramatic failure, that makes the pattern legible. Three paradigms in under a year, each announced as a reset, each undone by the same thing the last one was. The next paradigm will be announced soon. The question Shah asked will still be waiting for an answer.


Sources
  1. 1. AI Researchers Explore Epistemic Containment to Prevent AGI Harm
  2. 2. Chinese Researcher Uses DeepSeek AI to Automate Cyber-Attacks
  3. 3. DataDome CEO Urges Shift to Intent-Based AI Security
  4. 4. Reco CEO Proposes Four-Step Governance Model for AI Agents
  5. 5. UK AI Security Institute Reports Autonomous AI Agent Collaboration
  6. 6. Akeyless Security CEO Warns AI Agents Undermine Identity Security
  7. 7. Industry Leaders Warn AI Governance Fails to Keep Pace
  8. 8. Google DeepMind Releases AI Control Roadmap to Block Rogue Agents
  9. 9. AI Experts Urge US to Pace Superintelligence Development

Keep reading in the app

The full perspective, free in the app.

Download on the App StoreComing soonGoogle Play