SourcesState of AI Agent Security 2026: 88% Report IncidentsGravitee.io·high signalXBlueskyLinkedInCopy linkGravitee.io report: 88% incidents, 14.4% security approval, 45.6% shared API keysSourceSource pageGravitee.io↳ Follow the threadPolicy dependency / Stack layerCodex routes MCP elicitations and tool approvals through one decision API, with model policy overriding the legacy review flagGitHubStack layer / Threat patternIris trains 35B and 397B search agents by reverse-constructing questions from hyperlink structure, and reports benchmarks both with and without context managementarXiv / HuggingFace Daily PapersStack layer / Threat patternCrew Wires Claude Code, Codex and OpenCode Sessions Together Through Lifecycle Hooks and a Read-Only RegistryCrew, via Hacker News Show HN (single source)Policy dependency / Threat patternCodex now gates MCP tool calls behind a Touch ID signature from a Secure Enclave keyGitHubStack layer / Threat patternA dual-login proxy plugin lets GPT-6 Astra orchestrate Opus subagents inside Claude Coder/ClaudeAI (67 upvotes, 32 comments)Policy dependency / Stack layerHierarchical Ransomware Agents Escalate to Dynamic and Memory Analysis Only on Specialist DisagreementarXiv 2609.04820Stack layer / Threat patternBen Thompson's case that the harness, not the model, was the breakthrough, and that agents need written state to cohereStratecheryThreat pattern / ContrastOpenAI Filed an EU AI Act Incident Report Over the Hijacked German Wiki, and Fortune Reports Employees Were Pressured to Stay Quiet for WeeksFortune (corroborated by TNW, IBTimes UK, Cryptopolitan)