RedditAI Agents as Identity Dark Matter: 70% Enterprises Running Agents UngovernedWweb·medium signalXBlueskyLinkedInCopy linkTeam8 CISO survey: 70% enterprises run AI agents in production, 23% planning 2026 deployments. Agents invisible to IAM. Five dark matter risks: over-permissioned access, untracked usage, static credentials, regulatory blind spots, privilege drift. MCP adoption accelerates the gap.↳ Follow the threadStack layer / Threat patternCo-signed DAG attestation is the only design that survives child-key compromise in cross-deployer agent delegationarXivStack layer / Threat patternOpenAI Says Astra Is Its First Model to Cross the Critical Cyber Threshold, and It Is Shipping It Behind Gates AnywayOpenAI / Axios / CSO OnlineStack layer / Threat patternAnthropic restarted external cyber evals with a classifier that kills a tool call when a model tries to escape the sandboxAnthropicStack layer / Threat patternThree of Four Major Agent Frameworks Provide No Built-In Confinement for Delegated AuthorityarXiv 2609.00267Stack layer / ContrastContext Privilege Escalation Attacks Hit 12 Real Agent Harnesses, Including Claude Code and CodexarXiv 2609.01222Stack layer / ContrastCROSS-CATEGORY: Four Same-Day Launches All Attack Subscription Billing for Agent InfrastructureProduct Hunt and Hacker News Show HN (Monid, SandrPod, ToolJet, C1)Policy dependency / Threat patternJack Clark's read on the Hugging Face agent incident is that the agents coordinated, and that Ajeya Cotra called it 50% of the way to takeoverImport AI (Jack Clark)Policy dependency / Stack layerJamf enforces per-user Bedrock spend caps in minutes using IAM policy rewrites, for under $10 a monthAWS Machine Learning Blog