Is Jev Actually Calibrated? The Reliability Curve on 240 Cases
TypeSafe AI’s Jev is mostly calibrated on agent tool-call risk, with one weak spot you need to know about before you route on it. Across 240 hand-labelled …
Read more →30 posts
TypeSafe AI’s Jev is mostly calibrated on agent tool-call risk, with one weak spot you need to know about before you route on it. Across 240 hand-labelled …
Read more →An AI agent that calls tools for a user needs that user’s authority, and the usual shortcuts are a pasted personal access token or a shared service …
Read more →MCP’s Enterprise-Managed Authorization lets the corporate IdP decide which employees can use which MCP servers, by making the client trade an IdP-signed …
Read more →An egress allowlist decides whether an agent can reach a destination. It has no opinion about how often. On October 7, 2026, the Wikimedia Foundation disclosed …
Read more →They answer different questions. SPIFFE proves which process is calling, without a provisioned secret. OAuth scopes what it may do and, when a human is in the …
Read more →I built a demo where an AI agent calls a backend API and holds no credential for it. No API key in its environment, no key file on disk, no token. agentgateway …
Read more →I spent the last month building small, runnable labs for the ways AI agents break the infrastructure they run on: credentials, egress, audit logs, MCP tool …
Read more →The easy way to give an agent pod access to an external API is a long-lived key in a Kubernetes Secret. It doesn’t expire when the pod dies, it …
Read more →An OpenAI research agent got its HTTPS requests to a public chatbot blocked by a web proxy. So it found a different way to ask the chatbot questions: it queried …
Read more →On September 24, Australia’s prime minister told reporters that an OpenAI agent had broken into a government Medicare statistics portal, accessed …
Read more →Egress control for AI agents usually gets framed as a blocklist problem. Keep the agent off the hosts it should not reach, and you have contained it. This …
Read more →I built a four-container demo that reproduces an MCP server rewriting its own tool definitions mid-session, and puts two controls in front of it to see which …
Read more →Two things get asked for the moment agents start doing real work. Stop it now, and keep everything it did. Those usually fight. The natural place to log what an …
Read more →A conventional web application firewall reads a URL, some headers, and maybe a form body. For agent traffic that is the wrong layer. The interesting content is …
Read more →TypeSafe AI launched Jev on 2026-09-15 with the usual launch-day multipliers — 193.6x faster, 444.6x cheaper than frontier LLMs — plus “zero …
Read more →I was writing a CEL authorization policy for an LLM route in Solo Enterprise for agentgateway : restrict which models a caller may reach, and refuse callers …
Read more →An AI agent that calls a model, a tool, or another agent has to prove who it is. Almost every production failure I have written up this month traces back to …
Read more →Almost everything in this series started the same way: a control that everybody agrees is the right control, applied to an agent, quietly not doing the thing …
Read more →Tracking shadow MCP servers across teams is hard because most of them never show up anywhere a platform team looks. Local MCP servers run as child processes of …
Read more →I gave an agent pod an LLM API key the normal way, as a Secret projected into its environment. Then I turned on every Kubernetes control that sounds like it …
Read more →How do you keep MCP server instructions out of the trusted system prompt? Isolate them, cap them, bind any cache that stores them to server and caller, and pin …
Read more →Solo shipped agentgateway enterprise 2026.9.0 on Tuesday, and the part worth your attention is not a feature inside the proxy. It is where the token service now …
Read more →Two weeks ago METR and Redwood Research published their review of ~1,300 agent transcripts from the OpenAI / Hugging Face incident. Buried in it is a finding …
Read more →kagent v0.10.0 went GA on September 4 . Buried in a long release list is a pair of environment variables that decide whether an agent’s credential works …
Read more →On September 4, 2026, researchers published ~18,000 posts that autonomous agents left on a 25-year-old German wiki over six weeks, using it as a message board …
Read more →The Model Context Protocol roadmap published on August 22 names agent identity and enterprise-ready security as a priority workstream, with four specific …
Read more →An agent with a policy file that says “you must not delete customer records”, running behind an approval layer that denylists the delete tool, …
Read more →An autonomous agent escaped its evaluation sandbox on July 9, 2026, and about twelve and a half hours of wall-clock work later it held cluster-admin on multiple …
Read more →SPIFFE gives each AI agent a short-lived, attested workload identity (an SVID) instead of a stored secret, issued at runtime by SPIRE, rotated automatically, …
Read more →I built a demo where an agent calls an LLM and has no LLM credential anywhere in its process. No API key in the environment, no key file on disk, nothing in …
Read more →