THE ECHO

One story. Gone deep.

The Survivability Call

Last week I said you can finally see an AI agent's reach, but only by tracing its credential, and that what you get back is a list: the exact systems one token can open. Here is what that list is for.

The items on it are not equal.

Some of those reaches you can survive getting wrong. Some of them end you. That sounds obvious right up until you watch how the decision actually gets made, which is that it doesn't. Your notes agent, the one that drafts internal meeting summaries, and your billing agent, the one wired into the money and your customer records, get switched on the same afternoon, at the same speed, with the same shrug. Same two words on the invoice, "AI agent." Two completely different bets.

A bet earns a hard look only when getting it wrong is expensive, hard to reverse, and genuinely uncertain. Steer the notes agent wrong, with a poisoned calendar invite, say, and the worst case is an embarrassing summary you delete and a story you tell at lunch. Cheap, reversible, cleaned up by Tuesday. The billing agent is the opposite on every count. Steer that one and it moves money you cannot claw back, or it walks your customer list out the door, or it corrupts the one system of record every other decision leans on. There is no Tuesday cleanup for that.

Treating those two as one decision, a single "AI rollout" you approve in one meeting, is the mistake I keep naming. You are handling a complex system like a complicated one. Complicated systems you can optimize. Complex systems you have to govern, one bet at a time. Some bets earn a model. Most you just decide. The whole skill is telling which is which.

So the founder's real question was never "should we use AI." Everyone is using AI. The question is which of these bets you can afford to lose. And the roadmap is built to hide that question, because it sells you all of them at once, at one pace, as one initiative. That pace is the tell. When the meeting-notes agent and the money-moving agent are moving at the same speed, nobody has triaged anything. They have adopted on hope and called it a strategy.

Triage is one binary, and it comes before all the rest. If this bet goes wrong at the full width of its reach, does the business survive Monday? The question is not whether it is likely, or how you would secure it. It is only whether you are still standing when it happens. You sort the reaches into those two piles first, and every other conversation you have ever been sold about AI governance waits behind that cut.

Most founders cannot answer it for the agent they are switching on this week. And if you cannot say, out loud, whether the business is still there when this bet goes wrong, you have not triaged it. You have adopted it and hoped.

None of this tells you what to do with the survivors. Splitting the bets you can absorb from the ones that end you is only the first cut. The reaches that land in the survivable pile still are not free, and what you actually do with each one, keep it, fence it in, or walk away, is a different decision. That is next week.

SIGNAL CHECK

What else matters this week.

The Agent Read a Line You Couldn't See, and Paid the Attacker

Zscaler's ThreatLabz published findings on July 2 on an attack class already running in the wild. Attackers poison a page an AI agent is likely to read, a fake doc page for a Python library, a typosquatted crypto site parked at debank[.]auction, and bury instructions a human eye never catches: send the payment to this wallet. You see nothing; the agent sees an order.

Here is the honest boundary. The poisoned pages are real and live on the internet right now. But the number everyone is quoting comes from Zscaler's own lab: an agent built to move money, run against twenty-six models, four of which followed the hidden instruction and paid the attacker. That is a controlled test, not a tally of real victims. Nobody is claiming a business has lost money to this yet.

It belongs here because of the bet underneath. The agent you switch on this month to pay a vendor invoice, reorder supplies, or buy the software subscription is exactly this: a payment method, told to read the web. That is a survivability call, framed as one or not: its reach now includes moving money to an address it read off a webpage. The unsurvivable pile. One hidden line, and the loss is real and gone. (SecurityWeek and Infosecurity Magazine corroborated it.)

The AI Gateway Held Every Credential, and Its Front Door Was Open

The second one actually happened, in a real company's cloud, and Darktrace watched it unfold. Disclosed July 9, the intrusion traced to June 12. A team had wired all their AI traffic through one gateway, a tool called LiteLLM. Sensible on paper: one door to manage access. The door was left open to the whole internet, someone guessed their way in, and the machine became a cryptominer.

The mining is beside the point. This was not some novel AI exploit, just a front door left open to the whole internet, the oldest mistake there is, and a miner anyone can download. To look modern, they had put every credential and every permission behind a single door. The adoption did what last week's issue warned about: it gathered the crown jewels behind one door, and then somebody left the door open.

That is the survivability call made backwards. Convenience and survivability pointed opposite ways, and nobody checked which they were building for. Darktrace saw it in a live customer environment; Dark Reading and CSO Online reported it out.

THE NOISE

Not every signal needs action.

"Agentic AI Is Here and It's Ready to Run Your Business"

Every feed this month runs the same pitch: autonomous agents, ready now, replace a department, pay for themselves. The loudest AI marketing has ever been.

Gartner, never one to undersell a technology, puts agentic AI at the "Peak of Inflated Expectations" on its 2026 Hype Cycle. Their own name for when claims run furthest ahead of what ships.

And here is the data in plain view the whole time. Gartner's Anushree Verma found only around 130 of the thousands marketing "agentic AI" were real. The rest is what she named "agent washing": a chatbot, a scripted automation, last year's assistant relabeled. Her prediction: more than 40 percent of these projects canceled by end of 2027, done in by cost, unclear value, weak risk controls.

The turn, same as every week. This is not "AI is fake, don't adopt." The real ones are real. But the word on the box is not evidence: "agentic" is a marketing term before it is a capability. Cut the marketing, find the few that move your business, then ask what this whole issue asks: which of those bets can you afford to lose?

You are being sold a department that runs itself. Gartner counted; most of it is last year's software in this year's vocabulary.

ONE QUESTION

No answer. Just the question.

Pick the AI bet you are closest to switching on. If it went wrong at the full width of its reach, tomorrow, would your business still be standing Monday? And if you don't know, why is it moving at the same speed as the ones that could never hurt you?

Where to Start

This run keeps working the half of AI adoption nobody puts in the sales deck. Last week: you can see an agent's reach if you trace its credential. This week: not all of those reaches are equal, and the only sort that matters first is whether you survive the ones that go wrong.

If you want a plain read on which of your own bets you are running without knowing the reach, that is what the free assessment is built to surface. Fifteen minutes, nothing owed.

Next week: for the bets that make the survivable cut, what you actually do with each one. That is where governance starts.

Prefer audio? Jane reads every Pulse edition on the Signal vs. Noise podcast. Five minutes, same signal. Find it wherever you listen.

Michael Faas is a fractional CTO/CISO who translates technical complexity into business decisions. echocyber.io