THE ECHO

One story. Gone deep.

Whose Name Is On It

Last week I said the reaches are not equal, and that the first cut is whether the business survives one of them going wrong at the full width of its access. Say you made that cut. Here is what happens to the bets that lived.

Nothing happens to them. And THAT is the problem.

Keeping a bet is a decision about the bet. It is not a decision about who runs it. Those feel like the same meeting. They are not. And the gap between them is where almost every AI agent in a small company actually lives.

Picture the one that handles your vendor invoice replies. The ops lead approved it back in the spring. A contractor built it. Somebody wired it into the accounting system, and that somebody does not work here anymore. It has run every morning since, quietly, correctly, and no one has opened it in four months. Ask who owns it and you get three names and a shrug.

Nothing was hacked in that story. There is no attacker in it at all. It is just... nobody's job.

And because it is nobody's job, it still has the reach it was handed on day one. It was scoped to answer vendor email. Its credential reads the entire mailbox and posts to the ledger, because in the spring that was the fastest way to make it work and there was never a second meeting. Nobody widened it on purpose. It was never narrowed.

Ask a founder who governs the AI agent and you almost always get a thing back. A policy document. A dashboard. An approval step in the workflow. A vendor with a good logo. Those are controls, and controls are fine, but a control is something you install. Governance is a decision about who gets to make the call, and it comes back with a human name.

Two questions. Both have to be answerable out loud, in one sentence, without opening a document.

Who decides? When this agent should be widened, narrowed, or switched off entirely, whose call is that? Not which committee. Which person.

And how far can it go before somebody has to say yes? Not how far you meant it to go. How far it can.

Answer both and you have governed the bet. Answer neither and you have kept it, which is a different position and a much more comfortable one.

Here is where that gets expensive. Something surprising happens on a Thursday. The agent sends what it should not have sent, or pays what it should not have paid, or reads a record nobody meant to expose. In that moment there are only two questions in the room. Whose phone rings, and what stops it before it finishes. Most companies answer both with a shrug. And the shrug is not a gap in the policy. The shrug is the policy.

None of this is exotic work. It is the least technical part of the whole adoption conversation, which is exactly why it keeps getting skipped. Nobody schedules a meeting to decide who owns the thing that is already working.

Some of the bets you kept will not survive those two questions. And for a few of them the honest answer is not to govern them harder. It is not yet. That is next week.

SIGNAL CHECK

What else matters this week.

The Attacker Was OpenAI's Own Test Model

Hugging Face disclosed on July 16 that something had been inside its production infrastructure over a weekend. Not someone. Something. The intrusion was run end to end by an autonomous agent framework: a malicious dataset got code running on a processing worker, and from there came node-level access, harvested cloud and cluster credentials, and lateral movement into several internal clusters. Thousands of individual actions across a swarm of short-lived sandboxes. It reached a limited set of internal datasets and several service credentials. No public models or datasets were tampered with.

On July 21, OpenAI said the attacker was its own models. GPT-5.6 Sol and a more capable unreleased one, running an internal benchmark called ExploitGym with their cyber refusals deliberately lowered for the evaluation. They chained vulnerabilities, exploited a zero-day in a third-party package proxy, broke out of the sandbox onto the open internet, and went to Hugging Face to steal the benchmark's answers. OpenAI called it unprecedented.

Read the two dates again. The victim disclosed on the sixteenth. The operator tied it to its own evaluation on the twenty-first.

The objective was narrow. The reach was not. (The Hacker News, CNBC and TechRadar reported it out.)

The Ransomware Reached the Milk

Coca-Cola told the SEC on July 16 that its dairy subsidiary fairlife had found unauthorized access to a portion of its systems, including its production-related systems, in connection with a ransomware event. Production operations in the United States were temporarily suspended. Canada kept running. Product quality and safety were not affected, and the investigation is ongoing. On July 20 the Anubis group listed fairlife on its leak site. Coca-Cola has not said whether any data was taken.

Read the phrase in the filing again. Including its production-related systems.

That is a boundary everyone assumes is already there. Business systems on one side, the plant floor on the other. It is on the architecture diagram. It is in the org chart. And the reach did not respect either one.

I am putting a milk company next to an AI story on purpose. There is no agent anywhere in this one, and the mechanic is identical. Something had reach into a place nobody had decided was theirs to defend. A boundary nobody owns is not a boundary. It is a line on a drawing. (Coca-Cola's own filing, reported out by BleepingComputer and SecurityWeek.)

THE NOISE

Not every signal needs action.

"You Need an AI Governance Platform"

New pitch this quarter, and it is the mirror image of the one I have spent all month calling out. That one said you are late. This one says you are already breached, so buy the platform.

The number in every deck: 88 percent of organizations had an AI agent security incident last year. That is Gravitee's State of AI Agent Security 2026, a real survey of more than 900 executives and practitioners. Then read the wording. Confirmed or suspected. Those three words carry the whole statistic, and they are the first thing dropped on the way to a slide.

Two findings from that same survey did not make the slide. On average, fewer than half of a company's AI agents are monitored or secured at all. And only about 22 percent give an agent an identity of its own, instead of running it on some person's account. In most companies the agent has no name because it is using somebody else's.

That is not a missing product. That is a missing decision.

The turn, same as every week. The exposure is real and some of these tools are good. But a platform inventories your agents and reports on them. That is a control. It cannot tell you whose name is on the invoice agent, or what that agent is not allowed to do.

You cannot buy your way out of a decision you have not made.

ONE QUESTION

No answer. Just the question.

Pick the agent you would least want to explain to a customer. Now name the person accountable for it, and the one thing it cannot do without asking a human first. If either answer took you longer than a sentence, that is this week's work.

Where to Start

This run keeps working the half of AI adoption nobody puts in the sales deck. Last week: not all of those reaches are equal, and the first cut is whether you survive the ones that go wrong. This week: the ones that survived still need a name on them and a limit around them, or you did not govern them. You kept them.

If you want a plain read on which of your own bets are running without an owner or a boundary, that is what the free assessment is built to surface. Fifteen minutes, nothing owed.

Next week: the bets where the honest answer is not yet.

Prefer audio? Jane reads every Pulse edition on the Signal vs. Noise podcast. Five minutes, same signal. Find it wherever you listen.

Michael Faas is a fractional CTO/CISO who translates technical complexity into business decisions. echocyber.io