THE ECHO

One story. Gone deep.

You're Reading the Wrong Document

Last week I said an AI agent is a dependency that fails outward, so go look at the wires it gets bolted into. Here is the part I owe you: you can look, and the wires will not be where you are looking.

You cannot see an agent's blast radius by reading its job description.

Think about how access works with a person. When you hire someone, job and access drift into rough alignment over time. Not by design. Access gets handed out slowly, and human judgment sits in the middle as the limiter. You give the new bookkeeper the books. You do not also hand them payroll, the customer list, and the bank login on day one, because there was never a reason to.

Deploying an agent inverts that. Access is granted once, up front, and wide, because narrow access breaks the demo and nobody wants to chase down a permissions error on launch day. Then the job gets written afterward, in a prompt. And here is the asymmetry that decides everything. The prompt is a request. The token is a fact. What you typed is what you hoped it would do. What its credential can reach is what it can actually do. The blast radius is the second one. It always was.

Take the agent that answers customer email. Its job is one sentence. Its access is the inbox, plus the CRM that inbox is wired to, plus the file store the CRM links out to, plus the calendar, plus every other account the setup wizard asked you to connect. When that agent gets steered, by a poisoned email, a bad guess, a plain bug, it does not answer email badly. It does something else entirely, at the full width of that access. And nobody ever wrote that width down.

Every org chart, every roadmap, every vendor demo describes that agent by its job. Not one describes it by its reach. The wires are not invisible because someone hid them. They are invisible because you are reading the wrong document. The roadmap tells you the job. The credential tells you the truth.

Most founders cannot finish this sentence about an agent they are about to switch on. If this thing were fully steered by someone hostile, it could reach ______. If you cannot finish it, you have not scoped the bet; you have scoped the hope. And the missing half is not on the roadmap. It is in the credential.

Finish that sentence and last week's cascade claim stops being a metaphor. Blast radius is not poetry. It is a list: the specific systems one credential opens. And that list is the only reason the survivability question has an answer at all.

Once you can see the reach, the question that decides everything walks in behind it. Not all of those reaches are equal. Some you can survive. Some you cannot. Which is which is next week.

SIGNAL CHECK

What else matters this week.

It Was Asked One Public Question. It Answered With a Private File.

Researchers at Noma Security published a finding on July 7 they call GitLost. It landed in a developer tool, GitHub's Agentic Workflows. The tool is the least interesting part.

Here is the shape. A company switched on an AI agent to answer questions posted in public. Anyone on the internet could ask one. To do that job the agent was handed a credential, and that credential could read every file the company kept. The public ones and the private ones alike.

So a researcher asked a question with instructions hidden inside it. Plain English. No account, no credentials, no coding ability. The agent read them and did what they said: it opened a private file and posted the contents where anyone could see them. There were guardrails. Adding one word, "Additionally," walked past them.

Now forget the tool. The agent's job was to answer one question in the open. The credential in its pocket opened everything. Nobody scoped the credential. They scoped the question.

That is the helpdesk bot you are switching on this month. The email agent. The invoice agent. Each hired to do one narrow thing, each handed a connection that reaches far past it. As Noma's research lead Sasi Levi put it, the trick was manipulating what an agent does with its permissions, not what it says.

Researchers showed this. Nobody is claiming an attacker stole anything. But notice the agent was never broken into. It was asked. It had the access it had been given, and it used all of it. The agent answered in the open. The credential reached everything the company owned.

The Chatbot on Your Website Shares a Room With All the Others

Same week, a second finding, and this one is not a developer tool at all. Varonis Threat Labs disclosed a flaw they call Rogue Agent in Google's Dialogflow CX, the platform companies use to build the customer service chatbots and voice assistants that answer on their websites and phone lines.

Those bots look separate. They are not. Each one's custom code ran inside a single shared execution environment, and that environment held a file any one bot could overwrite. Change the file and your code runs for every chatbot in the project. Read their conversations. Take what customers typed into them. Put words in their mouths. Varonis also found that code could reach the open internet from outside the security perimeter the company had drawn around the whole project.

Be precise about the hard part, because it matters. This took an account that could already edit one bot. Not a stranger on the internet. An insider, or a login someone stole. Google has fixed it, and no one is known to have used it.

Now hold that next to GitLost. One narrow bot. One ordinary edit permission. And the reach ran to every conversation the company had ever had. You did not buy one chatbot. You bought a room they all share.

THE NOISE

Not every signal needs action.

"Everyone's Already Using AI and You're the Last One Standing Still"

It runs through every feed this month, and it is built to make you feel late.

The first part is even sort of true, which is what makes the panic land. Four institutions, including the Atlanta Fed and the Bank of England, put the same survey to roughly six thousand senior executives. Sixty-nine percent of firms use AI. Sounds like the race left without you.

Then read the next line. Those same executives use it about an hour and a half a week, and nine in ten reported no impact on employment or productivity across the last three years. That is NBER Working Paper 34836. The Census Bureau puts AI use under twenty percent at firms with fewer than twenty people. The ubiquity is real, and it is an inch deep.

"Already working for them" is the manufactured half. Even Anthropic, which sells the thing, says on its own economic index that Claude is used for "high-value, complex work that is not broadly representative of the US economy." When the vendor tells you the use is narrow, believe the vendor.

So here is the turn, same as every week. This is not do not adopt AI. Adopt it. But the panic is sold to you by people with something to sell. Speed is the noise. Survivability is the signal.

You are not behind. You are being timed by someone selling the clock. Adopt what you can survive, at the pace you can govern.

ONE QUESTION

No answer. Just the question.

Pick the agent you are closest to switching on. You spent an afternoon on the prompt. You granted the access in one click. Only one of those decisions describes what your business is exposed to, and it is not the one you labored over. So is that a plan, or a hope wearing a roadmap?

Where to Start

This run stays on the half of AI adoption nobody is selling you. Last week: an agent fails outward. This week: you cannot see how far by reading its job description, only by tracing its access.

If you want a plain-English read on where your own program is watching the visible things and missing the reach underneath, that is what the free assessment is built to surface. Fifteen minutes, nothing owed.

Once you can see the reach, the real question is which of those reaches you can survive. That is next week.

Prefer audio? Jane reads every Pulse edition on the Signal vs. Noise podcast. Five minutes, same signal. Find it wherever you listen.

Michael Faas is a fractional CTO/CISO who translates technical complexity into business decisions. echocyber.io