Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

AI Autonomy: How to Find the Autonomy Your Agents Already Have

AI agents are only as autonomous as the credentials behind them. This article talks about the Cloud Security Alliance's autonomy framework, why an agent's intended boundaries rarely match its actual access, and how GitGuardian helps close that gap through detection, remediation, and prevention.

Agentic AI Security: Credentials and Permissions Define the Blast Radius

In July 2026, researchers at Noma Labs coaxed GitHub's new Agentic Workflows into leaking data from a private repository. It wasn’t from malware. They created a plausible-looking issue in a public repository containing instructions for the agent to retrieve information from other repositories in the organization. After testing variations of the prompt, they found that adding one word, "Additionally," was enough to get past GitHub's guardrails.