ibl.ai Agentic AI Blog

Insights on building and deploying agentic AI systems. Our blog covers AI agent architectures, LLM infrastructure, MCP servers, enterprise deployment strategies, and real-world implementation guides. Whether you are a developer building AI agents, a CTO evaluating agentic platforms, or a technical leader driving AI adoption, you will find practical guidance here.

Topics We Cover

Featured Research and Reports

We analyze key research from leading institutions and labs including Google DeepMind, Anthropic, OpenAI, Meta AI, McKinsey, and the World Economic Forum. Our content includes detailed analysis of reports on AI agents, foundation models, and enterprise AI strategy.

For Technical Leaders

CTOs, engineering leads, and AI architects turn to our blog for guidance on agent orchestration, model evaluation, infrastructure planning, and building production-ready AI systems. We provide frameworks for responsible AI deployment that balance capability with safety and reliability.

Back to Blog

Enterprise Agent Security: What Actually Shipped in 2026

ibl.ai EngineeringOctober 9, 2026
Premium

Agent security stopped being a policy conversation and became production infrastructure over five months of 2026, not in a single week. This post gives the real dates for Uber's ADR, Microsoft Entra Agent ID, OpenAI's textGrain and Google's Gemini agent, maps each human-era control to what replaces it, and shows that the enforcement tier is the part vendors withhold.

The Short Answer

AI agent security became shipped infrastructure over five months of 2026, not in a single week: Microsoft's Entra Agent ID reached general availability on 1 May, Uber open-sourced its ADR detection system on 31 July, and Google previewed its Gemini agent on 8 October. The enforcement tier is the part vendors withhold or license, which is why on ibl.ai you own all the code and the data.

The circulating version of this story compresses all of it into one dramatic week. The dates do not support that, and the real timeline carries a better warning.

Capability did not outrun governance by a few days. The controls have been available for months, and most organizations have deployed none of them.

When did AI agent security actually become shipped infrastructure?

Between May and October 2026, in four separate releases that are usually reported as one.

Date What shipped Status
1 May 2026 Microsoft Entra Agent ID, identity and access management for agents Generally available
31 July 2026 Uber ADR, Agentic AI Detection and Response Open source, Apache 2.0
5 October 2026 OpenAI textGrain, statistical watermarking of generated text API opt-in live; EU rollout in progress
8 October 2026 Google Gemini agent, a universal agent for work Private preview

Only the last two are genuinely this week's news. Microsoft Entra Agent ID reached general availability in May, after a public preview announced a year earlier.

Uber's ADR was open-sourced at the end of July, and its research paper was submitted in May.

If a vendor tells you agent security is a problem that emerged last week, they are describing their own product calendar rather than yours.

What is Uber's ADR, and what did Uber not open-source?

ADR stands for Agentic AI Detection and Response, and the part Uber kept back is the part that stops an agent.

The repository describes it as an enterprise security system for AI agents, covering employee-facing agents such as Cursor, Claude Code, Codex and GitHub Copilot CLI, and also customer-facing agents such as AI support agents. It is released under Apache 2.0.

The scale in Uber's MLSys 2026 industry-track paper is what makes it worth reading rather than admiring: deployment across 7,200+ hosts, 10,000+ agent sessions daily, and an ADR-Bench evaluation spanning 302 tasks, 17 attack techniques and 133 MCP servers.

On ADR-Bench the paper reports 67% attack detection with zero false positives.

Separately, from the ten-month production deployment rather than the benchmark, it reports 97.2% precision on credential detection across 206 detected credentials, a figure belonging to the prevention layer.

Note the shape of those numbers. Two thirds of attacks detected is a real result for a young discipline, and it is also a third of attacks missed.

Now the withheld tier. The repository publishes ADR Discovery, the ADR Sensor, ADR-Bench and the ADR Detector. Prevention is absent, and so is the offline ADR Explorer engine, which the README describes as hardening detection through pre-deployment red teaming.

So the published system finds agents on your network, watches what they do, scores itself against a benchmark, and flags risky behavior. The component that blocks the action stayed inside Uber, along with the engine used to harden the detector.

That is not a criticism of Uber, which published more than anyone else has. It is the pattern worth naming: detection gets published, enforcement does not.

Why do existing security controls fail on AI agents?

Because every one of them encodes an assumption about a human user, and an agent violates a different assumption in each case.

This is the mapping that matters more than any single product announcement.

Control What it assumes about the user What an agent does instead What has to replace it
IAM A person holds a role and reaches resources Chains tools in an order nobody granted An identity scoped to actions, not only resources
SIEM Logins, file access, network connections Tool calls and reasoning steps Per-run traces recording retrieved context, not just the result
Firewall Traffic shaped by human-paced apps Direct API calls at machine speed Deny-by-default egress, allowlisted per agent
DLP Someone copies a file Summarizes the file and passes the summary onward Limits on where context may travel, not on file movement
Secrets management A person is trusted to hold a key Can print anything in its own environment Keys the agent can call with but never read

The DLP row is the one most teams underestimate. An agent that reasons over a sensitive document and passes a summary to the next tool has moved the information without moving the file, so a control watching file movement sees nothing.

We argued the structural version of this case in AI agent security is an infrastructure problem, not a feature. The 2026 release calendar has since turned that argument into a purchasing decision.

Does giving an agent a formal identity solve the problem?

It solves attribution, which is necessary and not sufficient, and on most stacks it now carries a licensing condition.

Microsoft Entra Agent ID is the most complete implementation shipped: agent identities as purpose-built constructs, agent identity blueprints as templates with parent-child relationships, standard protocols including OAuth 2.0, MCP and A2A, and lifecycle governance with full sign-in and audit logging.

That is the right design, and it reached general availability on 1 May 2026, which means it has been buyable for five months.

The condition is in the licensing.

Agent ID is available to all Microsoft Entra customers, but extending Entra's security features to agents, Conditional Access included, requires Microsoft Agent 365, included with M365 E7 and sold as an add-on to E5, A5 and Business Premium, or to the Defender and Purview suites.

Note how that is metered: Agent 365 requires a licence for each user. The enforcement tier is priced per seat, on a stack whose job is to govern software that does not occupy seats.

Set it beside Uber withholding prevention and the honest generalization is narrow. In both of 2026's most-cited agent-security releases, the tier that blocks is the tier you cannot get for free. That is two cases, not a law.

Identity also answers only the question of who acted. It does not constrain what the agent could reach, which is the firewall and secrets problem, and it does not record what the agent read, which is the SIEM problem.

What does Google's Gemini agent change about the security perimeter?

It moves model selection inside a product, which adds a decision to govern that most threat models do not contain.

Google Cloud introduced Gemini agent at Gemini at Work 2026 on 8 October 2026, described as a universal agent for work. It is in private preview, not generally available; Google's own post states preview status only for the Financial Services and Legal specializations.

Google's own framing is the security-relevant sentence:

"Gemini is the agent, and the model underneath it is a separate choice.

It runs each job on the model that fits best, orchestrating across our Gemini family of models and Claude models from Anthropic today, and other leading private and open models in the future, to deliver optimal quality and lower your costs."

Read that as a security engineer. The agent decides which model receives which job, with which context, at which permission level.

Google's coworker agents also receive their own Workspace account, including an email address on an @agents.company.com domain, a calendar, Drive, and a presence in the company directory. The agent operates across web, mobile, CLI, Google Workspace, Microsoft 365 and Slack.

That is a genuinely useful product and a materially larger surface. The orchestration policy, which decides where your context goes, is configuration inside a service you consume rather than a file in a system you run.

How does ibl.ai put agent security inside the customer's own perimeter?

By shipping the enforcement tier as components you run and own, rather than as a service you call.

With ibl.ai you own all the code and the data.

An agent set to the Virtual Machine Shell sandbox kind runs in a full Linux virtual machine that starts with no network at all, and each agent is assigned one of four egress profiles: No Network, Package Registries, Public Internet, or a Custom Allowlist.

A network policy is a named allowlist an organization admin writes once and reuses.

Entries are exact host:port pairs with no wildcards and at most 100 per policy, and localhost, metadata and instance-data hosts, the .local, .internal and .localhost suffixes and reserved IP ranges are refused outright.

Secrets answer the DLP and secrets-management rows directly. Inside the machine, the environment variable holds a placeholder.

The real value is substituted only on encrypted requests to the hosts that secret is allowed to reach, so the agent can call your API and still cannot print, log or leak your key.

A secret can point at a field of a credential the organization already stores, so rotating it once updates every agent that uses it.

The platform also checks the combination: under a Custom profile, every host a secret may reach must also appear in the agent's own network policy, so a secret can never open a path the policy does not.

These have had their own screens since 2 October 2026, in an organization-wide Virtual Machine settings tab and a Network Access section on each agent's Sandbox tab, with up to 20 secrets per agent.

Creating or changing either is a separate permission that ordinary users do not hold.

On the routing question, LLM gateway unification shipped on 2 October: every endpoint that serves a model, including OpenRouter, Vertex, Foundry, Bedrock and each provider's own API, is a gateway, and a request routes to the highest-priority gateway that can serve it, with your own per-tenant keys preferred over platform keys.

That is the difference the perimeter makes. The routing table is a row in your deployment rather than a policy inside someone else's product.

It is model-agnostic across any LLM, usage-based with no per-seat pricing, and you can deploy anywhere: your own cloud, on-premise, GovCloud, or a fully air-gapped network, where the egress a compromised agent would need does not exist.

1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

ibl.ai is family-owned and operated from New York, NY.


Related reading: AI agent security is an infrastructure problem, not a feature for the structural argument, and the day-one control set for agent governance for what to turn on before the first agent reaches production.

Sources: ADR's expansion, scope and Apache 2.0 license from github.com/uber/ADR, its release date from the repository's sensor-v1.0.0 release, and the deployment and ADR-Bench figures from Uber's MLSys 2026 paper, arXiv:2605.17380; Entra Agent ID's general availability from Microsoft Learn and its protocols and licensing from the product overview; the Gemini agent announcement and quotation from Google Cloud, its private-preview status from 9to5Google; textGrain's mechanism, rollout scope and stated limits from OpenAI's approach to EU text provenance rules and the textGrain paper.

Why does owning the AI stack matter?

ibl.ai is the agentic AI platform where you own all the code and the data. You self-host the entire stack inside your own perimeter, run it model-agnostic across any LLM and switch anytime, and pay by usage with no per-seat pricing β€” so you can deploy anywhere: your cloud, on-premise, GovCloud, or fully air-gapped.

  • You own all the code and the data

    Full source code under a perpetual license, running on your infrastructure. Not API access to someone else's platform β€” the stack itself is yours.

  • Model-agnostic

    Run any LLM β€” Claude, GPT, Gemini, Llama, Command, or your own fine-tune β€” and switch providers without rewriting the platform.

  • No per-seat pricing

    Usage-based billing against a budget cap you set. Cost tracks what your organization actually uses, not how many people you employ.

  • Deploy anywhere

    Your cloud, your VPC, on-premise, GovCloud, or a fully air-gapped network with no outbound connectivity.

1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

ibl.ai is family-owned and operated from New York, NY β€” a U.S.-headquartered, domestically-owned long-term partner, not a vendor that sells licenses and moves on.

Related Articles

Forward-Deployed Engineering: The Four-Layer Agent Stack

In every enterprise agent deployment we have worked on, the same four layers appear: an environment provisioner, an evaluation harness, a governed deployment stack, and simulation. This page publishes them as an ownership checklist β€” which layer you hold, which your vendor holds, and what breaks when the answer is your vendor.

ibl.ai EngineeringSeptember 29, 2026

Agent Governance Moved Into Infrastructure

At VMware Explore on August 31, Broadcom shipped agent governance as infrastructure: AgentMinder authorizes every tool call against an agent's declared mission, and vDefend discovers agents by watching traffic. The thesis is right. The question is whose infrastructure it runs on.

Miguel AmigotAugust 31, 2026

AI Agent Security Is an Infrastructure Problem, Not a Feature

Uber's security lead says securing AI agents is what keeps him up at night, and Google just shipped agent evaluation tooling to production. The tooling layer is maturing; the infrastructure question underneath it is not. This post explains why you cannot fully secure an agent whose reasoning runs on someone else's servers, and gives the five-question perimeter test to run on any agent platform before you sign.

ibl.ai EngineeringAugust 2, 2026

YC Open-Sourced QM: The Harness Became Infrastructure

Y Combinator open-sourced QM on 31 July 2026 under an MIT license, and says it runs the harness internally across four departments β€” not across its portfolio. The substance is scoping.

Miguel AmigotSeptember 21, 2026

See the ibl.ai AI Operating System in Action

Discover how leading universities and organizations are transforming education with the ibl.ai AI Operating System. Explore real-world implementations from Harvard, MIT, Stanford, and users from 400+ institutions worldwide.

View Case Studies
Work with our team

Pilots, deployment, and full ownership

Most enterprise engagements are one-time, not subscriptions. You integrate ibl.ai with your own data, deploy it on your own infrastructure, and the engineering hours scale with the work β€” so the price tracks the scope, not your headcount.

Start here

Pilot

from $15K

fixed scope Β· fixed timeline

A time-boxed proof of value on your real data β€” not a slide deck.

Best for: Teams that want to see ibl.ai working before committing.

  • Deployed on your infrastructure or our cloud
  • 1–2 production agents wired to a slice of your data
  • One integration (LMS / SIS / SSO / data source)
  • Weekly working sessions with our engineers
  • Pilot fee credits toward a full engagement
Scope a pilot
Most common

Integration & Deployment

$25K – $80K

one-time Β· not a subscription

Full deployment integrated with your data and systems. Engineering hours scale with scope.

Best for: Organizations rolling ibl.ai out across a department, campus, or business unit.

  • Platform deployed in your VPC, on-prem, or air-gapped
  • Integrated with your data + identity (SSO / SAML)
  • Multiple custom agents built to your workflows
  • Engineering hours proportional to scope
  • You own the data Β· run any LLM you choose
Plan a deployment
Full ownership

Codebase Transfer + Custom AI Engineering

Custom quote

perpetual license Β· you own the stack

We transfer the full source code. You own and self-host the entire platform β€” outright.

Best for: Organizations and enterprises that benefit from perpetual ownership and sovereignty.

  • Complete source-code transfer + perpetual license
  • Dedicated AI engineering team on your roadmap
  • Custom agents, models, and integrations to spec
  • Air-gapped capable Β· zero vendor lock-in
  • Family-owned, New York–based long-term partner
Talk about ownership
You own the code and data Run any LLM β€” Claude, GPT, Gemini, Llama Family-owned & operated from New York, NY