The Short Answer
AI agent security became shipped infrastructure over five months of 2026, not in a single week: Microsoft's Entra Agent ID reached general availability on 1 May, Uber open-sourced its ADR detection system on 31 July, and Google previewed its Gemini agent on 8 October. The enforcement tier is the part vendors withhold or license, which is why on ibl.ai you own all the code and the data.
The circulating version of this story compresses all of it into one dramatic week. The dates do not support that, and the real timeline carries a better warning.
Capability did not outrun governance by a few days. The controls have been available for months, and most organizations have deployed none of them.
When did AI agent security actually become shipped infrastructure?
Between May and October 2026, in four separate releases that are usually reported as one.
| Date | What shipped | Status |
|---|---|---|
| 1 May 2026 | Microsoft Entra Agent ID, identity and access management for agents | Generally available |
| 31 July 2026 | Uber ADR, Agentic AI Detection and Response | Open source, Apache 2.0 |
| 5 October 2026 | OpenAI textGrain, statistical watermarking of generated text | API opt-in live; EU rollout in progress |
| 8 October 2026 | Google Gemini agent, a universal agent for work | Private preview |
Only the last two are genuinely this week's news. Microsoft Entra Agent ID reached general availability in May, after a public preview announced a year earlier.
Uber's ADR was open-sourced at the end of July, and its research paper was submitted in May.
If a vendor tells you agent security is a problem that emerged last week, they are describing their own product calendar rather than yours.
What is Uber's ADR, and what did Uber not open-source?
ADR stands for Agentic AI Detection and Response, and the part Uber kept back is the part that stops an agent.
The repository describes it as an enterprise security system for AI agents, covering employee-facing agents such as Cursor, Claude Code, Codex and GitHub Copilot CLI, and also customer-facing agents such as AI support agents. It is released under Apache 2.0.
The scale in Uber's MLSys 2026 industry-track paper is what makes it worth reading rather than admiring: deployment across 7,200+ hosts, 10,000+ agent sessions daily, and an ADR-Bench evaluation spanning 302 tasks, 17 attack techniques and 133 MCP servers.
On ADR-Bench the paper reports 67% attack detection with zero false positives.
Separately, from the ten-month production deployment rather than the benchmark, it reports 97.2% precision on credential detection across 206 detected credentials, a figure belonging to the prevention layer.
Note the shape of those numbers. Two thirds of attacks detected is a real result for a young discipline, and it is also a third of attacks missed.
Now the withheld tier. The repository publishes ADR Discovery, the ADR Sensor, ADR-Bench and the ADR Detector. Prevention is absent, and so is the offline ADR Explorer engine, which the README describes as hardening detection through pre-deployment red teaming.
So the published system finds agents on your network, watches what they do, scores itself against a benchmark, and flags risky behavior. The component that blocks the action stayed inside Uber, along with the engine used to harden the detector.
That is not a criticism of Uber, which published more than anyone else has. It is the pattern worth naming: detection gets published, enforcement does not.
Why do existing security controls fail on AI agents?
Because every one of them encodes an assumption about a human user, and an agent violates a different assumption in each case.
This is the mapping that matters more than any single product announcement.
| Control | What it assumes about the user | What an agent does instead | What has to replace it |
|---|---|---|---|
| IAM | A person holds a role and reaches resources | Chains tools in an order nobody granted | An identity scoped to actions, not only resources |
| SIEM | Logins, file access, network connections | Tool calls and reasoning steps | Per-run traces recording retrieved context, not just the result |
| Firewall | Traffic shaped by human-paced apps | Direct API calls at machine speed | Deny-by-default egress, allowlisted per agent |
| DLP | Someone copies a file | Summarizes the file and passes the summary onward | Limits on where context may travel, not on file movement |
| Secrets management | A person is trusted to hold a key | Can print anything in its own environment | Keys the agent can call with but never read |
The DLP row is the one most teams underestimate. An agent that reasons over a sensitive document and passes a summary to the next tool has moved the information without moving the file, so a control watching file movement sees nothing.
We argued the structural version of this case in AI agent security is an infrastructure problem, not a feature. The 2026 release calendar has since turned that argument into a purchasing decision.
Does giving an agent a formal identity solve the problem?
It solves attribution, which is necessary and not sufficient, and on most stacks it now carries a licensing condition.
Microsoft Entra Agent ID is the most complete implementation shipped: agent identities as purpose-built constructs, agent identity blueprints as templates with parent-child relationships, standard protocols including OAuth 2.0, MCP and A2A, and lifecycle governance with full sign-in and audit logging.
That is the right design, and it reached general availability on 1 May 2026, which means it has been buyable for five months.
The condition is in the licensing.
Agent ID is available to all Microsoft Entra customers, but extending Entra's security features to agents, Conditional Access included, requires Microsoft Agent 365, included with M365 E7 and sold as an add-on to E5, A5 and Business Premium, or to the Defender and Purview suites.
Note how that is metered: Agent 365 requires a licence for each user. The enforcement tier is priced per seat, on a stack whose job is to govern software that does not occupy seats.
Set it beside Uber withholding prevention and the honest generalization is narrow. In both of 2026's most-cited agent-security releases, the tier that blocks is the tier you cannot get for free. That is two cases, not a law.
Identity also answers only the question of who acted. It does not constrain what the agent could reach, which is the firewall and secrets problem, and it does not record what the agent read, which is the SIEM problem.
What does Google's Gemini agent change about the security perimeter?
It moves model selection inside a product, which adds a decision to govern that most threat models do not contain.
Google Cloud introduced Gemini agent at Gemini at Work 2026 on 8 October 2026, described as a universal agent for work. It is in private preview, not generally available; Google's own post states preview status only for the Financial Services and Legal specializations.
Google's own framing is the security-relevant sentence:
"Gemini is the agent, and the model underneath it is a separate choice.
It runs each job on the model that fits best, orchestrating across our Gemini family of models and Claude models from Anthropic today, and other leading private and open models in the future, to deliver optimal quality and lower your costs."
Read that as a security engineer. The agent decides which model receives which job, with which context, at which permission level.
Google's coworker agents also receive their own Workspace account, including an email address on an @agents.company.com domain, a calendar, Drive, and a presence in the company directory. The agent operates across web, mobile, CLI, Google Workspace, Microsoft 365 and Slack.
That is a genuinely useful product and a materially larger surface. The orchestration policy, which decides where your context goes, is configuration inside a service you consume rather than a file in a system you run.
How does ibl.ai put agent security inside the customer's own perimeter?
By shipping the enforcement tier as components you run and own, rather than as a service you call.
With ibl.ai you own all the code and the data.
An agent set to the Virtual Machine Shell sandbox kind runs in a full Linux virtual machine that starts with no network at all, and each agent is assigned one of four egress profiles: No Network, Package Registries, Public Internet, or a Custom Allowlist.
A network policy is a named allowlist an organization admin writes once and reuses.
Entries are exact host:port pairs with no wildcards and at most 100 per policy, and localhost, metadata and instance-data hosts, the .local, .internal and .localhost suffixes and reserved IP ranges are refused outright.
Secrets answer the DLP and secrets-management rows directly. Inside the machine, the environment variable holds a placeholder.
The real value is substituted only on encrypted requests to the hosts that secret is allowed to reach, so the agent can call your API and still cannot print, log or leak your key.
A secret can point at a field of a credential the organization already stores, so rotating it once updates every agent that uses it.
The platform also checks the combination: under a Custom profile, every host a secret may reach must also appear in the agent's own network policy, so a secret can never open a path the policy does not.
These have had their own screens since 2 October 2026, in an organization-wide Virtual Machine settings tab and a Network Access section on each agent's Sandbox tab, with up to 20 secrets per agent.
Creating or changing either is a separate permission that ordinary users do not hold.
On the routing question, LLM gateway unification shipped on 2 October: every endpoint that serves a model, including OpenRouter, Vertex, Foundry, Bedrock and each provider's own API, is a gateway, and a request routes to the highest-priority gateway that can serve it, with your own per-tenant keys preferred over platform keys.
That is the difference the perimeter makes. The routing table is a row in your deployment rather than a policy inside someone else's product.
It is model-agnostic across any LLM, usage-based with no per-seat pricing, and you can deploy anywhere: your own cloud, on-premise, GovCloud, or a fully air-gapped network, where the egress a compromised agent would need does not exist.
1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.
ibl.ai is family-owned and operated from New York, NY.
Related reading: AI agent security is an infrastructure problem, not a feature for the structural argument, and the day-one control set for agent governance for what to turn on before the first agent reaches production.
Sources: ADR's expansion, scope and Apache 2.0 license from github.com/uber/ADR, its release date from the repository's sensor-v1.0.0 release, and the deployment and ADR-Bench figures from Uber's MLSys 2026 paper, arXiv:2605.17380; Entra Agent ID's general availability from Microsoft Learn and its protocols and licensing from the product overview; the Gemini agent announcement and quotation from Google Cloud, its private-preview status from 9to5Google; textGrain's mechanism, rollout scope and stated limits from OpenAI's approach to EU text provenance rules and the textGrain paper.