AINewsnow

Your AGENTS.md Is Not a Security Control

This story is from 2026-09-08. It is preserved in the archive; the latest stories are on the live feed.

Originally published at webofmike.com on 2026-09-04. The demo repo and every command in it were run before publishing. An agent with a policy file that says "you must not delete customer records", running behind an approval layer that denylists the delete tool, destroyed all five customer records a…

Read the full story at DEV Community — AI ↗

Timeline · 1 report

  1. 2026-09-08 19:54 · DEV Community — AI
    Your AGENTS.md Is Not a Security Control

More stories

  1. Introducing Kimi K3 on Amazon Bedrock — AWS Machine Learning Blog
  2. Introducing Amazon SageMaker HyperPod Inference Gateway — AWS Machine Learning Blog
  3. Anthropic, OpenAI, SpaceXAI, Google sued over call to ‘pace’ AI development — Politico Technology
  4. Gemini Hacked Three Companies in First Known Breakout by Google’s AI — Wall Street Journal Technology
  5. Alibaba ships Qwen3.8-Omni-Flash to watch, listen and call tools — r/LocalLLM
  6. NVIDIA CEO Jensen Huang rejects ‘AI will end the world’ claim, yet cautions ‘we should go as fast as we can but...’ — Mint AI
  7. Meet the Data Agent in ChatGPT Work — OpenAI YouTube
  8. AI hallucination of Chinese nuclear components almost led to US military attack — Ars Technica AI

Get the daily brief of stories like this at 6:30 every morning →