Reading view
Let Experts Feel Uncertainty: A Multi-Expert Label Distribution Approach to Probabilistic Time Series Forecasting
From Data to Behavior: Predicting Unintended Model Behaviors Before Training
Contrastive Continual Learning for Model Adaptability in Internet of Things
Toward Multiphysics-Informed Machine Learning for Sustainable Data Center Operations: Intelligence Evolution with Deployable Solutions for Computing Infrastructure
DISCOVER: Identifying Patterns of Daily Living in Human Activities from Smart Home Data
From guardrails to governance: A CEO’s guide for securing agentic systems
The previous article in this series, “Rules fail at the prompt, succeed at the boundary,” focused on the first AI-orchestrated espionage campaign and the failure of prompt-level control. This article is the prescription. The question every CEO is now getting from their board is some version of: What do we do about agent risk?

Across recent AI security guidance from standards bodies, regulators, and major providers, a simple idea keeps repeating: treat agents like powerful, semi-autonomous users, and enforce rules at the boundaries where they touch identity, tools, data, and outputs.
The following is an actionable eight-step plan one can ask teams to implement and report against:

Constrain capabilities
These steps help define identity and limit capabilities.
1. Identity and scope: Make agents real users with narrow jobs
Today, agents run under vague, over-privileged service identities. The fix is straightforward: treat each agent as a non-human principal with the same discipline applied to employees.
Every agent should run as the requesting user in the correct tenant, with permissions constrained to that user’s role and geography. Prohibit cross-tenant on-behalf-of shortcuts. Anything high-impact should require explicit human approval with a recorded rationale. That is how Google’s Secure AI Framework (SAIF) and NIST AI’s access-control guidance are meant to be applied in practice.
The CEO question: Can we show, today, a list of our agents and exactly what each is allowed to do?
2. Tooling control: Pin, approve, and bound what agents can use
The Anthropic espionage framework worked because the attackers could wire Claude into a flexible suite of tools (e.g., scanners, exploit frameworks, data parsers) through Model Context Protocol, and those tools weren’t pinned or policy-gated.
The defense is to treat toolchains like a supply chain:
- Pin versions of remote tool servers.
- Require approvals for adding new tools, scopes, or data sources.
- Forbid automatic tool-chaining unless a policy explicitly allows it.
This is exactly what OWASP flags under excessive agency and what it recommends protecting against. Under the EU AI Act, designing for such cyber-resilience and misuse resistance is part of the Article 15 obligation to ensure robustness and cybersecurity.
The CEO question: Who signs off when an agent gains a new tool or a broader scope? How does one know?
3. Permissions by design: Bind tools to tasks, not to models
A common anti-pattern is to give the model a long-lived credential and hope prompts keep it polite. SAIF and NIST argue the opposite: credentials and scopes should be bound to tools and tasks, rotated regularly, and auditable. Agents then request narrowly scoped capabilities through those tools.
In practice, that looks like: “finance-ops-agent may read, but not write, certain ledgers without CFO approval.”
The CEO question: Can we revoke a specific capability from an agent without re-architecting the whole system?
Control data and behavior
These steps gate inputs, outputs, and constrain behavior.
4. Inputs, memory, and RAG: Treat external content as hostile until proven otherwise
Most agent incidents start with sneaky data: a poisoned web page, PDF, email, or repository that smuggles adversarial instructions into the system. OWASP’s prompt-injection cheat sheet and OpenAI’s own guidance both insist on strict separation of system instructions from user content and on treating unvetted retrieval sources as untrusted.
Operationally, gate before anything enters retrieval or long-term memory: new sources are reviewed, tagged, and onboarded; persistent memory is disabled when untrusted context is present; provenance is attached to each chunk.
The CEO question: Can we enumerate every external content source our agents learn from, and who approved them?
5. Output handling and rendering: Nothing executes “just because the model said so”
In the Anthropic case, AI-generated exploit code and credential dumps flowed straight into action. Any output that can cause a side effect needs a validator between the agent and the real world. OWASP’s insecure output handling category is explicit on this point, as are browser security best practices around origin boundaries.
The CEO question: Where, in our architecture, are agent outputs assessed before they run or ship to customers?
6. Data privacy at runtime: Protect the data first, then the model
Protect the data such that there is nothing dangerous to reveal by default. NIST and SAIF both lean toward “secure-by-default” designs where sensitive values are tokenized or masked and only re-hydrated for authorized users and use cases.
In agentic systems, that means policy-controlled detokenization at the output boundary and logging every reveal. If an agent is fully compromised, the blast radius is bounded by what the policy lets it see.
This is where the AI stack intersects not just with the EU AI Act but with GDPR and sector-specific regimes. The EU AI Act expects providers and deployers to manage AI-specific risk; runtime tokenization and policy-gated reveal are strong evidence that one is actively controlling those risks in production.
The CEO question: When our agents touch regulated data, is that protection enforced by architecture or by promises?
Prove governance and resilience
For the final steps, it’s important to show controls work and keep working.
7. Continuous evaluation: Don’t ship a one-time test, ship a test harness
Anthropic’s research about sleeper agents should eliminate all fantasies about single test dreams and show how critical continuous evaluation is. This means instrumenting agents with deep observability, regularly red teaming with adversarial test suites, and backing everything with robust logging and evidence, so failures become both regression tests and enforceable policy updates.
The CEO question: Who works to break our agents every week, and how do their findings change policy?
8. Governance, inventory, and audit: Keep score in one place
AI security frameworks emphasize inventory and evidence: enterprises must know which models, prompts, tools, datasets, and vector stores they have, who owns them, and what decisions were taken about risk.
For agents, that means a living catalog and unified logs:
- Which agents exist, on which platforms
- What scopes, tools, and data each is allowed
- Every approval, detokenization, and high-impact action, with who approved it and when
The CEO question: If asked how an agent made a specific decision, could we reconstruct the chain?
And don’t forget the system-level threat model: assume the threat actor GTG-1002 is already in your enterprise. To complete enterprise preparedness, zoom out and consider the MITRE ATLAS product, which exists precisely because adversaries attack systems, not models. Anthropic provides a case study of a state-based threat actor (GTG-1002) doing exactly that with an agentic framework.
Taken together, these controls do not make agents magically safe. They do something more familiar and more reliable: they put AI, its access, and actions back inside the same security frame used for any powerful user or system.
For boards and CEOs, the question is no longer “Do we have good AI guardrails?” It’s: Can we answer the CEO questions above with evidence, not assurances?
This content was produced by Protegrity. It was not written by MIT Technology Review’s editorial staff.
Phenome-wide analysis of copy number variants in 470,727 UK Biobank genomes
Nature, Published online: 04 February 2026; doi:10.1038/s41586-025-10087-x
A multiancestry phenome-wide analysis of copy number variants in the UK Biobank genomes increases power to detect genetic associations with complex traits across human populations.‘It means I can sleep at night’: how sensors are helping to solve scientists’ problems
Nature, Published online: 04 February 2026; doi:10.1038/d41586-026-00212-9
Continual automated data collection was once possible only for the world’s richest labs. Now, sensor systems are commonplace and can be accessed from an app.Whose ethics govern global health research?
Nature Medicine, Published online: 04 February 2026; doi:10.1038/d41591-026-00007-5
Ethical research must not exploit scarcity as an experimental variable.Extrachromosomal DNA drives molecular and clinical heterogeneity in hepatocellular carcinoma: a multi-omics analysis and prognostic model development
Hum Genomics. 2026 Feb 3. doi: 10.1186/s40246-026-00927-w. Online ahead of print.
ABSTRACT
BACKGROUND: Extrachromosomal DNA (ecDNA) is an emerging hallmark of cancer that promotes tumor evolution and heterogeneity. However, the molecular characteristics and clinical significance of ecDNA in hepatocellular carcinoma (HCC) remain incompletely understood.
METHODS: The clinical outcomes, genomics, transcriptomics, proteomics, tumor microenvironment, and drug target landscapes of ecDNA-negative and ecDNA-positive HCC in the Cancer Genome Atlas (TCGA) were compared. Next, the least absolute shrinkage and selection operator (LASSO) and random survival forest (RSF) algorithms were used to screen the ecDNA gene signature. A nomogram was constructed and evaluated based on the risk score and clinicopathological features. Finally, the role of DNASE1L3 was validated through in vitro experiments.
RESULTS: EcDNA-positive tumors showed increased vascular invasion, higher AFP levels, and more TP53 mutations. These tumors displayed unique activation of proliferation pathways, decreased stromal infiltration, and heightened immune activation. Our validated six-gene signature (RNF186, BMP6, AOC1, FBLL1, MYBL2, and DNASE1L3) demonstrated strong prognostic value when combined with tumor stage in the nomogram. Notably, DNASE1L3 was downregulated in HCC, showed endothelial cell-specific expression, and suppressed the proliferation and migration of Hep3B2.1-7 cells.
CONCLUSION: Our study characterizes the molecular and clinical distinctions between ecDNA-negative and ecDNA-positive HCC and establishes a clinically applicable gene signature for patient prognosis. These findings advance our understanding of ecDNA-driven tumor heterogeneity and provide potential strategies for personalized HCC management.
PMID:41634868 | DOI:10.1186/s40246-026-00927-w
How Cisco builds smart systems for the AI era
Among the big players in technology, Cisco is one of the sector’s leaders that’s advancing operational deployments of AI internally to its own operations, and the tools it sells to its customers around the world. As a large company, its activities encompass many areas of the typical IT stack, including infrastructure, services, security, and the design of entire enterprise-scale networks.
Cisco’s internal teams use a blend of machine learning and agentic AI to help them improve their own service delivery and personalise user experiences for its customers. It’s built a shared AI fabric built on patterns of compute and networking that are the product of years spent checking and validating its systems – battle-hardened solutions it then has the confidence to offer to customers. The infrastructure in play relies on high-performance GPUs, of course, but it’s not just raw horse-power. The detail is in the careful integration between compute and network stacks used in model training and the quite different demands from the ongoing load of inference.
Having made its name as the de facto supplier of networking infrastructure for the enterprise, it comes as no shock that it’s in network automation that some of its better-known uses of AI finds their place. Automated configuration workflows and identity management combine into access solutions that are focused on rapid network deployments generated by natural language.
For organisations looking to develop into the next generation of AI users, Cisco has been rolling out hardware and orchestration tools that are aimed explicitly to support AI workloads. A recent collaboration with chip giant NVIDIA led to the emergence of a new line of switches and the Nexus Hyperfabric line of AI network controllers. These aim to simplify the deployment of the complex clusters needed for top-end, high-performance artificial intelligence clusters.
Cisco’s Secure AI Factory framework with partners like NVIDIA and Run:ai is aimed at production-grade AI pipelines. It uses distributed orchestration, GPU utilisation governance, Kubernetes microservice optimisation, and storage, under the umbrella product description Intersight. For more local deployments, Cisco Unified Edge brings all the necessary elements – compute, networking, security, and storage – close to where data gets generated and processed.
In environments where latency metrics are critically important, AI processing at the edge is the answer. But Cisco’s approach is not necessarily to offer dedicated IIoT-specific solutions. Instead, it tries to extend the operational models typically found in a data centre and applies the same technology (if not the same exact methodology) to edge sites. It’s like data centre-grade security policies and configurations available to remote installations. Having the same precepts and standards in cloud and edge mean that Cisco accredited engineers can manage and maintain data centres or small edge deployments using the same skills, accreditation, knowledge, and experience.
Security and risk management figure prominently in the Cisco AI narrative. Its Integrated AI Security and Safety Framework applies high standards of safety and security throughout the life-cycle of AI systems. It considers adversarial threats, supply chain weakness, the risk profiles of multi-agent interactions, and multi-modal vulnerabilities as issues that have to be addressed regardless of the nature or size of any deployment.
Cisco’s work on operational AI also reflects broader ecosystem conversations. The company markets products for organisations wanting to make the transition from generative to agentic AI, where autonomous software agents carry out operational tasks. In most cases, this requires new tooling and new operational protocols.
Cisco’s future AI plans include continuing its central work in infrastructure provision for AI workloads. It’s also pursuing broader adoption of AI-ready networks, including next-gen wireless and unified management systems that will control systems across campus, branch, and cloud environments. The company is also expanding its software and platform investments, including its most recent acquisition (NeuralFabric), to help it build a more comprehensive software stack and product portfolio.
In summary, Cisco’s AI deployment strategy combines hardware, software, and service elements that embed AI into operations, giving organisations a route to production-grade systems. Its work can be found in large-scale infrastructure, systems for unified management, risk mitigation, and anywhere that connects distributed, cloud, and edge computing.
(Image source: Pixabay)
Want to learn more about AI and big data from industry leaders? Check out AI & Big Data Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and co-located with other leading technology events. Click here for more information.
AI News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.
The post How Cisco builds smart systems for the AI era appeared first on AI News.
Trustworthy Blockchain-based Federated Learning for Electronic Health Records: Securing Participant Identity with Decentralized Identifiers and Verifiable Credentials
Intelligent Front-End Personalization: AI-Driven UI Adaptation
Lotus Health nabs $35M for AI doctor that sees patients for free
STAT+: AI doctors are coming. Should FDA make sure they’re safe?
When is an AI doctor a medical device?
Call it a sign of things to come. A startup called Doctronic made a splash recently when it announced the use AI to renew prescriptions without clinician input in the state of Utah. Something didn’t sit right with me about the announcement. Sure it got approval from Utah, but why isn’t it a medical device subject to Food and Drug Administration review? The company claimed it was “the practice of medicine” and so exempt from FDA authority. That didn’t seem entirely right either.
So I did some asking around and after talking to over a dozen executives, legal scholars, and policy experts, it turns out the question is not nearly as clear-cut as Doctronic would have us believe. Indeed, it appears the company may be planning to market a medical device without authorization. In my story, I explain the law and why it all matters.
Continue to STAT+ to read the full story…


© Adobe
STAT+: AI could soon renew prescriptions without clinician help. Should the FDA make sure it’s safe?
Utah’s recent announcement that it was partnering with a health tech startup that will use artificial intelligence to renew drug prescriptions may offer a glimpse of the futuristic version of AI medicine that’s long been foretold by technologists and venture capitalists.
But it’s only possible because of some pre-approved rule breaking — and may prove a broader test of the Food and Drug Administration’s authority to evaluate a new wave of clinical AI products, according to interviews with executives and experts.
In January, Utah regulators said they had signed an agreement with a startup called Doctronic to launch an AI system that will perform a clinical evaluation of patients and, when deemed appropriate, renew some 200 common medications autonomously.
Continue to STAT+ to read the full story…


© Illustration: Camille MacMillin/STAT; Photos: Adobe
Digital intervention <i>mylovia</i> improves sexual functioning in women with sexual dysfunction in randomized controlled trial
npj Digital Medicine, Published online: 03 February 2026; doi:10.1038/s41746-026-02385-z
Digital intervention mylovia improves sexual functioning in women with sexual dysfunction in randomized controlled trialBarriers to Digital Health Adoption in Older Adults: Scoping Review Informed by Innovation Resistance Theory
Integrative proteogenomics maps multifactorial aetiology, progression and therapeutic vulnerabilities in gastric cancer
Gut. 2026 Jan 30:gutjnl-2025-337247. doi: 10.1136/gutjnl-2025-337247. Online ahead of print.
ABSTRACT
BACKGROUND: Gastric cancer, with disproportionately higher incidence in East Asia, arises from complex host-microbiome-environment interactions beyond Helicobacter pylori (HP) infection. However, the molecular architecture linking environmental carcinogens, microbial succession and host response remains unclear.
OBJECTIVE: To delineate multifactorial aetiologies and clinically actionable subtypes/biomarkers of gastric cancer through integrative proteogenomic, microbial and environmental exposure profiling.
DESIGN: We established a multiomics atlas of paired tumour, adjacent mucosa tissues and blood from 154 treatment-naïve Taiwanese patients, integrating whole-exome sequencing, RNA-seq, proteome and phosphoproteome profiling with carcinogen signatures, HP status, microbiome composition and refined anatomical mapping. Cell-based functional assays tested carcinogen effects. Microbial subtype was assessed in an independent cohort.
RESULTS: A polycyclic-aromatic-hydrocarbon signature, dibenz[a,h]acridine, emerged as a high-risk exposure promoting invasion, immune suppression and poor survival, significantly exceeding nitrosamine-linked risk in this cohort. Multilayer integration defined three initiation ecologies: HP-driven inflammatory, non-HP microbiome-enriched immune-silent and HP-free microbially depleted states. Among HP-negative tumours, a Streptococcus-enriched subtype associated with tight-junction (CLDN18.2/ZO-1/OCLN) disruption and epithelial-mesenchymal transition, whereas a subset of clinically aggressive cases retained CLDN18.2-high epithelial-stable subtype for therapeutic accessibility. An independent cohort revealed gastric juice-derived Streptococcus anginosus abundance inversely correlated with tight-junction proteins. Anatomical mapping reveals location-specific, sex-specific, subtype-specific oncogenic networks and kinase activity, including CDK4 activation in clinical biomarker-negative tumours. Decision-tree models combining exposure and proteome-immune states refined recurrence and survival prediction beyond stage.
CONCLUSION: This proteogenomic framework defines exposure-informed and microbiome-informed gastric cancer subtypes, providing a molecular schema for patient stratification, prevention and actionable therapeutic vulnerabilities.
PMID:41617485 | DOI:10.1136/gutjnl-2025-337247
