Chem Biol Interact. 2026 Feb 7:111952. doi: 10.1016/j.cbi.2026.111952. Online ahead of print.
ABSTRACT
The scarcity of reliable biomarkers and predictive models for platinum resistance in lung adenocarcinoma (LUAD) poses a significant clinical challenge. This study endeavors to identify molecular subtypes related to platinum resistance and construct a robust predictive model through multi-omics techniques. We performed integrative analysis of public datasets using advanced bioinformatics strategies, including spatial transcriptome deconvolution and consensus clustering. Bulk RNA deconvolution analysis was conducted to characterize tumor microenvironment heterogeneity. Feature selection was performed using the Supervised Principal Component (SuperPC) algorithm, followed by diagnostic model construction validated through receiver operating characteristic (ROC) analysis. Functional validation was performed through cytological experiments measuring cisplatin IC50 alterations following gene manipulation in LUAD cell lines. Consensus clustering revealed distinct LUAD subtypes, with Cluster1 demonstrating significant platinum resistance. We first subtyped the patients in the bulk transcriptome data based on consistency clustering, and then analyzed the differences between different platinum-resistant subtypes (Cluster 1 and Cluster 2), so as to screen 333 isotype-specific differentially expressed genes and 15 platinum resistance-related (PRR) genes were selected through machine learning. A refined 5-gene signature (ANKRD29/CACNA2D2/DSP/HSD17B6/SPP1) achieved exceptional predictive performance (AUC=0.9639). Spatial transcriptomics demonstrated compartmentalized expression patterns: SPP1/DSP localized to tumor niches, HSD17B6/CACNA2D2 to epithelial regions, and ANKRD29 depletion in stromal areas. Cellular colocalization analysis revealed malignant epithelial PH proximity to myeloid and mast cells. Functional validation confirmed that ANKRD29/CACNA2D2 overexpression sensitized A549/DDP cells to cisplatin, while DSP/SPP1/HSD17B6 overexpression induced resistance. Experiments in nude mice have shown that these genes are closely related to cisplatin resistance in LUAD. This study identifies the Cluster1 subtype and malignant epithelial PH as crucial determinants of platinum resistance in LUAD. Our innovative 5-gene predictive model exhibits clinical-grade diagnostic accuracy, and spatial transcriptomic characterization offers mechanistic insights into the dynamics of the tumor microenvironment.
Background: Since their introduction with the Digital Care Act in 2019, DiGA are a part of the German statutory healthcare system. In order to become a DiGA, mHealth apps have to complete a certification process covering both technical and evidence related aspects. After completion, DiGA are added to the DiGA-directory, containing a list of all reimbursable DiGA within German statutory health insurance (SHI). The first apps were added at the end of 2020 with the number steadily increasing. The novelty of the introduction leads to problems and barriers to optimal use along the way, which is studied from different stakeholder perspectives in this research article. Objective: The aim of the survey was to identify problems and barriers in the context of certification, financing and use of DiGA in Germany. Methods: We used semi-structured expert interviews to evaluate the perspective of stakeholders of the German healthcare system on DiGA. The interview guide was developed according to Helfferich, the interviews were transcribed and analyzed using the qualitative content approach by Mayring and Kuckartz. Results: We identified problems from stakeholder perspectives regarding the certification/admission, financing and service distribution regarding DiGA. The interviewed stakeholders reported problems with authorization of DiGA and the corresponding process. DiGA prices and the different negotiation positions were criticized, as well as financial challenges for smaller DiGA-manufacturers. Within service provision, technical problems, e. g., with activation codes or software surrounding DiGA-prescription were mentioned. Problems were also seen in insufficient knowledge and skills on the side of the patients as well as the medical providers. Conclusions: mHealth applications provide potentially disruptive innovations within the healthcare sector. Nevertheless, since the evidence-based and regulated use of this technology is relatively new there are still problems and barriers limiting the optimized, patient-centered use. This study provides an overview of problems in the context of DiGA in Germany from the stakeholder perspective. Since other countries showed interest in potentially adopting the German system, valuable implications can be drawn from this survey.
Phenomics. 2025 Dec 15;5(5):469-486. doi: 10.1007/s43657-024-00188-4. eCollection 2025 Oct.
ABSTRACT
Quantifying individual health status from increasingly accumulated omics data is essential for both early prevention and intervention of diseases, which attracts great attention from communities of biology and medicine. Most of the existing approaches mainly classify individuals into different catalogues or classes based on phenotypes and biomarkers. However, an individual's health status from a dynamical systems viewpoint can be viewed as a non-equilibrium steady state, which can generally be characterized by two key features, i.e. (1) homeostatic potential that represents the ability of homeostatic resilience to withstand perturbations or maintain functions at the current state/phenotype of this individual and (2) phenotypic potential that represents the state/phenotype of the individual on the whole process from health to disease. Here, we proposed a health state manifold (HSM) method derived from dynamic network biomarker method and diffusion map theory to quantify individual health status with the characterization of such two features in a robust and accurate manner based on multi-omics data. To verify our method, HSM method was applied to the quantification of diabetes mellitus (rat subjects) and the Roux-en-Y Gastric Bypass (human subjects) for both disease progression process and recovery process, which demonstrated its effectiveness and potential for personalized medicine and preventive medicine.
SUPPLEMENTARY INFORMATION: The online version contains supplementary material available at 10.1007/s43657-024-00188-4.
Cancer Res. 2026 Feb 9. doi: 10.1158/0008-5472.CAN-25-2854. Online ahead of print.
ABSTRACT
Pancreatic ductal adenocarcinoma (PDAC) patients with diabetes mellitus (DM) exhibit poor clinical outcomes. Metabolic reprogramming of both cancer cells and immune compartments plays a crucial role in shaping the anti-tumor immune response in PDAC. DM-induced metabolic alteration may disrupt the intricate crosstalk between immune cells and tumor-associated immune factors, profoundly influencing PDAC progression. Here, we performed an integrated, spatially resolved multi-omics study to investigate DM-associated, cell-specific metabolic remodeling within the PDAC tumor microenvironment. DM influenced interactions between tumor cells and immune cells, which accelerated PDAC growth in both humans and mice. PDAC patients with DM exhibited higher tumor-stage, poorer differentiation, and worse outcomes. Spatial metabolic and transcriptional profiling revealed that SREBP2-dependent cholesterol biosynthesis exacerbated PDAC progression. Increased cholesterol biosynthesis promoted neutrophil recruitment and accelerated formation of neutrophil extracellular traps (NETs) by stimulating the CXCL1-CXCR1/CXCR2 signaling axis, ultimately promoting PDAC growth. Inhibition of SREBP2, pharmacological blockade of CXCL1, or perturbation of NETs markedly reduced PDAC growth in diabetic mouse models. Together, these multi-omics analyses and follow-up mechanistic studies constitute an integrated approach that elucidates a metabolic mechanism by which diabetes promotes PDAC development by remodeling the tumor immune microenvironment and highlights a potential therapeutic strategy for PDAC with DM.
arXiv:2602.06390v1 Announce Type: cross
Abstract: Synthetic tabular data enables sharing and analysis of sensitive records, but its practical deployment requires balancing distributional fidelity, downstream utility, and privacy protection. We study a simple, model agnostic post processing framework that can be applied on top of any synthetic data generator to improve this trade off. First, a mode patching step repairs categories that are missing or severely underrepresented in the synthetic data, while largely preserving learned dependencies. Second, a k nearest neighbor filter replaces synthetic records that lie too close to real data points, enforcing a minimum distance between real and synthetic samples. We instantiate this framework for two neural generative models for tabular data, a feed forward generator and a variational autoencoder, and evaluate it on three public datasets covering credit card transactions, cardiovascular health, and census based income. We assess marginal and joint distributional similarity, the performance of models trained on synthetic data and evaluated on real data, and several empirical privacy indicators, including nearest neighbor distances and attribute inference attacks. With moderate thresholds between 0.2 and 0.35, the post processing reduces divergence between real and synthetic categorical distributions by up to 36 percent and improves a combined measure of pairwise dependence preservation by 10 to 14 percent, while keeping downstream predictive performance within about 1 percent of the unprocessed baseline. At the same time, distance based privacy indicators improve and the success rate of attribute inference attacks remains largely unchanged. These results provide practical guidance for selecting thresholds and applying post hoc repairs to improve the quality and empirical privacy of synthetic tabular data, while complementing approaches that provide formal differential privacy guarantees.
arXiv:2601.18226v2 Announce Type: replace
Abstract: Conventional agent systems often struggle in open-ended environments where task distributions continuously drift and external supervision is scarce. Their reliance on static toolsets or offline training lags behind these dynamics, leaving the system's capability boundaries rigid and unknown. To address this, we propose the In-Situ Self-Evolving paradigm. This approach treats sequential task interactions as a continuous stream of experience, enabling the system to distill short-term execution feedback into long-term, reusable capabilities without access to ground-truth labels. Within this framework, we identify tool evolution as the critical pathway for capability expansion, which provides verifiable, binary feedback signals. Within this framework, we develop Yunjue Agent, a system that iteratively synthesizes, optimizes, and reuses tools to navigate emerging challenges. To optimize evolutionary efficiency, we further introduce a Parallel Batch Evolution strategy. Empirical evaluations across five diverse benchmarks under a zero-start setting demonstrate significant performance gains over proprietary baselines. Additionally, complementary warm-start evaluations confirm that the accumulated general knowledge can be seamlessly transferred to novel domains. Finally, we propose a novel metric to monitor evolution convergence, serving as a function analogous to training loss in conventional optimization. We open-source our codebase, system traces, and evolved tools to facilitate future research in resilient, self-evolving intelligence.
arXiv:2602.05183v2 Announce Type: replace-cross
Abstract: Large language models (LLMs) are increasingly trained in complex Reinforcement Learning, multi-agent environments, making it difficult to understand how behavior changes over training. Sparse Autoencoders (SAEs) have recently shown to be useful for data-centric interpretability. In this work, we analyze large-scale reinforcement learning training runs from the sophisticated environment of Full-Press Diplomacy by applying pretrained SAEs, alongside LLM-summarizer methods. We introduce Meta-Autointerp, a method for grouping SAE features into interpretable hypotheses about training dynamics. We discover fine-grained behaviors including role-playing patterns, degenerate outputs, language switching, alongside high-level strategic behaviors and environment-specific bugs. Through automated evaluation, we validate that 90% of discovered SAE Meta-Features are significant, and find a surprising reward hacking behavior. However, through two user studies, we find that even subjectively interesting and seemingly helpful SAE features may be worse than useless to humans, along with most LLM generated hypotheses. However, a subset of SAE-derived hypotheses are predictively useful for downstream tasks. We further provide validation by augmenting an untrained agent's system prompt, improving the score by +14.2%. Overall, we show that SAEs and LLM-summarizer provide complementary views into agent behavior, and together our framework forms a practical starting point for future data-centric interpretability work on ensuring trustworthy LLM behavior throughout training.
arXiv:2602.05687v2 Announce Type: replace-cross
Abstract: Individuals are increasingly generating substantial personal health and lifestyle data, e.g. through wearables and smartphones. While such data could transform preventative care, its integration into clinical practice is hindered by its scale, heterogeneity and the time pressure and data literacy of healthcare professionals (HCPs). We explore how large language models (LLMs) can support sensemaking of patient-generated health data (PGHD) with automated summaries and natural language data exploration. Using cardiovascular disease (CVD) risk reduction as a use case, 16 HCPs reviewed multimodal PGHD in a mixed-methods study with a prototype that integrated common charts, LLM-generated summaries, and a conversational interface. Findings show that AI summaries provided quick overviews that anchored exploration, while conversational interaction supported flexible analysis and bridged data-literacy gaps. However, HCPs raised concerns about transparency, privacy, and overreliance. We contribute empirical insights and sociotechnical design implications for integrating AI-driven summarization and conversation into clinical workflows to support PGHD sensemaking.
In a randomized controlled study involving 1,298 participants from a general sample, performance of humans when assisted by a large language model (LLM) was sensibly inferior to that of the LLM alone when assessing ten medical scenarios leading to disease identification and recommendations for treatment.
Background: Mobile phone ecological momentary assessment (EMA) methods are a well-established measure of eating and drinking behaviors, but compliance can be poor. Micro-EMA (μEMA), which collects information with a single tap response to brief questions on smartwatches, offers a novel application that may improve response rates. To our knowledge, there is no data evaluating μEMA to measure eating habits in children or in low-to-middle-income countries. Objective: In this study, we investigated the feasibility of micro-EMA to measure eating patterns in Malaysian children and adolescents. Methods: We invited 100 children and adolescents aged 7-18 years in Segamat, Malaysia, to participate in 2021-2022. Smartwatches were distributed to 83 children and adolescents who agreed to participate. Participants were asked to wear the smartwatch for 8 days and respond to 12 prompts per day, hourly, from 9AM to 8PM, asking for information on their meals, snacks, and drinks consumed. A questionnaire captured their experiences using the smartwatch and μEMA interface. Response rate (proportion of prompts responded to) assessed participants’ adherence. We explored associations between response rate with time of day, across days, age, and sex using multilevel binomial logistic regression modeling. Results: Eighty-two participants provided usable smartwatch data. The median number (IQR) of meals, drinks, and snacks per day was 2 (2-4), 3 (1-5), and 1 (0-2), respectively, on the first day of the study. The median response rate across the study was 68% (IQR 50-83). The response rate decreased across study days from 74% (68-78) on Day 1 to 40% (30-50) on Day 7 (odds ratio [OR] per study day 0.73, 95% CI 0.64-0.83). Response rate was lowest at the start of the day and highest between the hours of 12 PM and 2 PM. Female participants responded to more prompts than male participants (OR 1.72, 95% CI 1.03-2.86). There was no evidence of differential response by age (OR 0.73, 95% CI 0.41-1.28). Most participants (65%) rated their experience using the smartwatch positively, with 33% saying they were happy to participate in future studies using the smartwatch. For children that did not wear the smartwatch for the full study duration (n=22), discomfort was the most common complaint (41%). Conclusions: In this study of the feasibility of μEMA on smartwatches to measure eating in Malaysian children, we found the method was acceptable. However, response rates declined across study days, resulting in substantial missingness. Future studies (eg, through focus groups) should explore approaches to improving response to event prompts, trial alternative devices to increase children’s comfort, and evaluate revised protocols for reporting of intake events.
BACKGROUND: Compelling evidence supports the biomarker potential of microbiome in pancreatic adenocarcinoma. Given the knowledge gap on the characteristics and significance of microbiome in early-onset pancreatic ductal adenocarcinoma (eoPDAC, age <50 years), we aimed to evaluate microbiome profiles in resected specimens from individuals with eoPDAC and average-onset PDAC (aoPDAC, age >50 years).
MATERIALS AND METHODS: We carried out shotgun metagenomic sequencing in resected specimens from individuals with eoPDAC (n = 24) and aoPDAC (n = 20). Statistical tests included Wilcoxon test, permutational analysis of variance, multiomic classifier modeling, differential abundance analysis, and linear regression. All P values were adjusted for multiple testing and P < 0.05 was considered statistically significant.
RESULTS: We successfully sequenced several bacteria and fungi in the tumor specimens from 44 individuals with resected PDAC (24 eoPDAC and 20 aoPDAC). The alpha diversity of the bacterial microbiome was higher in eoPDAC tumor tissue compared with aoPDAC (P = 0.04). In contrast, the fungal mycobiome's alpha diversity was higher for aoPDAC tumor tissue (P = 0.02). Key organisms with differential abundance between tumor tissue from individuals with eoPDAC and aoPDAC included Bacillus, Candida, Collimonas, Cupriavidus, Enterobacter, Escherichia, Klebsiella, Malasseiza, Mucilaginibacter, Neisseria, and Sphingomonas. Higher bacterial diversity in tumor tissue was associated with better overall survival for individuals with eoPDAC (R = 0.26, P = 0.02).
CONCLUSIONS: Shotgun metagenomic sequencing identified bacterial microbiome and fungal mycobiome in tumors from individuals with eoPDAC and aoPDAC. We observed significant differences in alpha and beta diversity and relative abundances of organisms suggesting distinct microbiome signatures. Microbiome associations with survival were observed in eoPDAC indicating unique potential as prognostic biomarker.
Extrachromosomal DNA (ecDNA) is a major source of oncogenic fusions across cancer types, generating tissue-specific fusion landscapes with diagnostic potential. EcDNA-borne PVT1 5′-end fusions stabilize partner RNAs and boost oncogene output.
arXiv:2602.04735v1 Announce Type: cross
Abstract: Large Language Models (LLMs) can acquire unintended biases from seemingly benign training data even without explicit cues or malicious content. Existing methods struggle to detect such risks before fine-tuning, making post hoc evaluation costly and inefficient. To address this challenge, we introduce Data2Behavior, a new task for predicting unintended model behaviors prior to training. We also propose Manipulating Data Features (MDF), a lightweight approach that summarizes candidate data through their mean representations and injects them into the forward pass of a base model, allowing latent statistical signals in the data to shape model activations and reveal potential biases and safety risks without updating any parameters. MDF achieves reliable prediction while consuming only about 20% of the GPU resources required for fine-tuning. Experiments on Qwen3-14B, Qwen2.5-32B-Instruct, and Gemma-3-12b-it confirm that MDF can anticipate unintended behaviors and provide insight into pre-training vulnerabilities.
arXiv:2602.04881v1 Announce Type: cross
Abstract: Internet of Things (IoT) deployments operate in nonstationary, dynamic environments where factors such as sensor drift, evolving user behavior, and heterogeneous user privacy requirements can affect application utility. Continual learning (CL) addresses this by adapting models over time without catastrophic forgetting. Meanwhile, contrastive learning has emerged as a powerful representation-learning paradigm that improves robustness and sample efficiency in a self-supervised manner. This paper reviews the usage of \emph{contrastive continual learning} (CCL) for IoT, connecting algorithmic design (replay, regularization, distillation, prompts) with IoT system realities (TinyML constraints, intermittent connectivity, privacy). We present a unifying problem formulation, derive common objectives that blend contrastive and distillation losses, propose an IoT-oriented reference architecture for on-device, edge, and cloud-based CCL, and provide guidance on evaluation protocols and metrics. Finally, we highlight open unique challenges with respect to the IoT domain, such as spanning tabular and streaming IoT data, concept drift, federated settings, and energy-aware training.
arXiv:2503.01733v3 Announce Type: replace-cross
Abstract: Smart homes equipped with ambient sensors offer a transformative approach to continuous health monitoring and assisted living. Traditional research in this domain primarily focuses on Human Activity Recognition (HAR), which relies on mapping sensor data to a closed set of predefined activity labels. However, the fixed granularity of these labels often constrains their practical utility, failing to capture the subtle, household-specific nuances essential, for example, for tracking individual health over time. To address this, we propose DISCOVER, a framework for discovering and annotating Patterns of Daily Living (PDL) - fine-grained, recurring sequences of sensor events that emerge directly from a resident's unique routines. DISCOVER utilizes a self-supervised feature extraction and representation-aware clustering pipeline, supported by a custom visualization interface that enables experts to interpret and label discovered patterns with minimal effort. Our evaluation across multiple smart-home environments demonstrates that DISCOVER identifies cohesive behavioral clusters with high inter-rater agreement while achieving classification performance comparable to fully-supervised baselines using only 0.01% of the labels. Beyond reducing annotation overhead, DISCOVER establishes a foundation for longitudinal analysis. By grounding behavior in a resident's specific environment rather than rigid semantic categories, our framework facilitates the observation of within-person habitual drift. This capability positions the system as a potential tool for identifying subtle behavioral indicators associated with early-stage cognitive decline in future longitudinal studies.
The previous article in this series, “Rules fail at the prompt, succeed at the boundary,” focused on the first AI-orchestrated espionage campaign and the failure of prompt-level control. This article is the prescription. The question every CEO is now getting from their board is some version of: What do we do about agent risk?
Across recent AI security guidance from standards bodies, regulators, and major providers, a simple idea keeps repeating: treat agents like powerful, semi-autonomous users, and enforce rules at the boundaries where they touch identity, tools, data, and outputs.
The following is an actionable eight-step plan one can ask teams to implement and report against:
Eight controls, three pillars: govern agentic systems at the boundary. Source: Protegrity
Constrain capabilities
These steps help define identity and limit capabilities.
1. Identity and scope: Make agents real users with narrow jobs
Today, agents run under vague, over-privileged service identities. The fix is straightforward: treat each agent as a non-human principal with the same discipline applied to employees.
Every agent should run as the requesting user in the correct tenant, with permissions constrained to that user’s role and geography. Prohibit cross-tenant on-behalf-of shortcuts. Anything high-impact should require explicit human approval with a recorded rationale. That is how Google’s Secure AI Framework (SAIF) and NIST AI’s access-control guidance are meant to be applied in practice.
The CEO question: Can we show, today, a list of our agents and exactly what each is allowed to do?
2. Tooling control: Pin, approve, and bound what agents can use
The Anthropic espionage framework worked because the attackers could wire Claude into a flexible suite of tools (e.g., scanners, exploit frameworks, data parsers) through Model Context Protocol, and those tools weren’t pinned or policy-gated.
The defense is to treat toolchains like a supply chain:
Pin versions of remote tool servers.
Require approvals for adding new tools, scopes, or data sources.
Forbid automatic tool-chaining unless a policy explicitly allows it.
This is exactly what OWASP flags under excessive agency and what it recommends protecting against. Under the EU AI Act, designing for such cyber-resilience and misuse resistance is part of the Article 15 obligation to ensure robustness and cybersecurity.
The CEO question:Who signs off when an agent gains a new tool or a broader scope? How does one know?
3. Permissions by design: Bind tools to tasks, not to models
A common anti-pattern is to give the model a long-lived credential and hope prompts keep it polite. SAIF and NIST argue the opposite: credentials and scopes should be bound to tools and tasks, rotated regularly, and auditable. Agents then request narrowly scoped capabilities through those tools.
In practice, that looks like: “finance-ops-agent may read, but not write, certain ledgers without CFO approval.”
The CEO question:Can we revoke a specific capability from an agent without re-architecting the whole system?
Control data and behavior
These steps gate inputs, outputs, and constrain behavior.
4. Inputs, memory, and RAG: Treat external content as hostile until proven otherwise
Most agent incidents start with sneaky data: a poisoned web page, PDF, email, or repository that smuggles adversarial instructions into the system. OWASP’s prompt-injection cheat sheet and OpenAI’s own guidance both insist on strict separation of system instructions from user content and on treating unvetted retrieval sources as untrusted.
Operationally, gate before anything enters retrieval or long-term memory: new sources are reviewed, tagged, and onboarded; persistent memory is disabled when untrusted context is present; provenance is attached to each chunk.
The CEO question: Can we enumerate every external content source our agents learn from, and who approved them?
5. Output handling and rendering: Nothing executes “just because the model said so”
In the Anthropic case, AI-generated exploit code and credential dumps flowed straight into action. Any output that can cause a side effect needs a validator between the agent and the real world. OWASP’s insecure output handling category is explicit on this point, as are browser security best practices around origin boundaries.
The CEO question:Where, in our architecture, are agent outputs assessed before they run or ship to customers?
6. Data privacy at runtime: Protect the data first, then the model
Protect the data such that there is nothing dangerous to reveal by default. NIST and SAIF both lean toward “secure-by-default” designs where sensitive values are tokenized or masked and only re-hydrated for authorized users and use cases.
In agentic systems, that means policy-controlled detokenization at the output boundary and logging every reveal. If an agent is fully compromised, the blast radius is bounded by what the policy lets it see.
This is where the AI stack intersects not just with the EU AI Act but with GDPR and sector-specific regimes. The EU AI Act expects providers and deployers to manage AI-specific risk; runtime tokenization and policy-gated reveal are strong evidence that one is actively controlling those risks in production.
The CEO question: When our agents touch regulated data, is that protection enforced by architecture or by promises?
Prove governance and resilience
For the final steps, it’s important to show controls work and keep working.
7. Continuous evaluation: Don’t ship a one-time test, ship a test harness
Anthropic’s research about sleeper agents should eliminate all fantasies about single test dreams and show how critical continuous evaluation is. This means instrumenting agents with deep observability, regularly red teaming with adversarial test suites, and backing everything with robust logging and evidence, so failures become both regression tests and enforceable policy updates.
The CEO question: Who works to break our agents every week, and how do their findings change policy?
8. Governance, inventory, and audit: Keep score in one place
AI security frameworks emphasize inventory and evidence: enterprises must know which models, prompts, tools, datasets, and vector stores they have, who owns them, and what decisions were taken about risk.
For agents, that means a living catalog and unified logs:
Which agents exist, on which platforms
What scopes, tools, and data each is allowed
Every approval, detokenization, and high-impact action, with who approved it and when
The CEO question: If asked how an agent made a specific decision, could we reconstruct the chain?
And don’t forget the system-level threat model: assume the threat actor GTG-1002 is already in your enterprise. To complete enterprise preparedness, zoom out and consider the MITRE ATLAS product, which exists precisely because adversaries attack systems, not models. Anthropic provides a case study of a state-based threat actor (GTG-1002) doing exactly that with an agentic framework.
Taken together, these controls do not make agents magically safe. They do something more familiar and more reliable: they put AI, its access, and actions back inside the same security frame used for any powerful user or system.
For boards and CEOs, the question is no longer “Do we have good AI guardrails?” It’s: Can we answer the CEO questions above with evidence, not assurances?
This content was produced by Protegrity. It was not written by MIT Technology Review’s editorial staff.