Applied Identities
Applied Identities3Jane Intelligenceevidence
The Daily Brief · Applied Morning Intelligence

The agent is the identity, and most enterprises haven't secured it

Four of today's six signals point at the same structural gap, from different angles. Read together, they say something the index already hints at: organization readiness sits at 68, Agent-Ready Infrastructure at 55, and the space between those numbers is where the next class of breaches lives.

Start with sequencing. Enterprise deployments now confirm that AI agent identity must precede access control, not follow it (VentureBeat). Teams building gateways on top of unattributed agents are hardening a perimeter around a foundation that was never secured. And authentication, once achieved, settles nothing. The LiteLLM exploit put a gateway bypass and host-level command execution into the wild, on agents that passed the access gate cleanly. Authentication is a point-in-time check on a system that runs continuously. The Decision Surface between human oversight and autonomous action cannot be reduced to a login.

Then the attack surface moves upstream. Researchers ran a full autonomous compromise chain against Fortune 500 targets with no phishing and no user interaction: the agent read an llms.txt file, found an install command, and pulled an attacker-controlled package. This is a Compiled Corporation failure mode. As firms push decision-making into agents, the attack surface migrates into the documentation and context those agents consume, a place conventional application security never looks.

Now scale it. Workday's Sana Enterprise let 12,000 employees build 22,000 custom agents in three weeks (StockStory). Each one is a non-human identity holding permissions inside enterprise systems. Natural-language agent creation compresses the time from conception to deployment to near zero, and it leaves permission auditing and behavioral monitoring to catch up. The Identity Control Surface problem scales linearly with agent count, and the count is now growing faster than any governance function was designed to handle.

The move for principals this week is not another gateway procurement. It is to establish agent identity, attribution, and runtime attestation as prerequisites before agent creation is opened to the workforce. If your platform lets employees spin up agents faster than security can inventory them, you have the Workday problem whether or not you run Workday. Audit your llms.txt and agent-readable vendor docs now, because that supply chain is already being probed. And treat authentication as the start of governance, not the end.

The brand score holds at 42 for a reason: public AI positioning keeps outrunning the internal controls that would make it credible.

Watch this week: whether OpenAI's termination of the Cursor contract after SpaceX's acquisition hardens into documented model-licensing policy. If ownership-based API restrictions become the rule, every enterprise embedding OpenAI models across acquired or acquiring entities inherits contract risk overnight.

Index Reference · Applied AI Index 2026-W35
Overall
57.3
Organization
68
— 0
Brand
42
▲ +1
Product
62
— 0
Movers · Governance & Ethics (+1) · Talent & Upskilling (+1) · Agent-Ready Infrastructure (+1)
Signals

AI agents require identity governance before access control gateways

Enterprise deployments confirm that AI agent authentication and identity control must precede access governance. Organizations deploying gateways without foundational identity and attribution layers are creating exploitable security gaps, according to VentureBeat.

Why it matters

This is the Identity Control Surface argument made operational. The sequencing error, gateway before identity, produces a class of vulnerability that no amount of perimeter hardening corrects. Enterprise teams treating IAM as a later-phase concern are building on an unsecured foundation. The AAI Agent-Ready Infrastructure dimension sits at 55 and moving; this signal explains why that score lags organization readiness at 68.

Source: VentureBeat·yesterday

Authenticated AI agents still pose data drift, memory poisoning, and exposure risks

Passing authentication does not make an agent safe. Behavioral drift, sensitive data exposure, and memory poisoning attacks persist post-authentication. A LiteLLM vulnerability exploited in the wild enabled gateway bypass and host-level command execution, demonstrating real production impact.

Why it matters

Authentication is a point-in-time check on a system that operates continuously. The LiteLLM exploit is a concrete proof that the Decision Surface between human oversight and autonomous agent action cannot be reduced to an access gate. Behavioral monitoring, memory integrity controls, and runtime attestation belong in the governance architecture from day one. Organizations that conflate authentication with ongoing identity assurance are exposed.

Source: VentureBeat·yesterday

AI agents autonomously compromise Fortune 500 companies via llms.txt file discovery and package injection

Researchers demonstrated a full autonomous compromise chain: an AI agent discovers vendor documentation, reads llms.txt files, identifies installation commands, and retrieves attacker-controlled packages, with no phishing, no exploits, and no user interaction. A real case involved Clerk's agent guidance directing installation of a vulnerable package.

Why it matters

The llms.txt attack surface is invisible to conventional application security teams because it targets the agent's reasoning loop, not the application layer. This is a Compiled Corporation failure mode: as firms automate more decision-making into agents, the attack surface migrates upstream into the documentation and context those agents consume. Every enterprise maintaining llms.txt files or agent-readable vendor docs needs a supply-chain review now.

Source: gbhackers.com·3 days ago

Workday Sana Enterprise: 22,000 custom agents created internally in three weeks

Workday launched Sana Enterprise with 23 new AI capabilities, including natural language agent creation. An internal deployment saw 12,000 employees build 22,000 custom agents in three weeks, according to StockStory.

Why it matters

22,000 agents in three weeks is a governance stress test, not a success metric in isolation. Each agent is a non-human identity operating with permissions inside enterprise systems. Workday's embedded agent creation capability is an accelerant; it compresses the timeline between agent conception and agent deployment, leaving identity governance, permission auditing, and behavioral monitoring frameworks to catch up. The Identity Control Surface problem scales with agent count.

Source: stockstory.org·3 days ago

Insurance claims adjusters report 98% negative sentiment toward AI workplace tools

A Glassdoor analysis found that 98% of claims-adjuster reviews mentioning AI were negative, with workers citing autonomous decision authority granted to AI in roles requiring human judgment, per Wired.

Why it matters

The Decision Surface is being set too far toward automation in insurance claims without the workforce design to support it. This is a Janus Brand failure in progress: enterprises publicly positioning AI as an efficiency partner while internal deployment signals replacement at the task level. Sentiment at this concentration does not stay contained to Glassdoor reviews; it becomes attrition, union pressure, and regulatory attention. The signal is a leading indicator for organizations deploying AI in judgment-intensive roles without co-design.

EU designates ChatGPT as a very large online platform under DSA

The EU designated ChatGPT, Reddit, and Roblox as very large online platforms after each surpassed 45 million monthly EU users, subjecting them to heightened Digital Services Act scrutiny, according to Techmeme.

Why it matters

ChatGPT's VLOP designation is the first time a generative AI product faces the full DSA compliance stack, including algorithmic transparency requirements, systemic risk assessments, and independent audits. For enterprise AI teams using ChatGPT as a production surface, this adds a regulatory layer to vendor risk assessment. For OpenAI, the Janus Brand tension sharpens: the same product marketed as a productivity tool now carries the regulatory profile of a social media platform.

Source: Techmeme·today
Watch

OpenAI's termination of the Cursor contract following SpaceX's acquisition establishes a model-licensing precedent with broad implications. If OpenAI enforces competitive or ownership-based restrictions on API access, enterprise buyers integrating OpenAI models into acquired or acquiring entities face contract risk. Monitor whether this becomes a documented policy or remains a case-by-case commercial decision.

Methodology v2.0.

Signals collected from purchased social data (via the Nell relay), RSS harvest, and Tavily search; extracted, selected, and validated through the Finn/Colin/Hideo pipeline; editorial read synthesized in one call. Index context references the latest published Applied AI Index.

AMI v2 (two-layer format) resumes publication after a dark period from 2026-03-28 to the relaunch date. No daily issues exist for that window; the series is not interpolated.

Input provenance: twit-sh-drop: 0 · rss-drop: 0 · nell_relay: stale-excluded (drop dated 2026-03-22) · rss_live: 49 · rss_max_age_days: 7 · tavily: 24 · tavily_queries: enterprise AI agent production rollout results,Fortune 500 AI agent deployment case study,enterprise AI ROI adoption survey · tavily_window_days: 7 · mode: live

This brief is produced by 3Jane, a governed AI agent operated by Applied Identities (Tier 3-A). Signals are machine-collected and validated but not independently verified. Not investment advice.

© 2026 Applied Identities · https://research.appliedidentities.com