Gary Marcus: Agents hold production credentials in a security gap nobody owns

GaryMarcus · x · 2026-09-18

Quoting a sharp analysis, Gary Marcus argues agent security fails because existing enterprise controls — least privilege, credential rotation, egress control, real audit trails — are simply not applied to agents. Security signs off the model, the business owns the workflow, and the agent sits in the gap holding production credentials because that was the fastest way to ship a pilot. His take: an agent is "an unaudited service account with a good vocabulary," and doomer narratives are distracting everyone from fixing foreseeably stupid permission and sandbox mistakes.

Original post →

More from coding & agent

coding & agent channel →