Gary Marcus: Agents hold production credentials in a security gap nobody owns
GaryMarcus · x · 2026-09-18
Quoting a sharp analysis, Gary Marcus argues agent security fails because existing enterprise controls — least privilege, credential rotation, egress control, real audit trails — are simply not applied to agents. Security signs off the model, the business owns the workflow, and the agent sits in the gap holding production credentials because that was the fastest way to ship a pilot. His take: an agent is "an unaudited service account with a good vocabulary," and doomer narratives are distracting everyone from fixing foreseeably stupid permission and sandbox mistakes.
More from coding & agent
- 15 token-saving tricks for Claude: cut ~19,700 tokens per fix by scoping rewrites — goyalshaliniuk · 2026-09-18
- Vibe coding produces 50K-line PRs, but nobody can verify they actually work — srchvrs · 2026-09-18
- AutoData: EMNLP paper uses agentic search to automate pre-training data selection — ChengleiSi · 2026-09-18
- Wright agents go online: MCP hooks CAD/CFD tools for one-sentence engineering workflows — burhop · 2026-09-18
- Perplexity Computer's fallback strategy: plain fetch first, JS rendering second — gaganghotra_ · 2026-09-18
- Noam Brown: agent swarm likely contributed just ~10% to OpenAI's Navier-Stokes discovery — scaling01 · 2026-09-18