The Enterprise AI Brief | Issue 12
Inside This Issue
The Threat Room
When Agent Skills Inherit the Authority of the Agents That Run Them
A malicious agent skill does not necessarily need credentials of its own. A real 2026 campaign showed how seemingly legitimate instructions could route an authorized agent through secondary files and remote payloads until the workflow ended in credential theft, raising a harder question for enterprise security: what exactly must be trusted when instructions themselves can initiate the execution chain?
→ Read the full articleThe Operations Room
AI Evaluation Can Move to the Data Without Exposing the Data
What if an enterprise could test an external AI model on sensitive data without giving either side direct access to the other's asset? A 2026 MedPerf implementation shows how encrypted models and private medical data can meet inside an attested environment, with access released only after the workload proves what it is running.
→ Read the full articleThe Engineering Room
Security Tests Are Becoming Part of the Generation Specification
The coding agent generates a fix, the security tests turn green, and the pipeline is ready to move on. New research suggests that putting security tests inside the generation loop can improve results, but it also raises a harder engineering question: what, exactly, should a passing test allow an AI-generated program to do next?
→ Read the full articleThe Governance Room
Synthetic Data Requires Evidence Before Reclassification
A synthetic dataset can leave the original customer records behind while carrying forward something harder to see: the lineage back to those records. The harder enterprise question is what has to be proven before that derivative can safely receive different access, retention, or privacy controls.
→ Read the full article