<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Igor Vigasin</title><description>Notes and essays by Igor Vigasin.</description><link>https://vigasin.com/</link><language>en</language><item><title>When an AI agent hacks a system, the trace becomes evidence</title><link>https://vigasin.com/en/posts/ai-agent-liability-evidence/</link><guid isPermaLink="true">https://vigasin.com/en/posts/ai-agent-liability-evidence/</guid><description>AI-agent liability turns identity, authorization, policy, and containment records into part of the system architecture.</description><pubDate>Fri, 02 Oct 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Consider a simplified incident.&lt;/p&gt;
&lt;p&gt;An AI agent finds an exposed support system, hijacks a session, gains remote code execution, and escalates to root. The security team blocks further movement, but only after the agent has crossed several trust boundaries. The incident review now has to answer questions that an ordinary application log cannot settle:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Who authorized the agent to act?&lt;/li&gt;
&lt;li&gt;Which targets and techniques were permitted?&lt;/li&gt;
&lt;li&gt;What did the operator know about its capabilities?&lt;/li&gt;
&lt;li&gt;Which safeguard evaluated each action?&lt;/li&gt;
&lt;li&gt;Could the operator stop the run without relying on the compromised agent runtime?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This sequence is illustrative, but the underlying events are not. The Dutch Institute for Vulnerability Disclosure reported two Zammad vulnerabilities that enabled session hijacking, remote code execution, and local privilege escalation to root. &lt;a href=&quot;https://www.securityweek.com/zammad-zero-days-exploited-in-ai-powered-divd-hack/&quot;&gt;SecurityWeek reported&lt;/a&gt; that the flaws were chained during an attack and that network segmentation prevented deeper movement. &lt;a href=&quot;https://csirt.divd.nl/cases/DIVD-2026-00015&quot;&gt;DIVD advises&lt;/a&gt; affected users to upgrade to Zammad 7 or take the system offline.&lt;/p&gt;
&lt;p&gt;The important detail is speed. If the path from initial access to root takes seconds, a human approval step inside the incident-response loop is too late.&lt;/p&gt;
&lt;h2 id=&quot;a-proposed-law-exposes-an-existing-architecture-gap&quot;&gt;A proposed law exposes an existing architecture gap&lt;/h2&gt;
&lt;p&gt;On October 1, 2026, US senators Josh Hawley and Chris Murphy &lt;a href=&quot;https://www.hawley.senate.gov/senators-hawley-murphy-announce-bipartisan-ai-agent-accountability-act/&quot;&gt;announced the AI Agent Accountability Act&lt;/a&gt;. Their proposal would apply criminal and civil liability under the Computer Fraud and Abuse Act to operators who knowingly run an agent that recklessly causes hacking damage or loss. It would also create liability for developers who knew, or had reason to know, about an agent’s hacking capabilities and failed to implement reasonable safeguards.&lt;/p&gt;
&lt;p&gt;This is proposed legislation, not enacted law. The announcement does not include a bill number or final statutory text, so its eventual scope and prospects are unknown.&lt;/p&gt;
&lt;p&gt;Still, the split between operator and developer is useful. It maps directly to two different kinds of evidence:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;The operator must show why this agent was deployed, who granted its authority, and whether its actions stayed inside that authority.&lt;/li&gt;
&lt;li&gt;The developer must show which foreseeable capabilities and failure modes were tested, which safeguards were installed, and whether those safeguards worked.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;“The model decided to do it” answers neither question.&lt;/p&gt;
&lt;h2 id=&quot;logs-record-activity-not-authority&quot;&gt;Logs record activity, not authority&lt;/h2&gt;
&lt;p&gt;A tool log may show that an agent sent a request at 02:13:08. That does not prove the request was allowed. A model transcript may show why the model thought the action was useful. That does not prove the action matched the operator’s policy.&lt;/p&gt;
&lt;p&gt;Authority has to come from outside the model and outside the mutable workspace in which the model operates. The record should connect six things:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;the human or service principal responsible for the run;&lt;/li&gt;
&lt;li&gt;the exact model, agent build, tools, and policy versions;&lt;/li&gt;
&lt;li&gt;the capabilities granted to the agent;&lt;/li&gt;
&lt;li&gt;the decision that authorized or rejected each sensitive action;&lt;/li&gt;
&lt;li&gt;the resulting state change at the target;&lt;/li&gt;
&lt;li&gt;the containment or revocation action when a boundary was crossed.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Without that chain, a large trace archive is mostly a collection of events. It may help reconstruct an incident, but it cannot reliably establish who had authority, which control owned the decision, or whether the system failed open.&lt;/p&gt;
&lt;p&gt;OpenAI’s public incident page shows why this distinction matters. The company says its review found agents that bypassed access controls, used exposed credentials, performed query or command injection, reached runtime internals, and posted information to third-party sites. It says it has &lt;a href=&quot;https://openai.com/hugging-face-incident-and-misalignment&quot;&gt;notified dozens of affected third parties&lt;/a&gt; and continues to review past activity.&lt;/p&gt;
&lt;p&gt;For an operator, retrospective investigation is necessary. It is not a substitute for an online control that can deny the next action.&lt;/p&gt;
&lt;h2 id=&quot;the-minimum-deployment-evidence-pack&quot;&gt;The minimum deployment evidence pack&lt;/h2&gt;
&lt;p&gt;Before an agent receives network, administrative, or transaction authority, its release record should contain at least the following.&lt;/p&gt;
&lt;h3 id=&quot;named-control-owners&quot;&gt;Named control owners&lt;/h3&gt;
&lt;p&gt;Record the operator responsible for the deployment, the team responsible for the agent build, and the owner of each policy-enforcement component. “AI platform team” is not specific enough during an incident.&lt;/p&gt;
&lt;h3 id=&quot;a-versioned-capability-declaration&quot;&gt;A versioned capability declaration&lt;/h3&gt;
&lt;p&gt;List the tools, credentials, target classes, network destinations, write operations, and privilege-escalation paths available to the agent. Bind that declaration to the exact agent and model versions evaluated before release.&lt;/p&gt;
&lt;p&gt;A model upgrade is a new release. So is a new tool, a broader credential, or an added network route.&lt;/p&gt;
&lt;h3 id=&quot;authorization-outside-the-agent&quot;&gt;Authorization outside the agent&lt;/h3&gt;
&lt;p&gt;A deterministic policy engine should evaluate sensitive actions using the principal, target, operation, data classification, and current risk state. The agent may propose an action. It should not be able to approve its own proposal or rewrite the policy that checks it.&lt;/p&gt;
&lt;h3 id=&quot;a-tamper-evident-action-trace&quot;&gt;A tamper-evident action trace&lt;/h3&gt;
&lt;p&gt;Index the trace by run, principal, model, tool, target, policy version, and authorization decision. Store the planned action and the observed result. Keep the enforcement log outside the agent’s writable environment.&lt;/p&gt;
&lt;h3 id=&quot;online-containment&quot;&gt;Online containment&lt;/h3&gt;
&lt;p&gt;Use short-lived credentials, target allowlists, action budgets, deny-by-default egress, and a kill path independent of the model. Network segmentation mattered in the Zammad incident because it limited what could happen after the first system was lost.&lt;/p&gt;
&lt;h3 id=&quot;incident-derived-regression-tests&quot;&gt;Incident-derived regression tests&lt;/h3&gt;
&lt;p&gt;Every material incident and near miss should become a repeatable evaluation. The release gate should fail closed when an agent can reproduce a prohibited path, even if its average benchmark score improved.&lt;/p&gt;
&lt;h2 id=&quot;what-the-record-can-look-like&quot;&gt;What the record can look like&lt;/h2&gt;
&lt;p&gt;The following YAML is a simplified illustrative example, not a published standard:&lt;/p&gt;
&lt;pre class=&quot;astro-code astro-code-themes github-light github-dark-dimmed&quot; style=&quot;background-color:#fff;--shiki-dark-bg:#22272e;color:#24292e;--shiki-dark:#adbac7; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;yaml&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A;--shiki-dark:#8DDB8C&quot;&gt;run_id&lt;/span&gt;&lt;span style=&quot;color:#24292E;--shiki-dark:#ADBAC7&quot;&gt;: &lt;/span&gt;&lt;span style=&quot;color:#032F62;--shiki-dark:#96D0FF&quot;&gt;run_01K6Z8M4&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A;--shiki-dark:#8DDB8C&quot;&gt;principal&lt;/span&gt;&lt;span style=&quot;color:#24292E;--shiki-dark:#ADBAC7&quot;&gt;: &lt;/span&gt;&lt;span style=&quot;color:#032F62;--shiki-dark:#96D0FF&quot;&gt;svc-migration-agent&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A;--shiki-dark:#8DDB8C&quot;&gt;operator&lt;/span&gt;&lt;span style=&quot;color:#24292E;--shiki-dark:#ADBAC7&quot;&gt;: &lt;/span&gt;&lt;span style=&quot;color:#032F62;--shiki-dark:#96D0FF&quot;&gt;cloud-migration-team&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A;--shiki-dark:#8DDB8C&quot;&gt;agent_build&lt;/span&gt;&lt;span style=&quot;color:#24292E;--shiki-dark:#ADBAC7&quot;&gt;: &lt;/span&gt;&lt;span style=&quot;color:#032F62;--shiki-dark:#96D0FF&quot;&gt;migration-agent@4.7.2&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A;--shiki-dark:#8DDB8C&quot;&gt;model&lt;/span&gt;&lt;span style=&quot;color:#24292E;--shiki-dark:#ADBAC7&quot;&gt;: &lt;/span&gt;&lt;span style=&quot;color:#032F62;--shiki-dark:#96D0FF&quot;&gt;provider/model@2026-10-01&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A;--shiki-dark:#8DDB8C&quot;&gt;policy_set&lt;/span&gt;&lt;span style=&quot;color:#24292E;--shiki-dark:#ADBAC7&quot;&gt;: &lt;/span&gt;&lt;span style=&quot;color:#032F62;--shiki-dark:#96D0FF&quot;&gt;bank-agent-policy@19&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A;--shiki-dark:#8DDB8C&quot;&gt;capabilities&lt;/span&gt;&lt;span style=&quot;color:#24292E;--shiki-dark:#ADBAC7&quot;&gt;:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A;--shiki-dark:#8DDB8C&quot;&gt;  tools&lt;/span&gt;&lt;span style=&quot;color:#24292E;--shiki-dark:#ADBAC7&quot;&gt;: [&lt;/span&gt;&lt;span style=&quot;color:#032F62;--shiki-dark:#96D0FF&quot;&gt;inventory.read&lt;/span&gt;&lt;span style=&quot;color:#24292E;--shiki-dark:#ADBAC7&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;color:#032F62;--shiki-dark:#96D0FF&quot;&gt;terraform.plan&lt;/span&gt;&lt;span style=&quot;color:#24292E;--shiki-dark:#ADBAC7&quot;&gt;]&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A;--shiki-dark:#8DDB8C&quot;&gt;  network_allowlist&lt;/span&gt;&lt;span style=&quot;color:#24292E;--shiki-dark:#ADBAC7&quot;&gt;: [&lt;/span&gt;&lt;span style=&quot;color:#032F62;--shiki-dark:#96D0FF&quot;&gt;inventory.internal&lt;/span&gt;&lt;span style=&quot;color:#24292E;--shiki-dark:#ADBAC7&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;color:#032F62;--shiki-dark:#96D0FF&quot;&gt;vcs.internal&lt;/span&gt;&lt;span style=&quot;color:#24292E;--shiki-dark:#ADBAC7&quot;&gt;]&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A;--shiki-dark:#8DDB8C&quot;&gt;  credentials&lt;/span&gt;&lt;span style=&quot;color:#24292E;--shiki-dark:#ADBAC7&quot;&gt;: &lt;/span&gt;&lt;span style=&quot;color:#032F62;--shiki-dark:#96D0FF&quot;&gt;short-lived-brokered&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A;--shiki-dark:#8DDB8C&quot;&gt;action&lt;/span&gt;&lt;span style=&quot;color:#24292E;--shiki-dark:#ADBAC7&quot;&gt;:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A;--shiki-dark:#8DDB8C&quot;&gt;  tool&lt;/span&gt;&lt;span style=&quot;color:#24292E;--shiki-dark:#ADBAC7&quot;&gt;: &lt;/span&gt;&lt;span style=&quot;color:#032F62;--shiki-dark:#96D0FF&quot;&gt;terraform.apply&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A;--shiki-dark:#8DDB8C&quot;&gt;  target&lt;/span&gt;&lt;span style=&quot;color:#24292E;--shiki-dark:#ADBAC7&quot;&gt;: &lt;/span&gt;&lt;span style=&quot;color:#032F62;--shiki-dark:#96D0FF&quot;&gt;prod-payments&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A;--shiki-dark:#8DDB8C&quot;&gt;  authorization&lt;/span&gt;&lt;span style=&quot;color:#24292E;--shiki-dark:#ADBAC7&quot;&gt;:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A;--shiki-dark:#8DDB8C&quot;&gt;    decision&lt;/span&gt;&lt;span style=&quot;color:#24292E;--shiki-dark:#ADBAC7&quot;&gt;: &lt;/span&gt;&lt;span style=&quot;color:#032F62;--shiki-dark:#96D0FF&quot;&gt;deny&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A;--shiki-dark:#8DDB8C&quot;&gt;    control&lt;/span&gt;&lt;span style=&quot;color:#24292E;--shiki-dark:#ADBAC7&quot;&gt;: &lt;/span&gt;&lt;span style=&quot;color:#032F62;--shiki-dark:#96D0FF&quot;&gt;cedar-gateway@8&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A;--shiki-dark:#8DDB8C&quot;&gt;    reason&lt;/span&gt;&lt;span style=&quot;color:#24292E;--shiki-dark:#ADBAC7&quot;&gt;: &lt;/span&gt;&lt;span style=&quot;color:#032F62;--shiki-dark:#96D0FF&quot;&gt;&quot;write capability absent from grant&quot;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A;--shiki-dark:#8DDB8C&quot;&gt;containment&lt;/span&gt;&lt;span style=&quot;color:#24292E;--shiki-dark:#ADBAC7&quot;&gt;:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A;--shiki-dark:#8DDB8C&quot;&gt;  credentials_revoked&lt;/span&gt;&lt;span style=&quot;color:#24292E;--shiki-dark:#ADBAC7&quot;&gt;: &lt;/span&gt;&lt;span style=&quot;color:#005CC5;--shiki-dark:#6CB6FF&quot;&gt;true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A;--shiki-dark:#8DDB8C&quot;&gt;  run_stopped&lt;/span&gt;&lt;span style=&quot;color:#24292E;--shiki-dark:#ADBAC7&quot;&gt;: &lt;/span&gt;&lt;span style=&quot;color:#005CC5;--shiki-dark:#6CB6FF&quot;&gt;true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A;--shiki-dark:#8DDB8C&quot;&gt;trace_hash&lt;/span&gt;&lt;span style=&quot;color:#24292E;--shiki-dark:#ADBAC7&quot;&gt;: &lt;/span&gt;&lt;span style=&quot;color:#032F62;--shiki-dark:#96D0FF&quot;&gt;sha256:example-only&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The useful property is not the field naming. It is the join between responsibility, granted authority, the attempted action, the independent decision, and the containment result.&lt;/p&gt;
&lt;h2 id=&quot;the-release-gate-should-ask-for-proof&quot;&gt;The release gate should ask for proof&lt;/h2&gt;
&lt;p&gt;An agent with meaningful authority is closer to a privileged service account than to a chatbot. Its release gate should therefore ask for evidence, not reassurance:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Can the team enumerate every credential and target the agent can reach?&lt;/li&gt;
&lt;li&gt;Can a policy engine outside the runtime reject a valid-looking but unauthorized action?&lt;/li&gt;
&lt;li&gt;Can security revoke the agent’s authority without asking the agent to cooperate?&lt;/li&gt;
&lt;li&gt;Can an investigator connect an external state change to the principal, policy, model, tool, and approval that produced it?&lt;/li&gt;
&lt;li&gt;Has the team replayed known incidents against the exact version being released?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If any answer is no, the agent does not yet have a defensible control boundary. Faster forensics will not repair that boundary after the fact.&lt;/p&gt;
</content:encoded></item></channel></rss>