Research · Publications

Methods, evaluations and reports.

Formal publications, evaluation reports and technical documentation from the Xybern research team.

Prompt Injection Is an Authorisation Problem
2026-06-08 ·Xybern Research
Prompt Injection Is an Authorisation Problem

The security industry has spent two years trying to solve prompt injection at the model layer, where the defender cannot win. Prompt injection is not a model problem. It is an authorisation problem, and authorisation problems are solved at the authorisation layer.

Read →
AI Agents Need Permission Boundaries
2026-05-26 ·Xybern Research
AI Agents Need Permission Boundaries

Permission boundaries are not an optional hardening step for agentic systems. They are the foundational primitive that makes agents safe to deploy. This piece defines what a real boundary is, why the naive approaches fail, and how enforcement has to work to be meaningful.

Read →
Why OAuth Is Not Enough For AI Agents
2026-05-25 ·Xybern Research
Why OAuth Is Not Enough For AI Agents

OAuth was designed for delegated access between deterministic applications. AI agents are not deterministic. This piece breaks down the six specific places where OAuth fails for AI agents and what a proper authorisation layer requires.

Read →
The Authorisation Layer: The Infrastructure AI Agents Are Missing
2026-05-20 ·Xybern Research
The Authorisation Layer: The Infrastructure AI Agents Are Missing

AI agents are being deployed across enterprise systems without the one infrastructure layer they need most: an authorisation layer. This piece defines the pattern, explains why existing approaches fail, and lays out what production-grade AI agent governance actually looks like.

Read →

No articles match this filter.

Try selecting All to see everything.

Stay updated

Research that matters.

Get the latest from Xybern on AI enforcement research, model releases and product updates.

Request a pilot How it works