Research · Publications

Methods, evaluations and reports.

Formal publications, evaluation reports and technical documentation from the Xybern research team.

Read Access Is Write Access
2026-07-24 ·Xybern Research
Read Access Is Write Access

Every access control system rests on one assumption: read is safe, write is dangerous. For AI agents that distinction has quietly collapsed. An agent that can read can exfiltrate it, be steered by it, and reconnoitre with it. Read-only is not a safe default, and permission tiers no longer govern risk. The action does.

Read →
There Is No Kill Switch
2026-07-13 ·Xybern Research
There Is No Kill Switch

We will just shut it down is the reassurance every executive reaches for about AI agents. It is a fantasy. The kill switch cannot detect the failure in time, cannot win the race against the agent, and cannot reverse what was already done. The only real off switch is a control on every action, before it executes.

Read →
The Intern With Root
2026-07-06 ·Xybern Research
The Intern With Root

You would reject the onboarding ticket before you finished reading it: standing access to everything, no probation, no review, acting at machine speed, influenced by untrusted input. That is how enterprises deploy AI agents. The agent is the new hire, and it needs the controls we spent decades learning humans required.

Read →
The Agent Did Nothing Wrong
2026-06-29 ·Xybern Research
The Agent Did Nothing Wrong

The coming AI agent disaster will have no bug, no broken component, no negligent engineer. The model will be correct, the credentials valid, the APIs healthy, the logs complete. Everything will have worked as designed. Correctness of the parts is not safety of the whole, and safety lives in the layer that governs the actions between them.

Read →
You Cannot Audit What You Did Not Authorise
2026-06-19 ·Xybern Research
You Cannot Audit What You Did Not Authorise

Enterprises are mistaking detailed agent logs for an audit trail. A log proves an action happened. A regulator asks whether the control operated, and you cannot reconstruct an authorisation decision that was never made. The audit record is a byproduct of authorising each action.

Read →
AI Agents Are Non-Human Identities
2026-06-19 ·Xybern Research
AI Agents Are Non-Human Identities

AI agents are non-human identities, but of a kind the NHI playbook was never built for. Vaulting, rotation, scoping and lifecycle all govern the credential. An agent’s risk lives in the action it decides to take. The credential controls are necessary but not sufficient.

Read →
Zero Trust For AI Agents
2026-06-15 ·Xybern Research
Zero Trust For AI Agents

The security industry spent a decade adopting Zero Trust, then quietly granted AI agents the exact implicit trust it dismantled. Agents violate every Zero Trust principle. Closing the gap means extending verification to the layer Zero Trust never had to reach: the individual action.

Read →
Prompt Injection Is an Authorisation Problem
2026-06-08 ·Xybern Research
Prompt Injection Is an Authorisation Problem

The security industry has spent two years trying to solve prompt injection at the model layer, where the defender cannot win. Prompt injection is not a model problem. It is an authorisation problem, and authorisation problems are solved at the authorisation layer.

Read →
AI Agents Need Permission Boundaries
2026-05-26 ·Xybern Research
AI Agents Need Permission Boundaries

Permission boundaries are not an optional hardening step for agentic systems. They are the foundational primitive that makes agents safe to deploy. This piece defines what a real boundary is, why the naive approaches fail, and how enforcement has to work to be meaningful.

Read →
Why OAuth Is Not Enough For AI Agents
2026-05-25 ·Xybern Research
Why OAuth Is Not Enough For AI Agents

OAuth was designed for delegated access between deterministic applications. AI agents are not deterministic. This piece breaks down the six specific places where OAuth fails for AI agents and what a proper authorisation layer requires.

Read →
The Authorisation Layer: The Infrastructure AI Agents Are Missing
2026-05-20 ·Xybern Research
The Authorisation Layer: The Infrastructure AI Agents Are Missing

AI agents are being deployed across enterprise systems without the one infrastructure layer they need most: an authorisation layer. This piece defines the pattern, explains why existing approaches fail, and lays out what production-grade AI agent governance actually looks like.

Read →

No articles match this filter.

Try selecting All to see everything.

Stay updated

Research that matters.

Get the latest from Xybern on AI enforcement research, model releases and product updates.

Request a pilot How it works