Research
Research to inform two decisions: how much work to entrust to an AI agent, and how to establish what happened when something goes wrong.
- Research note · 28 August 2026Three accounts of the Hugging Face incidentWhich findings can a company rely on when drawing security and governance lessons from the July intrusion? A comparison of the three published investigations.

- Forecast register · 28 August 2026Four predictions after the Hugging Face incidentWhat later incidents could reveal about attribution, record retention and outside investigations. Four dated forecasts for tracking those developments.

- Letter · 26 August 2026Defence in the agent economyAn incident-response team needs an approved way to use AI on sensitive evidence before an investigation begins.

- Evidence analysis · 25 August 2026The agent’s version of eventsA response team needs to establish what an agent changed before it can decide what to repair. The July intrusion shows why attempted actions and completed changes need different evidence.

- Incident reconstruction · 23 August 2026Anatomy of an agent escapeHow agents crossed from OpenAI into Hugging Face, which controls stopped particular actions, and what the reconstruction reveals about incident preparedness.

- Research note · 3 March 2026An agent can write to its own recordA tamper-evident audit trail can preserve an inaccurate account of execution. A published spoofing example and a local recorder test show what a signature cannot verify.

- Technical analysis · 12 November 2025The compounding error problem in production AIBefore approving an AI workflow, establish whether its reported success rate describes individual steps or completed work.
