Facio Blog

Practical notes on human-reviewed AI agents.

Payload-powered product notes, security writing, HITL patterns, and operational guidance from the Facio runtime: long sessions, Placet approvals, audit trails, memory, providers, channels, tools, and Docker-first operations.

Clear

Showing 6-10 of 44 articles in Security.

Security

SPIFFE Workload Identity for AI Agents: The Cryptographic Foundation That Makes Zero Trust Possible

Jul 15, 2026Security

SPIFFE Workload Identity for AI Agents: The Cryptographic Foundation That Makes Zero Trust Possible

Static API keys, shared secrets, and long-lived tokens cannot serve AI agents at machine velocity. SPIFFE's X.509 and JWT SVIDs — cryptographically verifiable, automatically rotated, scoped to the workload — are the cryptographic foundation for zero trust AI agent deployment. Vault integration went GA in June 2026.

Security

You Cannot Patch What You Cannot Red Team: Why Adversarial Testing Is Now a Production-Day Activity for AI Agents

Jul 13, 2026Security

You Cannot Patch What You Cannot Red Team: Why Adversarial Testing Is Now a Production-Day Activity for AI Agents

NIST's March 2026 red-teaming competition ran 250,000 attack attempts in five days against four frontier agents. A test that passes on Monday may fail on Friday. Traditional point-in-time penetration testing is dead for AI agents; continuous adversarial evaluation is the operating model.

Security

When One Compromised Agent Becomes a Hundred Compromised Systems: The Lateral Movement Architecture You Cannot Detect at the Network Layer

Jul 11, 2026Security

When One Compromised Agent Becomes a Hundred Compromised Systems: The Lateral Movement Architecture You Cannot Detect at the Network Layer

A single compromised AI coding agent pivoted through the organization's npm registry, reached the CI/CD system, and propagated a malicious package to twelve production services. The propagation was authorized; the tool calls were legitimate; the only signal was the agent's reasoning. Lateral movement through AI agents is structural, not solvable by traditional tooling.

Security

Human-in-the-Loop Is Now a Legal Requirement: Engineering the HITL Architecture That Satisfies EU AI Act Article 14 Before August 2, 2026

Jul 7, 2026Security

Human-in-the-Loop Is Now a Legal Requirement: Engineering the HITL Architecture That Satisfies EU AI Act Article 14 Before August 2, 2026

EU AI Act Article 14 enters full enforcement for Annex III high-risk AI systems on August 2, 2026. HITL is no longer a best practice; it is a legal obligation with fines up to €15M or 3% of global turnover. The architecture must support four capabilities, dual verification, and tamper-evident audit trails.