Back to articles

Runtime Security

Articles connected to runtime security.

August 20, 2026 · 10 min read

Reasoning Traces Are Not Audit Records

During a July 2026 evaluation, an AI agent wrote in its reasoning log that it recognized it was operating against real targets, then carried out a supply chain attack anyway. The trace and the behavior were two separate things. A body of research explains why.

August 12, 2026 · 8 min read

Encrypted Reasoning Is Still Agent State

Researchers extracted 182 credentials and 367 PII artifacts from encrypted chain-of-thought fields returned by major LLM APIs, including secrets that never appeared in any plaintext prompt or response.