You can’t secure what you can’t see.
RAID Files | Episode 03
Hosted by Dominika Pietrzak, RAID
Your AI agents don’t just answer anymore. They act, and most security teams can’t say exactly what they’re allowed to touch. That gap is the subject of this episode. Anthropic has published openly about how containment for Claude has failed more than once across its own products, and they’re not the only ones still working this out. Agents are already wired into Slack, GitHub, internal documents, emails, cloud accounts, customer records, and CI/CD pipelines. Prompt injection remains unsolved, so the odds of an agent getting coerced into doing something it shouldn’t are real.
In this episode, Dom breaks down the three questions every security leader should be asking about their AI agents right now: what agents you have, whether you’d catch one misbehaving, and what your chosen framework misses. She closes with a 90-day plan you can hand your team today, covering the OWASP agent taxonomy, the OWASP Agentic Top 10, and the AIUC-1 to OWASP crosswalk along the way.
YOUR AGENTS ACT ON THEIR OWN.
They read the document, decide what happens next, call a tool, update the ticket, write the code. That’s not a chatbot risk. That’s a workforce risk.
THEY’RE ALREADY WIRED INTO EVERYTHING.
Slack. GitHub. Email. Cloud accounts. Customer records. CI/CD pipelines. There’s barely a system left they haven’t touched.
EVEN ANTHROPIC CAN’T FULLY CONTAIN CLAUDE.
By their own admission, containment has failed more than once. Prompt injection is still unsolved. If the team building the frontier can’t close that gap, don’t assume yours already has.
YOU CAN’T SECURE WHAT YOU CAN’T SEE.
Most security teams can’t list every agent running inside their business. Shadow AI is already there, doing real work, touching real systems, answering to no one.
Find out what you’re running.
Sources referenced
AIUC OWASP TOP 10 | OWASP TOP 10 | STATE OF AGENTIC AI SECURITY AND GOVERNANCE | ANTHROPIC – HOW WE CONTAIN CLAUDE