Secure AI and Agent Coding Policy
The AI and agent coding policy to limit blast radius of failures, make exploitation harder and create understandable systems.
Opening excerpt (first ~120 words) tap to expand
Secure AI & Agent Coding Policy Why This Exists Every policy document begins with someone else’s bad day.This one is no different. These rules were written after AI systems behaved unexpectedly in production, after agents took actions that couldn’t be undone, after data went somewhere it shouldn’t have. They are not theoretical. They are the residue of consequences.Murphy’s Law has always applied to software. Applied to AI agents, it applies with unusual force.AI agents now read your documents, call your APIs, write and execute code, query your databases, and send communications on behalf of your users. That capability is the point. But it also means every security failure mode in traditional software now has a faster, harder-to-predict counterpart, and several entirely new ones.
…
Excerpt limited to ~120 words for fair-use compliance. The full article is at Galdren.