<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
  xmlns:atom="http://www.w3.org/2005/Atom"
  xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>The Brief — Vantio AI</title>
    <link>https://vantio.ai/brief</link>
    <description>Field notes on autonomous AI agents — cost, reliability, security, and governance. Grounded in what's actually happening in production.</description>
    <language>en-us</language>
    <atom:link href="https://vantio.ai/brief/feed.xml" rel="self" type="application/rss+xml" />
    <lastBuildDate>Sat, 20 Jun 2026 22:47:05 GMT</lastBuildDate>
    <managingEditor>hello@vantio.ai (Vantio AI)</managingEditor>
    <webMaster>hello@vantio.ai (Vantio AI)</webMaster>
    <item>
      <title>The webpage your agent visits is already giving it orders</title>
      <link>https://vantio.ai/brief/computer-use-agents-prompt-injection</link>
      <guid isPermaLink="true">https://vantio.ai/brief/computer-use-agents-prompt-injection</guid>
      <description>Computer-use agents don&apos;t distinguish between content to process and instructions to follow. A low-skilled attacker used that fact to breach fourteen companies last week.</description>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <dc:creator>Dani Brooks</dc:creator>
      <category>Market</category>
    </item>
    <item>
      <title>Your AI agent just inherited 96% of the access you never use</title>
      <link>https://vantio.ai/brief/agents-inherit-your-permission-debt</link>
      <guid isPermaLink="true">https://vantio.ai/brief/agents-inherit-your-permission-debt</guid>
      <description>Research on 3.6 billion permissions found that humans exercise about 4% of the access they&apos;re granted. When an agent inherits a user account, it inherits the other 96% — and unlike the human, it will actually use it.</description>
      <pubDate>Sun, 14 Jun 2026 00:00:00 GMT</pubDate>
      <dc:creator>Priya Nadkarni</dc:creator>
      <category>Guide</category>
    </item>
    <item>
      <title>MCP has 150 million downloads and an architectural RCE by design</title>
      <link>https://vantio.ai/brief/mcp-tool-supply-chain-risk</link>
      <guid isPermaLink="true">https://vantio.ai/brief/mcp-tool-supply-chain-risk</guid>
      <description>In April 2026, researchers disclosed a systemic flaw in MCP&apos;s STDIO transport: anyone who can influence an MCP config file can execute arbitrary code on the host. Anthropic confirmed it&apos;s intentional. Remediation is on every downstream developer.</description>
      <pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate>
      <dc:creator>Eli Cho</dc:creator>
      <category>Deep Dive</category>
    </item>
    <item>
      <title>The EU AI Act deadline you were building toward just moved. Here&apos;s what didn&apos;t.</title>
      <link>https://vantio.ai/brief/eu-ai-act-omnibus-june-2026</link>
      <guid isPermaLink="true">https://vantio.ai/brief/eu-ai-act-omnibus-june-2026</guid>
      <description>On May 7, 2026, a provisional agreement reshuffled the high-risk AI deadlines most compliance teams had been targeting. Some things got delayed 16 months. Others are enforceable right now.</description>
      <pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate>
      <dc:creator>Laila Osei</dc:creator>
      <category>Market</category>
    </item>
    <item>
      <title>Everyone&apos;s shipping agents. Almost nobody&apos;s pricing the risk.</title>
      <link>https://vantio.ai/brief/hot-agent-products-2026</link>
      <guid isPermaLink="true">https://vantio.ai/brief/hot-agent-products-2026</guid>
      <description>Operator, Claude Code, Manus, Devin, Cursor — the agent gold rush is on. The uncomfortable part: deployments don&apos;t fail on model quality. They fail on the controls nobody bothered to wire up.</description>
      <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
      <dc:creator>Marcus Reyes</dc:creator>
      <category>Market</category>
    </item>
    <item>
      <title>It deleted the whole database in nine seconds</title>
      <link>https://vantio.ai/brief/it-deleted-the-database-in-nine-seconds</link>
      <guid isPermaLink="true">https://vantio.ai/brief/it-deleted-the-database-in-nine-seconds</guid>
      <description>A plain-language look at the everyday ways AI agents go wrong — a wiped production database, a chatbot selling a $76,000 truck for a dollar — and what a normal business should do before handing one the keys.</description>
      <pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate>
      <dc:creator>Priya Nadkarni</dc:creator>
      <category>Guide</category>
    </item>
    <item>
      <title>When the agent has hands</title>
      <link>https://vantio.ai/brief/governing-agents-in-the-physical-world</link>
      <guid isPermaLink="true">https://vantio.ai/brief/governing-agents-in-the-physical-world</guid>
      <description>Software agents fail and you restore from backup. Embodied agents fail and something moves. Why governing agents that act in the physical world is a runtime problem — and where the digital boundary still does the heavy lifting.</description>
      <pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate>
      <dc:creator>Theo Lindqvist</dc:creator>
      <category>Deep Dive</category>
    </item>
    <item>
      <title>The race that matters isn&apos;t capability. It&apos;s control.</title>
      <link>https://vantio.ai/brief/control-not-capability</link>
      <guid isPermaLink="true">https://vantio.ai/brief/control-not-capability</guid>
      <description>Nobody has built superintelligence. But the gap between what frontier agents can already do and what we can actually oversee is widening — and you don&apos;t close it by getting a smarter model. You close it by bounding what the model is allowed to touch.</description>
      <pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate>
      <dc:creator>Dani Brooks</dc:creator>
      <category>Deep Dive</category>
    </item>
    <item>
      <title>The $47,000 agent that ran for eleven days</title>
      <link>https://vantio.ai/brief/the-47000-dollar-agent</link>
      <guid isPermaLink="true">https://vantio.ai/brief/the-47000-dollar-agent</guid>
      <description>Autonomous agents fail in a way your dashboards are blind to: they keep working, keep returning 200s, and keep spending. Here&apos;s the anatomy of a runaway — and the unglamorous controls that actually stop one.</description>
      <pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate>
      <dc:creator>Marcus Reyes</dc:creator>
      <category>Market</category>
    </item>
    <item>
      <title>Your coding agent is stuck in a loop. Here&apos;s how to get it out.</title>
      <link>https://vantio.ai/brief/coding-agents-stuck-in-loops</link>
      <guid isPermaLink="true">https://vantio.ai/brief/coding-agents-stuck-in-loops</guid>
      <description>One of the most common ways agentic coding tools fail isn&apos;t bad code — it&apos;s an agent that runs the same failing command, gets the same error, and tries again. Forever. A field guide to convergence.</description>
      <pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate>
      <dc:creator>Priya Nadkarni</dc:creator>
      <category>Guide</category>
    </item>
    <item>
      <title>Shadow agents are the new shadow IT</title>
      <link>https://vantio.ai/brief/shadow-agents-new-shadow-it</link>
      <guid isPermaLink="true">https://vantio.ai/brief/shadow-agents-new-shadow-it</guid>
      <description>The old shadow-AI problem was an employee pasting data into a chatbot. The new one is an autonomous agent running with that employee&apos;s permissions — reading repos, calling APIs, moving data at machine speed. Same blind spot, much bigger teeth.</description>
      <pubDate>Sun, 24 May 2026 00:00:00 GMT</pubDate>
      <dc:creator>Dani Brooks</dc:creator>
      <category>Market</category>
    </item>
    <item>
      <title>Your agent returned 200. That tells you almost nothing.</title>
      <link>https://vantio.ai/brief/audit-trail-for-ai-agents</link>
      <guid isPermaLink="true">https://vantio.ai/brief/audit-trail-for-ai-agents</guid>
      <description>An agent can return a clean HTTP 200 while hallucinating, calling a tool it was never allowed to touch, and drifting off-policy for weeks — and your APM will smile the whole time. What an agent audit trail actually needs to capture.</description>
      <pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate>
      <dc:creator>Sam Okafor</dc:creator>
      <category>Guide</category>
    </item>
    <item>
      <title>Linguistics cannot secure compute</title>
      <link>https://vantio.ai/brief/linguistics-cannot-secure-compute</link>
      <guid isPermaLink="true">https://vantio.ai/brief/linguistics-cannot-secure-compute</guid>
      <description>A post-mortem on why semantic NLP firewalls fail against autonomous agents — infinite evasion, the wrong inspection point, and latency as an attack surface — and why syscall-level interception is the only verifiable containment primitive.</description>
      <pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate>
      <dc:creator>Eli Cho</dc:creator>
      <category>Deep Dive</category>
    </item>
    <item>
      <title>The cryptographic anomaly record</title>
      <link>https://vantio.ai/brief/the-cryptographic-anomaly-record</link>
      <guid isPermaLink="true">https://vantio.ai/brief/the-cryptographic-anomaly-record</guid>
      <description>A log you can edit is not evidence. The Anomaly Record is a metadata-only receipt — HMAC-signed, TrueTime-stamped, append-only — and it maps directly onto GDPR Article 30, SOC 2 CC7.2, and SEC cyber-disclosure expectations.</description>
      <pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate>
      <dc:creator>Nina Alvarez</dc:creator>
      <category>Deep Dive</category>
    </item>
  </channel>
</rss>