verifiedagents.ai
All posts

5 min readAI Agents · Cybersecurity

Contain First, Count Second: AI Agent Blast Radius

By Josh Woodruff, Founder & CEO, MassiveScale.AI | Founding Chair, Agentic Trust Framework at the CSAI Foundation

Hero: Contain First, Count Second: AI Agent Blast Radius

TL;DR: Contain the damage first and finish the inventory second. Attackers using AI find and use weaknesses faster than discovery projects finish, so blast-radius controls beat complete counting. The same shift, containment over enumeration, came up on three separate security calls inside eight days in August 2026. Counting still counts. It just can't be the thing you wait on.

Last updated October 5, 2026. Rebuilt for verifiedagents.ai: the argument, the five controls that work on agents you haven't found, the coverage numbers, and the week-one list.

What does containment over enumeration mean?

Enumeration is finding everything. Containment is making sure no single thing can hurt you much. When attackers move faster than your discovery cycle, the second pays off sooner and the first never quite finishes.

Security has one saying that's been true for twenty years: you can't protect what you don't know is out there. I've said it. I've probably said it on stage. And in August 2026 I watched a group of security leaders agree it's no longer the right place to start. An AI model can find a weakness and use it faster than a normal remediation cycle closes, while your inventory project takes a quarter. That's the whole argument in two sentences.

Why does count-everything-first fail for agents?

Because the population changes faster than the count. Agents get created in a chat window and vanish minutes later. New ones arrive through tools your team already approved. By the time the discovery scan finishes, its answer is about last month.

The failure is a sequencing mistake, not a laziness problem. A team decides inventory is step one and funds a discovery project, then parks every control decision behind it. Nine months later they hold a number nobody trusts and no controls, and the agents that worried them have been replaced by different agents. The containment work they could have done in month one would still be protecting them today.

What are the five blast-radius controls?

Blast radius is how much damage one agent can do before somebody stops it. These five shrink it, and none requires a finished inventory, because each is a property of the environment rather than of the list.

  1. A separate identity per agent.

    Not a shared service account, and not the launching human's credential. An agent running as a person has that person's reach, and afterward you can't tell their actions apart.

  2. A default ceiling.

    Set the maximum before you know what each agent needs: no production data by default, no write access to a system of record without a specific grant. It applies to agents you haven't met yet, which is the point.

  3. A stop that works fast.

    One agent or all of them, without a change ticket. And tested, not assumed. Plenty of teams have a kill switch on paper and not in practice.

  4. A log the agent can't edit.

    What it did, what it touched, when, and under whose authority. The difference between an incident and a mystery.

  5. A network path that funnels.

    Agents reach outside systems through one route you control, which is the one place a policy can actually be applied.

The access half of this is familiar ground: least privilege for AI agents covers it in depth.

Does inventory still count?

Yes, and this argument gets flattened into "don't bother counting," which is wrong. What changes is that inventory becomes a continuous measurement instead of a prerequisite. The one-week version is in how to count the AI agents in your company, and it runs in the background while containment ships.

Measure coverage instead of chasing completeness. "84 percent of the agents we know about run with their own identity" is honest and improvable, and boards accept a partial number with a trend line. "We have 412 agents" is a claim you'll defend the moment it moves.

How do you decide what to contain first?

Rank by reach, speed, impact, and reversibility. You don't need discovery for that. Ask your engineers two questions: which agents touch money, and which agents can change something a customer sees. You'll get five names. Those five are the program.

The temptation runs the other way, toward the easy agents that close fast and look like progress on a slide. That instinct produces a clean report and no protection. And skip the products promising to automate all of it. As one security leader put it flatly in 2026: an autonomous system that runs your security operations by itself doesn't exist.

What can you do in the next week?

  • Name your five highest-impact agents, by asking engineers rather than tools.

  • Check whether any of them run as a person. The single highest-value finding of the week.

  • Test one kill switch for real: shut an agent off and time it, then find out what else broke.

  • Publish one coverage number, such as the percentage of known agents with their own identity.

  • Write the default ceiling in one sentence, so it binds agents that don't exist yet.

Frequently asked questions

Isn't "you can't protect what you don't know" still true?

True, and no longer a good starting instruction. Discovery runs slower than agent creation, so treating it as step one means the controls never ship. The order changed, not the value.

How is this different from least privilege?

Least privilege is one of the five controls. Containment is the wider goal: it also covers identity, the stop, the unalterable log, and the single route out. Least privilege limits what one agent may do. Containment limits what happens when the limit fails.

Does containment help against prompt injection?

It limits the damage rather than preventing the attack. No filter reliably blocks instructions hidden in content an agent reads, so the working defense is what the agent can reach after it's fooled. That's a containment question.

How long does this take compared to inventory?

Weeks, because the ceiling and identity separation extend systems you already run. Full inventories have taken clients two or three quarters and still come back incomplete. That timeline difference is the whole reason to reverse the order.

Key takeaways

  • Containment over enumeration: build the damage limits before the list is done.

  • The five controls work on agents you haven't found, because they're environmental.

  • Report coverage percentages, not totals you'll have to defend.

  • Rank by reach, speed, impact, reversibility. Two questions to engineering get you started.

  • Inventory continues in the background. It stopped being the gate.

Shrink the radius this month

The free ATF assessment shows which of the five controls you're missing, in about ten minutes.

I spent years telling people to find everything first. The attacker got faster, and the advice has to change with it.

See where your agents stand.

The free assessment takes ten minutes and scores you on the five elements of the Agentic Trust Framework.