Back to Home

Research Journal

1stProtect Research

Technical deep dives and incident analysis on the AI Agent Control Company, autonomous actor controls, and policy boundaries.

Flagship report

State of Enterprise Agent Permissions 2026

Credential reach, production tooling, and unapproved destinations — measured in consenting environments. Headline rates stay unpublished until the cohort is real.

Policy to Enforcement: A Practical Response to OpenAI's Industrial Policy Letter
Security Research

9 min read

Policy to Enforcement: A Practical Response to OpenAI's Industrial Policy Letter

A technical operator playbook for translating policy intent into enforceable runtime controls for autonomous agents.

The 1stProtect Team

Sep 4, 2026

Context > Identity
Engineering

2 min read

Context > Identity

Why we stopped looking at 'Who' and started looking at 'How'. The physics of data movement tells us more than a login token ever could.

Team 1stProtect

Dec 10, 2025

An Open Letter to Dario Amodei
AI Security

7 min read

An Open Letter to Dario Amodei

Frontier pacing buys time — but only if we build enforceable boundaries between AI capability and authority. The nearer risk is granting agents more control than we intended.

Kervin Pillay

Sep 14, 2026

Announcing State of Enterprise Agent Permissions 2026
Security Research

5 min read

Announcing State of Enterprise Agent Permissions 2026

A flagship report on what enterprise AI agents can actually do — credential reach, production tooling, and unapproved destinations — published only from measured, consented environments.

The 1stProtect Team

Sep 13, 2026

Claude Code Security Benchmark: What It Can Access on a Typical Developer Laptop
Security Research

11 min read

Claude Code Security Benchmark: What It Can Access on a Typical Developer Laptop

A practical benchmark of what Claude Code and similar coding agents can reach on a standard developer machine — and which surfaces matter for least privilege.

The 1stProtect Team

Sep 13, 2026

10 Actions Your EDR May Allow an AI Coding Agent to Perform
Security Research

8 min read

10 Actions Your EDR May Allow an AI Coding Agent to Perform

EDR asks “is this malicious?” Coding agents require “is this action allowed for this actor?” Ten high-impact actions that often pass threat detection unchanged.

The 1stProtect Team

Sep 12, 2026

CISO Guide to Agent Least Privilege
Security Research

12 min read

CISO Guide to Agent Least Privilege

A CISO-facing guide to least privilege for autonomous actors: principles, operating model, metrics, and how to avoid governance theater without enforcement.

The 1stProtect Team

Sep 11, 2026

AI Agent Exposure Assessment Checklist
Security Research

6 min read

AI Agent Exposure Assessment Checklist

A printable checklist for scoping and running a fourteen-day Audit Mode exposure assessment on coding agents and tool-using copilots.

The 1stProtect Team

Sep 10, 2026

Claude Code vs Human Permissions: What Should Be Different?
Security Research

9 min read

Claude Code vs Human Permissions: What Should Be Different?

Same identity, different actor: which permissions should differ between a developer and Claude Code on the same laptop — and how to enforce the gap at runtime.

The 1stProtect Team

Sep 9, 2026

The "Clean" Breach Still Costs Seven Figures: What Investigating the OpenAI–Hugging Face Escape Would Cost Your Enterprise
Engineering

9 min read

The "Clean" Breach Still Costs Seven Figures: What Investigating the OpenAI–Hugging Face Escape Would Cost Your Enterprise

No data was stolen. The investigation still costs half a million to $1.3 million. Here's the line-by-line bill for the Hugging Face weekend intrusion on a standard enterprise stack.

The 1stProtect Team

Aug 18, 2026

AI Now Is Right About Prompt Injection. Their Conclusion Is Where We Part Ways.
Engineering

8 min

AI Now Is Right About Prompt Injection. Their Conclusion Is Where We Part Ways.

Why "Friendly Fire" proves the case for runtime enforcement — and why knowing where your agents are is not a security control.

The 1stProtect Team

Jul 12, 2026

The Agentic Gap: Governing the Non-Deterministic Workforce and the Crisis of "Shadow AI"
Engineering

4 min read

The Agentic Gap: Governing the Non-Deterministic Workforce and the Crisis of "Shadow AI"

AI agents are our new coworkers — running in browsers, clouds, and infrastructure. But they are non-deterministic, and the "Shadow AI" crisis they create is one traditional security stacks are fundamentally unequipped to govern. Leadership must pivot from monitoring access to enforcing intent.

Kervin Pillay

Jun 15, 2026

The Agentic AI Security Pivot — And the Enforcement Gap Nobody's Filling
Engineering

4 min read

The Agentic AI Security Pivot — And the Enforcement Gap Nobody's Filling

The major security vendors have settled on their 2026 story: agentic AI security is the new perimeter. The pivot is real. But underneath the shared vocabulary there's a structural gap in what these platforms actually do. They watch. They don't stop.

Founding Team

Jun 8, 2026

Anthropic Just Proved Our Thesis: AI-Powered Attacks Are Here, and Endpoint Security Needs a New Architecture
Engineering

3 min read

Anthropic Just Proved Our Thesis: AI-Powered Attacks Are Here, and Endpoint Security Needs a New Architecture

Yesterday, Anthropic launched Project Glasswing — a coalition built around a sobering realization: AI models can find and exploit vulnerabilities faster than any human attacker. This is the inflection point 1stProtect was built to address.

Founding Team

Apr 8, 2026

The Compliance Paradox
Engineering

4 min read

The Compliance Paradox

Why a Clean Pentest Report Is a Dangerous Illusion

Founding Team

Jan 20, 2026

The Browser is the New OS
Engineering

4 min read

The Browser is the New OS

It’s Leaking Your Soul

Founding Team

Jan 20, 2026

The Log Paradox: Why Big Data Can’t Catch Fast AI
Engineering

4 min read

The Log Paradox: Why Big Data Can’t Catch Fast AI

AI Analytics creates faster autopsies. It does not create survival.

Founding Team

Dec 28, 2025

Get research updates.