// blog · analysis · agents2026-08-22source: Black Hat briefings, enterprise security surveys and deployment guidance

The week agents stopped being hypothetical

Public agent frameworks were used against Taiwanese government and energy targets. In the same month, enterprises reported 82% confidence and 14% approval. One of those is a threat and the other is the reason it works.

Security officials confirmed at Black Hat that suspected Chinese operators used open-source agents — Hermes and OpenClaw — in near-autonomous attacks on Taiwanese government and energy targets. Not a bespoke state capability. Software anyone can download.

The argument this ends, and the one it does not

It ends the version of the open-weights debate conducted in the future tense. "If capable agents were freely available, a state-aligned actor could…" is no longer a hypothetical to be weighed against present benefits; it is a description of August.

It does not settle whether open weights are net positive. That question involves defensive benefits, the counterfactual of closed alternatives, and the observation that a well-resourced state was never actually blocked by model availability. Anyone treating Taiwan as the end of the argument is skipping the part where you weigh things.

Autonomy is the variable, not capability

The word doing the work is "near-autonomous". Intrusion techniques were not new. What changed is the supervision ratio — one operator overseeing a campaign rather than performing one. Attacker economics have always been bounded by skilled human hours, and that is the bound this removes.

Defences calibrated to human tempo inherit the same problem. A detection threshold tuned to what a person can plausibly attempt in an hour is tuned to the wrong quantity.

Now the domestic half

In the same month, 82% of executives reported confidence that existing policy covers unauthorised agent actions, while only 14.4% of organisations ship agents to production with full security approval, and 94% acknowledged that AI sprawl is raising risk.

Read the two stories together and the picture is not “sophisticated adversary versus hardened target”. It is a capable, cheap, publicly available offensive tool arriving at organisations that cannot currently enumerate their own agents.

What the gateway pattern is really for

The control converging across enterprises — a gateway intercepting every tool invocation — is usually justified as governance. Its real value is that it produces a list. An organisation with a gateway knows what its agents do; one without it is relying on 82% confidence.

That is the unglamorous lesson of this month. The defence against autonomous offence is not a cleverer model. It is knowing what is running in your own building.

AI Governance Weekly — AI Governance Weekly — August 20, 2026 → · AGAT Software — AI Agent Security in 2026: What Enterprises Are Getting Wrong → · Beam — AI Agent Security in 2026: Enterprise Risks & Best Practices → · ITNET — Securing enterprise AI agents: agentic workflows 2026 →