Four regimes, four clocks. Which one fires first after an incident?
CRA reporting went live on 11 September 2026. With NIS2, GDPR and the AI Act, one event can start four clocks, and the fastest gives you 24 hours.
Covers agent security and incidents: what an attacker can reach once an AI system holds credentials.
Owen Castellanos writes The Guardrail coverage of agent security and incidents. He is interested in one question above the others: when a model is persuaded to do the wrong thing, what is it authorised to do next?
He writes post-incident analysis the way an engineer reads one, looking for the telemetry gap rather than the villain. Where an incident is described publicly, he says who reported it first and what remains unconfirmed.
He is sceptical of controls that depend on detecting an attack, and interested in controls that make a successful attack boring.
Tips, corrections and documents go to owen@theguardrailreport.com. If you are reporting an error in a published briefing, quote the sentence and, where it concerns a legal obligation, the provision you believe we misread.
CRA reporting went live on 11 September 2026. With NIS2, GDPR and the AI Act, one event can start four clocks, and the fastest gives you 24 hours.
Anthropic's September 2026 report shows stolen AI keys funding attacks and a fake reseller harvesting them. The controls for these keys lag a decade.
Prompt injection defences fail sometimes. Scope decides what happens then. Four permission questions that bound the damage when the model is convinced.
The AI Act sets a six month floor on log retention and says nothing about content. What you record decides whether an investigation takes hours or weeks.
Top of the OWASP list since 2025, and used against a vendor sandbox in the September 2026 threat report. Four control classes, honestly rated.