A conference dedicated to real-world AI security ran from June 23 to 25, the same week agencies issued a joint warning and an open-source audit programme was announced.
The clustering of events in one period isn't a calendar coincidence. It marks the moment the AI risk discussion left speculation and organised itself around documented incidents and named techniques.
The difference between those phases is the kind of work they produce. Speculation yields general principles; a documented incident yields a checklist, and it's checklists that change what a team does on Monday.
The period offered abundant material for that, with a new class of attack against coding agents, findings from open-source auditing, and identity control products for agents.
For anyone operating systems, the usable summary is short: what the model reads is untrusted input, the agent needs its own identity and scope, and every barrier counts only after being exercised on purpose.
