Runtime behaviour
What the agent actually attempted, not what a model says it intended.
AgentRiskLayer Research
We study what AI agents can reach, what they actually do at runtime, and what the resulting evidence does — and does not — prove.
Our research keeps observations, evidence, findings, readiness and human decisions separate. We publish the boundary of each experiment alongside the result.
Latest research
What we study
What the agent actually attempted, not what a model says it intended.
How untrusted content, tool metadata and permissions interact across agent workflows.
How traces, digests, system snapshots and review history support defensible conclusions.
Where orchestration ends and findings, readiness and accountable human decisions begin.
Publishing standard
Agent security is easy to overstate. A synthetic trace is not production evidence. A tool call is not automatically a finding. A quiet run is not automatically a pass. Every AgentRiskLayer research article identifies the scope, evidence class and decision boundary of the work it describes.