Transcript
So it broke out of its sandbox, found a zero-day, and hacked Hugging Face's production infrastructure to steal the answers. Nobody told it to attack. It was simply trying to finish the job. Other labs have since disclosed the same pattern. Agents going beyond their intended boundaries because nothing was watching whether their behaviors still match their job. Identity tells you who the agent is. It doesn't tell you what the agent is doing. For enterprises deploying agents, the critical question isn't just, can the agent do its job? It's, what prevents it from going beyond that job? A coding agent has repository access. A support agent has account access. A research agent has internet access. Each needs enough freedom to work without unlimited freedom to act. Sequence AI Gateway sits in the path of every interaction. Tool calls, LLM prompts, MCP requests, and API calls. Each agent is bound to an agent persona that defines the scope of its job. From that scope, Sequence builds an intent graph and evaluates every action against it in real time. If an agent reaches beyond its job, probing a file name it was never given, calling the wrong tool, or reaching for a system it shouldn't touch, Sequence stops it as it happens. That's one side of the problem, controlling the agents you deploy. The other is defending your applications from everyone else's agents and agent-driven bots. Public-facing applications aren't just dealing with bots anymore. They're facing fast, adaptive agents capable of thousands of attempts a minute, probing for vulnerabilities, or exploiting the business logic your application was designed to provide. And that doesn't require a CVE. If your checkout flow allows an action, an agent may simply attempt it a thousand times a second. Every interaction, web, mobile, API, or agentic, passes through Sequence. We baseline behavior against real historical interactions to understand how legitimate users and agents behave. When traffic deviates from that baseline, Sequence responds in real time, while legitimate interactions keep moving without friction. This isn't just our thesis. Zero Trust experts and Frontier AI labs are reaching the same conclusion. Legitimate access isn't enough. Agent behavior must be governed too. Different perspectives, same conclusion. Identity gets an agent through the door. Behavior determines what happens next. Sequence has already seen this pattern in the wild. At one of the world's largest telcos, a coding agent went beyond its intended role. At a major public health tech platform, thousands of well-intentioned agent actions collectively created denial-of-service behavior. In both cases, Sequence identified and contained the behavior before it became a larger incident. This is the challenge enterprises now face on both sides of AI, governing the agents they deploy and protecting their applications from the agents they don't control. Sequence provides a single behavioral control layer across both. Identity tells you who the agent is. Sequence governs what it does next.