Discussion about this post

User's avatar
State of Play's avatar

Thanks for this. Tier 4 assumes you can enumerate the tool calls worth gating, but a recent finding cuts against that: safety filters that blocked a risky request in one chat turn failed completely once the same request got split across an automated workflow's steps, and 88% of firms reported an AI-agent security incident in the past year. That's the same gap behind the S3 buckets and PII leaks you open with: at a high-growth shop the registered surface and the running one diverge continuously, so tier 4 needs discovery running as a standing control, not a one-time intake before the gates go up.

No posts

Ready for more?