Blog
AI security insights, research, and product updates from the Humanbound team.

Beyond AI Security: The Rise of AI SecOps: Splunk + Humanbound
Splunk is where most SOCs already live. Here's how Humanbound streams AI agent security findings into Splunk as structured, HMAC-signed webhooks, so agent security gets the same real-time alerting and incident response as everything else the SOC already handles.

Beyond AI Security: The Rise of AI SecOps: Microsoft PyRIT + Humanbound
PyRIT is Microsoft's open-source, research-grade red teaming framework. Here's how a point-in-time PyRIT engagement and Humanbound's continuous, compliance-mapped monitoring plug into each other, including how PyRIT's findings can train the Humanbound Firewall directly.

Beyond AI Security: The Rise of AI SecOps: Promptfoo + Humanbound
Promptfoo and Humanbound aren't competing for the same slot. Here's how Promptfoo's CI red teaming and Humanbound's continuous, compliance-mapped monitoring plug into each other, including how Promptfoo's scan results can train the Humanbound Firewall directly.

Agent Security Debt: Nobody Is Trying to Break Your AI Agent until It Ships
In 2017 I got a CVE for an unencrypted smart bulb. Nine years later, AI agents are shipping with the same gap: nobody tried to break them before launch. Here's how to break your own agent this afternoon, before someone else does.

The Agent Attack Scenario Library: A Community Reference, Mapped to OWASP
A community library of agent attack scenarios, each mapped to the OWASP Top 10 for Agentic Applications and paired with the guardrail that closes it. Open, credited, and free to contribute to.

Why we open-sourced humanbound-firewall
We released humanbound-firewall under Apache-2.0. A multi-tier runtime defense for AI agents, with each layer inspectable, escalating on uncertainty, and trainable on your own adversarial test data.

AI Security Means Two Different Things. Mythos Just Made That Visible.
AI security maps to two different markets: AI for security (AI4Sec) and security for AI (Sec4AI). The Claude Mythos Preview made the distinction unmissable. Here is how to tell which one you are actually buying.

Beyond Moderation: Why LLM Systems Need a Policy Layer
Moderation APIs catch harm and injection attempts but fail to enforce domain-specific policy. A cross-domain evaluation shows why production LLM systems need both moderation and policy reasoning layers.

Your Agent Passed Its Security Test. That Was Three Weeks Ago.
The security industry is applying shift-left to AI agents. But AI agents aren't deterministic. The gap between testing on deploy and staying secure in production is where risk accumulates.

The Enforcement Illusion: Why AI Agent Security Starts with Testing, Not Walls
The AI agent security market is fragmenting into enforcement, identity, and control plane vendors. But the incident data tells a different story: most agents ship without any adversarial testing at all.

