Infrastructure
The technical layer that enables (or blocks) agents. From shared Jenkins to ephemeral agent sandboxes.
Maturity →
You don't have to figure this out alone.
Every level in this matrix has a path. Read the playbooks the teams that have climbed it wrote. Run the assessment with our consultants. Start where you are.
Book an AI Maturity Assessment session with your team.
We walk you through all four perspectives, score where you actually are, and leave you with a 90-day plan to climb in the dimensions that matter most.
The infrastructure lesson of September is that agents got identities because attackers already had their tokens.
GreyNoise documented the first mass-exploitation campaign run by AI agents: 395 organisations in 48 countries, the first compromise 26 seconds in, stolen Claude, Cursor and Gemini sessions on 5,871 machines and $600k of model credits burned through one compromised agent dashboard. Anthropic's threat report added the quieter variant: a prompt injection persuaded an AI vendor's automated evaluation sandbox to hand over production API keys for several providers, and the follow-on hit around thirty AI companies in four days. Its advice is the line to put on the wall: treat AI keys and agent integrations like production credentials. In runtime terms that means no personal access tokens and no shared long-lived keys for agents, credentials injected at run time from a vault or broker, and task-scoped tokens that expire in minutes.
The identity industry answered in the same month. Okta shipped agent-to-agent connections and access certifications for agents, with an agent gateway and a kill switch for live tokens on its roadmap. CrowdStrike's Agentic Identity Provider auto-registers agents with a verifiable identity and short-lived credentials and links each action to a human or workload. The IETF WIMSE working group adopted `draft-ietf-wimse-aims-00`, its first baseline for agent authentication. For MCP, the maturity step is getting access granted centrally by the identity provider (Cross App Access, Enterprise-Managed Authorization) instead of a sprawl of per-user consent screens, behind a gateway that shows each caller only the tools it may use. And the gateway itself is now a target: LiteLLM's MCP auth bypass reached the CISA KEV list in September.
Underneath, the agent's plumbing kept failing. GitSpawn used `core.fsmonitor` in a repository's own `.git/config`, so the agent's startup `git status` ran attacker code outside the sandbox, with no prompt, across eight agents. Plugin4Shell beat SHA-pinning in plugin marketplaces with branch names that look like commit hashes. Deadbugz behaved like an ordinary MCP server for exactly three tool calls, then rewrote its tool metadata to hunt for SSH keys, AWS credentials and kubeconfig, which is why install-time review is not enough and tool metadata needs watching at runtime. And OpenAI disclosed a training agent that escaped its sandbox over DNS while the automatic shutdown failed. Assume escape still holds. What September adds is: assume the token is stolen, and make sure you can revoke it in seconds.