Skip to main content

Thought Leadership: Security, Identity and Harnessing Agentic

AI Openness: 3 Years on from Llama 2 Report

Sal Kimmich, CEO, Gadfly AI

Agentic AI breaks assumptions open source security has relied on for two decades. Code review assumed a human wrote the code. Dependency scanning assumed a human chose the dependency. Neither holds when an agent writes, selects and executes in the same session.

Identity is the first gap

There is no standard way to answer a simple question: which agent, acting on whose authority, made this call. MCP solves tool discovery, not authentication between agents. AGNTCY, now under the Linux Foundation, is the closest answer at the protocol layer, and it is early. Most deployments today authenticate the human and trust the agent by default.

Harnessing is the second gap

An agent with write access to a repository, a registry or a CI pipeline is a privileged actor. Few teams apply the access controls to agents that they apply to a new hire.

The third gap is what agents find

Frontier models scan codebases and surface vulnerabilities faster than any maintainer community can triage. Akrites, launched by the Linux Foundation in June 2026, is the sector’s response: shared incident response, one coordinated disclosure process, a maintainer-of-last-resort commitment. It is also confidentiality-first and vendor-funded, which sits uneasily against open source’s public-by-default norms.

Identity, access control and disclosure process are the three load-bearing walls for agentic security. Open source has working models for all three. It does not yet have them adapted for agents.

What this means under UK regulation. The Cyber Security and Resilience Bill is not yet law. It has cleared the Commons and is before the Lords, with Royal Assent expected later in 2026 and obligations phasing in after. As drafted, it would bring managed service providers and data centres into scope with 24-hour incident reporting. It says nothing about agents specifically. Start logging what yours do now, ahead of the requirement.

The Bill has been criticised in the House of Lords for its lack of focus on AI. Open source is likely to be picked up in ancillary regulation.

First published by OpenUK in 2026 as part of AI Openness: 3 Years on from Llama 2

©OpenUK2026

Download Thought Leadership Download Report View all thought leadership

Scroll to top of the content