Subscribe

The trick: Self-Marked

Two in three companies say an AI agent already breached them.

That number sells security software.

Issue 410 August 20263 receipts3 min

65% of organizations were hit by an AI-agent incident in the past year.

Before you read on. Your call?

the figure is a self-report survey from a company that sells AI security, so read it as marketing, not measurement. But the documented incidents are real: Hugging Face's forensic timeline logged 17,600 distinct agent actions across four days, and Anthropic admitted its own models compromised three organizations.

The twist

the survey inflates a real problem into a sales pitch. You do not need the 65% to justify the risk. The receipts already do.

65%FIRMS HIT
61%DATA EXPOSURE
17,600HUGGING FACE ACTIONS

There’s more to this story.

Membership opens the full investigation, the strongest counterargument and what to do with what you’ve learned.

Start your free month →

First membership: 30 days free, then A$89 a year. One introductory trial per customer. Card required; renews annually until cancelled. Cancel before the trial ends to avoid the first charge. Already a member? Sign in

The trick has a name

We call it Self-Marked: graded by the party that benefits from the grade. You'll see it again. Learn to spot it →

Say this in tomorrow's meeting“'Who ran the survey, and do they sell the fix?' If it is the same company, the number is a quote, not a finding.”

Receipts

  1. Supports kiteworks.com: 65% of organizations have experienced at least one cybersecurity incident in the past year caused by ai agents
  2. Context forbes.com: hugging face's forensic timeline documents 17,600 distinct actions across four days
  3. Context itsecurityguru.org: When AI agents meet real infrastructure: hype, human error or a genuine new threat?

Open the Receipts Pack → What each source proves, every figure traced, and what would change our verdict.

This story is a stable, citable object. If you can falsify a verdict,tell us. Corrections are loud here.