Eighty-eight percent of IT leaders report at least one security breach involving AI agents in the last 12 months, according to the AvePoint State of AI 2026 report. Despite this frequency, the industry remains stuck in a cycle of reactive deployment. The ngCERT GHOSTJACKING advisory, released October 6, 2026, attempts to break this cycle by shifting the focus from detection to structural prevention.
The advisory formalizes nine hardening steps, including deny-by-default network egress, human-in-the-loop approval, and the use of least-privilege Model Context Protocol (MCP) servers. It also mandates treating tool output as untrusted, implementing short-lived scoped credentials, segmenting agent execution, and disabling autonomous code, file system, or shell access by default. The core directive is clear: stop trying to detect malicious intent and start restricting the agent’s ability to act on it. Detection tools are largely ineffective against actions that appear legitimate to the system.
The gap between this technical roadmap and actual enterprise implementation is wide. Consider the adoption of agent-jackstop, a set of drop-in configurations for Cursor and Claude Code released by Tenet Security in June 2026. After four months, the repository has only 25 stars and 6 forks. While enterprise adoption data for this specific tool is not public, this low engagement serves as a proxy for the broader inertia in deploying open-source security hardening. Organizations are aware of the risks, yet they are not integrating available defensive configurations into their workflows.
This inertia is a governance failure, not a technical one. Survey data highlights a persistent disconnect: while 86% of IT and security decision-makers view AI agents as mission-critical, only 37% have established a formal AI policy, according to the Darktrace 2026 State of AI Cybersecurity report. Furthermore, only 15% of organizations have defined ownership for most of their agents. This lack of oversight is compounded by the complexity of the environment; only 5% of organizations use a single agentic platform, while 43% rely on four or more, effectively multiplying the hardening surface. Additionally, 54% of organizations report having between 1 and 100 unsanctioned agents, creating a shadow AI problem that complicates any attempt at centralized security.
The urgency for hardening is underscored by the reality of prompt injection. As noted in the OWASP Top 10 for Agentic Applications 2026, Agent Goal Hijack (ASI01) is the number one risk. Hardening measures like those in the ngCERT advisory are designed to reduce the blast radius, not to provide immunity. Even the creators of agent-jackstop explicitly state that their configurations do not make an agent immune to prompt injection. Enterprises must accept that these risks are inherent to the architecture of current agentic systems.
The burden of this reality falls squarely on the enterprise. When Tenet Security demonstrated Agentjacking against a $250B Fortune 100 company – hijacking over 100 agents with an 85% success rate – they highlighted the vulnerability of injectable Sentry DSNs across 2,388 organizations. Sentry acknowledged the disclosure on June 3, 2026, but declined to provide a root-cause fix, labeling the issue as technically not defensible. This response confirms that organizations cannot wait for vendors to patch these architectural flaws.
The path forward requires a shift toward trust-through-defaults. As detailed in previous coverage of ngCERT GHOSTJACKING, Agentjacking at DEF CON 34, and Federal MCP Exposure, the technical components for securing these systems are available. The hardening gap is a governance choice. Until organizations move from acknowledging the 88% breach rate to enforcing the nine-step protocol, they remain exposed to the predictable consequences of their own agentic infrastructure.
