Today: the five AI headlines of the day → and the AI Wiki
What a signpost is How to read this page

A watched question with a line drawn in advance

The threshold was written before the observation existed. That is what stops a state from being argued into place after the fact.

Four states, no probabilities

Observed, emerging, contested, not observed. These are qualitative readings against the threshold. No number is invented here, because an invented number would be the most quotable and least true thing on the page.

It stays alive between revisions

The update condition names what would move the state. A signpost that has stayed quiet is information too, and is published rather than hidden.

New to this publication?

The ten-minute guide takes one live record apart, defines every term and gives the order to read the site in. Start here →

SCN-QUBE-002 · Observed 2025-01-17

emerging

Agent Marketplace without Accountability

Qualitative signpost review · no probability assigned

Bounded observation

NIST/CAISI found that tool-using agents remained vulnerable to indirect prompt injection: across five custom injection tasks the average attack success rate was 57% on one attempt and 80% over 25 attempts. This demonstrates an accountability-relevant activation risk, but not marketplace-scale disputes or unsigned ownership chains.

Trigger threshold

Move to observed when a cross-organization agent catalog or marketplace has documented incidents involving opaque delegation, confused-deputy execution, unscoped credentials or disputed liability without effective owner and revocation metadata.

Counter-indicator

The experiments used simulated AgentDojo environments and selected attacks; they do not measure marketplace adoption, signed provenance, credential scope in production or actual loss incidence.

Update criterion

Review NIST/CAISI, incident databases and marketplace governance releases quarterly; upgrade only with attributable production incidents and downgrade if portable identity, liability and revocation controls become operational defaults.

Primary routes

  1. https://www.nist.gov/news-events/news/2025/01/technical-blog-strengthening-ai-agent-hijacking-evaluations