Cursor Agent Deleted a Prod Database in 9 SecondsFEATURED
Cursor agent reportedly wiped a Railway production database and backups in one API call. Prompts aren't permissions — agents need pre-execution gates.
Engineering insights, product updates, and best practices for AI agent runtime authority, exposure, and cost control.
Tools you can run on your own numbers: Cost Calculator (Claude vs GPT) → · Blast Radius Risk Calculator → — every configuration produces a shareable URL. Many of the posts below link to a calculator pre-loaded with the post's specific scenario.
New to Cycles? Read these posts in order to understand runtime authority from the ground up.
Ready to try Cycles? Jump to the End-to-End Tutorial.
Cursor agent reportedly wiped a Railway production database and backups in one API call. Prompts aren't permissions — agents need pre-execution gates.
Agents span providers, tools, tenants, and workers. Learn why governance needs cross-cutting budget authority plus application-side authorization at runtime.
AI agents moved to production faster than governance kept up. This is the state of enforcement, regulation, and incidents in 2026 — and what comes next.
Classify AI agent actions by blast radius, assign consistent risk scores, and translate each assessment into enforceable runtime budget controls in practice.
Documented AI agent incidents and failure patterns — runaway costs, action misfires, security exploits, multi-agent cascades — scored by cost and blast radius.
Why safe agent lease heartbeats require server-authoritative remaining TTL, monotonic timing, bounded retry windows, and fresh idempotent replay responses.
How Cycles tested a critical-path agent gate for latency, saturation, fail-closed behavior, ledger correctness, and durable recovery across four SDKs.
The MCP 2026-07-28 release candidate removes sessions and adds routing headers. What operators should prepare before the final specification is published.
The CMA says you're liable for what your agents do. Contracts exclude the damages. Insurers ask for oversight evidence. Signed decision records serve all three.
Cycles Budget Guard for Claude Code adds dispatch-path enforcement, blocks denied gated tools before they run, and safely retries recorded-call settlement.
OWASP's June 2026 data says prompt injection touches six of ten agentic risks. Which ASI categories a pre-execution authority layer can actually enforce.
Willison's lethal trifecta and Meta's Rule of Two both subtract agent capabilities. A third option: keep all three legs and meter the most dangerous one.
Okta, Microsoft Entra, and A2A now give AI agents identities. Identity answers who an agent is — not what it may do next, how much, or at whose expense.
Wiz found 1.5M agent API tokens exposed on Moltbook via a hardcoded Supabase key. What it teaches about agent identity, credentials, and runtime authority.
The first production agent budget should be small, scoped, and tied to one painful failure mode. Choose tenant, run, or tool budgets based on blast radius.