Give an AI agent read access to a Kubernetes fleet and one lesson repeats across every public incident: the controls that held were infrastructure, the controls that failed were prompts. Here is the four-rung containment ladder practitioners have converged on.
Residency maps answer where the bytes sit. The question a regulator actually asks is who can compel access to them, under whose law, with what notice to you. What changed in the last eighteen months, and how to decide.
Two incidents a week apart, one where an agent was the attacker and one where it was the trusted insider. Neither involved a bypassed control. The gap is that we decide authorization once, at connect time, and then trust forever at runtime.
Alberta ran roughly 50 AI agents across every repository the province owns. The results are impressive. Here is the security review I would run on the review itself.
Clearing houses, the shared memory layer agents read and write, are the high ground of the agent era. They are also the softest thing in the stack. Why memory poisoning is the breach pattern this architecture invites, and the four properties that have to be designed in.