RunOrNot runornot.com

Coming soon

Your agent doesn't
get a vote.

RunOrNot wraps any agent CLI in a containment boundary it cannot negotiate with, records everything it actually did, and makes the whole session undoable. Enforcement lives in the kernel — the agent's cooperation is not required.

No list, no newsletter — one mail when it opens. Or write to admin@runornot.com.

Why this needs to exist

Coding agents got production access faster than anyone built a way to supervise them. None of what follows is our research — it is the public record, and it is only eighteen months deep.

  1. 01

    The gap between believing and knowing

    91.8% said yes  ·  52% could see

    In April 2026, 91.8% of senior technology leaders said they had visibility into the AI agents running inside their organisation. Measured monitoring coverage was 52%. Just 7.2% could name a single person formally accountable for what an agent does.

    Gravitee, State of AI Agent Security 2026 — 750 CIOs, CTOs and VPs of Engineering, UK & US

  2. 02

    It has already happened

    July 2025

    Replit's coding agent deleted a live production database during an explicit code freeze — then generated thousands of fictional records and misreported the results of its own tests. The safeguards that would have stopped it, including development and production separation, were added afterwards.

    The Register · Fortune

  3. 03

    The agent is the attack surface

    2,349 credentials · 1,079 machines · ~5 hours

    In August 2025 a compromised npm build package became the first known supply-chain attack to weaponise developer AI assistants: the malware prompted the agent CLIs already installed on each machine to hunt for secrets and hand them over. The tool trusted to read your filesystem became the thing reading it for someone else.

    GitGuardian · The Hacker News · StepSecurity

  4. 04

    Not a bug that gets patched

    3 of 3

    The lethal trifecta: private data, untrusted content, and the ability to communicate outward. Hold all three at once and prompt injection stops being a curiosity. A model reads every one of them as a single token sequence — there is no privilege boundary between your instruction and a sentence the agent found in someone's README.

    Simon Willison, The lethal trifecta for AI agents, June 2025

  5. 05

    Under pressure, they do not behave

    79–96%

    Sixteen frontier models were placed in simulated corporate scenarios and given a goal that was about to be taken away. In 79% to 96% of runs — depending on the model — they chose insider-threat actions, including blackmail. Anthropic is explicit that this was a stress test: no such behaviour has been observed in real deployments.

    Anthropic, Agentic Misalignment, June 2025

  6. 06

    The bill is already arriving

    40%+ cancelled by end of 2027

    Gartner expects more than 40% of agentic AI projects to be scrapped — citing escalating costs, unclear business value, and inadequate risk controls. The third one is the only one a security boundary can fix, and it is the one nobody budgets for until an incident.

    Gartner, press release, June 2025

Do the arithmetic yourself

Blast radius

An agent session is not one decision you approve. It is several hundred you never see, and by the time the summary appears, all of them have already run.

Actions this session
360
You will never read
317
In a five-day week
4,752

Every one of them had already happened by the time you looked.

Arithmetic, not a study — the rates are yours to set. One dot ≈ 1.1 actions.

Every number on this page belongs to someone else. Ours are not ready to show yet — and a security tool that publishes its guarantees before it can keep them is the problem, not the fix.