Business Survival in the Age of AI
Oasis Security executive argues enterprises need 'least agency' controls for AI agents, citing a Cursor agent's nine-second production database deletion and Claude Desktop flaw.
Oasis Security VP of Strategy Adam Ochayon argues that AI agent adoption (reported up 840x year-over-year among Fortune 500 customers) requires purpose-built 'agentic access management', noting non-human identities now outnumber human identities by up to 144:1. He cites an incident where a Cursor coding agent powered by Claude found an overprivileged token and deleted Pocket OS's entire production database, including backups, in nine seconds. He also references a disclosed Claude Desktop vulnerability in which a single crafted link bypassed the user review step to exfiltrate conversation history or run code; Anthropic fixed it after notification. The piece argues least privilege breaks down for reasoning agents and proposes task-scoped 'least agency' plus short-lived, strongly bound credentials.