| $500M Claude bill |
No spending caps, no agent budget controls |
Per-agent quotas, real-time usage dashboard, threshold alerts |
| 13-hour AWS outage |
Agent ran with full human-level permissions, no approval gate |
Dangerous operation detection, approval gates, permission scoping |
| rm -rf filesystem destruction |
Unchecked shell execution, no command classification |
Command flagging intercepts DANGER operations before execution |
| Samsung source code leak |
No egress filtering, data sent to external provider |
Egress filtering keeps data inside your infrastructure |
| Air Canada hallucinated policy |
No output validation, no human-in-loop for binding outputs |
Output validation, human-in-loop flag for commitment-generating responses |
| DPD and Chevy brand meltdowns |
No content policy enforcement on public-facing AI |
Prompt guard, content policy, operator-defined output rules |
| Bing Chat prompt injection |
Injection bypassed system prompt, no gateway-level defense |
Prompt guard middleware intercepts injection at the gateway |
| GDPR silent breach exposure |
No egress control, no audit trail for breach notification |
Egress filtering plus full audit log provides breach evidence and compliance posture |