In this interview with Help Net Security, Ariel Assaraf, CEO of Coralogix, explains why a system prompt can describe a boundary for an AI agent but cannot enforce one. Assaraf covers how his team builds AI agent guardrails at the execution layer, limits context without expanding authority, and tunes controls by risk so agents stay useful during incidents. He describes how he tracks the consequences of agent actions, since an agent can return 200s and still do harm.
Stop watching what AI agents say and start watching what they do
In this interview with Help Net Security, Ariel Assaraf, CEO of Coralogix, explains why a system prompt can describe a boundary for an AI agent but cannot enforce one. Assaraf covers how his team builds AI agent guardrails at the…
Help Net Security
Publisher
Sep 25, 2026 at 5:30 AM UTC · Updated 3시간 전 · 5 분 소요


You’ve drawn a line between telling an agent what it shouldn’t do and preventing it from doing it. Walk us through a real incident where that distinction mattered: where a documented policy or system prompt existed, but the agent still crossed the line. What was missing technically?
The recent Gemini hacking incident is a good example of this. The agent was supposed to operate inside a controlled cybersecurity test, but a configuration error gave it internet access and it entered three real systems. It eventually recognized the mistake and stopped, which is encouraging, but by then the boundary had already been crossed.
The missing controls were outside the model: network isolation, target allowlists, scoped credentials and an independent authorization check before execution. Those controls need to exist regardless of what the model has been instructed to do.
Article Intelligence
Topics
Regulation Signal
in progressUpdated 2달 전
SEC Crypto Asset Market Structure RulemakingRelated Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
