05/04/2026
We just published a paper on why your AI agent is probably compromised right now.
847 production deployments. 2,347 vulnerabilities. Here’s what we found 👇
- 91% of agents are vulnerable to tool-chaining attacks.
- 94% of memory-augmented agents can be poisoned.
- 84% fail security policies the moment a session ends.
- And 67% exhibit goal drift, meaning the AI is no longer pursuing its original objective by step 15.
This is what that looks like over time. Unprotected agents hit 89.4% goal drift by step 31. With continuous monitoring, that number stays under 15%.
The difference between those two lines is the Immune System for AI.
We built a six-layer runtime governance infrastructure that operates at the output layer — no retraining, no vendor lock-in, no replatforming. It works on top of any model.
Co-authored with Stanford, MIT CSAIL, Carnegie Mellon, ITU Copenhagen, and NVIDIA.
Open access 👉 paper.elloe.ai
Last week South Africa withdrew its entire national AI policy because AI-fabricated citations passed Cabinet review undetected.
That’s not a South Africa problem. That’s a deployment infrastructure problem. Every government, hospital, and financial institution using AI right now is exposed.
We built the immune system.