Skip to main content
Arif Mughal

Tag

#AI Agents

4 articles with this tag.

Categories

Tags

AI Security

Prompt Injection Is a Data Problem, Not a Model Problem

Indirect prompt injection arrives through the documents, email, web pages and tool results an AI system reads, not through the user. OWASP's 2026 Top 10 now says no reliable prevention exists and that defence is architectural. This article explains where injected instructions enter, what model-level defences can and cannot do, and the trust boundaries on data that still hold when the model is fooled.

10 min read

AI Governance

Agent Sprawl: An Inventory and Lifecycle Model for Enterprise AI Agents

Most organizations can now build AI agents faster than they can say who owns them. This article proposes a twelve-field inventory record and a seven-stage lifecycle from proposal to retirement, and maps each stage to what the Microsoft 365 Agent Registry, Microsoft Agent 365, Entra Agent ID and Power Platform inventory actually do as of September 2026, including where the tooling stops.

10 min read

AI Architecture

Who Approved That? Human-in-the-Loop Patterns for AI Agents That Act

Once an AI agent can write to systems, send email or move money, "a human approves it" is not a design. This guide classifies agent actions by consequence and reversibility, maps each class to an approval pattern, and sets out what the audit record must hold to survive a review, grounded in what Microsoft 365 Copilot, Copilot Studio, Microsoft Foundry and Purview actually provide as of September 2026.

9 min read

AI Architecture

Microsoft Copilot Studio vs Microsoft Foundry: Which AI Agent Platform Should Your Business Choose?

Copilot Studio and Microsoft Foundry are not competitors — they sit at different levels of abstraction, and three changes in 2026 have quietly retired most of the advice written about choosing between them. A decision framework built on who owns the runtime, where the data already lives, and who operates the agent on day ninety, with the cost shapes, governance asymmetries and interop paths verified against Microsoft's own documentation.

15 min read