ChanlChanl
Blog/Security & Compliance

Security & Compliance

Browse 23 articles in security & compliance.

Security & Compliance Articles

23 articles · Page 1 of 2

Government Building with AI Circuit Pattern Overlay, Representing Intelligence Agencies Publishing Guidance on Agentic AI Adoption
Security & Compliance·11 min read

The Five Eyes Published an Unusually Specific AI Agent Advisory

The Five Eyes published the first joint guidance on agentic AI security. For CX builders it's specific: tool permissions, schema injection, and human oversight.

Read More
Abstract illustration of a tangled network of nodes with one highlighted red connection point
Security & Compliance·14 min read

Agentjacking: how attackers hijack production AI agents

Agentjacking is a new attack class that targets the data your agent trusts, not the model itself. Learn how attackers exploit CRM notes, tool responses, and knowledge bases to hijack production CX agents, and how to stop them.

Read More
A numbered security checklist overlaid on a circuit-board pattern, rendered in dark tones with warm amber accent lighting
Security & Compliance·18 min read

The OWASP Top 10 for agentic AI: a CX builder's field guide

OWASP published its first Top 10 for Agentic Applications in 2026. Here's what every team building CX agents needs to know, including the three risks that traditional AppSec was never designed to catch.

Read More
Diagram showing AI agent OAuth identity flows and permission scopes in a production CX system
Security & Compliance·14 min read

Your AI agents need their own identity

Most CX agents share a single API key with every other service on your stack. Here's how to implement proper agent identity: OAuth 2.0, scope minimization, JIT provisioning, and instant kill switches.

Read More
Architectural diagram of a multi-agent delegation chain with explicit trust tokens shown between each layer, rendered on a dark technical background
Security & Compliance·15 min read

When your agents call other agents, don't assume trust

Multi-agent systems create delegation chains where each agent trusts the one that called it. That assumption is how prompt injection and privilege escalation get in. Here's how to enforce scoped trust instead.

Read More
Blueprint-style diagram of a secure agent workspace with labeled permission zones for CRM, billing, and customer data
Security & Compliance·15 min read

Agent containment: what Microsoft's MXC means for CX

Microsoft unveiled MXC at Build 2026: OS-level sandboxes for AI agents with policy-driven containment and Entra-backed identity. Here's what it means for teams building CX agents.

Read More
Developer Building Scoped Credentials for an AI Agent on a Laptop
Security & Compliance·13 min read

How to Build Production-Safe Credentials for AI Agents

After PocketOS lost its production database to a nine-second AI agent error, here's the credential model that would have stopped it: vaults, scoping, RBAC, and boundary tests.

Read More
EU Flag and an AI Compliance Checklist for the August 2026 EU AI Act High-Risk Deadline
Security & Compliance·12 min read

The EU AI Act Deadline Is 11 Weeks Away. Your CX Agent Is Probably High-Risk

The EU AI Act's high-risk compliance deadline is August 2, 2026, just 11 weeks away. Here's what CX teams building AI agents for European markets need to have in place before then.

Read More
A clean late-evening desk, a phone resting after a call, a single line crossed out on a notepad. Calm, no triumph.
Security & Compliance·13 min read read

Build a Save-Desk Voice Agent That Won't Get You Sued

FTC click-to-cancel was vacated. State laws still bite. The cancel-first architecture, one-shot offers, and audit trail for a save-desk voice agent.

Read More
Warm clinic waiting room at golden hour. An elderly patient holds a phone gently, eyes calm. A nurse passes softly in the background. Teal and copper palette.
Security & Compliance·12 min read read

How to Build a Healthcare Appointment Voice Agent (FHIR, 270/271, HIPAA)

Most voice AI tutorials stop after hello. The real build: identity verification, FHIR slots, 270/271 eligibility, A2P SMS, escalation, with HIPAA gates intact.

Read More
A parent on the phone with a hand on a sleeping child's forehead at dawn. Quiet, attentive, calm.
Security & Compliance·12 min read

Building an AI Nurse Line Without Practicing Medicine

Health systems pay $20-30 per nurse-line call. AI is the obvious cost play, but every triage agent raises a malpractice question. Here's the safe architecture.

Read More
An ID Card Propped Against a Notebook on a Quiet Desk at Evening, Two Hands Tilting a Phone Down to Photograph It
Security & Compliance·12 min read

Build a KYC Voice Agent: 4-Minute Account Open, 5-Year Audit Log

Voice collects name, DOB, SSN. SMS hands the camera the rest. OFAC screens before the next word. Architecture of a KYC voice agent that survives a BSA exam.

Read More

El briefing de Signal

Un email por semana. Cómo los equipos líderes de CS, ingresos e IA están convirtiendo conversaciones en decisiones. Benchmarks, playbooks y lo que funciona en producción.

500+ líderes de CS e ingresos suscritos