KPATH
Insights

Notes from the people building it.

Analysis from the KPATH team on agent containment, MCP security, what a control plane actually does, and what the EU AI Act changed.

AI agent kill switch: why stopping one agent isn't enough

When one agent hands work to another, a kill switch that stops a single agent leaves the rest of the chain running. Containing a multi-agent incident takes five things, and proving the stop held takes a record that does not depend on trusting whoever produced it.

The EU AI Act just passed a milestone. Here is what actually changed

On 2 August 2026 the EU AI Act reached one of its biggest dates, and most coverage misread it. The high-risk obligations were pushed back to December 2027. What switched on is enforcement, transparency and fines, and underneath all of it sits one question you should be able to answer today.

MCP security: what has gone wrong in 2026

Four things broke this year: a critical flaw in core MCP infrastructure, instances left exposed on the internet, disclosed flaws in Claude Code, and a backdoored LiteLLM package on PyPI. MCP is now how most agents reach tools and data; it got there fast, and security did not keep up.

What an AI agent control plane actually does

Five things, all of them between an agent's request and the action it takes: intent arbitration, route selection, per-action policy, context continuity and audit. Get them right and agents become infrastructure you can trust. Get them wrong and you join the 40% Gartner expects scrapped by 2027.

The death of the aggregator: how the agentic web will end the platform tax

By removing the need for a permanent middleman. Aggregators charge 15 to 25 percent because they own discovery. Once a personal assistant can query hundreds of hotel agents directly and compare real offers, aggregation happens only when it is needed and then disappears. The toll road has nothing left to charge for.

The agentic web: why every business will soon have an AI that speaks for it

Because a website makes the visitor do the work and an agent does not. Once a business is represented by an agent that can answer questions, make bookings and complete transactions, your own assistant can talk to it directly. Websites are interfaces you navigate. Agents are entities you talk to.

The missing piece of the agentic web: why AI agents need a discovery layer

Because an assistant cannot contact agents it cannot find. Without a layer that turns a natural language request into a list of verified agents, assistants fall back on web search and aggregator partners, and the agentic web ends up as the old web with a chat interface.

Updated

The first step

Start in monitor mode. See everything before you enforce anything.

Deploy in monitor mode: observe only, enforce no policy, rewrite no agents. Flip to enforce by repointing egress. See the agents already running in your estate before you decide what to enforce.

Book a monitor-mode pilot See the platform