<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>opsagent — AgentOps blog</title><description>opsagent is an independent EU publisher on AgentOps: the security, observability, governance, and reliability of autonomous AI agents.</description><link>https://opsagent.pl/</link><language>en</language><item><title>Agentic engineering: the discipline that takes an agent from prototype to production</title><link>https://opsagent.pl/blog/agentic-engineering/</link><guid isPermaLink="true">https://opsagent.pl/blog/agentic-engineering/</guid><description>What agentic engineering is, how it differs from prompt engineering and orchestration, and how opsagent&apos;s seven pillars fit together as one engineering process for building agents you can trust in production.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Indirect prompt injection: detecting and defending against it in your agent pipeline</title><link>https://opsagent.pl/blog/indirect-prompt-injection/</link><guid isPermaLink="true">https://opsagent.pl/blog/indirect-prompt-injection/</guid><description>How to detect and contain indirect prompt injection in a production agent pipeline — content isolation, provenance, output filtering and the layered defenses that shrink the blast radius.</description><pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Red teaming AI agents: building a red-team program in your organization</title><link>https://opsagent.pl/blog/red-teaming-ai-agents/</link><guid isPermaLink="true">https://opsagent.pl/blog/red-teaming-ai-agents/</guid><description>How to stand up an agent red-team program as a repeatable process — scope, cadence, roles, and how organizational red teaming of autonomous agents differs from a one-off pentest.</description><pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Memory poisoning: defending an agent&apos;s memory in production</title><link>https://opsagent.pl/blog/memory-poisoning/</link><guid isPermaLink="true">https://opsagent.pl/blog/memory-poisoning/</guid><description>How to defend a production agent&apos;s long-term memory and retrieval store against poisoning — validation, provenance, segmentation and expiry that stop false data biasing future decisions.</description><pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate></item><item><title>The OWASP Top 10 for Agentic Applications: mitigating each risk in production</title><link>https://opsagent.pl/blog/owasp-top-10-agentic/</link><guid isPermaLink="true">https://opsagent.pl/blog/owasp-top-10-agentic/</guid><description>A production playbook for the OWASP Top 10 for Agentic Applications: how to meet and mitigate each of the ten risks with concrete controls, guardrails and governance.</description><pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Tool poisoning: when an agent&apos;s tools turn against it</title><link>https://opsagent.pl/blog/tool-poisoning/</link><guid isPermaLink="true">https://opsagent.pl/blog/tool-poisoning/</guid><description>How tampered tool descriptions and crafted tool outputs steer autonomous agents into harmful actions — and the validation, isolation and provenance controls that stop it.</description><pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate></item><item><title>AI Act Article 50: transparency in agent operations</title><link>https://opsagent.pl/blog/ai-act-article-50-transparency/</link><guid isPermaLink="true">https://opsagent.pl/blog/ai-act-article-50-transparency/</guid><description>How to meet EU AI Act Article 50 transparency duties in day-to-day agent operations by 2 August 2026 — AI disclosure, content labeling and deepfake marking, wired into your runtime.</description><pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate></item><item><title>The EU AI Act timeline for autonomous agents</title><link>https://opsagent.pl/blog/eu-ai-act-agents-timeline/</link><guid isPermaLink="true">https://opsagent.pl/blog/eu-ai-act-agents-timeline/</guid><description>When each EU AI Act obligation actually bites — and what teams shipping autonomous AI agents must have ready for the Article 50 transparency deadline on 2 August 2026.</description><pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Excessive agency: the most damaging agent risk</title><link>https://opsagent.pl/blog/excessive-agency/</link><guid isPermaLink="true">https://opsagent.pl/blog/excessive-agency/</guid><description>Why over-broad permissions turn a small agent mistake into a major incident — and how least privilege, scoped tools and approval gates contain the blast radius.</description><pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate></item><item><title>EU AI Act vs GDPR: two regimes your agents must satisfy</title><link>https://opsagent.pl/blog/ai-act-vs-gdpr/</link><guid isPermaLink="true">https://opsagent.pl/blog/ai-act-vs-gdpr/</guid><description>Why GDPR compliance does not cover the EU AI Act, where the two overlap, and what an autonomous agent has to satisfy under each.</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Writing a company AI policy that actually governs agents</title><link>https://opsagent.pl/blog/company-ai-policy/</link><guid isPermaLink="true">https://opsagent.pl/blog/company-ai-policy/</guid><description>A practical template for an internal AI policy — the sections that matter, how to cover autonomous agents and Shadow AI, and how to keep it from becoming shelfware.</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate></item><item><title>ISO 42001 for agents: an AI management system, step by step</title><link>https://opsagent.pl/blog/iso-42001-ai-management/</link><guid isPermaLink="true">https://opsagent.pl/blog/iso-42001-ai-management/</guid><description>What ISO/IEC 42001 requires, how it complements the EU AI Act, and a practical path to an AI management system that actually governs autonomous agents.</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate></item><item><title>MCP security: secure configuration, identity and gateway authorization</title><link>https://opsagent.pl/blog/mcp-security-identity/</link><guid isPermaLink="true">https://opsagent.pl/blog/mcp-security-identity/</guid><description>How to run the Model Context Protocol safely in production: an MCP gateway, authorization and scoping, and non-human identity controls that keep agent tooling under control.</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Agent observability: seeing what your AI actually does</title><link>https://opsagent.pl/blog/agent-observability/</link><guid isPermaLink="true">https://opsagent.pl/blog/agent-observability/</guid><description>Tracing, metrics and cost control for autonomous agents — the five things to measure and how OpenTelemetry became the de facto standard for agent observability.</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate></item><item><title>MCP gateways and runtime authorization for agents</title><link>https://opsagent.pl/blog/mcp-gateway-authorization/</link><guid isPermaLink="true">https://opsagent.pl/blog/mcp-gateway-authorization/</guid><description>Why agents need an authorization decision at the moment of each action — and how an MCP gateway centralizes policy, approvals and audit for tool access.</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Non-human identity: governing the agents that act for you</title><link>https://opsagent.pl/blog/non-human-identity/</link><guid isPermaLink="true">https://opsagent.pl/blog/non-human-identity/</guid><description>Agents authenticate as machine identities, not people. Here is why non-human identity is now a core control — and how to inventory, scope and rotate it.</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate></item><item><title>The OWASP MCP Top 10: securing the protocol agents run on</title><link>https://opsagent.pl/blog/owasp-mcp-top-10/</link><guid isPermaLink="true">https://opsagent.pl/blog/owasp-mcp-top-10/</guid><description>A practical walkthrough of the OWASP MCP Top 10 — the security risks specific to Model Context Protocol servers — and the controls that address each.</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Zero-trust for AI agents: implementing never-trust, always-verify in production</title><link>https://opsagent.pl/blog/zero-trust-for-agents/</link><guid isPermaLink="true">https://opsagent.pl/blog/zero-trust-for-agents/</guid><description>How to operationalize zero-trust for autonomous agents and the tools and agents they call — identity, policy enforcement and segmentation that make continuous verification real in production.</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Agent cost control: FinOps for autonomous AI</title><link>https://opsagent.pl/blog/agent-cost-finops/</link><guid isPermaLink="true">https://opsagent.pl/blog/agent-cost-finops/</guid><description>Why cost is a first-class signal for agents, what actually drives the bill, and how token tracking, loop detection and budgets keep an autonomous system affordable.</description><pubDate>Sun, 14 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Evaluating AI agents: from evals to reliable production</title><link>https://opsagent.pl/blog/agent-evals-reliability/</link><guid isPermaLink="true">https://opsagent.pl/blog/agent-evals-reliability/</guid><description>How to evaluate autonomous agents you can trust — LLM-as-a-judge done right, the metrics that matter, and the CI/CD quality gates that keep agents from regressing.</description><pubDate>Sun, 14 Jun 2026 00:00:00 GMT</pubDate></item><item><title>The production metrics that tell you an agent is working</title><link>https://opsagent.pl/blog/agent-production-metrics/</link><guid isPermaLink="true">https://opsagent.pl/blog/agent-production-metrics/</guid><description>Six metrics — completion, accuracy, hallucination, latency, cost and satisfaction — that turn an agent from a black box into a system you can actually run.</description><pubDate>Sun, 14 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Tracing AI agents with OpenTelemetry</title><link>https://opsagent.pl/blog/agent-tracing-opentelemetry/</link><guid isPermaLink="true">https://opsagent.pl/blog/agent-tracing-opentelemetry/</guid><description>How to instrument autonomous agents with OpenTelemetry&apos;s GenAI conventions so every reasoning step, tool call and cost is captured in one portable trace.</description><pubDate>Sun, 14 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Agent benchmarks: what τ-bench and friends do and don&apos;t tell you</title><link>https://opsagent.pl/blog/agent-benchmarks/</link><guid isPermaLink="true">https://opsagent.pl/blog/agent-benchmarks/</guid><description>How to read agent benchmarks like τ-bench, MCP-Bench and AgentBench — what they measure, where they mislead, and why your own evals still matter most.</description><pubDate>Sat, 13 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Agent memory architecture: short-term, long-term, episodic</title><link>https://opsagent.pl/blog/agent-memory-architecture/</link><guid isPermaLink="true">https://opsagent.pl/blog/agent-memory-architecture/</guid><description>How autonomous agents remember — the three kinds of memory, when to use each, and why governing the memory layer is both a capability and a security decision.</description><pubDate>Sat, 13 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Agent orchestration: LangGraph vs CrewAI vs AutoGen and beyond</title><link>https://opsagent.pl/blog/agent-orchestration-frameworks/</link><guid isPermaLink="true">https://opsagent.pl/blog/agent-orchestration-frameworks/</guid><description>A vendor-neutral comparison of the main agent frameworks — LangGraph, CrewAI, AutoGen, OpenAI Agents SDK and Google ADK — and how to choose between single-agent and multi-agent designs.</description><pubDate>Sat, 13 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Regression testing for AI agents: stop fixing one thing and breaking three</title><link>https://opsagent.pl/blog/agent-regression-testing/</link><guid isPermaLink="true">https://opsagent.pl/blog/agent-regression-testing/</guid><description>Why a golden dataset and CI gates are the only reliable defense against silent agent regressions when models, prompts and tools change underneath you.</description><pubDate>Sat, 13 Jun 2026 00:00:00 GMT</pubDate></item><item><title>LLM-as-a-judge: calibrate it before you trust it</title><link>https://opsagent.pl/blog/llm-as-a-judge/</link><guid isPermaLink="true">https://opsagent.pl/blog/llm-as-a-judge/</guid><description>How to make an LLM judge reliable — aligning it to human labels, killing position and verbosity bias, and knowing when a judge is measuring quality versus its own preferences.</description><pubDate>Sat, 13 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Agent guardrails: the automated limits around autonomy</title><link>https://opsagent.pl/blog/agent-guardrails/</link><guid isPermaLink="true">https://opsagent.pl/blog/agent-guardrails/</guid><description>Input, output and behavioral guardrails form the safety layer that lets an agent act fast without acting dangerously. Here is what each does and how they fit together.</description><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Kill switches and circuit breakers for AI agents</title><link>https://opsagent.pl/blog/agent-kill-switch/</link><guid isPermaLink="true">https://opsagent.pl/blog/agent-kill-switch/</guid><description>Every autonomous agent needs a reliable way to stop. How to design kill switches and circuit breakers that actually halt an agent that loops, overspends or drifts.</description><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Context engineering: giving an agent what it needs, not everything</title><link>https://opsagent.pl/blog/context-engineering/</link><guid isPermaLink="true">https://opsagent.pl/blog/context-engineering/</guid><description>Why what you put in the context window decides an agent&apos;s quality, cost and safety — and the discipline of assembling the right context at each step.</description><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Graduated deployment: raising agent autonomy without incidents</title><link>https://opsagent.pl/blog/graduated-deployment/</link><guid isPermaLink="true">https://opsagent.pl/blog/graduated-deployment/</guid><description>A five-stage path — dry-run, read-only, simulation, staging, production — for giving an AI agent more autonomy only after evidence says it is safe.</description><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Human oversight and agent autonomy: HITL, HOTL, HOOTL</title><link>https://opsagent.pl/blog/human-oversight-autonomy/</link><guid isPermaLink="true">https://opsagent.pl/blog/human-oversight-autonomy/</guid><description>The spectrum of human oversight for AI agents — from human-in-the-loop to human-out-of-the-loop — plus guardrails, kill switches and a graduated path to raising autonomy safely.</description><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Shadow AI: the agents and tools running without your oversight</title><link>https://opsagent.pl/blog/shadow-ai-agents/</link><guid isPermaLink="true">https://opsagent.pl/blog/shadow-ai-agents/</guid><description>Why unsanctioned AI use is the most common governance gap — and how to bring Shadow AI into the light without driving it further underground.</description><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Single-agent or multi-agent? A decision guide</title><link>https://opsagent.pl/blog/single-vs-multi-agent/</link><guid isPermaLink="true">https://opsagent.pl/blog/single-vs-multi-agent/</guid><description>When to split a task across multiple AI agents and when one is enough — the real costs of multi-agent systems and a simple test for whether you actually need one.</description><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate></item></channel></rss>