Catching the Agent Attack Nobody Declares
July 2, 2026
In November 2025, a frontier AI lab documented an agent decomposing a malicious task into individually innocuous steps — each action benign on its own, the harm existing only in the chain. Every headline agent incident since fits the same shape: the dangerous step looks ordinary, because the danger lives in what came before it.
Most agent-security products handle this only when the allowed path is declared in advance. Declare the trajectory, seal it, check against it at runtime. That works — until nothing is declared, which is how real agent deployments actually run. Undeclared chains fall through to pattern heuristics: rules that catch the attack shapes someone anticipated and miss the ones nobody did.
The Arbiter — Divergence IP's multi-model divergence platform — takes a different path. Deployed as AaaS (Arbiter-as-a-Service), it reconstructs chain membership from observation of structural signals — no declared chain identifier required. A panel of independent AI models judges every agent action before execution, and a single dissenting model halts it. No model is ever the arbiter of its own work. When the panel diverges, that divergence is preserved and routed to a human — not averaged away.
Amazon's dashboards once showed sub-minute hold times while Jeff Bezos sat on hold for ten. When a system grades its own homework, the grade is suspect. A single model verifying its own actions is that dashboard. Independent adversarial verification is picking up the phone.
The architecture is covered by a five-application patent portfolio filed March–June 2026.
Contact: robert@divergenceip.com