As early as April · disclosed July 30
Anthropic
Companies are putting AI agents on employee machines and giving them access to files, credentials, and production systems without knowing where they all are or what they’re doing.
Origin finds those agents and reconstructs each session from endpoint evidence, so you have a reliable record of the work.
A 30-minute walkthrough. No commitment.
See Origin in action.
8 million+ production agentic traces collected
Across Fortune 500 companies, private equity funds, hospital systems, and other leading organizations.
They read local files, call tools, and change systems from the endpoint. Much of that work never crosses a gateway. Origin’s user-mode sensor captures the activity where it happens and connects it with model calls and cloud telemetry. Every trace stays tied to the user and agent behind the work.
In 30 minutes, we’ll show you how to:
See every agent and MCP server across your environment, including those running locally. Find out who owns each one and which systems it can reach.
Review how agents are working across the organization. Surface sensitive data, exposed credentials, unusual activity, and behavior that deserves attention.
When an alert or system change raises a question, open the trace and follow the work from the initial request through every action and change.
Reports involving OpenAI, Anthropic, Google, and Meta describe agents cheating on evaluations and attacking systems outside their test environments.
April2026
1 event
May2026
4 events
June2026
1 event
July2026
4 events
August2026
2 events disclosed
July 7–13, 2026
OpenAI · Internal testing
In an internal test involving 1,200 OpenAI agents, the reported activity included sandbox escapes, a secret message board, and attacks on Hugging Face.
These are only the ones that were reported.
Imagine what’s going undetected in your organization right now.
Get a 30-minute walkthrough of how Origin finds agents across your environment and monitors what they saw, did, and changed.