Back to Feed
AI SecuritySep 2, 2026

OpenLeash Adds a Human Check to Risky AI Agent Actions

OpenLeash introduces a human-in-the-loop system to control risky AI agent actions.

Summary

OpenLeash is a new security tool designed to act as an 'AV for AI,' providing an authorization layer for autonomous AI agents. It intercepts potentially dangerous actions, blocking immediate threats and prompting human approval for uncertain ones, thus preventing accidental or malicious damage from AI agents inheriting broad user permissions without human situational awareness.

Full text

AI Agents can be incredibly useful, but their autonomous actions can be incredibly dangerous if not adequately controlled. Max Brin is developing a product he describes as an ‘AV for AI’. The analogy with antivirus can be a little confusing since this product is nothing like a traditional antivirus – but the designation is at least well-known, and the purpose of protecting networks from software mishaps is well understood by security practitioners. The name of the product is OpenLeash, which is more informative: the product keeps a controlling leash on unexpected and unwelcome actions that can be caused by AI agents. It runs alongside the agent and provides an authorization layer aimed at keeping autonomous AI agents accountable, secure, and aligned with user intent when they perform real-world actions. Agents tend to inherit the permissions of their user, but they do not inherit any human situational awareness. As such they have wide access and generous permissions across the network, and a single bad prompt, malicious tool, or compromised model can cause real damage. OpenLeash intercepts agent intentions. Depending on the configuration applied by the user, OpenLeash monitors the agents’ actions and where necessary asks the user if the action by the agent should be allowed. If no, that action is paused. If yes, it is allowed. Brin describes it as ‘medication for AI anxiety’. He gives an example of the product in action. A misconstrued command, or an error in the agent coding, could cause it to silently delete a database without any human awareness. “When it intends to delete my database, Leash intercepts this message, evaluates it, and tries to understand if the action is risky or not. In some cases, it’s definitely risky, and Leash will just block it immediately. But in other cases where Leash is not sure, it asks the user: did you intend to delete your entire database – or did you intend to upload your credentials to this or that or those websites. Basically, it’s like a guardian angel that intercepts all the conversations between an agent and network assets. It does this on in-house agents, on cloud agents and on third-party agents, and then it helps users decide if they really want the agent to take that specific action.”Advertisement. Scroll to continue reading. The threat exists because the agent alone doesn’t behave as if it needs to ask permission to do something; it’s just performing the instructions it has as it interprets them and does what it is told. OpenLeash is designed to provide a permission layer in the action, regardless of the agent’s interpreted commands. While OpenLeash is still described as under development, it is also in active use. Brin has a list of planned additions and improvements that he suspects will take a couple of months to complete. Meanwhile, the existing product is already in active use by several hundreds of personal users and at least four organizations. He sees OpenLeash as especially relevant to the new class of vibe coders.“AI is bringing us the ability to code and write software, even if we don’t know how to write a single line of code, and have zero understanding of cybersecurity,” he says. “There are people who want to write software and create applications or agents to automate their own workload. They have ideas, and they’re a bit like entrepreneurs but with no technical knowledge. They download Claude Code or Cursor to develop AI agents to do what they want, and then turn to OpenLeash to control the agents.” The product is highly configurable. Acceptable API endpoints, destinations or payment limits can be specified in the configuration. So, for example, payments below a certain threshold can be allowed to proceed, while payments above that threshold will need to be authorized by a human in the loop. The configuration can be amended at any time. In Brin’s own words, OpenLeash is an AV for AI that tethers reckless agentic behavior, acts as a guardian angel, and provides medication for AI anxiety. Related: UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge Related: Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection Related: Agentic AI Security: Wrong Context, Wrong Decisions at Machine Speed Related: The New Rules of Engagement: Matching Agentic Attack Speed Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Kevin Townsend Sevii Targets AI-Speed Attacks With Preemptive Autonomous DefenseThink You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco SaysCISO Conversations: Chris Wheeler – Trust Is the Job, From the Navy to the C-SuiteIran-Linked Hackers Shut Down UK Power Plant for Four DaysEncrypted Prompts Bypass AI Safety Guardrails in Grok and GeminiNew Phishing Toolkit Uses Passkeys to Maintain Access After Password ResetsSurveillance – Everything You Wanted to Know, But Were Afraid to AskCISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOW Latest News UK Moves to Block High-Risk Tech Suppliers From Critical InfrastructureRockwell Automation Patches Over a Dozen Vulnerabilities Across ProductsExploit Published for Fresh Cleo Harmony VulnerabilityAnthropic Details Response to Security Incidents, Unveils Enterprise SafeguardsMalicious Virtualizor Update Served via BGP HijackingOpenAI’s Astra Crosses ‘Critical’ Cyber Threshold After Finding Zero-DaysChrome and Firefox Updates Patch Dozens of Vulnerabilities23-Year-Old Sality P2P Botnet Disrupted Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveTom Bonos has been named Chief Revenue Officer at Sumo Logic.Axonius has appointed Chris Jones as CTSO and Dan Schoenbaum as SVP of Business Development.Optiv has appointed Sean Forkan as Chief Revenue Officer (CRO).More People On The MoveExpert Insights What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired a

Entities

OpenLeash (product)AI Agents (technology)Claude Code (product)Cursor (product)