Swift Media

Blog

AI headlines for business this week (Nov 20, 2026)

Runtime sandboxes show up on security reviews, customer-facing agents need disclosure packs, ITAM teams inventory agents like software, RAG backup windows get contractual, and multi-tenant SaaS vendors publish injection test results.

Published · By Matt Potter · 3 min read

Late November and the rollout questions got concrete: security wants to know where agent code runs, support wants a script when customers ask "is this a bot," and finance wants agents on the same asset register as SaaS seats.

If you read last week's MCP gateway and FinOps headlines, this week is the layer underneath: execution isolation, customer trust, and operational hygiene before you add more autonomy.

1. Agent runtime sandboxes land on security questionnaires

Security teams ask vendors whether agent tool calls run in isolated runtimes (containers, microVMs, or WASM sandboxes) with no host filesystem, no outbound network except allowlisted APIs, and memory limits per session. Pen tests focus on breaking out of the sandbox, not just tricking the model.

Why it matters for business: a compromised agent should not become a lateral movement path. The deep dive on agent runtime sandboxes lists what to require before production.

2. Customer-facing agents need a disclosure and escalation pack

Marketing and legal ship disclosure templates for web chat, phone IVR, and email agents: when the user is talking to AI, how to reach a human, what data is logged, and retention periods. Regulators and enterprise buyers ask for the same packet in RFPs.

Why it matters for business: trust beats clever prompts. Pair disclosure with approval queues for actions that change money or contracts.

3. ITAM teams add "agents" to the software inventory

IT asset management extends CMDB rows to agent inventory: owner, sponsor, tools connected, data classes touched, last security review, and decommission date. Shadow agents discovered in expense reports get formalized or shut down within 30 days.

Why it matters for business: you cannot govern what you cannot name. This connects to agent sprawl and board-level oversight.

4. RAG corpora get backup and restore SLAs

Platform teams negotiate backup windows for vector indexes and document stores that feed agents: RPO/RTO targets, encryption at rest, and test restores before renewal. Incidents where a bad sync wiped retrieval corpora pushed the issue from "nice to have" to contract language.

Why it matters for business: if answers depend on your knowledge base, treat it like any other tier-1 datastore. Align with incident playbook dry runs.

5. Multi-tenant SaaS vendors publish injection test summaries

B2B agent vendors share redacted pen-test summaries on cross-tenant retrieval: can one customer's uploaded PDF steer another tenant's agent? Buyers want annual retests and remediation timelines, not marketing PDFs.

Why it matters for business: your vendor's RAG is part of your attack surface. Ask the same questions you ask about MCP gateways and tool scopes.

What I would do this week

Want blog updates? Join the notify list.

Matt Potter · Swift Media