AI agents can be incredibly useful, but their autonomous actions can be incredibly dangerous if not adequately controlled.
Max Brin is developing a product that he calls “AV for AI”. The antivirus analogy can be a bit confusing, since this product has nothing to do with a traditional antivirus program – but at least the name is familiar and the purpose of protecting networks from software mishaps is well understood by security experts. The name of the product is OpenLeashwhat is more informative: The product maintains control over unexpected and unwanted actions that may be caused by AI agents.
It runs alongside the agent and provides an authorization layer aimed at making autonomous AI agents accountable and secure when executing real-world actions and aligned with the user’s intent.
Agents tend to inherit their user’s permissions, but they do not inherit human situational awareness. This gives them broad access and generous permissions across the network, and a single faulty command prompt, malicious tool, or compromised model can cause real damage.
OpenLeash intercepts agent intent. Depending on the configuration used by the user, OpenLeash monitors the actions of the agents and, if necessary, asks the user whether the agent’s action should be allowed. If no, this action is stopped. If yes, it is allowed. Brin describes it as a “medicine for AI anxiety.”
He gives an example of the product in action. A misinterpreted command or an error in the agent’s coding could result in a database being silently deleted without human knowledge. “When it intends to delete my database, Leash intercepts that message, evaluates it, and tries to understand whether the action is risky or not. In some cases, it’s definitely risky and Leash just blocks it outright. In other cases, when Leash isn’t sure, it asks the user: Were you planning on deleting your entire database – or were you planning on uploading your credentials to this or that or that website? Basically, it’s like a guardian angel intercepting everything.” Conversations between an agent and network resources occur on internal agents, on cloud agents, and on third-party agents, and then help users decide whether they really want the agent to perform that particular action.”
The threat exists because the agent alone does not behave as if it needs to ask permission to do something; It’s just a matter of carrying out the instructions it’s given by interpreting them and doing what it’s told. OpenLeash is designed to provide a layer of authority in the action, independent of the agent’s interpreted commands.
While OpenLeash is still described as being in development, it is also being actively used. Brin has a list of planned additions and improvements that he says will take a few months to complete. The existing product is now actively used by several hundred private users and at least four organizations.
He thinks OpenLeash is particularly relevant for the new class of Vibe programmers. “AI gives us the ability to program and write software even if we don’t know how to write a single line of code and have no understanding of cybersecurity,” he says. “There are people who want to write software and create applications or agents to automate their own workload. They have ideas and are a bit like entrepreneurs, but without technical knowledge. They download Claude Code or Cursors to develop AI agents that do what they want, and then turn to OpenLeash to control the agents.”
The product is highly configurable. Acceptable API endpoints, destinations or payment limits can be specified in the configuration. For example, payments below a certain threshold may be permitted, while payments above that threshold must be authorized by someone in the loop. The configuration can be changed at any time.
In Brin’s own words, OpenLeash is an AV for AI that curbs reckless agent behavior, acts as a guardian angel, and provides medicine for AI anxiety.
Related: In addition to the industry’s commitment, the British government is also introducing a plan to counter agent AI
Related: Critical vulnerability exposes GitHub Agentic workflows to the possibility of immediate injection
Related: Agentic AI Security: Wrong context, wrong decisions at machine speed
Related: The new rules of engagement: Appropriate agent attack speed
