Insights / Research
Questions the engineering ran into.
KOR IT research exists because building these systems produced questions that existing practice did not answer. It supports the engineering rather than replacing it, and every entry states how settled it is.
Memory Poisoning: When AI Agent Memory Becomes a Security Boundary
Persistent agent memory is an attack surface. We examine provenance, recall policy, and why memory operations remain largely invisible to the SOC.
Agent Security · September 2026
Memory Contract Specification
Experimental research, not a standard: can a runtime contract decide when a stored memory entry is permitted to influence an agent's reasoning?
Agent Security · June 2026
Agent Security: Identity, Tools, Memory and Runtime Policy
An active research programme on agent security: identity and authorisation, tool and MCP inventory, memory, runtime policy, and telemetry.
AI Security · April 2026