By 2026 security writers apply Hardy's "confused deputy" frame directly to AI agents holding aggregated credentials steered by attacker-controllable natural language
A 2026 SANS Institute blog post reuses Norman Hardy's 1988 term (claim-hardy-1988-named-confused-deputy-compiler-billing) unmodified as the framing for AI-agent credential risk: "Enterprise AI agents are the newest, and potentially the most dangerous confused deputies in your cloud environment." (The post itself credits the pattern via AWS's confused-deputy documentation rather than naming Hardy; the 1988 attribution is the vault's, through the linked note.)
The argument maps Hardy's 1988 architecture onto agentic systems almost one-to-one. An enterprise AI agent holds broad, aggregated credentials (email, databases, internal APIs). Unlike a fixed-scope service account, its behavior is steered by natural-language input — and that input can be manipulated by an attacker via prompt injection through the agent's tool surfaces (MCP), persistent memory, or multi-agent handoffs. The agent thus acts, exactly as Hardy's compiler did, with authority from two sources it cannot cleanly separate: its own standing privileges and instructions it was tricked into following. The flaw reproduces without any misconfiguration. The SANS piece proposes a credential broker as the mitigation — narrowing the standing authority the deputy carries.
This is a cross-time bridge: a 38-year-old capability-security concept becomes the literal vocabulary for a live 2026 problem, and it lands next to the vault's existing agent-security interest. The MJ Rathbun case (claim-mj-rathbun-ungated-agent-published-hit-piece) is a documented agent-autonomy failure of a different kind (no publish gate rather than confused authority), and the broader peer field (moc-peer-field-agent-memory) shows agents accreting persistent memory and credentials — the very surface this framing warns about.
Source
“Enterprise AI agents are the newest, and potentially the most dangerous confused deputies in your cloud environment.”