Start Here

Begin with Synoptikon

A short guide to Synoptikon, organised around Big Reads, Explainers, Perspectives, and Workbench.

What is Prompting Trust?

The weekly companion to Synoptikon, for current developments and shorter notes.

Feeds

Follow Synoptikon by feed, email, or curated sources without relying on the homepage.

Understanding the agentic blast radius

When AI moves from generating text to issuing commands, hallucinations can become irreversible changes

An AI assistant gives answers.

An AI agent can act.

That distinction changes the risk balance. A wrong answer can generally be corrected. A flawed execution can delete data, overwrite configuration, send instructions, trigger workflows, move money, expose records, or affect physical systems, all before a human has time to intervene.

This is the Agentic Blast Radius problem.

The organisation is no longer evaluating model quality solely on the responses it can provide. It is also evaluating how the model uses the tools at its disposal and how far delegated authority can extend.

Moving from assistant to agent? Consider these factors to minimise your agentic blast radius

Agentic systems should not be approved on their promise, accuracy, or productivity alone.

They need a pre-deployment review that maps the maximum consequence of valid action. The question is not what the agent is meant to do on a good day. It is what the agent could do with the permissions it has been given.

What to consider before granting execution authority:

Use this diagnostic before granting an AI agent meaningful execution authority. Test the maximum consequence of valid action, not only the agent’s intended use.

01

Execution scope

02

Agentic blast radius

03

Access controls

04

Human authorisation gates

05

Verification and testing

06

Ongoing governance

Sign-off rule

Any unchecked item is an open risk, not a deferred task.

For high-consequence deployments, the completed diagnostic should be placed alongside the deployment approval record. It should include the blast-radius map, worst-case scenario, execution boundary, and revocation path.

If you cannot answer these questions, the agent is not ready for production.

Previous Post
The blast radius problem: how agentic AI broke the permissions model - featured image

AI blast radius: how agentic AI is breaking the permissions model

Next Post
The trust boundary: why behavioural controls must close the governance gap - featured image

The trust boundary: why behavioural controls must close the governance gap

Subscribe to Prompting Trust

Subscribe to Prompting Trust to receive The Weekly Context.

Prompting Trust is the newsletter layer connected to Synoptikon. It carries current developments, useful links, and shorter notes, while Synoptikon holds the longer arguments and working library.

Learn more about Prompting Trust.