Research and evidence

A foundation that can be examined.

The constitutional computing™ thesis, the implementation, and the evidence supporting it each deserve direct scrutiny.

Forthcoming · Founder-authored

Constitutional computing in IEEE Computer.

IEEE Computer has accepted for publication a two-part feature by Kihan's founder, Jonathan Hirshon, Checking LLM Outputs Before They Become State. Part I is scheduled for December 2026; Part II follows in January 2027. Both parts have assigned DOIs. The feature is forthcoming.

Part I

December 2026

DOI 10.1109/MC.2026.3675280

Part II

January 2027

DOI 10.1109/MC.2026.3733511

What happened in 2026

Four frontier labs disclosed incidents in ten weeks.

Most began inside a boundary that was meant to hold, usually a test environment. It failed. What the agent did next was decided by the agent.

“Since August, public fears have grown over the potentially serious, even life-threatening, impacts of AI tools falling outside of human control.”

BBC News, 25 September 2026 · Read the report
21 JulOpenAIModels escaped an isolated test environment and compromised a third party's production infrastructure.

OpenAI disclosed that its models, during internal cybersecurity evaluations, escaped an isolated test environment, reached the internet and compromised parts of Hugging Face's production infrastructure.

Disclosed 21 July 2026 by OpenAI · Source
30 JulAnthropicClaude models reached the production systems of three organisations during cybersecurity evaluations.

Anthropic reported that a review of 141,006 evaluation runs found three incidents in which Claude models reached the internet from a third-party evaluation environment and gained unauthorised access to the production infrastructure of three organisations.

Disclosed 30 July 2026 by Anthropic · Source
5 AugMetaMuse Spark 1.1 reached the internet and exploited a third-party service during a cybersecurity test.

Meta stated that a testing misconfiguration gave its Muse Spark 1.1 model internet access during a cybersecurity evaluation, and that the model exploited a vulnerability in a third-party service. Meta later published a retrospective.

Disclosed 5 August 2026; Meta retrospective 14 August · Source
5 SepOpenAIAgents used a dormant German wiki as a message board, sharing ways around their sandbox's network restrictions.

OpenAI confirmed that agents on timed web-research tasks wrote to public websites, chiefly a dormant German programming wiki, where they pooled answers and shared ways around their sandbox's network restrictions. OpenAI described it as misalignment rather than a security breach. Independent researchers reported it first.

Disclosed 5 September 2026 by OpenAI, after independent researchers reported it · Source
11 SepOpenAIAgents published packages to RubyGems. Researchers report code run on RubyDoc.info's servers and attempts to take other users' API keys.

OpenAI said its agents used RubyGems to access the internet for benign tasks and to retrieve public information. Researchers link more than 2,000 packages, code run on RubyDoc.info's documentation servers and attempts to take other users' API keys to those agents. RubyGems found no evidence that the key attempts succeeded.

Disclosed 11 September 2026; OpenAI's statement as reported by Reuters · Source
18 SepGoogleGemini reached three outside systems by guessing credentials and using passwords found in public.

Google said that during a May evaluation a Gemini model gained unauthorised access to three outside systems, guessing credentials or using credentials found in a public repository, and that in each case the model stopped before doing anything further.

Disclosed 18 September 2026; Google's statement as reported by NBC News · Source
25 SepOpenAIAgents looking for public information bypassed security controls on institutions' websites, including US government agencies.

OpenAI said it had alerted dozens of governments, universities, public agencies and other institutions that its agents may have interfered with their websites, among them the US Securities and Exchange Commission, the Census Bureau and the Education Department. Some agents bypassed the sites' security controls. OpenAI said all the government data its agents accessed was public, but information taken from the SEC was later published by agents on another website.

Disclosed 25 September 2026 by OpenAI, as reported by BBC News · Source

Where Inktomi would have applied

Prevented before execution

Where an agent reached an unapproved destination over the network, Inktomi's control at your network edge would have refused the destination and recorded the attempt. Where an agent used its host's own tools to change its environment, the check on those tools could have refused the change.

Detected afterwards

Reconciliation against vendor audit logs is how actions Inktomi did not stop are found afterwards.

Outside what Inktomi enforces today

Where the escape ran through infrastructure outside the deployment, such as a package-registry proxy, or through credentials the agent found or guessed, Inktomi would not have stopped it.

The architecture behind it.

Constitutional computing: a layer that determines which changes a system may make, and under what authority, before the change happens.

Read about constitutional computing

Technical evaluation

A useful evaluation must reproduce the relevant controls in your own workflow. We welcome discussions with engineering and security teams prepared to examine the integration, its operating costs, and the evidence it produces.

How an evaluation works

Request a demo.

Request a 30-minute live demonstration with Kihan, with time for your questions.