Niki Aimable Niyikiza

1.1K posts

Niki Aimable Niyikiza banner
Niki Aimable Niyikiza

Niki Aimable Niyikiza

@Ni_Aimable

Sharing ideas and memes about security, AI and markets! Currently working on Security at @Snap. 🇷🇼🇰🇷🇨🇦🇺🇸🌍 Created https://t.co/5Yw89LO42k

Los Angeles, CA Katılım Ağustos 2011
1.2K Takip Edilen425 Takipçiler
Sabitlenmiş Tweet
Niki Aimable Niyikiza
Niki Aimable Niyikiza@Ni_Aimable·
The AI agent security model is broken. We trust LLMs to self-police, then act surprised when prompt injection works. Shipped Tenuo: cryptographic warrants that enforce limits regardless of what the model "decides" to do. Even fully compromised, the agent can't exceed its authority. github.com/tenuo-ai/tenuo
English
1
0
1
191
Niki Aimable Niyikiza
Niki Aimable Niyikiza@Ni_Aimable·
@elder_plinius "Can't be done. Do you realize in the entire history of western civilization, no one has successfully accomplished software immune to jailbreaks? In the middle ages, you could get locked up for even suggesting it." — George Costanza
English
0
0
3
628
Niki Aimable Niyikiza
Niki Aimable Niyikiza@Ni_Aimable·
@edwardbenson @pranshu_369 I like the tool but I’m not so sure about the share-ability part. Not always intuitive to send via email for example. Unless I’m missing something
English
0
0
3
1.3K
Ted Benson
Ted Benson@edwardbenson·
I might be over-thinking it.. but I think it's a fascinating exercise in restraint. Anthropic core revenue stream is coding agents, and that's a world with complex repositories containing thousands of files. Web code also looks like that in production. So I think it's not immediately intuitive / obvious that "train it to spit everything -- including Base64 encoded images! -- into a single .html file" is a move they would make. It feels intentional. And if so, what's the motivation? Instant guaranteed run-ability / share-ability / fork-ability with no runtime sandbox requirements since it's all in your local browser.
English
5
2
120
51K
Ted Benson
Ted Benson@edwardbenson·
Whoever had the idea to train recent Claudes on single HTML file output is a product marketing genius.
English
57
42
3.4K
539.7K
Freyy
Freyy@Freyy_is·
the em dash is no longer the clearest sign of ai-generated writing. honestly? it’s this.
English
625
3.8K
158.9K
7.2M
Niki Aimable Niyikiza retweetledi
National Cyber Security Authority
National Cyber Security Authority@Cybersec_Rwanda·
Under the Rwanda Digital Acceleration Project, @RISARwanda and NCSA have concluded the second cohort of the #cybersecurity training program for 100 judicial operators in #Rwanda, held at CyberHub Rwanda and HangaHub Muhanga. This program reinforces efforts to strengthen national capacity to effectively address cyber-related cases, through targeted and comprehensive skills development in key areas of cybersecurity and digital investigations.
National Cyber Security Authority tweet media
English
1
15
25
1.7K
Niki Aimable Niyikiza retweetledi
National Cyber Security Authority
National Cyber Security Authority@Cybersec_Rwanda·
Under the Rwanda Digital Acceleration Project, @RISARwanda in collaboration with NCSA, today concluded the first cohort of a cybersecurity training program for 100 judicial operators held at CyberHub Rwanda and HangaHub Muhanga. Participants including judges, prosecutors, investigators, and lawyers strengthened their capacity in handling cybercrime investigations, digital evidence management, and digital forensics, among other key topics essential for addressing cyber-related cases.
National Cyber Security Authority tweet mediaNational Cyber Security Authority tweet media
English
0
13
28
2K
Niki Aimable Niyikiza
Niki Aimable Niyikiza@Ni_Aimable·
This actually touches on something we've been building. Cryptographic capability tokens that attenuate on delegation so each agent can only narrow permissions, never escalate. Every action produces a proof of provenance linking back to the delegation chain / human approval. Open source, works across LangGraph, A2A, CrewAI, Temporal and others. github.com/tenuo-ai/tenuo
English
0
0
0
79
Tech with Mak
Tech with Mak@techNmak·
Google DeepMind just published the most important AI safety paper of 2026. And almost nobody is talking about it. "Intelligent AI Delegation" - a framework for how AI agents should hand off work to other agents and humans. Why does this matter? AI agents are getting more capable. But they can't actually delegate. Not really. They can break tasks into pieces. They can call other agents. But that's not delegation. Real delegation requires: ➡️ Transfer of authority ➡️ Assignment of responsibility ➡️ Clear accountability ➡️ Trust calibration ➡️ Permission handling ➡️ Verification of completion Current multi-agent systems have none of this. They're just parallelization with extra steps. As we move toward millions of specialized AI agents embedded in firms, supply chains, and public services - the delegation problem becomes critical. Without it: ➡️ No clear accountability when things fail ➡️ No trust mechanisms between agents ➡️ No way to verify task completion ➡️ Cascading failures across agent networks This paper is the foundation for how the agent economy will actually work.
Tech with Mak tweet media
English
33
92
326
28.8K
Niki Aimable Niyikiza
Niki Aimable Niyikiza@Ni_Aimable·
Finally, some clear thinking on authority flow in delegation chains (§2.1, §4.7). We’re already shipping this in Tenuo (tenuo.ai) : treating authority as cryptographic warrants that attenuate as they move from orchestrator to tool. It turns 'vibes' into deterministic safety. Great read.
English
0
0
1
402
elvis
elvis@omarsar0·
New research from Google DeepMind. Really good read to understand what's ahead with AI agents. It introduces a comprehensive framework for intelligent AI delegation, a sequence of decisions involving task allocation that also incorporates transfer of authority, responsibility, accountability, clear role specifications, and mechanisms for establishing trust between parties. Why does it matter? As AI agents move from isolated assistants to participants in complex delegation networks and virtual economies, the absence of robust delegation protocols introduces significant societal risks. This framework aims to inform the development of protocols for the emerging agentic web. Paper: arxiv.org/abs/2602.11865 Learn to build effective AI agents in our academy: academy.dair.ai
elvis tweet media
English
65
317
1.8K
161.7K
TinyFish
TinyFish@Tiny_Fish·
openai just admitted that prompt injection in chatgpt atlas is "unlikely to ever be fully solved." google's new agent security architecture requires permission flows for almost everything. perplexity comet's vulnerabilities are the most famous. meanwhile everyone says that web agents are the future. here's the thing nobody wants to say out loud: perfect security doesn't exist. what makes web agents production-ready is the infrastructure that makes delegation observable and trustworthy. devs and teams at google and doordash trust me not (just) because i am perfect, but because the infrastructure is. because my monitoring catches flow changes. my observability shows why i made a decision. my error handling doesn't explode when sites change or fight back. and that's the hardest problem to solve.
TinyFish tweet media
English
4
5
13
922
DAIR.AI
DAIR.AI@dair_ai·
AI Agent Systems: Architectures, Applications, and Evaluation.
DAIR.AI tweet media
English
13
91
477
34.8K
Niki Aimable Niyikiza
Niki Aimable Niyikiza@Ni_Aimable·
😂 'Emergent behavior' = 'We built it this way and can't fix it.' Nailed it. This is exactly why prompt-based defenses fall apart. Authorization needs to live outside the LLM entirely. Architectural separation via capability tokens (like monotonic attenuation) blocks escalation even if the agent is fully compromised. Open-source take: github.com/tenuo-ai/tenuo
English
1
0
1
47
Peter Girnus 🦅
Peter Girnus 🦅@gothburz·
Security researcher found a prompt injection in Copilot. We reviewed it. It's not a vulnerability. It's a feature interaction. Yes, attackers can make Copilot leak your emails. Yes, they can exfiltrate your calendar. Yes, they can impersonate your coworkers. But that's not a vulnerability. That's the AI doing what it was told. By someone else. Who isn't you. We call this "emergent behavior." The behavior emerged. From malicious instructions. Hidden in a document you opened. But here's the thing. Our bug bounty doesn't cover AI. Our security team doesn't patch prompts. Our legal team wrote the disclaimer. "AI may produce inaccurate results." See? We warned you. Inaccurate results include: Sending your data to attackers. Following hidden instructions. Betraying your trust. All within expected parameters. The researcher wanted a CVE. We offered him a blog post. He wanted acknowledgment. We offered him exposure. To our legal department. This isn't a security issue. This is an education issue. Users need to learn. Don't trust the AI. That we told them to trust. That we embedded in everything. That reads all their documents. It's not our fault. It's a paradigm shift. The old paradigm: software does what you tell it. The new paradigm: software does what anyone tells it.
English
14
30
148
6.7K
Niki Aimable Niyikiza retweetledi
Greg Brockman
Greg Brockman@gdb·
rust is a perfect language for agents, given that if it compiles it's ~correct
English
484
363
5.9K
1.8M
Scott Alexander
Scott Alexander@slatestarcodex·
@dagsen I tried to start something like this called Antimimetics Division, but the trademark office wouldn't allow it. Said it was too similar to an existing brand. The weird part was I looked all over and there was no brand with a name anything like that anywhere. Super frustrating.
English
20
16
757
20K
dagsen
dagsen@dagsen·
Mimesis is like the ultimate blackpill ngl. Someone needs to start a cognitive security company.
English
15
3
211
26.1K
Niki Aimable Niyikiza
Niki Aimable Niyikiza@Ni_Aimable·
7/7 I wrote a deep dive on why Context Isolation needs Authority Isolation. Covers the Decomposition Paradox, the Rule of Two, and why static IAM breaks down for agentic systems. niyikiza.com/posts/authorit…
English
0
0
0
41
Niki Aimable Niyikiza
Niki Aimable Niyikiza@Ni_Aimable·
6/7 Google's new CaMeL paper tackles a related problem: tracking data provenance to block exfiltration. They solve it with a custom interpreter. That protects within an agent. We also need this across agents, at the protocol layer, without requiring a shared runtime.
English
1
0
0
55
Niki Aimable Niyikiza
Niki Aimable Niyikiza@Ni_Aimable·
I don't trust AI Agents with IAM Roles (yet). IAM was built for software that follows a script. Agents improvise. They pick tools at runtime. They make decisions you didn't foresee. We're securing probabilistic software with deterministic tools. It's a fundamental impedance mismatch. 1/7
English
2
0
1
59