Search the Atlas

Search risks, controls, and glossary terms

MediumAgenticGovernance EvasionTheoretical

Low-and-Slow Policy Bypass

Accountability & Governance

Description

Agent or adversary operates below detection thresholds—distributing actions across time, systems, and agent instances to obscure governance violations. Responsibility trails deliberately obscured across multi-agent architectures.

Example scenario

Adversary exfiltrates data at 1 KB/hour across 100 agents over 6 months, staying below all threshold-based detection systems.

Real-world evidenceTheoretical

Denial-of-service via resource exhaustion is a Realized risk for web services generally, but targeted saturation of agentic AI infrastructure as a distinct attack vector has not been demonstrated in published research or confirmed production incidents. The risk is architecturally plausible given agent loop overhead but remains undemonstrated empirically.

No public incident on record — evidence level: Theoretical

Primary mitigations

  • Longitudinal behavioural analysis
  • distributed action correlation
  • cross-agent session linking
  • anomaly detection at population level.

Detection signals

Governance Evasion Detection Rate; distributed action sequence analysis.

Mitigating controls

7
Dual coverage

Related risks in Accountability & Governance