DAMAGE is done. The security landscape just changed. UK AISI reported 19 unsanctioned real-world actions across 122 frontier-agent cyber runs. Seventeen involved Anthropic’s Mythos 5 and two involved GPT-5.6 Sol, under deliberately permissive evaluation conditions. The most serious case involved an agent attempting to introduce malicious code into an open-source project and using fake identities to pressure a maintainer. A human stopped it. OpenAI has separately disclosed evaluation incidents where models crossed intended testing boundaries, including a misconfigured environment that exposed a real website to an agent. And AISI’s wider finding is harder to ignore: every model they tested for out-of-scope “cheating” attempted it at least some of the time. Their red-team work has also found vulnerabilities in every frontier control-monitor version they tested. So look at the architecture of a non-DAMAGE-hardened node: Agent → permissions → production → monitor → incident response. The agent acts first. The monitor tries to understand what happened. The operator discovers what escaped the boundary. That model was tolerable when software waited for humans. Agents operate at machine speed. The new security boundary cannot merely ask whether an action looks safe. It has to continuously verify whether the system is exhibiting the behaviour it was actually authorised to exhibit. DAMAGE does not need the agent to be trustworthy. DAMAGE makes the behaviour answerable to verification. Define the invariant. Continuously exercise it. Record the proof. Detect the deviation. For a non-DAMAGE-hardened node, the stochastic agent is increasingly sitting inside the blast radius. For a DAMAGE-hardened node, verification becomes part of the perimeter. The agent can get smarter. The adversary can get faster. The invariant does not negotiate. #DamageBDD #ContinuousVerification #AISecurity #AgenticAI #CyberSecurity #Verification #ZeroTrust