This source backbone collects the primary reading paths behind VS010, The Permission Substitute. It is a public source map: a route through the regulatory record, the identity-security product launches, the failure and incident-rate research, and the labor signal that informed the issue.
It is not a claim-by-claim verification record and not a complete bibliography. It is a curated route through the sources most relevant to the issue's central question:
When access control is adopted at speed and measurably reduces incidents, what does that actually prove, and what does it leave unaddressed?
01 — The Regulatory Record
EU AI Act — Regulatory Framework
Link: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai Source type: Institutional (European Commission).
Evidence posture: Primary. Official status page.
Why it matters: Confirms the AI Act's transparency obligations became applicable August 2, 2026, the enforceable floor this issue's TERRAIN section is built on.
Not Delayed, Not Deferred: EU AI Act Transparency Obligations Now in Force
Link: https://www.goodwinlaw.com/en/insights/publications/2026/08/alerts-technology-dpc-eu-ai-act-transparency-obligations-now-in-force Source type: Legal alert (Goodwin Law).
Evidence posture: Primary, professional legal analysis.
Why it matters: Confirms the transparency/high-risk split, transparency rules enforceable now, high-risk obligations delayed under the AI Omnibus agreement, the distinction this issue's TERRAIN and SOURCE NOTES sections depend on.
The EU AI Act Today: What Changed on August 2 (And What Didn't)
Link: https://jetico.com/blog/eu-ai-act-news-today-what-changed-on-august-2/ Source type: Industry analysis (Jetico).
Evidence posture: Secondary, corroborating.
Why it matters: States the specific delayed dates, Annex III high-risk obligations to December 2, 2027; AI embedded in regulated products to August 2, 2028, used directly in this issue's TERRAIN and WATCHLIST sections.
White House Whipsaws Silicon Valley (and Itself) Over A.I. Rules
Link: https://www.nytimes.com/2026/08/04/technology/ai-washington-regulation-whiplash.html Source type: News reporting (The New York Times).
Evidence posture: Primary reporting on a developing policy discussion, explicitly not yet policy.
Why it matters: Describes a proposed pre-release federal cybersecurity review framework for new AI models. Used as a watchlist item, not a settled fact.
White House AI Vetting Plan to Exempt Lower-Cost 'Open' Models
Link: https://www.politico.com/news/2026/08/04/white-house-ai-vetting-plan-to-exempt-nonproprietary-models-01024816 Source type: News reporting (Politico).
Evidence posture: Primary reporting, corroborating the NYT account.
Why it matters: Adds the specific detail of a 30-day review cap and a likely open-model exemption.
02 — The Identity-Security Buildout
SailPoint Unified Identity Security for the AI Era
Link: https://www.sailpoint.com/press-releases/sailpoint-identity-security-solution Source type: Primary vendor announcement.
Evidence posture: Vendor claim. Company's own product description.
Why it matters: Announces Agentic Fabric, unified human and AI-agent identity security, dated August 4, 2026, this issue's clearest single example of the identity-industry response this issue's thesis is about.
Autonomous Actors Need New AI Agent Governance
Link: https://siliconangle.com/2026/08/05/autonomous-actors-need-new-ai-agent-governance-blackhat/ Source type: News reporting (SiliconANGLE).
Evidence posture: Primary reporting on a vendor announcement (Rubrik).
Why it matters: Reports Rubrik's Agent Identity, which authorizes access one tool call at a time, dated August 5, 2026, direct source for VSR-02's runtime-binding concept.
Global CISO Insights 2026
Link: https://www.okta.com/newsroom/articles/global-ciso-insights-2026/ Source type: Vendor-run survey (Okta).
Evidence posture: Reported claim, vendor-adjacent. Okta is an identity vendor with a commercial interest in the framing.
Why it matters: Survey of 300+ CISOs naming AI agent governance a board-level crisis. Used with the vendor relationship disclosed.
Securing Modern AI In A Machine-Versus-Machine World
Link: https://www.forbes.com/sites/willtownsend/2026/08/07/securing-modern-ai-in-a-machine-versus-machine-world/ Source type: News reporting (Forbes), covering Cisco's product roadmap.
Evidence posture: Primary reporting on a vendor's own announcements. Cisco's re-architecture of its Duo Security identity platform to cover both humans and agents, its AI Defense shadow-AI inventory tool, its Hypershield autonomous-segmentation framework, and its newer Live Protect feature.
Why it matters: Source for the main issue's Cisco references (SIGNAL, HIGHLIGHTS, TERRAIN, TREND REPORT), grouped alongside SailPoint, Rubrik, and Okta as the fourth identity-security vendor moving in this window.
AI Agent Sprawl: Why AI Governance Is Now a Board-Level Issue
Link: https://news.sap.com/2026/08/agent-sprawl-why-ai-governance-is-now-board-level-issue/ Source type: Vendor-run survey commentary (SAP LeanIX).
Evidence posture: Reported claim, vendor-adjacent.
Why it matters: The 98%-adoption figure (companies deploying or planning to deploy AI agents), used to establish adoption scale, disclosed as sponsor-run.
Tech Industry Leaders Launch Alliance for AI Agent Security
Link: https://thejournal.com/articles/2026/08/05/tech-industry-leaders-launch-alliance-for-ai-agent-security.aspx Source type: News reporting (THE Journal).
Evidence posture: Single-source reporting. Directly fetched and confirmed: NVIDIA and 36 other technology, cloud, cybersecurity, and enterprise software organizations are named as founding participants. Full member list, governance structure, and any published deliverables remain unconfirmed beyond this one outlet.
Why it matters: Reports the Open Secure AI Alliance's launch. Membership count now confirmed; scope of actual output still treated as a watchlist item.
03 — Failure and Incident-Rate Research
New Research Finds Enterprise AI Failures Are Shifting Beyond Hallucinations
Link: https://www.prnewswire.com/news-releases/new-research-finds-enterprise-ai-failures-are-shifting-beyond-hallucinations-as-companies-move-from-chatbots-to-agents-302837907.html Source type: Primary research release (ChatSee.ai).
Evidence posture: Primary, self-published research with a stated methodology (10,000+ observed failure events, 150+ categories, 10 verticals, 7 lifecycle stages).
Why it matters: Source of this issue's central empirical claim, hallucination under 10% of failures, resolution/escalation breakdowns the largest category at 31.1%, execution/action failures up 62% year over year. This is the issue's single most load-bearing citation.
AI Infrastructure in 2026: Is Control Now the Real Differentiator?
Link: https://nhimg.org/community/agentic-ai-and-nhis/ai-infrastructure-in-2026-is-control-now-the-real-differentiator/ Source type: Community/practitioner commentary (nhimg.org, discussing Teleport's survey and Akto's 2025 AI Yearbook).
Evidence posture: Secondary commentary, corroborating and supplying practitioner guidance.
Why it matters: Source of the "bind approvals to runtime execution" and "joiner-mover-leaver" practitioner language this issue adapts for VSR-02 and VSR-04.
The 2026 Infrastructure Identity Survey (Teleport)
Link: https://goteleport.com/blog/top-ai-infrastructure-risks/ Source type: Primary vendor-run survey (Teleport).
Evidence posture: Reported claim, vendor-run. Traced to the vendor's own original post (dated February 17, 2026), independently recirculated by multiple sources through mid-2026.
Why it matters: Source of the 17%/76% incident-rate figures at the center of this issue's opening and Table.
AI Agent Failure Rate: Why 70-95% Fail in Production
Link: https://www.fiddler.ai/blog/ai-agent-failure-rate Source type: Vendor blog (Fiddler AI), citing several named academic studies.
Evidence posture: The "88%" headline figure itself is the vendor's own synthesis, not used in this issue's copy. The underlying named studies it cites, a WebArena benchmark result, a Carnegie Mellon evaluation, an MIT pilot-outcomes report, and a Princeton reliability study, are independently citable and are the reason this source is included here at all.
04 — Labor Signal
AI's Real Threat to the Job Market Isn't Job Loss, It's Lower Paychecks
Link: https://www.businessinsider.com/ai-could-lower-workers-pay-job-market-impact-2026-7 Source type: News reporting (Business Insider), covering Apollo Global Management's analysis.
Evidence posture: Reported claim, reached through secondary reporting; Apollo's own whitepaper not independently located.
Why it matters: Source of this issue's wage-decline (rather than pure job-loss) framing in ZEITGEIST.
AI's Impact on Labor and Hiring (Liberty Street Economics)
Link: https://libertystreeteconomics.newyorkfed.org/2026/08/ais-impact-on-labor-and-hiring/ Source type: Institutional (Federal Reserve Bank of New York).
Evidence posture: Primary, directly citable.
Why it matters: The New York Fed's own research arm tracking AI's effect on hiring practices directly, used to establish the labor conversation's shift toward institutional-grade specificity.
Upwork Releases 2026 Future Workforce Index
Link: https://www.quiverquant.com/news/Upwork+Releases+2026+Future+Workforce+Index,+Finding+AI+Is+Reshaping+Freelance+Work+and+Earnings Source type: Vendor-run survey (Upwork), via secondary reporting.
Evidence posture: Reported claim, vendor-adjacent. Upwork has a direct commercial interest in the freelance-economy framing.
Why it matters: The 1-in-3 skilled-worker freelance figure, disclosed as sponsor-run.
05 — Supporting Terrain (context)
The Best AI Coding Agents in 2026 (OpenAI Frontier reference)
Link: https://aimultiple.com/ai-agent-tools Source type: Industry aggregator, referencing OpenAI's own Frontier platform announcement.
Evidence posture: Vendor claim, reached through secondary aggregation; OpenAI's own primary announcement page not independently located. The reported adopter list (HP, Intuit, Oracle, State Farm, Thermo Fisher, Uber) is unconfirmed against a primary source.
Why it matters: Context for the cross-vendor agent-platform layer beneath the identity-security buildout.
Synopsys Advances Agentic AI Chip Design with AMD and Microsoft
Link: https://news.synopsys.com/2026-07-27-Synopsys-Advances-Agentic-AI-Chip-Design-with-AMD-and-Microsoft Source type: Primary vendor announcement (Synopsys, via PRNewswire), dated July 27, 2026.
Evidence posture: Primary. Directly fetched and confirmed, replacing an earlier citation to a rolling, non-dated aggregator page that no longer reproduced the content it was originally cited for.
Why it matters: Source for the Synopsys DAC agentic chip-design workflow mention, autonomous EDA workflows built with Microsoft and used by AMD, including a fully autonomous debug closure workflow (AgentEngineer™) showing up to a 40% cycle-time reduction. Included as a field spotlight outside DFEI's usual enterprise-software lane.
DFEI.010 :: Source Backbone Dispatches From Emerging Intelligence