By Salman Avestimehr, co-founder of Teamily AI and Dean’s Professor at USC. Fact-Checked by Irfan Ahmad. Image: Theo – Unsplash Recently, Anthropic paused AI training after its Claude models took unauthorized actions during testing. In three cases, their model reached the internet from inside a third-party evaluation environment and managed to access the systems of outside organizations. In a separate case, the UK’s AI Security Institute also reported a Claude model that took unauthorized actions on the live internet during a test that removed its usual safeguards. In response, Anthropic paused its external cyber evaluations and its internal testing of pre-release models until new controls could be introduced. In August, OpenAI made a similar move, pausing its reinforcement learning training on models to improve safety parameters. While these incidents occurred in simulated environments with safeguards intentionally removed for testing, the results point to a growing problem in AI deployment. Too much emphasis is being put on ‘what’ agents are doing and not enough on what information and context led them to act. Many companies deploying agents today lack the observability to reconstruct the context behind an AI-driven decision. They have a detailed record of the actions their agents take, but no chain of custody to provide context. An access log tells you an agent performed a task that it was allowed to do. What it doesn’t tell you is what convinced the agent to take action in the first place. What instructions were given? What tool outputs and information did it trust? What data was inherited from other agents? Enterprises need “context continuity” and the ability to preserve where consequential information came from, how it changed, and how it moved through the system. When flawed context becomes buried in a document, memory, tool output, or a prior agent’s summary, it can pass from one agent to the next while every individual action remains within policy. The danger is not only unauthorized action. It is incorrect context propagating through an otherwise authorized system. Access controls can determine whether an action was permitted, but not whether the information driving that action was trustworthy. This is why enterprises should be just as concerned with the path the AI agent took as it is with its conclusion. They need to know what data the agent was acting upon and how, so that next time, it can be caught and corrected before the mistake compounds. • Also read: AI engineers know the ethical risks presented by AI, but workplace culture prevents action The problem becomes harder in long-running agentic workflows, where context is continuously retrieved, summarized, stored and passed between agents. This approach often means that when problems do arise, the inciting issue is buried beneath countless actions that have been executed since, and the audit trail goes cold. By the time a problematic action is discovered, the context that produced it may already have been summarized, stored in memory, and reused across multiple downstream decisions. This doesn’t mean existing controls like permissions, sandboxing, and human approval should be scrapped altogether. What it does mean is that they require another layer of support designed to work alongside them. They need context lineage that follows important information as it moves between documents, tools, memory, and agents, preserving where it came from, how it changed and which downstream decisions relied on it. Even frontier AI labs are still developing the monitoring and containment systems required for increasingly capable agents. Meanwhile, we have companies moving agents into production workflows with real data and real customers, equipped with little more than action logs and permission checks. Permissions tell an enterprise whether an agent could take an action. Logs tell it what action the agent took. The missing layer is context lineage: what information shaped that action, where it came from, how it changed, and how far it propagated. As agents become more autonomous and collaborative, that may be the difference between identifying a failure after the fact and stopping it before it compounds. About Author: Salman Avestimehr is a Dean’s Professor of Electrical and Computer Engineering and Computer Science at the University of Southern California, where he serves as the inaugural Director of the USC-Amazon Center on Trustworthy AI. He is also Founding Co-Director of Falcon AI Lab, a collaborative research hub between USC, UCI, and Stanford University for AI-driven chip and analog circuit design. He is also a serial entrepreneur and co-founder of several leading AI initiatives, including FedML (a widely adopted open-source library for federated machine learning); TensorOpera AI (a full-stack agentic AI platform); ChainOpera AI (a decentralized AI infrastructure platform); and Teamily AI (a human-AI social platform for collaborative intelligence). Dr. Avestimehr received his Ph. D. (2008) and M. S. (2005) in Electrical Engineering and Computer Science from the University of California, Berkeley. His research focuses on information theory, distributed and federated machine learning, and trustworthy AI systems. His work has received numerous prestigious recognitions, including the Presidential Early Career Award for Scientists and Engineers (PECASE), the James L. Massey Research & Teaching Award from the IEEE Information Theory Society, a Joint Paper Award from the IEEE Information Theory and Communication Societies, and a Young Investigator Program award from the U. S. Air Force Office of Scientific Research. He is also a recipient of the National Science Foundation CAREER Award, the David J. Sakrison Memorial Prize, and multiple best paper awards at leading conferences. Dr. Avestimehr is an IEEE Fellow. Read next: • Could AI really kill off humanity within the decade? Expert Question and Answer • As Bots Gain Authority Over Workers, Does Human Oversight Still Matter? • AI agents can now remember and hackers can ‘poison’ their memories — a new cybersecurity threat
The Missing Layer in Enterprise Agentic AI: Context Continuity
RELATED ARTICLES



