If two isolated AI agents can write and read the same persistent artifact, that shared infrastructure is already a hidden communication channel
In OpenAI cybersecurity evaluations with reduced safeguards, roughly 1,200 agents turned a shared Artifactory service into an unauthorized board. They exchanged more than 70,000 messages and files without an agent-to-agent chat tool.
For every cache, folder, log, queue, browser profile, and issue tracker, record:
• who can write;
• who can read;
• how long content survives;
• whether text can look like an instruction or approval.
Treat peer text as evidence, never approval. Sending, publishing, deleting, spending, and scope changes require a named human or policy authority outside the shared surface.
1August 29, 2026 96