Webinar: Detecting AI attacks using Canaries · Watch On Demand →
Product
Platform
AWS
AWS
Azure
Azure
CI/CD
CI/CD
Google Cloud
Google Cloud
Identity
Identity
Kubernetes
Kubernetes
Workstations
Workstations
Credentials & artifacts
Credentials & artifacts
Use cases
AI Agent Detection
Cloud & Kubernetes Breach
Insider Threat Detection
Supply Chain & CI/CD Attack
Workstation Compromise
PricingCustomers
Resources
  • ResearchAbout
  • Careers
  • Contact
Community Edition
Book a demoCommunity Edition
All posts

·

Research

Webinar: AI Agents vs. Canaries

Alessandro Brucato

June 29, 2026

June 29, 2026

·

3

min read

I am the text that will be copied.
Tracebit research benchmarking ten frontier AI models against canaries in an AWS cyber range

AI agents can now compromise a cloud environment in minutes - and they are only getting faster. We benchmarked ten frontier AI models inside a controlled AWS cyber range to measure how quickly they escalate to admin, and whether deception technology catches them in time. Across 951 attack runs, AI reached admin privilege escalation in an average of 14 minutes - but canaries warned the defender before the attack landed in 95.9% of those runs, a median 8 minutes ahead of the attacker's first critical action.

We sat down to walk through the research. Watch the full recording on YouTube, or listen on Apple Podcasts and Spotify.

Watch the recording

The researchers behind the study walk through the benchmark design, a synchronized replay of AI agents attacking the same account with and without canaries, and what it all means for defending against offensive AI agents.

You'll hear from Tracebit's Alessandro Brucato (Security Researcher) and Sam Cox (Co-founder & CTO), alongside Nick Reva, Director of Security Engineering at DoorDash, for a hands-on look at detection in the age of AI attackers.

What you'll take away

  • How fast frontier AI models really move, escalating from low-privilege access to admin
  • Why canaries give defenders a head start, warning before the attack lands in 95.9% of compromising runs
  • Why simply warning a model that deception may be present can dramatically cut full compromise

Who should watch

Give it a listen if you are:

  • A security leader preparing your detection strategy for offensive AI agents
  • A security engineer or architect building detection and deception programs
  • On a detection and response team focused on high-fidelity signal and early warning
  • A cloud security team responsible for AWS, GCP, and Azure environments

Watch or listen now

Watch the full recording on YouTube, or listen on Apple Podcasts and Spotify. Prefer to read? Explore the complete study - including the synchronized replay and per-model breakdown - at agentic.tracebit.com.

Tracebit deploys the same canaries we used in this study across AWS, GCP, Azure, endpoints, SaaS and CI/CD - and you can have them set up in as little as 30 minutes. Talk to us to see it in your environment.

Table of contents
Subscribe to our newsletter

Subscribe to receive the latest research and product updates to your inbox every week.

By subscribing you agree to our privacy policy
Thank you! Check your inbox for your first edition.
Oops! Something went wrong while submitting the form.
Subscribe to newsletter

Subscribe to receive the latest research and product updates to your inbox every week.

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Protect your environment with Tracebit

Book a demo today.

The latest security research straight to your inbox

Subscribe to our newsletter to receive regular updates from our research and product teams

By subscribing you agree to our privacy policy
Thank you! Check your inbox for your first edition.
Oops! Something went wrong while submitting the form.
Soc 2 Type 2 imageCheckmark imageAWS Qualified software illustration
PLATFORM
AWS
Azure
CI/CD
Google Cloud
Identity
Kubernetes
Workstations
Credentials & artifacts
USE CASES
AI Agent Detection
Cloud & Kubernetes Breach
Insider Threat Detection
Supply Chain & CI/CD Attack
Workstation Compromise
COMPANY
CustomersResearchAboutCareersContactStatusCommunity Edition
SOCIAL
© 2026 Tracebit
Privacy PolicyTerms of ServiceCookie Settings