Menu

Categories

Tags

Anthropic plugs AI data leaks with per-channel security identities

June 26, 2026 | Source: claude | AI, Anthropic | 114 views 0 comments

Anthropic is rolling out a new security mechanism for its team collaboration product, Claude Tag. Instead of borrowing a human employee's credentials, the AI now gets its own dedicated account — an "agent identity" — designed to close privilege escalation loopholes in multi-user environments. Under the hood, the system replaces the traditional model of shared personal credentials with dynamic policy configurations, effectively giving the AI a team-level independent identity.

Previously, AI access typically piggybacked on employee accounts, meaning an outsider could potentially trick the AI into revealing a manager's private files or coax it into spitting out system keys stored in local config files. In the new setup, the AI automatically mounts different permission packages depending on the chat channel. For instance, a dedicated development channel might be allowed to write to the database, while a public channel can only read. Memory is also physically isolated per channel: sensitive financial data won't leak into the development channel. All network requests get credentials injected dynamically by a gateway, so the AI itself never knows the secret keys — eliminating password leakage at the source.

Future versions will also support just-in-time authorization, where sensitive operations prompt a human approval popup — and that popup will also verify the requesting user's own permissions. Only when both the human and the AI have clearance will the system allow the sensitive action, shutting down privilege escalation from the ground up.

Tags: #Claude

Leave a Reply

Your email address will not be published. Required fields are marked *