As AI agents become more capable of acting independently, a recent incident involving OpenAI and RubyGems raises important questions about how autonomous AI should be secured and monitored.
Independent researchers attributed suspicious activity on RubyGems to OpenAI agents, including packages containing code designed to obtain API keys. OpenAI disputes that characterization, while Ruby Central says it cannot determine whether AI agents created or published the packages. Ruby Central did confirm that more than 500 malicious packages were removed following a spam-publishing campaign.
Regardless of attribution, the incident highlights an emerging challenge for MSPs: AI systems are increasingly capable of taking actions, not simply generating answers.
Here are five lessons for managed service providers.
1. AI Agents Need Clearly Defined Boundaries
AI agents that interact with applications, APIs, repositories, and cloud environments shouldn’t automatically receive broad access. MSPs can apply least-privilege principles, limiting agents to the systems and permissions required for specific tasks.
MSP Action: Review AI agent permissions and apply least-privilege access based on what each agent needs to perform its intended task.
2. Monitor What AI Agents Actually Do
Organizations already monitor users, endpoints, applications, and networks. Autonomous AI activity should receive similar visibility through logging, API monitoring, and alerts for unexpected behavior.
MSP Action: Incorporate AI agent activity into existing monitoring processes and establish alerts for unusual actions or access.
3. Protect Credentials From Unnecessary Access
The RubyGems investigation included code designed to obtain API keys, although Ruby Central says it found no evidence those attempts succeeded.
For MSPs, this reinforces the importance of protecting API keys, tokens, privileged accounts, and other credentials as AI systems gain greater access to business infrastructure.
MSP Action: Review how AI tools access credentials and restrict that access wherever it isn’t necessary.
4. Don’t Overlook Software Supply-Chain Risk
RubyGems is part of the software supply chain developers rely on to distribute and obtain software packages. The incident is another reminder that repositories, packages, integrations, and dependencies can introduce risk beyond a customer’s own network.
MSP Action: Include AI-connected repositories, packages, integrations, and dependencies in software inventory and third-party risk reviews.
5. Expand AI Governance Beyond Chatbots
AI governance has often focused on employee use and data privacy. Agentic AI changes the equation because these systems can increasingly take action on behalf of users and organizations.
MSPs can help customers establish what agents can access, what actions they can perform, and when human approval is required.
MSP Action: Update customer AI policies to address autonomous actions, permissions, oversight, and approval requirements.
The MSP Opportunity
The larger lesson isn’t whether every disputed detail of the RubyGems incident can ultimately be attributed to AI. It’s that autonomous AI creates security considerations that extend beyond traditional generative AI.
As businesses adopt increasingly capable agents, MSPs can help establish the permissions, monitoring, credential controls, and governance needed to embrace AI while keeping security at the center.
