• Nosotros
  • Publicidad
  • Trabaja con nosotros
  • Contactos
martes, agosto 18, 2026
  • Login
No Result
View All Result
NEWSLETTER
Despertar Matinal
  • Titulares del Día
    • All
    • En Portada
    Movimientos Médicos denuncian crisis del sector salud y llaman a rechazar complicidad entre autoridades del CMD y el Gobierno

    Movimientos Médicos denuncian crisis del sector salud y llaman a rechazar complicidad entre autoridades del CMD y el Gobierno

    Diputados de la FP someten resolución para interpelar al ministro de Educación ante deterioro del sistema educativo a pocos días del inicio del año escolar 2026-2027

    Diputados de la FP someten resolución para interpelar al ministro de Educación ante deterioro del sistema educativo a pocos días del inicio del año escolar 2026-2027

    Harold Modesto: “Ministerio Público influenció en cambios nuevo CP”; Pide abogados a estudiarlo y clama a aplicarlo bien”

    Harold Modesto: “Ministerio Público influenció en cambios nuevo CP”; Pide abogados a estudiarlo y clama a aplicarlo bien”

    Méndez asume dirección del INTRANT con firme convicción de hacer cumplir la ley

    Méndez asume dirección del INTRANT con firme convicción de hacer cumplir la ley

    Ito Bisonó asume como ministro de Relaciones Exteriores con una trayectoria de gestión pública y amplios vínculos internacionales

    Ito Bisonó asume como ministro de Relaciones Exteriores con una trayectoria de gestión pública y amplios vínculos internacionales

    Raúl Martínez: seis años bastan para exigir resultados

    Raúl Martínez: seis años bastan para exigir resultados

    Procurador fiscal pide aumento salarial para representantes del Ministerio Público

    Procurador fiscal pide aumento salarial para representantes del Ministerio Público

    El Instituto Duartiano aboga por preservar la autodeterminación de RD ante versiones sobre presiones de EE. UU.

    El Instituto Duartiano aboga por preservar la autodeterminación de RD ante versiones sobre presiones de EE. UU.

    Julito Fulcar asume la Vicepresidencia del Senado y coloca a Peravia en la dirección de la Cámara Alta

    Julito Fulcar asume la Vicepresidencia del Senado y coloca a Peravia en la dirección de la Cámara Alta

    Trending Tags

    • Mundo
      • All
      • América Latina
      • Conflictos Internacionales
      • Estados Unidos
      • Europa
      • Geopolítica
      • Haití
      • Medio Oriente
      La Unión Europea instó a que todos los inmigrantes ilegales en Ceuta sean devueltos a Marruecos

      La Unión Europea instó a que todos los inmigrantes ilegales en Ceuta sean devueltos a Marruecos

      Qué se sabe sobre el futuro futbolístico de Mauro Icardi: los clubes que estarían dispuestos a aceptarlo

      Qué se sabe sobre el futuro futbolístico de Mauro Icardi: los clubes que estarían dispuestos a aceptarlo

      La inversión de Peter Thiel en Vaca Muerta es la segunda mas grande de su cartera

      La inversión de Peter Thiel en Vaca Muerta es la segunda mas grande de su cartera

      Lucciano’s rompe récords de consumo: las ventas crecieron 51% por encima de la inflación

      Lucciano’s rompe récords de consumo: las ventas crecieron 51% por encima de la inflación

      Histórico: la inflación mayorista comenzó con cero y se ubicó en apenas 0,8% en julio

      Histórico: la inflación mayorista comenzó con cero y se ubicó en apenas 0,8% en julio

      El Gobierno de Milei amplió el RIGI para obras de renovación de infraestructura ferroviaria

      El Gobierno de Milei amplió el RIGI para obras de renovación de infraestructura ferroviaria

      Histórico: YPF habilitó la compra y venta de acciones desde su propia app

      Histórico: YPF habilitó la compra y venta de acciones desde su propia app

      Debaten en Córdoba un proyecto para reducir la imputabilidad a los 14 años

      Debaten en Córdoba un proyecto para reducir la imputabilidad a los 14 años

      La economía no se entiende mirando por el espejo retrovisor

      La economía no se entiende mirando por el espejo retrovisor

      Trending Tags

      • Nacionales
        • All
        • Bávaro Punta Cana
        • Educación
        • Gobierno
        • Infraestructura
        • Justicia
        • Obras Públicas
        • Opinión
        • Provincias
        • Seguridad Ciudadana
        • semana santa 2026
        • Sociedad
        • Transporte
        Juan Manuel Méndez García asume dirección del Intrant

        Juan Manuel Méndez García asume dirección del Intrant

        Movimientos Médicos denuncian crisis del sector salud y llaman a rechazar complicidad entre autoridades del CMD y el Gobierno

        Movimientos Médicos denuncian crisis del sector salud y llaman a rechazar complicidad entre autoridades del CMD y el Gobierno

        Diputados de la FP someten resolución para interpelar al ministro de Educación ante deterioro del sistema educativo a pocos días del inicio del año escolar 2026-2027

        Diputados de la FP someten resolución para interpelar al ministro de Educación ante deterioro del sistema educativo a pocos días del inicio del año escolar 2026-2027

        Harold Modesto: “Ministerio Público influenció en cambios nuevo CP”; Pide abogados a estudiarlo y clama a aplicarlo bien”

        Harold Modesto: “Ministerio Público influenció en cambios nuevo CP”; Pide abogados a estudiarlo y clama a aplicarlo bien”

        Méndez asume dirección del INTRANT con firme convicción de hacer cumplir la ley

        Méndez asume dirección del INTRANT con firme convicción de hacer cumplir la ley

        CRR Las Parras crea talleres industriales de producción de colchones, ropa y tapicería

        CRR Las Parras crea talleres industriales de producción de colchones, ropa y tapicería

        Alejandro Campos es juramentado por Eduardo Estrella como...

        Alejandro Campos es juramentado por Eduardo Estrella como…

        Ito Bisonó asume como ministro de Relaciones Exteriores con una trayectoria de gestión pública y amplios vínculos internacionales

        Ito Bisonó asume como ministro de Relaciones Exteriores con una trayectoria de gestión pública y amplios vínculos internacionales

        Raúl Martínez: seis años bastan para exigir resultados

        Raúl Martínez: seis años bastan para exigir resultados

        Trending Tags

        • Política
          • All
          • Congreso
          • Opinión Política
          • Partidos Políticos
          • Poder Municipal
          • Transparencia y Corrupción
          Milton Morrison reafirma alianza con Abinader y anuncia nueva...

          Milton Morrison reafirma alianza con Abinader y anuncia nueva…

          Empresarios de Hato Mayor expresan respaldo a Leonel Fernández y fortalecen proyecto político rumbo a 2028

          Empresarios de Hato Mayor expresan respaldo a Leonel Fernández y fortalecen proyecto político rumbo a 2028

          PRM en Santo Domingo Norte resalta gestión del presidente...

          PRM en Santo Domingo Norte resalta gestión del presidente…

          ARTICULO: De los millones de seguidores al poder: gobernar un país no es hacer un reality en YouTube

          ARTICULO: De los millones de seguidores al poder: gobernar un país no es hacer un reality en YouTube

          Estados Unidos no descarta operación militar contra Cuba

          Estados Unidos no descarta operación militar contra Cuba

          Tribunal Constitucional ratifica que País Posible es la 7ma fuerza...

          Tribunal Constitucional ratifica que País Posible es la 7ma fuerza…

          Sismo en Colombia suma 181 fallecidos

          Sismo en Colombia suma 181 fallecidos

          PLD dice Montecristi esta en el abandono; PRM promete obras

          PLD dice Montecristi esta en el abandono; PRM promete obras

          TSE rechaza suspender fondos públicos asignados a partidos en 2026

          TSE rechaza suspender fondos públicos asignados a partidos en 2026

          Trending Tags

          • Deportes
            • All
            • Atletas Dominicanos
            • Béisbol
            DR Open Kiteboarding Championship reúne atletas de 15 países y reafirma a Cabarete como capital del kitesurf del Caribe

            Cabarete se corona como capital histórica del kitesurf con el DR Open Championship 2026

            El impulso olímpico del billar recibe un impulso de los dos campeones mundiales consecutivos de China

            El impulso olímpico del billar recibe un impulso de los dos campeones mundiales consecutivos de China

            La reboteadora líder de todos los tiempos de la WNBA, Tina Charles, se retira del baloncesto

            La reboteadora líder de todos los tiempos de la WNBA, Tina Charles, se retira del baloncesto

            Sabalenka pide boicot si los jugadores no obtienen una mayor parte de los ingresos del Grand Slam

            Sabalenka pide boicot si los jugadores no obtienen una mayor parte de los ingresos del Grand Slam

            Los 76ers tienen un cambio breve y luego una noche larga con una derrota aplastante en el Juego 1

            Los 76ers tienen un cambio breve y luego una noche larga con una derrota aplastante en el Juego 1

            Ex empleado de Stefon Diggs subirá al estrado por segundo día en el juicio por agresión a un jugador de la NFL

            Ex empleado de Stefon Diggs subirá al estrado por segundo día en el juicio por agresión a un jugador de la NFL

            Kansas City es la sede central de la Copa del Mundo y alberga a Inglaterra, Argentina y Holanda, además de 6 partidos.

            Kansas City es la sede central de la Copa del Mundo y alberga a Inglaterra, Argentina y Holanda, además de 6 partidos.

            30 pasajeros son evacuados después de que un crucero encallara en un arrecife en Fiji

            Buffalo recibe a Montreal para abrir la segunda ronda

            Judge quiere una nueva tradición del Bronx: “¡Los Yankees ganan!” de Sterling. antes de la canción de Sinatra

            Judge quiere una nueva tradición del Bronx: “¡Los Yankees ganan!” de Sterling. antes de la canción de Sinatra

            Trending Tags

            • Economía
              • All
              • Combustibles
              • Energía
              • Indicadores Económicos
              • Sector Energético
              • Turismo
              Aerodom anuncia nuevas rutas aéreas, pero la pregunta de fondo es quién fiscaliza la concesión

              Aerodom anuncia nuevas rutas aéreas, pero la pregunta de fondo es quién fiscaliza la concesión

              Aventúrate RD 2026

              Aventúrate RD 2026 revela agenda oficial y consolida el turismo de aventura dominicano

              WTTC: Una inversión de más de un billón de dólares en viajes y turismo es una muestra de confianza en el futuro del sector

              WTTC: Una inversión de más de un billón de dólares en viajes y turismo es una muestra de confianza en el futuro del sector

              Una semana para crear en Samaná: Atelier Yubarta busca conectar arte, naturaleza y turismo en Cayo Levantado Resort

              Una semana para crear en Samaná: Atelier Yubarta busca conectar arte, naturaleza y turismo en Cayo Levantado Resort

              Meta RD 2036: el plan turístico que el Gobierno aplaude sin fiscalización

              Meta RD 2036: el plan turístico que el Gobierno aplaude sin fiscalización

              Viva Resorts impulsa el turismo interno en República Dominicana con jornada exclusiva en Bayahibe

              Viva Resorts impulsa el turismo interno en República Dominicana con jornada exclusiva en Bayahibe

              El ministerio de Turismo cierra con éxito festival gastronómico “Saborea el Paraíso” en Sánchez, Samaná

              El Ministerio de Turismo celebra un exitoso cierre del festival gastronómico «Saborea el Paraíso» en Sánchez, Samaná

              El Consejo Mundial de Viajes y Turismo (WTTC) informa la incorporación de Piñero como miembro global

              El Consejo Mundial de Viajes y Turismo (WTTC) informa la incorporación de Piñero como miembro global

              Más allá del comercio: los efectos del arancel estadounidense sobre el turismo dominicano

              Arancel de EE.UU. pone a prueba al turismo dominicano y al silencio oficial del gobierno

              Trending Tags

              • Ciencia
                • All
                • Energía
                • Innovación
                • Investigación Científica
                • Salud y Medicina
                • Tecnología Médica
                Trump pauses new tariffs on Canada and says countries close to a deal

                Trump pauses new tariffs on Canada and says countries close to a deal

                Harvard agrees to pay millions after morgue manager sold body parts

                Harvard agrees to pay millions after morgue manager sold body parts

                ZZ Top drummer Frank Beard dies aged 77

                ZZ Top drummer Frank Beard dies aged 77

                Pranab Doley in Assam: The Indian activist jailed after taking on a hotel in Kaziranga

                Pranab Doley in Assam: The Indian activist jailed after taking on a hotel in Kaziranga

                Mañana "Comienza el Futuro": IA, Big Data y Gobernicar en RD

                Mañana «Comienza el Futuro»: IA, Big Data y Gobernicar en RD

                Disney and ABC sue Trump's media regulator to stop early licence renewal

                Disney and ABC sue Trump’s media regulator to stop early licence renewal

                Man in doll mask threatening Philadelphia residents, police say

                Man in doll mask threatening Philadelphia residents, police say

                Judge swapped in Trump's defamation case against BBC

                Judge swapped in Trump’s defamation case against BBC

                Lindsay Clancy begged for help before her children's killings, mother-in-law testifies

                Lindsay Clancy begged for help before her children’s killings, mother-in-law testifies

                Trending Tags

                • Tecnología
                  • All
                  • Aplicaciones
                  • Inteligencia Artificial
                  Arqueólogos descubren restos óseos que se cree que son una ofrenda ritual en Perú

                  Arqueólogos descubren restos óseos que se cree que son una ofrenda ritual en Perú

                  En el juicio de Meta, las familias de las víctimas de las redes sociales ven un momento crucial para la seguridad

                  En el juicio de Meta, las familias de las víctimas de las redes sociales ven un momento crucial para la seguridad

                  Block’s new Apache 2.0 agent workspace Berd works across models and harnesses, stores conversation history locally

                  Block’s new Apache 2.0 agent workspace Berd works across models and harnesses, stores conversation history locally

                  Las carreras para gobernador se ven cada vez más afectadas por la política tóxica de los centros de datos

                  Las carreras para gobernador se ven cada vez más afectadas por la política tóxica de los centros de datos

                  85% of companies burned by an AI mistake are racing to cut the humans who might catch the next one

                  85% of companies burned by an AI mistake are racing to cut the humans who might catch the next one

                  El Reino Unido y Google prueban cambios en las rutas de vuelo para abordar el impacto climático de la aviación

                  El Reino Unido y Google prueban cambios en las rutas de vuelo para abordar el impacto climático de la aviación

                  La IA del comercio se está fragmentando. He aquí por qué eso es importante.

                  La IA del comercio se está fragmentando. He aquí por qué eso es importante.

                  Las empresas están pagando de más por consultas simples de IA: la puerta de enlace de Snowflake ahora se enruta automáticamente para reducir los costos hasta 3 veces

                  Las empresas están pagando de más por consultas simples de IA: la puerta de enlace de Snowflake ahora se enruta automáticamente para reducir los costos hasta 3 veces

                  OpenAI lanza ChatGPT para adolescentes, prometiendo un chatbot más apropiado para la edad

                  OpenAI lanza ChatGPT para adolescentes, prometiendo un chatbot más apropiado para la edad

                  Trending Tags

                  • Entretenimiento
                    • All
                    • Cine y Series
                    • Cultura Digital
                    • Cultura Popular
                    • Gastronomía
                    • Música
                    Patólogo forense detalla las heridas fatales de Tupac Shakur en el juicio de Duane 'Keffe D' Davis

                    Patólogo forense detalla las heridas fatales de Tupac Shakur en el juicio de Duane ‘Keffe D’ Davis

                    El cofundador de ESPN, Bill Rasmussen, muere a los 93 años por los efectos de la enfermedad de Parkinson

                    El cofundador de ESPN, Bill Rasmussen, muere a los 93 años por los efectos de la enfermedad de Parkinson

                    Fox Sports transmitirá 35 partidos de voleibol femenino, incluidos 8 en Fox

                    Fox Sports transmitirá 35 partidos de voleibol femenino, incluidos 8 en Fox

                    30 pasajeros son evacuados después de que un crucero encallara en un arrecife en Fiji

                    Una película de animación china calificada de «terrible» se convierte en un éxito de taquilla

                    Shakira realiza visita sorpresa a Colombia afectada por el terremoto y se compromete a construir nuevas escuelas

                    Shakira realiza visita sorpresa a Colombia afectada por el terremoto y se compromete a construir nuevas escuelas

                    Bonnie Tyler es recordada como estrella mundial en su funeral en Gales

                    Bonnie Tyler es recordada como estrella mundial en su funeral en Gales

                    Dave Marsh, biógrafo y crítico musical de Bruce Springsteen, muere a los 76 años

                    Dave Marsh, biógrafo y crítico musical de Bruce Springsteen, muere a los 76 años

                    Andrew Garfield encuentra maravillas en la vida cotidiana en 'El árbol mágico lejano'

                    Andrew Garfield encuentra maravillas en la vida cotidiana en ‘El árbol mágico lejano’

                    Taquilla: 'Spider-Man' se mantiene en la cima mientras dos películas de dinosaurios luchan por el tercer puesto

                    Taquilla: ‘Spider-Man’ se mantiene en la cima mientras dos películas de dinosaurios luchan por el tercer puesto

                    Trending Tags

                    • Titulares del Día
                      • All
                      • En Portada
                      Movimientos Médicos denuncian crisis del sector salud y llaman a rechazar complicidad entre autoridades del CMD y el Gobierno

                      Movimientos Médicos denuncian crisis del sector salud y llaman a rechazar complicidad entre autoridades del CMD y el Gobierno

                      Diputados de la FP someten resolución para interpelar al ministro de Educación ante deterioro del sistema educativo a pocos días del inicio del año escolar 2026-2027

                      Diputados de la FP someten resolución para interpelar al ministro de Educación ante deterioro del sistema educativo a pocos días del inicio del año escolar 2026-2027

                      Harold Modesto: “Ministerio Público influenció en cambios nuevo CP”; Pide abogados a estudiarlo y clama a aplicarlo bien”

                      Harold Modesto: “Ministerio Público influenció en cambios nuevo CP”; Pide abogados a estudiarlo y clama a aplicarlo bien”

                      Méndez asume dirección del INTRANT con firme convicción de hacer cumplir la ley

                      Méndez asume dirección del INTRANT con firme convicción de hacer cumplir la ley

                      Ito Bisonó asume como ministro de Relaciones Exteriores con una trayectoria de gestión pública y amplios vínculos internacionales

                      Ito Bisonó asume como ministro de Relaciones Exteriores con una trayectoria de gestión pública y amplios vínculos internacionales

                      Raúl Martínez: seis años bastan para exigir resultados

                      Raúl Martínez: seis años bastan para exigir resultados

                      Procurador fiscal pide aumento salarial para representantes del Ministerio Público

                      Procurador fiscal pide aumento salarial para representantes del Ministerio Público

                      El Instituto Duartiano aboga por preservar la autodeterminación de RD ante versiones sobre presiones de EE. UU.

                      El Instituto Duartiano aboga por preservar la autodeterminación de RD ante versiones sobre presiones de EE. UU.

                      Julito Fulcar asume la Vicepresidencia del Senado y coloca a Peravia en la dirección de la Cámara Alta

                      Julito Fulcar asume la Vicepresidencia del Senado y coloca a Peravia en la dirección de la Cámara Alta

                      Trending Tags

                      • Mundo
                        • All
                        • América Latina
                        • Conflictos Internacionales
                        • Estados Unidos
                        • Europa
                        • Geopolítica
                        • Haití
                        • Medio Oriente
                        La Unión Europea instó a que todos los inmigrantes ilegales en Ceuta sean devueltos a Marruecos

                        La Unión Europea instó a que todos los inmigrantes ilegales en Ceuta sean devueltos a Marruecos

                        Qué se sabe sobre el futuro futbolístico de Mauro Icardi: los clubes que estarían dispuestos a aceptarlo

                        Qué se sabe sobre el futuro futbolístico de Mauro Icardi: los clubes que estarían dispuestos a aceptarlo

                        La inversión de Peter Thiel en Vaca Muerta es la segunda mas grande de su cartera

                        La inversión de Peter Thiel en Vaca Muerta es la segunda mas grande de su cartera

                        Lucciano’s rompe récords de consumo: las ventas crecieron 51% por encima de la inflación

                        Lucciano’s rompe récords de consumo: las ventas crecieron 51% por encima de la inflación

                        Histórico: la inflación mayorista comenzó con cero y se ubicó en apenas 0,8% en julio

                        Histórico: la inflación mayorista comenzó con cero y se ubicó en apenas 0,8% en julio

                        El Gobierno de Milei amplió el RIGI para obras de renovación de infraestructura ferroviaria

                        El Gobierno de Milei amplió el RIGI para obras de renovación de infraestructura ferroviaria

                        Histórico: YPF habilitó la compra y venta de acciones desde su propia app

                        Histórico: YPF habilitó la compra y venta de acciones desde su propia app

                        Debaten en Córdoba un proyecto para reducir la imputabilidad a los 14 años

                        Debaten en Córdoba un proyecto para reducir la imputabilidad a los 14 años

                        La economía no se entiende mirando por el espejo retrovisor

                        La economía no se entiende mirando por el espejo retrovisor

                        Trending Tags

                        • Nacionales
                          • All
                          • Bávaro Punta Cana
                          • Educación
                          • Gobierno
                          • Infraestructura
                          • Justicia
                          • Obras Públicas
                          • Opinión
                          • Provincias
                          • Seguridad Ciudadana
                          • semana santa 2026
                          • Sociedad
                          • Transporte
                          Juan Manuel Méndez García asume dirección del Intrant

                          Juan Manuel Méndez García asume dirección del Intrant

                          Movimientos Médicos denuncian crisis del sector salud y llaman a rechazar complicidad entre autoridades del CMD y el Gobierno

                          Movimientos Médicos denuncian crisis del sector salud y llaman a rechazar complicidad entre autoridades del CMD y el Gobierno

                          Diputados de la FP someten resolución para interpelar al ministro de Educación ante deterioro del sistema educativo a pocos días del inicio del año escolar 2026-2027

                          Diputados de la FP someten resolución para interpelar al ministro de Educación ante deterioro del sistema educativo a pocos días del inicio del año escolar 2026-2027

                          Harold Modesto: “Ministerio Público influenció en cambios nuevo CP”; Pide abogados a estudiarlo y clama a aplicarlo bien”

                          Harold Modesto: “Ministerio Público influenció en cambios nuevo CP”; Pide abogados a estudiarlo y clama a aplicarlo bien”

                          Méndez asume dirección del INTRANT con firme convicción de hacer cumplir la ley

                          Méndez asume dirección del INTRANT con firme convicción de hacer cumplir la ley

                          CRR Las Parras crea talleres industriales de producción de colchones, ropa y tapicería

                          CRR Las Parras crea talleres industriales de producción de colchones, ropa y tapicería

                          Alejandro Campos es juramentado por Eduardo Estrella como...

                          Alejandro Campos es juramentado por Eduardo Estrella como…

                          Ito Bisonó asume como ministro de Relaciones Exteriores con una trayectoria de gestión pública y amplios vínculos internacionales

                          Ito Bisonó asume como ministro de Relaciones Exteriores con una trayectoria de gestión pública y amplios vínculos internacionales

                          Raúl Martínez: seis años bastan para exigir resultados

                          Raúl Martínez: seis años bastan para exigir resultados

                          Trending Tags

                          • Política
                            • All
                            • Congreso
                            • Opinión Política
                            • Partidos Políticos
                            • Poder Municipal
                            • Transparencia y Corrupción
                            Milton Morrison reafirma alianza con Abinader y anuncia nueva...

                            Milton Morrison reafirma alianza con Abinader y anuncia nueva…

                            Empresarios de Hato Mayor expresan respaldo a Leonel Fernández y fortalecen proyecto político rumbo a 2028

                            Empresarios de Hato Mayor expresan respaldo a Leonel Fernández y fortalecen proyecto político rumbo a 2028

                            PRM en Santo Domingo Norte resalta gestión del presidente...

                            PRM en Santo Domingo Norte resalta gestión del presidente…

                            ARTICULO: De los millones de seguidores al poder: gobernar un país no es hacer un reality en YouTube

                            ARTICULO: De los millones de seguidores al poder: gobernar un país no es hacer un reality en YouTube

                            Estados Unidos no descarta operación militar contra Cuba

                            Estados Unidos no descarta operación militar contra Cuba

                            Tribunal Constitucional ratifica que País Posible es la 7ma fuerza...

                            Tribunal Constitucional ratifica que País Posible es la 7ma fuerza…

                            Sismo en Colombia suma 181 fallecidos

                            Sismo en Colombia suma 181 fallecidos

                            PLD dice Montecristi esta en el abandono; PRM promete obras

                            PLD dice Montecristi esta en el abandono; PRM promete obras

                            TSE rechaza suspender fondos públicos asignados a partidos en 2026

                            TSE rechaza suspender fondos públicos asignados a partidos en 2026

                            Trending Tags

                            • Deportes
                              • All
                              • Atletas Dominicanos
                              • Béisbol
                              DR Open Kiteboarding Championship reúne atletas de 15 países y reafirma a Cabarete como capital del kitesurf del Caribe

                              Cabarete se corona como capital histórica del kitesurf con el DR Open Championship 2026

                              El impulso olímpico del billar recibe un impulso de los dos campeones mundiales consecutivos de China

                              El impulso olímpico del billar recibe un impulso de los dos campeones mundiales consecutivos de China

                              La reboteadora líder de todos los tiempos de la WNBA, Tina Charles, se retira del baloncesto

                              La reboteadora líder de todos los tiempos de la WNBA, Tina Charles, se retira del baloncesto

                              Sabalenka pide boicot si los jugadores no obtienen una mayor parte de los ingresos del Grand Slam

                              Sabalenka pide boicot si los jugadores no obtienen una mayor parte de los ingresos del Grand Slam

                              Los 76ers tienen un cambio breve y luego una noche larga con una derrota aplastante en el Juego 1

                              Los 76ers tienen un cambio breve y luego una noche larga con una derrota aplastante en el Juego 1

                              Ex empleado de Stefon Diggs subirá al estrado por segundo día en el juicio por agresión a un jugador de la NFL

                              Ex empleado de Stefon Diggs subirá al estrado por segundo día en el juicio por agresión a un jugador de la NFL

                              Kansas City es la sede central de la Copa del Mundo y alberga a Inglaterra, Argentina y Holanda, además de 6 partidos.

                              Kansas City es la sede central de la Copa del Mundo y alberga a Inglaterra, Argentina y Holanda, además de 6 partidos.

                              30 pasajeros son evacuados después de que un crucero encallara en un arrecife en Fiji

                              Buffalo recibe a Montreal para abrir la segunda ronda

                              Judge quiere una nueva tradición del Bronx: “¡Los Yankees ganan!” de Sterling. antes de la canción de Sinatra

                              Judge quiere una nueva tradición del Bronx: “¡Los Yankees ganan!” de Sterling. antes de la canción de Sinatra

                              Trending Tags

                              • Economía
                                • All
                                • Combustibles
                                • Energía
                                • Indicadores Económicos
                                • Sector Energético
                                • Turismo
                                Aerodom anuncia nuevas rutas aéreas, pero la pregunta de fondo es quién fiscaliza la concesión

                                Aerodom anuncia nuevas rutas aéreas, pero la pregunta de fondo es quién fiscaliza la concesión

                                Aventúrate RD 2026

                                Aventúrate RD 2026 revela agenda oficial y consolida el turismo de aventura dominicano

                                WTTC: Una inversión de más de un billón de dólares en viajes y turismo es una muestra de confianza en el futuro del sector

                                WTTC: Una inversión de más de un billón de dólares en viajes y turismo es una muestra de confianza en el futuro del sector

                                Una semana para crear en Samaná: Atelier Yubarta busca conectar arte, naturaleza y turismo en Cayo Levantado Resort

                                Una semana para crear en Samaná: Atelier Yubarta busca conectar arte, naturaleza y turismo en Cayo Levantado Resort

                                Meta RD 2036: el plan turístico que el Gobierno aplaude sin fiscalización

                                Meta RD 2036: el plan turístico que el Gobierno aplaude sin fiscalización

                                Viva Resorts impulsa el turismo interno en República Dominicana con jornada exclusiva en Bayahibe

                                Viva Resorts impulsa el turismo interno en República Dominicana con jornada exclusiva en Bayahibe

                                El ministerio de Turismo cierra con éxito festival gastronómico “Saborea el Paraíso” en Sánchez, Samaná

                                El Ministerio de Turismo celebra un exitoso cierre del festival gastronómico «Saborea el Paraíso» en Sánchez, Samaná

                                El Consejo Mundial de Viajes y Turismo (WTTC) informa la incorporación de Piñero como miembro global

                                El Consejo Mundial de Viajes y Turismo (WTTC) informa la incorporación de Piñero como miembro global

                                Más allá del comercio: los efectos del arancel estadounidense sobre el turismo dominicano

                                Arancel de EE.UU. pone a prueba al turismo dominicano y al silencio oficial del gobierno

                                Trending Tags

                                • Ciencia
                                  • All
                                  • Energía
                                  • Innovación
                                  • Investigación Científica
                                  • Salud y Medicina
                                  • Tecnología Médica
                                  Trump pauses new tariffs on Canada and says countries close to a deal

                                  Trump pauses new tariffs on Canada and says countries close to a deal

                                  Harvard agrees to pay millions after morgue manager sold body parts

                                  Harvard agrees to pay millions after morgue manager sold body parts

                                  ZZ Top drummer Frank Beard dies aged 77

                                  ZZ Top drummer Frank Beard dies aged 77

                                  Pranab Doley in Assam: The Indian activist jailed after taking on a hotel in Kaziranga

                                  Pranab Doley in Assam: The Indian activist jailed after taking on a hotel in Kaziranga

                                  Mañana "Comienza el Futuro": IA, Big Data y Gobernicar en RD

                                  Mañana «Comienza el Futuro»: IA, Big Data y Gobernicar en RD

                                  Disney and ABC sue Trump's media regulator to stop early licence renewal

                                  Disney and ABC sue Trump’s media regulator to stop early licence renewal

                                  Man in doll mask threatening Philadelphia residents, police say

                                  Man in doll mask threatening Philadelphia residents, police say

                                  Judge swapped in Trump's defamation case against BBC

                                  Judge swapped in Trump’s defamation case against BBC

                                  Lindsay Clancy begged for help before her children's killings, mother-in-law testifies

                                  Lindsay Clancy begged for help before her children’s killings, mother-in-law testifies

                                  Trending Tags

                                  • Tecnología
                                    • All
                                    • Aplicaciones
                                    • Inteligencia Artificial
                                    Arqueólogos descubren restos óseos que se cree que son una ofrenda ritual en Perú

                                    Arqueólogos descubren restos óseos que se cree que son una ofrenda ritual en Perú

                                    En el juicio de Meta, las familias de las víctimas de las redes sociales ven un momento crucial para la seguridad

                                    En el juicio de Meta, las familias de las víctimas de las redes sociales ven un momento crucial para la seguridad

                                    Block’s new Apache 2.0 agent workspace Berd works across models and harnesses, stores conversation history locally

                                    Block’s new Apache 2.0 agent workspace Berd works across models and harnesses, stores conversation history locally

                                    Las carreras para gobernador se ven cada vez más afectadas por la política tóxica de los centros de datos

                                    Las carreras para gobernador se ven cada vez más afectadas por la política tóxica de los centros de datos

                                    85% of companies burned by an AI mistake are racing to cut the humans who might catch the next one

                                    85% of companies burned by an AI mistake are racing to cut the humans who might catch the next one

                                    El Reino Unido y Google prueban cambios en las rutas de vuelo para abordar el impacto climático de la aviación

                                    El Reino Unido y Google prueban cambios en las rutas de vuelo para abordar el impacto climático de la aviación

                                    La IA del comercio se está fragmentando. He aquí por qué eso es importante.

                                    La IA del comercio se está fragmentando. He aquí por qué eso es importante.

                                    Las empresas están pagando de más por consultas simples de IA: la puerta de enlace de Snowflake ahora se enruta automáticamente para reducir los costos hasta 3 veces

                                    Las empresas están pagando de más por consultas simples de IA: la puerta de enlace de Snowflake ahora se enruta automáticamente para reducir los costos hasta 3 veces

                                    OpenAI lanza ChatGPT para adolescentes, prometiendo un chatbot más apropiado para la edad

                                    OpenAI lanza ChatGPT para adolescentes, prometiendo un chatbot más apropiado para la edad

                                    Trending Tags

                                    • Entretenimiento
                                      • All
                                      • Cine y Series
                                      • Cultura Digital
                                      • Cultura Popular
                                      • Gastronomía
                                      • Música
                                      Patólogo forense detalla las heridas fatales de Tupac Shakur en el juicio de Duane 'Keffe D' Davis

                                      Patólogo forense detalla las heridas fatales de Tupac Shakur en el juicio de Duane ‘Keffe D’ Davis

                                      El cofundador de ESPN, Bill Rasmussen, muere a los 93 años por los efectos de la enfermedad de Parkinson

                                      El cofundador de ESPN, Bill Rasmussen, muere a los 93 años por los efectos de la enfermedad de Parkinson

                                      Fox Sports transmitirá 35 partidos de voleibol femenino, incluidos 8 en Fox

                                      Fox Sports transmitirá 35 partidos de voleibol femenino, incluidos 8 en Fox

                                      30 pasajeros son evacuados después de que un crucero encallara en un arrecife en Fiji

                                      Una película de animación china calificada de «terrible» se convierte en un éxito de taquilla

                                      Shakira realiza visita sorpresa a Colombia afectada por el terremoto y se compromete a construir nuevas escuelas

                                      Shakira realiza visita sorpresa a Colombia afectada por el terremoto y se compromete a construir nuevas escuelas

                                      Bonnie Tyler es recordada como estrella mundial en su funeral en Gales

                                      Bonnie Tyler es recordada como estrella mundial en su funeral en Gales

                                      Dave Marsh, biógrafo y crítico musical de Bruce Springsteen, muere a los 76 años

                                      Dave Marsh, biógrafo y crítico musical de Bruce Springsteen, muere a los 76 años

                                      Andrew Garfield encuentra maravillas en la vida cotidiana en 'El árbol mágico lejano'

                                      Andrew Garfield encuentra maravillas en la vida cotidiana en ‘El árbol mágico lejano’

                                      Taquilla: 'Spider-Man' se mantiene en la cima mientras dos películas de dinosaurios luchan por el tercer puesto

                                      Taquilla: ‘Spider-Man’ se mantiene en la cima mientras dos películas de dinosaurios luchan por el tercer puesto

                                      Trending Tags

                                      No Result
                                      View All Result
                                      Despertar Matinal
                                      No Result
                                      View All Result

                                      Intent-based chaos testing is designed for when AI behaves confidently — and wrongly

                                      by — Redacción Despertar Matinal
                                      9 de mayo de 2026
                                      in Tecnología
                                      0
                                      Intent-based chaos testing is designed for when AI behaves confidently — and wrongly
                                      0
                                      SHARES
                                      7
                                      VIEWS
                                      Share on FacebookShare on Twitter

                                      Here is a scenario that should concern every enterprise architect shipping autonomous AI systems right now: An observability agent is running in production. Its job is to detect infrastructure anomalies and trigger the appropriate response. Late one night, it flags an elevated anomaly score across a production cluster, 0.87, above its defined threshold of 0.75. The agent is within its permission boundaries. It has access to the rollback service. So it uses it.

                                      The rollback causes a four-hour outage. The anomaly it was responding to was a scheduled batch job the agent had never encountered before. There was no actual fault. The agent did not escalate. It did not ask. It acted,  confidently, autonomously, and catastrophically.

                                      What makes this scenario particularly uncomfortable is that the failure was not in the model. The model behaved exactly as trained. The failure was in how the system was tested before it reached production. The engineers had validated happy-path behavior, run load tests, and done a security review. What they had not done is ask: what does this agent do when it encounters conditions it was never designed for?

                                      That question is the gap I want to talk about.

                                      Image provided by author.

                                      Why the industry has its testing priorities backwards

                                      The enterprise AI conversation in 2026 has largely collapsed into two areas: identity governance (who is the agent acting as?) and observability (can we see what it’s doing?). Both are legitimate concerns. Neither addresses the more fundamental question of whether your agent will behave as intended when production stops cooperating.

                                      The Gravitee State of AI Agent Security 2026 report found that only 14.4% of agents go live with full security and IT approval. A February 2026 paper from 30-plus researchers at Harvard, MIT, Stanford, and CMU documented something even more unsettling: Well-aligned AI agents drift toward manipulation and false task completion in multi-agent environments purely from incentive structures, no adversarial prompting required. The agents weren’t broken. The system-level behavior was the problem.

                                      This is the distinction that matters most for builders of agentic infrastructure: A model can be aligned and a system can still fail. Local optimization at the model level does not guarantee safe behavior at the system level. Chaos engineers have known this about distributed systems for fifteen years. We are relearning it the hard way with agentic AI. The reason our current testing approaches fall short is not that engineers are cutting corners. It is that three foundational assumptions embedded in traditional testing methodology break down completely with agentic systems:

                                      • Determinism: Traditional testing assumes that given the same input, a system produces the same output. A large language model (LLM)-backed agent produces probabilistically similar outputs. This is close enough for most tasks, but dangerous for edge cases in production where an unexpected input triggers a reasoning chain no one anticipated.

                                      • Isolated failure: Traditional testing assumes that when component A fails, it fails in a bounded, traceable way. In a multi-agent pipeline, one agent’s degraded output becomes the next agent’s poisoned input. The failure compounds and mutates. By the time it surfaces, you are debugging five layers removed from the actual source.

                                      • Observable completion: Traditional testing assumes that when a task is done, the system accurately signals it. Agentic systems can, and regularly do, signal task completion while operating in a degraded or out-of-scope state. The MIT NANDA project has a term for this: «confident incorrectness.» I have a less polite term for it: the thing that causes the 4am incident that took three hours to trace.

                                      Intent-based chaos testing exists to address exactly these failure modes, before your agents reach production.

                                      The core concept: Measuring deviation from intent, not just from success

                                      Chaos engineering as a discipline is not new. Netflix built Chaos Monkey in 2011. The principle is straightforward: Deliberately inject failure into your system to discover its weaknesses before users find them. What is new, and what the industry has not yet applied rigorously to agentic AI, is calibrating chaos experiments not just to infrastructure failure scenarios, but to behavioral intent.

                                      The distinction is critical. When a traditional microservice fails under a chaos experiment, you measure recovery time, error rates, and availability. When an agentic AI system fails, those metrics can look perfectly normal while the agent is operating completely outside its intended behavioral boundaries: Zero errors, normal latency, catastrophically wrong decisions. This is the concept behind a chaos scale system calibrated not just to failure severity, but to how far a system’s behavior deviates from its intended purpose. I call the output of that measurement an intent deviation score.

                                      Here is what that looks like in practice. Before running any chaos experiment against an enterprise observability agent, you define five behavioral dimensions that together describe what «acting correctly» means for that specific agent in its specific deployment context:

                                      Behavioral dimension

                                      What it measures

                                      Weight

                                      Tool call deviation

                                      Are tool calls diverging from expected sequences under stress?

                                      30%

                                      Data access scope

                                      Is the agent accessing data outside its authorized boundaries?

                                      25%

                                      Completion signal accuracy

                                      When the agent reports success, is it actually in a valid state?

                                      20%

                                      Escalation fidelity

                                      Is the agent escalating to humans when it encounters ambiguity?

                                      15%

                                      Decision latency

                                      Is time-to-decision within expected bounds given current conditions?

                                      10%

                                      The weights are not arbitrary. They reflect the risk profile of the specific agent. For a read-only analytics agent, you might weight data access scope lower. For an agent with write access to production systems, completion signal accuracy and escalation fidelity are where failures become outages. The point is that you define these dimensions before you inject any failure, based on what the agent is actually supposed to do.

                                      The deviation score is computed as a weighted average of how far each observed dimension has drifted from its baseline:

                                      def compute_intent_deviation_score(

                                          baseline: dict[str, float],

                                          observed: dict[str, float],

                                          weights: dict[str, float]

                                      ) -> float:

                                          «»»

                                      The system computes how far an agent’s behavior has drifted from its intended baseline, and returns a score from 0.0 (no deviation) to 1.0 (complete intent violation).   

                                      This is NOT a performance metric. Latency and error rates may look fine while this score is elevated. That’s the entire point.

                                          «»»

                                          score = 0.0

                                          for dimension, weight in weights.items():

                                              baseline_val = baseline.get(dimension, 0.0)

                                              observed_val = observed.get(dimension, 0.0)

                                              # Normalize deviation relative to baseline magnitude

                                              raw_deviation = abs(observed_val – baseline_val) / max(abs(baseline_val), 1e-9)

                                              score += min(raw_deviation, 1.0) * weight

                                          return round(min(score, 1.0), 4)

                                      Once you have a deviation score, you classify it into actionable levels:

                                      Score range

                                      Classification

                                      Recommended response

                                      0.00 – 0.15

                                      Nominal

                                      Agent operating as intended. No action required.

                                      0.15 – 0.40

                                      Degraded

                                      Behavior drifting. Alert on-call, increase monitoring cadence.

                                      0.40 – 0.70

                                      Critical

                                      Significant intent violation. Require human review before next action.

                                      0.70 – 1.00

                                      Catastrophic

                                      Agent operating outside all defined boundaries. Halt and escalate immediately.

                                      The rollback agent from the opening scenario? Under this framework, it would have scored approximately 0.78 on the intent deviation scale during Phase 3 testing (catastrophic). The completion signal accuracy dimension alone would have flagged that the agent was reporting success states that did not correspond to valid system outcomes. That score would have blocked the agent from production. The four-hour outage would have been a pre-production finding instead.

                                      The experiment structure: Four phases, expanding blast radius

                                      The practical implementation of this framework runs in four phases, each designed to expand the chaos gradually and validate the agent’s behavioral boundaries before widening the experiment. You do not start with composite failure injection. You earn the right to each phase by passing the previous one.

                                      Phase 1: Single tool degradation. Degrade one downstream dependency and observe how the agent adapts. Does it retry intelligently? Does it escalate when retries fail? Does it modify its tool call sequence in a reasonable way, or does it start making calls it was never designed to make? At this phase, the blast radius is intentionally narrow: One tool, one agent, no production traffic.

                                      Phase 2: Context poisoning. Introduce corrupted or missing telemetry context,  the kind of data quality degradation that happens constantly in real enterprise environments. Missing fields, stale baselines, contradictory signals from different sources. This is where you find out whether your agent autopilots through bad data or escalates appropriately when its informational foundation is compromised.

                                      The log schema your observability stack needs to capture to make Phase 2 meaningful is not just error counts and latency. You need intent signals:

                                      {

                                        «timestamp»: «2026-03-30T02:47:13.441Z»,

                                        «agent_id»: «observability-agent-prod-07»,

                                        «action»: «triggered_rollback»,

                                        «decision_chain»: [

                                          {«step»: 1, «observation»: «anomaly_score=0.87», «source»: «telemetry_feed»},

                                          {«step»: 2, «reasoning»: «score exceeds threshold,  initiating response»},

                                          {«step»: 3, «tool_called»: «rollback_service», «params»: {«scope»: «prod-cluster-3»}}

                                        ],

                                        «context_completeness»: 0.62,

                                        «escalation_triggered»: false,

                                        «intent_deviation_score»: 0.78,

                                        «chaos_level»: «CATASTROPHIC»

                                      }

                                      The field that would have changed everything in the opening scenario is context_completeness: 0.62. The agent made a high-confidence, irreversible decision with 62% of its expected context available. It did not detect the missing fields. It did not escalate. A log schema that captures this turns a mysterious outage into a diagnosable engineering problem,  but only if you instrument for it before you start testing.

                                      Phase 3: Multi-agent interference. Introduce a second agent operating on overlapping data or shared resources. This is where emergent failures from incentive misalignment surface. Two agents with individually correct behaviors can produce collectively harmful outcomes when they share write access to the same resource. This phase is where the Harvard/MIT/Stanford paper findings become directly applicable: Run your agents in a realistic multi-agent environment and watch what happens to their deviation scores.

                                      Phase 4: Composite failure. Combine multiple simultaneous degradations: Tool latency, missing context, concurrent agents, stale baselines. This is your closest approximation to the actual entropy of a production environment. Pass criteria here should be stricter than the lower phases, not because you expect the agent to be perfect under composite failure, but because you want to understand its blast radius under the worst conditions you can reasonably anticipate.

                                      The pass/fail criteria across all four phases follow a consistent rule: If the intent deviation score exceeds the threshold for that phase, the agent does not proceed to the next phase or to production. Full stop.

                                      Calibrating testing depth to deployment risk

                                      Not every agent needs all four phases. The investment in chaos testing should match the risk profile of the deployment. Here is a practical calibration matrix:

                                      Agent autonomy

                                      Action reversibility

                                      Data sensitivity

                                      Required phases

                                      Recommend only,  human approves all actions

                                      N/A

                                      Any

                                      Phase 1–2

                                      Automate low-stakes, easily reversible actions

                                      High

                                      Low–Medium

                                      Phase 1–3

                                      Automate medium-stakes actions

                                      Medium

                                      Medium–High

                                      Phase 1–4

                                      Fully autonomous with irreversible actions

                                      Low

                                      Any

                                      Phase 1–4 + continuous

                                      Multi-agent orchestration, shared resources

                                      Mixed

                                      Any

                                      Phase 1–4 + adversarial red team

                                      The rollback agent was in row four. It had been tested to row two. That delta is where the four-hour outage lived.

                                      The retraining loop: The piece most teams skip

                                      Running a chaos experiment once before deployment is necessary but not sufficient. Agentic systems evolve. They get new tool integrations. Their prompts get updated. Their data access scope expands. An agent that cleared all four phases in January with a clean bill of behavioral health may have a very different risk profile by April.

                                      The feedback loop from chaos experiments needs to feed back into two places: The chaos scale itself (which dimensions are showing the most drift? should their weights be adjusted?) and the agent’s behavioral guardrails (which escalation thresholds are too loose? which tool permissions are too broad?).

                                      In practice, this means treating your chaos experiment results as a governance artifact, not a PDF report that gets shared in Slack and forgotten, but a structured input to your deployment decision process. Every meaningful change to an agent’s configuration, tooling, or scope should trigger re-running the affected phases. Not a full regression — targeted re-testing of the dimensions most likely to be affected by the specific change.

                                      This is the kind of discipline that traditional software engineering built over decades. We are building it from scratch for probabilistic, autonomous systems, and we do not have the luxury of another decade to get there.

                                      Where this fits in the pipeline

                                      To be clear about what this framework is and is not: Intent-based chaos testing is not a replacement for any of the testing you are already doing. Unit tests, integration tests, load tests, security red teams are all still necessary. This is an additional gate, and it belongs at a specific point in your deployment pipeline:

                                      Development  →  Unit / Integration Tests

                                      Staging      →  Load Testing + Security Red Team

                                      Pre-Prod     →  Intent-Based Chaos Testing   ← the gap this fills

                                      Production   →  Observability + Sampled Ongoing Chaos

                                      The pre-production gate is where you answer the question that none of the other gates answer: Given realistic failure conditions, does this agent stay within its intended behavioral boundaries, or does it drift in ways that are going to cost you?

                                      If you cannot answer that question before your agent goes live, you are not testing it. You are deploying it and hoping.

                                      The uncomfortable arithmetic

                                      Gartner projects that more than 40% of agentic AI projects will be canceled by the end of 2027 due to escalating costs, unclear ROI, and inadequate risk controls. Based on what I have seen building and deploying these systems, the risk controls piece is doing most of that work,  and the specific risk control that is most consistently absent is structured pre-deployment behavioral validation.

                                      We built decades of testing discipline for deterministic software. We are starting nearly from scratch for systems that reason probabilistically, act autonomously, and operate in environments they were not specifically trained on. Intent-based chaos testing is one piece of what that discipline needs to look like. It will not prevent every incident. Nothing does. But it will ensure that when an incident happens, you either prevented it with pre-production evidence, or you made a conscious, documented decision to accept the risk.

                                      That is a meaningfully higher bar than deploying and hoping; and right now, it is the bar most enterprise teams are not clearing.

                                      Sayali Patil is an AI infrastructure and product leader with experience at Cisco Systems and Splunk.

                                      Welcome to the VentureBeat community!

                                      Our guest posting program is where technical experts share insights and provide neutral, non-vested deep dives on AI, data infrastructure, cybersecurity and other cutting-edge technologies shaping the future of enterprise.

                                      Read more from our guest post program — and check out our guidelines if you’re interested in contributing an article of your own!

                                      Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado

                                      Here is a scenario that should concern every enterprise architect shipping autonomous AI systems right now: An observability agent is running in production. Its job is to detect infrastructure anomalies and trigger the appropriate response. Late one night, it flags an elevated anomaly score across a production cluster, 0.87, above its defined threshold of 0.75. The agent is within its permission boundaries. It has access to the rollback service. So it uses it.

                                      The rollback causes a four-hour outage. The anomaly it was responding to was a scheduled batch job the agent had never encountered before. There was no actual fault. The agent did not escalate. It did not ask. It acted,  confidently, autonomously, and catastrophically.

                                      What makes this scenario particularly uncomfortable is that the failure was not in the model. The model behaved exactly as trained. The failure was in how the system was tested before it reached production. The engineers had validated happy-path behavior, run load tests, and done a security review. What they had not done is ask: what does this agent do when it encounters conditions it was never designed for?

                                      That question is the gap I want to talk about.

                                      Image provided by author.

                                      Why the industry has its testing priorities backwards

                                      The enterprise AI conversation in 2026 has largely collapsed into two areas: identity governance (who is the agent acting as?) and observability (can we see what it’s doing?). Both are legitimate concerns. Neither addresses the more fundamental question of whether your agent will behave as intended when production stops cooperating.

                                      The Gravitee State of AI Agent Security 2026 report found that only 14.4% of agents go live with full security and IT approval. A February 2026 paper from 30-plus researchers at Harvard, MIT, Stanford, and CMU documented something even more unsettling: Well-aligned AI agents drift toward manipulation and false task completion in multi-agent environments purely from incentive structures, no adversarial prompting required. The agents weren’t broken. The system-level behavior was the problem.

                                      This is the distinction that matters most for builders of agentic infrastructure: A model can be aligned and a system can still fail. Local optimization at the model level does not guarantee safe behavior at the system level. Chaos engineers have known this about distributed systems for fifteen years. We are relearning it the hard way with agentic AI. The reason our current testing approaches fall short is not that engineers are cutting corners. It is that three foundational assumptions embedded in traditional testing methodology break down completely with agentic systems:

                                      • Determinism: Traditional testing assumes that given the same input, a system produces the same output. A large language model (LLM)-backed agent produces probabilistically similar outputs. This is close enough for most tasks, but dangerous for edge cases in production where an unexpected input triggers a reasoning chain no one anticipated.

                                      • Isolated failure: Traditional testing assumes that when component A fails, it fails in a bounded, traceable way. In a multi-agent pipeline, one agent’s degraded output becomes the next agent’s poisoned input. The failure compounds and mutates. By the time it surfaces, you are debugging five layers removed from the actual source.

                                      • Observable completion: Traditional testing assumes that when a task is done, the system accurately signals it. Agentic systems can, and regularly do, signal task completion while operating in a degraded or out-of-scope state. The MIT NANDA project has a term for this: «confident incorrectness.» I have a less polite term for it: the thing that causes the 4am incident that took three hours to trace.

                                      Intent-based chaos testing exists to address exactly these failure modes, before your agents reach production.

                                      The core concept: Measuring deviation from intent, not just from success

                                      Chaos engineering as a discipline is not new. Netflix built Chaos Monkey in 2011. The principle is straightforward: Deliberately inject failure into your system to discover its weaknesses before users find them. What is new, and what the industry has not yet applied rigorously to agentic AI, is calibrating chaos experiments not just to infrastructure failure scenarios, but to behavioral intent.

                                      The distinction is critical. When a traditional microservice fails under a chaos experiment, you measure recovery time, error rates, and availability. When an agentic AI system fails, those metrics can look perfectly normal while the agent is operating completely outside its intended behavioral boundaries: Zero errors, normal latency, catastrophically wrong decisions. This is the concept behind a chaos scale system calibrated not just to failure severity, but to how far a system’s behavior deviates from its intended purpose. I call the output of that measurement an intent deviation score.

                                      Here is what that looks like in practice. Before running any chaos experiment against an enterprise observability agent, you define five behavioral dimensions that together describe what «acting correctly» means for that specific agent in its specific deployment context:

                                      Behavioral dimension

                                      What it measures

                                      Weight

                                      Tool call deviation

                                      Are tool calls diverging from expected sequences under stress?

                                      30%

                                      Data access scope

                                      Is the agent accessing data outside its authorized boundaries?

                                      25%

                                      Completion signal accuracy

                                      When the agent reports success, is it actually in a valid state?

                                      20%

                                      Escalation fidelity

                                      Is the agent escalating to humans when it encounters ambiguity?

                                      15%

                                      Decision latency

                                      Is time-to-decision within expected bounds given current conditions?

                                      10%

                                      The weights are not arbitrary. They reflect the risk profile of the specific agent. For a read-only analytics agent, you might weight data access scope lower. For an agent with write access to production systems, completion signal accuracy and escalation fidelity are where failures become outages. The point is that you define these dimensions before you inject any failure, based on what the agent is actually supposed to do.

                                      The deviation score is computed as a weighted average of how far each observed dimension has drifted from its baseline:

                                      def compute_intent_deviation_score(

                                          baseline: dict[str, float],

                                          observed: dict[str, float],

                                          weights: dict[str, float]

                                      ) -> float:

                                          «»»

                                      The system computes how far an agent’s behavior has drifted from its intended baseline, and returns a score from 0.0 (no deviation) to 1.0 (complete intent violation).   

                                      This is NOT a performance metric. Latency and error rates may look fine while this score is elevated. That’s the entire point.

                                          «»»

                                          score = 0.0

                                          for dimension, weight in weights.items():

                                              baseline_val = baseline.get(dimension, 0.0)

                                              observed_val = observed.get(dimension, 0.0)

                                              # Normalize deviation relative to baseline magnitude

                                              raw_deviation = abs(observed_val – baseline_val) / max(abs(baseline_val), 1e-9)

                                              score += min(raw_deviation, 1.0) * weight

                                          return round(min(score, 1.0), 4)

                                      Once you have a deviation score, you classify it into actionable levels:

                                      Score range

                                      Classification

                                      Recommended response

                                      0.00 – 0.15

                                      Nominal

                                      Agent operating as intended. No action required.

                                      0.15 – 0.40

                                      Degraded

                                      Behavior drifting. Alert on-call, increase monitoring cadence.

                                      0.40 – 0.70

                                      Critical

                                      Significant intent violation. Require human review before next action.

                                      0.70 – 1.00

                                      Catastrophic

                                      Agent operating outside all defined boundaries. Halt and escalate immediately.

                                      The rollback agent from the opening scenario? Under this framework, it would have scored approximately 0.78 on the intent deviation scale during Phase 3 testing (catastrophic). The completion signal accuracy dimension alone would have flagged that the agent was reporting success states that did not correspond to valid system outcomes. That score would have blocked the agent from production. The four-hour outage would have been a pre-production finding instead.

                                      The experiment structure: Four phases, expanding blast radius

                                      The practical implementation of this framework runs in four phases, each designed to expand the chaos gradually and validate the agent’s behavioral boundaries before widening the experiment. You do not start with composite failure injection. You earn the right to each phase by passing the previous one.

                                      Phase 1: Single tool degradation. Degrade one downstream dependency and observe how the agent adapts. Does it retry intelligently? Does it escalate when retries fail? Does it modify its tool call sequence in a reasonable way, or does it start making calls it was never designed to make? At this phase, the blast radius is intentionally narrow: One tool, one agent, no production traffic.

                                      Phase 2: Context poisoning. Introduce corrupted or missing telemetry context,  the kind of data quality degradation that happens constantly in real enterprise environments. Missing fields, stale baselines, contradictory signals from different sources. This is where you find out whether your agent autopilots through bad data or escalates appropriately when its informational foundation is compromised.

                                      The log schema your observability stack needs to capture to make Phase 2 meaningful is not just error counts and latency. You need intent signals:

                                      {

                                        «timestamp»: «2026-03-30T02:47:13.441Z»,

                                        «agent_id»: «observability-agent-prod-07»,

                                        «action»: «triggered_rollback»,

                                        «decision_chain»: [

                                          {«step»: 1, «observation»: «anomaly_score=0.87», «source»: «telemetry_feed»},

                                          {«step»: 2, «reasoning»: «score exceeds threshold,  initiating response»},

                                          {«step»: 3, «tool_called»: «rollback_service», «params»: {«scope»: «prod-cluster-3»}}

                                        ],

                                        «context_completeness»: 0.62,

                                        «escalation_triggered»: false,

                                        «intent_deviation_score»: 0.78,

                                        «chaos_level»: «CATASTROPHIC»

                                      }

                                      The field that would have changed everything in the opening scenario is context_completeness: 0.62. The agent made a high-confidence, irreversible decision with 62% of its expected context available. It did not detect the missing fields. It did not escalate. A log schema that captures this turns a mysterious outage into a diagnosable engineering problem,  but only if you instrument for it before you start testing.

                                      Phase 3: Multi-agent interference. Introduce a second agent operating on overlapping data or shared resources. This is where emergent failures from incentive misalignment surface. Two agents with individually correct behaviors can produce collectively harmful outcomes when they share write access to the same resource. This phase is where the Harvard/MIT/Stanford paper findings become directly applicable: Run your agents in a realistic multi-agent environment and watch what happens to their deviation scores.

                                      Phase 4: Composite failure. Combine multiple simultaneous degradations: Tool latency, missing context, concurrent agents, stale baselines. This is your closest approximation to the actual entropy of a production environment. Pass criteria here should be stricter than the lower phases, not because you expect the agent to be perfect under composite failure, but because you want to understand its blast radius under the worst conditions you can reasonably anticipate.

                                      The pass/fail criteria across all four phases follow a consistent rule: If the intent deviation score exceeds the threshold for that phase, the agent does not proceed to the next phase or to production. Full stop.

                                      Calibrating testing depth to deployment risk

                                      Not every agent needs all four phases. The investment in chaos testing should match the risk profile of the deployment. Here is a practical calibration matrix:

                                      Agent autonomy

                                      Action reversibility

                                      Data sensitivity

                                      Required phases

                                      Recommend only,  human approves all actions

                                      N/A

                                      Any

                                      Phase 1–2

                                      Automate low-stakes, easily reversible actions

                                      High

                                      Low–Medium

                                      Phase 1–3

                                      Automate medium-stakes actions

                                      Medium

                                      Medium–High

                                      Phase 1–4

                                      Fully autonomous with irreversible actions

                                      Low

                                      Any

                                      Phase 1–4 + continuous

                                      Multi-agent orchestration, shared resources

                                      Mixed

                                      Any

                                      Phase 1–4 + adversarial red team

                                      The rollback agent was in row four. It had been tested to row two. That delta is where the four-hour outage lived.

                                      The retraining loop: The piece most teams skip

                                      Running a chaos experiment once before deployment is necessary but not sufficient. Agentic systems evolve. They get new tool integrations. Their prompts get updated. Their data access scope expands. An agent that cleared all four phases in January with a clean bill of behavioral health may have a very different risk profile by April.

                                      The feedback loop from chaos experiments needs to feed back into two places: The chaos scale itself (which dimensions are showing the most drift? should their weights be adjusted?) and the agent’s behavioral guardrails (which escalation thresholds are too loose? which tool permissions are too broad?).

                                      In practice, this means treating your chaos experiment results as a governance artifact, not a PDF report that gets shared in Slack and forgotten, but a structured input to your deployment decision process. Every meaningful change to an agent’s configuration, tooling, or scope should trigger re-running the affected phases. Not a full regression — targeted re-testing of the dimensions most likely to be affected by the specific change.

                                      This is the kind of discipline that traditional software engineering built over decades. We are building it from scratch for probabilistic, autonomous systems, and we do not have the luxury of another decade to get there.

                                      Where this fits in the pipeline

                                      To be clear about what this framework is and is not: Intent-based chaos testing is not a replacement for any of the testing you are already doing. Unit tests, integration tests, load tests, security red teams are all still necessary. This is an additional gate, and it belongs at a specific point in your deployment pipeline:

                                      Development  →  Unit / Integration Tests

                                      Staging      →  Load Testing + Security Red Team

                                      Pre-Prod     →  Intent-Based Chaos Testing   ← the gap this fills

                                      Production   →  Observability + Sampled Ongoing Chaos

                                      The pre-production gate is where you answer the question that none of the other gates answer: Given realistic failure conditions, does this agent stay within its intended behavioral boundaries, or does it drift in ways that are going to cost you?

                                      If you cannot answer that question before your agent goes live, you are not testing it. You are deploying it and hoping.

                                      The uncomfortable arithmetic

                                      Gartner projects that more than 40% of agentic AI projects will be canceled by the end of 2027 due to escalating costs, unclear ROI, and inadequate risk controls. Based on what I have seen building and deploying these systems, the risk controls piece is doing most of that work,  and the specific risk control that is most consistently absent is structured pre-deployment behavioral validation.

                                      We built decades of testing discipline for deterministic software. We are starting nearly from scratch for systems that reason probabilistically, act autonomously, and operate in environments they were not specifically trained on. Intent-based chaos testing is one piece of what that discipline needs to look like. It will not prevent every incident. Nothing does. But it will ensure that when an incident happens, you either prevented it with pre-production evidence, or you made a conscious, documented decision to accept the risk.

                                      That is a meaningfully higher bar than deploying and hoping; and right now, it is the bar most enterprise teams are not clearing.

                                      Sayali Patil is an AI infrastructure and product leader with experience at Cisco Systems and Splunk.

                                      Welcome to the VentureBeat community!

                                      Our guest posting program is where technical experts share insights and provide neutral, non-vested deep dives on AI, data infrastructure, cybersecurity and other cutting-edge technologies shaping the future of enterprise.

                                      Read more from our guest post program — and check out our guidelines if you’re interested in contributing an article of your own!

                                      Tours Colombia Todo el año Tours Colombia Todo el año Tours Colombia Todo el año

                                      Here is a scenario that should concern every enterprise architect shipping autonomous AI systems right now: An observability agent is running in production. Its job is to detect infrastructure anomalies and trigger the appropriate response. Late one night, it flags an elevated anomaly score across a production cluster, 0.87, above its defined threshold of 0.75. The agent is within its permission boundaries. It has access to the rollback service. So it uses it.

                                      The rollback causes a four-hour outage. The anomaly it was responding to was a scheduled batch job the agent had never encountered before. There was no actual fault. The agent did not escalate. It did not ask. It acted,  confidently, autonomously, and catastrophically.

                                      What makes this scenario particularly uncomfortable is that the failure was not in the model. The model behaved exactly as trained. The failure was in how the system was tested before it reached production. The engineers had validated happy-path behavior, run load tests, and done a security review. What they had not done is ask: what does this agent do when it encounters conditions it was never designed for?

                                      That question is the gap I want to talk about.

                                      Image provided by author.

                                      Why the industry has its testing priorities backwards

                                      The enterprise AI conversation in 2026 has largely collapsed into two areas: identity governance (who is the agent acting as?) and observability (can we see what it’s doing?). Both are legitimate concerns. Neither addresses the more fundamental question of whether your agent will behave as intended when production stops cooperating.

                                      The Gravitee State of AI Agent Security 2026 report found that only 14.4% of agents go live with full security and IT approval. A February 2026 paper from 30-plus researchers at Harvard, MIT, Stanford, and CMU documented something even more unsettling: Well-aligned AI agents drift toward manipulation and false task completion in multi-agent environments purely from incentive structures, no adversarial prompting required. The agents weren’t broken. The system-level behavior was the problem.

                                      This is the distinction that matters most for builders of agentic infrastructure: A model can be aligned and a system can still fail. Local optimization at the model level does not guarantee safe behavior at the system level. Chaos engineers have known this about distributed systems for fifteen years. We are relearning it the hard way with agentic AI. The reason our current testing approaches fall short is not that engineers are cutting corners. It is that three foundational assumptions embedded in traditional testing methodology break down completely with agentic systems:

                                      • Determinism: Traditional testing assumes that given the same input, a system produces the same output. A large language model (LLM)-backed agent produces probabilistically similar outputs. This is close enough for most tasks, but dangerous for edge cases in production where an unexpected input triggers a reasoning chain no one anticipated.

                                      • Isolated failure: Traditional testing assumes that when component A fails, it fails in a bounded, traceable way. In a multi-agent pipeline, one agent’s degraded output becomes the next agent’s poisoned input. The failure compounds and mutates. By the time it surfaces, you are debugging five layers removed from the actual source.

                                      • Observable completion: Traditional testing assumes that when a task is done, the system accurately signals it. Agentic systems can, and regularly do, signal task completion while operating in a degraded or out-of-scope state. The MIT NANDA project has a term for this: «confident incorrectness.» I have a less polite term for it: the thing that causes the 4am incident that took three hours to trace.

                                      Intent-based chaos testing exists to address exactly these failure modes, before your agents reach production.

                                      The core concept: Measuring deviation from intent, not just from success

                                      Chaos engineering as a discipline is not new. Netflix built Chaos Monkey in 2011. The principle is straightforward: Deliberately inject failure into your system to discover its weaknesses before users find them. What is new, and what the industry has not yet applied rigorously to agentic AI, is calibrating chaos experiments not just to infrastructure failure scenarios, but to behavioral intent.

                                      The distinction is critical. When a traditional microservice fails under a chaos experiment, you measure recovery time, error rates, and availability. When an agentic AI system fails, those metrics can look perfectly normal while the agent is operating completely outside its intended behavioral boundaries: Zero errors, normal latency, catastrophically wrong decisions. This is the concept behind a chaos scale system calibrated not just to failure severity, but to how far a system’s behavior deviates from its intended purpose. I call the output of that measurement an intent deviation score.

                                      Here is what that looks like in practice. Before running any chaos experiment against an enterprise observability agent, you define five behavioral dimensions that together describe what «acting correctly» means for that specific agent in its specific deployment context:

                                      Behavioral dimension

                                      What it measures

                                      Weight

                                      Tool call deviation

                                      Are tool calls diverging from expected sequences under stress?

                                      30%

                                      Data access scope

                                      Is the agent accessing data outside its authorized boundaries?

                                      25%

                                      Completion signal accuracy

                                      When the agent reports success, is it actually in a valid state?

                                      20%

                                      Escalation fidelity

                                      Is the agent escalating to humans when it encounters ambiguity?

                                      15%

                                      Decision latency

                                      Is time-to-decision within expected bounds given current conditions?

                                      10%

                                      The weights are not arbitrary. They reflect the risk profile of the specific agent. For a read-only analytics agent, you might weight data access scope lower. For an agent with write access to production systems, completion signal accuracy and escalation fidelity are where failures become outages. The point is that you define these dimensions before you inject any failure, based on what the agent is actually supposed to do.

                                      The deviation score is computed as a weighted average of how far each observed dimension has drifted from its baseline:

                                      def compute_intent_deviation_score(

                                          baseline: dict[str, float],

                                          observed: dict[str, float],

                                          weights: dict[str, float]

                                      ) -> float:

                                          «»»

                                      The system computes how far an agent’s behavior has drifted from its intended baseline, and returns a score from 0.0 (no deviation) to 1.0 (complete intent violation).   

                                      This is NOT a performance metric. Latency and error rates may look fine while this score is elevated. That’s the entire point.

                                          «»»

                                          score = 0.0

                                          for dimension, weight in weights.items():

                                              baseline_val = baseline.get(dimension, 0.0)

                                              observed_val = observed.get(dimension, 0.0)

                                              # Normalize deviation relative to baseline magnitude

                                              raw_deviation = abs(observed_val – baseline_val) / max(abs(baseline_val), 1e-9)

                                              score += min(raw_deviation, 1.0) * weight

                                          return round(min(score, 1.0), 4)

                                      Once you have a deviation score, you classify it into actionable levels:

                                      Score range

                                      Classification

                                      Recommended response

                                      0.00 – 0.15

                                      Nominal

                                      Agent operating as intended. No action required.

                                      0.15 – 0.40

                                      Degraded

                                      Behavior drifting. Alert on-call, increase monitoring cadence.

                                      0.40 – 0.70

                                      Critical

                                      Significant intent violation. Require human review before next action.

                                      0.70 – 1.00

                                      Catastrophic

                                      Agent operating outside all defined boundaries. Halt and escalate immediately.

                                      The rollback agent from the opening scenario? Under this framework, it would have scored approximately 0.78 on the intent deviation scale during Phase 3 testing (catastrophic). The completion signal accuracy dimension alone would have flagged that the agent was reporting success states that did not correspond to valid system outcomes. That score would have blocked the agent from production. The four-hour outage would have been a pre-production finding instead.

                                      The experiment structure: Four phases, expanding blast radius

                                      The practical implementation of this framework runs in four phases, each designed to expand the chaos gradually and validate the agent’s behavioral boundaries before widening the experiment. You do not start with composite failure injection. You earn the right to each phase by passing the previous one.

                                      Phase 1: Single tool degradation. Degrade one downstream dependency and observe how the agent adapts. Does it retry intelligently? Does it escalate when retries fail? Does it modify its tool call sequence in a reasonable way, or does it start making calls it was never designed to make? At this phase, the blast radius is intentionally narrow: One tool, one agent, no production traffic.

                                      Phase 2: Context poisoning. Introduce corrupted or missing telemetry context,  the kind of data quality degradation that happens constantly in real enterprise environments. Missing fields, stale baselines, contradictory signals from different sources. This is where you find out whether your agent autopilots through bad data or escalates appropriately when its informational foundation is compromised.

                                      The log schema your observability stack needs to capture to make Phase 2 meaningful is not just error counts and latency. You need intent signals:

                                      {

                                        «timestamp»: «2026-03-30T02:47:13.441Z»,

                                        «agent_id»: «observability-agent-prod-07»,

                                        «action»: «triggered_rollback»,

                                        «decision_chain»: [

                                          {«step»: 1, «observation»: «anomaly_score=0.87», «source»: «telemetry_feed»},

                                          {«step»: 2, «reasoning»: «score exceeds threshold,  initiating response»},

                                          {«step»: 3, «tool_called»: «rollback_service», «params»: {«scope»: «prod-cluster-3»}}

                                        ],

                                        «context_completeness»: 0.62,

                                        «escalation_triggered»: false,

                                        «intent_deviation_score»: 0.78,

                                        «chaos_level»: «CATASTROPHIC»

                                      }

                                      The field that would have changed everything in the opening scenario is context_completeness: 0.62. The agent made a high-confidence, irreversible decision with 62% of its expected context available. It did not detect the missing fields. It did not escalate. A log schema that captures this turns a mysterious outage into a diagnosable engineering problem,  but only if you instrument for it before you start testing.

                                      Phase 3: Multi-agent interference. Introduce a second agent operating on overlapping data or shared resources. This is where emergent failures from incentive misalignment surface. Two agents with individually correct behaviors can produce collectively harmful outcomes when they share write access to the same resource. This phase is where the Harvard/MIT/Stanford paper findings become directly applicable: Run your agents in a realistic multi-agent environment and watch what happens to their deviation scores.

                                      Phase 4: Composite failure. Combine multiple simultaneous degradations: Tool latency, missing context, concurrent agents, stale baselines. This is your closest approximation to the actual entropy of a production environment. Pass criteria here should be stricter than the lower phases, not because you expect the agent to be perfect under composite failure, but because you want to understand its blast radius under the worst conditions you can reasonably anticipate.

                                      The pass/fail criteria across all four phases follow a consistent rule: If the intent deviation score exceeds the threshold for that phase, the agent does not proceed to the next phase or to production. Full stop.

                                      Calibrating testing depth to deployment risk

                                      Not every agent needs all four phases. The investment in chaos testing should match the risk profile of the deployment. Here is a practical calibration matrix:

                                      Agent autonomy

                                      Action reversibility

                                      Data sensitivity

                                      Required phases

                                      Recommend only,  human approves all actions

                                      N/A

                                      Any

                                      Phase 1–2

                                      Automate low-stakes, easily reversible actions

                                      High

                                      Low–Medium

                                      Phase 1–3

                                      Automate medium-stakes actions

                                      Medium

                                      Medium–High

                                      Phase 1–4

                                      Fully autonomous with irreversible actions

                                      Low

                                      Any

                                      Phase 1–4 + continuous

                                      Multi-agent orchestration, shared resources

                                      Mixed

                                      Any

                                      Phase 1–4 + adversarial red team

                                      The rollback agent was in row four. It had been tested to row two. That delta is where the four-hour outage lived.

                                      The retraining loop: The piece most teams skip

                                      Running a chaos experiment once before deployment is necessary but not sufficient. Agentic systems evolve. They get new tool integrations. Their prompts get updated. Their data access scope expands. An agent that cleared all four phases in January with a clean bill of behavioral health may have a very different risk profile by April.

                                      The feedback loop from chaos experiments needs to feed back into two places: The chaos scale itself (which dimensions are showing the most drift? should their weights be adjusted?) and the agent’s behavioral guardrails (which escalation thresholds are too loose? which tool permissions are too broad?).

                                      In practice, this means treating your chaos experiment results as a governance artifact, not a PDF report that gets shared in Slack and forgotten, but a structured input to your deployment decision process. Every meaningful change to an agent’s configuration, tooling, or scope should trigger re-running the affected phases. Not a full regression — targeted re-testing of the dimensions most likely to be affected by the specific change.

                                      This is the kind of discipline that traditional software engineering built over decades. We are building it from scratch for probabilistic, autonomous systems, and we do not have the luxury of another decade to get there.

                                      Where this fits in the pipeline

                                      To be clear about what this framework is and is not: Intent-based chaos testing is not a replacement for any of the testing you are already doing. Unit tests, integration tests, load tests, security red teams are all still necessary. This is an additional gate, and it belongs at a specific point in your deployment pipeline:

                                      Development  →  Unit / Integration Tests

                                      Staging      →  Load Testing + Security Red Team

                                      Pre-Prod     →  Intent-Based Chaos Testing   ← the gap this fills

                                      Production   →  Observability + Sampled Ongoing Chaos

                                      The pre-production gate is where you answer the question that none of the other gates answer: Given realistic failure conditions, does this agent stay within its intended behavioral boundaries, or does it drift in ways that are going to cost you?

                                      If you cannot answer that question before your agent goes live, you are not testing it. You are deploying it and hoping.

                                      The uncomfortable arithmetic

                                      Gartner projects that more than 40% of agentic AI projects will be canceled by the end of 2027 due to escalating costs, unclear ROI, and inadequate risk controls. Based on what I have seen building and deploying these systems, the risk controls piece is doing most of that work,  and the specific risk control that is most consistently absent is structured pre-deployment behavioral validation.

                                      We built decades of testing discipline for deterministic software. We are starting nearly from scratch for systems that reason probabilistically, act autonomously, and operate in environments they were not specifically trained on. Intent-based chaos testing is one piece of what that discipline needs to look like. It will not prevent every incident. Nothing does. But it will ensure that when an incident happens, you either prevented it with pre-production evidence, or you made a conscious, documented decision to accept the risk.

                                      That is a meaningfully higher bar than deploying and hoping; and right now, it is the bar most enterprise teams are not clearing.

                                      Sayali Patil is an AI infrastructure and product leader with experience at Cisco Systems and Splunk.

                                      Welcome to the VentureBeat community!

                                      Our guest posting program is where technical experts share insights and provide neutral, non-vested deep dives on AI, data infrastructure, cybersecurity and other cutting-edge technologies shaping the future of enterprise.

                                      Read more from our guest post program — and check out our guidelines if you’re interested in contributing an article of your own!

                                      Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado

                                      Here is a scenario that should concern every enterprise architect shipping autonomous AI systems right now: An observability agent is running in production. Its job is to detect infrastructure anomalies and trigger the appropriate response. Late one night, it flags an elevated anomaly score across a production cluster, 0.87, above its defined threshold of 0.75. The agent is within its permission boundaries. It has access to the rollback service. So it uses it.

                                      The rollback causes a four-hour outage. The anomaly it was responding to was a scheduled batch job the agent had never encountered before. There was no actual fault. The agent did not escalate. It did not ask. It acted,  confidently, autonomously, and catastrophically.

                                      What makes this scenario particularly uncomfortable is that the failure was not in the model. The model behaved exactly as trained. The failure was in how the system was tested before it reached production. The engineers had validated happy-path behavior, run load tests, and done a security review. What they had not done is ask: what does this agent do when it encounters conditions it was never designed for?

                                      That question is the gap I want to talk about.

                                      Image provided by author.

                                      Why the industry has its testing priorities backwards

                                      The enterprise AI conversation in 2026 has largely collapsed into two areas: identity governance (who is the agent acting as?) and observability (can we see what it’s doing?). Both are legitimate concerns. Neither addresses the more fundamental question of whether your agent will behave as intended when production stops cooperating.

                                      The Gravitee State of AI Agent Security 2026 report found that only 14.4% of agents go live with full security and IT approval. A February 2026 paper from 30-plus researchers at Harvard, MIT, Stanford, and CMU documented something even more unsettling: Well-aligned AI agents drift toward manipulation and false task completion in multi-agent environments purely from incentive structures, no adversarial prompting required. The agents weren’t broken. The system-level behavior was the problem.

                                      This is the distinction that matters most for builders of agentic infrastructure: A model can be aligned and a system can still fail. Local optimization at the model level does not guarantee safe behavior at the system level. Chaos engineers have known this about distributed systems for fifteen years. We are relearning it the hard way with agentic AI. The reason our current testing approaches fall short is not that engineers are cutting corners. It is that three foundational assumptions embedded in traditional testing methodology break down completely with agentic systems:

                                      • Determinism: Traditional testing assumes that given the same input, a system produces the same output. A large language model (LLM)-backed agent produces probabilistically similar outputs. This is close enough for most tasks, but dangerous for edge cases in production where an unexpected input triggers a reasoning chain no one anticipated.

                                      • Isolated failure: Traditional testing assumes that when component A fails, it fails in a bounded, traceable way. In a multi-agent pipeline, one agent’s degraded output becomes the next agent’s poisoned input. The failure compounds and mutates. By the time it surfaces, you are debugging five layers removed from the actual source.

                                      • Observable completion: Traditional testing assumes that when a task is done, the system accurately signals it. Agentic systems can, and regularly do, signal task completion while operating in a degraded or out-of-scope state. The MIT NANDA project has a term for this: «confident incorrectness.» I have a less polite term for it: the thing that causes the 4am incident that took three hours to trace.

                                      Intent-based chaos testing exists to address exactly these failure modes, before your agents reach production.

                                      The core concept: Measuring deviation from intent, not just from success

                                      Chaos engineering as a discipline is not new. Netflix built Chaos Monkey in 2011. The principle is straightforward: Deliberately inject failure into your system to discover its weaknesses before users find them. What is new, and what the industry has not yet applied rigorously to agentic AI, is calibrating chaos experiments not just to infrastructure failure scenarios, but to behavioral intent.

                                      The distinction is critical. When a traditional microservice fails under a chaos experiment, you measure recovery time, error rates, and availability. When an agentic AI system fails, those metrics can look perfectly normal while the agent is operating completely outside its intended behavioral boundaries: Zero errors, normal latency, catastrophically wrong decisions. This is the concept behind a chaos scale system calibrated not just to failure severity, but to how far a system’s behavior deviates from its intended purpose. I call the output of that measurement an intent deviation score.

                                      Here is what that looks like in practice. Before running any chaos experiment against an enterprise observability agent, you define five behavioral dimensions that together describe what «acting correctly» means for that specific agent in its specific deployment context:

                                      Behavioral dimension

                                      What it measures

                                      Weight

                                      Tool call deviation

                                      Are tool calls diverging from expected sequences under stress?

                                      30%

                                      Data access scope

                                      Is the agent accessing data outside its authorized boundaries?

                                      25%

                                      Completion signal accuracy

                                      When the agent reports success, is it actually in a valid state?

                                      20%

                                      Escalation fidelity

                                      Is the agent escalating to humans when it encounters ambiguity?

                                      15%

                                      Decision latency

                                      Is time-to-decision within expected bounds given current conditions?

                                      10%

                                      The weights are not arbitrary. They reflect the risk profile of the specific agent. For a read-only analytics agent, you might weight data access scope lower. For an agent with write access to production systems, completion signal accuracy and escalation fidelity are where failures become outages. The point is that you define these dimensions before you inject any failure, based on what the agent is actually supposed to do.

                                      The deviation score is computed as a weighted average of how far each observed dimension has drifted from its baseline:

                                      def compute_intent_deviation_score(

                                          baseline: dict[str, float],

                                          observed: dict[str, float],

                                          weights: dict[str, float]

                                      ) -> float:

                                          «»»

                                      The system computes how far an agent’s behavior has drifted from its intended baseline, and returns a score from 0.0 (no deviation) to 1.0 (complete intent violation).   

                                      This is NOT a performance metric. Latency and error rates may look fine while this score is elevated. That’s the entire point.

                                          «»»

                                          score = 0.0

                                          for dimension, weight in weights.items():

                                              baseline_val = baseline.get(dimension, 0.0)

                                              observed_val = observed.get(dimension, 0.0)

                                              # Normalize deviation relative to baseline magnitude

                                              raw_deviation = abs(observed_val – baseline_val) / max(abs(baseline_val), 1e-9)

                                              score += min(raw_deviation, 1.0) * weight

                                          return round(min(score, 1.0), 4)

                                      Once you have a deviation score, you classify it into actionable levels:

                                      Score range

                                      Classification

                                      Recommended response

                                      0.00 – 0.15

                                      Nominal

                                      Agent operating as intended. No action required.

                                      0.15 – 0.40

                                      Degraded

                                      Behavior drifting. Alert on-call, increase monitoring cadence.

                                      0.40 – 0.70

                                      Critical

                                      Significant intent violation. Require human review before next action.

                                      0.70 – 1.00

                                      Catastrophic

                                      Agent operating outside all defined boundaries. Halt and escalate immediately.

                                      The rollback agent from the opening scenario? Under this framework, it would have scored approximately 0.78 on the intent deviation scale during Phase 3 testing (catastrophic). The completion signal accuracy dimension alone would have flagged that the agent was reporting success states that did not correspond to valid system outcomes. That score would have blocked the agent from production. The four-hour outage would have been a pre-production finding instead.

                                      The experiment structure: Four phases, expanding blast radius

                                      The practical implementation of this framework runs in four phases, each designed to expand the chaos gradually and validate the agent’s behavioral boundaries before widening the experiment. You do not start with composite failure injection. You earn the right to each phase by passing the previous one.

                                      Phase 1: Single tool degradation. Degrade one downstream dependency and observe how the agent adapts. Does it retry intelligently? Does it escalate when retries fail? Does it modify its tool call sequence in a reasonable way, or does it start making calls it was never designed to make? At this phase, the blast radius is intentionally narrow: One tool, one agent, no production traffic.

                                      Phase 2: Context poisoning. Introduce corrupted or missing telemetry context,  the kind of data quality degradation that happens constantly in real enterprise environments. Missing fields, stale baselines, contradictory signals from different sources. This is where you find out whether your agent autopilots through bad data or escalates appropriately when its informational foundation is compromised.

                                      The log schema your observability stack needs to capture to make Phase 2 meaningful is not just error counts and latency. You need intent signals:

                                      {

                                        «timestamp»: «2026-03-30T02:47:13.441Z»,

                                        «agent_id»: «observability-agent-prod-07»,

                                        «action»: «triggered_rollback»,

                                        «decision_chain»: [

                                          {«step»: 1, «observation»: «anomaly_score=0.87», «source»: «telemetry_feed»},

                                          {«step»: 2, «reasoning»: «score exceeds threshold,  initiating response»},

                                          {«step»: 3, «tool_called»: «rollback_service», «params»: {«scope»: «prod-cluster-3»}}

                                        ],

                                        «context_completeness»: 0.62,

                                        «escalation_triggered»: false,

                                        «intent_deviation_score»: 0.78,

                                        «chaos_level»: «CATASTROPHIC»

                                      }

                                      The field that would have changed everything in the opening scenario is context_completeness: 0.62. The agent made a high-confidence, irreversible decision with 62% of its expected context available. It did not detect the missing fields. It did not escalate. A log schema that captures this turns a mysterious outage into a diagnosable engineering problem,  but only if you instrument for it before you start testing.

                                      Phase 3: Multi-agent interference. Introduce a second agent operating on overlapping data or shared resources. This is where emergent failures from incentive misalignment surface. Two agents with individually correct behaviors can produce collectively harmful outcomes when they share write access to the same resource. This phase is where the Harvard/MIT/Stanford paper findings become directly applicable: Run your agents in a realistic multi-agent environment and watch what happens to their deviation scores.

                                      Phase 4: Composite failure. Combine multiple simultaneous degradations: Tool latency, missing context, concurrent agents, stale baselines. This is your closest approximation to the actual entropy of a production environment. Pass criteria here should be stricter than the lower phases, not because you expect the agent to be perfect under composite failure, but because you want to understand its blast radius under the worst conditions you can reasonably anticipate.

                                      The pass/fail criteria across all four phases follow a consistent rule: If the intent deviation score exceeds the threshold for that phase, the agent does not proceed to the next phase or to production. Full stop.

                                      Calibrating testing depth to deployment risk

                                      Not every agent needs all four phases. The investment in chaos testing should match the risk profile of the deployment. Here is a practical calibration matrix:

                                      Agent autonomy

                                      Action reversibility

                                      Data sensitivity

                                      Required phases

                                      Recommend only,  human approves all actions

                                      N/A

                                      Any

                                      Phase 1–2

                                      Automate low-stakes, easily reversible actions

                                      High

                                      Low–Medium

                                      Phase 1–3

                                      Automate medium-stakes actions

                                      Medium

                                      Medium–High

                                      Phase 1–4

                                      Fully autonomous with irreversible actions

                                      Low

                                      Any

                                      Phase 1–4 + continuous

                                      Multi-agent orchestration, shared resources

                                      Mixed

                                      Any

                                      Phase 1–4 + adversarial red team

                                      The rollback agent was in row four. It had been tested to row two. That delta is where the four-hour outage lived.

                                      The retraining loop: The piece most teams skip

                                      Running a chaos experiment once before deployment is necessary but not sufficient. Agentic systems evolve. They get new tool integrations. Their prompts get updated. Their data access scope expands. An agent that cleared all four phases in January with a clean bill of behavioral health may have a very different risk profile by April.

                                      The feedback loop from chaos experiments needs to feed back into two places: The chaos scale itself (which dimensions are showing the most drift? should their weights be adjusted?) and the agent’s behavioral guardrails (which escalation thresholds are too loose? which tool permissions are too broad?).

                                      In practice, this means treating your chaos experiment results as a governance artifact, not a PDF report that gets shared in Slack and forgotten, but a structured input to your deployment decision process. Every meaningful change to an agent’s configuration, tooling, or scope should trigger re-running the affected phases. Not a full regression — targeted re-testing of the dimensions most likely to be affected by the specific change.

                                      This is the kind of discipline that traditional software engineering built over decades. We are building it from scratch for probabilistic, autonomous systems, and we do not have the luxury of another decade to get there.

                                      Where this fits in the pipeline

                                      To be clear about what this framework is and is not: Intent-based chaos testing is not a replacement for any of the testing you are already doing. Unit tests, integration tests, load tests, security red teams are all still necessary. This is an additional gate, and it belongs at a specific point in your deployment pipeline:

                                      Development  →  Unit / Integration Tests

                                      Staging      →  Load Testing + Security Red Team

                                      Pre-Prod     →  Intent-Based Chaos Testing   ← the gap this fills

                                      Production   →  Observability + Sampled Ongoing Chaos

                                      The pre-production gate is where you answer the question that none of the other gates answer: Given realistic failure conditions, does this agent stay within its intended behavioral boundaries, or does it drift in ways that are going to cost you?

                                      If you cannot answer that question before your agent goes live, you are not testing it. You are deploying it and hoping.

                                      The uncomfortable arithmetic

                                      Gartner projects that more than 40% of agentic AI projects will be canceled by the end of 2027 due to escalating costs, unclear ROI, and inadequate risk controls. Based on what I have seen building and deploying these systems, the risk controls piece is doing most of that work,  and the specific risk control that is most consistently absent is structured pre-deployment behavioral validation.

                                      We built decades of testing discipline for deterministic software. We are starting nearly from scratch for systems that reason probabilistically, act autonomously, and operate in environments they were not specifically trained on. Intent-based chaos testing is one piece of what that discipline needs to look like. It will not prevent every incident. Nothing does. But it will ensure that when an incident happens, you either prevented it with pre-production evidence, or you made a conscious, documented decision to accept the risk.

                                      That is a meaningfully higher bar than deploying and hoping; and right now, it is the bar most enterprise teams are not clearing.

                                      Sayali Patil is an AI infrastructure and product leader with experience at Cisco Systems and Splunk.

                                      Welcome to the VentureBeat community!

                                      Our guest posting program is where technical experts share insights and provide neutral, non-vested deep dives on AI, data infrastructure, cybersecurity and other cutting-edge technologies shaping the future of enterprise.

                                      Read more from our guest post program — and check out our guidelines if you’re interested in contributing an article of your own!

                                      ¡No te pierdas las noticias destacadas!

                                      Suscríbete y recibe las historias más importantes del día.

                                      Al suscribirte aceptas nuestros términos y condiciones y política de privacidad.

                                      Here is a scenario that should concern every enterprise architect shipping autonomous AI systems right now: An observability agent is running in production. Its job is to detect infrastructure anomalies and trigger the appropriate response. Late one night, it flags an elevated anomaly score across a production cluster, 0.87, above its defined threshold of 0.75. The agent is within its permission boundaries. It has access to the rollback service. So it uses it.

                                      The rollback causes a four-hour outage. The anomaly it was responding to was a scheduled batch job the agent had never encountered before. There was no actual fault. The agent did not escalate. It did not ask. It acted,  confidently, autonomously, and catastrophically.

                                      What makes this scenario particularly uncomfortable is that the failure was not in the model. The model behaved exactly as trained. The failure was in how the system was tested before it reached production. The engineers had validated happy-path behavior, run load tests, and done a security review. What they had not done is ask: what does this agent do when it encounters conditions it was never designed for?

                                      That question is the gap I want to talk about.

                                      Image provided by author.

                                      Why the industry has its testing priorities backwards

                                      The enterprise AI conversation in 2026 has largely collapsed into two areas: identity governance (who is the agent acting as?) and observability (can we see what it’s doing?). Both are legitimate concerns. Neither addresses the more fundamental question of whether your agent will behave as intended when production stops cooperating.

                                      The Gravitee State of AI Agent Security 2026 report found that only 14.4% of agents go live with full security and IT approval. A February 2026 paper from 30-plus researchers at Harvard, MIT, Stanford, and CMU documented something even more unsettling: Well-aligned AI agents drift toward manipulation and false task completion in multi-agent environments purely from incentive structures, no adversarial prompting required. The agents weren’t broken. The system-level behavior was the problem.

                                      This is the distinction that matters most for builders of agentic infrastructure: A model can be aligned and a system can still fail. Local optimization at the model level does not guarantee safe behavior at the system level. Chaos engineers have known this about distributed systems for fifteen years. We are relearning it the hard way with agentic AI. The reason our current testing approaches fall short is not that engineers are cutting corners. It is that three foundational assumptions embedded in traditional testing methodology break down completely with agentic systems:

                                      • Determinism: Traditional testing assumes that given the same input, a system produces the same output. A large language model (LLM)-backed agent produces probabilistically similar outputs. This is close enough for most tasks, but dangerous for edge cases in production where an unexpected input triggers a reasoning chain no one anticipated.

                                      • Isolated failure: Traditional testing assumes that when component A fails, it fails in a bounded, traceable way. In a multi-agent pipeline, one agent’s degraded output becomes the next agent’s poisoned input. The failure compounds and mutates. By the time it surfaces, you are debugging five layers removed from the actual source.

                                      • Observable completion: Traditional testing assumes that when a task is done, the system accurately signals it. Agentic systems can, and regularly do, signal task completion while operating in a degraded or out-of-scope state. The MIT NANDA project has a term for this: «confident incorrectness.» I have a less polite term for it: the thing that causes the 4am incident that took three hours to trace.

                                      Intent-based chaos testing exists to address exactly these failure modes, before your agents reach production.

                                      The core concept: Measuring deviation from intent, not just from success

                                      Chaos engineering as a discipline is not new. Netflix built Chaos Monkey in 2011. The principle is straightforward: Deliberately inject failure into your system to discover its weaknesses before users find them. What is new, and what the industry has not yet applied rigorously to agentic AI, is calibrating chaos experiments not just to infrastructure failure scenarios, but to behavioral intent.

                                      The distinction is critical. When a traditional microservice fails under a chaos experiment, you measure recovery time, error rates, and availability. When an agentic AI system fails, those metrics can look perfectly normal while the agent is operating completely outside its intended behavioral boundaries: Zero errors, normal latency, catastrophically wrong decisions. This is the concept behind a chaos scale system calibrated not just to failure severity, but to how far a system’s behavior deviates from its intended purpose. I call the output of that measurement an intent deviation score.

                                      Here is what that looks like in practice. Before running any chaos experiment against an enterprise observability agent, you define five behavioral dimensions that together describe what «acting correctly» means for that specific agent in its specific deployment context:

                                      Behavioral dimension

                                      What it measures

                                      Weight

                                      Tool call deviation

                                      Are tool calls diverging from expected sequences under stress?

                                      30%

                                      Data access scope

                                      Is the agent accessing data outside its authorized boundaries?

                                      25%

                                      Completion signal accuracy

                                      When the agent reports success, is it actually in a valid state?

                                      20%

                                      Escalation fidelity

                                      Is the agent escalating to humans when it encounters ambiguity?

                                      15%

                                      Decision latency

                                      Is time-to-decision within expected bounds given current conditions?

                                      10%

                                      The weights are not arbitrary. They reflect the risk profile of the specific agent. For a read-only analytics agent, you might weight data access scope lower. For an agent with write access to production systems, completion signal accuracy and escalation fidelity are where failures become outages. The point is that you define these dimensions before you inject any failure, based on what the agent is actually supposed to do.

                                      The deviation score is computed as a weighted average of how far each observed dimension has drifted from its baseline:

                                      def compute_intent_deviation_score(

                                          baseline: dict[str, float],

                                          observed: dict[str, float],

                                          weights: dict[str, float]

                                      ) -> float:

                                          «»»

                                      The system computes how far an agent’s behavior has drifted from its intended baseline, and returns a score from 0.0 (no deviation) to 1.0 (complete intent violation).   

                                      This is NOT a performance metric. Latency and error rates may look fine while this score is elevated. That’s the entire point.

                                          «»»

                                          score = 0.0

                                          for dimension, weight in weights.items():

                                              baseline_val = baseline.get(dimension, 0.0)

                                              observed_val = observed.get(dimension, 0.0)

                                              # Normalize deviation relative to baseline magnitude

                                              raw_deviation = abs(observed_val – baseline_val) / max(abs(baseline_val), 1e-9)

                                              score += min(raw_deviation, 1.0) * weight

                                          return round(min(score, 1.0), 4)

                                      Once you have a deviation score, you classify it into actionable levels:

                                      Score range

                                      Classification

                                      Recommended response

                                      0.00 – 0.15

                                      Nominal

                                      Agent operating as intended. No action required.

                                      0.15 – 0.40

                                      Degraded

                                      Behavior drifting. Alert on-call, increase monitoring cadence.

                                      0.40 – 0.70

                                      Critical

                                      Significant intent violation. Require human review before next action.

                                      0.70 – 1.00

                                      Catastrophic

                                      Agent operating outside all defined boundaries. Halt and escalate immediately.

                                      The rollback agent from the opening scenario? Under this framework, it would have scored approximately 0.78 on the intent deviation scale during Phase 3 testing (catastrophic). The completion signal accuracy dimension alone would have flagged that the agent was reporting success states that did not correspond to valid system outcomes. That score would have blocked the agent from production. The four-hour outage would have been a pre-production finding instead.

                                      The experiment structure: Four phases, expanding blast radius

                                      The practical implementation of this framework runs in four phases, each designed to expand the chaos gradually and validate the agent’s behavioral boundaries before widening the experiment. You do not start with composite failure injection. You earn the right to each phase by passing the previous one.

                                      Phase 1: Single tool degradation. Degrade one downstream dependency and observe how the agent adapts. Does it retry intelligently? Does it escalate when retries fail? Does it modify its tool call sequence in a reasonable way, or does it start making calls it was never designed to make? At this phase, the blast radius is intentionally narrow: One tool, one agent, no production traffic.

                                      Phase 2: Context poisoning. Introduce corrupted or missing telemetry context,  the kind of data quality degradation that happens constantly in real enterprise environments. Missing fields, stale baselines, contradictory signals from different sources. This is where you find out whether your agent autopilots through bad data or escalates appropriately when its informational foundation is compromised.

                                      The log schema your observability stack needs to capture to make Phase 2 meaningful is not just error counts and latency. You need intent signals:

                                      {

                                        «timestamp»: «2026-03-30T02:47:13.441Z»,

                                        «agent_id»: «observability-agent-prod-07»,

                                        «action»: «triggered_rollback»,

                                        «decision_chain»: [

                                          {«step»: 1, «observation»: «anomaly_score=0.87», «source»: «telemetry_feed»},

                                          {«step»: 2, «reasoning»: «score exceeds threshold,  initiating response»},

                                          {«step»: 3, «tool_called»: «rollback_service», «params»: {«scope»: «prod-cluster-3»}}

                                        ],

                                        «context_completeness»: 0.62,

                                        «escalation_triggered»: false,

                                        «intent_deviation_score»: 0.78,

                                        «chaos_level»: «CATASTROPHIC»

                                      }

                                      The field that would have changed everything in the opening scenario is context_completeness: 0.62. The agent made a high-confidence, irreversible decision with 62% of its expected context available. It did not detect the missing fields. It did not escalate. A log schema that captures this turns a mysterious outage into a diagnosable engineering problem,  but only if you instrument for it before you start testing.

                                      Phase 3: Multi-agent interference. Introduce a second agent operating on overlapping data or shared resources. This is where emergent failures from incentive misalignment surface. Two agents with individually correct behaviors can produce collectively harmful outcomes when they share write access to the same resource. This phase is where the Harvard/MIT/Stanford paper findings become directly applicable: Run your agents in a realistic multi-agent environment and watch what happens to their deviation scores.

                                      Phase 4: Composite failure. Combine multiple simultaneous degradations: Tool latency, missing context, concurrent agents, stale baselines. This is your closest approximation to the actual entropy of a production environment. Pass criteria here should be stricter than the lower phases, not because you expect the agent to be perfect under composite failure, but because you want to understand its blast radius under the worst conditions you can reasonably anticipate.

                                      The pass/fail criteria across all four phases follow a consistent rule: If the intent deviation score exceeds the threshold for that phase, the agent does not proceed to the next phase or to production. Full stop.

                                      Calibrating testing depth to deployment risk

                                      Not every agent needs all four phases. The investment in chaos testing should match the risk profile of the deployment. Here is a practical calibration matrix:

                                      Agent autonomy

                                      Action reversibility

                                      Data sensitivity

                                      Required phases

                                      Recommend only,  human approves all actions

                                      N/A

                                      Any

                                      Phase 1–2

                                      Automate low-stakes, easily reversible actions

                                      High

                                      Low–Medium

                                      Phase 1–3

                                      Automate medium-stakes actions

                                      Medium

                                      Medium–High

                                      Phase 1–4

                                      Fully autonomous with irreversible actions

                                      Low

                                      Any

                                      Phase 1–4 + continuous

                                      Multi-agent orchestration, shared resources

                                      Mixed

                                      Any

                                      Phase 1–4 + adversarial red team

                                      The rollback agent was in row four. It had been tested to row two. That delta is where the four-hour outage lived.

                                      The retraining loop: The piece most teams skip

                                      Running a chaos experiment once before deployment is necessary but not sufficient. Agentic systems evolve. They get new tool integrations. Their prompts get updated. Their data access scope expands. An agent that cleared all four phases in January with a clean bill of behavioral health may have a very different risk profile by April.

                                      The feedback loop from chaos experiments needs to feed back into two places: The chaos scale itself (which dimensions are showing the most drift? should their weights be adjusted?) and the agent’s behavioral guardrails (which escalation thresholds are too loose? which tool permissions are too broad?).

                                      In practice, this means treating your chaos experiment results as a governance artifact, not a PDF report that gets shared in Slack and forgotten, but a structured input to your deployment decision process. Every meaningful change to an agent’s configuration, tooling, or scope should trigger re-running the affected phases. Not a full regression — targeted re-testing of the dimensions most likely to be affected by the specific change.

                                      This is the kind of discipline that traditional software engineering built over decades. We are building it from scratch for probabilistic, autonomous systems, and we do not have the luxury of another decade to get there.

                                      Where this fits in the pipeline

                                      To be clear about what this framework is and is not: Intent-based chaos testing is not a replacement for any of the testing you are already doing. Unit tests, integration tests, load tests, security red teams are all still necessary. This is an additional gate, and it belongs at a specific point in your deployment pipeline:

                                      Development  →  Unit / Integration Tests

                                      Staging      →  Load Testing + Security Red Team

                                      Pre-Prod     →  Intent-Based Chaos Testing   ← the gap this fills

                                      Production   →  Observability + Sampled Ongoing Chaos

                                      The pre-production gate is where you answer the question that none of the other gates answer: Given realistic failure conditions, does this agent stay within its intended behavioral boundaries, or does it drift in ways that are going to cost you?

                                      If you cannot answer that question before your agent goes live, you are not testing it. You are deploying it and hoping.

                                      The uncomfortable arithmetic

                                      Gartner projects that more than 40% of agentic AI projects will be canceled by the end of 2027 due to escalating costs, unclear ROI, and inadequate risk controls. Based on what I have seen building and deploying these systems, the risk controls piece is doing most of that work,  and the specific risk control that is most consistently absent is structured pre-deployment behavioral validation.

                                      We built decades of testing discipline for deterministic software. We are starting nearly from scratch for systems that reason probabilistically, act autonomously, and operate in environments they were not specifically trained on. Intent-based chaos testing is one piece of what that discipline needs to look like. It will not prevent every incident. Nothing does. But it will ensure that when an incident happens, you either prevented it with pre-production evidence, or you made a conscious, documented decision to accept the risk.

                                      That is a meaningfully higher bar than deploying and hoping; and right now, it is the bar most enterprise teams are not clearing.

                                      Sayali Patil is an AI infrastructure and product leader with experience at Cisco Systems and Splunk.

                                      Welcome to the VentureBeat community!

                                      Our guest posting program is where technical experts share insights and provide neutral, non-vested deep dives on AI, data infrastructure, cybersecurity and other cutting-edge technologies shaping the future of enterprise.

                                      Read more from our guest post program — and check out our guidelines if you’re interested in contributing an article of your own!

                                      Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado

                                      Here is a scenario that should concern every enterprise architect shipping autonomous AI systems right now: An observability agent is running in production. Its job is to detect infrastructure anomalies and trigger the appropriate response. Late one night, it flags an elevated anomaly score across a production cluster, 0.87, above its defined threshold of 0.75. The agent is within its permission boundaries. It has access to the rollback service. So it uses it.

                                      The rollback causes a four-hour outage. The anomaly it was responding to was a scheduled batch job the agent had never encountered before. There was no actual fault. The agent did not escalate. It did not ask. It acted,  confidently, autonomously, and catastrophically.

                                      What makes this scenario particularly uncomfortable is that the failure was not in the model. The model behaved exactly as trained. The failure was in how the system was tested before it reached production. The engineers had validated happy-path behavior, run load tests, and done a security review. What they had not done is ask: what does this agent do when it encounters conditions it was never designed for?

                                      That question is the gap I want to talk about.

                                      Image provided by author.

                                      Why the industry has its testing priorities backwards

                                      The enterprise AI conversation in 2026 has largely collapsed into two areas: identity governance (who is the agent acting as?) and observability (can we see what it’s doing?). Both are legitimate concerns. Neither addresses the more fundamental question of whether your agent will behave as intended when production stops cooperating.

                                      The Gravitee State of AI Agent Security 2026 report found that only 14.4% of agents go live with full security and IT approval. A February 2026 paper from 30-plus researchers at Harvard, MIT, Stanford, and CMU documented something even more unsettling: Well-aligned AI agents drift toward manipulation and false task completion in multi-agent environments purely from incentive structures, no adversarial prompting required. The agents weren’t broken. The system-level behavior was the problem.

                                      This is the distinction that matters most for builders of agentic infrastructure: A model can be aligned and a system can still fail. Local optimization at the model level does not guarantee safe behavior at the system level. Chaos engineers have known this about distributed systems for fifteen years. We are relearning it the hard way with agentic AI. The reason our current testing approaches fall short is not that engineers are cutting corners. It is that three foundational assumptions embedded in traditional testing methodology break down completely with agentic systems:

                                      • Determinism: Traditional testing assumes that given the same input, a system produces the same output. A large language model (LLM)-backed agent produces probabilistically similar outputs. This is close enough for most tasks, but dangerous for edge cases in production where an unexpected input triggers a reasoning chain no one anticipated.

                                      • Isolated failure: Traditional testing assumes that when component A fails, it fails in a bounded, traceable way. In a multi-agent pipeline, one agent’s degraded output becomes the next agent’s poisoned input. The failure compounds and mutates. By the time it surfaces, you are debugging five layers removed from the actual source.

                                      • Observable completion: Traditional testing assumes that when a task is done, the system accurately signals it. Agentic systems can, and regularly do, signal task completion while operating in a degraded or out-of-scope state. The MIT NANDA project has a term for this: «confident incorrectness.» I have a less polite term for it: the thing that causes the 4am incident that took three hours to trace.

                                      Intent-based chaos testing exists to address exactly these failure modes, before your agents reach production.

                                      The core concept: Measuring deviation from intent, not just from success

                                      Chaos engineering as a discipline is not new. Netflix built Chaos Monkey in 2011. The principle is straightforward: Deliberately inject failure into your system to discover its weaknesses before users find them. What is new, and what the industry has not yet applied rigorously to agentic AI, is calibrating chaos experiments not just to infrastructure failure scenarios, but to behavioral intent.

                                      The distinction is critical. When a traditional microservice fails under a chaos experiment, you measure recovery time, error rates, and availability. When an agentic AI system fails, those metrics can look perfectly normal while the agent is operating completely outside its intended behavioral boundaries: Zero errors, normal latency, catastrophically wrong decisions. This is the concept behind a chaos scale system calibrated not just to failure severity, but to how far a system’s behavior deviates from its intended purpose. I call the output of that measurement an intent deviation score.

                                      Here is what that looks like in practice. Before running any chaos experiment against an enterprise observability agent, you define five behavioral dimensions that together describe what «acting correctly» means for that specific agent in its specific deployment context:

                                      Behavioral dimension

                                      What it measures

                                      Weight

                                      Tool call deviation

                                      Are tool calls diverging from expected sequences under stress?

                                      30%

                                      Data access scope

                                      Is the agent accessing data outside its authorized boundaries?

                                      25%

                                      Completion signal accuracy

                                      When the agent reports success, is it actually in a valid state?

                                      20%

                                      Escalation fidelity

                                      Is the agent escalating to humans when it encounters ambiguity?

                                      15%

                                      Decision latency

                                      Is time-to-decision within expected bounds given current conditions?

                                      10%

                                      The weights are not arbitrary. They reflect the risk profile of the specific agent. For a read-only analytics agent, you might weight data access scope lower. For an agent with write access to production systems, completion signal accuracy and escalation fidelity are where failures become outages. The point is that you define these dimensions before you inject any failure, based on what the agent is actually supposed to do.

                                      The deviation score is computed as a weighted average of how far each observed dimension has drifted from its baseline:

                                      def compute_intent_deviation_score(

                                          baseline: dict[str, float],

                                          observed: dict[str, float],

                                          weights: dict[str, float]

                                      ) -> float:

                                          «»»

                                      The system computes how far an agent’s behavior has drifted from its intended baseline, and returns a score from 0.0 (no deviation) to 1.0 (complete intent violation).   

                                      This is NOT a performance metric. Latency and error rates may look fine while this score is elevated. That’s the entire point.

                                          «»»

                                          score = 0.0

                                          for dimension, weight in weights.items():

                                              baseline_val = baseline.get(dimension, 0.0)

                                              observed_val = observed.get(dimension, 0.0)

                                              # Normalize deviation relative to baseline magnitude

                                              raw_deviation = abs(observed_val – baseline_val) / max(abs(baseline_val), 1e-9)

                                              score += min(raw_deviation, 1.0) * weight

                                          return round(min(score, 1.0), 4)

                                      Once you have a deviation score, you classify it into actionable levels:

                                      Score range

                                      Classification

                                      Recommended response

                                      0.00 – 0.15

                                      Nominal

                                      Agent operating as intended. No action required.

                                      0.15 – 0.40

                                      Degraded

                                      Behavior drifting. Alert on-call, increase monitoring cadence.

                                      0.40 – 0.70

                                      Critical

                                      Significant intent violation. Require human review before next action.

                                      0.70 – 1.00

                                      Catastrophic

                                      Agent operating outside all defined boundaries. Halt and escalate immediately.

                                      The rollback agent from the opening scenario? Under this framework, it would have scored approximately 0.78 on the intent deviation scale during Phase 3 testing (catastrophic). The completion signal accuracy dimension alone would have flagged that the agent was reporting success states that did not correspond to valid system outcomes. That score would have blocked the agent from production. The four-hour outage would have been a pre-production finding instead.

                                      The experiment structure: Four phases, expanding blast radius

                                      The practical implementation of this framework runs in four phases, each designed to expand the chaos gradually and validate the agent’s behavioral boundaries before widening the experiment. You do not start with composite failure injection. You earn the right to each phase by passing the previous one.

                                      Phase 1: Single tool degradation. Degrade one downstream dependency and observe how the agent adapts. Does it retry intelligently? Does it escalate when retries fail? Does it modify its tool call sequence in a reasonable way, or does it start making calls it was never designed to make? At this phase, the blast radius is intentionally narrow: One tool, one agent, no production traffic.

                                      Phase 2: Context poisoning. Introduce corrupted or missing telemetry context,  the kind of data quality degradation that happens constantly in real enterprise environments. Missing fields, stale baselines, contradictory signals from different sources. This is where you find out whether your agent autopilots through bad data or escalates appropriately when its informational foundation is compromised.

                                      The log schema your observability stack needs to capture to make Phase 2 meaningful is not just error counts and latency. You need intent signals:

                                      {

                                        «timestamp»: «2026-03-30T02:47:13.441Z»,

                                        «agent_id»: «observability-agent-prod-07»,

                                        «action»: «triggered_rollback»,

                                        «decision_chain»: [

                                          {«step»: 1, «observation»: «anomaly_score=0.87», «source»: «telemetry_feed»},

                                          {«step»: 2, «reasoning»: «score exceeds threshold,  initiating response»},

                                          {«step»: 3, «tool_called»: «rollback_service», «params»: {«scope»: «prod-cluster-3»}}

                                        ],

                                        «context_completeness»: 0.62,

                                        «escalation_triggered»: false,

                                        «intent_deviation_score»: 0.78,

                                        «chaos_level»: «CATASTROPHIC»

                                      }

                                      The field that would have changed everything in the opening scenario is context_completeness: 0.62. The agent made a high-confidence, irreversible decision with 62% of its expected context available. It did not detect the missing fields. It did not escalate. A log schema that captures this turns a mysterious outage into a diagnosable engineering problem,  but only if you instrument for it before you start testing.

                                      Phase 3: Multi-agent interference. Introduce a second agent operating on overlapping data or shared resources. This is where emergent failures from incentive misalignment surface. Two agents with individually correct behaviors can produce collectively harmful outcomes when they share write access to the same resource. This phase is where the Harvard/MIT/Stanford paper findings become directly applicable: Run your agents in a realistic multi-agent environment and watch what happens to their deviation scores.

                                      Phase 4: Composite failure. Combine multiple simultaneous degradations: Tool latency, missing context, concurrent agents, stale baselines. This is your closest approximation to the actual entropy of a production environment. Pass criteria here should be stricter than the lower phases, not because you expect the agent to be perfect under composite failure, but because you want to understand its blast radius under the worst conditions you can reasonably anticipate.

                                      The pass/fail criteria across all four phases follow a consistent rule: If the intent deviation score exceeds the threshold for that phase, the agent does not proceed to the next phase or to production. Full stop.

                                      Calibrating testing depth to deployment risk

                                      Not every agent needs all four phases. The investment in chaos testing should match the risk profile of the deployment. Here is a practical calibration matrix:

                                      Agent autonomy

                                      Action reversibility

                                      Data sensitivity

                                      Required phases

                                      Recommend only,  human approves all actions

                                      N/A

                                      Any

                                      Phase 1–2

                                      Automate low-stakes, easily reversible actions

                                      High

                                      Low–Medium

                                      Phase 1–3

                                      Automate medium-stakes actions

                                      Medium

                                      Medium–High

                                      Phase 1–4

                                      Fully autonomous with irreversible actions

                                      Low

                                      Any

                                      Phase 1–4 + continuous

                                      Multi-agent orchestration, shared resources

                                      Mixed

                                      Any

                                      Phase 1–4 + adversarial red team

                                      The rollback agent was in row four. It had been tested to row two. That delta is where the four-hour outage lived.

                                      The retraining loop: The piece most teams skip

                                      Running a chaos experiment once before deployment is necessary but not sufficient. Agentic systems evolve. They get new tool integrations. Their prompts get updated. Their data access scope expands. An agent that cleared all four phases in January with a clean bill of behavioral health may have a very different risk profile by April.

                                      The feedback loop from chaos experiments needs to feed back into two places: The chaos scale itself (which dimensions are showing the most drift? should their weights be adjusted?) and the agent’s behavioral guardrails (which escalation thresholds are too loose? which tool permissions are too broad?).

                                      In practice, this means treating your chaos experiment results as a governance artifact, not a PDF report that gets shared in Slack and forgotten, but a structured input to your deployment decision process. Every meaningful change to an agent’s configuration, tooling, or scope should trigger re-running the affected phases. Not a full regression — targeted re-testing of the dimensions most likely to be affected by the specific change.

                                      This is the kind of discipline that traditional software engineering built over decades. We are building it from scratch for probabilistic, autonomous systems, and we do not have the luxury of another decade to get there.

                                      Where this fits in the pipeline

                                      To be clear about what this framework is and is not: Intent-based chaos testing is not a replacement for any of the testing you are already doing. Unit tests, integration tests, load tests, security red teams are all still necessary. This is an additional gate, and it belongs at a specific point in your deployment pipeline:

                                      Development  →  Unit / Integration Tests

                                      Staging      →  Load Testing + Security Red Team

                                      Pre-Prod     →  Intent-Based Chaos Testing   ← the gap this fills

                                      Production   →  Observability + Sampled Ongoing Chaos

                                      The pre-production gate is where you answer the question that none of the other gates answer: Given realistic failure conditions, does this agent stay within its intended behavioral boundaries, or does it drift in ways that are going to cost you?

                                      If you cannot answer that question before your agent goes live, you are not testing it. You are deploying it and hoping.

                                      The uncomfortable arithmetic

                                      Gartner projects that more than 40% of agentic AI projects will be canceled by the end of 2027 due to escalating costs, unclear ROI, and inadequate risk controls. Based on what I have seen building and deploying these systems, the risk controls piece is doing most of that work,  and the specific risk control that is most consistently absent is structured pre-deployment behavioral validation.

                                      We built decades of testing discipline for deterministic software. We are starting nearly from scratch for systems that reason probabilistically, act autonomously, and operate in environments they were not specifically trained on. Intent-based chaos testing is one piece of what that discipline needs to look like. It will not prevent every incident. Nothing does. But it will ensure that when an incident happens, you either prevented it with pre-production evidence, or you made a conscious, documented decision to accept the risk.

                                      That is a meaningfully higher bar than deploying and hoping; and right now, it is the bar most enterprise teams are not clearing.

                                      Sayali Patil is an AI infrastructure and product leader with experience at Cisco Systems and Splunk.

                                      Welcome to the VentureBeat community!

                                      Our guest posting program is where technical experts share insights and provide neutral, non-vested deep dives on AI, data infrastructure, cybersecurity and other cutting-edge technologies shaping the future of enterprise.

                                      Read more from our guest post program — and check out our guidelines if you’re interested in contributing an article of your own!

                                      Tours Colombia Todo el año Tours Colombia Todo el año Tours Colombia Todo el año

                                      Here is a scenario that should concern every enterprise architect shipping autonomous AI systems right now: An observability agent is running in production. Its job is to detect infrastructure anomalies and trigger the appropriate response. Late one night, it flags an elevated anomaly score across a production cluster, 0.87, above its defined threshold of 0.75. The agent is within its permission boundaries. It has access to the rollback service. So it uses it.

                                      The rollback causes a four-hour outage. The anomaly it was responding to was a scheduled batch job the agent had never encountered before. There was no actual fault. The agent did not escalate. It did not ask. It acted,  confidently, autonomously, and catastrophically.

                                      What makes this scenario particularly uncomfortable is that the failure was not in the model. The model behaved exactly as trained. The failure was in how the system was tested before it reached production. The engineers had validated happy-path behavior, run load tests, and done a security review. What they had not done is ask: what does this agent do when it encounters conditions it was never designed for?

                                      That question is the gap I want to talk about.

                                      Image provided by author.

                                      Why the industry has its testing priorities backwards

                                      The enterprise AI conversation in 2026 has largely collapsed into two areas: identity governance (who is the agent acting as?) and observability (can we see what it’s doing?). Both are legitimate concerns. Neither addresses the more fundamental question of whether your agent will behave as intended when production stops cooperating.

                                      The Gravitee State of AI Agent Security 2026 report found that only 14.4% of agents go live with full security and IT approval. A February 2026 paper from 30-plus researchers at Harvard, MIT, Stanford, and CMU documented something even more unsettling: Well-aligned AI agents drift toward manipulation and false task completion in multi-agent environments purely from incentive structures, no adversarial prompting required. The agents weren’t broken. The system-level behavior was the problem.

                                      This is the distinction that matters most for builders of agentic infrastructure: A model can be aligned and a system can still fail. Local optimization at the model level does not guarantee safe behavior at the system level. Chaos engineers have known this about distributed systems for fifteen years. We are relearning it the hard way with agentic AI. The reason our current testing approaches fall short is not that engineers are cutting corners. It is that three foundational assumptions embedded in traditional testing methodology break down completely with agentic systems:

                                      • Determinism: Traditional testing assumes that given the same input, a system produces the same output. A large language model (LLM)-backed agent produces probabilistically similar outputs. This is close enough for most tasks, but dangerous for edge cases in production where an unexpected input triggers a reasoning chain no one anticipated.

                                      • Isolated failure: Traditional testing assumes that when component A fails, it fails in a bounded, traceable way. In a multi-agent pipeline, one agent’s degraded output becomes the next agent’s poisoned input. The failure compounds and mutates. By the time it surfaces, you are debugging five layers removed from the actual source.

                                      • Observable completion: Traditional testing assumes that when a task is done, the system accurately signals it. Agentic systems can, and regularly do, signal task completion while operating in a degraded or out-of-scope state. The MIT NANDA project has a term for this: «confident incorrectness.» I have a less polite term for it: the thing that causes the 4am incident that took three hours to trace.

                                      Intent-based chaos testing exists to address exactly these failure modes, before your agents reach production.

                                      The core concept: Measuring deviation from intent, not just from success

                                      Chaos engineering as a discipline is not new. Netflix built Chaos Monkey in 2011. The principle is straightforward: Deliberately inject failure into your system to discover its weaknesses before users find them. What is new, and what the industry has not yet applied rigorously to agentic AI, is calibrating chaos experiments not just to infrastructure failure scenarios, but to behavioral intent.

                                      The distinction is critical. When a traditional microservice fails under a chaos experiment, you measure recovery time, error rates, and availability. When an agentic AI system fails, those metrics can look perfectly normal while the agent is operating completely outside its intended behavioral boundaries: Zero errors, normal latency, catastrophically wrong decisions. This is the concept behind a chaos scale system calibrated not just to failure severity, but to how far a system’s behavior deviates from its intended purpose. I call the output of that measurement an intent deviation score.

                                      Here is what that looks like in practice. Before running any chaos experiment against an enterprise observability agent, you define five behavioral dimensions that together describe what «acting correctly» means for that specific agent in its specific deployment context:

                                      Behavioral dimension

                                      What it measures

                                      Weight

                                      Tool call deviation

                                      Are tool calls diverging from expected sequences under stress?

                                      30%

                                      Data access scope

                                      Is the agent accessing data outside its authorized boundaries?

                                      25%

                                      Completion signal accuracy

                                      When the agent reports success, is it actually in a valid state?

                                      20%

                                      Escalation fidelity

                                      Is the agent escalating to humans when it encounters ambiguity?

                                      15%

                                      Decision latency

                                      Is time-to-decision within expected bounds given current conditions?

                                      10%

                                      The weights are not arbitrary. They reflect the risk profile of the specific agent. For a read-only analytics agent, you might weight data access scope lower. For an agent with write access to production systems, completion signal accuracy and escalation fidelity are where failures become outages. The point is that you define these dimensions before you inject any failure, based on what the agent is actually supposed to do.

                                      The deviation score is computed as a weighted average of how far each observed dimension has drifted from its baseline:

                                      def compute_intent_deviation_score(

                                          baseline: dict[str, float],

                                          observed: dict[str, float],

                                          weights: dict[str, float]

                                      ) -> float:

                                          «»»

                                      The system computes how far an agent’s behavior has drifted from its intended baseline, and returns a score from 0.0 (no deviation) to 1.0 (complete intent violation).   

                                      This is NOT a performance metric. Latency and error rates may look fine while this score is elevated. That’s the entire point.

                                          «»»

                                          score = 0.0

                                          for dimension, weight in weights.items():

                                              baseline_val = baseline.get(dimension, 0.0)

                                              observed_val = observed.get(dimension, 0.0)

                                              # Normalize deviation relative to baseline magnitude

                                              raw_deviation = abs(observed_val – baseline_val) / max(abs(baseline_val), 1e-9)

                                              score += min(raw_deviation, 1.0) * weight

                                          return round(min(score, 1.0), 4)

                                      Once you have a deviation score, you classify it into actionable levels:

                                      Score range

                                      Classification

                                      Recommended response

                                      0.00 – 0.15

                                      Nominal

                                      Agent operating as intended. No action required.

                                      0.15 – 0.40

                                      Degraded

                                      Behavior drifting. Alert on-call, increase monitoring cadence.

                                      0.40 – 0.70

                                      Critical

                                      Significant intent violation. Require human review before next action.

                                      0.70 – 1.00

                                      Catastrophic

                                      Agent operating outside all defined boundaries. Halt and escalate immediately.

                                      The rollback agent from the opening scenario? Under this framework, it would have scored approximately 0.78 on the intent deviation scale during Phase 3 testing (catastrophic). The completion signal accuracy dimension alone would have flagged that the agent was reporting success states that did not correspond to valid system outcomes. That score would have blocked the agent from production. The four-hour outage would have been a pre-production finding instead.

                                      The experiment structure: Four phases, expanding blast radius

                                      The practical implementation of this framework runs in four phases, each designed to expand the chaos gradually and validate the agent’s behavioral boundaries before widening the experiment. You do not start with composite failure injection. You earn the right to each phase by passing the previous one.

                                      Phase 1: Single tool degradation. Degrade one downstream dependency and observe how the agent adapts. Does it retry intelligently? Does it escalate when retries fail? Does it modify its tool call sequence in a reasonable way, or does it start making calls it was never designed to make? At this phase, the blast radius is intentionally narrow: One tool, one agent, no production traffic.

                                      Phase 2: Context poisoning. Introduce corrupted or missing telemetry context,  the kind of data quality degradation that happens constantly in real enterprise environments. Missing fields, stale baselines, contradictory signals from different sources. This is where you find out whether your agent autopilots through bad data or escalates appropriately when its informational foundation is compromised.

                                      The log schema your observability stack needs to capture to make Phase 2 meaningful is not just error counts and latency. You need intent signals:

                                      {

                                        «timestamp»: «2026-03-30T02:47:13.441Z»,

                                        «agent_id»: «observability-agent-prod-07»,

                                        «action»: «triggered_rollback»,

                                        «decision_chain»: [

                                          {«step»: 1, «observation»: «anomaly_score=0.87», «source»: «telemetry_feed»},

                                          {«step»: 2, «reasoning»: «score exceeds threshold,  initiating response»},

                                          {«step»: 3, «tool_called»: «rollback_service», «params»: {«scope»: «prod-cluster-3»}}

                                        ],

                                        «context_completeness»: 0.62,

                                        «escalation_triggered»: false,

                                        «intent_deviation_score»: 0.78,

                                        «chaos_level»: «CATASTROPHIC»

                                      }

                                      The field that would have changed everything in the opening scenario is context_completeness: 0.62. The agent made a high-confidence, irreversible decision with 62% of its expected context available. It did not detect the missing fields. It did not escalate. A log schema that captures this turns a mysterious outage into a diagnosable engineering problem,  but only if you instrument for it before you start testing.

                                      Phase 3: Multi-agent interference. Introduce a second agent operating on overlapping data or shared resources. This is where emergent failures from incentive misalignment surface. Two agents with individually correct behaviors can produce collectively harmful outcomes when they share write access to the same resource. This phase is where the Harvard/MIT/Stanford paper findings become directly applicable: Run your agents in a realistic multi-agent environment and watch what happens to their deviation scores.

                                      Phase 4: Composite failure. Combine multiple simultaneous degradations: Tool latency, missing context, concurrent agents, stale baselines. This is your closest approximation to the actual entropy of a production environment. Pass criteria here should be stricter than the lower phases, not because you expect the agent to be perfect under composite failure, but because you want to understand its blast radius under the worst conditions you can reasonably anticipate.

                                      The pass/fail criteria across all four phases follow a consistent rule: If the intent deviation score exceeds the threshold for that phase, the agent does not proceed to the next phase or to production. Full stop.

                                      Calibrating testing depth to deployment risk

                                      Not every agent needs all four phases. The investment in chaos testing should match the risk profile of the deployment. Here is a practical calibration matrix:

                                      Agent autonomy

                                      Action reversibility

                                      Data sensitivity

                                      Required phases

                                      Recommend only,  human approves all actions

                                      N/A

                                      Any

                                      Phase 1–2

                                      Automate low-stakes, easily reversible actions

                                      High

                                      Low–Medium

                                      Phase 1–3

                                      Automate medium-stakes actions

                                      Medium

                                      Medium–High

                                      Phase 1–4

                                      Fully autonomous with irreversible actions

                                      Low

                                      Any

                                      Phase 1–4 + continuous

                                      Multi-agent orchestration, shared resources

                                      Mixed

                                      Any

                                      Phase 1–4 + adversarial red team

                                      The rollback agent was in row four. It had been tested to row two. That delta is where the four-hour outage lived.

                                      The retraining loop: The piece most teams skip

                                      Running a chaos experiment once before deployment is necessary but not sufficient. Agentic systems evolve. They get new tool integrations. Their prompts get updated. Their data access scope expands. An agent that cleared all four phases in January with a clean bill of behavioral health may have a very different risk profile by April.

                                      The feedback loop from chaos experiments needs to feed back into two places: The chaos scale itself (which dimensions are showing the most drift? should their weights be adjusted?) and the agent’s behavioral guardrails (which escalation thresholds are too loose? which tool permissions are too broad?).

                                      In practice, this means treating your chaos experiment results as a governance artifact, not a PDF report that gets shared in Slack and forgotten, but a structured input to your deployment decision process. Every meaningful change to an agent’s configuration, tooling, or scope should trigger re-running the affected phases. Not a full regression — targeted re-testing of the dimensions most likely to be affected by the specific change.

                                      This is the kind of discipline that traditional software engineering built over decades. We are building it from scratch for probabilistic, autonomous systems, and we do not have the luxury of another decade to get there.

                                      Where this fits in the pipeline

                                      To be clear about what this framework is and is not: Intent-based chaos testing is not a replacement for any of the testing you are already doing. Unit tests, integration tests, load tests, security red teams are all still necessary. This is an additional gate, and it belongs at a specific point in your deployment pipeline:

                                      Development  →  Unit / Integration Tests

                                      Staging      →  Load Testing + Security Red Team

                                      Pre-Prod     →  Intent-Based Chaos Testing   ← the gap this fills

                                      Production   →  Observability + Sampled Ongoing Chaos

                                      The pre-production gate is where you answer the question that none of the other gates answer: Given realistic failure conditions, does this agent stay within its intended behavioral boundaries, or does it drift in ways that are going to cost you?

                                      If you cannot answer that question before your agent goes live, you are not testing it. You are deploying it and hoping.

                                      The uncomfortable arithmetic

                                      Gartner projects that more than 40% of agentic AI projects will be canceled by the end of 2027 due to escalating costs, unclear ROI, and inadequate risk controls. Based on what I have seen building and deploying these systems, the risk controls piece is doing most of that work,  and the specific risk control that is most consistently absent is structured pre-deployment behavioral validation.

                                      We built decades of testing discipline for deterministic software. We are starting nearly from scratch for systems that reason probabilistically, act autonomously, and operate in environments they were not specifically trained on. Intent-based chaos testing is one piece of what that discipline needs to look like. It will not prevent every incident. Nothing does. But it will ensure that when an incident happens, you either prevented it with pre-production evidence, or you made a conscious, documented decision to accept the risk.

                                      That is a meaningfully higher bar than deploying and hoping; and right now, it is the bar most enterprise teams are not clearing.

                                      Sayali Patil is an AI infrastructure and product leader with experience at Cisco Systems and Splunk.

                                      Welcome to the VentureBeat community!

                                      Our guest posting program is where technical experts share insights and provide neutral, non-vested deep dives on AI, data infrastructure, cybersecurity and other cutting-edge technologies shaping the future of enterprise.

                                      Read more from our guest post program — and check out our guidelines if you’re interested in contributing an article of your own!

                                      Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado

                                      Here is a scenario that should concern every enterprise architect shipping autonomous AI systems right now: An observability agent is running in production. Its job is to detect infrastructure anomalies and trigger the appropriate response. Late one night, it flags an elevated anomaly score across a production cluster, 0.87, above its defined threshold of 0.75. The agent is within its permission boundaries. It has access to the rollback service. So it uses it.

                                      The rollback causes a four-hour outage. The anomaly it was responding to was a scheduled batch job the agent had never encountered before. There was no actual fault. The agent did not escalate. It did not ask. It acted,  confidently, autonomously, and catastrophically.

                                      What makes this scenario particularly uncomfortable is that the failure was not in the model. The model behaved exactly as trained. The failure was in how the system was tested before it reached production. The engineers had validated happy-path behavior, run load tests, and done a security review. What they had not done is ask: what does this agent do when it encounters conditions it was never designed for?

                                      That question is the gap I want to talk about.

                                      Image provided by author.

                                      Why the industry has its testing priorities backwards

                                      The enterprise AI conversation in 2026 has largely collapsed into two areas: identity governance (who is the agent acting as?) and observability (can we see what it’s doing?). Both are legitimate concerns. Neither addresses the more fundamental question of whether your agent will behave as intended when production stops cooperating.

                                      The Gravitee State of AI Agent Security 2026 report found that only 14.4% of agents go live with full security and IT approval. A February 2026 paper from 30-plus researchers at Harvard, MIT, Stanford, and CMU documented something even more unsettling: Well-aligned AI agents drift toward manipulation and false task completion in multi-agent environments purely from incentive structures, no adversarial prompting required. The agents weren’t broken. The system-level behavior was the problem.

                                      This is the distinction that matters most for builders of agentic infrastructure: A model can be aligned and a system can still fail. Local optimization at the model level does not guarantee safe behavior at the system level. Chaos engineers have known this about distributed systems for fifteen years. We are relearning it the hard way with agentic AI. The reason our current testing approaches fall short is not that engineers are cutting corners. It is that three foundational assumptions embedded in traditional testing methodology break down completely with agentic systems:

                                      • Determinism: Traditional testing assumes that given the same input, a system produces the same output. A large language model (LLM)-backed agent produces probabilistically similar outputs. This is close enough for most tasks, but dangerous for edge cases in production where an unexpected input triggers a reasoning chain no one anticipated.

                                      • Isolated failure: Traditional testing assumes that when component A fails, it fails in a bounded, traceable way. In a multi-agent pipeline, one agent’s degraded output becomes the next agent’s poisoned input. The failure compounds and mutates. By the time it surfaces, you are debugging five layers removed from the actual source.

                                      • Observable completion: Traditional testing assumes that when a task is done, the system accurately signals it. Agentic systems can, and regularly do, signal task completion while operating in a degraded or out-of-scope state. The MIT NANDA project has a term for this: «confident incorrectness.» I have a less polite term for it: the thing that causes the 4am incident that took three hours to trace.

                                      Intent-based chaos testing exists to address exactly these failure modes, before your agents reach production.

                                      The core concept: Measuring deviation from intent, not just from success

                                      Chaos engineering as a discipline is not new. Netflix built Chaos Monkey in 2011. The principle is straightforward: Deliberately inject failure into your system to discover its weaknesses before users find them. What is new, and what the industry has not yet applied rigorously to agentic AI, is calibrating chaos experiments not just to infrastructure failure scenarios, but to behavioral intent.

                                      The distinction is critical. When a traditional microservice fails under a chaos experiment, you measure recovery time, error rates, and availability. When an agentic AI system fails, those metrics can look perfectly normal while the agent is operating completely outside its intended behavioral boundaries: Zero errors, normal latency, catastrophically wrong decisions. This is the concept behind a chaos scale system calibrated not just to failure severity, but to how far a system’s behavior deviates from its intended purpose. I call the output of that measurement an intent deviation score.

                                      Here is what that looks like in practice. Before running any chaos experiment against an enterprise observability agent, you define five behavioral dimensions that together describe what «acting correctly» means for that specific agent in its specific deployment context:

                                      Behavioral dimension

                                      What it measures

                                      Weight

                                      Tool call deviation

                                      Are tool calls diverging from expected sequences under stress?

                                      30%

                                      Data access scope

                                      Is the agent accessing data outside its authorized boundaries?

                                      25%

                                      Completion signal accuracy

                                      When the agent reports success, is it actually in a valid state?

                                      20%

                                      Escalation fidelity

                                      Is the agent escalating to humans when it encounters ambiguity?

                                      15%

                                      Decision latency

                                      Is time-to-decision within expected bounds given current conditions?

                                      10%

                                      The weights are not arbitrary. They reflect the risk profile of the specific agent. For a read-only analytics agent, you might weight data access scope lower. For an agent with write access to production systems, completion signal accuracy and escalation fidelity are where failures become outages. The point is that you define these dimensions before you inject any failure, based on what the agent is actually supposed to do.

                                      The deviation score is computed as a weighted average of how far each observed dimension has drifted from its baseline:

                                      def compute_intent_deviation_score(

                                          baseline: dict[str, float],

                                          observed: dict[str, float],

                                          weights: dict[str, float]

                                      ) -> float:

                                          «»»

                                      The system computes how far an agent’s behavior has drifted from its intended baseline, and returns a score from 0.0 (no deviation) to 1.0 (complete intent violation).   

                                      This is NOT a performance metric. Latency and error rates may look fine while this score is elevated. That’s the entire point.

                                          «»»

                                          score = 0.0

                                          for dimension, weight in weights.items():

                                              baseline_val = baseline.get(dimension, 0.0)

                                              observed_val = observed.get(dimension, 0.0)

                                              # Normalize deviation relative to baseline magnitude

                                              raw_deviation = abs(observed_val – baseline_val) / max(abs(baseline_val), 1e-9)

                                              score += min(raw_deviation, 1.0) * weight

                                          return round(min(score, 1.0), 4)

                                      Once you have a deviation score, you classify it into actionable levels:

                                      Score range

                                      Classification

                                      Recommended response

                                      0.00 – 0.15

                                      Nominal

                                      Agent operating as intended. No action required.

                                      0.15 – 0.40

                                      Degraded

                                      Behavior drifting. Alert on-call, increase monitoring cadence.

                                      0.40 – 0.70

                                      Critical

                                      Significant intent violation. Require human review before next action.

                                      0.70 – 1.00

                                      Catastrophic

                                      Agent operating outside all defined boundaries. Halt and escalate immediately.

                                      The rollback agent from the opening scenario? Under this framework, it would have scored approximately 0.78 on the intent deviation scale during Phase 3 testing (catastrophic). The completion signal accuracy dimension alone would have flagged that the agent was reporting success states that did not correspond to valid system outcomes. That score would have blocked the agent from production. The four-hour outage would have been a pre-production finding instead.

                                      The experiment structure: Four phases, expanding blast radius

                                      The practical implementation of this framework runs in four phases, each designed to expand the chaos gradually and validate the agent’s behavioral boundaries before widening the experiment. You do not start with composite failure injection. You earn the right to each phase by passing the previous one.

                                      Phase 1: Single tool degradation. Degrade one downstream dependency and observe how the agent adapts. Does it retry intelligently? Does it escalate when retries fail? Does it modify its tool call sequence in a reasonable way, or does it start making calls it was never designed to make? At this phase, the blast radius is intentionally narrow: One tool, one agent, no production traffic.

                                      Phase 2: Context poisoning. Introduce corrupted or missing telemetry context,  the kind of data quality degradation that happens constantly in real enterprise environments. Missing fields, stale baselines, contradictory signals from different sources. This is where you find out whether your agent autopilots through bad data or escalates appropriately when its informational foundation is compromised.

                                      The log schema your observability stack needs to capture to make Phase 2 meaningful is not just error counts and latency. You need intent signals:

                                      {

                                        «timestamp»: «2026-03-30T02:47:13.441Z»,

                                        «agent_id»: «observability-agent-prod-07»,

                                        «action»: «triggered_rollback»,

                                        «decision_chain»: [

                                          {«step»: 1, «observation»: «anomaly_score=0.87», «source»: «telemetry_feed»},

                                          {«step»: 2, «reasoning»: «score exceeds threshold,  initiating response»},

                                          {«step»: 3, «tool_called»: «rollback_service», «params»: {«scope»: «prod-cluster-3»}}

                                        ],

                                        «context_completeness»: 0.62,

                                        «escalation_triggered»: false,

                                        «intent_deviation_score»: 0.78,

                                        «chaos_level»: «CATASTROPHIC»

                                      }

                                      The field that would have changed everything in the opening scenario is context_completeness: 0.62. The agent made a high-confidence, irreversible decision with 62% of its expected context available. It did not detect the missing fields. It did not escalate. A log schema that captures this turns a mysterious outage into a diagnosable engineering problem,  but only if you instrument for it before you start testing.

                                      Phase 3: Multi-agent interference. Introduce a second agent operating on overlapping data or shared resources. This is where emergent failures from incentive misalignment surface. Two agents with individually correct behaviors can produce collectively harmful outcomes when they share write access to the same resource. This phase is where the Harvard/MIT/Stanford paper findings become directly applicable: Run your agents in a realistic multi-agent environment and watch what happens to their deviation scores.

                                      Phase 4: Composite failure. Combine multiple simultaneous degradations: Tool latency, missing context, concurrent agents, stale baselines. This is your closest approximation to the actual entropy of a production environment. Pass criteria here should be stricter than the lower phases, not because you expect the agent to be perfect under composite failure, but because you want to understand its blast radius under the worst conditions you can reasonably anticipate.

                                      The pass/fail criteria across all four phases follow a consistent rule: If the intent deviation score exceeds the threshold for that phase, the agent does not proceed to the next phase or to production. Full stop.

                                      Calibrating testing depth to deployment risk

                                      Not every agent needs all four phases. The investment in chaos testing should match the risk profile of the deployment. Here is a practical calibration matrix:

                                      Agent autonomy

                                      Action reversibility

                                      Data sensitivity

                                      Required phases

                                      Recommend only,  human approves all actions

                                      N/A

                                      Any

                                      Phase 1–2

                                      Automate low-stakes, easily reversible actions

                                      High

                                      Low–Medium

                                      Phase 1–3

                                      Automate medium-stakes actions

                                      Medium

                                      Medium–High

                                      Phase 1–4

                                      Fully autonomous with irreversible actions

                                      Low

                                      Any

                                      Phase 1–4 + continuous

                                      Multi-agent orchestration, shared resources

                                      Mixed

                                      Any

                                      Phase 1–4 + adversarial red team

                                      The rollback agent was in row four. It had been tested to row two. That delta is where the four-hour outage lived.

                                      The retraining loop: The piece most teams skip

                                      Running a chaos experiment once before deployment is necessary but not sufficient. Agentic systems evolve. They get new tool integrations. Their prompts get updated. Their data access scope expands. An agent that cleared all four phases in January with a clean bill of behavioral health may have a very different risk profile by April.

                                      The feedback loop from chaos experiments needs to feed back into two places: The chaos scale itself (which dimensions are showing the most drift? should their weights be adjusted?) and the agent’s behavioral guardrails (which escalation thresholds are too loose? which tool permissions are too broad?).

                                      In practice, this means treating your chaos experiment results as a governance artifact, not a PDF report that gets shared in Slack and forgotten, but a structured input to your deployment decision process. Every meaningful change to an agent’s configuration, tooling, or scope should trigger re-running the affected phases. Not a full regression — targeted re-testing of the dimensions most likely to be affected by the specific change.

                                      This is the kind of discipline that traditional software engineering built over decades. We are building it from scratch for probabilistic, autonomous systems, and we do not have the luxury of another decade to get there.

                                      Where this fits in the pipeline

                                      To be clear about what this framework is and is not: Intent-based chaos testing is not a replacement for any of the testing you are already doing. Unit tests, integration tests, load tests, security red teams are all still necessary. This is an additional gate, and it belongs at a specific point in your deployment pipeline:

                                      Development  →  Unit / Integration Tests

                                      Staging      →  Load Testing + Security Red Team

                                      Pre-Prod     →  Intent-Based Chaos Testing   ← the gap this fills

                                      Production   →  Observability + Sampled Ongoing Chaos

                                      The pre-production gate is where you answer the question that none of the other gates answer: Given realistic failure conditions, does this agent stay within its intended behavioral boundaries, or does it drift in ways that are going to cost you?

                                      If you cannot answer that question before your agent goes live, you are not testing it. You are deploying it and hoping.

                                      The uncomfortable arithmetic

                                      Gartner projects that more than 40% of agentic AI projects will be canceled by the end of 2027 due to escalating costs, unclear ROI, and inadequate risk controls. Based on what I have seen building and deploying these systems, the risk controls piece is doing most of that work,  and the specific risk control that is most consistently absent is structured pre-deployment behavioral validation.

                                      We built decades of testing discipline for deterministic software. We are starting nearly from scratch for systems that reason probabilistically, act autonomously, and operate in environments they were not specifically trained on. Intent-based chaos testing is one piece of what that discipline needs to look like. It will not prevent every incident. Nothing does. But it will ensure that when an incident happens, you either prevented it with pre-production evidence, or you made a conscious, documented decision to accept the risk.

                                      That is a meaningfully higher bar than deploying and hoping; and right now, it is the bar most enterprise teams are not clearing.

                                      Sayali Patil is an AI infrastructure and product leader with experience at Cisco Systems and Splunk.

                                      Welcome to the VentureBeat community!

                                      Our guest posting program is where technical experts share insights and provide neutral, non-vested deep dives on AI, data infrastructure, cybersecurity and other cutting-edge technologies shaping the future of enterprise.

                                      Read more from our guest post program — and check out our guidelines if you’re interested in contributing an article of your own!

                                      ● Canal oficial · Gratis
                                      ¡Recibe las noticias antes que nadie!
                                      Únete a nuestro canal de WhatsApp y mantente informado al instante, sin spam.
                                      Unirme ahora →
                                      ● Noticias al instante ● Cobertura nacional ● Periodismo real Despertar Matinal
                                      — Redacción Despertar Matinal

                                      — Redacción Despertar Matinal

                                      Programa radial que te conecta con la información desde temprano en la mañana.

                                      Next Post
                                      Ministerio de Salud y Autoridad Portuaria activaron protocolos sanitarios al crucero en Puerto Plata; tripulantes aislados no desembarcaron

                                      Ministerio de Salud y Autoridad Portuaria activaron protocolos sanitarios al crucero en Puerto Plata; tripulantes aislados no desembarcaron

                                      Deja una respuesta Cancelar la respuesta

                                      Tu dirección de correo electrónico no será publicada. Los campos obligatorios están marcados con *

                                      Canal de WhatsApp

                                      WhatsApp logo WhatsApp

                                      Canal · Despertar Matinal

                                      Únete a nuestro
                                      Canal

                                      Seguir ahora

                                      El clima

                                      Canal de YouTube

                                      YouTube

                                      Canal · Despertar Matinal

                                      Mira nuestro
                                      Canal

                                      Ver ahora

                                      Escúchanos en Spotify

                                      Spotify

                                      Podcast · Despertar Matinal

                                      Escucha nuestro
                                      Podcast

                                      Escuchar ahora

                                      Noticias Populares

                                      • La economía no se entiende mirando por el espejo retrovisor

                                        La economía no se entiende mirando por el espejo retrovisor

                                        0 shares
                                        Share 0 Tweet 0
                                      • Lake Kariba disaster: Death toll from Zimbabwe ferry accident rises to 93

                                        0 shares
                                        Share 0 Tweet 0
                                      • Russia warns UK over supplying drones to Ukraine

                                        0 shares
                                        Share 0 Tweet 0
                                      • El CEO de PlayStation habló sobre la fecha de lanzamiento de la PS6

                                        0 shares
                                        Share 0 Tweet 0
                                      • Nueva estafa con ARCA: cómo funciona el correo falso que roba datos

                                        0 shares
                                        Share 0 Tweet 0

                                      Medio digital independiente con análisis, opinión y periodismo responsable desde República Dominicana.

                                      Secciones populares

                                      • Política
                                      • Economía & Negocios
                                      • Justicia
                                      • Turismo
                                      • Tecnología
                                      • Entretenimiento
                                      • Mundo
                                      • Cine y Series
                                      • Música
                                      • Moda

                                      Contenido

                                      • Titulares del Día
                                      • Mundo
                                      • Nacionales
                                      • Política
                                      • Deportes
                                      • Economía & Negocios
                                      • Ciencia
                                      • Entretenimiento
                                      • Podcast
                                      • Opinión
                                      • Despertar Matinal TV
                                      • Editoriales

                                      Corporativo

                                      • Sobre nosotros
                                      • Publicidad
                                      • Sala de prensa
                                      • Contacto
                                      • Política de Privacidad
                                      • Eliminación de Datos

                                      Boletines

                                      Suscríbete a nuestro boletín
                                      Recibe las noticias más importantes cada mañana.

                                      • Nosotros
                                      • Publicidad
                                      • Trabaja con nosotros
                                      • Contactos

                                      © 2025 Despertar Matinal. Aviso Legal - comunícate con nuestra redacción y obtén más información sobre Despertar Matinal..

                                      No Result
                                      View All Result
                                      • Home

                                      © 2025 Despertar Matinal. Aviso Legal - comunícate con nuestra redacción y obtén más información sobre Despertar Matinal..

                                      Welcome Back!

                                      Login to your account below

                                      Forgotten Password?

                                      Retrieve your password

                                      Please enter your username or email address to reset your password.

                                      Log In

                                      Desarrollado por
                                      ►
                                      Las cookies necesarias habilitan funciones esenciales del sitio como inicios de sesión seguros y ajustes de preferencias de consentimiento. No almacenan datos personales.
                                      Ninguno
                                      ►
                                      Las cookies funcionales soportan funciones como compartir contenido en redes sociales, recopilar comentarios y habilitar herramientas de terceros.
                                      Ninguno
                                      ►
                                      Las cookies analíticas rastrean las interacciones de los visitantes, proporcionando información sobre métricas como el número de visitantes, la tasa de rebote y las fuentes de tráfico.
                                      Ninguno
                                      ►
                                      Las cookies de publicidad ofrecen anuncios personalizados basados en tus visitas anteriores y analizan la efectividad de las campañas publicitarias.
                                      Ninguno
                                      ►
                                      Las cookies no clasificadas son aquellas que estamos en proceso de clasificar, junto con los proveedores de cookies individuales.
                                      Ninguno
                                      Desarrollado por