Security1 publisher3 min readPublished
Uber ships ADR, and hands agent-security vendors a number to be measured against
The Agentic AI Detection and Response system runs in production at Uber. Three of its five components are now open source, including a 300-task, 133-MCP-server benchmark.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- ADR (Agentic AI Detection and Response) is an enterprise security system for AI agents.
- ADR is deployed in production at Uber.
- ADR helps organizations secure employee-facing agents such as Cursor, Claude Code and Codex, as well as customer-facing agents such as AI support agents.
- The accompanying paper, 'ADR: An Agentic Detection System for Enterprise Agentic AI Security', was accepted to MLSys 2026 (Proceedings of the Ninth Conference on Machine Learning and Systems, 2026).
- ADR secures enterprise AI agents through five complementary capabilities: discovering unsanctioned AI tools, observing agent activity, evaluating defenses, detecting threats, and preventing unsafe actions.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Uber has published ADR, an "Agentic AI Detection and Response" system that it says is deployed in production internally to secure employee-facing agents such as Cursor, Claude Code and Codex, plus customer-facing support agents [1][2][3]. The release matters less as software than as a published reference point: the accompanying benchmark gives buyers a concrete thing to point at when a vendor says it does "AI agent security" [10].
The architecture Uber describes has five parts: discovering unsanctioned AI tools, observing agent activity, benchmarking defenses, detecting threats, and preventing unsafe actions [5]. Three of the five are in the open-source drop [18]. Discovery, which inventories installed AI applications, CLI agents, local model runtimes and MCP servers on employee endpoints, is held back [6]. So is Prevention, the part that actually blocks an action [7]. So is ADR Explorer, the offline engine Uber says it uses to harden detection through pre-deployment red teaming [8]. What you get is the Sensor, the benchmark and the Detector [12], under Apache 2.0, with AgentDojo vendored under MIT inside the benchmark tree [13].
The observability claim is the one with production mileage behind it. Uber says the sensor captures agent intent, tool use and execution traces across more than seven AI coding tools on macOS, Linux and Windows, as well as internal automation and customer-facing support agents [9]. That is the unglamorous half of this problem and the half most teams have skipped: before you can detect a compromised coding agent, you need a unified record of what it decided to do and which tools it called.
ADR-Bench is the part that creates an obligation for everyone else. Uber puts it at more than 300 tasks across 133 MCP servers, with coverage of what it counts as all 17 agent attack techniques [10]. That works out to roughly 2.3 tasks per MCP server, so the design bias is breadth of environment rather than depth per server [19]. The 17-technique taxonomy is Uber's own accounting, and the benchmark ships synthetic fixtures - fake credentials, emulated environments, prompt-injection scenarios - that Uber labels for defensive research only [10][16]. Detection itself is two-tier: high-recall triage first, deeper agentic reasoning only on sessions that look suspicious [11]. The default detector is a dual-agent configuration called adr, with a keyless llamafirewall baseline available for smoke tests [14], and the quickstart exports both an Anthropic and an OpenAI API key [15]. That tells you where the reasoning happens and, by extension, where the per-session cost lands.
The paper behind it was accepted to the Ninth Conference on Machine Learning and Systems in 2026, and the repository includes a reproducibility document covering benchmark inflation, detector runs and figure generation [4][17].
Watch three things. Whether Discovery and Prevention ever ship, because an observe-and-detect stack without an enforcement point leaves the response half of "detection and response" as an exercise for the reader [6][7]. Whether any commercial agent-security vendor publishes its own ADR-Bench results rather than describing its coverage in prose [10]. And whether the two-tier detector's numbers hold outside Uber's telemetry, given that the red-teaming engine used to harden it was not released [8][11].