Uber has released ADR (Agentic AI Detection and Response), an open-source security platform designed to protect enterprise AI agents used by both employees and customers. The company said the system is already deployed in production at Uber and presented the work at MLSys 2026. The public release on GitHub includes ADR Sensor for telemetry and observability, ADR-Bench for security benchmarking, and ADR Detector for threat detection, with support for monitoring AI coding tools and multiple operating systems.
The repository also includes reproducibility documentation, detector baselines, and a benchmark suite containing more than 300 tasks and 133 MCP servers aimed at defensive research. Uber said the benchmark data is synthetic and includes fake credentials, emulated environments, and prompt-injection scenarios to test agent security. Some internal capabilities, including prevention features and the offline ADR Explorer red-teaming engine, were not included in the open-source release.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
Uber's ADR research paper, titled "ADR: An Agentic Detection System for Enterprise Agentic AI Security," was accepted to MLSys 2026. The project is described as accompanying research on securing enterprise AI agents.
Uber published the ADR (Agentic AI Detection and Response) repository on GitHub as an open-source security system for enterprise AI agents. The release includes ADR Sensor, ADR-Bench, and ADR Detector, while prevention features and the offline ADR Explorer engine were not included.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.