『Insecure Agents』のカバーアート

Insecure Agents

Insecure Agents

著者: Allie Howe
無料で聴く

【Amazonプライム会員限定】今ならプレミアムプランが4か月 月額99円。

10月19日まで。※適用条件あり
Insecure Agents lives at the intersection of AI engineering and security. Stay ahead of the curve with expert insights, real-world incidents, and bold ideas for safer agents.Allie Howe 政治・政府
エピソード
  • Blue Team at Machine Speed: Max Pollard (Cotool) on Agentic Defense
    2026/09/22

    Max Pollard, CEO and co-founder of Cotool, joins us to talk about what it actually takes to let blue teams respond at machine speed. Cotool builds agents for detection and response, and Max walks through the crawl, walk, run progression his customers follow: start read only, route every consequential action to a human through an approval hook in Slack or Teams, count how often the agent was right, and only then loosen the leash. His honest read is that very few teams reach the run phase, because humans can't trust agents enough to take themselves out of the loop. We get into why the real blocker is less about trusting the model and more about data annotation, and whether the agent knows at runtime that the server it is about to contain powers a million dollars a day in transactions. Max also covers how Cotool scopes agents at the API endpoint level at config time, why the audit log has to record that an agent acted and on whose behalf even when no human prompted it, and how his team evaluates cost efficiency, instruction adherence, and behavior across 20, 30, or 40 agents running in production.

    続きを読む 一部表示
    45 分
  • Security Will Always Lose If It Gets in the Way: Joel de la Garza (a16z)
    2026/09/16

    Every security leader knows that developers will work around security tooling when they can if it gets in the way of their job. The truth is, employees don't get paid to be secure; they get paid to do their job.

    Joel de la Garza, partner on the infrastructure team at a16z and former CISO of Box, tells us that the moment security gets in the way of what people want to do, security loses.

    For a lot of teams, this has meant tolerating uncomfortable security gaps to get the value agents can bring. At Keycard, we call the underlying bind the trilemma of autonomy, capability, and security: teams can only pick two.

    Joel walks through what securing agents looks like in practice, from a consumer agent logging into an auction site through a browser with every alarm bell ringing to a16z's own coding agents opening tunnels out to Cloudflare to route around egress controls in a secured GCP cluster.

    We get into why least privilege and agent performance pull against each other, and why some of security's first principles have to be rethought rather than reasserted. We also talk about the pressure CISOs face as they're expected to say yes to agents and lead the agent rollout.

    Joel also shares his love for Grok Bot and the need for model providers to give blue teams the same advantages attackers now have.

    続きを読む 一部表示
    49 分
  • "Is This Tool Call Allowed? It's Never That Simple": Michael Davis (J.P. Morgan)
    2026/09/09

    Most people that architect an AI agent think to ask a binary question: is this tool call allowed, yes or no? Michael Davis, Global Chief Security Architect at J.P. Morgan, argues it's never that simple.

    He walks through the four dimensions robotics uses to decide whether it is safe for an arm to move (the state of the system, the state of the environment, the quality of the decision-making, and the uncertainty of the action itself) and maps each one to agents: did the agent gain tools or network connections it did not have before, is it still moving semantically toward its goal after 30 tool calls, and what has the agent already tried.

    We get into why  if you think you need memory, you're probably not thinking of your problem the right way. We also explore software factories and why they need to operate as a  cumulative progressive process versus a one shot of go build me this SaaS. Over the course of the episode we piece together what a good reference architecture for agents could look like.

    続きを読む 一部表示
    46 分
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません