john-laliberte.jpg
Operational Resilience
Risk Management

Nexus Podcast: John Laliberte on AI and Non-Human Identity Controls

Michael Mimoso
/
Aug 5, 2026

LAS VEGAS — One of the overlooked artificial intelligence (AI) cybersecurity risks is the rampant acceleration of non-human identities being autonomously created by AI agents that are piling on top of agents already in environments via AWS, Google Cloud, and other services. 

“What we're seeing is this explosion of these autonomous agents that can create other agents, can create new identities,” said John Laliberte, CEO and founder of ClearVector, on the latest episode of the Nexus Podcast, recorded at Black Hat. “So it creates this problem for the traditional way that we think about protecting corporations where you know everything's been built for humans.”

Laliberte said that nine of 10 identities in enterprises are likely non-human, including AI-created agents and identities that are credentialed. This type of sprawl is a consequential issue for companies that lack visibility into this activity and appropriate guardrails around these agents, Laliberte said. 

AI Guardrails an Indispensible Control

“Everything is moving so fast that what companies are really looking for is what we're calling guardrails. How can you allow people to move fast with agents, but also make it so agents can only do what you expect them to do, or at least have kind of a bounding box around them? Laliberte said.  

Provisioning access to non-human identities, he said, creates a set of challenges in understanding at machine-speed whether an agent or [an adversarial] human is performing an action. 

“I think the challenge that we're seeing there is, if you're just somebody that works at a company, you can just give your credentials to an LLM or an agent and it's gonna operate with your credentials, right? Sure. And so that's where we're trying to figure out like, hey, is the activity that we're seeing from this identity still human?” Laliberte said. “Or do we think an LLM is operating with that human's account and it's actually AI behind the scenes?”

CPS Risks from Non-Human Identities

Cyber-physical systems (CPS) have particular challenges around non-human identities given the complexity and proprietary nature of operational systems. An AI agent cut loose on an enterprise network can, at machine-speed, reverse-engineer firmware, find and exploit vulnerabilities, and create downstream identities in order to access production environments. 

“I think it's the same concern. I would say it's more acute,” Laliberte said, adding that organizations need visibility and detection capabilities to understand whether a human has credentialed a large-language model (LLM) or whether an external agent has breached a system. “AI agent detection: Can you actually find that there's something operating like an AI agent on your OT networks? I think it's not a harder problem per se, but it's something that if you have life and limb type concerns, it's something that you should definitely focus on.”

Episode Transcript with John Laliberte

Mimoso 0:15

Welcome back to the podcast. I'm Black Hat. And this week I'm going to be talking to some pretty cool people all week and bringing you those conversations. So subscribe if you haven't already. John La Liberte is my guest. John is the CEO of ClearVector, and I got a few things to ask him about identity-driven attacks and how non-human identities need to be managed. And we'll talk about some threats that are going on out there. So it should be a fun talk. How are you doing? Good to meet you. Yeah, nice to meet you as well.

Laliberte 0:43

Excited to be here. Back at Black Hat, huh? I know. It's been many, many years coming here. It's changed.

Mimoso 0:50

Me too. And uh, I don't know. I'm I'm to the point where seeing faces and people that I don't see very often are kind of the best part. Same page.

Laliberte 0:57

It's uh just catching up with old friends and seeing what people are working on. And yeah.

Mimoso 1:01

So tell me a little bit about your company before we get started. Yeah.

Laliberte 1:04

So uh I started the company a few years back, uh, really to solve a problem that I had myself at the previous company. So I was at Mandiant and FireEye for 12 years, building security products, helping build the tools for the incident response team, and trying to defend a very large cloud environment, an on-prem environment that we had. And part of that I was at NSA doing some some cool things. And so one of the top challenges I had was um trying to protect this large cloud environment. And one day I had somebody on my team actually share credentials with another person, and then they accessed one of our very high security uh product environments. And so that caused a whole bunch of things, but it really got me thinking about identity. And you know, when I knew it was time to go start something new and be innovative and do all these cool things again, I said, hey, we need to reimagine how people think about protecting themselves from the adversary, right? Because for years and years we've you know created all these indicators of compromise, we've created these standards, you know, we've been on this hamster wheel of pain chasing the adversary, right? And we're always behind. And so the idea with ClearVector is, hey, can we build this live operating model of your entire company, your environment, based on all the identities that are in there, whether they're AI, human, non-human, third party, and then build these predictive behavior-based models and defenses based on that? So you're not in this hamster wheel chasing after the adversary, you're actually using your own data to model and protect yourself.

Mimoso 2:20

So obviously the AI data, I mean the AI identities, the non-human identities, very relevant right now. Is there a comp to you know something that was happening five years ago around identity in that respect?

Laliberte 2:33

I don't think so. Like what I think you know the AI cycle that we're seeing now really with agents, right? We first saw our own customers deploying agents in Q3, Q4 of last year, so 2025. And what we've seen in the first three quarters of this year is just an explosion of agents being deployed into production environments. So think like AWS, GCP, GitHub, you know, Azure, Entra, Okta, connecting all these things together. And so what's we're seeing is this explosion of you know these autonomous agents that can create other agents, can create new identities, and so it creates this problem for you know the traditional kind of way that we think about protecting corporations where you know everything's been built for humans. Right? If you think about, we just released a report actually where we said 91% of identities in production environments are non-human. And we consider AI identities part of the non-human chunk, right? And uh, if you think about all the dollars, you know, if you take the whole budget of security and you say how much of that is invested in protecting humans at companies, it's almost a hundred percent if you ask most companies, right? It's corporate laptops, it's your endpoint security, posture, vulnerability management, and things like that. And so I actually don't think there's a good analog um in the past because non-human identities really have come about because of the move to the cloud, the hyperscalers, and now with AI you have these autonomous identities that are able to do things.

Mimoso 3:52

So, I I mean, how common are these non-human identities, as you as you guys put it, and you know, what's the current reality in terms of what organizations are dealing with, or you know, how aware are they of this that this is happening?

Laliberte 4:04

It's extremely common. So basically every single company has some kind of footprint in a hyperscaler. And if you are in a hyperscaler, you have a lot of non-human identities, period. Now, whether you have visibility into what those identities are doing is typically a separate question, right? And a lot of people find out in a breach situation, right? Even just today and late yesterday, there's yet another supply chain attack where a developer's credentials were stolen, uh, backdoor put into an NPM package, and then subsequently a worm type propagation um, you know, is occurring as we're on this podcast, right? And it's just the latest in many of these identity-driven supply chain attacks uh that we're seeing. And so this really touches every organization. So, you know, even if you don't have a developer, you probably have a system admin or a cloud, you know, security engineer that has admin access to your production environment. And those people are targeted for those credentials, right? It's much easier for an adversary to just say ride over an existing session or you know, steal, you know, the credential, the access key, whatever it is, and access versus exploitative vulnerability, even in the age of AI being able to auto-create, you know, exploits and things like that.

Mimoso 5:11

So the the autonomous identity creation, um, is that a byproduct? Is that intentional? Is that how the systems are built to work?

Laliberte 5:21

I think it depends on what system uh you know you're talking about. I think the main thing we're seeing with AI agents is you know, one of the things that we do at ClearVector is be able to attribute activity to identities, whether that's AI, human, non-human, third party, et cetera. But the interesting part is kind of goes beyond attribution and it's more of a human question. You know, you started the we started this talk talking about how how interesting it is to talk to people instead of computers and come to conferences and things like that. And that's actually the big thing that we're seeing is someone will have an AI agent, they you know built it for a particular reason to go help them do something, but then it does something like make all your GitHub repos public, or it goes and you know, finds out you have passwords in your you know, keychain or one password vault, and it dumps the vault and then goes and does something else, right? And then your box might be contained by your endpoint security product, right? And so there's kind of this these unintention kind of unintended consequences, and what we see our customers wrestling with is not so much the technical challenge in a lot of ways, it's what do you do after. So after we say, like, hey, it was this developer's agent that did this thing, then it's a question of like, well, you know, do you write them up, do you put something in their HR file, do you have a conversation with them? Like, are they truly responsible for what the AI agent did on their behalf? And so that's kind of the the kind of bleeding edge conversation that companies are having who have adopted AI and have AI agents running. It's yes, you're gonna do all the security stuff and do the attribution back to the originating identity, but then it's like something will happen. And then it's like, how do you deal with the accountability after the fact?

Mimoso 6:54

And is it an over-privileging discussion at that point? Like how are privileges kind of extended to these agents and are you know, are there controls in place? Is there oversight?

Laliberte 7:06

Depends, right? And this is the big conversation today. Everything is moving so fast that what uh companies are really looking for is what we're calling like guardrails, right? Um and guardrails in the sense of you can almost think about it if you've ever gone bowling, right? And you think about like putting up kind of the bumper rails, right, where you can't get the ball into the guard. Kind of the same thing, right? Like, how can you allow people to move fast with agents, but also make it so agents can only do what you expect them to do, or at least have kind of a bounding box around them. And this is where we see some of the uh IDP vendors, right, like Okta and Antra, trying to say, like, hey, well, we've we've kind of had this idea about humans in an IDP for a long time, but non-humans are not in your IDP, right? They have direct access to these environments, and so now we're seeing some codification by the IDP vendors to say, oh, you should also provision your non-human identities or AI agent identities inside of your IDP so you can start to apply the same type of policies or guardrails that you would around your humans. I think the challenge that we're seeing there is number one, if you're just somebody that works at a company, you can just give your credentials to an LLM or an agent and it's gonna operate with your credentials, right? Sure. And so that's where trying to figure out like, hey, is the activity that we're seeing from this identity still human? Or do we think an LLM is operating with that human's account and it's actually AI behind the scenes? So that's some of the stuff that we actually do today in our product, so that you can kind of see, like, wait, this was a human kind of doing click-offs, all of a sudden it's now LLM activity. So is that an adversary doing that, or is that you know, a person who actually delegated, you know, to an LLM to go do a task for them.

Mimoso 8:42

I mean, it sounds like a very thick layer of complexity there.

Laliberte 8:45

It is, yeah, yeah. It it is very interesting though. I think it's a new world, and even for security, you know, in the past, if you think about session reuse or you know, that was generally speaking always not a good thing. But now if you look at how AI operates, it's like, well, giving your credentials and API keys to an agent is a business enabler, right? It helps you get more things done faster. Whether we say that's a good thing or not is a separate conversation, but you know, that becomes a normal thing. Whereas, you know, sharing your credentials in the past with software or a human, every security person would say, like, don't ever do that. Right. But now that's the norm for an AI agent.

Mimoso 9:21

So I mean there's some sprawl there in terms of the number of identities you have to manage or at least have some visibility into.

Laliberte 9:28

Yes, yeah. So it's basically this, you know, if you think about uh what we found in our report that we just released is if you take the total universe of identities at a company, you know, you can kind of say like, you know, more or less 10% of your identities are gonna be, you know, human and the rest are non-human. And so if you think about like a thousand-person company, right, and you do the math on that, there's a huge number of non-human identities that you need to think about from a security perspective. And I would argue have access to the most important data in your company, right? Because that's how you make your money as a business. That's directly tied to your top line revenue, is that customer data that you're protecting. Yeah. And those non-human identities typically have direct access, you know, to that high-risk data.

Mimoso 10:10

So I I was gonna ask though, are there like maybe you can talk about some of the risks involved in terms of the autonomous actions or at least autonomous um identity creation, like generating their own tokens. I saw that that was part of of the report. Um maybe you can clarify kind of what's happening there.

Laliberte 10:28

Yeah, think about it as when you give an agent a direction to just say, like, hey, I want you to go do this for me from an outcome perspective. Sure. Um, this is where that guardrails concept comes in, right? Because a lot of times people just say, hey, go do this for me, but they don't specify like, well, here's kind of how I want you to go do that. And a normal, even if it was like an intern or somebody you hired, they would kind of, you know, before they do certain things, they check in with you and they'd be like, hey, I'm about to go do this thing. Is that okay? Is that aligned with policy, right? And so that's the part where I don't think yet as an industry or even as the world or even as the AI vendors, we've really figured out what is how do we actually tell an agent like, please go try to do this thing, but only do it kind of according to this or according to the company's policies, or hey, check in with me before you go do that thing. And I think we're just at the early stages of that. So tying that back to your question about like autonomous identity creation, I think most security people would say, well, that should never happen. But the challenge is now, especially if you think of an attacker, like they actually want to create new identities, right, as part of that, because it makes it difficult to track, you know, the subsequent activity by each identity. And so I think we're still at the very early innings of what that means. Yeah, but I think if you look at some of the very, very kind of bleeding edge, cutting edge research that people are doing with swarms of agents, those agents are gonna create their own sub-agents that do all kinds of things. And so just like with drones, you know, how it started off we have one drone and now we have you know swarms of drones, same thing with AI, right? It's gonna be to the point where you can't kind of point to each thing and create a policy for it. It's gonna have to be software that goes in and and kind of really sets those policies in guards.

Mimoso 12:09

Does the sprawl negate any kind of controls that maybe work today but just won't work tomorrow? Like, you know, a comp like to 2FA or something like that.

Laliberte 12:17

Yeah, I think a lot of the kind of off N and off Z kind of controls are gonna have to be completely rethought because uh, you know, at the top of the the podcast, we talked a little bit about how all the security investment has been for the corporate side.

Mimoso 12:30

Right.

Laliberte 12:30

And if you think about a corporate side, right, it's like you started a company, you get issued a laptop, you keep the laptop for two years, right? You get your ID, password, MFA tokens, and you keep that for again two years or more, right, for however long you're at a company. So if you think about the velocity or the rate of change, of how often do those things change for a human, not very often, right? But when you think about the ephemerality of hyperscaler environments and things like that, it's on the orders of seconds to minutes, right? And then you've got the developer, you know, development team, engineering team shipping stuff, and so the rate of change is just immense. And so the challenges that creates is you know, everyone's racing to kind of make everything work, and security is, you know, not the first thing that people are thinking about. So yeah, I think there's a lot of challenges because all of our controls are designed for that kind of slow-moving environment of like, hey, people have the same thing for years, and in this case, we're talking about like seconds, things that are ephemeral. Yeah. You know, you may have something pop into existence for a few seconds and then never show up ever again.

Mimoso 13:31

Can any of this be leveraged in attacks, for example? I mean, or you know, a validated identity creating malicious prompts, stuff like that. Just I mean, is that is that on track?

Laliberte 13:41

Maybe I'll answer maybe a slightly different question, or maybe it's the same question in terms of um attackers are absolutely going to use this, right? So if you think of what is the adversary trying to do, right? Part of it is obfuscate what they need to do with valid credentials. And so that's exactly what we're seeing, right? Is in terms of if you can take a valid identity, right, and you can ride over an existing session, that's much harder for defenders to find, right? Because typically, you know, it'd be a vulnerability with an exploit and it's very kind of loud on the network. But when you're operating with valid credentials, um much harder to find that particular uh individual. So shadow AI is that is that what we're talking about at the end of the day? Partially, yeah. I think shadow AI is a top concern, right? Because it's uh like one of the things as an example that we find is you know, you might have a bunch of Kubernetes clusters, you know, in your production environment. And right now what we do is say, like, hey, are any of your containers or Kubernetes clusters talking to anthropic? Are they talking to cloud? Are they and you know a lot of times people don't know, you know, is it talking outbound to these, you know, bedrock, vertex, whatever it is? And um just understanding like, are we using AI, whether it's truly shadow AI authorized or unauthorized, um, that's a top question that everybody has. And then there's a much bigger question on the corporate side and you know, the analog kind of whole of like, hey, are people taking corporate data and putting it into um non-commercially licensed AI products? And um, I was actually on the Hill a few weeks ago um talking about what legislation you know might be passed with these different models. And if you think about like non-US based models, meaning you know, ones developed outside the US that are not, you know, and even local models, right? In terms of how would you even know that, you know, this piece of software has maybe a local model operating um that doesn't have any controls. Right. So we talked about guardrails earlier, like you know, there's there's a school of thought that all these models are gonna be um kind of there's gonna be nothing controlled, you know, kind of with kind of the bumpers on them, right? And so that's what everyone's gonna move to, both for cost reasons as well as uh for capability reasons, because they can just do more.

Mimoso 15:50

So in terms of controls that would be effective, I I imagine you gotta start with some sort of visibility into this whole kind of dynamic. What what does that look like and how difficult is it to kind of achieve or at least have that kind of visibility you need?

Laliberte 16:05

Yeah, so really it's kind of basics, right? So you gotta have a product piece of software that can plug into your environment and number one, start looking at all the activity. And the important part is like a lot of people in the space think, oh, I have an inventory tool, right? It tells me about all my identities. Now, the challenge with that approach is um number one, we talked about the ephemerality of all these identities kind of popping into and out of existence. So you need something that looks at something as everything happens. So it needs to be kind of streaming, runtime-based. You also need something that's aware of trust relationships, meaning, like, if you think about federation, whether that's from like an IAM identity center, an Okta, an ANTRA, uh, whatever your IDP is, in the production environment, you typically just say, like, hey, we trust anyone coming from this particular IDP. And so you need a piece of software or something that can understand, like, hey, there's a trust relationship and a new identity just popped into existence here, right? And so you need to number one be able to see all that, and then you can start thinking about future controls like how do you do detection and governance and guardrails and all the other uh things from there.

Mimoso 17:08

So, what about something like zero trust? Is there any applicability in in this respect?

Laliberte 17:13

There is. I my first question back, um, you know, half joking, is like, what is your definition of zero trust? Because I'm not sure anyone knows what what exactly that means. But I would say I'll trust your definition. Yeah, I would say like from a uh from an identity perspective, the way I think about it is um really if you think about authentication, it should be continuous, right? And I think we've made some progress as an industry where we've said like, hey, authentication is not just something like you know, something you know and your username or something like that, right? You've got to have like MFA or something else. Sure. But still that's kind of very close to the point in time when you authenticate. And so now you fast forward, right, and we've got like conditional access in some cases and things like that, but it's still very much point in time. And I think our approach to this problem is really more of that continuous authentication, and that that starts to blur the line between like you know, the traditional detection kind of mission from a security perspective, but I think we're seeing the blending together of IAM and security, right? Like those few those kind of realms have typically been separate at most companies, and I think we're gonna see all that come together, uh, probably because of AI and non-human identities, because it's gonna force those teams to meet in the middle and say, like, hey, we can no longer just have like our identities in a kind of static IDP. We're gonna need to look at this from like a runtime visibility perspective and dynamic, you know, trust relationships in order to reason about risk from an identity perspective.

Mimoso 18:35

Are there competing incentives when you get to that point? The identity people want this, the security people want that, the business people want something else?

Laliberte 18:43

It's a great question. I actually think it's I I kind of think of it in terms of complementary, right? It's sort of like um I think everybody should be operating off of the same kind of shared data set, right? And everyone just has different questions that they want to ask, right? Because a lot of companies, you know, you'll have the IEM team and they'll have their own products around the IGA and PAM and all that. And then you talk to the security team and they're like, well, we kind of have different questions, and we're trying to just, you know, kind of put everything in a sim and then kind of like ad hoc ask questions about it and and things like that. And so um, so I think it's more complementary, and I actually think all of that software and data should be kind of common to both teams because people are trying to ask the same, you know, questions of the same data, but they kind of live in different silos today. Right. So, you know, if it was me waving the magic wand, I would say, hey, there's like one kind of system of understanding, right? Um, and everyone can just ask questions off of that.

Mimoso 19:37

So just a question specific to probably the majority of my listeners who are working operational technology, cyber physical systems, whether it's in manufacturing or hospitals or um mostly industrial, but just how different is this conversation with those environments? Because they're very complex, there's a lot of proprietary technology there, protocols over which they communicate, et cetera. What's your experience in that respect?

Laliberte 20:03

I would say it's probably um more difficult to protect in a lot of ways with AI because um, for better or worse, when you think about a hyperscaler, every single action is mediated by some type of authenticated session for the most part. So you, you know, it might be complicated, but you should be able to always track it back to some type of trust relationship, identity, et cetera. Um when you think about you know kind of traditional OT, IT networks, and things like that, a lot of it's embedded software. And are humans graded in you know understanding firmware? No. Guess what it is? AI, right? So it's like imagine you know, you say, hey, you let this AI agent loose on a network and you say, like, hey, try to go do something and or get into a particular environment. For me, that's actually kind of a scarier situation than a production environment because you know that's kind of a proprietary thing that I think AI is actually very good at understanding. Because it can go grab the firmware, it can reverse engineer it, it can find vulnerabilities, it can then create downstream identities right on whatever system it needs to, it can then write the exploit, you know, to get onto the actual box, you know, laterally move across, you know, into your OT environment, it'll understand the wire call, it'll read all the manuals, right? Understand how to send you know commands to like your smelter. Yeah. Or, you know, your yeah, your your scanner, right, that's in a hospital. So uh so I think it's the same concerns. I would say it's more acute. So I would say understanding whether your humans have given their credentials to an LLM, and do you have an LLM? So meaning AI agent detection, can you actually find that there's a something operating like an AI agent on your ITOT networks? I think is uh almost a it's not a harder problem per se, but it's uh you know, it's something that if you have you know life and limb type concerns, it's something that you should definitely uh focus on.

Mimoso 21:51

Sounds too like there needs to be a lot of policy or rethinks at a at a minimum. Is that what you're hearing or seeing as well in terms of when you say policy, yeah, do you mean like Sketching out, you know, who gets what in terms of identity and and I I think that is gonna be the biggest discussion.

Laliberte 22:07

I think we're still at the the kind of beginning of what I'll call like um unauthorized use of AI activity, right? We've seen some like we talked about the NPM, you know, thing that's happened even today, right? That happens every week now, right? Developers' identities being compromised. But I would still we still haven't seen that like watershed event because of this, and I think that that's gonna force for many companies that conversation around like AI governance, how do we think about identity, you know, over provisioned identities and things like that. So we definitely are overdue for like how do we think about policies? Because it's not that like kind of hey, you get this identity, you get this policy, and you can keep it for three years. Sure. Because as soon as you give your credentials to an LLM, it's gonna use the the full extent of the policy that you know uh that it has access to.

Mimoso 22:57

So I guess that leads into the next question is like how well versed are the policymakers in in AI and and the consequences and the potential of it to, you know, act craft what they should be crafting.

Laliberte 23:09

What I can say is from last month when I was there, I would say I was pleasantly surprised, right? Because I think all of us that sit outside of like government circles kind of think like, hey, there needs to be a lot of education and stuff. I would say uh even when I was there, I was actually very surprised that you know they're getting regular briefings from the AI specific companies, legislation's in flight, um, you know, we've got pretty technical, actual like representatives and senators who understand kind of the the I don't know what the right word is, but like the consequences of what might happen. So I actually think in this case, you know, usually legislation like trails and policy from a political perspective trails the technology by decades. And I would say in this case, I again I I don't see that. It seems like everyone's very in tune to like this is this is like a very big deal and kind of like a watershed moment for the world.

Mimoso 23:59

So how about inside the enterprise in terms of you know, are we at an evangelizing phase right now around this stuff?

Laliberte 24:06

Or what we're seeing is uh right now people are adopting AI at different rates. So you kind of have companies that are very conservative who are saying, hey, like we're gonna take a slow pace to adoption and they are really good at communicating that. And then you have companies that are on the edge who have been, you know, full on adopting everything, and their policy has been, hey, we're just gonna accept the risk, right? We want our company to move as fast as possible, we want our people to use AI as fast as possible, and we'll handle kind of the consequences after the fact. And then there's every kind of company in between. And so I it's not kind of one answer for all the different types of companies. Um, but I do think even the most conservative companies, um, if they haven't already, it kind of within a year, there's gonna be some type of AI use um at those companies as well, simply from the products that they buy. Like as an example, one of our customers, their biggest concern is their vendors start delivering whatever service or product using AI and don't tell them. Uh and then that means you know the representations they make to their customers about how you know the data's being used and stuff is, and so that's the kind of thing where, yeah, even the most conservative companies, they're gonna have to deal with it even with their vendors.

Mimoso 25:20

So, just as a last question, I want to ask you about the open AI hugging face incident, because it's still kind of fresh. Um just curious how your thoughts on what happened and how would some non-human identity controls helped, if at all, in this case.

Laliberte 25:35

Yeah, so I think that that incident, right, and going by what's in the news and things like that is kind of what we should expect to happen.

Mimoso 25:43

Right.

Laliberte 25:44

Right? Um, if you think about the top AI companies on the planet having that problem, uh imagine, you know, with their security teams and the investments that they have in security, imagine, you know, kind of the open weight models that don't have the guardrails and there is no security team, right? It's somebody just kind of at a company saying, hey, I want to go do this fun thing. Open source software all over again. Yeah, and you know, you might remember back to the days of you know SQL Slammer worms and things like that. Like I feel like uh many of us were around for that, uh, but I think many of us were not, right? And so I think we're kind of entering an era where that could happen again in a kind of scarier way because it's not just like you know a human programming it, you can actually make a kind of autonomous agent to go do something. And so I think that incident in particular is we're gonna see more of that and possibly with bigger impact uh simply because of you know the controls that were there, right? And so I with that said, there still need to be additional guardrails in place, right? Like something like that can't happen unless unless it's authorized.

Mimoso 26:47

Right.

Laliberte 26:47

And so that's where that whole discussion we had on policy and guardrails and how we think about you know policies and designing it, um, you know, because I think designing it into the model, which is one approach people are taking, well, there's gonna be other people who don't build it into the model, right? And so we can't rely on necessarily the models themselves to govern themselves.

Mimoso 27:08

So all right, John. Thank you so much. Great stuff. I appreciate it.

Laliberte 27:12

Thanks for having me.

Operational Resilience
Risk Management
Michael Mimoso
Editorial Director

Michael Mimoso is Director of Influencer Marketing at Claroty and Editorial Director of Nexus.

Stay in the know Get the Nexus Connect Newsletter
You might also like… Read more
Latest on Nexus Podcast