Why I Dont Trust Your AI Agent | Kane Narraway, Canva

Why I Dont Trust Your AI Agent | Kane Narraway, Canva

With over 200 AI security vendors in the market, how does an enterprise CISO decide whether to build a custom solution, buy an off-the-shelf product, or just wait out the hype?

In this episode of the AI Security Podcast, Ashish and Caleb are joined by Kane Narraway, Head of Enterprise Security at Canva, to debate the realities of AI security in modern enterprises. Kane breaks down why simply sandboxing AI agents doesn't work for workforce productivity, explaining that an overly restrictive sandbox renders an agent useless because it inherently needs access to external files and databases to do its job.

We dive deep into the "Confused Deputy" problem, the struggle of granting granular least privilege to AI tools (like letting a bot summarize only Caleb's emails), and whether the old-school concept of network proxies is about to make a massive comeback as the ultimate control layer for AI routing and authorization. Finally, Kane shares why he believes the scariest near-future threat isn't malware, but contractors utilizing "Bring Your Own Agent" (BYOA) in enterprise environments.


Questions asked:

(00:00) Introduction to AI Agents in the Enterprise(01:50) Kane Narraway’s Background (Digital Forensics, Atlassian, Shopify, Canva)(02:50) The Build vs. Buy Debate in the Era of 200+ AI Security Vendors(09:00) Using Wrappers and Harnesses to Control Vendor APIs (Island Browser Example)(11:00) Why GitOps and PRs are Better for AI Configuration than MCP Deployments(13:00) The "Confused Deputy" Problem: Single-Player vs. Multi-Player AI Bots(16:50) How to Handle Agent Identity: "On Behalf Of" (OBO) vs. SPIFFE / NHI(22:50) Why Sandboxing AI Agents Fails for the General Workforce(28:20) Intent-Based Security and the Lack of Granular Access Controls(29:40) Are Proxies the Next Gen Firewall for AI Agents?(34:00) The Terrifying Future of "Bring Your Own Agent" (BYOA)(38:50) The "Gravel Road" Strategy for Managing Shadow IT and Vibe Coding(42:00) Dealing with Vendors Trying to Exploit Shadow IT Land Grabs(49:30) What Security Leaders are Over-Indexing On (Discovery vs. True Access)(50:40) The "You Laugh, You Lose" Cybersecurity Joke Challenge


Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(58)

Baiting the Bot: How to Use Deception to Stop Autonomous AI Agents

Baiting the Bot: How to Use Deception to Stop Autonomous AI Agents

When AI agents start swarming your enterprise, they won't care about stealth. They will land a beachhead and instantly spawn 500 agents to crawl, probe, and exfiltrate data at machine speed. Is your d...

23 Jul 51min

Why AI Agents Are Forcing a Redesign of Application Security?

Why AI Agents Are Forcing a Redesign of Application Security?

When the CEO of Anthropic declares that human coding will disappear within six months, followed quickly by the death of software engineering itself, what does that mean for the future of cybersecurity...

26 Jun 51min

Why Asset Intelligence is Replacing the CMDB & Static Dashboards

Why Asset Intelligence is Replacing the CMDB & Static Dashboards

Why do CISOs still struggle with asset intelligence in 2026? Despite decades of security tooling, most organizations still have a massive 40% "dark matter" blind spot in their environment and the expl...

11 Jun 42min

The AI AuthZ Problem: Why Human Least Privilege Fails for Autonomous Agents

The AI AuthZ Problem: Why Human Least Privilege Fails for Autonomous Agents

Why are security leaders terrified of connecting AI agents to production data? Because unlike humans, AI agents don't apply judgment, and they operate at machine speed, meaning they can relentlessly h...

4 Jun 47min

Securing AI at the Speed of Engineering | DoorDash | Forward Deployed Security | GRC Engineering

Securing AI at the Speed of Engineering | DoorDash | Forward Deployed Security | GRC Engineering

Is your security team moving at the speed of your engineering team? In this special live recording of the AI Security Podcast from San Francisco, Ashish is joined by Nick Reva (Global Director, Engine...

21 Mai 1h 3min

Verification vs. Validation: How Autonomous AI is Changing Cybersecurity

Verification vs. Validation: How Autonomous AI is Changing Cybersecurity

Are autonomous AI agents operating unchecked in your enterprise? With the release of open source frameworks like OpenClaw, deploying an AI agent is now as simple as texting, but it comes with massive,...

13 Mai 1h 10min

The Zero-Click AI Hack: How to Contain the Blast Radius of Autonomous Agents

The Zero-Click AI Hack: How to Contain the Blast Radius of Autonomous Agents

Is an AI agent's identity a workload or an action? Ashish spoke to Elie Bursztein, Distinguished Research Scientist and co-author of Google SAIF (Secure AI Framework) about how it is neither and that ...

29 Apr 47min

Populært innen Teknologi

lydartikler-fra-aftenposten
teknisk-sett
tomprat-med-gunnar-tjomlid
smart-forklart
elektropodden
rss-ki-praten
fornybaren
shifter
rss-ai-forklart
teknologi-og-mennesker
rss-bouvet-bobler
rss-alt-som-gar-pa-strom
rss-kunstig-intelligens-med-elisabeth-maren-og-morten
nasjonal-sikkerhetsmyndighet-nsm
rss-fisketimen
rss-alt-vi-kan
rss-polypod
digital-forretningsforstaelse
energi-og-klima
rss-nkom-innsikt