NETWORK SECURITY
Like it always is with technology and humans, we have a tendency to innovate first and ask questions next. The internet, email, the cloud, IoT – they were all widely adopted when the flaws and security concerns garnered attention. And just like that, the agentic era is now upon us and we seem to have some interesting questions. Important questions, in fact – how do we control these non-deterministic actors, what does autonomous security and governance look like and, at the end of the day, who should be held responsible for rogue AI?
Venturing educated answers to these complicated queries are 1Password CTO Nancy Wang; SVP of Tenable Jason Merrick; Mayank Upadhyay, Chief Security and Trust Officer at Snowflake; and Mayank Agarwal, Founder and CTO of Resolve AI. The venue is Snowflake Summit 26 in San Francisco, California, US, and the answers we seek are from The Future of AI Security and Governance media panel.
Mayank Upadhyay opens the conversations by setting the scene.“ When you go back three years, if you’ re an engineer building something, you know exactly how you’ re going to connect APIs across two different systems,” he says recalling the hardcoded, structured interactions, each of which were visible, mapped out and predictable in comparison to the unpredictable nature of the agentic world where the agent“ wires this up on the fly”.
“These agents are a little bit like interns”
Mayank Upadhyay Chief Security and Trust Officer, and Vice President of Engineering Snowflake
“ You give it [ the agent ] a call and say, solve this problem for me. It goes out there and tries all the paths that it has access to because it’ s inheriting your permissions. And this creates a lot of problems,” Upadhyay points out. The first of which, he says, is“ talking to tools which are capable of doing things on your behalf”. These tools are capable of exfiltrating data – maybe even through accident, by using a tool or by writing it down in a place it really shouldn’ t.“ Or maybe it brings down a production service. There’ s all sorts of dangerous actions that could happen,” Upadhyay points out.
“ These agents are a little bit like interns,” he says.“ You give them a credit card, you say,‘ Hey, go buy me this shoe.’ And before you know it, it’ s bought you a car!” Upadhyay says that we can’ t simply plead“ with an agent to stay on the straight and narrow line”. Instead,“ you have to put these ironclad constraints around it to limit what it’ s able to do”. This is where he notes the ideas around identity and permissioning become“ really, really important in this new agentic world”.
cybermagazine. com 107