Skip to main content

Alex Bovee

Sep 30, 2026

12:22
I know Jim wants to talk about Hugging Face, but I want to ask you just kind of one question around this idea of AI agents, and maybe for people who haven't gotten, you know, neck deep [chuckles] or deeper into this sort of world, how would you-- If someone says, "Okay, what's the difference between an AI agent and, like, a service account or some other sort of traditional things that have defined permissions versus what an AI might have?" How do you, you know, make that g- I guess, make that case or make that argument or the explanation to people who are struggling to understand what the difference is?
12:52
Yeah, I think the, the most simplistic way I sort of think about the difference between humans, applications, agents, and agentic workloads is really, uh, there's two dimensions.
13:03
One is, uh, trustworthiness and then determinism.
13:07
And so, uh, if you look at determinism, uh, you know, there's two dimensions to that, non-deterministic and deterministic.
13:14
And if you look at, let's just pick on humans for a second.
13:18
Humans are non-deterministic, but I would argue generally trustworthy, meaning we all have reputations.
13:25
We don't want to get fired.

13 MINS LATER

26:53
[laughs]
Mr. NHIHOST
4:12
Okay, and do you think, um, agentic AI security equals NHI security?
4:17
Um, not necessarily.
4:20
I, I mean, look, NHI is kind of one of these terms that, um, means different things to different people, and you probably get five different, uh, definitions of it depending on who you ask.
4:31
You know, some people, when you talk to them about NHI, they think service accounts.
4:35
Some people, when you talk to them about NHI, they think keys and tokens and API keys.
4:40
Um, but I think, uh, agentic identity really is i- its own, um, set of identity problems from kind of, you know, delegated authorization on behalf of a user for personal productivity agents.
4:56
Um, you know, SaaS or infrastructure enterprise agents really have their own kind of service account and, um, like standalone identity th- uh, upon which you need to, like, authorize their activity and authenticate them.
Mr. NHIHOST
5:41
Now, do you think AI agents behave more like employees or software, to your earlier point?
12:25
Okay, so look, uh, we're now gonna be talking about, you know, the, the main focus in this podcast, right, which is identity is the third generation of security, right? So when we talk about that, like, you know, what were the first two generations? What defined them, and why have they now reached their limits, uh, and now s- being surpassed by identity as the third generation of security? Do you wanna share a center?
12:52
Yeah, the first gen- yeah, the first generation I think of is very much was network-centric security.
12:56
Um, and that was because of the traditional kind of corporate IT infrastructure was very on-prem focused.
13:04
You know, people, uh, came into the office every day.
13:07
Everyone was in the office.
13:08
There was, um, a network infrastructure that surrounded the digital enterprise and kept the bad guys out and kept the resources in, and we layered a lot of technologies into the network.
13:19
Um, DLP, egress firewall, um, uh, you know, um, subnets to be able to restrict access to different applications.

21 MINS LATER

34:55
What are you doing at C1? What are some of the capabilities that you're building into your, your platform?
6:09
Tell me more about this rise of the agentic enterprise that we're seeing.
6:14
Yeah, I mean, I think we've gone through and, w- well, we've done...
6:18
We've gone through the agentic transformation ourselves at C1.
6:21
We've built a cloud-based software factory.
6:25
We have a platform for hosting internal Vibe Coded applications.
6:30
Uh, we encourage our team to use AI tools.
6:32
We use our own products internally to enable our team to adopt AI MCPs, uh, and tools and automate, um, you know, manual processes.
11:07
Yeah
6:32
So how do our underlying access architectures have to evolve to verify trust in a world where, frankly, seeing is just no longer believing, isn't it?
6:43
Yeah, I remember a year ago, there was multiple examples of I think it was people deep faking CEOs and board members and trying to get financial transactions made and things like that.
6:53
So I think there's different, I would say, classes of deep fake type attacks.
6:59
There's more of your broad based social engineering type attacks.
7:03
And I think one of the impacts of AI on that is it AI is able to do that at scale and in a very targeted way.
7:09
I think we're going to see a lot of asymmetry happening in those types of attacks.
7:13
And then the second category is much more of your targeted attack where you're trying to deep fake the CEO calling the CFO asking for a immediate wire transfer to pay for something.

11 MINS LATER

18:12
I'm just wondering as well, sitting here, do you see a future where AI predicts access needs and then revokes them based on anomalies or when the need for that access is simply gone before the human even notices?
6:32
So how do our underlying access architectures have to evolve to verify trust in a world where, frankly, seeing is just no longer believing, isn't it?
6:43
Yeah, I remember a year ago, there was multiple examples of I think it was people deep faking CEOs and board members and trying to get financial transactions made and things like that.
6:53
So I think there's different, I would say, classes of deep fake type attacks.
6:59
There's more of your broad based social engineering type attacks.
7:03
And I think one of the impacts of AI on that is it AI is able to do that at scale and in a very targeted way.
7:09
I think we're going to see a lot of asymmetry happening in those types of attacks.
7:13
And then the second category is much more of your targeted attack where you're trying to deep fake the CEO calling the CFO asking for a immediate wire transfer to pay for something.

11 MINS LATER

18:12
I'm just wondering as well, sitting here, do you see a future where AI predicts access needs and then revokes them based on anomalies or when the need for that access is simply gone before the human even notices?

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.