A
Ashish Rajan
3
APPEARANCES
3
PODCASTS
012
DEC 30
JAN 6
JAN 13
JAN 20
JAN 27
FEB 3
FEB 10
FEB 17
FEB 24
MAR 3
MAR 10
MAR 17
MAR 24
MAR 31
APR 7
APR 14
APR 21
APR 28
MAY 5
MAY 12
MAY 19
MAY 26
JUN 2
JUN 9
JUN 16
JUN 23
JUN 30
JUL 7
JUL 14
JUL 21
JUL 28
AUG 4
AUG 11
AUG 18
AUG 25
SEP 1
SEP 8
SEP 15
SEP 22
SEP 29
OCT 6
OCT 13
OCT 20
OCT 27
NOV 3
NOV 10
NOV 17
NOV 24
DEC 1
DEC 8
DEC 15
DEC 22
DEC 29
JAN 5
JAN 12
JAN 19
JAN 26
FEB 2
FEB 9
FEB 16
FEB 23
MAR 2
MAR 9
MAR 16
MAR 23
MAR 30
APR 6
APR 13
APR 20
APR 27
MAY 4
MAY 11
MAY 18
MAY 25
JUN 1
JUN 8
JUN 15
JUN 22
JUN 29
JUL 6
JUL 13
JUL 20
JUL 27
AUG 3
AUG 10
AUG 17
AUG 24
AUG 31
SEP 7
SEP 14
SEP 21
SEP 28
OCT 5
Sep 30, 2026
Giving Your AI Agent Its Own Identity with Ashish Rajan
10:14
10:20
10:29
10:35
10:52
11:11
15:05

Ron EddingsHOST
What would you say is your assessment, hot or not? Like is that a good idea or a bad idea?

Ashish RajanGUEST
I'll answer it in a way for a small business with one laptop, and I'll answer it another way where it's an enterprise with thousands of people trying to solve a similar problem.

Ashish RajanGUEST
For a small business without adding complexity, I think that is the simplest way to go forward.

Ashish RajanGUEST
You can technically extend that to, hey, what if the actual Jennifer wants to ever log in and see what's going on? You can probably have some kind of an authentication for that, and then you could probably, I would say what a lot of people do is they have a chief of staff or a orchestrator agent on top.

Ashish RajanGUEST
The idea behind that is that that agent then becomes responsible for the identity of everything you called out instead of her going logging in looking, okay, today what is the marketing agent doing? Or today, what is the, like the wine sommelier agent doing for in, in this example? Now that's the scenario for a small business.

Ashish RajanGUEST
Now let's extend that to an enterprise where there are thousands of developers with probably a similar scenario where they have basically been drinking the AGI pill or AI, AI pill I guess.

Ron EddingsHOST
And I saw something a few days ago that I was like, "What?" Well, it says, "Gemini hacked three companies in the first known breakout by Google's AI." And I thought to myself, "How in the world did Gemini do that?" Like, I've used Gemini so much, and I think it's great, but can it really hack? You know, like, what, what was your thoughts when you saw that news story?
Cloud Was the Warning. AI Is the Test. | Ashish Rajan
33:19
33:30
33:35
33:43
34:01

Ashish RajanGUEST
The whole idea is that when your agent starts drifting away from an existing behavior, how do you pick up on that? And then that's the term that you're looking for.

Ashish RajanGUEST
And anyone who's watching or listening to this, they'll probably, uh, Google this, and I'll highly encourage this.

Ashish RajanGUEST
But the whole idea is that evals are, in the most simplest term, a set of deterministic checks you do.

Ashish RajanGUEST
It's alw- it's always a set of deterministic checks you do to identify that in my, in my case, um, the example that I gave earlier, I would put a deterministic eval check for if the person asks for a password, a write action, it's always a no.

Ashish RajanGUEST
But the moment it starts going in that direction, and this is continuous by the way.
6 MINS LATER
39:49
Cloud, containers, right now, uh, with AI, right? So as security professionals, what have we learnt from all of these changes? Um, and about how-- like, what have we learnt about, well, we can't stop it, so how do we say yes without also kind of lying to ourselves that, "Ah, it'll be fine"?
The Blueprint for AI Security: Defending Against Prompt Injection & Shadow AI - Ashish Rajan
7:55
8:08
8:16
8:28
8:45

Ashish RajanGUEST
Those are the three a- big areas, and the, the through line between all of this is, uh, which is what makes it the weakest link, is that there are, depending on how you see this, the basic foundations haven't really changed.

Ashish RajanGUEST
We-- Containers, cloud, infra security, we have done all that for decades, so that will continue to be in that first two bucket.

Ashish RajanGUEST
Where it becomes a bit lack-- Well, let's just say a bit more relaxing control is there is no solution for the prompt injections of the world, where if it has a web interface, so which brings up exposure.

Ashish RajanGUEST
So for me, for those two applications, the number one thing is if you have done the fundamentals, the only thing I'd probably worry about is, am I being exposed to the internet? If I, uh, have an endpoint exposed to the internet, I want to be able to, A, identify what they are and make sure they're patched.

Ashish RajanGUEST
But also at the same time, if ever there's a vulnerability found, I want the meantime of response or resolution to be quicker.
19 MINS LATER

