Skip to main content
Jack Cable

Jack Cable

American software developer

Jul 7, 2026

7:30
So can you talk a little bit about how AI is fundamentally changing the conversation around secure by design and, you know, what it really means for this type of initiative going forward?
7:42
Certainly.
7:43
Right.
7:43
So I think it's helpful to break it down into kind of two angles.
7:47
Right.
7:47
One is on the offense, what this enables adversaries to do.
7:51
And then two is kind of what this means for defenders and folks who are building products on the offensive side.

8 MINS LATER

16:07
Can you talk a little bit about what this means for organizations on the ground? What are some of the risks here that they're facing? What are some of the things that you know, CISOs need to think about when we're looking at kind of the intersection of AI and coding and what are you seeing there?
10:52
Mm.
10:52
Whether it's, right, I don't know, customer support where, um, you can now automate intake of that and analysis, right, and reduce the work, I don't know, 10, 50, 100 fold.
11:04
And again, there are risks associated with that, but the, the benefits are so high, um, that I think it, it's not really an option just to, to ignore it, right? So, so then the question becomes how do you do this in a sanctioned way, right? And, and from my perspective right now, um, it, it's about balancing both those deterministic controls that can constrain what an agent can do.
11:25
It's also, right, and this is why, right, when you ask Claude to do something, every five seconds it'll be like, "Okay, allow this, allow this, allow this" right?

6 MINS LATER

17:46
Mm.
17:46
Right? It, it, um, kind of has to be one or the other in some ways, right? Like when I, right now when I use Claude, I do give it access to my email, but I say like, "Okay, yeah, go and do this task." It will, and then says, "Okay, here is what I recommend or what I've found." Oftentimes just for querying information, right? So again, it's if you can lock down what the riskiest attack paths are, right? Primarily in the context of email, just to, to keep using that example, right? Sending email, does your agent really need to be able to send email on your behalf, right? 'Cause that's the third element of that, that lethal triangle, is being able to exfiltrate information.
21:32
Yeah
21:32
... incredibly capable tools that allow every team to scale in their specific tasks, right? They can build software that gets to exactly what they need.
21:42
Um, so my, my advice would be, right, really to, to embrace it and figure out how to give your teams, right, the, these kind of paved roads to, um, build securely, right, to, to deploy in a sanctioned environment, all of that, right? Because otherwise, right, they're, they're not, not going to do it.
22:01
They're gonna set up, you know, u- use one of the, um, you know, tools like Lovable or V0, deploy things out there, right? We, we've seen, you know, tools getting created u- that use customer data and, and have the potential to, to leak it.
22:17
Um, so, so my advice would be to figure out a sanctioned way to allow teams to build and deploy these tools in a way that, that has some constraints around it and isn't gonna expose anything.

8 MINS LATER

30:21
And to explain to the audience, an MCP server is like a stan- think API, but now in a way that, uh, uh, that a, that a, that a, uh, an, an AI agent can understand, right? So you're connecting different systems to each other and, well-There's maybe a risk there [laughs] because who, who knows what could possibly go wrong, right? [laughs]
30:42
Yeah.
30:42
So, so I'd say, right, it, it's, um ...

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.