Skip to main content
Max Corbridge

Max Corbridge

CEO and Co-founder of Secure Agentics, an ethical hacker and AI security expert specializing in runtime security for AI agents.

Aug 13, 2026

32:19
Of the agents that you have actually broken, was there any, like, single control that had it been in place would have stopped you most often?
32:30
Yes, and I can talk about this both from the attacking and from the now building AI systems that we're launching.
32:35
So I would say one of the most common things that we see people doing wrong with agents is giving them all of the access, right? Because it's nice and easy.
32:44
And that's where, although it sounds great to just hand over access to everything and to run everything in YOLO mode and to connect it to all the APIs and all of this stuff to g- to make your life nice and easy, that's where the risk of something going wrong and someone like me coming along and compromising that agent, then suddenly it has all of the access that you just gave it.
33:05
So my opportunities for things in terms of post exploitation next steps are vast.
33:10
The places that do this really well know exactly what role that agent serves, and they restrict the permissions and how this agent is able to behave to almost exactly the operational re-remit that you have in mind for it, and you can't stray away from that.
33:27
So I guess you could call that least privilege access, privilege separation.

11 MINS LATER

45:01
What are the builders of these systems systematically not doing today that they should be? And are there safe defaults that the frameworks could ship out to close off a big chunk of the risk that they pose?

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.