
Max Corbridge
CEO and Co-founder of Secure Agentics, an ethical hacker and AI security expert specializing in runtime security for AI agents.
1
APPEARANCES
1
PODCASTS
012
DEC 30
JAN 6
JAN 13
JAN 20
JAN 27
FEB 3
FEB 10
FEB 17
FEB 24
MAR 3
MAR 10
MAR 17
MAR 24
MAR 31
APR 7
APR 14
APR 21
APR 28
MAY 5
MAY 12
MAY 19
MAY 26
JUN 2
JUN 9
JUN 16
JUN 23
JUN 30
JUL 7
JUL 14
JUL 21
JUL 28
AUG 4
AUG 11
AUG 18
AUG 25
SEP 1
SEP 8
SEP 15
SEP 22
SEP 29
OCT 6
OCT 13
OCT 20
OCT 27
NOV 3
NOV 10
NOV 17
NOV 24
DEC 1
DEC 8
DEC 15
DEC 22
DEC 29
JAN 5
JAN 12
JAN 19
JAN 26
FEB 2
FEB 9
FEB 16
FEB 23
MAR 2
MAR 9
MAR 16
MAR 23
MAR 30
APR 6
APR 13
APR 20
APR 27
MAY 4
MAY 11
MAY 18
MAY 25
JUN 1
JUN 8
JUN 15
JUN 22
JUN 29
JUL 6
JUL 13
JUL 20
JUL 27
AUG 3
AUG 10
AUG 17
AUG 24
AUG 31
SEP 7
Aug 13, 2026
SE Radio 733: Max Corbridge on Securing AI Agents
32:30
32:35
32:44
33:05
33:10
A
32:19Amey AmbadeHOST
Of the agents that you have actually broken, was there any, like, single control that had it been in place would have stopped you most often?

Max CorbridgeGUEST
Yes, and I can talk about this both from the attacking and from the now building AI systems that we're launching.

Max CorbridgeGUEST
So I would say one of the most common things that we see people doing wrong with agents is giving them all of the access, right? Because it's nice and easy.

Max CorbridgeGUEST
And that's where, although it sounds great to just hand over access to everything and to run everything in YOLO mode and to connect it to all the APIs and all of this stuff to g- to make your life nice and easy, that's where the risk of something going wrong and someone like me coming along and compromising that agent, then suddenly it has all of the access that you just gave it.

Max CorbridgeGUEST
So my opportunities for things in terms of post exploitation next steps are vast.

Max CorbridgeGUEST
The places that do this really well know exactly what role that agent serves, and they restrict the permissions and how this agent is able to behave to almost exactly the operational re-remit that you have in mind for it, and you can't stray away from that.
11 MINS LATER
A
45:01Amey AmbadeHOST
What are the builders of these systems systematically not doing today that they should be? And are there safe defaults that the frameworks could ship out to close off a big chunk of the risk that they pose?