Jun 30, 2026 · 41 min · 15 segments
Some guests have seen the field from one seat. Phil Venables has seen it from most of them: CISO at Goldman Sachs, the first CISO for Google Cloud, and now a partner at Ballistic Ventures. So when he…
Phil VenablesGuestMoHostYeah, no, I mean, you guys definitely have a very cool portfolio.
I mean, I've been on one of your podcasts.
And again, all the topics that y'all cover at Ballistics is super cool.
And I think you're probably one of the best people suited to like, I guess, talk about this space as well.
And it's really hard to just cut through it.
So that's kind of how I want to start.
Because you've seen this from a lot of places and angles where most people haven't.
So what's kind of like the vantage point that you're seeing for AI security from like, what is all the noise that people are really just like getting bogged down by versus what is actually helpful?

Yeah, so there's, as with any massive technology shift, just like we've seen in prior shifts of internet, mobile, cloud, AI is probably an even more pervasive shift.

And when you look at how it impacts security, you've got to unpick it a little bit.

So there's The security of AI, and so that's all of the things that security and risk teams are doing to make sure that their organizations, when they deploy AI for business purposes, that they're doing that in safe, secure, regulatory compliant, managed ways that manage all the risks, not just the security risks of those AI deployments.

And this you see across everything from software security, security operations, a whole range of different things.

And then finally, you've got this broader impact of how AI is affecting the entire security landscape.

And I think, as you know, that's what's dominated the headlines for the past few months with the so-called mythos moment.

Although that's a little bit of a false moment in time because the quarters and year before that, everybody in the security community was seeing and realizing the profound effect that AI models, particularly models trained for coding, could have on finding vulnerabilities and chaining vulnerabilities together for attack.

So one element of this is we've got this tidal wave of vulnerabilities that is hitting us because the models are so good at finding vulnerabilities.

Long-term, though, everybody is applying those models to their own code base to find and fix things at rates that we've not seen before.

Secondly, though, which I think is largely going under-reported, but for me is more worrying, is the extent to which attackers are now using AI to industrialize what they're doing.

Attackers have always been resource constrained, and so there's always been more targets that they've not exploited than they have exploited.
Yeah, no, I mean, you guys definitely have a very cool portfolio.
I mean, I've been on one of your podcasts.
And again, all the topics that y'all cover at Ballistics is super cool.
And I think you're probably one of the best people suited to like, I guess, talk about this space as well.
And it's really hard to just cut through it.
So that's kind of how I want to start.
Because you've seen this from a lot of places and angles where most people haven't.
So what's kind of like the vantage point that you're seeing for AI security from like, what is all the noise that people are really just like getting bogged down by versus what is actually helpful?

Yeah, so there's, as with any massive technology shift, just like we've seen in prior shifts of internet, mobile, cloud, AI is probably an even more pervasive shift.

And when you look at how it impacts security, you've got to unpick it a little bit.

So there's The security of AI, and so that's all of the things that security and risk teams are doing to make sure that their organizations, when they deploy AI for business purposes, that they're doing that in safe, secure, regulatory compliant, managed ways that manage all the risks, not just the security risks of those AI deployments.

And this you see across everything from software security, security operations, a whole range of different things.

And then finally, you've got this broader impact of how AI is affecting the entire security landscape.

And I think, as you know, that's what's dominated the headlines for the past few months with the so-called mythos moment.

Although that's a little bit of a false moment in time because the quarters and year before that, everybody in the security community was seeing and realizing the profound effect that AI models, particularly models trained for coding, could have on finding vulnerabilities and chaining vulnerabilities together for attack.

So one element of this is we've got this tidal wave of vulnerabilities that is hitting us because the models are so good at finding vulnerabilities.

Long-term, though, everybody is applying those models to their own code base to find and fix things at rates that we've not seen before.

Secondly, though, which I think is largely going under-reported, but for me is more worrying, is the extent to which attackers are now using AI to industrialize what they're doing.

Attackers have always been resource constrained, and so there's always been more targets that they've not exploited than they have exploited.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.