Sep 8, 2026 · 47 min · 11 segments
AI attackers can now move at a speed and scale that traditional security operations were never designed to handle.In this episode of \*\*So What About AI Agents\*\*, Philippe Trounev sits down with…
Neal IyerGuest
Philippe TrounevHost
So it almost sounds like this harness will supersede like frameworks or like we'll have to change frameworks like SOC 2, right? So right now organizations have these policies and procedures in place and they're outdated.

I mean, startups just, you know, they make up a bunch of policies and they get certified.

Like we've seen those scandals with like rubber mill SOC 2 certification things because in the agentic world, it doesn't make sense.

So it's almost like this harness will need to be like a mandated like on the federal level.

So where do you see this go? Is this getting regulated? What kind of regulations are they going to put in to enforce this type of like agentic security layers? And those are going to be more expensive than the traditional SOC tools.

As far as activity from regulators on this front in terms of protecting security operations related agents, I haven't seen a ton so far.

But what I have seen individual organizations do a lot of, which is a good start in my mind, right, is most of the, you know, what I would call strategically important organizations in America have set up what they call as internal AI governance boards, where they are wetting each agentic solution, be it vendor acquired, be it built internally against a set of standards.

And the kinds of questionnaires I have been seeing, they ask these exact things like, can you prove to me that there are guardrails where you won't just go lock out my CEO's computer while they're on an earnings call, right? Can you demonstrate to me that if there is a prompt injection attack that is attempted against this agent, that I have a reasonable workflow? I mean, firstly, the prompt injection isn't just going to succeed.

And then I have a reasonable workflow around it to basically mitigate any damage that might come out of that prompt injection, right? So I think a lot of this has been organizations doing this by themselves, Some of the organizations that we have, like the healthcare, you know, security.

So by the way, and this may not be known to everybody, but the good thing about security is we are a tight community and people talk to each other a fair bit, right? So you may have, you know, say take airlines, right? They fiercely compete with each other as businesses.

But when it comes to the cybersecurity teams within each of these organizations, they're actually, you know, They usually maintain like cadence calls and they talk to each other on a monthly basis.

And there are also industry organizations, you know, FSISAC being a financial services one, healthcare ISAC and so on, where there are a lot of these ideas and sort of standards that are shared as best practices and more and more organizations start to adopt these.

So, so far, we haven't seen a ton on what you mentioned from a regulatory standpoint.

And these organizations, as they share ideas with each other, are starting to enforce some of these guardrails or some of these baselines from any agentic solutions, whether developed internally, whether vendor acquired, from being utilized for security operations.

And a lot of the questions that are in them try to address, like try to get at not mandating a harness, but you can't quite achieve those checkboxes unless you have a harness around them, right?

So it almost sounds like this harness will supersede like frameworks or like we'll have to change frameworks like SOC 2, right? So right now organizations have these policies and procedures in place and they're outdated.

I mean, startups just, you know, they make up a bunch of policies and they get certified.

Like we've seen those scandals with like rubber mill SOC 2 certification things because in the agentic world, it doesn't make sense.

So it's almost like this harness will need to be like a mandated like on the federal level.

So where do you see this go? Is this getting regulated? What kind of regulations are they going to put in to enforce this type of like agentic security layers? And those are going to be more expensive than the traditional SOC tools.

As far as activity from regulators on this front in terms of protecting security operations related agents, I haven't seen a ton so far.

But what I have seen individual organizations do a lot of, which is a good start in my mind, right, is most of the, you know, what I would call strategically important organizations in America have set up what they call as internal AI governance boards, where they are wetting each agentic solution, be it vendor acquired, be it built internally against a set of standards.

And the kinds of questionnaires I have been seeing, they ask these exact things like, can you prove to me that there are guardrails where you won't just go lock out my CEO's computer while they're on an earnings call, right? Can you demonstrate to me that if there is a prompt injection attack that is attempted against this agent, that I have a reasonable workflow? I mean, firstly, the prompt injection isn't just going to succeed.

And then I have a reasonable workflow around it to basically mitigate any damage that might come out of that prompt injection, right? So I think a lot of this has been organizations doing this by themselves, Some of the organizations that we have, like the healthcare, you know, security.

So by the way, and this may not be known to everybody, but the good thing about security is we are a tight community and people talk to each other a fair bit, right? So you may have, you know, say take airlines, right? They fiercely compete with each other as businesses.

But when it comes to the cybersecurity teams within each of these organizations, they're actually, you know, They usually maintain like cadence calls and they talk to each other on a monthly basis.

And there are also industry organizations, you know, FSISAC being a financial services one, healthcare ISAC and so on, where there are a lot of these ideas and sort of standards that are shared as best practices and more and more organizations start to adopt these.

So, so far, we haven't seen a ton on what you mentioned from a regulatory standpoint.

And these organizations, as they share ideas with each other, are starting to enforce some of these guardrails or some of these baselines from any agentic solutions, whether developed internally, whether vendor acquired, from being utilized for security operations.

And a lot of the questions that are in them try to address, like try to get at not mandating a harness, but you can't quite achieve those checkboxes unless you have a harness around them, right?
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.