Craig Thomas

speaker
382 appearances 2 recordings 1 series first heard Jun 2026 last heard 8 Jul

Craig Thomas’s voice in public audio — every appearance, attributed to the second.

Trend

recordings per month · last 12 months
1 · Jul OctJan 26AprJulnow

Recordings per month over the last 12 months — 2 in all, peaking in Jul 2026 with 1.

Appearances

newest first · ▶ plays the moment
No one really designed for that data path, but it happened because the model was helpful.
It got what it needed, but it now logged that information where it shouldn't have.
And then I think another big thing is, yeah, I can't explain what it did problem.
And so that can be from the CISO's hat or from the CIO or business's hat.
A CISO can generally reconstruct a human attacker's path, reconstructing the AI agent's decision tree across a multi-step workflow with external data inputs.
It's generally, it's just a hard thing to do, right?
Regulators, board members, incident responders, they all want the story.
But today, a lot of organizations can't tell it.
And then the other kind of interesting story is unexpected answers or behaviors.
We actually have an ongoing conversation with a potential customer.
They built their own chatbot.
And going to change some details here to not reveal anything, but you go ask this chatbot a question, for instance, what do I feed my new puppy, right?
99 times out of a hundred or 999 times out of a thousand responds with the skew for puppy food, a link, you can buy it straight from their website.
However, one time out of that, it actually responds completely randomly and not only randomly, but in a really bad way to potentially feed your puppy something that's poisonous.
So that can't happen.
We have to understand what those responses are and make sure they're accurate a hundred percent of the time, because otherwise the company can be liable there.
So those are a couple of the two big things, Noah, about unexpected outcomes, both from a cyber side as well as the business and liability side that jump out to me.
And then kind of the third is just that reputational risk from outputs, not just access.
An AI system that publishes incorrect or biased content at scale or gives inappropriate recommendations to customers, like I talked about, it's a brand and legal risk.
It doesn't fit neatly into traditional security frameworks.
Showing 301–320 of 382 · page 16 of 20 ← Previous Next →