Craig Thomas

speaker
382 appearances 2 recordings 1 series first heard Jun 2026 last heard 8 Jul

Craig Thomas’s voice in public audio — every appearance, attributed to the second.

Trend

recordings per month · last 12 months
1 · Jul OctJan 26AprJulnow

Recordings per month over the last 12 months — 2 in all, peaking in Jul 2026 with 1.

Appearances

newest first · ▶ plays the moment
From a security practitioner, your policy alone is not oversight.
We've always said that, right?
Paperwork doesn't make you more secure.
Policy document does not stop an agent mid-call, right?
So real oversight requires actual runtime enforcement.
The ability to inspect, block, or rate limit that AI-generated API traffic in real time.
That closed-loop model, really, to know, see, stop, and prove.
You need to know what the AI systems are running and what they've connected to.
You need to see what they're doing in real time.
You need to be able to stop the behavior before the consequences compound.
And increasingly, you need to be able to prove to auditors that you did this, right?
Most organizations have no, at least partially, and they've got some logs, but see, stop, and prove definitely are the gaps.
And then humans in the loop do matter, right?
But they need to be at the right points.
You can't put a human in the loop for every API call.
You put humans at decision gates for high risk actions, boundary crossing transactions, but then the system has to surface those moments automatically, right?
So
As you're looking at tooling and other things, those key aspects need to bubble up so that humans can take action quickly, understand the context around that, and then the tool has to be able to enforce these policies, like you said, at machine speed.
The security organization can't put the no in an innovation, right?
We've heard that many times, right?
Showing 321–340 of 382 · page 17 of 20 ← Previous Next →