Craig Thomas

speaker
382 appearances 2 recordings 1 series first heard Jun 2026 last heard 8 Jul

Craig Thomas’s voice in public audio — every appearance, attributed to the second.

Trend

recordings per month · last 12 months
1 · Jul OctJan 26AprJulnow

Recordings per month over the last 12 months — 2 in all, peaking in Jul 2026 with 1.

Appearances

newest first · ▶ plays the moment
But as we've talked about, AI flips that assumption today.
Those are stateless remediations applied to stateful harm.
The damage is already done.
It's already materialized.
AI agents often hold open sessions with those external services.
So rotating a credential after the agent has already acted doesn't undo the action.
And so that's really what we have to fundamentally look at.
I like to equate it to restarting a pod is like locking a door.
After someone's already walked out with your files, it's good.
They're clean.
You're good now, but it doesn't matter.
And really in that traditional sense, that traditional web app, the worst case of a single compromise is usually bounded.
One record touch, a single session hijacked, but with an AI agent,
that has that tool use, that single compromise session, might have already browsed your internal wiki, drafted an email, scheduled a meeting, queried your CRM.
All that happened before your orchestration layer or those pod restarts happened, right?
You can't unsend that email by rotating their credential or simply restarting that pod.
It's really static controls, these firewall rules, IAM policies, they can't evaluate intent.
And so a lot of looking at AI is really about that intent, that semantic drift.
This threat's moved from who gets in to what happens after they're in.
So you're assuming these credentials are legit, but then once they get in, that spreads.
Showing 21–40 of 382 · page 2 of 20 ← Previous Next →