Craig Thomas

speaker
382 appearances 2 recordings 1 series first heard Jun 2026 last heard 8 Jul

Craig Thomas’s voice in public audio — every appearance, attributed to the second.

Trend

recordings per month · last 12 months
1 · Jul OctJan 26AprJulnow

Recordings per month over the last 12 months — 2 in all, peaking in Jul 2026 with 1.

Appearances

newest first · ▶ plays the moment
And so this changes how you reason about those agent permissions.
You can grant broader access if you have confidence in your ability to contain quickly.
Without that confidence, you're forced into over-restriction, which then ultimately limits utility.
And I think it's really important reframe for CISOs thinking about AI agent architecture, right?
As a previous CISO and dealing with those day in and day out, right now, the dominant strategy is least privilege taken to an extreme.
You give the agent almost nothing and hope it can still be useful.
Then the business comes back to you.
They're mad that this agent isn't very useful and you're the bad guy again, right?
But
So that works until the business decides it really needs that agent to actually be useful and now you're in a fight.
But the good news is if you have real containment capability, really that calculus can change, can grant broader permissions because you're confident that if something goes wrong, you can catch it fast and the damage is bounded like we talked about.
Security stops being the ceiling on that utility and starts being the foundation that makes higher utility possible.
I really like to see so can now enable the business, provide the security, provide the governance versus just having to stop the progress as you start to get this additional visibility and confidence.
Yeah, a couple jumped to mind right away.
You know, a data movement outside the approved endpoint.
If a model is exfiltrating to unexpected destinations, you need to know when your data is leaving, right?
Because that becomes a real pain point and has some real legal and monetary consequences.
So that's one.
Another is prompt injection executing, especially when it alters the agent's stated goal or override system's instructions.
A tool that exceeds its scope.
Showing 101–120 of 382 · page 6 of 20 ← Previous Next →