How Do You Defend Against AI That Can Hack?
Episode
22 min
Read time
2 min
Topics
Productivity, Investing, Fundraising & VC
AI-Generated Summary
Key Takeaways
- ✓AI Guardrail Conflict: Security teams triaging incidents ask models the same questions attackers do — "what's vulnerable, how do I exploit it?" — triggering refusals that block defenders. Blue teams need fallback routing to open-weight models like GLM or Qwen that lack commercial guardrails, making model flexibility a core operational requirement, not a preference.
- ✓Agentic Software Scale: 50% of enterprise applications will be agentic by end of 2025, inside environments averaging 6,000–7,000 unique software instances. Security teams cannot vet each one's backend model, guardrails, or data access. Defenders must shift focus from perimeter control to visibility into what each agentic process is installed to do and what it actually does.
- ✓Behavioral Detection Breakdown: Behavior-based security tools assume defenders can define what normal software looks like — agentic software invalidates that assumption entirely. Because AI agents take unpredictable paths to complete tasks, teams cannot tune detection thresholds up or down effectively. The required shift is toward pre-execution governance: controlling what software can do before it runs.
- ✓Honeypot False Positive Problem: Deception-based defenses — previously considered high-precision — now generate noise when AI agents autonomously discover planted credentials and attempt to use them legitimately. One deployment saw customer alert rates shift from near-100% true positives to high false-positive volumes overnight. Teams relying on honeypots need to audit whether agentic processes have access to those environments.
- ✓Signature Detection Obsolescence: Static detection rules and signature-based approaches are no longer viable as a primary defense layer against AI-driven attacks. Targeted rules still serve narrow use cases — flagging admin access to specific production services — but broad signature coverage will degrade regardless of tuning investment. Teams should reallocate resources toward dynamic, model-assisted detection pipelines.
What It Covers
A16z's Joel De La Garza speaks with Nick Warner of Neo and Max Pollard of Kotul at Black Hat about how AI agents create a security blind spot: existing tools were built to detect humans and malware, and AI agents are neither, forcing a fundamental rethink of enterprise defense strategies.
Key Questions Answered
- •AI Guardrail Conflict: Security teams triaging incidents ask models the same questions attackers do — "what's vulnerable, how do I exploit it?" — triggering refusals that block defenders. Blue teams need fallback routing to open-weight models like GLM or Qwen that lack commercial guardrails, making model flexibility a core operational requirement, not a preference.
- •Agentic Software Scale: 50% of enterprise applications will be agentic by end of 2025, inside environments averaging 6,000–7,000 unique software instances. Security teams cannot vet each one's backend model, guardrails, or data access. Defenders must shift focus from perimeter control to visibility into what each agentic process is installed to do and what it actually does.
- •Behavioral Detection Breakdown: Behavior-based security tools assume defenders can define what normal software looks like — agentic software invalidates that assumption entirely. Because AI agents take unpredictable paths to complete tasks, teams cannot tune detection thresholds up or down effectively. The required shift is toward pre-execution governance: controlling what software can do before it runs.
- •Honeypot False Positive Problem: Deception-based defenses — previously considered high-precision — now generate noise when AI agents autonomously discover planted credentials and attempt to use them legitimately. One deployment saw customer alert rates shift from near-100% true positives to high false-positive volumes overnight. Teams relying on honeypots need to audit whether agentic processes have access to those environments.
- •Signature Detection Obsolescence: Static detection rules and signature-based approaches are no longer viable as a primary defense layer against AI-driven attacks. Targeted rules still serve narrow use cases — flagging admin access to specific production services — but broad signature coverage will degrade regardless of tuning investment. Teams should reallocate resources toward dynamic, model-assisted detection pipelines.
Notable Moment
Nick Warner noted that building Neo's software taxonomy five to seven years ago would have required hundreds of threat researchers and years of work. Using AI agents, the same taxonomy was completed in weeks — illustrating how defenders now access capabilities previously unavailable at any budget.
Episode Transcript
One of the interesting things in the OpenAI Hugging Face breach has been the difficulty that Hugging Face actually had responding to the incident. Model providers have great reason to establish guardrails, safeguards, because these are super capable systems. The unfortunate side effect of that is, as a defender, I may not be able to respond effectively. The challenge with the existing security tools that are out there is they really were built to tackle two things. The first being people and the second is malware. And AI and AI agents and agentic processes are neither one of those things. Even some of the more modern techniques like deception, it worked really well. And it's sort of ironic. We're defending AI, and we're also defending from AI. 50% of enterprise apps will be agentic by the end of this year, and the average enterprise is something like six or 7,000 unique pieces of software within their environment. The problem's gonna get more complex and more challenging. We seem to be speed running every technology cycle that's ever happened before this one. What is the path forward for a lot of this inference? Cybersecurity was built to defend against two things, people and malware. AI agents are neither. In this episode, a 16 z's Joel De La Garza sits down with Nick Warner of Neo and Max Pollard of Kotul to unpack what that means for security teams as increasingly capable models move from the cloud onto endpoints and into enterprise software. They discuss why AI guardrails can actually make life harder for defenders, why traditional signatures and behavioral detection are starting to break down, and what happens when software no longer behaves predictably enough for security teams to define what normal looks like. And from Black Hat, they look at the other side of the equation. The same AI that's creating an entirely new attack surface is also giving defenders tools they could never have built before. Awesome. Well, thank you so much, guys, for joining us. I think maybe let's set the stage for the discussion. It's been a very active couple weeks. We've obviously had the crazy pace of AI development. Every week, there seems to be a new model released. There seems to be new capability. There's some new fields metal getting won or some new vulnerability getting discovered. And in the news recently has been the report that models from Frontier Labs have found a way to escape containment and hack things on the Internet, which has been a pretty interesting revelation. That's a very sophisticated capability. I guess there's probably two things happening. Right? There's a discussion about, well, how secure is the Internet actually? Also combined with, man, these models are surely progressing and doing some great stuff. So we've got the two of you here to discuss this, and I think maybe Max will start with you. One of the interesting things in the OpenAI Hugging Face story breach event has been the …
Get the full transcript (4,390 words) + summary by email — free
One-time email with the complete transcript and AI summary of this episode. No account needed.
One email, no spam. We’ll also show you what SignalCast does.
You just read a 3-minute summary of a 19-minute episode.
Get a16z Podcast summarized like this every Monday — plus up to 2 more podcasts, free.
Pick Your Podcasts — FreeKeep Reading
More from a16z Podcast
Stripe’s AI Strategy: Build More, Not Less
Aug 17 · 54 min
Masters of Scale
The new rules of brand building, with Wieden+Kennedy CEO
Aug 4
More from a16z Podcast
Ben Horowitz and Travis Kalanick on Building Again
Aug 14 · 33 min
Up First (NPR)
Trump's Iran Negotiations, Entertainment Mergers, NBA finals
Jun 13
More from a16z Podcast
We summarize every new episode. Want them in your inbox?
Stripe’s AI Strategy: Build More, Not Less
Ben Horowitz and Travis Kalanick on Building Again
The Two Ways to Sell AI: Lighthouse or Landgrab?
Garry Tan on Taste, Agents and Founder Ambition
The CISO Playbook for AI Agents | Datadog
Similar Episodes
Related episodes from other podcasts
Masters of Scale
Aug 4
The new rules of brand building, with Wieden+Kennedy CEO
Up First (NPR)
Jun 13
Trump's Iran Negotiations, Entertainment Mergers, NBA finals
Huberman Lab
May 18
How to Overcome Social Anxiety | Dr. Nick Epley
The Rich Roll Podcast
Apr 13
Everything Is A Story: Journalist Nick Bilton Thinks AI Might End Humanity & How Stories Could Save Us
The Daily (NYT)
Mar 4
A New Media Empire
Explore Related Topics
This podcast is featured in Best Business Podcasts (2026) — ranked and reviewed with AI summaries.
Read this week's Investing & Markets Podcast Insights — cross-podcast analysis updated weekly.
You're clearly into a16z Podcast.
Every Monday, we deliver AI summaries of the latest episodes from a16z Podcast and 192+ other podcasts. Free for one show.
Start My Monday DigestNo credit card · Unsubscribe anytime