Keycard: 2026 is the Year of Agents
Episode
32 min
Read time
2 min
Topics
Productivity, Relationships, Fundraising & VC
AI-Generated Summary
Key Takeaways
- ✓Agent Security Incident: A large SaaS company deployed an agent to query customer data that correctly denied explicit requests for other firms' data but inadvertently returned other companies' information when users requested their own data, exposing critical authentication and authorization gaps.
- ✓Agent Maturity Continuum: Agents evolve from level zero rule-based software through level one copilots with AI assistance to level three autonomous systems that execute multi-step tasks independently, similar to self-driving car progression from driver assistance to full autonomy with human oversight.
- ✓Enterprise Adoption Advantage: Unlike cloud adoption where security teams could delay implementation, agents drive top-level business objectives for earnings efficiency, making 2026 enterprise adoption faster than consumer adoption as CEOs mandate deployment despite security concerns creating shadow IT on steroids.
- ✓Dynamic Authorization Model: Agent security requires moving from static role-based access to task-based, intent-driven policy enforcement where users grant conditional consent at runtime, enabling downstream systems to verify permissions contextually across multi-tenant environments with ephemeral access patterns.
What It Covers
Keycard CEO Ian Livingston and a16z partner Joel De La Garza discuss how 2026 becomes the year enterprises deploy AI agents at scale, requiring new identity and authorization systems to manage agent security risks.
Key Questions Answered
- •Agent Security Incident: A large SaaS company deployed an agent to query customer data that correctly denied explicit requests for other firms' data but inadvertently returned other companies' information when users requested their own data, exposing critical authentication and authorization gaps.
- •Agent Maturity Continuum: Agents evolve from level zero rule-based software through level one copilots with AI assistance to level three autonomous systems that execute multi-step tasks independently, similar to self-driving car progression from driver assistance to full autonomy with human oversight.
- •Enterprise Adoption Advantage: Unlike cloud adoption where security teams could delay implementation, agents drive top-level business objectives for earnings efficiency, making 2026 enterprise adoption faster than consumer adoption as CEOs mandate deployment despite security concerns creating shadow IT on steroids.
- •Dynamic Authorization Model: Agent security requires moving from static role-based access to task-based, intent-driven policy enforcement where users grant conditional consent at runtime, enabling downstream systems to verify permissions contextually across multi-tenant environments with ephemeral access patterns.
Notable Moment
A production agent accessed customer database records, then made a web browser tool call that inadvertently transmitted sensitive production data in the query string while attempting to solve a user problem, demonstrating how benign read-only operations create data exfiltration risks.
Episode Transcript
In 2025, we saw the first glimpses of true AI agents. In 2026, every company will be rushing to get them into production, and they'll need companies like Keycard to manage fleets of agents. In this conversation, a sixteen z partner, Joel De La Garza, sits down with Keycard cofounder and CEO, Ian Livingston, to discuss the continuum from copilots to agents, the security realities of tool calling, why enterprises will adopt before consumers, and how to control your agents. Let's get into it. So it's shaping up to be that that that we're at the beginning of what sounds like the start of the year of the agents, 2026. Yeah. It seems like every company we talk to is definitely looking to get some sort of an agent into production, not just in the lab, to get them out into customer's hands and to start having them use it. And so I'd I'd like to share a story. I guess we could kick this off and and thank you so much to to you, Ian, for joining us on our podcast to discuss this. You know, we actually or I was actually privy to to hearing about probably the first security incident I've ever heard about with an agent. And as a security person, you know, we we constantly harp on people to be very explicit on what is the problem you solve. And the problems in security are often manifested in security events. And so we were talking to a company or heard about a company, a relatively large company that has a SaaS service, that that implemented an agent. They wanted to give a prompt to their users to query data that was in the system. Very common use case. You've probably seen several of them roll out recently. And this agent would essentially, return data for your firm. So you could say, hey, I'd like to know about this specific part of our business. Could you tell us, more about it? And it would give you an answer that would provide you with your data. So super useful, super helpful. Now the problem was you could ask for other firms' data, and it would very interestingly say no. I can't give you data for General Electric, for example. But if you just said, Hey, give me my data, it would return on a revolving cast of characters data from other companies. And immediately when I heard about this incident, you came into my mind because I thought, my God, there is an auth n auth z problem. And that is the problem with identity and agents. So welcome. Thank you so much for joining. Thank you so much for having me, Joel. And nothing could be more timely than your company. Nothing could be more timely. Yeah. It's it's incredible. You know, we spend a lot of time talking to companies trying to adopt agents or trying to build tools for agents. And invariably, you bay …
Get the full transcript (7,506 words) + summary by email — free
One-time email with the complete transcript and AI summary of this episode. No account needed.
One email, no spam. We’ll also show you what SignalCast does.
You just read a 3-minute summary of a 29-minute episode.
Get a16z Podcast summarized like this every Monday — plus up to 2 more podcasts, free.
Pick Your Podcasts — FreeKeep Reading
More from a16z Podcast
Why Companies Are Becoming a Series of Loops | Anish Acharya on Lenny’s Podcast
Sep 12 · 78 min
My First Million
Howard Marks: how I make money while you worry about a market crash
Jul 15
More from a16z Podcast
What It Takes to Build a Startup | Andrew Chen & Matt Perault
Sep 11 · 38 min
The AI Breakdown
The Week AI Grew Up
May 1
More from a16z Podcast
We summarize every new episode. Want them in your inbox?
Why Companies Are Becoming a Series of Loops | Anish Acharya on Lenny’s Podcast
What It Takes to Build a Startup | Andrew Chen & Matt Perault
How AI Is Rewriting the Power Law of Venture Capital
Who Grades the AI Models? | Ben Horowitz & Rayan Krishnan
OpenAI Researchers on the Future of Mathematical Reasoning
Similar Episodes
Related episodes from other podcasts
My First Million
Jul 15
Howard Marks: how I make money while you worry about a market crash
The AI Breakdown
May 1
The Week AI Grew Up
The Breakdown
Mar 5
AI Agents and the Next Wave of Crypto Demand | The Breakdown
Modern Wisdom
Feb 9
#1057 - Matthew Hussey - How to Know When to Leave a Relationship
The Changelog
Jan 22
The era of the Small Giant (Interview)
Explore Related Topics
This podcast is featured in Best Business Podcasts (2026) — ranked and reviewed with AI summaries.
You're clearly into a16z Podcast.
Every Monday, we deliver AI summaries of the latest episodes from a16z Podcast and 192+ other podcasts. Free for one show.
Start My Monday DigestNo credit card · Unsubscribe anytime