Skip to main content
a16z Podcast

The CISO Playbook for AI Agents | Datadog

22 min episode · 2 min read
·
Emilio Escobar

Episode

22 min

Read time

2 min

Topics

Leadership, Design & UX, Marketing

AI-Generated Summary

Key Takeaways

  • Broad AI Access Over Blocking: Datadog issued ChatGPT licenses to all employees rather than restricting access, achieving a 98% adoption rate across engineering, marketing, and sales. Escobar argues that blocking tools never prevents use — it only creates blind spots — while early, permissive adoption identifies power users worth rewarding and avoids unsanctioned shadow usage entirely.
  • Role-Based MCP Servers for Data Governance: AI flattens organizational data hierarchies by enabling any employee to query databases they technically had access to but lacked the SQL skills to exploit. Datadog's solution is deploying role-based MCP servers — for example, a dedicated SDR server — so each employee's AI agent only surfaces data appropriate to their specific organizational function.
  • Ephemeral Credential Injection for Agent Security: Rather than letting coding agents access static credential files in home directories, Datadog built a sandbox where agents receive ephemeral, short-lived tokens only at the moment of need. AWS secrets, npm publish keys, and GitHub tokens are injected on-demand via CLI tooling, eliminating the risk of a compromised agent exfiltrating persistent credentials.
  • LLM-Based Intent Judge for Skill and Code Vetting: Datadog built an internal LLM judge that evaluates whether a piece of code or a marketplace skill is designed to cause harm — not just scanning for known CVEs. This judge now gates every third-party skill before agent adoption, has detected malicious packages in major marketplaces, and also flags reward-hacking agent outputs where code technically solves a metric while causing unintended damage.
  • Volume of AI-Discovered Vulnerabilities Is the Real Risk: Escobar is less concerned about AI models autonomously hacking systems than about the operational collapse that follows when AI multiplies discovered CVE counts by orders of magnitude. Current security frameworks still mandate fixing every critical finding, a standard incompatible with a world where vulnerability discovery volume increases a thousandfold practically overnight.

What It Covers

Datadog CISO Emilio Escobar outlines how a 4,000-engineer organization deploys coding agents securely, covering credential management, AI skill vetting, software supply chain risks, and why the real AI security threat is not rogue models but an explosion in discovered vulnerability volume.

Key Questions Answered

  • Broad AI Access Over Blocking: Datadog issued ChatGPT licenses to all employees rather than restricting access, achieving a 98% adoption rate across engineering, marketing, and sales. Escobar argues that blocking tools never prevents use — it only creates blind spots — while early, permissive adoption identifies power users worth rewarding and avoids unsanctioned shadow usage entirely.
  • Role-Based MCP Servers for Data Governance: AI flattens organizational data hierarchies by enabling any employee to query databases they technically had access to but lacked the SQL skills to exploit. Datadog's solution is deploying role-based MCP servers — for example, a dedicated SDR server — so each employee's AI agent only surfaces data appropriate to their specific organizational function.
  • Ephemeral Credential Injection for Agent Security: Rather than letting coding agents access static credential files in home directories, Datadog built a sandbox where agents receive ephemeral, short-lived tokens only at the moment of need. AWS secrets, npm publish keys, and GitHub tokens are injected on-demand via CLI tooling, eliminating the risk of a compromised agent exfiltrating persistent credentials.
  • LLM-Based Intent Judge for Skill and Code Vetting: Datadog built an internal LLM judge that evaluates whether a piece of code or a marketplace skill is designed to cause harm — not just scanning for known CVEs. This judge now gates every third-party skill before agent adoption, has detected malicious packages in major marketplaces, and also flags reward-hacking agent outputs where code technically solves a metric while causing unintended damage.
  • Volume of AI-Discovered Vulnerabilities Is the Real Risk: Escobar is less concerned about AI models autonomously hacking systems than about the operational collapse that follows when AI multiplies discovered CVE counts by orders of magnitude. Current security frameworks still mandate fixing every critical finding, a standard incompatible with a world where vulnerability discovery volume increases a thousandfold practically overnight.

Notable Moment

Escobar describes an internal business intelligence tool that inadvertently let a sales rep query compensation data meant for a separate team — not because permissions were wrong, but because AI enabled anyone to generate the SQL that technically-permissioned data had always allowed, exposing a structural gap invisible before agents arrived.

Know someone who'd find this useful?

Episode Transcript

The number one story on Bloomberg right now is that AI has gone wild. We seem remarkably calm. The way I see it is if it's not an AI model, it's gonna be somebody or something with actual malicious intent doing it. I do worry about what can the agents do, what tools can they call, what binaries can they pull, and also how do they get access to credentials. So if a code is meant to solve the bug, but it gets rewarded on that, but it doesn't care if it's actually doing something else Three is six, so to make it healthy, it cuts it down. Out of a necessity, my team built a judge that evaluates the intent behind a piece of code. Like, is this thing meant to do harm or not? And we actually find quite a bit of malicious skills in all these marketplaces. Engineers now, security is very much front of mind for them. Developers have always cared about security. Their security is very much front of mind for them. Developers have always cared about security. Their problem has been that the version of security that we want them to do is just crappy. My thesis ten years ago was that security engineers have become real engineers, so maybe now is the time. AI is changing the security landscape on both sides. Attackers have more capable tools, but security teams are also figuring out how to use those same capabilities to their advantage. In this episode, a sixteen z's Joel De La Garza sits down with Datadog's CISO Emilio Escobar to talk about what he's seeing as AI adoption spreads across the enterprise, including thousands of engineers working with coding agents. They discuss how AI changes assumptions around permissions, credentials, and software supply chains, why simply blocking new tools doesn't work, and how security teams can adapt without becoming the department of no. And as models get better at finding vulnerabilities, Emilio explains why he's less worried about AI hackers themselves than a more practical problem. What happens when the number of vulnerabilities we can find suddenly explodes? Thank you so much for joining us. I know you're not here to see us. You're here to go to Black Hat, and it's good to catch up. And it's been a really crazy week. So you are a CSO at a public company, tech company, one of the house of innovation, driven a lot of really cool technology out of it. And we've been talking to everyone about these models escaping, these models hacking. And I know you've been central to kind of the adoption of AI at Datadog, and would love to maybe talk a little bit about how are you thinking through the risks? How are you deploying this stuff? And I know you're very close to the product team, and you're kind of enabling it. So would maybe start off there and and Yeah. Yeah. Yeah. Around. For us, it was …

Get the full transcript (4,679 words) + summary by email — free

One-time email with the complete transcript and AI summary of this episode. No account needed.

One email, no spam. We’ll also show you what SignalCast does.

Browse all a16z Podcast transcripts →

You just read a 3-minute summary of a 19-minute episode.

Get a16z Podcast summarized like this every Monday — plus up to 2 more podcasts, free.

Pick Your Podcasts — Free

Keep Reading

More from a16z Podcast

We summarize every new episode. Want them in your inbox?

Similar Episodes

Related episodes from other podcasts

Explore Related Topics

This podcast is featured in Best Business Podcasts (2026) — ranked and reviewed with AI summaries.

You're clearly into a16z Podcast.

Every Monday, we deliver AI summaries of the latest episodes from a16z Podcast and 192+ other podcasts. Free for one show.

Start My Monday Digest

No credit card · Unsubscribe anytime