Building an AI Guardian for Enterprise with Onyx Security CEO Maxim Bar Kogan
Episode
41 min
Read time
2 min
Topics
Startups, Leadership, Artificial Intelligence
AI-Generated Summary
Key Takeaways
- ✓Enterprise agent breakdown: In a typical enterprise today, autonomous coding agents like Claude Code and Cursor account for roughly 50% of AI deployments, low-code automation platforms represent 45%, and internally built first-party agents make up the remaining 2-5%. Autonomous coding agents are currently the fastest-growing category and arrive with virtually no built-in security controls.
- ✓Why existing security tools fail agents: Identity security requires scoped permissions, but enterprises must grant agents broad access to be useful. Endpoint and API security tools cannot evaluate agent intent — they cannot distinguish between Claude Code legitimately deleting a database versus doing so erroneously on an unrelated task. Context-aware oversight requires purpose-built tooling.
- ✓Small model triage architecture: Rather than running a full frontier model to monitor every agent action, Onyx trains small, narrow models with one function: deciding whether a smarter oversight agent needs to intervene. This two-tier approach keeps latency low and costs viable while preserving high-quality review for genuinely risky actions.
- ✓Independent vendor advantage over labs: Enterprises refuse to share historical agent behavior data with Anthropic or OpenAI, fearing it will be used for training. Third-party security vendors like Onyx can access that behavioral history without conflict of interest, enabling anomaly detection the labs structurally cannot perform — a durable competitive moat as multi-vendor AI environments expand.
- ✓Mýthos-level vulnerability risk response: Automated vulnerability research, once considered decades away, is arriving now. Security teams should prioritize immediate patching of known vulnerabilities while simultaneously deploying foundational AI-specific controls — identity lockdown, endpoint detection, and an AI security control plane — rather than waiting for labs to phase-release advanced offensive-capable models gradually.
What It Covers
Maxim Bar Kogan, CEO of Onyx Security, explains how his Israel-based startup trains specialized small models to oversee autonomous AI agents in enterprise environments, addressing a security gap that existing identity, endpoint, and API tools cannot fill as agent deployments grow exponentially across Fortune 500 companies.
Key Questions Answered
- •Enterprise agent breakdown: In a typical enterprise today, autonomous coding agents like Claude Code and Cursor account for roughly 50% of AI deployments, low-code automation platforms represent 45%, and internally built first-party agents make up the remaining 2-5%. Autonomous coding agents are currently the fastest-growing category and arrive with virtually no built-in security controls.
- •Why existing security tools fail agents: Identity security requires scoped permissions, but enterprises must grant agents broad access to be useful. Endpoint and API security tools cannot evaluate agent intent — they cannot distinguish between Claude Code legitimately deleting a database versus doing so erroneously on an unrelated task. Context-aware oversight requires purpose-built tooling.
- •Small model triage architecture: Rather than running a full frontier model to monitor every agent action, Onyx trains small, narrow models with one function: deciding whether a smarter oversight agent needs to intervene. This two-tier approach keeps latency low and costs viable while preserving high-quality review for genuinely risky actions.
- •Independent vendor advantage over labs: Enterprises refuse to share historical agent behavior data with Anthropic or OpenAI, fearing it will be used for training. Third-party security vendors like Onyx can access that behavioral history without conflict of interest, enabling anomaly detection the labs structurally cannot perform — a durable competitive moat as multi-vendor AI environments expand.
- •Mýthos-level vulnerability risk response: Automated vulnerability research, once considered decades away, is arriving now. Security teams should prioritize immediate patching of known vulnerabilities while simultaneously deploying foundational AI-specific controls — identity lockdown, endpoint detection, and an AI security control plane — rather than waiting for labs to phase-release advanced offensive-capable models gradually.
Notable Moment
Bar Kogan reveals that large enterprises are now sanctioning OpenAI's operator-level tools company-wide, driven directly by CEO mandates rather than security team approvals — a reversal of the traditional procurement flow that signals how urgency around AI productivity is overriding standard enterprise security governance processes.
Episode Transcript
As you're exponentially doing more things with the eyes, you're gonna start having really bad action happen. And we've seen some of that happen lately with agents accidentally publishing code and tokens that they weren't supposed to. Like, definitely enterprise are starting to realize that that risk has grown exponentially and that they don't have any way to stop the adoption. They just now have to do something to reduce the chance of these agent actions being, illegitimate or incorrect. But we're allowed to look at a lot of historical data of how these agents have behaved, but any person that are not willing to have Anthropic or OpenAI give that historical data because they know these are very data hungry companies that will want to train on that data. Hi, listeners. Welcome back to Know Prior. Today, I'm here with Maxim Bar Kokan, the cofounder and CEO of Onyx Security, an Israel based startup of researchers, mathematicians, and engineers building agents to watch the AI agents. We talk about specialized model training, Mythos, alignment research, and the Israeli ecosystem in security and now AI. Welcome. Maxim, thanks so much for doing this. Thank you. Pleasure to be here. Everyone is much more concerned about security and the impact of AI on security than they were, certainly a few months ago. The consensus risk story, two two years ago when you started the company was basically, like, DLP for chatbots. Like, what are what are employees putting into ChatGPT? Now we have clearly something that is not quite panic, but close to market wide panic. How did you decide to bet on agent actions, when you started? Look, I think for us, the pivotal point was, AutoGPT. I think AutoGPT kind of let everyone's imagination, including ours, run wild because it was a Can you remind listeners what that was? Sure. So AutoGPT, and I'm sorry if I don't know the guy behind it, but a huge, huge fan. They created the first, as far as I know, first really autonomous agent running on LLMs. Right? So agent that, you know, would let LLM not generate text, but decide what to do and then give that agent an API access to do that thing, a tool to do it and then we'll do that in a loop. So it basically in theory could let agents do very complicated things, anything a person could do on the computer. Now, granted it didn't work that well, it was too early. The models were not good enough. GPT four was not good enough, but I think it did give everyone a glimpse into the future of, you know, what if the models were good enough and then basically using that same structure, we would have very capable agents doing stuff for us. I think that was in many ways, cloud code today is not dissimilar to other GPD back then. I think they were a bit early on on again before the models …
Get the full transcript (7,078 words) + summary by email — free
One-time email with the complete transcript and AI summary of this episode. No account needed.
One email, no spam. We’ll also show you what SignalCast does.
Browse all No Priors: Artificial Intelligence | Technology | Startups transcripts →
You just read a 3-minute summary of a 38-minute episode.
Get No Priors: Artificial Intelligence | Technology | Startups summarized like this every Monday — plus up to 2 more podcasts, free.
Pick Your Podcasts — FreeKeep Reading
More from No Priors: Artificial Intelligence | Technology | Startups
From Restoring Sight to Reimagining the Brain, with Max Hodak
Aug 20 · 31 min
Bankless
Trump's Grand Strategy: Iran, China & The New World Order | Kamran Bokhari
Mar 18
More from No Priors: Artificial Intelligence | Technology | Startups
What Chess.com Teaches US About Superhuman Capabilities, with CEO Erik Allebest
Aug 13 · 46 min
Beyond Biotech
Using AI to crack undruggable drug targets
Feb 13
Books, tools, and gear mentioned in this episode
SignalCast may earn commission on purchases via these links.
Tools
by OpenAI
“Bar Kogan reveals that large enterprises are now sanctioning OpenAI's operator-level tools company-wide, driven directly by CEO mandates”
by Anthropic
“In a typical enterprise today, autonomous coding agents like Claude Code and Cursor account for roughly 50% of AI deployments”
“In a typical enterprise today, autonomous coding agents like Claude Code and Cursor account for roughly 50% of AI deployments”
company
“Maxim Bar Kogan, CEO of Onyx Security, explains how his Israel-based startup trains specialized small models to oversee autonomous AI agents in enterprise environments”
More from No Priors: Artificial Intelligence | Technology | Startups
We summarize every new episode. Want them in your inbox?
From Restoring Sight to Reimagining the Brain, with Max Hodak
What Chess.com Teaches US About Superhuman Capabilities, with CEO Erik Allebest
Chasing Trillion-Dollar Companies, Founder Ambition, Token Budgets, and Regulatory Capture with Sarah & Elad
Building an Autonomous Enterprise for Real-World Services with Netic Founder Melisa Tokmak
Building an Autonomous Delivery Experience with DoorDash Co-Founders Andy Fang and Stanley Tang
Similar Episodes
Related episodes from other podcasts
Bankless
Mar 18
Trump's Grand Strategy: Iran, China & The New World Order | Kamran Bokhari
Beyond Biotech
Feb 13
Using AI to crack undruggable drug targets
The Full Ratchet
Feb 2
501. Spotting the Next Big Thing, Why This Cycle Is Different, Acceptable vs Unacceptable Risk, and Why Duration Is a Feature Not a Bug (Jon Callaghan)
The Ezra Klein Show
Oct 28
The Israeli Right’s Plan to Carve Up Gaza
Modern Wisdom
Aug 22
Ex-Gang Member: What Makes A Violent Man Change? - Johnny Chang - #1140
Explore Related Topics
This podcast is featured in Best AI Podcasts (2026) — ranked and reviewed with AI summaries.
Read this week's Startups & Product Podcast Insights — cross-podcast analysis updated weekly.
You're clearly into No Priors: Artificial Intelligence | Technology | Startups.
Every Monday, we deliver AI summaries of the latest episodes from No Priors: Artificial Intelligence | Technology | Startups and 192+ other podcasts. Free for one show.
Start My Monday DigestNo credit card · Unsubscribe anytime