跳到正文
原文
Tomer Tunguz 博客(VC 分析)·· 3 小时前AI 评分30

Lemonade CISO Jonathan Jaffe:AI 时代每个智能体都需要独立身份与策略框架

Security in the Age of AI Agents: Office Hours with Jonathan Jaffe

AI 导读

Lemonade CISO Jonathan Jaffe 在 Office Hours 中提出,AI 对防守方与攻击方同样强大,被低估的防守方会因全栈厂商同步加固而收窄漏洞可利用窗口。

正文

In short : Jonathan Jaffe, CISO at Lemonade, explains why AI is good for defenders, not attackers, and why every AI agent needs its own identity and policy framework.

When security practitioners become engineers, the mission changes from managing people to architecting the automated policies that govern an agentic world.

Jonathan Jaffe, CISO at Lemonade, joined me on Office Hours to discuss what this means for how we build, secure, & operate AI systems when both sides are automated.

AI is just as powerful for defenders as it is for attackers. The fear narrative underestimates this fact. Defenders harden everywhere, simultaneously, because every vendor in the stack is also racing to ship.

“There are tens of thousands of attack targets out there. The chances that you’re going to be one of those is small. At the same time, all of the vendors that you use will also have access to this to improve their services.”

The window of exploitability is narrowing. Yes, AI will write more vulnerable code. But AI-written code also gets reviewed, pen-tested, & patched faster than any human pipeline. Plus, the total number of bugs within a particular piece of software is finite. As the velocity of solving or resolving bugs increases, software will become far more resilient.

Security teams are becoming engineering teams. At Lemonade, every security person is an engineer. They built their own AI platform with agents on top of it. One agent reads threat intel. Another checks whether the vulnerable method is actually called in production code.

“Automation is the only way you can deal with the scale of what’s coming at us now.”

Every agent needs an identity. On a single endpoint, we could be running 200 or 10,000 agents, but each one of them needs to be numbered and then governed by policy at the point of action.

“Every agent needs to have an identity, and more than that, you need a way to control policy for all of these agents in a much more complex way than current identity and access management systems do.”

Modern agentic security engineering is rapidly transforming, and we should expect to see significantly hardened systems as a result. It’s a bright future for security and security professionals.

I’m grateful to Jonathan for sharing his insights at Office Hours!

Get the next one in your inbox

The 1-minute read that turns tech data into strategic advantage.
Read by 150k+ founders & operators.

GP at Theory Ventures. Former Google PM. Sharing data-driven insights on AI, web3, & venture capital.

Bloomberg • WSJ • Economist

来源:Tomer Tunguz 博客(VC 分析) · tomtunguz.com