transcribe

Building an AI Guardian for Enterprise with Onyx Security CEO Maxim Bar Kogan

No Priors: AI, Machine Learning, Tech, & Startups · 41m · transcribed May 2026
More from No Priors: AI, Machine Learning, Tech, & Startups Business
𝕏 Share ▶ YouTube 📥 PDF 🤖 .md

Transcript

0:00 as you're exponentially doing more things with the eyes, you're going to start having really bad actions happen. And we've seen some of that happen lately with agents accidentally publishing code and tokens that they weren't supposed to. Like definitely enterprises are starting to realize that that risk is grown exponentially and that they don't have any way to stop the adoption. They just now have to do something to reduce the chance of these agent actions being illegitimate or incorrect. But we're allowed to look at a lot of historical data of how these agents have behaved. But enterprise today are not willing to have entropic or open AI keep that historical data because they know these are very data companies that will want to train on that data.

0:45 >> Hi listeners, welcome back to No Priors. Today I'm here with Maximbar Kogan, the co-founder and CEO of Onyx Security, an Israelbased startup of researchers, mathematicians, and engineers building agents to watch the AI agents. We talk about specialized model training, Mythos, alignment research, and the Israeli ecosystem in security and now AI. Welcome, Maxim. Thanks so much for doing this. >> Thank you. Pleasure to be here. Everyone is much more concerned about security and the impact of AI on security than they were um certainly a few months ago.

1:18 The consensus risk story uh two two years ago when you started the company was basically like DLP for chat bots like what are what are employees putting into chat GPT. Now we have clearly something that is not quite panic but close to marketwide panic. How did you decide to bet on agent actions um when you started? >> Look, I think for us the pivotal point was uh AutoGPT. I think AutoGPT kind of a let everyone's imagination including ours run wild because it was a >> Can you remind listeners what that was?

1:52 >> Sure. So, AutoGPT um and I'm sorry if I don't know the guy behind it, but a huge huge fan. H they created the first as far as I know first really autonomous agent running on LLMs right so agent that you know would let LLM not generate text but decide what to do and then give that agent an API access to do that thing a tool to do it and then would do that in a loop so it basically in theory could let agents do very complicated things anything a person could do on a computer now in granted it didn't work that well it was too early. The models were not good enough. GPT4 was not good enough. But I think it did give everyone a glimpse into the future of you know what if the models were good enough and then basically using that same structure we could have very capable agents doing stuff for us. I think that was in many ways cloud code today is not dissimilar to autograph back then. I think they were a bit early on on again before the malls were ready but the concept was right and the thought that stickked with me was I was very IPL even back then. So I was uh I was uh thinking oh my god malls are going to be way smarter than us when that happens. How do we oversee these very uh smart uh agents that are, you know, they're smarter than us?

3:18 They're very capable. Uh how we're going to feel easy about them doing stuff for us, especially when they start managing really important stuff, you know, then one day they're managing your water supply and your electricity, your uh power grid, right? How do you control them? And that was like the thing I was kind of obsessed about that thought. H I was also too early. So I think at the time enterprises were not using any agents. Uh there were hardly any agents out there and and talking with a lot of security buds at the time they were like oh dude you're way too early like this is not uh something that's going to happen as you question. I said is anyone going to do this before you run out of money?

3:57 And and I think there was a good chance that uh I would have run out of money before because I think you were right like I think it there was an element of chance here but then I think the market did happen. So we had suddenly reasoning models that could do long horizon tasks. We had a cloud code which became like the really first widely used autonomous agent and then we had co-work and open claw and and I think we're starting to see now that these types of agents that are very autonomous even though they're like uh everyone was afraid to build them. So everyone started building these low code platforms that were much more limited much more based on connectors. H those platforms ended up being quite limited.

4:43 So that we didn't get the productivity gains from those limited platforms. But when we started getting the crazy benefits from these very unleashed agents that could do everything that had much less controls baked into them and even very large enterprises decided they're going to adopt it. You know like tropics revenue is coming from enterprises that are paying for cloud code to do a lot of the work that developers used to do. That was a bit about kind of how we started and we definitely were in luck that very autonomous agents appeared uh before uh it was too late.

5:17 >> So can you describe a little bit just because it's um I I think both uh close to impossible and then very useful in this period of AI to think about what is deployment right now and then you know what's changing about capability. What's the oneliner on what the Onyx product does today and then like how you think about long-term vision >> today? Like Onyx is really does do two two things. Number one is we train models and build agents that can oversee other agents. And the goal of that is to say, okay, we need someone to be able to tell that all of these actions that are now happening by these AIs that we're adopting are legitimate because that number the number of these actions is going exponentially. And so things that we thought might be useful in the past like a human in the loop now that you're going to have 100x, a thousandx, a millionx of these actions, h that's not going to work. And then we take that capability and we basically productize it in a product that we call the control plane or the secure control plane where we come to the present say hey let's let's find all of your AIS and autonomous agents and hook them up to onyx to this system where we can oversee what your eyes are doing so that uh you don't run into the risk of as you're exponentially doing more things with the eyes you're going to start having really bad actions happen and and we've seen some of that happen lately with down times that were caused by a just doing the wrong thing, agents accidentally publishing code and tokens uh that they weren't supposed to and so on. So like definitely enterprise are starting to realize that that risk is growing exponentially and that they don't have any way to stop the adoption. So like they just now have to do something to reduce the chance of these agent actions being uh illegitimate or incorrect.

7:11 Yeah, I I think um the one of the core reasons obviously the foundation model labs are going after code is because it is very powerful in general and can do you know in theory all things software can uh over time. Um the flip side of that is it can do all things software can right and so uh I joyously am already in the camp of having allowed a having been over permissive with my agents such that it deleted data permanently and caused rework. So I'm like oh okay I think I see I need some guardian guardian spirits around it. Um given your deployments today and talking to large enterprises what is the state of deployment right? uh like how much do you see that's within these uh more scoped like studio-l like platforms versus uh you know uh free free riding coding agents you know how how much are you actually seeing in large enterprises in different sectors >> yeah so I think right now in our typical enterprise we're going to see if we break it down to three categories so we break it down to various SAS platforms that are typically more low code uh where people build agents in this drag and drop way and they're not really autonomous agents, right? They're kind of the simp kind of I would think of them more as automations and then there are um first party agents people are building in their cloud potentially because it's an application they want inside the company or even a product they're planning to release to the customers that is agentic. And then the third category is very autonomous coding agents and assistants. Of these categories, I would say roughly at this point over 50% is the autonomous uh coding agents and assistance in the average enterprise.

8:59 Then probably 45% is is those uh uh low code automations. And the last 2% are really the first party ones that they're building themselves because obviously it's much harder to build effective agents. So, and it's much easier to adopt agents off the shelf or or build them with low code. So, and that's what we're seeing and we're inducing that the autonomous are also the fastest growing category. So, it used to be that only developers and we would see cloud code growing like fire in our customer base and now we're seeing a cloud co-working even faster.

9:35 We're starting to see to our own surprise actually people adopting openclaw as a legitimate sanctioned tool in the company because the CEO is very driven to adopt AI. H so I think that today autonomous ads are by far the fastest growing category and and uh today typically comes without any controls. So enterprises uh already buy let's say a hundred billion dollars of security today. Um they have uh lots of different protections at the endpoint and network and cloud and identity domains. Uh what's relevant here for securing agents or is none of it like how do you how do you think about the existing protection set? Security is always a space where you have some overlap between different tooling but in this and you have the concept of defensive debt as well. So you want to have defenses at different levels of your technology stack to solve the problem. And that said, I think in this space we're kind of in a lot of enterprise are are kind of helpless because I'll take an example the identity approach. Like traditionally if we have an software system that's running in our company we'll our first and most important control will be to limit what permission it has right because and then no matter what even if it goes wrong even if it's compromised it can't um typically do stuff that was originally allowed to do but with these autonomous AIs with these assistants with these coding agents we kind of want them to have our permissions because we want to we want to tell cloud co to do something or cloud co-work to do something and we want to then go have lunch and we want to come back and see that it's done and we want to give it so many diverse tasks as well that we kind of can't find the right set of permissions to do so suddenly our identity security software is not very useful then if you think about endpoint security right or or API security like if we tell our cloud code that we want to recreate a database and it should delete it and recreate it.

11:54 That's great. That's going to save our DevOps team and our platform teams a lot of time. It's it's a great benefit of cloud code. But if cloud code is working on an unrelated task and suddenly thinks that maybe the right thing to do is to delete our database and recreate it, maybe we don't want that to happen. And unfortunately our endpoint providers or API security tools, they don't know what cloud was thinking. why is it doing what it's doing? Right? So, a lot of these existing tools, they don't have the context to understand what these very flexible, unpredictable systems are doing. If you're not building some kind of controls that are built for these systems, then you're either going to end up limiting them a lot, making them almost uh much less useful to the enterprise, or uh you're going to miss a lot of pretty dangerous things that they might be doing. As somebody who has worked in security for a long time, my first very traditional instinct on a problem like this is like that sounds like a problem for a proxy with a policy engine. We make some rules, we make the rules smarter. Like why why doesn't that work or did you did you try it?

13:03 >> There are few things that I mean proxies integration method I would say. So there's some there are some AI systems where like you would want to integrate with a proxy if that's the easiest way to do it. But number one, there's a lot of systems where that's just not viable technically because AI today runs on the cloud on someone else's infrastructure on your endpoint and just proxy is not always an option. And the second thing is the question okay great you're proxying so you're seeing the data you're seeing but that's not the hard problem. The hard problem is understanding if what I should do now it turns out that in the case of AI systems that is the hard question like what is the engine that needs to underwrite these different actions and say if they're okay or not and because we need to be able to understand what another system is thinking what is it planning to do and then have our own opinion on that and consider we're we're trying to understand if some of the smartest models in the world are doing the right thing so who for we to do it, how are we going to do it correctly, right? And so that turns out to be a really difficult technical question.

14:11 >> Part of the solution for Onyx has been training its own models like what can you say about that? >> If you if you tried today, let's say you were trying to build a solution to oversee and kind of control how other agents are operating, may maybe the first thing a lot of our listeners might think is say, well, I'll just ask cloud code to do it. and and and in in a sense they would be right because cloud code is great and maybe we can ask it to spawn a version of itself for every agent that we have and kind of keep monitoring everything that agent is starting to do and if you think that there's a problem um intervene. So that approach it has obviously it's pretty naive and there are some ways in which it totally fails we could talk about but it has some merit to it right. So it does seem intuitive that it's a good idea to have uh capable agents reviewing what other agents are doing. Same as we have capable humans reviewing what other humans are doing, right? But then the problems that you're going to run into is how do I make this work from a uh cost, latency, and reliability perspective? Because if I need to run an agent for every agent you're running as your security vendor, h you're going to be paying for me more than you're paying for your AI, right?

15:34 So it's not it's pretty much a dealbreaker and also it's going to be so slow. So you're not going to be happy with whatever latency you're going to get. And so the challenge then becomes to how do I know what are the times where I need to interject with these smart agents to look at what's happening and that's when actually what you want to do is you want to try to train very smart models that are um actually let me correct said very not smart models but models that are just good at one thing.

16:10 They're very small. They're they almost can't do anything else other than be able to say, "Should I have a smarter agent? Look at this." And if you manage to bake in that intuition into those small models, well, in the sense that they don't miss a lot of stuff and they don't call that other agent too much, then you can get to a really good balance of we're very performant. We have smart agents overseeing things when needed, but we're not uh but our costs are low and our latency is low. And then that becomes the challenge because you need to make sure that as the frontier models get smarter and the hardnesses become more evolved, you need to be able to have models that are on your side that are small and effective at continuously h being able to say now is the time this is the action where I think someone should take a closer look and that's why on strains models for this purpose and it's you know most of the hard things that we're doing are in this space.

17:14 >> Yeah. You you and I actually both love to play blitz chess and I I look at Guardian as a system that's a little bit analogous like it's not clear either of us as going to be competitive with Magnus in a real game. But if the if you play if you play enough times with the right data and all you have to do is make intuitive decisions under time pressure very very quickly, it's actually a different game, right? And and do you think do you think that makes sense or am I reaching here?

17:43 >> Yeah, I actually I didn't think about it, but yeah, there's a lot of analogies because I think if you look at top chess players in the world like most of the moves that they make are intuitive. They don't calculate forward. They've seen so much games and they've played so much games that they already have a good sense of what is the right move and that they're not taking too much risk here by taking this move without calculating.

18:05 And then if you look at those games, every once in a while they do stop for suddenly a really long period of time to just calculate forward a lot of options because they know this is a critical move in the game. There's risk. You need to think through what you're doing and you need to decide correctly. I think that's very similar. It's the efficient way to to to run computation, right? You don't want to spend too much intelligence where you don't have to and you want to spend a lot of intelligence overwhelmingly a lot in situation where there's high risk. You guys are a team mostly based in Israel today. Um I think the the world has accepted that there is a cohort of amazing Israeli security talent that comes out of you know the military and offensive security and then you know repeat repeat entrepreneurs like you guys. I think the DNA at Onyx is a little bit different here. Your co-founder Gil came out of building synthetic data and working at Nvidia.

19:02 like how do you what would you characterize the like talent at Onyx as particularly good at and then you know are are people actually training interesting frontier models in Israel now? >> So first of all I think Israel is is a bit started maybe a bit late in the game but is catching up quickly. So I think there's now amazing companies in Israel building world models building AI infrastructure that's uh top of its glass building chips. So I think Israel in general is becoming uh very strong in AI and we're proud to be a part of that movement and I think you're right. Our company has a a very mixed DNA between cyber and AI which kind of reflects mind and Gail's backgrounds. Most of the people in our company, most of our research engineering come from a unit in the Israeli intelligence where we actually deal with math and cyber and the intersection thereof. And so I think it it is also reflected in in kind of the type of talent that we bring in. I think it's important for a few reasons.

20:08 The first and foremost is that we want to be more than just a security company long term. We think that to solve this problem well it's going to require deep AI expertise but then that the problem is not just cyber security. The problem is how do we control advanced AI long term and that problem even if you just forget about you know enterprise security and the different gaps in various controls that they currently have first principles that problem just sounds very important to me. So I think it will be crucially important if you have AI companies that are $10 trillion companies. We think you want a company that is not the vendor of the AI itself to oversee and help you control what AI is doing. And we think that's an opening that's you know a hundred billion plus opening for a really important company.

21:02 Um, and then if you think about what is what is going to take uh to control advance that long term, then we're just scratching the surface because long term you're going to have to also understand much better what models are thinking, what models are what's happening on the internals of these models as they're operating. And that's also a lot of where our research is focused. >> So the industry is um quite divided on this issue. I I mean amongst the people who think about whether or not uh mechanistic interpretability or research into better understanding models is is possible like that's a question and it uh so it's something you believe in.

21:43 >> We believe that there's been a lot of strong progress in that direction. We believe that understanding the internal weights and activations, what is the internal structure, the mathematical structure of these systems is going to be at least part of the solution. And in many ways we think that and this is maybe um you know we'll only know when we get there but we think that for our level of intelligence it's kind of difficult to understand very quickly what is the internal structure of a large language model what is the internal structure of the way >> you mean >> our level like human intelligence or our level of your model okay human intelligence >> oh yeah yeah I think Like yeah, exactly.

22:32 I think as as humans, it might still be very difficult to understand what weights and activations mean and maybe mechanistic interpretability. It seems like, oh, maybe that's too hard or shouldn't be possible. But as we're starting to have models that are much smarter than us, at least in some important ways, we think that uh we'll be able to start cracking mechanistic capability much more effectively. And I and I think it's going to be extremely rewarding. by the way long-term uh for understanding in intelligence in general like not just overseeing but just understanding what intelligence is how it works what's the difference between the smarter model and the less smart model >> I completely agree that the opportunity to understand and trust and secure and govern um these super intelligent AIs is a is a very large opportunity. Uh the if we just scroll back today, the security person in me says, "Well, then I have to give you all the permissions and understanding that I have to give these companies too." Like how do you get customers or you know the Fortune 100s you're working with already um or you know technives everybody cares about their own security and business to trust you now as a you like less than 100 people. Right.

23:50 >> Right. Um, I think it's one of those things that should not be possible. So, in theory, um, in theory, like there's no reason why a Fortun 10 or 20 company would work with us because, you know, who are we? We're a 2-year-old company or like a few people from uh, you know, Pan, Matic, Cyber, but I think it it's an opening that only happens when the pain is very strong. So their pain is so strong that they're going to say, "Oh my god, I just saw this company come out of stealth, but it's a problem that I have daily, so I'll give them a call." And suddenly you get inbound from these large customers, which is of course like uh the best thing you could hope for as a entrepreneur.

24:38 And I think it it reflects in my opinion their understanding that a lot of the startups in this space are still small and new, but there's going to be a huge company here and we want to find the right horse to bet on. So we're going to take a look at these companies and number two that if we don't do anything then in a very short time this will disable our business. At the end of the day security people are in the business of revenue preservation. They understand that this is a between the tourists.

25:06 They want to partner with someone that's promising and early rather than not doing anything. >> The other thing besides agent actions across their surface area that every CISO I know is freaking out about and every engineering leader is freaking out about is the um I would just describe it as the uh plummeting cost of vulnerability finding with these coding tools. >> Yes. And that has caused a number of issues for vendors um uh uh that are are being compromised like um how do you think people should react to this other issue?

25:45 >> I think mythos is is really like if you if you took me 10 years ago automated vulnerability research looked like a a dream that would take 20 50 years to to happen. H maybe it's because you know we were doing a lot of that in the Israeli intelligence and we like to pat oursel on the shoulder of how difficult the job is that we're doing but but it did look really far and suddenly it's coming all at once and so I think that first of all the market is not overreacting I think this is a huge change in what this means for security teams if you're a pragmatic security person today you you understand that you need to move very quickly Your strategy might look something like I need to do the fastest quick fixes I can to mitigate the immediate risk. So maybe I'll invest in uh whatever the funers that have been found. Let's try to to mitigate for them whether it is through patching or through mitigating controls.

26:46 H but then the real solution and every security leader um at large enterprise knows it is that we need to have the foundational pieces in place to avoid those risks and the foundational pieces are we need to have identity as locked down. We need to have um a firewall. We need to have endpoint detection. And for different asset classes in your enterprise, for different parts of your stack, there's a different foundational security mechanism that you need in place for the AI attack surface that you now have or for the AIS in your company, you also need a foundational security and that's kind of the role we play in that space. So if you're as part of your preparation for Mythus level models and and beyond, you're going to need a lot of foundational uh security tools to fortify your different uh uh parts of the enterprise and we're playing that part in the AI space.

27:45 >> Do you have a point of view on the phased rollout or controlled roll out with glass swing and daybreak from from Ant and OpenAI in this area? I don't have a strong opinion, but I think it's a on the one hand like if we knew that there's not going to be anyone who's going to release a method level model soon, I think that would be great because it gives enough time for to prepare to build the knowhow to build the playbooks to share that around in the community and to make sure that we're not starting to see airlines go down and power plants go down and really like disastrous effects that could happen. The problem is that if anyone gets to a mids level model earlier then in retrospect it would look like a huge mistake because we could have at least given companies the choice to start moving very quickly and give more companies access to methus. Now they're all vulnerable because you know there's a Chinese model that's mythus level and there's nothing they can do about it. So I think hopefully we'll manage to do the gradual roll out correctly. I would really encourage that we expand the amount of companies that get access to this and make it much easier for people to get. I would advise everyone to assume that these models are coming anyway. The only thing you can do right now is to invest in these foundational controls that will stop the downstream effects of these vulnerabilities are going to be found in their systems.

29:11 >> Do you see in um large enterprises like any holdouts? Right. Uh, and I I would say I actually haven't spent a bunch of time talking to people about this recently, but I remember a year and a half, two years ago, there were large companies that just said like, "We're going to ban all of this stuff until it's safe." >> Yeah, I hardly see it anymore. I think in the financial sector, there's some companies that are more uh opinionated on what they allow. They still allow agents, but they're maybe like more u granular as to like maybe we're only going to allow these two tools. I personally think that the companies that are going to do well are the companies that are going to allow a lot of different tools because the landscape is changing so quickly. If you bet on OpenAI a year ago, that would have been the safest bet in the world, but suddenly Antropic has much better models and better tools and potentially a year from now there's someone else has much better tools. So, uh, I think there's a price to pay. But I think if you're a large company, your risk profile is and should be different.

30:21 Like, you know, when you're a startup, you want to have your agents do everything for you because you have everything to gain and you have nothing to lose. Where you're large, where JP Morgan, you have so much to lose and you can maybe take a bit more time to gain what you can gain from AI. And by the way, I you know JP Morgan is adopting AI very quickly. I think it is okay for companies to have a nuanced view the bigger they are on on how they're adopting AI.

30:46 >> How do you think about that question for yourself like risk profile pace the environment is changing very quickly um and then you know uh you see a lot of problems growing the the scope of the product and the research thesis here is already quite large. we are kind of in luck in the AI security space because yes there are a lot of vendors there's a lot of new technologies that are coming up but the but the two core pillars of how 2026 AI works have not changed in the last few years. So, we're still using largely LLM foundation models that are not entirely dissimilar to how they were a few years back. And we're still building agents in pretty much the same way where we have an LLM decide what are the tool calls that we're going to make and generate those. And so that does allow a company today like us to skate to a lot of different applications that are utilizing these two primitives while still keeping the core technology that we're developing fairly lean and focused. Now, of course, there's always a risk that tomorrow there's a completely new LLM paradigm that could happen or a completely new agent paradigm that could happen. And that's why we do try to, you know, uh we have a strong opinions loosely held about what does that look like in 2027. We maybe have a good picture for 2026, but for 2027, we're very open-minded and we think that's the right stance to be for the next two years until we see what does AGI ASI look like.

32:36 >> Do you see the set of problems you're addressing trust in the models as um and governance of them as something that the labs could ever do or do you think it's a structural thing? I I ask because the number one question amongst the startup ecosystem in the Bay Area today is you know if you assume capability improves or you know when the labs just gets hungrier from their already currently ambitious stance uh why wouldn't they do this too and and so I I ask you the same question >> today if you if you're a private person or if you're a security buyer there are some places where you don't want to trust the same person that you're buying it from. So, you know, maybe, you know, if you're buying a car, you're not going to have the same guy that you're buying it from certify that the car is good, right? You're maybe going to have someone else do it. And if you're a security uh team, you're not going to trust the vendor of a product to tell you that this product is not going to mess your environment. You're going to want to have an independent party whose whole business depends on telling you that this thing is correct and being right, this this thing is legitimate and being right. So that's like there's the buyer psychology in the space that I think really goes in our favor and then I think there's the core problems like why are models even making mistakes? Why are agents even making mistakes right so that I would broadly categorize it into two things one is you know there's the jagged intelligence of these models and there's like sometimes kind of very silly mistakes that they make and I think that problem will go away. I think we're heading for much smarter models that make less silly mistakes and and our role is not going to be to prevent silly mistakes. That will be taken care of by the the model vendors because they're very incentivized to do it. Um, I think what is the other fast growing category of things that we're seeing models do wrong is places where they're actually not making a thing that is like a silly mistake, but more I would say have a independent uh, you would even say semi-aware or semi-conscious h perspective on what should happen and that perspective might not always align with your perspective.

34:53 And I think that is a problem that we've seen grow hand inhand with models getting smarter. Maybe just the the way it is that as you get smarter you have more independent thoughts and and more uh you're more conscious and I think that problem is actually seemingly very hard to tackle today even for the large vendors. And one of the key things that are making it easier for us to understand and detect these things versus the other vendors is that you know we're allowed to do certain things that they're not. So for example, we're allowed to look at a lot of historical data of how these agents have behaved. But enterprises today are not willing to have anthropic or open AI give that historical data because they know these are very data companies that will want to train on that data. And so I think there are some ways in which you are given more in which us we're given more context uh and more latitude uh to know if something is happening that is wrong compared to the past compared to how these agent typically behave and so on that the vendors don't have and is really important in in solving this problem. And the last thing I'll say is that you're not dealing with one vendor.

36:10 So, we're heading for a world where there's a multitude of different vendors for many reasons. You know, you're going to have for cost reasons open source models that people are going to use because it's cheaper and you're going to have um uh models that are better at different tasks and at different cost uh profiles. And so it is be going to be unrealistic to expect all the vendors to provide the same level of security and to assume that as you're trying to adopt technology very quickly especially coming from new vendors that obviously have not yet built out all of that. So I think that these are the reasons why I think it would be very difficult for this problem to be just completely solved by the large labs. Just to close and also thinking about what you know people in Silicon Valley or outside of security may not know you're building this from Tel Aviv right >> I think one of the deepest adversarial thinking benches in the world is is the Israeli ecosystem 8200 whiz Armis Island Denniso group right um what do you think that the researchers engineers business people in you know the tech ecosystem outside of security and then in in the labs in particular are are missing about what what needs to happen in security and you know alignment which is what you're talking about here. What is really important when you're building security products in general and I think what what people in Israel have really good know is just understand how security teams work because at the end of the day no matter what is the technical problem you're solving you're building a tool for people for an organization that organization has a certain structure there are certain teams there are certain flow of responsibilities of information and creating a product for this audience that they they don't just doesn't just solve the technical problem but they actually love is really hard. You need to really care about just the dayto-day of these different functions and you need to have people in your ecosystems that have built products for them in the past that know them like they know their best friend like they know what they do when they step into the office in the morning they drink their coffee. What are the system they're opening? What is their boss wanting from them? What are their colleagues wanting from them? what are they going to get praised for? What are they going to get mad for? Then you need to take that and make it as your product. And I think that's I think today one of the kind of really hard things that people in Israel learned to because they've had so much contact with these buyers and and end users. And yeah, I would just encourage people to be much more curious about the day-to-day of security people. And it's a cliche to say it, but these people are actually saving us daily from attackers stealing our money, taking our data, and they're kind of keeping our way of life as it is in this digital world. So, yeah, I think more love to security teams around the world.

39:13 >> I'm going to ask you to just square that with something else you've told me, Maxim, which is you're the most AGI pill person I'm going to meet in in Israel. embedded in what you said is a belief that we will continue to have defensive security teams >> for some number of years. So you do believe that >> I do think that uh security teams are also going to be become completely high powered and but I do think that you know they're going to be run by AI agents and like everything else in in in kind of the knowledge work space I would in the in the near future but I do think that it's important to be grounded and today when I sell a product I sell it to a human audience with a few agents and by the way we also invest in making our systems very convenient for agents to use and it's important that I focus on delivering an amazing experience today for people who buy the product today and as that audience becomes more agents than humans it will be important for us to evolve and to make it work really well for agents doing the work so I think the core principle is the same we need to really be minded of who is the end user what is their experience for a human it might be not overwhelming um with too much information that is irrelevant. For an agent, it might be not wasting too many tokens in their context when we talk to them. Maybe it's the same thing really. So I think it's important that uh we always remind them that who's using the system and what will be the best experience for them.

40:45 >> Awesome. Thanks so much for doing this Maxim. >> Appreciate it. Thank you very much. >> Find us on Twitter at no prior pod. Subscribe to our YouTube channel if you want to see our faces. Follow the show on Apple Podcasts, Spotify, or wherever you listen. That way, you get a new episode every week. And sign up for emails or find transcripts for every episode at no-briers.com.

Summary

Maximbar Kogan, co-founder and CEO of Onyx Security, discusses the rising concerns around AI security, particularly regarding the actions of autonomous agents and the need for oversight mechanisms. As enterprises increasingly adopt AI tools, the risk of unintended actions and vulnerabilities grows, necessitating specialized solutions to monitor and control these agents effectively.

- The exponential growth of AI agent actions has led to heightened security risks for enterprises.
- Onyx Security focuses on training models to oversee and validate the actions of AI agents, addressing the limitations of traditional security measures.
- The emergence of autonomous agents, such as AutoGPT, has shifted the landscape, prompting enterprises to adopt more capable AI tools.
- Current enterprise deployments show a significant shift towards autonomous coding agents, which are rapidly becoming the dominant category.
- Existing security frameworks struggle to manage the unpredictable nature of AI agents, necessitating new foundational security tools tailored for AI.
- The Israeli tech ecosystem is becoming a leader in AI and security, with a unique blend of expertise in both fields.
- Trust in AI models and their governance is crucial, and independent oversight is necessary to ensure security and legitimacy.
- The future of security will involve a mix of human oversight and AI agents, requiring products that cater to both user experiences.
© transcribe · For agents Built with care and craft by Gokul Rajaram