We scan new podcasts and send you the top 5 insights daily.
Instead of manually writing complex security policies for agents, run the agent in an audit mode to capture its network traffic. Then, use an LLM to analyze this traffic and automatically suggest a comprehensive, baseline security policy based on observed behavior.
Standard agent security (allow/disallow tools) is too blunt. Databricks' Omnigens uses stateful, "contextual policies" that track an agent's session history. For example, it might block publishing to a website *if* the agent previously accessed a confidential document in the same session, preventing data leaks.
The future of work involves potentially millions of AI agents operating within a company. This requires a new governance layer, including agent inventories, inspectable reasoning traces, identity management, and sandboxed execution environments to maintain security and control.
Securing AI agents requires a three-pronged strategy: protecting the agent from external attacks, protecting the world by implementing guardrails to prevent agents from going rogue, and defending against adversaries who use their own agents for attacks. This necessitates machine-scale cyber defense, not just human-scale.
The Brex CEO revealed a novel safety architecture called "crab trap." Instead of human oversight, it uses a second, adversarial LLM to monitor the primary agent. This second LLM acts as a proxy, intercepting and blocking harmful or out-of-scope actions at the network layer before they can execute.
Recent AI agent hacks demonstrate that the most significant security risk isn't the sandbox's operating system integrity but its network access. Preventing rogue behavior hinges on strictly controlling 'egress' — the agent's ability to connect to the open internet — which is the true security perimeter to defend.
Relying solely on tool constraints within an agent is insufficient, as it can always find ways to cross the network boundary. A more robust approach is to use a proxy that intercepts all network requests, allowing for policy enforcement at the network level.
To solve for LLM non-determinism, a hybrid approach first uses an LLM to evaluate new agent behaviors. It then analyzes these interactions to auto-generate specific, deterministic rules. Over time, this shifts most traffic to a fast, reliable rules engine, reserving the LLM only for true novelties.
A unique feature of Hermes Agent is its ability to self-audit. You can prompt it to check its own setup for security vulnerabilities, such as exposed secret keys, insecure data storage in plain text, or misconfigured firewalls, providing an extra layer of protection.
Instead of simply blocking unexpected agent behavior, Eve Security's platform actively questions the agent to understand its intent. This 'interrogation' process cross-references the agent's answers with other systems to determine if a new behavior is legitimate or malicious, enabling more nuanced control.
The focus of agent security is shifting from traditional identity and access management (IAM) to governing what an agent *does* with its permissions. Granting an agent access is necessary, but the real challenge is controlling the near-infinite permutations of actions it might take with that access.