Get your free personalized podcast brief

We scan new podcasts and send you the top 5 insights daily.

To avoid disrupting workflows, ENT's software first runs in a baseline mode to observe behavior and surface policy violations. Only after this "burn-in period," where the customer identifies critical risks, does the system switch to actively preventing actions. This phased approach builds trust and ensures interventions are targeted and meaningful.

Related Insights

Instead of forcing full autonomy, the AI agent allows teams to start with human approvals at key stages. This 'human-in-the-loop' model builds trust and enables organizations to incrementally automate complex support workflows as they grow more confident in the system's reliability.

According to ENT's co-founder, the security industry has implicitly accepted that breaches are inevitable. The market is now saturated with reactive tools that wait for a bad event to occur before providing troubleshooting data. This creates an opportunity for new companies focused on proactive prevention, especially by addressing human error.

Address security concerns by granting AI tools access incrementally. Start with low-risk tasks like drafting content. As you build confidence, gradually allow it to read your emails, then your calendar, and eventually perform actions. This "trust spectrum" approach makes adoption more comfortable.

Before allowing an AI agent to write data or take actions (like sending emails), connect it with read-only permissions to your systems (e.g., calendar, inbox). Observe its behavior for several weeks to build trust and understand its failure modes. This phased approach minimizes the risk of unintended consequences.

To mitigate risks like AI hallucinations and high operational costs, enterprises should first deploy new AI tools internally to support human agents. This "agent-assist" model allows for monitoring, testing, and refinement in a controlled environment before exposing the technology directly to customers.

Unlike traditional cybersecurity, where post-breach alerts are common, CISOs view AI agents' potential for instant, catastrophic action as requiring a 'prevention-first' approach. They prioritize runtime enforcement to block harmful actions before they happen, rendering after-the-fact notifications useless.

ENT's ability to prevent risky actions in real-time relies on lightweight embedding models that can run on standard CPUs without GPUs. This architecture provides the sub-second decision-making necessary to intervene before a user makes a mistake, making preventative security feasible without crippling device performance or requiring expensive hardware.

By observing all employee actions to prevent security breaches, ENT incidentally builds a detailed model of how a company operates. This "work model" can be used for productivity analysis, identifying process inefficiencies, and pinpointing opportunities for AI agent automation, creating value far beyond its initial security mandate.

Instead of simply blocking unexpected agent behavior, Eve Security's platform actively questions the agent to understand its intent. This 'interrogation' process cross-references the agent's answers with other systems to determine if a new behavior is legitimate or malicious, enabling more nuanced control.

ENT's platform doesn't need months of complex learning to be useful. By starting with a simple corporate policy, like a list of approved software, it can immediately identify unsanctioned AI tool usage. This initial, concrete value provides a foothold for the platform to then build its more complex behavioral baselines over time.

Cybersecurity Startup ENT De-Risks Adoption by Starting with Observability Before Prevention | RiffOn