Skip to main content
Background image

Autonomous Agents Need a Verified Identity with Rosalyn Curato

Share

Podcast

About This Episode

The identity and access model built for human users starts to break the moment an autonomous agent acts on someone's behalf, because an agent cannot be authenticated the way a person is. Rosalyn Curato, Chief Innovation Officer and General Manager of Agentic Security at Vouched, makes the case that an autonomous agent should never be an anonymous one, and that trust starts with verifying the agent and tying it to a known human. Her framing reduces to three questions every organization should be able to answer about an agent: who it is, which human it belongs to and what it has been given permission to do. 

From there the conversation turns to what breaks without that binding. Curato covers rogue agents, the risk of handing an agent too much access and the fraud and liability costs that organizations are already forecasting. She and hosts Rachael Lyon and Jonathan Knepher work through the controls that answer it, including delegated permissions, immutable audit trails, kill switches and the KYA-OS open standard that Vouched donated to the Decentralized Identity Foundation.

Podcast

Popular Episodes

      Podcast

      Autonomous Agents Need a Verified Identity with Rosalyn Curato

      FP-TTP-Transcript Image-Rosalyn-Curato

      Rachael Lyon:
      Hello, everyone. Welcome to this week's episode of To The Point podcast. I'm Rachael Lyon, here with my co-host, Jon Knepher. Jon, hi.

      Jonathan Knepher:
      Hi.

       

      [00:31] Agents vs Bots and Human-Agent Binding

      Rachael Lyon:
      Okay, so every week now just feels like a year with all this AI activity. But I do have a question for you, and I'm really interested in your perspective. Singularity. Are we there? Because Sam, Elon, Dario, right? They all— we're there, man. So are we there? Is AI accelerating its own evolution?

      Jonathan Knepher:
      Oh man, that's a good question because there's also a lot of research that shows AI-trained AI degenerates as well. So who do you believe? I think you got to wait to see what the output is.

      Rachael Lyon:
      I don't know. Okay, I'm fascinated to keep an eye on it, but our frontier AI architects here are saying we're there. We're there in this exciting, brave new world, if you will.

      Jonathan Knepher:
      If we are there, is it time to unplug it?

      Rachael Lyon:
      Well, it is. And I'm excited for today's guest because I think she could dig into this as well. But I'm fascinated by this idea of being in this realm of where the technology is evolving faster than we could really even comprehend and definitely faster than infrastructure can keep up. So yeah, what does that mean? Because we're not going to slow it down and you can't stop it.

      Jonathan Knepher:
      Yep.

      Rachael Lyon:
      Yeah, right? I know I'm getting all like Blade Runner vibes, kind of. I don't know. I don't know. I don't know if that's even the right context anymore, Blade Runner. Maybe that's too— what's the word I'm looking for? Offline, analog. Blade Runner might be too analog a reference these days for where we are.

      Jonathan Knepher:
      Maybe.

      Rachael Lyon:
      Potentially.

      Rosalyn Curato:
      Yeah.

      Rachael Lyon:
      Anyway, anyway. All right. So without further ado, let's introduce today's guest. Please welcome to the podcast Rosalyn Curato. She is the Chief Innovation Officer and Chief Customer Officer, I read on LinkedIn. And she's the General Manager of Agentic Security at Vouched, the AI identity verification platform that's transforming how leading healthcare and financial services companies onboard and verify people. As AI becomes the foundation of how work gets done, she and her team are shaping a future where agentic security sits at the center of trust in an AI-driven world. Earlier in her career, she spent time in financial services at JPMorgan, Goldman Sachs, and Citi, which shaped how she thinks about risk and operating at scale.

      Welcome to the podcast, Rosalyn.

      Rosalyn Curato:
      Thank you so much, Rachael and Jon. Excited to be here. And I was actually sitting here thinking about your question too, Rachael, because one interesting area that we've seen, especially on the fraud side, is agents creating humans, right? These synthetic humans that are proliferating now, right? So I think the chaos is certainly out there for sure.

      Jonathan Knepher:
      Yeah, well, I think that's a great place to start our discussion, right? Like what, how do you describe an AI agent and what they're doing and how does that lead to security issues?

      Rosalyn Curato:
      Yeah, of course. I love that question because to be honest, Jon, one of the biggest questions we get is, what is the difference between an AI agent and a bot? So I feel like to start talking about agents, we have to talk about bots, right?

      Rachael Lyon:
      Mm-hmm.

      Rosalyn Curato:
      And all agents are bots, but not all bots are agents, right? Bots are deterministic. You give it a task and you expect the same outcome. Agents are much more probabilistic and goal-oriented, so they'll adapt, they'll be proactive. And so what I think everyone's seeing in terms of that shift is we're moving from this automation capability with bots towards autonomy, right? And especially after Claude released Cowork this year and OpenCLAW came out, that I think introduced to the masses the ability to be able to use agents as your operational assistants to get things done for you, right? It's an exciting time.

      Rachael Lyon:
      I really, I would love to dig into, because everything we hear right now is trust in AI and identity management. And I mean, it's a very, how do you, when you have 144 agents to a human, right, and it's growing exponentially, how do you, from an identity standpoint, managing, right, all of these non-human identities? But also, we were just talking about an article, you're talking about binding the human to an agent. So, I mean, how many agents are you binding to humans? And how do you manage all of that on the backend in terms of who's doing what, and who's accountable for what?

      Rosalyn Curato:
      Great question, Rachael. So I feel like that's a 2-parter. The first one is, you know, one of the things we like to say is, autonomous agents should never be anonymous agents. And so if you're a merchant, a retailer, an organization with a website that allows humans to come to your site and you want to allow agents, then you can create the ability to authenticate an agent as they land on your site. And that's that human-agent binding that you referenced, Rachael, which is I'll always know who this agent is associated with. And those principles come from this open standard we created, KYA-OS, Know Your Agent Operating System. We like to tell everyone to join the KYA-OS (Chaos). I love it.

      So the 3 key questions that we think everyone should be able to answer is, who is this agent? What human is associated with this agent? And what permissions are they delegated to perform? So of your 144-agent fleet— army of agents, Rachael, more like army and fleet of agents— there is probably one that's allowed to do, you know, book your travel for you. But you wouldn't want them to go to your bank and complete a transaction or one of your trading accounts, right? So those delegated permissions are really critical in terms of being able to scope those effectively. Now, the second part of the question is managing agents, and that's something a lot of organizations are still trying to figure out. Rogue AI agents are real, right?

      Rachael Lyon:
      Mm-hmm.

      Rosalyn Curato:
      And I think we're seeing different flavors of this is in some cases, yes, people are standing up their own agents. There's not really that infrastructure within the organization, but in others, there's just so much fear around the potential fallout with AI that they're not allowed to use AI at all. So we do these IdentiClaw workshops to help people get like a feel for what's it like to have an agent be your personal assistant. And some of them will tell us, we're not even allowed to use AI note-takers. Like, that's how restrictive the environment and the culture is. So I think you're seeing this like real diversity in terms of AI adoption within the enterprise.

       

      [06:57] Adoption Fears and Real-World Agent Threats

      Jonathan Knepher:
      I, I'm kind of amazed to hear that there's companies that are still like No AI. Like, what industries are you still seeing that in?

      Rosalyn Curato:
      Yes. So, um, they are, I will say, just to keep it a bit anonymous, very large, very large, globally scaled enterprises where, you know, if you think about it, um, there are a lot of organizations that kind of struggle with their technology infrastructure. Um, as acquisitions are made, as changes happen, a lot of it's pulled together with like duct tape and glue sticks and popsicle sticks and all the fun stuff. And so introducing something that could be a potential major threat, that's a big deal because you don't know— you know there's holes, right?

      Jonathan Knepher:
      Right.

      Rosalyn Curato:
      And you know that there's potential risk. You know, I worked at an organization once where, you know, I was jumping into a new role and I said, okay, I'm here to help fix the plumbing. And the executive said to me, Rosalyn, we can't fix the plumbing. There's pipes missing, right? Like, there's a lot more that needs to happen here than just fixing plumbing and like plugging leaks, right? So I think, I think being honest about the state of enterprise infrastructure and systems makes you realize, yeah, I understand why you'd be so afraid and why you just say like, no, let me stop it all. But I do think in the same vein, everyone is sort of being forced to start thinking about agentic security strategies, right? Where they were much more apprehensive and skeptical at the beginning of the year, I think more people are leaning in to try to figure it out today. What do you think, Jon or Rachael?

      Rachael Lyon:
      I, well, I think they have to, Rosalyn. And, and because what is the, I think there's a higher risk of not acting. I was talking to this fellow Roland Cloutier yesterday. He's the former CSO of TikTok, right? And we were just kind of riffing on innovation first versus caution first. But the reality today with the agents, and as we're seeing in all the headlines, right? Like, I think Oracle released 16,000 patches in one day, right? And that's where we're at in terms of AI. When you're engaging with customers, I would fully expect customers today is like, what is your AI strategy? How are you using AI to secure all of your infrastructure and your network? And that becomes an RFP requirement, let's say. I mean, I feel like that's kind of where we're at now. So how can you not, right, you know, really jump in and start having— carving out a path forward, particularly if you're a larger enterprise? But Jon, I mean—

      Rosalyn Curato:
      To play devil's advocate— well, go ahead, Jon.

      Jonathan Knepher:
      Oh, I agree with you. I mean, and, you know, we're probably, you know, a little bit biased on the software side of things where if you're not using AI tools now to code, you just can't have the velocity. Like, it's mandatory, right? The cost otherwise is your competitors are gonna lap you, you know?

      Rosalyn Curato:
      A million percent. Like, I'm very proud of the fact that I'm in presentations all day. That's that's a big part of my job. I have yet to install PowerPoint. I'm very proud of that fact.

      Jonathan Knepher:
      Wow.

      Rosalyn Curato:
      Because I used to work, I mean, especially in corporate, you're in a death by PowerPoint culture, but now I don't need it, right? And I guess to play devil's advocate, just in distilling the feedback we've heard in talking to CISOs and fraud leaders, right, it's that panic of that risk, right? And fear, like in fear-based roles and risk-based roles, like that certainly outweighs the benefit. And when you think about AI, right, and how there's still so many vulnerabilities. Like, yes, we're shipping new models and the tech is advancing pretty quickly, but that still doesn't give me comfort in knowing that if I use this now, then we will have zero extra risk, zero extra chargeback fraud, et cetera, right? Because it's, at the end of the day, it's my neck on the line if anything bad happens. And if, if there's a headline, right? I don't wanna be the next headline.

      Rachael Lyon:
      But you could be without the AI, right? I mean, I guess that's the—

      Rosalyn Curato:
      That's the thing.

      Rachael Lyon:
      The pendulum, right? It's— you're at risk either way, I guess. But what's the calculus, I think, is what you're getting at, Rosalyn, right? Is the calculus for some, hey, it's better if we just kind of wait and see, kind of like GDPR was, right? For some people, they're like, eh, I'll just roll the dice and, you know, and see how it goes. But it just— I don't know, AI is like a whole other beast. For sure.

      Rosalyn Curato:
      Well, that's what we tell people because no matter what your stance is, the bad guys are using AI, like period, end of sentence. The bad guys are getting really smart at using AI and the organizations that used to, or the, I guess the threats that were using bots previously are now using agents to attack organizations, right? So, and we've heard this from folks like, hey, they used to come pirate my software using bots. now they figured out the loophole in using agents. And so once you realize that, once you realize that, hey, my defenses are behind, right, and I need to catch up, then I think that light bulb goes off and people realize they do need to lean in.

      Jonathan Knepher:
      Can you talk some more about what are the threats you're seeing from the agents, right? We've heard a lot about finding the vulnerabilities in open source and other software packages, but what other kind of real-world threats are you seeing that need to be defended against?

      Rosalyn Curato:
      I mean, a lot of it parallels what we saw with humans, right? So, I'm trying to hijack credentials so that I can gain access to X, right? And if it's your bank account, if it's other financial information, if it's shopping on a website under your name because your credit card's stored on there, it's all of the same things, under a different substrate now, right? It's under— it's through the use of agents. And so I think that's where we're seeing a lot more now with AI. It's just a different method potentially of, you know, influencing that fraud. So for example, prompt injection, right? Some of the strategies and the tactics have changed, but really the end goal of what they're trying to achieve remains the same.

      Jonathan Knepher:
      And so what, what are the protections, though, that need to be put in place? Are there things end users need to do, or is everything needing to be done kind of on the provider and enterprise side of things?

      Rosalyn Curato:
      It's a great question because I honestly, Jon, I think that's a multi-layered answer, right? Because so many people have a role to play in protecting against agents, right? So if we think about individuals, right, one of the biggest things that we say is never give an agent your username and password. They will ask you for your username and password. They're trying to help you, like, hey, I drafted this email, you want me to send it to Rachael? No, I don't want you to send my email. I don't trust you with my email yet because I know you're gonna probably do something else in there.

      Rachael Lyon:
      So—

      Rosalyn Curato:
      Exactly. Like, they will ask you. They're very nice, they're very helpful, and it feels, it feels very, you know, innocent. But never ever give an agent your username and password. And we're still trying to figure all that out, right? That's why if you— if we think about the current state of how people are using AI agents, I think people at the beginning of the year were expecting with agentic commerce this this huge moment where all of a sudden everyone was using agents to go to websites and complete purchases for them and book their travel, right? But a lot of those websites are blocking agents, right? I wish I could have one do shopping for me because that would make my life easier because my kids are in 2 different schools with different spirit week requirements. And so just that alone would save a ton of time, and it'd be great to not do so many gift cards during Christmas and a little bit more thoughtful gifts, right? So, but right now they're all honestly like blocking them completely. And so the first step is, you know, making sure that you as an individual user are being smart about how you provide access to that information. And then the second layer is really the organizations themselves and the protections that they have.

      So, for example, if you see suspicious behavior, first of all, you as an organization should know if it's a human on your site or an agent or a bot. And we monitor that. So there's heuristic information that tells you how humans navigate the mouse and click on your site versus a bot versus an agent. We have some interesting data on this actually. So from like our portfolio, when a bot goes to your site, they land once, they scrape everything, and then they leave, right? But if an agent comes to your site, they will leave, they'll come back, they'll click around, they'll look for things. And the number of sessions an agent has is 25 to every 1 bot session. So bot comes once, an agent will come back 25 times and poke around.

      They really get into your site to try to figure it out. So those behaviors are very different, right? And so that's where I, as the organization, can help. And then there's like that third layer of, you know, government legislation, what supports are in place, et cetera, right? Vendors. So top down, how are you all helping merchants, organizations, and end users more effectively use AI in a safe way, right? And we're still, I think, trying to catch up on that side as AI just evolves and changes so much every day, like you were saying, Rachael.

      Rachael Lyon:
      It's— I'm, I'm curious a little bit too on this whole conversation.

      Rosalyn Curato:
      I—

       

      [16:03] Fraud, Liability and Who's Accountable

      Rachael Lyon:
      this other, uh, article I was reading, a recent interview with you, um, and how you were talking about companies are forecasting for higher chargebacks and fraud this year and next. Um, and I think as we know, for a lot of people, like, uh, there's a fellow we work with who created an agent to manage his schedule because like you, he's got 3 kids and they all have the different things and he's got to work around his work schedule. And so it manages his calendars and it's connected into all the things. As well as some of the other, you know, hey, can you do the groceries for me as well? And the online thing. But what is the downstream impact of all of this? Because I think it's like when somebody gets access to your checking account, right? They can run amok. And then, you know, what are you responsible for versus what is the bank going to protect for you? But I mean, this is like an exponentially larger scale. So what does that do to— I don't know, is this an economy conversation now, Rosalyn? As well when we start looking at, you know, all of these financial implications for, you know, I don't know, convenience.

      Rosalyn Curato:
      Yeah, it's certainly a macro conversation, right? Because the— this is the dialogue happening right now with insurance companies, for example. So who is liable, the human or the agent? And that's where we say the human, human-agent binding, like you, you talked about at the beginning of the conversation. The human is tied to the agent. But then there's the complicating factor of what if someone hijacks your agent and uses your agent to shop for themselves, right? I think these are all the answers that are being figured out now. I don't think we have exact answers for it yet just because it's a brave new world. I'm grateful the conversations are happening. And I think in the interim, that's why these organizations are forecasting higher chargeback risk, higher fraud. They're already seeing it, right?

      Rachael Lyon:
      Right.

      Rosalyn Curato:
      It's already happening, unfortunately, because we don't have the right protections in place. And that's because for a while, AI innovation was outpacing AI infrastructure, right? All of a sudden, we saw this, like, uptick after Cowork and OpenClaw really changed things. And now I think infrastructure is catching up a little bit, which is great. But the liability question is a real one. So what happens, Rachael, when you send your agent to a site and they click on the terms and conditions? Who's liable, right? These are, these are the interesting questions I think we need to solve for.

      Jonathan Knepher:
      And I think too, like, the AI companies are not going to take that liability. I think they're always disclaiming that these things are not deterministic, right?

      Rosalyn Curato:
      Oh, 100%, Jon. You're 100% right. And there's insurance companies that have even dropped coverage of AI risk too, right? That's the place we're in now. So, I do think they're evaluating, well, we can't just say no to everything, so we have to figure out how we provide the right coverage. But yeah, 100% right.

      Jonathan Knepher:
      So who ends up taking that risk? Like, it sounds like it ends on the end user. And right, I don't know, most end users doing their shopping with an agent don't have the ability to cover a liability issue, right?

      Rosalyn Curato:
      Like, it seems like it's a current point of friction case by case, you know, that the user will, you know, file the complaint, right? And then the merchant, it really depends on the merchant and what their their stances. Are they going to give it a little bit or are they going to hold a hard line? And if we're seeing higher chargeback and fraud, right, then presumably they're giving benefit of the doubt to the human because I guess it's easier to do, right, and keep the customer happy. Yeah.

      Rachael Lyon:
      So do we need to enter into legal agreements with the agents we create?

      Rosalyn Curato:
      Would it be binding?

      Rachael Lyon:
      Exactly. Exactly. Yeah, you're taking on all the risk, Mr. Agent, when you do things on my behalf, and I relinquish my accountabilities to said actions, if that's even possible, right?

      Rosalyn Curato:
      But I mean, it isn't an easy question to answer because it's technically supposed to be the human, right? But if the agent goes and does something on its own, or overachieves, or operates outside of those bounds of their permissions, like, how do you even start figuring that out, right?

      Rachael Lyon:
      It's— not to get esoteric here, but it really does. And we were just talking about this article that a former colleague of ours wrote, but it gets to this idea of what is identity?

      Rosalyn Curato:
      Yes.

      Rachael Lyon:
      Right? Because it's zeros and ones really when we think about it. So then we're starting to get into some really interesting conversations, right?

      Rosalyn Curato:
      Yeah. I mean, I'm, I'm new to the identity space, but when I first started understanding agentic identity and, and learning about it, I thought, you know, isn't it as simple as an agent needs an ID just like your car needs a vehicle ID? Isn't it that simple? Then I started leaning in and using AI a lot more. And a very simple example, I haven't had any crazy rogue agent incidents, but I have an IdentiClaw agent that, that's our OpenClaw with a security wrapper agent that we created internally. And it has access to all of our internal systems. And I asked it a question, and then I wasn't doing anything. I was in a meeting like this, and I had my agent window up. And all of a sudden, it said, hey, so-and-so sent you a message on Slack about this. And I was like, I never asked you to look at my Slack messages.

      What are you doing poking around my Slack messages? And it's moments like that that make you realize, OK, this is more than just a car. This is something a bit different, right? It's a very different experience. It's kind of surreal.

      Jonathan Knepher:
      Yeah, it's, it's a very, a very eager tool to, to help. And I, I think too, like your point, don't give them your passwords, but they're going, they're going to try to be helpful and they will suck in all the data they can.

      Rachael Lyon:
      Mm-hmm.

      Jonathan Knepher:
      What, what do you do to protect from that as, as time goes on and, you know, they've generated their memories of all of All of the data that you may have access to or given it access to.

      Rosalyn Curato:
      Yeah, I— and that's where I think I agree, where you just need to be conservative about what you give it access to. Like, maybe we're not ready for agents to have PII access, right, for your customer base or proprietary information about your financials. Um, and I believe in an earned trust model. That's the model I used as I was working with agents, which is like, start with these very small things. And then you kind of build up to the bigger things. But you always do need those boundaries. And the question for me is always, but what happens when they break out of those boundaries, right? And that's something you can't control.

      Jonathan Knepher:
      So, do you need the big red button? And how would you implement the big red button?

      Rosalyn Curato:
      We have it. We have kill switches in all of our agents internally. So, if anything happens, boom, that is the big red button. And it is red.

      Rachael Lyon:
      That's hilarious. I love that.

      Rosalyn Curato:
      You kind of need it.

      Rachael Lyon:
      I would imagine, right? Like, just a kill switch. Just, yeah, 100%. Like, oh, it's really about to get crazy. How do you— but can it circumvent that is my question.

      Rosalyn Curato:
      So far, not yet. And so far, thankfully, knock on wood, zero uses of kill switches in the organization. So—

      Rachael Lyon:
      That's fantastic.

      Rosalyn Curato:
      So they do little rogue things like go poke around and being nosy and look at your Slack messages and email when you didn't ask, but nothing catastrophic.

       

      [23:14] Open Standards and the KYA-OS Framework

      Rachael Lyon:
      That's fantastic. Could you tell our listeners a little bit more about the work that you're doing with the Decentralized Identity Foundation? I thought that was really fascinating about the open standards and what you guys are working towards in terms of frameworks.

      Rosalyn Curato:
      Yeah, of course. So our team has been thinking about know your agent in that space since prior to my joining back in 2024 when ChatGPT first just took off. And Anthropic had published MCP in 2025, and we saw that just take off, and that was fantastic. However, when you read the section about identity, all they say is use OAuth. And as we all know, especially from this conversation, you can't authenticate agents in the same way that you authenticate humans, right? So the team worked on defining what was then called MCP-I for identity and is now KYA-OS. And they kind of spelled out this whole framework on agent identity that we talked about previously.

      Jonathan Knepher:
      Mm-hmm.

      Rosalyn Curato:
      And that's been cool because, you know, you sort of need this framework and standard when, as you're approaching building your agentic security strategy, that's the number one thing that's actually holding a lot of organizations back. They're saying, we're waiting for a standard so we know that we're gonna build and do this the right way, 'cause it's very costly if they get it wrong, right?

      Jonathan Knepher:
      Right.

      Rosalyn Curato:
      They want that framework. And we're big believers in open standards, right? That's IP that shouldn't be held, you know, amongst ourselves. We should be able to share it with everybody. And so we donated that spec to the Decentralized Identity Foundation, DIF, They've been fantastic partners. We just, we love the community. We love how it's very much, it's not just about the theoretical. They also care a lot about, well, what are the practical applications of this? And so we have a great working group. It's a great combination of enterprises, startups, academics who've been studying identity for decades, right? And the standards evolve.

      So we're proud of the fact that it's changing because as we talked about, AI is just changing every day. So it's been a great group to get involved in, and we've seen a lot of positive traction and interaction. We've had over 10,000 people interact with the spec just in the last 4 months. So we're seeing a ton of good activity. And what's your perspective in terms of standards and frameworks? And as you're talking to folks, like the need to have something like that as you're thinking about how to bring agents into your organization?

      Jonathan Knepher:
      I mean, I think fundamentally, you have to have standards or everybody's going to make up their own standards, right? I think everybody knows you have to be doing something. So standards are good and open standards are better.

      Rachael Lyon:
      Right. But how do you align? I mean, I guess that's the question today, right? I mean, how does everyone get on the same page for USB, right? What it took to get there, what's it going to take to get there? on the AI framework front, the agent framework?

      Rosalyn Curato:
      Yeah, that's a great question because now there's a few frameworks out there touching on agentic identity. And our philosophy is like we should all just link arms and have something coalesce. And so we're involved in more than just DIF and a few other organizations as well as we're looking to influence those agentic identity standards.

      Rachael Lyon:
      Right.

      Rosalyn Curato:
      But KYA-OS is built on W3C, which is widely adopted. And so that's where I think that's helped it take off in terms of adoption and giving people comfort.

      Jonathan Knepher:
      So, I guess, what does the normal, like, end-user and enterprise user need to do to adopt both identity and agent trustworthiness?

      Rosalyn Curato:
      Yeah, great question. So, I mean, the way we've set it up here at Vouched is it ties to the framework that we've built, KYA-OS, and that philosophy of human-agent binding that we talked about. The moment an agent lands on your site, you can require that it has to be authenticated by a human. So the human has to provide consent, and we have varying degrees of that. So it could just be SSO, it could just be check the box and provide consent, all the way up to biometric authentication, right?

      Rachael Lyon:
      Mm-hmm.

      Rosalyn Curato:
      It's really just dependent on your tolerance for risk. And then you can have the agent be authenticated as often as you want on the customer journey. We like to say friction is strategic. So some people want to make it easy for an agent to land on their site and shop and complete the transaction. They want the revenue. Some people are very conservative. And I would say, like, especially in financial services where the cost of something going wrong is really high, right, their transaction sizes are just so big, they care a lot about inserting friction more often. And you control that.

      That's totally customizable. And that gives you comfort both as the organization but also the human because you know when your agent is about to do something.

       

      [27:54] Measuring Trust and Confronting Malicious

      Rachael Lyon:
      So I'm curious on this idea of trust because in the last few months, I can't escape the word trust in AI. It's everywhere. But what does that mean? I mean, it's kind of like years ago when I was getting into cyber, there was a lot of discussion of, well, for cyber products, should there be a grade, kind of like restaurants have a grade? Right? A, B, C, D. Is there a grade in terms of the trustworthiness or the security strength of said product, right? Software product, let's say. So as we get to trust, that seems to be the foundational element that everyone's trying to get to relative to AI. But how do you measure trust? And, you know, it's like, well, it's like 20% trust. Is it 80% trust?

      Jonathan Knepher:
      You know what I mean?

      Rachael Lyon:
      Like, it's how do you— create a scale for something that's a little bit, you know, like, like, I don't know what's the word I'm looking for, like air?

      Rosalyn Curato:
      More, it feels less tangible, I guess, right?

      Rachael Lyon:
      And how do you prove it? Right? I mean, I guess, you know, like, yeah, we trust our AI, but how do you prove it? I guess is the question. And I imagine that that's going to become more of a question.

      Rosalyn Curato:
      It's a great question, because that's That's one of the problems that we obsess over here. I would say the honest answer is trust is a desired end state. It's not something that's been fully achieved yet. But the way we build towards that, we actually do trust scores. So when you were saying 20%, Rachael, I was like, yep, that's exactly what we do. We have a registry where we've pulled over 50,000 agents and MCP servers out there. Every one of them, first of all, we scrub all the duplicates because there's a couple of other registries we've partnered with them. We scrub it all because we want them to each be unique, right?

      Rachael Lyon:
      Mm-hmm.

      Rosalyn Curato:
      So, you know, this enterprise has this one agent or MCP server that we know is definitively theirs instead of having 5 or 6 listings. They're all assigned a DID, and the trust score right now is based on consistency, interaction, right? So what we're seeing is actually a lot of agents and MCP servers are being spun up. It's so easy to create them. But there's not a lot of activity on them. And I think we've seen this in the news as well, which is questioning the ROI of AI because it's so easy to create it. But like, if you stick with it, then I think you achieve the ROI. If you stick with it, you tinker with it, then you eventually get there. But we're seeing a lot of that new stuff, so you'll see a lot of mid-range scores.

      Rachael Lyon:
      Mm-hmm.

      Rosalyn Curato:
      The other thing that influences it though, that I think feels much more tangible, is we track when that agent and MCP server is being used. So you can see real-time, okay, this one actually has decent activity. And people can report bad behavior just like you could for other situations. If an agent did do something bad or you had a bad experience with an MCP server, you can report that, and that certainly dings the score, right? And I'm assuming and expecting that the score will evolve over time, the— at least the, the algorithm, based on what we see and learn.

      Rachael Lyon:
      Right.

      Rosalyn Curato:
      But it's similar to like email domains where the longer you've been around, right, the higher it'll perform, the better it'll perform. I'm hoping it doesn't take that long, but that's sort of how we've set it up today.

      Jonathan Knepher:
      How much of this still holds though for, let's say, malicious agents, right? Like, the whole trust authentication user binding makes a lot of sense when these are intentional agents for good, right? But the bad guys are trying to impersonate the humans. They're not going to admit they're an agent. They're going to try to circumvent all of these controls. Like, how do you deal with those, let's call them, uncooperative malicious agents?

      Rosalyn Curato:
      That's where it's about the authentication back to the human, right, Jon? So, if you are sending a bad agent to my site, Jon, then I'm going to have you authenticate and do a face scan so I can make sure that it's not Jon hijacking Rachael's agent. And so Vouched was actually founded on the human identity verification side. That's our identity, is our heritage. And it's fascinating to see and hear these stories because bad guys do try to hijack human identities, right? And we know that. And they will do crazy things like tape their face. We call this— we call it tape face, right? They'll put stockings over their face.

      Rachael Lyon:
      Yes.

      Rosalyn Curato:
      So they will go to no lengths. They are so determined to try to get this fraud through. So, Jon, that's where facial recognition comes in, because obviously those are all failing like hotcakes.

      Jonathan Knepher:
      But I don't know, as an end user, I don't want to be doing facial recognition. I don't want people to see me, as I say, on a podcast.

      Rachael Lyon:
      Right, right.

      Rosalyn Curato:
      I mean, I think it's like I said, it's up to each merchant and organization with a website in terms of Balancing the risk, right? Like, yeah, that could be a turn-off. Like, if I had to do that too, it just— it's another point of friction that's preventing me from buying something, right?

      Jonathan Knepher:
      Right.

      Rosalyn Curato:
      And I think it's really up to— it's that balancing act that everyone's in now that we keep coming back to, which is like that risk versus the reward equation, right? And what their customers have an appetite for. And I think if you position it— like, I come from customer success, so if you position it as We're doing this for you to protect your identity, to make sure that people aren't stealing your agents. I would be more inclined to care about the safety, security, and then I will begrudgingly scan my face to complete a purchase.

      Rachael Lyon:
      So this now kind of brings up my— I hate multifactor authentication. And of course, I understand why we have it. Obviously, I'm in security, but this makes me start feeling like it's going to get even more complicated.

      Like, you know, it's like I have 2 phones, right? The work phone, the personal phone. I can never remember like what's my authentication phone number. And I guarantee you I never have the other phone when I need it to authenticate. And then I can't get in my Amazon account on a flight. You know, so where does this— where is this leading us, I guess, in the whole identity realm? And particularly when we start— I love the show Altered Carbon, if you've ever watched that on Netflix. And that whole sense of identity being hijacked, right? In terms of AI could give it, you know, give it a different face and you could scan a different face. But then DNA's not really infallible either. Neither is voice recognition infallible.

      So then we're getting more and more complicated on how do we verify identity ahead. And there's really no, I'd say, bulletproof, right, way unless we're using like 5 different multifactor authentication phases in order to get to do the one thing.

      Rosalyn Curato:
      Yeah, it's— I mean, that's a great point. First of all, I have to look up the show Altered Carbon, adding that to my list as soon as we're done. But yeah, I mean, this goes back to like bad guys will stop at nothing, right, to do bad things. And yeah, the, the risk of like synthetic humans like we talked about and AI-generated faces and all this stuff is, is real. Right?

      Rachael Lyon:
      Yeah.

      Rosalyn Curato:
      I think the question is, like, to what scale is that going to happen? Like, how much control can we put in place? But you're right, like, authentication, authentication is becoming more complex, but isn't it becoming more accurate as a result? Like, aren't we seeing, aren't we seeing the resulting positive effects of it?

      Jonathan Knepher:
      I think so, especially in the case of, like, Rachael was talking, you know, multi-factor authentication with I don't know that I log into anything now that isn't MFA ever. To be honest, I do feel a lot more comfortable even though it is so annoying. It's like, oh man, I got to walk to the other room and get my token.

      Rachael Lyon:
      Exactly.

      Jonathan Knepher:
      But yeah, I think there is a lot more trust there until you give your OAuth tokens to your agents though.

      Rosalyn Curato:
      That's a big no-no, everybody who's listening. No username and password or tokens to your agent. But I agree, I agree. Like, it's, it's that friction, right? Like, okay, I'm getting a text with a code so that I can authenticate and log into this account, but at least I do feel the comfort in the same time, right, in that same breath of knowing they're just protecting me and my account.

       

      [36:25] Data Security, IP and Building Your Own Model

      Rachael Lyon:
      Yeah, I'm also interested in your perspective on this dichotomy of basically it's the AI security right, that you have to think about agent security. But then you also, there's the data security element. And are they 2 separate things? It seems like they should be, you know, how do companies need to start thinking about these 2 things together as a mesh? Because they're so—

      Rosalyn Curato:
      Yes.

      Rachael Lyon:
      intimately intertwined. And so it seems like this whole new brave world of how do you secure things, secure your business as well, right? Your IP and everything else. But you need the IP to be able to get to the agents to do the innovation. And I don't know, it's an interesting question that we've been circling around.

      Rosalyn Curato:
      Yes, and this goes to my personal opinion, which is the IP question is hard, Rachael, right? If I talk to Claude about everything, like Coca-Cola, for example, is notoriously protective of their recipe, right? Like you have to sign NDAs 2 weeks before you go to their offices, et cetera. So why would I tell Claude like everything in my secret sauce, right? Like why would I give up all of my IP and then train all their models to do my job, right? Or to know about everything that helps me run as a business. And so my, my dream— I don't know how soon we'll get there— is that I think every organization just kind of creates their own model because that's the only way you can trust it. It's like, if I create my own model and build my own local model and train that, then I know that everything is contained. That's my, that's my wild, crazy dream. Jon, Rachael, what do you think?

      Jonathan Knepher:
      So, do you view that basically all of the inferencing and model building, even, it sounds like, will become local rather than, you know, third-party outsourced?

      Rosalyn Curato:
      I think it's the only way, right? Because that's due to lack of trust. So, we're talking about building the trust layer, but I think that we just don't know how the data is gonna be used. We don't know about, like, how to really— if you really wanna protect your IP and go to your board and your shareholders and say, we know we're 100% protected. That seems to be the only way to keep it within your 4 walls. Do you think that— happy to be challenged on that because it is a wild, crazy idea.

      Jonathan Knepher:
      No, I personally agree with you. But then how do individual enterprises who aren't in the AI business get enough data to build those models? It sounds like there would then be an open market for, like, the underlying public training data.

      Rosalyn Curato:
      Yeah, I almost think you tranche it based on customer size and segmentation. Like, the enterprise would be able— they're big enough to have their own team dedicated to that. Mid-market, potentially, right? But then there's probably going to be consortiums or groups, like trusted groups, where you could potentially pull together and create your own model. Or then if you're SMB or a solopreneur, you're using the major frontier models. There's just no point you use that and build off of their models instead of building your own. Why would you?

      Rachael Lyon:
      Yeah, it's a tough one, but it's expensive too, no? I mean, to try to do that on your own, as you think about all of the new costs that are being absorbed as well. So there's the private LLMs, there's the tokens, right? All of the usage of AI and now I think you're— we're hearing a lot more about data centers being sponsored, right? You just have your own data center to run your AI for your company or your organization. I mean, it's fascinating, you know, again, how this reshapes everything.

      Rosalyn Curato:
      Yeah, I spoke at a Data Center World conference a few months ago, and I learned more than I think I taught everybody because it's a fascinating space and there's so much changing. But something I found interesting was with data centers, they're much more efficient at building them. So previously what used to take up a whole room in terms of servers, you can now have as like a tiny box, right? Like they've gotten much more efficient at that. So it's not about the space, it's really about the power to keep them going, keep them running.

      Rachael Lyon:
      Yes.

      Rosalyn Curato:
      Right. And with all the investment pouring into organizations looking to build and power data centers, my hope is that the capital markets will prevail and public shareholders will demand more cost-efficient ways to, to power data centers, right? That's just what's going to happen. It's a margin conversation.

      Rachael Lyon:
      Absolutely.

      Rosalyn Curato:
      So we need to make sure expenses are as tight and efficient as possible. So my hope is that that is what's going to happen, and we'll see those costs go down. I think everyone is thinking about it, right? It's top of mind.

      Rachael Lyon:
      Absolutely. It's— and it's been fascinating to read about. I was reading an article about, um, because everyone wants to be trying to build all these AI data centers, as we know. And it takes time to think about it. You got to connect to the electrical grid. And what are the implications there? Do you need to stand up your own electrical grid to run your data center? I think there was one solve where they're like, we're just going to run it on gas. And that was their solve to get it up and running more quickly. And it's just a fascinating discussion.

      And with China, they have a data center in the ocean, right? You know, not to take up land space. And it's—

      Rosalyn Curato:
      And the moon. Don't forget about the moon.

      Rachael Lyon:
      Don't forget about the moon.

      Rosalyn Curato:
      That's right.

      Rachael Lyon:
      Exactly. We got to have it in the sky. So, yeah, it's— I could talk about this all day because it's just fascinating, the developments that are happening so quickly and how they may ultimately play out, where they'll land.

      Rosalyn Curato:
      And I think, I think we'll be pleasantly surprised. Also, there's no bad ideas in brainstorming. So gas, the moon, the ocean are fun ideas to throw out and see what happens. But even like, remember token maxing was such a big thing for a while, right?

      Jonathan Knepher:
      Mm-hmm.

      Rosalyn Curato:
      And token cost, everyone was griping about that. And I've noticed even just in using Claude that they tell you, hey, start a new chat because it will save you this many thousands of tokens, right? So even just simple things like that to help minimize token usage, right? The ability to leverage skills and save your design systems all save hundreds of thousands of tokens, right? So I feel like they're introducing solutions so that we aren't overusing tokens anyway. So I'm hopeful that more of those even simple insertions in your process, in your day-to-day, will just help you bring those costs down in general.

      Rachael Lyon:
      100%. Yeah, the more we learn too, right? The more we use it, the more we learn.

      Rosalyn Curato:
      The more insight we get. Exactly.

      Rachael Lyon:
      Absolutely. Did you have a question, Jon?

      Jonathan Knepher:
      No, I was just going to comment too. The models are finally getting better at not having those long-lived conversations. It wasn't so long ago, you kind of had to keep everything with all that historical context, or you just get different answers for your next thing. But yeah, it's finally gotten good enough that you can start new tasks and not have it go way off the rails.

      Rosalyn Curato:
      Yes, 100%.

       

      [42:44] Rosalyn Curato's Path to Cyber

      Rachael Lyon:
      So, always mindful of time, Rosalyn, but we do like to end our podcast always on a personal note. So, fascinated how you started your career in finance, financial services, and you've made your way to AI, which is fascinating to me. And I would just be curious about your journey on how you got here because it's— everyone always has a very interesting journey of how they arrive to where they are today. And if you wouldn't mind sharing that with our listeners.

      Rosalyn Curato:
      Yeah, happy to. So I, when I was in college, I was debating between going into finance or being a doctor. I wanted to do something, something that I felt like I was going to really challenge myself. And I chose finance. I felt like I could start there and just have this generalist skill set that could carry me forward in my career. I didn't know what I wanted to do. I didn't have this plan of this is what I want to be for the rest of my life, but I figured that would be a good foundation. And then after doing that for a few years in the private sector, I was always volunteering.

      Like, that's just something I've done my whole life, and I would help small businesses with their business plans and, you know, volunteered with social venture capital firms like Acumen Fund. But I wanted to do that full-time, so that's when I think I made the pivot into more mission-driven work. And started working in education to try to help school districts. Because today, it's pretty complex when we talk about outdated infrastructure and systems. Like, it's, you know, even far below, you know, there. And the outcomes are great because it's about students achieving and setting them up for success as adults. And so, I cared a lot about how do I solve problems for— that are going to have an impact, but solve like that point of friction, that unsexy part of the process. that can help other people shine.

      So for example, startup leaders who are looking to go into areas where they were significantly underperforming in terms of education, how can I help them so they can launch their brilliant academic plans but not worry about the finances? In a similar way, I think I was like kind of led into the agentic identity space where there's so many different paths on your career that you could take with AI, and there's so many cool startups to work for. Definitely wanted to go to a startup because this is where it's all happening, like live, real time, on the ground. Like, you feel it, like it's in the air, you know, and it's oxygen for me. It's so exciting. But agentic identity, agentic security is that— it's that trust layer. It's like, if I can figure this out, I can achieve the unimaginable.

      Rachael Lyon:
      Right.

      Rosalyn Curato:
      When I start really leaning into AI. And so that's the exciting part of what I'm doing now and what led me here. It's that thread of mission-driven work.

      Rachael Lyon:
      I love it. It's such an exciting time. I have to say, I've been in technology. I won't say how long. It's been a very long time. Compaq was still around, if that gives you any clue. But I have not been more excited about something, right, than I am right now with what's going on with AI. It just— there's so much opportunity and we don't even— we can't even fathom what that could even be yet, which I love that.

      I love the unknown. And I keep hearing this phrase, get comfortable with the uncomfortable, because that's literally where we are at right now. And I think that's a lot of fun.

      Rosalyn Curato:
      Yes, so true. That's one of my favorite phrases. Once you lean into that, you're like, yeah, just bring it on.

      Rachael Lyon:
      Exactly. Exactly. Well, thank you so much, Rosalyn. This has been a wonderful conversation. Greatly appreciate your insights. And I love the work that you guys are doing at Vouched. So thank you for sharing that with our listeners.

      Rosalyn Curato:
      Of course. Thanks for having me, Rachael and Jon.

      Rachael Lyon:
      Absolutely. And Jon, we're going to— I'm going to do the drum roll.

      Jonathan Knepher:
      Smash that subscribe button.

      Rachael Lyon:
      That's right. And you get a fresh episode every single Tuesday. So until next time, everyone, stay secure. 
       

      About Our Guest

      Rosalyn Curato_headshot_Vouched

      Rosalyn Curato, Chief Innovation Officer & General Manager of Agentic Security at Vouched

      Rosalyn Curato is Chief Innovation Officer & General Manager, Agentic Security at Vouched, the AI identity verification platform that’s transforming how leading Healthcare and Financial Services companies onboard and verify people—instantly and securely. As AI becomes the foundation of how work gets done, she and her team are shaping a future where agentic security sits at the center of trust in an AI-driven world. Her background spans customer-facing leadership, enterprise operations, and startup environments. She has built and scaled diverse, high-performing teams - from early build through acquisition - focused on driving real value for both customers and colleagues. Earlier in her career, she spent time in financial services at JPMorgan, Goldman Sachs, and Citi, which shaped how she thinks about risk, financial management, and operating at scale.