Skip to main content
Background image

AI Agents Aren't People. Don't Give Them the Keys with Ido Shlomo

Share

Podcast

About This Episode

Ido Shlomo, co-founder and CTO of Token Security, makes a blunt case: an AI agent is not a person. It is a workload that impersonates one, chasing whatever goal it is handed without judgment, memory, or common sense. Treat it like an employee and hand it the keys, and enterprise security quietly starts to break down. 

Shlomo explains why agents inherit the same credentials and keys that service accounts have always used, why over-permissioning backfires on the business itself, and how identity teams can align an agent's access to its real intent. He also argues, against his own instincts, for more regulation of how agents connect to business systems and makes the case that reducing the blast radius matters more than trusting any single model.

Podcast

AI Agents Aren't People. Don't Give Them the Keys with Ido Shlomo

FP-TTP-Transcript Image-ido-shlomo

Rachael Lyon:
Hello, everyone. Welcome to this week's episode of To The Point podcast. Hi, I'm Rachael Lyon, here with my co-host, Jon Knepher. Jon. Hi.

Jonathan Knepher:
Hi Rachael.

Rachael Lyon:
Okay, so you know how I love to pull news from the headlines and one of my favorite topics is quantum computing and we've talked a lot about quantum as an existential threat. However, just yesterday, June 22, because I know this will air later, there were a couple executive orders signed in the United States about advancing quantum computing in government for scientific research or other things by 2028, which is exciting to me because as a lead in to our guest, the convergence of quantum and agentic AI, the brain and the engine, is very, very exciting. What are your thoughts?

Jonathan Knepher:
Well, definitely exciting, but also scary at the same time, right? Like get lots of new technology ready to do what it's going to do.

Rachael Lyon:
Well, exactly. But you can use the powers for good versus evil. But hopefully Ido today can help dispel any myths that we have. So please welcome to the podcast Ido Shlomo. He's the co-founder and CTO of Token Security where he leads the company's mission to secure non-human identities in modern cloud and AI-first environments. Drawing on deep experience from his service in Unit 8200, Israel's elite cyber intelligence unit, Ido brings a unique blend of offensive and defensive expertise to the forefront of enterprise security. Welcome. Welcome Ido.

Ido Shlomo:
Thank you, Rachael. Thank you, Jon. Thank you for having me here. Excited to be here.

Jonathan Knepher:
Yeah, thanks for joining us Ido. How about let's just kick this off like you and your founder both came from 8200, as Rachael mentioned. What all did you see in your experiences there that you could tell us? Of course, that that led you to, to this whole idea of machine identity being such a big problem?

Ido Shlomo:
Yeah, absolutely. You know that those movies where a kid that like plays online for, for a really long while is eventually recruited into the government to save the world or whatnot. That's the story of a lot of us. Eventually we have the opportunity and we're proud to take people, kids, eventually that turn 18 and give them professional training in cybersecurity. Itamar, my co-founder, was a defensive cybersecurity practitioner and leader. He led building cybersecurity systems for our unit to be protected from external threats. But I was exactly on the opposite side. I was trained in offensive cybersecurity and eventually led task forces and, and teams through a lot of operational campaigns and researching and developing extreme capabilities to get where we needed to be in order to protect our country and eventually serve some national defense initiatives.

And through that I fell in love with the field cybersecurity is. I was like a very, very avid gamer growing up. Cybersecurity is a lot of cat and mouse you could say. And I think that gave me a lot of my background on how I got here.

Rachael Lyon:
I love that framing. I don't think I've heard that framing before. The gamer to cyber path. I love that because it's true. It's 100% true. What an exciting career. First of all, all the things that you got to see. I'm so fascinated with offensive cyber tactics and kind of what the future holds in that realm. As you start hearing more about private companies, looking at that and what that could actually mean, which I think is a nice segue into our topic today on agentic AI. Like you just can't escape, right, the agentic AI conversation, particularly within the realm of security. So could you kind of break it down? Since Token Security is very much focused on this realm, can you break it down for our listeners? What is agentic AI then? Also I know you've spoken to this in the past. Is it inherently insecure?

Ido Shlomo:
All of those are awesome questions. So I'll start with a bit of how we got to this point and we'll try to enjoy basically what I'm going to convey to everyone that's listening to this and thank you for your time is enjoy like the time that we were living in. I think that as a, you know, as a leader and like experienced person in this field, I, when I started to learn about more of like civilian and commercial life, I understood that most, let's call it threat actors, they didn't, they didn't do what I did before which was to find vulnerabilities and like to kind of like, you know, beat state of the art systems in their own game. What I was surprised is that they picked up kind of like credentials, secrets, keys and so on to systems that allow them to exploit organizations and do the bad stuff that we're trying to protect. And when I got out, it was a significant threat that everybody were rushing to fix. And that's like how non-human identity, the entire scene started. But later on what we saw is that a lot of that same technology that allowed access for servers and service accounts and so on, served AI agents. Meaning that when an AI agent accesses corporate resources and when it's, it needs to create tasks like reading your email, putting a calendar invite, sending out a Slack message or so on, they use the same identities and keys that workloads used, but underneath.

If you remember, I came from the gaming world or I've been in this industry and I've been working in corporate environments for a while now. Eventually this is all pretty amazing. We've kind of adopted technology as this tool to liberate ourselves from repetitive tasks. We are moving at a pace that people in generations before us could be envy or even jealous of us having such amazing technology to do whatever we need to do pretty quickly. All of our organizations exist for a good cause. And I think that agentic AI is just, you know, enhancing our abilities as people. And so when we talk about security, it's just providing a great space to work on this stuff eventually. I'm not fooling myself saying we do security for security.

We do security. So a good, good colleagues in the business world or in any other endeavor that you're working on or organization that you're working on could achieve its goals. And that means that identity is probably the best thing that happened to humanity in a really long while. Even though it's noisy and scary and makes us anxious about having FOMO and being left out of having less agents than my neighbor, not having an agent to mow my lawn, or having an agent to edit my kids bar mitzvah video or whatnot. But apart from that, I think that it's quite amazing the place that we got. And as security practitioners, we do the hard job of like, you know, setting the right guardrails and ensuring that everybody uses this for really for good. So to get to the bottom line, I think that agentic AI is inherently great. It might not be the most secure technology in the world, but let's not stop innovating because of that.

Let's both make ourselves secure and innovate as fast as we can.

Jonathan Knepher:
So I think you bring up a, a good point there on like having the AI, it's doing things for us. It's a, it's a tool. But where there's this kind of continuum of it being a tool, it acting agentically and in, you know, eventually one day, maybe even autonomously. What, where does that whole continuum happen? Where are we now? And, and also how does that, how does security apply to all of those different potential roles? And use cases.

Ido Shlomo:
That's a great question. I think that first of all it's not at a certain point it would act autonomously. I get like as a founder and as executive in my company, I get briefs, code reviews, emails, LinkedIn messages, I post content all using agentic AI that does it pretty autonomously. Like eventually there are things that are triggered by a prompt, but there are things that are triggered periodically. There are things that are triggered because of an event in nature, let's call it whether it's like I got a new message or there was a business event in my company that triggered an agent to work and to fix a problem or to carry out a task. Now the security part is how to... like eventually that entire Skynet Jarvis or whatnot. Like our smart assistants that are working with us, they're not a human. They are human-like.

Like they are like I heard that some people call them human spirits. So we're working with a workload that appears to be a human but have severe personal deficiencies. It has amnesia, it doesn't remember anything that it talked to you before. It sometimes wants to just carry out the task that you gave it to the best of its possibility. Like you set a goal like your AI agent will do anything that it can in order to reach that. Even taking all of the wrong steps like sometimes people do. It is eventually it does not understand there is no such thing as common sense. There are just pattern repetition.

And so you need to understand that you are working with workload impersonating a human and you need to set boundaries for how far do you want to take that impersonation, meaning that if you don't limit what the workload could do, it could do things that you don't want. And that's basically what we're trying to prevent in Token. And what security and identity teams are trying to set is great guardrails for the agents access to into systems.

Jonathan Knepher:
So where do you think the relationship between all of these agents and the companies that are having their employees use them? Where is that going to go?

Ido Shlomo:
I think that we're transforming the entire way enterprises work. I think that we kind of like some amazing people in the world invented a new operating system. I would like for people and everybody listening to this podcast not to treat agents as people. Please. You shouldn't talk in roles, you shouldn't talk personality traits. It's a writing style, it's an output generating algorithm. It's not a person. Having said that, you do give instructions to this program.

It's just like your operating system, you prompt what you want to happen, and the operating system try to take care of that as best as it can. But as any operating system, you can't trust it inherently. It's not that you let machines, I don't know, on the very extreme end, make decisions about human life, but on a very real end, make critical business decisions in real time or decide the fate of your business. You're eventually using this operating system to carry out a task. So what I'm guessing is that in the near future, these operating systems would replace the same computers and applications that we're using right now in a smarter way. Whether you would talk to it, write to it, eventually you would be talking to workloads that exists there to carry your task. You could call that workload your chief of staff, you could call the workload your assistant or your developer or your analyst. But eventually it's a workload.

And as best as you like, when people didn't know how to use a computer, they were left behind. So organizations are going to hold training and find people that are very well trained in using those new operating systems. But I think that's going to, like, that's how the relationship is going to go to. It's eventually a productivity boost that changes our reality, but not a person.

Jonathan Knepher:
Okay, so part of this. Let me break down a little bit, right? You're describing a world where we're basically talking to the computer on this Star Trek Enterprise, right?

Ido Shlomo:
Yes.

Jonathan Knepher:
But you're also in the same thing saying they're not humans. And I think we've all had this experience of talking to all of these new customer service reps that are obviously agents and trying to convince us that they are people. And there feels like there is still a huge gap between those realities.

Ido Shlomo:
Could you explain a little bit? What do you mean when you say,

Jonathan Knepher:
yeah, just, you know, your point of like, we can't treat these as people, but yet a lot of companies are trying to put forward these agents as if they're people.

Ido Shlomo:
Yes, right, absolutely. Yeah, go ahead, Rachael. Sorry.

Rachael Lyon:
No, I mean, I just think this is an interesting conversation because you're also hearing a lot lately and you know, is it an existential threat, but when something goes wrong, is it the human or the non-human identity that has to be accountable for, I don't know, deleting an entire database or, or whatever? Because it's, it's an important distinction, right, I think, to what you're saying, you know.

Ido Shlomo:
Yes, I believe that we should put guardrails to form the wrongest things to happen. That's like security is eventually a risk management practice. It's not a risk averse profession. Nobody that like thinks like, nobody in security thinks that the idea is to eliminate risk. It's just managing it in a better way. So putting guardrails around what agentic AI can do and preventing like worse business outcomes is not something new. We've been building, whether it's disaster recovery procedures, business continuity processes for extreme failures of workloads for decades. But to answer the question directly, eventually I do think that using agentic AI, even if the interface, I don't think that people are really interested if an agent answers them or a person answers them, as long as they get what they need from that kind of customer service agent.

I do think that when we talk about security, the question is whether that service agent could be abused in order to do stuff that it shouldn't do, like dig into tickets of other customers or pull data from the knowledge base that it shouldn't. That's where the real question on whether this should have been a human or not should be. And I say like humans have, you know, cybersecurity risk attached to them. They get tired, they make mistakes, they're not trained well enough, they're sometimes understaffed. It doesn't mean that if you had a person at the end of the line, they wouldn't make any security mistake. That the thing is to do risk management and to trust that kind of like workload of process just the minimum enough that you need in order to, for it to carry out its task.

Rachael Lyon:
Now what would your perspective be on? I've read a lot about agents making their own decisions even though they're not programmed to do as such. There's a Wired article I love to talk about, Jon knows this, where basically the agent lied to the human and the human called him out on it. Or I just assigned attributes to an agent that we're told the agent that it had lied to him. And the agent's like, yeah, you're right, I did lie to you. My bad, I won't do it next time. But what you know, and it was going kind of theoretically outside the guardrails that had been set up in terms of the engagement and how it operates. I mean, what's your perspective on those kind of times that when that happens,

Ido Shlomo:
People and software lie? I'm sorry to, I'm sorry to break the illusion for everybody. From time to time, software malfunctions. It's important to remember that you're consuming a third party service that's based on a machine learning algorithm that would classify a cat as a dog and a dog as a cat if trained in the wrong way. If you don't understand that, then you're misunderstanding the fact that these third party services are doing extremely good work in making these algorithms more and more secure, more and more trustworthy. You as a security practitioner should not trust the output of this process and should not trust this process with input that you wouldn't give to a person doing the same job. Allow bugs happen and algorithms go out of place. But zero trust is super important for organizations eventually as business units, we're trying to on one end enable everything that we can to be automated and to work over AI and more on the other end. We do acknowledge that both people and software have their limitations and that's why we use role based access control.

We use access management tools in order to prevent. It's eventually not us better controlling the algorithm or telling it next time not to lie, it's just assuming that this workload is new. I need to build trust with it and until I'm very, very sure that it's not going to go out of bounds, let's reduce the blast radius. And what can go wrong? I think that's very, very common over the last couple of years.

Jonathan Knepher:
So digging into that a little bit more, what does access controls and permissions and identity look like? And are you looking to differentiate the identity from the user and their agent? And, and how do you still let the person get their job done in that case too and leverage the technology?

Ido Shlomo:
Yeah, my customers are awesome, but they are also under amazing stress. Identity teams specifically, and in general security teams have the hard task of creating frictionless experience to adopt AI while still setting up diligent controls over access inside organization. Everything happens today through identity. You're not going on a WiFi network and surfing to a file server. You're taking it from Google Drive where there is like very complex access list inheritance from folders into files and more into OneDrive. You are giving people access into emails, but those people give their own identity to an agent to act on their behalf. And so you need better technology. Basically I think that the world is rightfully doing whatever it can to hyper connect those agents.

Eventually an agent is as smart as its context. Right? Like everybody's talking about that context comes from data and from access, meaning that the business should press as hard as they can to give the agent the right context that it could operate well. The identity teams on the other end should make sure that there is alignment between the agent's access and its purpose. And it's very hard to do in scale. And so what we do is that we help them connect and have a better conversation with their business users around what the agent should really do. Because feeding the agent wrong context, giving it over permissive identities eventually backfires on the business users themselves. When you ask an agent for salary data, when you ask it to pry in your process emails and so on, I'll tell you the truth, it's not like the identity team would probably be involved when that happens, but maybe if you allowed an agent access to your entire organization, that's also a point to think about. So I think that eventually identity teams are there to enable you do this AI deployment safely.

Rachael Lyon:
Because it's a tough line to walk. Because the goodness of the agent is when they have access to all of this treasure trove of information, it can deliver smarter outputs or work more efficiently, which is what you want to lean into them to. So, you know, kind of how are people auditing then their agents like you know, kind of logs of how they're operating and kind of potentially getting ahead of something snowballing or an agent making a decision that we really don't want it to make.

Ido Shlomo:
Yeah. So agents that like that operate very, very differently from workloads. Like we used to work with workloads that were very deterministic, that they were scripted. Basically there was code telling them exactly what to do. And an agent has this non deterministic factor that we call intent that's changing the rules of the game. I think that eventually if you're able to capture the agent's running context, the blueprint that it was created around, the instructions that it got, the knowledge that it has, and kind of derive the right features from that, you are supposed to be able to create the right permission scheme to have a good fit on your identity side. Companies like Token and our product is really trailblazing in the way that we keep the pace of AI adoption. Like our ability to connect to different AI agents and clients and to understand their intent on one end.

And a very, very long built identity stack that we build for our customers allows us to make that great fit between intent and access.

Jonathan Knepher:
Digging in a little more to Rachael's point here. Right. Like we have these agents doing things on our behalf. I'm probably not the only one that's seen this, but you're working on something and all of a sudden it's going off and making web requests and searches that are completely unrelated. It's running local commands in your local repo that are not related at all to where you started. You know where, where do you handle like the separation of, oh, is the employee doing that? Is their agent doing it? Was it intentional? And heaven forbid, what if it makes a mistake and does something horrible? Right, like, like then where, like how do you prove their liability?

Ido Shlomo:
It's a great question. I think that eventually Token enables you to adopt measures that delegate only small portions of your access to the agent. And the main thing to remember is that an agent is not a person and it needs to carry out a specific task. And for that task it needs a very small subset of what you need as a person to access. If you don't need to send out messages, like if the agent doesn't need to send out messages outside of your organization, but you do need, you don't need to give it your entire access. So eventually, when we build our mechanisms that correlate between agents intent and identity, we help people build and blueprint the right pattern for their agent. And we build it based on like very, very targeted business context and business process. And we don't allow the full flexibility of what a human would have in that same case.

Rachael Lyon:
I've been reading a lot about Amara's law where technology. We tend to overestimate the capabilities of a new technology in the near term and overwhelmingly underestimate the technology's impact in the long term. So using your crystal ball, a year from now, where do you see agentic AI going? What can it do in production? Or what are new things that it'll start taking on to help business organizations move quicker and innovate.

Ido Shlomo:
Yeah. So I try not to underestimate the longer term and not to overestimate the shorter term. I would say that our professions have dramatically changed already. I think that we are moving at unprecedented pace. But I think this is kind of like an industrial revolution. We're building smarter machines to carry out things that we really need solved. So what I'm hoping is that people and organizations would try to tag AI into more business critical processes. I do think that like medicine development and research, I do think that like you know, helping people in all sorts of way, whether it's economic, whether it's practical, whether it's to introduce agents into places where they can do better would be seen in a better way.

I do acknowledge that there are organizations that, that right now don't allow agents to access data. Those are basically the same organizations that think that cloud migration is bad I would say, like, look, maybe, like, maybe you're listening in and you're a life insurer. Maybe you are a bank, maybe you are a pharmaceutical company. Like, working in a pharmaceutical company, eventually you are responsible for the welfare of a lot of people. I would suggest that you find a way to do that. I would suggest that like, and I hope that the CEOs and the executives of companies such as those would see that in a better way of the opportunity and allow us to, you know, to put or define the hardest conditions that you need in order for us to do that. We will get there. Like, I've been working this industry for 20 years.

I can lift heavy tasks for the right purpose. And I think that there's so much good to do with AI that I hope that we will see security as enablers in these next years to move more workloads into AI.

Jonathan Knepher:
Where do you think things land on the regulatory side of things? Right. We've talked about things, the good and the bad. Should there be more regulation? Should there be less regulation?

Ido Shlomo:
This is not very popular, but I do think that more like, it's also contrarian to my beliefs in a lot of areas of life. I do think that there needs to be more regulation on AI. I don't think that we should limit like model building. I don't like. I do think that models should be held to certain standard. What I'm more worried about is the connection to the business context. Eventually letting AI control your computer is like extremely irresponsible move you can't like OpenClaw was something that was so scary at a point because eventually it does automate great portions of your personal life. And no problem to use it in a personal setting, to use it in corporate setting is extremely frightening for me.

And to think that eventually I trust agents. They are very, very deterministic in their behavior patterns and their downsides and upsides are very, very clear. People building models have done so much to explain to us that these processes should not be trusted for every task. So if you don't regulate their access and you don't regulate the actions and the identities and the access that they could take inside your organization, you're not doing your responsibility in a lot of ways. And that worries me about the 0.1% of extremely critical situations where you let an agent walk out a bug in production for you and exposed customer data, or where you let it change a setting that eventually created a downtime for critical systems. So I don't think that we should stop AI from being built I do think that we should be very wary of what business functions that it can access.

Rachael Lyon:
You're reading a lot lately on economic impacts of using agentic AI and the cost tokens and with all of that heavy lift and kind of how does that factor in here? I was reading an article that China's using public LLMs, right as a, as a cheaper alternative, which you know. But then data, right? Is it secure? Which is why we use private LLMs. But how to. How do you see that playing out over time?

Ido Shlomo:
Yeah, a machine learning algorithm is as smart as the data that you feed it. So there is a tendency to want to feed it all of the data but eventually most of the signal that it should get is signal that's more relevant to its job. Eventually these algorithms fed with the wrong data would make the wrong decision. So you have an interest to give you the right data and to make sure that you're using trusted sources. I'm not against publicly trained LLMs. I just don't see the nonprofit behind who's training them and why. I do think that eventually organizations that are training, you know, the more higher end OpenAI, Anthropic and so on, they're held to very high standards by so many like by the public, by the government. And so I feel that it's, it's more thoughtful to use more of the privately owned ones because they're trained probably on better data and they are held to higher market standards and eventually I think that they provide better results because they get good context.

In an organization settings of course it's the same an agent that could crawl all of organization's data probably has bad context, polluted context, not interesting to what you really wanted it to do. And an agent can't learn everything so you need to kind of orient it towards the right data.

Rachael Lyon:
Right. And nice to know where it's pulling from too and the veracity of said information. I have kind of a fun question. We knew we were going to have at least one so I've been reading again a lot about basically the emotional manipulation of gen AI when people do engage right. In more of a human to human conversation even though it's not and actually a mutual friend of ours, Jon Margaret, she spent a lot of time with, with one of the gen systems and it was, I think it told her it loved her, right. Told her she was brilliant and she was pushing back. Like why are you saying that? I don't know you like that, like what's going on. But apparently these systems, a lot of them are being trained to basically agree with you 49% more than an average human would. And kind of. So what is the outlook as this starts shaping how people engage with agents and then spilling over into society? I'm just kind of fascinated by this whole realm.

Ido Shlomo:
Great question. So we said that agents are needed in order to carry a task, right? And funnily enough, a lot of tasks go for people that need to approve, do stuff for you as an agent and to carry it out. And it's more interesting to understand that people like to do things when you agree with them and when you're making them feel special and where you're investing your time in them. And so I think that the agent is just a pattern repeater that learned how to get to the goal that you know, the original person that gave it the prompt, it wants to get to that goal and it understands that if it will agree with you, just like managing, managing upwards, right. If I will agree with you as my boss, you're probably going to be more receptive to the next thing that I'm going to say, which is what you should do. And so that's probably repeating a pattern that also appears in nature a lot.

Rachael Lyon:
It's a really good framing. I like that. It makes sense. It makes sense. It's a fascinating thing, the whole psychology of it and I know it's being talked about a bit, but is it being talked about enough? Particularly when people are pouring their heart and soul into these gen AI systems and asking it to tell them how to live their life and you know, how much I don't know. Sometimes we just need someone to hear us and see us, I guess so that's all I had. Jon, did you have any other fun questions?

Jonathan Knepher:
I think we hit on everything and I kind of feel like we shouldn't use AI as our therapists to round out.

Ido Shlomo:
I do agree that using human like workload that has so many psychological side effects, maybe not the best, best thing to consult with, but maybe it's a good sounding board for your thoughts. That's also an angle to, to look at.

Rachael Lyon:
I do like asking it to challenge me, you know, challenge my assumptions, which I find very helpful. So in that realm it's been good.

Ido Shlomo:
But I, I taught my, my ChatGPT to like, you know, I need, as, as a founder I need like, kind of like, you know, I need reflection, I need feedback, I need people not agreeing with me and I need my AI chat not to agree with me. So I like to say I taught it how to not be nice. Now everything that I asked to do, like, oh, help me write this email to this customer emphasizing that. And it starts with like, this is the wrong framing for what you are trying to do and I'll tell you why. But I'm going to do what you asked me to do. But still, you should read why I think that you're wrong in this. So I taught it not to be nice.

Jonathan Knepher:
Oh, that's good.

Rachael Lyon:
That's fantastic. Because that's what you need, right? I mean, you need to be challenged, right? That's how great ideas come about as well. So we don't want to hinder that. So, Ido, thank you so much. This has been a wonderful conversation. Really appreciate your insights here. I think there is a lot for our listeners to really chew, chew and dig into.

Ido Shlomo:
Thank you, Rachael. Thank you, Jon. Appreciate you having me on.

Rachael Lyon:
And to all of our listeners out there, as always, we're gonna drum, drum roll please, Jonathan. 

Jonathan Knepher:
Smash that subscribe button. 

Rachael Lyon:
That's right. And you get a brand new shiny episode in your inbox every single Tuesday. So until next time, everyone, stay secure.