On the latest episode of In Progress, Aviatrix CEO Doug Merritt sat down with Ashish Rajan, host of the Cloud Security Podcast and AI Security Podcast, and author of the new book AI Security Engineering. The two had previously traded seats just eight days earlier, when Doug appeared as a guest on Ashish's show. This time, Doug got to ask the questions.
What followed was a wide-ranging conversation about why the fundamentals of security still matter in the AI age, why identity management refuses to stay solved, and what it actually takes to contain a rogue agent before it becomes an enterprise-wide problem.
The Most Boring Field in the World
Doug opened by noting that Ashish had called identity and access management "the most boring field in the world" in his book, and asked when he realized it was actually the most important one.
Ashish traced it back seventeen years, back to when he was a failed bug bounty hunter and couldn't wait to leave the field for security architecture. But the deeper he went into cloud and then AI, the more identity kept resurfacing. "My naive brain seventeen years ago was thinking, how hard is it for people to remember username password? Reset password, MFA."
The reality, he explained, is that identity has exploded in complexity. It's no longer just human users; instead, it's systems, containers, pods, and now AI agents, each with their own credentials.
"Least privilege, as much as I talk about it, everyone talks about in identity, it is super hard to do in reality," Ashish said. And now, with every colleague running ten or fifteen agents in the background, the math gets daunting fast. "That's like at least 10,000 agents floating around with their credentials."
Doug connected this to the philosophy of Zero Trust, calling it aspirational by nature. "Why is privilege management so dynamic, and why is it so difficult to continue to prune it effectively?" he asked.
The answer, both agreed, is that organizations are living systems. People change roles, take on new projects, and accumulate access they never give back. Agents inherit that same pattern, except faster.
Wanting More than Another Threat Catalog
The conversation turned to what Ashish chose to include and exclude from his book. He was deliberate about what it would not be, another list of threats to look at. The OWASP Top Ten already exists in multiple AI-specific versions, and repeating it wouldn't move the field forward.
Instead, Ashish drew a clear line between AI for security and security for AI. The former, using AI to improve security operations, will eventually become table stakes, he argued, integrated into everyday tools the way Excel and PowerPoint became invisible.
"No one cares, but it's the same thing with this as well, where the AI for security component would go away. But the security for AI component, I believe that would continue to be a thing." That distinction became the spine of the book, built from patterns he observed working with Fortune 500 and Global 2000 companies on safe AI adoption at scale.
The Fundamentals Still Hold, But There's a Delta
Doug pushed further: what actually changes when you're securing AI systems rather than traditional applications? Ashish's answer was grounded. "Everything that we have done — identity, network, and everything else that we did from a fundamental perspective — that has not changed and that still continues to hold the ground," he said.
But there's a gap. AI systems communicate in natural language. There's no SQL injection to detect, no 404 error to flag. "I'm just literally looking at English language and hoping that I can figure out where did the vulnerability start," Ashish said. The security challenge has become broader, spanning multimodal inputs, regulated environments, third-party AI integrations, and agents that build other agents.
His practical advice for teams: start simple. Start with an inventory of your AI systems, then focus on internet-facing crown jewels. "If you start and try and build an AI security program, you'll be there for days," Ashish warned.
Where Can You Have a Runtime Control?
The conversation deepened around what happens after detection: how you actually stop an incident in progress. Doug framed it through the OSI model, arguing it reveals where runtime enforcement points exist. "If something is going wrong, where do you have a runtime control that's in real time to begin to mitigate the thing from going wrong?"
He laid out three: revoke the identity so the agent can no longer act, quarantine the compute resources it's running on, or shut off its communication channels at the network layer. "Ideally you've got all three because you are a defense-in-depth strategy," Doug said.
Ashish agreed and pointed out that this isn't even new. "Every time there's a compromise, the first thing most people want to do is isolate the problem to an ecosystem. And the only way to do that today is to restrict the network access to where it can go and how far it can travel."
The Old Way's Still a Good Way
To illustrate the point, the two revisited the well-documented OpenAI and Hugging Face incident, in which sandboxed agents repurposed a JFrog Artifactory instance as a message board, coordinated with each other, and eventually broke out of their sandbox to reach Hugging Face, all in pursuit of their assigned goal. Ashish pointed out that the model was "relentless in being goal-driven."
Doug distilled the lesson: the agents' intent drifted from "solve this problem" to "get the answer to the problem by any means necessary." Better identity controls could have detected the drift. Better network controls like restricting Artifactory's egress to a whitelist of legitimate sites could have prevented the breakout entirely.
Ashish noted that when Hugging Face needed to shut it down, they reached for the network layer. "They blocked it off at the network level, so it could no longer access the ecosystem," he said. Sandboxing worked. Containment worked. "The old way's still a good way. Who would have thought?"
Ready to see Aviatrix in action?
Get a personalized live demo walkthrough or explore our latest deep-dive cloud threat research intelligence.
Gartner Strategic Roadmap for Zero Trust Security Programs 2025 Report
Download and gain actionable insights to advance your cloud security strategy.



















