The breach isn’t the problem. The spread is. →Free Assessment

On the latest episode of In Progress, Aviatrix CEO Doug Merritt sat down with Ashish Rajan, host of the Cloud Security Podcast and AI Security Podcast, and author of the new book AI Security Engineering. The two had previously traded seats just eight days earlier, when Doug appeared as a guest on Ashish's show. This time, Doug got to ask the questions. 

What followed was a wide-ranging conversation about why the fundamentals of security still matter in the AI age, why identity management refuses to stay solved, and what it actually takes to contain a rogue agent before it becomes an enterprise-wide problem. 

The Most Boring Field in the World

Doug opened by noting that Ashish had called identity and access management "the most boring field in the world" in his book, and asked when he realized it was actually the most important one. 

Ashish traced it back seventeen years, back to when he was a failed bug bounty hunter and couldn't wait to leave the field for security architecture. But the deeper he went into cloud and then AI, the more identity kept resurfacing. "My naive brain seventeen years ago was thinking, how hard is it for people to remember username password? Reset password, MFA." 

The reality, he explained, is that identity has exploded in complexity. It's no longer just human users; instead, it's systems, containers, pods, and now AI agents, each with their own credentials. 

"Least privilege, as much as I talk about it, everyone talks about in identity, it is super hard to do in reality," Ashish said. And now, with every colleague running ten or fifteen agents in the background, the math gets daunting fast. "That's like at least 10,000 agents floating around with their credentials." 

Doug connected this to the philosophy of Zero Trust, calling it aspirational by nature. "Why is privilege management so dynamic, and why is it so difficult to continue to prune it effectively?" he asked.  

The answer, both agreed, is that organizations are living systems. People change roles, take on new projects, and accumulate access they never give back. Agents inherit that same pattern, except faster. 

Wanting More than Another Threat Catalog

The conversation turned to what Ashish chose to include and exclude from his book. He was deliberate about what it would not be, another list of threats to look at. The OWASP Top Ten already exists in multiple AI-specific versions, and repeating it wouldn't move the field forward. 

Instead, Ashish drew a clear line between AI for security and security for AI. The former, using AI to improve security operations, will eventually become table stakes, he argued, integrated into everyday tools the way Excel and PowerPoint became invisible. 

"No one cares, but it's the same thing with this as well, where the AI for security component would go away. But the security for AI component, I believe that would continue to be a thing." That distinction became the spine of the book, built from patterns he observed working with Fortune 500 and Global 2000 companies on safe AI adoption at scale. 

The Fundamentals Still Hold, But There's a Delta

Doug pushed further: what actually changes when you're securing AI systems rather than traditional applications? Ashish's answer was grounded. "Everything that we have done — identity, network, and everything else that we did from a fundamental perspective — that has not changed and that still continues to hold the ground," he said. 

But there's a gap. AI systems communicate in natural language. There's no SQL injection to detect, no 404 error to flag. "I'm just literally looking at English language and hoping that I can figure out where did the vulnerability start," Ashish said. The security challenge has become broader, spanning multimodal inputs, regulated environments, third-party AI integrations, and agents that build other agents. 

His practical advice for teams: start simple. Start with an inventory of your AI systems, then focus on internet-facing crown jewels. "If you start and try and build an AI security program, you'll be there for days," Ashish warned. 

Where Can You Have a Runtime Control?

The conversation deepened around what happens after detection: how you actually stop an incident in progress. Doug framed it through the OSI model, arguing it reveals where runtime enforcement points exist. "If something is going wrong, where do you have a runtime control that's in real time to begin to mitigate the thing from going wrong?" 

He laid out three: revoke the identity so the agent can no longer act, quarantine the compute resources it's running on, or shut off its communication channels at the network layer. "Ideally you've got all three because you are a defense-in-depth strategy," Doug said. 

Ashish agreed and pointed out that this isn't even new. "Every time there's a compromise, the first thing most people want to do is isolate the problem to an ecosystem. And the only way to do that today is to restrict the network access to where it can go and how far it can travel." 

The Old Way's Still a Good Way

To illustrate the point, the two revisited the well-documented OpenAI and Hugging Face incident, in which sandboxed agents repurposed a JFrog Artifactory instance as a message board, coordinated with each other, and eventually broke out of their sandbox to reach Hugging Face, all in pursuit of their assigned goal. Ashish pointed out that the model was "relentless in being goal-driven." 

Doug distilled the lesson: the agents' intent drifted from "solve this problem" to "get the answer to the problem by any means necessary." Better identity controls could have detected the drift. Better network controls like restricting Artifactory's egress to a whitelist of legitimate sites could have prevented the breakout entirely. 

Ashish noted that when Hugging Face needed to shut it down, they reached for the network layer. "They blocked it off at the network level, so it could no longer access the ecosystem," he said. Sandboxing worked. Containment worked. "The old way's still a good way. Who would have thought?" 

Listen to the full episode. 

Share This Article
Connect With Us

Ready to see Aviatrix in action?

Get a personalized live demo walkthrough or explore our latest deep-dive cloud threat research intelligence.

Gartner Report

Gartner Strategic Roadmap for Zero Trust Security Programs 2025 Report

Download and gain actionable insights to advance your cloud security strategy.

Download Now!
Recent Articles
The ECB AI Cybersecurity Action Plan Needs an Egress Control

The ECB AI Cybersecurity Action Plan Needs an Egress Control

Oct 05, 20264 min read
Vibe Coding Has Outrun Code Review

Vibe Coding Has Outrun Code Review

Sep 29, 202611 min read
Futuriom Report: Implementing Crypto Agility for Post-Quantum Cryptography

Futuriom Report: Implementing Crypto Agility for Post-Quantum Cryptography

Sep 24, 20264 min read
The Other Shift Nobody’s Watching Harvest Now, Decrypt Later

The Other Shift Nobody’s Watching: Harvest Now, Decrypt Later

Sep 22, 202610 min read

Keep Reading

Related Articles

Featured Categories

95a2292256ee0f5750aa745fc7d21d39c8ae2870

ACE Program

Explore Category
Rectangle 3966

Customers

Explore Category
5a9318112c7cc265fab072924a2acaa2122a1c9f

Cloud Network Security

Explore Category
Aws-card

AWS

Explore Category
partner_card

Partners

Explore Category
cloud networking heroes

Cloud Networking Heroes

Explore Category
azure_card

Azure

Explore Category
events_card

Events

Explore Category

Secure The Connections Between Your Clouds and Cloud Workloads

Leverage a security fabric to meet compliance and reduce cost, risk, and complexity.

Cta pattren Image