What It Takes to Safely Deploy AI Agents in Production
In this Techstrong.ai Leadership Insights interview, Runloop AI CEO Jonathan Wall examines the operational, security and governance challenges organizations face when deploying AI agents in production environments. He discusses the need for guardrails, observability, testing frameworks and runtime controls to ensure agents act reliably and safely at scale.
Transcript
Hello, and welcome to the latest edition of the Techstrong Insight series. I'm your host, Mike Bazaar. ai, and we're having a little chat about, well, AI agent safety.
They're starting to show up everywhere, but we're also starting to become aware of, well, just how powerful these things might really be, and we don't know exactly what they're doing and who might be using them when we're not looking. Jonathan, welcome to show. Yeah, thanks so much for having me, Mike.
It's, it's great to be here. I can't help w wonder if maybe we're a little bit over our skis when it comes to AI agents. I think people are deploying them and they're seeing new products all the time, but we're also starting to see a lot more, at least proof of concepts and some examples of how these AI agents can be compromised.
So, do we not think through all the security implications of all of this, but what's your assessment of where are we? Yeah, okay. That's a pretty broad question.
Uh, I would say there's a, a couple kind of, a couple things to click into there. Um, one would be just kind of around how people are using agents and then how people are deploying agents at scale. Um, I think one kind of curious thing, or something that I find a little puzzling or interesting is how many people are trusting these very powerful agents with really pretty broad access to their laptops.
Um, so your laptop, you know, if, if for me, for the sake of argument, if I happen to be doing a infrastructure risk code pushed to AWS, I'm signed into AWS I'm credentialed for network access to our production environment. Um, if I'm running cloud code as, you know, user wall on the various same laptop, you know, these guys have done great things. They've put in good guardrails, but, uh, that, that clo instance running is me, has access to a, a lot of the capabilities I have access to.
Um, so kind of one topic would be, you know, how safe, uh, is it to run on your laptop? I think that is, you know, kind of an area of, of open discussion. Um, I think then the, uh, you know, like kind of another dimension of this would be once you've deployed these agents to the cloud, right, where they can presumably run at scale, um, how do you provide them access to the correct things, but also prevent them from doing damaging things or, or, you know, expatriating data to un unintended sources.
So is it just now a matter of time before there's gonna be a series of catastrophic events involving AI agents and there'll be some backlash, or can we get in front of this a little bit and maybe put something in here to prevent that from happening? I would hope we can get in front of this. I think you've seen, like there've been a couple little flare ups.
You know, there, uh, I think last summer there, there was an engineer on, uh, on social media kind of bemoaning the fact that, that they accidentally just, uh, deleted their production database you see in the AI agent. Um, so I think there are some isolated incidents. Um, I would credit a lot of the agent builders to working really hard in terms of adding sandboxing.
So like the Claude folks, codex folks, Gemini folks, um, they do do their very best to sandbox, uh, the agents that run on your laptop. So, you know, there are certainly preventative steps people are taking on your laptop. I think when you start to deploy to the cloud, people are starting to take steps, but there's a lot of work left to do.
Um, you know, we think being very cautious about how you isolate the agent. So it's, it's in a sandbox that it can't escape. And even if it does escape that sandbox, it can't do kind of, uh, migratory attacks against its neighbors.
Um, we think that's necessary, uh, particularly in the case where someone might, you know, maliciously use the agent, right? You can do a lot of things, uh, to try to make the agent not do bad stuff, but, um, clever actors can kind of override that. I, I think we saw this with that kind of Chinese state sponsored attack that leveraged Claude that split up kind of their attack into lots of innocently seeming smaller tasks to try to not be noticed.
Um, so there's a bunch of stuff that people are trying to do on your laptop when you actually deploy to the cloud. Um, you have a lot more control, right? Um, the deployment environment is exactly how you set it up to be, right.
You can control what context is on there. Um, if people are doing a good job in terms of isolating these agents inside of containers and micro VMs, you can be pretty confident that they can't do kind of transitive attacks on their neighbors. Uh, you know, in in robust cloud environments, as you well know, um, give you the opportunity to have like very strict like network isolation and network boundaries as well.
Do we have the tools and technologies required to achieve that goal? Or do we need to maybe invent something that doesn't exist yet? But is it more a question of let's implement stuff that we already have that we haven't broadly adopted yet to deal with this?
Or do we need a different approach altogether? That's a really good question. I think it's kind of a blend of both answers.
Um, I would say that for the most part, we have a lot of the primitives we need, at least at the kind of traditional compute layer. Um, we have a lot of the pri primitives that we need. It's really a matter of composing them in an opinionated way so that it's easy and ergonomic to, uh, to kind of isolate these agents and be more confident, uh, in, in what it is they're able to do or not do.
Um, you know, to give an example, right? Like micro VMs are super powerful. Uh, they're used widely.
Uh, they, you know, they're greater. Um, you know, container technology exists, it's great. Um, there's wonderful network technologies like we use cilium ourselves, um, that let you do really fine grain networking controls.
It is great. Uh, it's just the, the problem then becomes how do you compose, you know, a lot of different layers of the stack in a fashion that is ergonomic and easy to use, um, so that people who are developing and then deploying these agents can, can, you know, reap the rewards of, of, of these kind of compelling technologies. Are security people conscious of all of this, or are they just kinda waiting and watching?
And I asked the question because I feel like nobody wants to be the proverbial party pooper, right? Everybody's having a great time when AI and agents, but nobody wants to be the one standing in the middle of the room going, you know, be careful out there. It could be doom and gloom.
So are they just kinda waiting for the crisis to emerge before they kind of step up a little bit more aggressively than they have to date? Yeah, I would say there are like a lot of different surface areas to contemplate here, right? Like if you, if you look at the laundry list of things I just gave you, right?
Like, uh, like network isolations, micro VMs, like these are very like nuts and bolts, like, uh, kind of physical infrastructure layer considerations. These are the kinds of things that I think people are really dialing into right now. Um, like a lot of our customers, you know, our, our company Run Loop AI supports these things, but it's, a lot of it is customer driven so that, you know, people are aware.
Um, I think that is a surface area that's like a little easier to reason about. I think some of the kind of AI level things and, and the prompt injection stuff is a little more open-ended and is a little bit harder to reason about. Um, I think when you throw, you know, more extensible patterns in the mix, like MCP, uh, like it, it kind of introduces another even broader surface area.
So I guess I would say that I do think that, that across the board people are, there are different security experts worried about different layers of the stack and doing different things. I don't know that there's any holistic solution in place just yet though. Well, so what's your best advice to folks about how to approach this?
Because I think that there is a lot of nuanced issues, and at the same time, there's a lot of technology that you need to master and they may not be familiar with. So is there a, a, a savvy way of thinking about all this and maybe having this conversation with the leadership of the company? Yeah, it's Kind of like, uh, I mean it's, it's, it's sounds a little boring, but it's the like, kind of the classical thing, right?
Like, you start with a position of like, what is technical necess technically the bare minimum of necessities? How do you set up like a least privileged environment and then gradually add things as you really need them, right? And, you know, this is why we think like a micro VM and good network isolations are really the right building blocks from there.
You also need to be very careful about the content that you're, you're making available and the tools you're making available, uh, you know, to any agent. And, you know, one layer above, you need to make sure that the agent never has direct, direct access to any sort of credentials that could be, you know, made rendered public via prompt injection. Uh, so it, I think it's, it's kind of the same old story for security, right?
Like you, you have to have a, an approach where you start from good principles least privileged access, and you kind of layer things on as minimally as possible for the thing to actually then function. Do you think auditors will soon figure this out and start asking more difficult questions of people, and will there be more compliance violations because the auditors will be like, well, I don't care if it was ai. The rule is the rule.
Yeah, this is gonna be an interesting one. I think the security engineers, I think kind of, at least in my experience, tend to kind of front run the compliance and audit type people. Um, so hopefully we've, we've raced ahead, so by the time they start asking these questions, we have good answers.
Um, right now, I'd say from an audit perspective, we're kind of in the kind of phase of like, hey, log everything and then we can see whose fault or what went wrong when it broke, as opposed to, uh, being a little more sophisticated. Mm-hmm. Um, but I, I think that will come, um, Do you think there will be more regulations about the usage of AI agents, or does, does lawmakers even understand how these things work yet?
And maybe it's a little bit beyond their core capability at the moment, but at some point, will somebody look at all this stuff and start making some new rules? Oh, I think, you know, lawmakers love to make laws. I'm sure they'd love to.
Um, yeah, I guess I would say as an industry that is in many ways, like kind of our, uh, maybe this is kind of our challenge is this, is this kind of nascent technology kind of, you know, grows to become mainstream and widely adopted technology is to, to see if we can sufficiently conform to like the existing regulatory standards with like mod modest extensions versus having like sweeping new, you know, laws and compliance burdens put in place. I, I would certainly hope so. Um, you know, I would certainly hope we, we can arrive at that outcome where there's, for every, you know, whether it be SOC two or you know, GDPR or any of these kind of standards, I would hope that there's just modest AI extensions to them as opposed to new, entirely new regulatory regimes that are really wide reaching.
I, I hope So. What is that one thing you see people doing today that just makes you shake your head a little bit and go, folks, we need to be a little bit smarter about this, because if we're not, things might go south. Uh, I think this is getting buttoned up rapidly now, like kind of in response, I think, to the, the state sponsored attack that, that anthropic revealed, uh, last fall.
But I do think running stuff on your laptop, you know, kind of as your user, um, launching an agent that has access to lots of files and lots of state on your system and lots of credentials, I think that was a little bit wild. Um, I think now the labs, the major lab, the major labs and, and, and, you know, Claude is doing a great job of this, or, or really Gemini as well, codex all of them are really, really trying to put good sandboxing in place for your local laptop. But, uh, you know, I think ultimately, at least in my opinion, the right answer is to not be running too many of these things directly on your laptop for them to have dedicated sandbox cloud environments, you know, and ultimately, hey, like, I don't want just one or two agents running.
I might want lots of them. So, you know, the scale of the cloud is appealing in, in that regard anyway. Um, so that, that might be something that, you know, I, I guess in the past it made me a little worried, but, uh, people are working pretty hard on that as well.
All right, folks. Well, you heard it here. Hey, you know, we gotta figure out how to maybe limit the scope of the potential breach, which in fundamentally just comes down.
Uh, we gotta run more of these things in isolation so that if something does go wrong, it doesn't go wrong everywhere. Hey, Jonathan, thanks for being on the show. Thanks so much.
Cheers. All right. And thank you all for watching the latest episode of the Techstrong AI Leadership series.
You can find this episode and others on our website. We invite you to check them all out. Until then, we'll see you next time.