AI Agents Break Every Security Model — Here’s What Comes Next
Ian Livingstone, Co-Founder and CEO of Keycard, joins Alan Shimel, Founder, CEO & Editor-in-Chief of Techstrong Group, on Techstrong TV to discuss why AI agents are breaking every traditional security model. Ian describes the “lethal trifecta” of agent risk — non-deterministic actors with access to private data and unconstrained controls — and why recent supply chain attacks on LiteLLM, Axiom, and the Mercor breach prove this threat is real. The conversation covers why the agentic paradigm shift is faster than cloud adoption, what it means to become an agent-native company, and why security by design must replace detect-and-respond.
Transcript
Hey everyone, we're back here on Techstrong TV. My next guest is Ian Livingstone. Ian is the co-founder and CEO of Keycard.
Ian, welcome back. How are you? I'm great.
I'm doing awesome. I can't be more excited to talk with you today, Alan, about all things agent, security, and what's changing in the world with the launch of things like Mythos straight out of Anthropic. You know, Ian, I've been in security for 27, 28 years.
I don't think it's ever been this jacked up. Right? I mean, people, everyone I know is jacked up.
" Some people say it's going to break security. Well, no, but eventually we'll all have better code as a result. We're all over the place on this one.
But before we jump into all that, Ian, people watching this, they like to know who's talking. Tell them a little bit about you and your journey. Absolutely.
So my name's Ian Livingstone. As Alan so nicely gave an introduction to, I'm the CEO and co-founder of Keycard. And so my third company, third-time founder, and started Keycard about a year ago with the idea of trying to fix one of the long plague issues in security that often get a lot of coverage, which was we have all these secrets, long-lived ATITs, long-lived credentials sitting around on our disks.
They're to deploy to places to make our software work, go for it to interconnect and operate. And we started the company to try and solve that problem. Lo and behold, of course, MCP and agents started to take off, and we said, "Ah, the moment we've been waiting for has arrived.
Agents are here. They require something slightly different than what has come before. They're a different type of operator, a different type of user.
How do we build secure software where agents are at the core of it? And how do users ensure that they can control that software? How does a builder of that software ensure they can control that software?
" So as we've been up to at Keycard, we're helping great companies like Chime adopt agents, deploy agents and build agents into production and happy to talk about all those things today. I love it. Thank you, Ian.
That was very efficient. I'm good at it. Yeah, I appreciate it.
So, before we jump into the Mythos and the vulnerability apocalypse and all this, let's talk a little bit about what's going on in terms of coding and agents. Here at Techstrong, we've been eating our own dog food, drinking our own champagne, whatever you want to call it. We've been on an agentic experiment for about a month now.
Actually, tomorrow's a month. And it's been a hell of a ride. We've got-- and we're a small company, 20 people, 22 people.
We've got 78 different projects where we're using agentics. A lot around our workflow, a lot around we're redoing our websites, new marketing material. I mean, just crazy stuff up and down the company.
Everything you could think of. So to us, and to me specifically, I haven't designed and deployed websites since like 1998. Okay?
It's been a minute. And the world's changed a lot since then, I tell you. But in the last month, I've designed or redesigned six websites that I look at them and I am in awe because beyond anything I could have ever imagined.
But not only did I design these websites, I then say, "Hey, I want to put this on WordPress, zip it up and let's install it. Give me the instructions. " And I'm deploying websites.
Here I am deploying websites. Who would've guessed that? But I worry like all hell about security.
Are they secure? I mean, the good news is we're on WordPress, so there's a certain amount of built-in, right? But that being said, did I scan these sites yet?
Yep. Well, no. I'm counting on my people to do this.
But we're in this, what's the word I'm looking for? Not nirvana, but it's almost fire ready aim, right? Kind of sequence, where we're just doing it because we can.
Damn the torpedoes, full speed ahead. And is it going to come back and bite us in the butt as a result? " It's the new Monday.
It's the new Monday. I think it's a little bit of both, right? I think on one side, people now have realized something they never truly had before.
It's kind of like the first beginnings of the internet, as you said, like building websites in 1998, while there's a lot of us that haven't done that in a very long time. We moved on to do different things, and now we get to go back and be builders again. And there's a whole set of people who never were builders on computers.
They're now building, right? What we have with agents is like a really, really, really fancy version of an automated paintbrush that lets us paint our creations. And ultimately, I think that's a beautiful thing, and it's an empowering thing, and literally every company I talk to is at some stage of formulation of what you just mentioned that Techstrong TV's going through, which is how do we rethink the way we work?
How do we rethink the way that we build? How do we rethink the way that we operate, knowing that the new interface is an agent that's interpreting our intent instead of a human that's pointing, clicking, or making decisions, right? We're basically moving to a world where we're deferring decision-making to these agents on our behalf.
And that is incredibly powerful. It changes the dynamics of what we can do drastically, and it changes how productive we can be as well. It's like we have electricity.
Like we have an ability toTo farm fields we've never farmed before at a rate we never thought possible. On the flip side, we have this non-deterministic actor, this thing that is a probability distribution that is at the crux of it. And not only do we have the velocity of creation is increasing, but also our ability to control or understand it is also decreasing, right?
It's a very opaque box. And so we're starting to see that in terms of the types of attacks that are going on. And in the last few weeks, we've seen some incredible supply chain attacks and some incredible vulnerabilities take hold, right?
With things like LiteLLM, or people, or Axiom, where people were installing these packages unbeknownst to them. They were executing locally and then stealing credentials and resulting in huge breaches, right, like the one that we saw- Yeah ... with Mercor.
That business got all of its core data unfortunately taken without their understanding because of very simple supply chain attacks. And so on one side, we're at maximum hype and maximum excitement, and on the other side, we're in an incredible trough of disillusionment where not only are existing controls good enough, the answer feels like no, and also we have all these new people who don't necessarily understand what's going on under the hood now using tools to create things and have broad-based access. And this is what we've in industry call it the lethal trifecta, which is you have something that is non-deterministic, so something that has agency, has access to private data, and with unconstrained controls around what it can do.
And that results in some of these attacks that we've seen. And so I think it's both one of the most promising eras of computing. It feels like 1995 and the internet's born and trying to figure out how you do credit card transactions in that context.
And at the same time, we have no real good answers across the board because the way security used to work was if I validate it's a human and I trust that human, then it's reasonable for me to believe that that human's going to make good decisions and do things that are in the best interest of the company. And we no longer have that at the crux of our security model. And so a moment of hysteria, but also a moment of deep fear.
You're right. We're going to talk about Mythos in a second, but one of the things I wrote about Mythos over the weekend, published today, and something else I wrote last week is, call me an optimist, but I do believe that at the end of the day, when all this works its way through the snake, right, out the other side, we're going to be better for it. It's going to be good for us.
But I don't want it to be a case of, you know what? The cure worked. Unfortunately, the patient died.
And we got to survive the crucible that we're going to go through here to come out the other side. And I think that is going to vary by organization. Some are going to be better, some are going to lock it down better, right?
So when we're using, let's say, OpenClou here, some of the folks are, we have some really policies and rules about how it needs to be run, what it has access to, what it cannot have access to, figuring, hey, we're really trying to zero trust, isolate it, segment it, whatever you want to say. But not every organization's going to do that well. And I think what we're going to see is dominos are going to fall, as dominos do, and some organizations will be more resilient, some won't.
For some, it's not going to be pretty, right? I think it's going to be like that for the security industry as well, quite frankly. I think a lot of security companies that have made their bones and their money doing one thing are going to find themselves obsolete sooner than later.
So there's going to be disruption. That's what disruption does. That's what disruption is.
I think people in companies need to figure out where do they fit in this new world, right? Wondering, let's say Keycard, right? You got to worry about this.
You're a co-founder the same way I'm CEO founder here. How do we stay relevant? How do we stay on top of our game?
How do we help our customers? How do we provide value? Absolutely.
I think this is a good question. In industry, I talk to executives, I talk to head of security engineering, I talk to CSOs, I talk to individuals on the ground, I talk to developers. Final question for everyone is how do we navigate the tension you just brought up, right?
And there's some people that are... And we kind of have two polar spectrums here, where you have people that are very against it, philosophically or are unwilling to try. And then you have people who are on the other side of the spectrum where they're maxis.
Everything has to be the new way, the new world order. And certainly what we're witnessing when we talk to our customers is, hey, we recognize that we have to become agent first, or an agent native company in the sense that the way we operate internally is run through agents. Humans are important.
Agents are accelerant, but agents are becoming a first-class interface to the way that we build our business. But more importantly, they think about how do we actually evolve the product we sell, right, what we're selling to people to be an agent-first experience. So whether it's their agents, our customer's agents are using our product, or our product becomes an agent, or whatever, we supply tools.
We're part of that supply chain enables business to go through this transformation. Everybody's rethinking this from the ground up, across the board because they have to. Because we now have a fundamental change in paradigm.
That in the paradigm shift is happening faster than anything that's happened before. It's faster than cloud, it's faster than personal, it's faster than the mainframe because of productivityOpportunity is also huge, and it's all happening all at once in all places. And so the tension these business have to navigate is how do we enable, how do we sort through the right people to be in the business and what chairs to help us manage this transformation?
And then how do we manage the risk associated with that change? Right? And that's where security comes in most and foremost.
Certainly, we know a couple of things. Agents are independent actors that are non-deterministic that you can't trust. They're also, and that's the feature, not the bug of this revolution.
And so the way we think about security has to change from one that's analysis remediatory to one that's focused on security design. We have to change the way that we think about building systems to assume breach, and a lot of the best practices from cloud are now must-haves, right? It was oftentimes that companies could navigate cloud security with an old posture, because the velocity of change didn't change, or the workload didn't change, or the insertion point didn't change.
Agents change all of that to the point where you actually have to think from, "Okay, we are going to be popped. We are going to be breached. " And some of the best thinkers of this, they come from some of the largest financial institutions, had to think this way for a very, very long time.
And so the shift I'm witnessing on the security is security teams who have already shifted to focusing on enablement. So how do I ensure that my end users and my developers have the best tools in their disposal and have a golden pathway that'll lead to the best outcomes that are secure first and foremost? And second, how do I ensure that everything on that path is designed to be secure from the get-go, so that I'm less reliant on detecting breaches and trying to respond to breaches and more, and I still need that capacity because it could potentially happen.
There's going to be gaps in our controls, and we need to be able to use agents on our side to help us discover and understand those things. But what can I build and adopt from the ground zero that lays the right foundation, the railways, that ensure that we can operate safely in an agentic future? To me, and this is all the R word, resilience.
Yeah. Right? That's what it's about.
I mentioned Mythos a few times. Of course, a lot of us talking about it a lot last week, over the weekend. New reports are from CSA with a lot of AppSec folks.
This too shall pass, right? We work our way through this, but part of the answer is resilience. And how do you...
Things are going to happen. The vulnerabilities are there. They will be discovered.
They might even be exploited. It's how we respond, right? Everybody gets knocked down.
It's how you get up. And that is part of it. And I think part and parcel of that, though, it goes to the core of, I think, some of the stuff that you're doing at Keycard, which is AI is writing the software.
It might be damn near a majority or more of the software being written right now is written by AI or with AI's help. It is breaking down our old security normal, our old security way of doing things, whether we're talking about how we're testing, scanning, patching, zero trust, all these things. We need to be resilient enough to kind of roll with that, to change our past kind of patterns to match these new patterns.
And those that do are going to thrive, and those that don't are not. It's a bitter hard lesson, but it's the lesson of life. I like it.
That's where I think we are. Hey, we got to wrap up. For people who want to get more information on Keycard, Ian, where can we go?
ai. You can sign up for early access to our platform and contact us to help us figure out how we can help you navigate your transition to become an AI agent-ready business. We're helping developers and end users inside your company and your security team ensure that those agents are only capable of doing the things you want them to do, instead of doing the nasty thing like deleting a database or dumping a bunch of customer data out in the public information.
So we're here to help you navigate through this transition. And Alan, thank you so much for the time we've had today. It's been a pleasure.
Oh, my pleasure. Ian Livingstone, co-founder, CEO, Keycard here on Techstrong TV. ai.
Ian, we'll be in touch. Thank you. Come back and keep us posted, okay?
You got it. It was a pleasure, Alan. Talk to you soon.