The Blind Spot of AI-Native Dev: Securing the Agentic Factory
The shift to AI-native development has moved the AppSec bottleneck from generating code to securing it, but the true threat isn’t just the sheer volume of new software—it’s the autonomous agents working behind the scenes. Broadcasting live from RSAC, Techstrong Group’s Alan Shimel sits down with Backslash Security’s Gil Friedman to discuss how malicious prompt injections and compromised APIs can manipulate the “AI factory” long before a single line of code is even committed. Friedman explains why traditional security tools are completely blind to these new attack surfaces and how organizations must establish visibility and strict guardrails to protect their data from non-deterministic agentic workflows.
Transcript
Hey everyone. We're back here continuing our afternoon coverage on day three of RSA. We've got a few more coming at you today, and looking forward to it.
But let me introduce you to our next guest. His name is Gil Friedman. Gil is with a company called Backslash.
And if our friend Ronnie Osnet is watching this, a big hello to Ronnie, who's now with Backslash full time, I know for a number of months, and unfortunately couldn't be here with us in person. So hello to you, Ronnie, and I hope to see you soon. " Thank you.
It's good to have you here. Before we talk about Backslash, and before we talk about AI, because everybody wants to talk about AI- Of course ... at RSA, let's talk about you a little bit.
Give people an idea of your journey, of how you came to be at Backslash, and little bit your background. Definitely. So I have long history in our industry.
Coming from background at SAP, I was VP of engineering over there. Mm-hmm. I was VP of engineering of this expense solution of Concur.
Mm-hmm. After that, I moved to Meta. Really?
I was a senior engineering manager over there in the worlds of ads and VR. An interesting place to be. Interesting, yes, super fast pace.
Mm-hmm. Right? And then moved to Zilliant.
I was VP of engineering over there. Okay. Yeah.
And then after all this experience, from the other side of the fence, the people that- You went to the dark side ... to the dark side, which is actually the bright side in some ways. The more interesting side.
Yes. So from being in large companies, some of them move slow, some of them move extremely fast and pretty much lead our industry, Meta, it was interesting for me to join Backslash Security because the domain is fascinating. This is the right time to be covering this problem space.
And it's interesting to see how people understand the whole domain, and slowly they realize that these new things that we have there, it's not just for engineers, it's not just about code anymore. We have now few AI components, and actually even by the time that we speak right now, probably there are more. Yeah.
Okay? Every day. Every day.
And each one of these components, it's a new attacking surface. And unfortunately, the AI security teams, or security teams, they have zero visibility into this world. And we would like to help them with that.
We don't want them to be the office of no. We would like them to be part of the discussions, and we would like to help them with their journey to have safe AI adoption. Love it.
When did you join Backslash? I joined Backslash almost six months ago. Okay.
So I know the co-founders. Yeah. I know some of the employees over there.
We used to work before at SAP. Okay. Of course, we had great experience, and we did amazing things back then.
For me, it was a very easy decision- Yeah ... to join them- We were friends ... and be part of the journey.
Yeah. Yeah. And look, I've done four or five startups.
It's always good. Even here at Techstrong, my executive team basically are people I've worked with 20 years. And so we're very comfortable.
Amazing. It's like family, and it works. How would you describe Backslash to people today?
So the easiest thing when we start describing about Backslash is even to ask some simple questions. Do you know which AI agents are being installed across all the machines? And do you know which MCPs, which skills?
And this is where kind of CISOs pause. Okay? They don't know.
They are constantly in a perfect storm, and they are terrified. And they understand the risks slowly. And we're here to support them with the journey.
And this journey consists of three important steps. The first step is about visibility. First of all, to turn the light on to see what we have there.
Okay? What we have there in the form of AI agents, and even who is logged in. Is it they are logged in with their corporate account, with the private account?
This is super important information, right? Which MCPs, which AI skills, which rules? And we don't just stop there.
Even if you know which AI skills are there, we provide you the information about the security posture of these AI skills. So it's not just to know what you have. You need to know what does it mean.
After this step, there's a second step about defining policies, and not just on some wiki page. Okay? Real policies about this environment, these AI agents and so on.
After you set up that, you can define guardrails to harden the environment. And then once you have a safe environment on all the workstations, we provide real-time protection, so you won't be exposed to any prompt injections, a data leakage from all these components. I love it.
That was great. That was a great way of describing it. So, before we go further, people who want to maybe get more information on Backslash, what's the website?
It's Backslash Security. Just type it and it's there. Backslash Security.
Yep. Okay. Now, to say we're living in an interesting time in security-- Well, to say we're living in an interesting time in general- General ...
is an understatement. Yeah. And certainly in security, right?
I don't know if we've ever seen this kind of rapid change. Not just change, I'll use the word disruption, right? Rapid disruption in how, what, who we did.
Even six months ago when you joined Backslash, you probably didn't foresee the impact and how quickly the impact of- Yeah ... Agentic and things like Claude Code Security and these kinds of things are. Right?
Because fundamentally, we've moved from a world where the bottleneck was how much code can I-- How many engineers? Each engineer averages 400 lines a day. Yeah.
A good engineer. 40 lines- Depends which lines, right? Right.
Which lines. Exactly. But 400 lines a day, and I got 10 engineers.
Right? So I could do 4,000 lines of code. That's amazing.
That's an expense. That was a big operation to do 4,000 lines of code a day. Yeah.
Well, with AI, we could do that in an hour or two, it seems. Right? True.
So, the whole focus, it's like when you have an equation, x plus y equals z, and all of a sudden x becomes 10x. Yeah. Y and z have to change.
I agree. And that's y is security here, right? You got 10x the code.
What are you doing around governance, around testing it, securing it? " If they're using AI to generate that much more code, we just don't have enough people to ever keep up. We've got to use AI for the governance piece of it.
I agree. But part of the problem is that it's not just engineers. No.
It's also financial advisors- Everybody ... PMs, right? The artifact now, it's not just code.
Right. Okay? It can be spreadsheets, can be a LinkedIn post, can be even applications, can even be skills.
Right? And the problem that you have these new attacking surfaces that, as mentioned, there's no visibility. And the problem that in some of the cases, if it's not about generating something, you can use your AI agent with MCP to pull some information.
For example, I would like to integrate with an API. My prompt will be, okay, I need more information. How can you use this API for this specific purpose?
The AI agent will come to MCP. The MCP will call some public repo. This public repo, okay, might contain some prompt injection, Base64 encoded, means it's not meant for me or for you.
No. We know who's the target, and that will be fed into the AI model. So it's not even about generating any code.
Okay? The factory that now we have there that works in a non-deterministic way with all kind of interesting components that we know-- Actually, we don't know how they interact between each other, okay? And we start with definitely very safe approach, okay?
But slowly, we trust all these components, right? And this is where the problem starts, okay? And our last line of defense, unfortunately right now, is the AI agent and the model.
Yeah. We cannot trust these two to make the right decisions for securing our environment, and to make sure that there won't be any prompt injections for one side, and to make also sure that there won't be any data leakage, and also to make sure that they won't run any script on our machine. So it's not even about the code that's being generated.
And definitely, I agree with you, this problem just got amplified, right? For sure. But now we have new problem that the traditional security solutions out there, whether it's a gateway, whether it's EDRs, whether it's AppSec, they're focusing on different problems.
And now we have a new attacking surface that is out of sight for all the CISO out there. Agreed. But if Mohammed doesn't come to the mountain, the mountain has to come to Mohammed.
Do you understand? Yeah. So if we can't trust this AI to do this, we don't know is that code really secure.
But yet we're still just churning out code. We can't hire enough people, right? We've proven that.
What is the answer? The answer-- Okay, let's start with part of the problem, okay? Few years ago, the model was engineer writes codeYou have the output.
Means that in explicit way, you know what was being produced. Slowly, through the years, it started with Copilot. That we had auto-suggest over there.
Still from security perspective, the risk was low because you can still see in front of your eyes, okay, you typed few commands, auto-complete. Okay, still fine. Slowly, we have more sophisticated AI agents that they don't just generate one line of code.
They generate 50 files at once, and although we think that it generates just as an output of our prompt, this is part of the problem. There are a lot of things that can influence what eventually will be generated. And the AI agents and the models, they understand English.
String. Okay? And there are some AI rules.
They can be injected. Yeah. They provide some malicious kind of- Activities ...
commands. Yep. Right?
They can be, even as I mentioned, they are agent. They have also their own rules. Okay?
Whether we can trust them or not, I don't know. They are agents. Part of the way for them to satisfy our prompt, they get a context.
Which context? Maybe by mistake we just add there, just for testing purposes, the API key. They will take that.
Okay? They will do something with that, that it's out of our sight because we already trust this whole thing, right? And it push it and will generate code with that.
There are also now skills that will also impact this whole factory behind the scenes. You have rules. Later on, you'll have more things over there.
And again, the problem is not just us with the agent. The problem is now there's a lot of components out there that impacts this prompt and will impact the generated code. And not just the generated code, because I would even argue that the generated code, it's output that we can see.
They all can do within this process some things that are not even impacting the generated code. It will impact the code, the machine behind the scenes. The whole, yeah.
So it's not just the generated code. And I can argue that generated code, okay, it's been amplified. The same tools that we had before, okay, they use some AI, it's going to scan it.
But that's in a way the same problem that we had before, just amplified. Right. But now we have different set of problems that it's not being amplified.
We didn't have them before. I see. So the traditional tools we already have won't cover us for protecting our environment from all these new attacking surfaces.
I love it. Gil, we're about out of time. Awesome.
Backslash security. Yep. That's where it's at.
Hey, thanks for coming in. I appreciate it. Thank you much.
Best of luck. Happy to. Look, I think we all agree.
Interesting times. Exactly. And we'll see how this works out.
Awesome. We're going to wrap up stuff here at RSA today. But hey, Ronnie, if you are watching, I hope to see you in person soon.
We will continue our coverage in just a bit, but right now we'll take quick break. This is Alan Shimmel.