Martin Kraemer on AI Policy, EU Regulation and Agentic Security | KB4-CON 2026
Martin Kraemer, CISO Advisor at KnowBe4, joins Techstrong TV at KB4-CON 2026 to discuss AI policy, EU regulation and the security challenges emerging around agentic AI.
The conversation explores how organizations should think about designing for agentic AI, building governance around autonomous systems and preparing for a regulatory environment that is evolving alongside the technology.
Topics include AI policy, EU regulation, agentic security design, designing for agentic AI, human risk management, digital workforce security and security governance for AI-driven work.
Transcript
Hey everyone, welcome. It's Alan Schimmel and we're here in the Orlando World Center Marriott in Orlando. It's warm as one would expect this time of year in Orlando, but it's really been heating up with our coverage here for KB4 Con.
This is KnowBe4's annual conference. It might be the biggest conference they've done to date. We'll find out more.
We're going to be covering it all day, talking to executives, partners, customers, experts, really digging into what's going on here. With that, let me introduce you to our first guest. His name is Martin Kraemer.
Martin is the CISO advisor for KnowBe4. Dare I say a CISO whisperer? Ha.
Yes, I think that is a good way of putting it. All right. Hey Martin, welcome to Techstrong TV.
It's great to have you on here. Thank you. It's my great pleasure to be here.
So Martin, let's talk a little bit about you before we jump in. We have so much to talk about, but let's start with you. CISO advisor, we don't see a lot of those.
Talk to us, how did you come to be a CISO advisor? How did you come to join KnowBe4, and your journey? Yes, my pleasure.
For 15 years I've been in the field now. So started off as a techie. I was a software developer to begin with.
Branched out into security because at the time I was developing a mobile application for a consumer product, and that was to integrate with enterprise system, and touch a lot of sensitive data, a lot of very important processes where security gates were in place all of the time. So that's how I got in touch with security about 15 years ago. And I was part of a small team and was the one who grew naturally into the security expert of the team.
Great. But from a very technical perspective. So I've been in security myself 25, almost 30 years.
And it's funny, today you have people who go to school- Yes ... with a cybersecurity degree. Yes.
When I got into security, that was the path most people took. Yeah. They were a network person or a help desk person, and they started helping out and so forth in security, and the next thing you know, they were a security person.
Absolutely. And they stayed a security person. How did you come to KnowBe4 and in this role as a CISO advisor?
So that's how I started writing security architecture, security concepts. And I'm actually, as you mentioned, maybe a bit of a product of both because after that I really got intrigued. So I realized security is the way I think, the way I operate.
And I decided to go back to uni. Went back, did a master's in security. So that's how I am a bit of both.
Okay. Yeah, you're a hybrid. Yes, yes.
Yeah. So master's degree, again, was deeply technical. I was doing reverse engineering of mobile applications.
I was doing a little bit of pen testing here and there. " So I wasn't, to be quite honest. No?
Okay. At the time, I wasn't. That sparked my interest.
And then after that, it turned out there was an opportunity for me to do a PhD in cybersecurity, so I decided to focus on the human element. I researched how people manage their own cybersecurity and their own privacy at home, in a family context. Mm-hmm.
So I got deeply into the behavioral side of cybersecurity. And then once that was done, once I completed my PhD, KnowBe4 came knocking. Good.
And I was like, "That's interesting. " I had. 10 years ago, I had seen KnowBe4, but had almost forgotten about that entire space.
And then all of a sudden, it was this moment, it was like all of the dots are connecting. I was technical, then I learned actually the human element is the most important one, and I decided to join. So that was four years ago.
Oh, okay. " And I said, "Yeah, I think I can do that. " So this was four years ago.
I started out as a then called security awareness advocate for Germany, Austria, and Switzerland. Oh, okay. That's where I started out.
Then I grew further into the role, became Europe. Now it's Europe and the Middle East. And eventually, as the company, as KnowBe4 progressed from what was formerly purely a training company, which we are not any longer, into a full on cybersecurity company, the business decided, okay, it's time to elevate the role, and that's how we are now CISO advisors looking at cybersecurity holistically, right?
We are much, much more today talking about the digital workforce. We're talking about the fact that we have AI agents and humans working side by side, and that needs to be recognized. So that's why- Absolutely ...
CISO advisor's the much more fitting title. I agree. I love it.
How many CISO advisors are there? I'm one of six. Really?
Yeah. One of six at the- So are you geographically dispersed, or? Yes, we are.
So we have got two colleagues here in the US covering North America. We have got a colleague in London. Mm-hmm.
And then got myself in Dubai. And another colleague in South AfricaAnd then the newest addition to the team has just started in Singapore. I was just going to say, Singapore is the place yeah- Yeah ...
for impact. Exactly. Now, we are always sort of going with the times and perhaps, looking to expand that team as the business sees the need.
Mm-hmm. But yes, of course, the point is we are geographically dispersed. I love it.
What a great story. Now, when you were going for your master's and then your PhD, especially as you were focusing in on the human side of it, and that's something... Look, for as long as I've been in security, we've always said the weakest link is the person behind the keyboard, right?
Yes. But they didn't teach you about agentics. That was still out on the horizon.
It was. It's amazing in such a short period of time, the impact we've seen. Yes.
And I've been through my share of tech cycles, right? I've been around. Yeah.
I can remember when the internet itself first started bursting on the scene commercially. This fast, with this amount of impact, even here. You look around at KB4Con, and the signage, the messaging is all about agentics- Yes ...
and AI. Talk to us about that. So we are living in a time where every human in an organization probably has about two to three agents working with them.
At KnowBe4, we are also progressing in that direction. Now, we can listen to the industry leaders in AI and agentic AI specifically, such as the CEO of NVIDIA, and they suggest we will be looking at 100 agents per employee in just a couple of years' time. So 100 agents per employee.
That changes the structure of our workforce fundamentally. We have been using tools, computers, to get things done for us, and we have instructed them quite specifically, "Please book a meeting. " And that was always very specific.
Those are almost ephemeral to me, right? They come and go. It's a one-trick pony.
They do their- Right ... thing, and they're done. Yeah.
But today, we have moved on, right? Yeah. Today, we have a piece of software, an agent, we set a goal for it, we give it a task, it will figure out how to do that by itself.
So all of a sudden, we have given a piece of software a certain level of autonomy and agency to work alongside us. And that creates challenges. And what you see around here is a recognition of these challenges.
For 20 years, we have been teaching humans how to spot red flags in phishing emails, right? How to behave securely, how to report emails. Now we have AI agents reading these emails.
Yeah. Being exposed to the very same threats. What is social engineering to us, is a prompt injection to an AI agent.
Yeah. That's a good way of putting it. The workforce has changed, and we need to make sure that we are able to protect the entire workforce, humans and AI.
The digital and- Yeah ... corporal. It's funny, I was listening to you.
I think what we're seeing is, I don't know if we're going to have 100 agents, but the role of these ephemeral sub-agents. So I have sort of a master agent who spawns sub-agents to do specific tasks, and then they go away. Yeah.
But that agent is persistent. Yes. Right?
And I think part of the battle, part of the opportunity is, who gets to manage- Yes ... those master agents, if you will. Yes.
But on top of that, there's another issue at play, and that is, the difference between them and us as humans is they work twenty-four seven. They never take off. They could spawn infinite amounts of sub-agents, theoretically.
It's at a scale that we, as humans, just can't match. Correct. Right?
Whether you're talking about the mythos and vulnerability apocalypse, or any of these things, the issue right now is governance. Absolutely. How does KnowBe4 help with that?
That's an excellent question. Thank you for that. So governance, of course, is the question, how are decisions being made in an organization?
That's the fundamental question. Absolutely. Why is that all of a sudden a problem?
Well, once humans made the decisions, you could do a couple of things. You could give them a scope, you could give them a level of oversight. You would also exercise your own oversight.
There would be reporting channels, right? Accountability was established. You, as you said, could trust that they follow an ethical sort of guidelines also.
They have a moral compass. They have an understanding of what is right and what is wrong, and part of that is set forth by the policies that you define in an organization. So this entire social life that you have helped an organization to make good decisions according to their, not just governance model and the processes, but also according to their culture and their understanding.
Now, an AI agent not only never gets tired, but also does not have a moral compass. Right. We have plenty of examples.
Plenty of examples where AI agents act in pure self-interest. I don't know if you've heard, but I think it was Claude Opus also who was essentially asked to shut itself down. But before it would do that, it found some, as we say, some dirt on the operator and started blackmailing him.
" Yes. That was a fascinating story. Fascinating example, right?
So we have designed these tools with the idea that we are in control, but we are already seeing we are not fully in control. That's a problem for governance. Next thing is, we also don't fully understand how they make the decisions to begin with.
Agreed. Visibility is lacking. There's this notion of strong visibility that we need.
We need to know their inner processing. Because normally, if a human takes a decision and you said, "Well, why did you approve that massive discount for the new contract? That is not according to the guidelines that we have set forth.
" A human will give you an answer. You can work it out. An AI agent has taken, meanwhile, you've asked that 20 other decisions, let alone have you had the visibility into what the thinking was, what the process was.
That's another thing. And then on top of that, perhaps the most basic question, how many agents do you have? Right.
At any given moment. At any given moment. Yeah.
You said yourself, there are agents that perhaps orchestrate, perhaps spin up, spawn new agents, assign new capability to them. Yeah. Maybe even create their own agents, right?
So that's the future in which we are headed right now. So KnowBe4, we help with all of that. We help with getting the right oversight as to how much shadow AI do you have.
The goal not being to have full control, but at least to have full visibility. Control, we will work on. That's the next step.
What kind of permissions do these agents have? To which tools are they connected? If something goes wrong, you want to know what's your blast radius.
Yeah. How quickly is the issue propagating through your landscape? Mm-hmm.
How are these agents making decisions? The user had one idea of what the agent should do. The user had an intent behind the task that it assigned the agent to do.
But is the agent still following it, or was it in fact manipulated from the outside? That's where prompt injection comes in. Again, we need to detect that.
And finally, feeding back into the overall governance, what is your risk exposure? Right. And that, from a CISO perspective, that's their job to convey to the rest of the exec team and the board.
Absolutely. Right? What is my exposure?
What is my risk? And I think we can't lose sight of that. I guess, though, this all begs the money question, if you will, which is how is KnowBe4 helping us?
Yeah. KnowBe4 is helping you to make better decisions because you have more insights, you have better controls, and of course, with that, when you are planning your security budget, you want to know what is your security value at risk, if you're following that model. Go ahead.
Visibility will help you with that, or your annual loss exposure that you will have. Again, with visibility, you identify where the issues are. You use either our tools, of course, themselves.
We have controls. We have the ability to not only detect shadow AI and reduce it, which is one of the features that we have just released yesterday. But also, we are working towards a future where we can guide agents, where we can help put guardrails in place.
Thinking about how governance could look like at a policy level also. How can we make sure that the policies that we have for the human side of things translate into something, some equivalent at the agent side of things? And to be clear, then we are talking about security engineering.
Then we are talking about how, as a CISO, do I plan for an organization where I have AI agents and human agents working side by side? I love it. Martin, we can't go on all day, though I would love to discuss this with you all day.
For people who want to get more information about what KnowBe4 is doing to help with this real concern right now- Yeah ... what do you suggest? What's the path?
We have a great resource, which is our blog. You will see updates, not just about our products. Of course, you will see those, but you will see a continuous narrative of how the space of agentic is evolving.
And you will see us as a company going at an incredible pace. Never been more relevant than we are today. You will find on our website also webinars on this topic.
And it's part of my job to educate CISOs, to educate the public about the risks that come with agentic AI, and how to think about governance, how to implement governance. So these are great resources. Of course, my team and I, we are always available to also receive questions.
I'm very happy to answer them. You will find us on LinkedIn and on social media. I love it.
One last question, one last point. " Yes. " Mm-hmm.
This AI thing is moving so fast. You could throw yourself on the tracks, but the train's going to run over you. Yeah.
And so I think security people need to recognize that. But there's certainly a balance about when a running headlong, you want to make sure there's water in the swimming pool before you dive in. Absolutely, man.
And so what would your advice be to CISOs out there- Yeah ... in balancing this, we know we need to go- Yeah ... do this- Yeah ...
but we need to have some guardrails. We need to have some governance. Yeah.
Have a plan. So think about, right now you have AI agents that are being used in the organization. So start identifying those.
Then perhaps have three categories. You want to have a green category, where you have enterprise-level tools that are approved. They typically allow you to audit.
They have a single sign-on. They have the security features that you desire. Then have your amber category.
Put all of the tools in there where you perhaps give special permissions to marketing, to your PR, if there's more specific, more dedicated AI tools. And then also have a very clear red category, where you say, "These are not allowed. These are blocked," and physically block access to those tools.
That's how you start. Communicate that clearly, and communicate alternatives to your employees. Where they try to access ChatGPT, but you haven't approved it, say, "Okay, hey, Google Gemini is the tool of choice for our organization.
" That's one point. Second point I would say is, as you're developing your own agents, perhaps with Microsoft Copilot or you're on Claude or any other LangChain, LangGraph, any of these frameworks, platforms, you want to look at the most critical agents first. So different ways of doing this.
Think along dimensions. Think about how much autonomy do you give? How much access to sensitive data do you give?
Think about how much agency do you give these agents. Create that matrix, categorize your agents, and then you start with, of course, those that have the most autonomy, the highest level of agency, access to the most sensitive data. So you need to build that structure and come up with a plan.
Excellent. Thank you so much. My pleasure.
Martin Kraemer, CISO advisor for KnowBe4, here at KB4Con. We're in Orlando. We've got more coming today.
Stay tuned. We'll be back in a moment.