AI Review Checkpoints, Agent Runtime Guardrails & Identity Management
Enterprise AI is moving past model selection and into the control layer. On this episode of Techstrong Gang, Mike Vizard, Jon Swartz, Tracy Ragan and Jeff Reich examine how teams are adding review checkpoints, runtime guardrails, cost controls and stronger identity discipline as AI systems move into production.
GitHub is testing a second-model review step in Copilot CLI, which signals a broader shift from single-model trust to cross-model verification. At the same time, flat AI subscription pricing is colliding with real agentic workloads, pushing buyers toward metering, observability and governance.
The panel also looks at how Broadcom and Capsule Security reflect a larger platform shift, where agent runtimes and guardrails are becoming infrastructure responsibilities instead of prompt-level workarounds. Identity management remains part of the same operational problem, as disconnected apps and manual access changes continue to create security gaps that get worse as AI sprawl expands.
The bigger theme is operational control. As enterprise AI scales, success depends less on model novelty and more on the systems that make agents observable, governable and safe to run.
Transcript
Hey everybody. Welcome to Friday. As usual, I'm starting off my Friday with the same basic reaction.
" So let's just jump in without much further ado. But Jon Swartz is here as always. John, how you doing, buddy?
I'm good. Good to see you, everybody. Good.
Tracy Ragan, good to see you again. Friday is kind of Tracy days. Yes, thank you.
It's always my way of reminding myself it's Friday. There you go. And Jeff Reich is here from the IDSA talking about identity, and we're going to have a deep conversation about that later in the show, so stay tuned for that.
But I'm going to jump in with just some kind of weirdness that's in the system and I can't wrap my head around it, but I'm going to try. So, GitHub is talking about, well, suggesting that maybe you should get a second opinion when consulting AI, especially within the CLI for application development. Which of course got me thinking, well, if it's good for the fact that I need a second opinion for when I'm building software, well, shouldn't that be true for just about everything we do with AI?
And now I got to get a second opinion and ask the second model for the same thing or to verify the first one. And at some point this starts to feel like a trip to the hospital where you get in there, you meet a doctor, and then the next thing you know, you got to get a second opinion from somebody else, the doctor, and the next thing you know, the bill starts to go up pretty heavily. And God forbid that that AI agent might be out of your, quote unquote, "network," because then it'll even be more expensive.
So John, is this whole thing going to get expensive in a hurry in a way that we hadn't thought? And at what point do I need maybe a third opinion? Yeah.
So even the name of this GitHub project, what is it called? Rubber Duck? The whole thing to me is goofy.
And I thought of it initially, I thought of it in three or four different ways. I thought about the second opinion, the doctor's second and third opinion, which usually means a higher bill. I thought of it as a kind of a constructive peer review, even like rudimentary fact-checking.
But I also thought about it as almost like corporate espionage or sabotage, and here's what I'm trying to get at. So are we going to expect teams to standardize a primary model and then a review model the way they standardize lenders and test frameworks? 7, which was just announced, rather than just having a second instance of OpenAI, the same model reviewing the work.
It kind of is head-spinning, and I can see how this can go right in a certain way, but I can see how it can go very wrong in a lot of ways. It can become expensive, confusing, and in a sense, these models are not exactly primed to work or cooperate with one another. Or maybe one might undermine the other for some competitive gain.
All these things just came to mind. It's true. So why would I trust one opinion from an AI model from a competitor of the other one?
Yeah, it becomes an interesting question. Also, when I go to the hospital and I get that second opinion, I don't particularly feel I'm better off than I was before, unless they happen to say something I like maybe, but that doesn't mean it was good advice in the first place, and maybe the first opinion was better than the second opinion. So I don't know how to sort this any more than you do.
But Tracy, does this make any more sense maybe from an application development point of view, or how are you thinking about all this? Okay. I just have to remind all of you, when we were talking about this oh, some time back, I said I want a multi-model consensus.
" ChatGPT is better at literally at writing. Claude's better at coding. They all have their specialty and I keep saying I want a consensus model.
So, I think in order... Well, there's many problems with large language models, and I can get on my soapbox again about small language models which are more accurate, and maybe you wouldn't need a consensus then. But I believe that this is the way to go in order to start getting better results from these models.
In particular, when we are starting to run down the road and the journey of agentic AI, and we're not just hallucinating, but we're acting on our hallucinations. So a consensus, I believe, will be important, and a reviewer will be an important piece of the puzzle. So how would that consensus work?
And I'm going to ask the question because Alan has a piece talking about jagged intelligence and the notion that some of these AI models are better than others, and I think he was referring to an article on The Times or somewhere, somebody was talking about this. And but we don't seem to know where and when to apply that particular understanding of which model might be better at what when. And so is the consensus model going to understand the inherent jagged intelligence of this, or is this just wind up being a bad AI version of a Glenn Close movie that happened about 30 years ago?
I think that the end user should be able to select the models they want a consensus from. Yeah. So yeah, I agree with your sentiment on a consensus opinion.
But those are so hard to reach sometimes, just in general. Like too many cooks, I guess, is what comes to mind. And so here's a question I would have for you or Jeff or Mike.
How would training biases influence the types of errors one model might catch that a other might consistently overlook? Jeff, go ahead. I have some thoughts on this.
And Tracy, we haven't been on a gang show together yet. I'm that guy. All right.
But my position on this is if you go back to- I'm old, so I always have references back, but they seem to work. When you create a development team or a team of programmers, as they used to be called, you don't get four people that all have the same exact training and the same exact background and create the same sort of code. Because it used to be that when someone created code, before it even went into testing, someone else reviewed it.
Now, I'm not suggesting we necessarily do that, but what you're hearing from GitHub is kind of the same concept, that when an entity creates something, another entity from a different perspective should be able to review it. They may not catch everything, but a review that says, "Here's more objective eyes," can help. And I think, Mike, to your example, I always thought when a second opinion, to me, the choice was, what lubrication do you want?
But I do think that having a second one works because you're building a team of AIs. Now, any one of agents, anyone that thinks, "I have one model, and here's my language model, and I'm using it, and everything it does is perfect," great. Let me know how that works out, because you are putting all of your faith in one entity, just like you might in one developer who might get sick or might meet that proverbial beer truck that has their name on it or whatever reason.
Depending on one is always going to get in the way, and this is simply a matter of risk management. For my more vital and important applications, yeah, I'm going to have to have multiple points of view. For something that's run-of-the-mill and maybe retrieving data but not changing it, sometimes you can get away with slipping one in without a second review.
I think that goes for people and agents. Tracy, what Jeff just described sounded an awful lot like a pizza box team. Remember?
You had a bunch of developers, and the size of the team was determined by how many pizza pies it would take to feed them. So are AI agents going to essentially, in the app dev world, just become another pizza box kind of team? I think that they need to be.
If they're going to be responsible for generating that much code, then we need a way to mimic that same environment, right? We do this all the time as humans. We get together, we talk about architecture, we ask each other what your experience has been to make a platform better.
That's the way platforms become better, is having many people support the process and have a discussion about it and open up areas that one person may not have thought about. Mm-hmm. I just believe that AI agents or AI, these LLMs are going to be the same way.
Some have expertise that the others don't have. It's just the nature of the beast. That's why I think a consensus is the way it should be, and I'm not a reviewer.
I even looked for a tool that allowed me to say, "Let me plug in X number of models, and then I want to ask a question, and I want three models to come back and give me the best answer. " And of course, there's nothing of the sort at this point because it would be costly, and I think we're going to talk about that, but it feels like the right way to go to me. It really does.
It solves some problems. Well, I get all that, but how would the consensus thing work in your mind? Because I'll give you this scenario.
Agents A say the answer is B, and then a separate set of agents say the answer is C, and they're going to argue amongst themselves to the point where they're going to get frustrated, and then what? They're going to call us to kind of referee the opinion? Yeah, who's the ultimate arbiter?
Yeah. " So you just want- Right? you just want the choice, right?
Essentially, right? I want the choice. Yeah.
Yeah. I want the choice. With some weights attached to it.
The same way as I evaluate a group of developers or architects trying to decide something. If three or four of them all agree this is the way to go and one or two say no, it's majority rule. Oh.
This is starting to sound a lot like baseball to me, John. Yeah. We got pitchers and catchers, and then we got umpires, and then we got AI checking out the umpires.
The batter. Yeah, we got AB, ABS. We have three people interpreting the pitcher, the catcher, and the hitter.
So yeah, I totally agree with Tracy. Diversity of opinion is ideal. I think it's the best way to do anything.
You want more opinions, but ultimately, somebody has to make the choice, and I think in this case... I've tried this experiment where I've asked several models for an answer to something, like say, what's the best headline for this story? And they're wildly divergent sometimes.
And ultimately, I guess the human makes the... My choice, I made the choice. I didn't depend on a machine to do it.
To me, I like the idea, I like the concept, but in practice, the execution is going to be a little bit tricky. So how will this also work this way? And I'm going to describe this, I'm sure everybody has friends like this, but I have friends that I dearly love, and I enjoy their company, and I take their word for absolutely nothing.
And it's- I have friends like that, too. And aren't we going to be in the same situation, Jeff, where we're going to have to put some sort of identity moniker around each individual AI agent, track its record, and have some understanding of its veracity? Yeah.
" Different person, right? If someone that's really good in finance, maybe that's someone you want to talk to. The diversity of opinions, and you can have relative ratings for having a good time at night, yeah, your drinking buddy's a 10, but they're a four when it comes to giving you advice for buying a car.
Mm. And ultimately, it's about trust, right? I just got back from a vulnerability conference in Phoenix, was great, VulCon 2026, and there were so many people that don't trust AI.
And I get it. They don't. And if we're going to have AI start actually making modifications to configurations and builds and workflows, there's got to be a way to have a second reviewer.
So I think that rubber duck is-- I was glad to see it, to be honest, because it's saying that this is going to be part of our infrastructure. And if changes are going to be made in our infrastructure through AI, then why shouldn't it have a reviewer just like humans do? Yeah.
But it gets better, and because I have more time on my hands than I know what to do with sometimes, bear with me on this one, but to your point, right? So we're moving from suggesting to the AI agents actually taking an action. Well, in the healthcare world, when I get that second or third opinion and somebody takes an action, they have a thing called insurance, that if things go wrong, I have some recourse that I might actually be able to recover some joy from my pain or make it up somehow to me.
And so, John, are we going to need AI agent insurance at some point? You know what? I actually think that you're spot on.
That's going to happen. I was thinking about this, do you grade this on agent reliability? Which, in a sense, kind of brings up you need some sort of insurance policy to protect you from bad advice.
I'm not going to go into it, but I know diagnoses that have been completely off that have led to really bad consequences for something as serious as health. God forbid this happens in this scenario, but conceivably, I think we're going down that road to insurance, yes. There's case law that's a foundation for it already, by the way.
If you haven't heard in the past month or two, the one that stands out most is the Air Canada case. And if you're not familiar with it, real quickly, the chatbot gave a bereavement fare to an individual for a bereavement trip. A grandfather had passed away.
And Air Canada then said, "No, that's not valid. The chatbot shouldn't have done that. " And he won in court, and Air Canada had to pay him back the difference.
Small case, but I think that's the seed that's going to start some case law precedent coming up. Right. Now, most businesses have some level of business insurance that cover all kinds of interesting scenarios.
So will this be a clause that now gets tucked into my business insurance that says, "Hey, when the AI agent goes haywire, I'm covered for X, Y, and Z"? What do you think? John Gordon.
I was thinking about risk factors within companies', 10-Ks or 10-Qs. What's going to happen eventually if an AI agent or if there's a conflict, there's no consensus and it leads to some sort of bad business decision or something that hurts the bottom line? That could conceivably happen.
When we're talking about insurance, we could also be talking about risk factors involved in AI agent decision-making, where there is no consensus and somebody's blamed for something that goes awry. I don't know. I'm just thinking the scenario could happen.
Go flip it the other way. Tracy, follow me on this. Let's say I am the insurance provider, and I become aware of the fact that you are using AI agents, and I don't know what your security protocols look like.
Might just raise your insurance because your risk went higher because I don't know what those AI agents are liable to do. And neither do I. That's probably a good call on the part of the insurance agent.
This is the topic of the day. How do you manage that? How do you control it?
How do you version it? How do you version a prompt? It's pretty much a Wild West out there, and there are no easy answers right now.
There just are not. All right. Except for I wish that we were more in tune to building everything that we build, including this new world of AI, with security by design, and we're not.
We're running so fast in the direction of AI that we're not even thinking about it. And from last week, I'm still thinking about memory poisoning, and how do you fix that? Mm-hmm.
There are so many pieces to this puzzle that proceed at your own risk. That seems to be the incurrence. Yes.
The lack of security by design has kept me employed for 50 years. Yeah. So Jeff, last thought on this to you, because, yes, I have been thinking about this way too much.
But isn't there somebody out there who is an auditor who's probably smiling to themselves thinking, "Wow, this is going to be awesome. " What do you say? Well, I'm not certain it's going to be an auditor that does it.
And I'm not dissing auditors, but I'm not certain that's the social group that's going to be leading that. But I do think where we're going to see itIs red teamers, whether they are employed to be a red teamer for the victim or they're employed to be a red teamer for the attacker, and that is already happening. So to your point, that technology exists.
You can go buy it on the dark web. The challenge is how do you commercialize it in the commercial world? And the downside to it right now is most auditors say, "I have a checklist.
" And by the time you're done with the checklist, the whole environment changed. Mm-hmm. So I'm going to leave this here, but if it was me and I was building out an AI agent and I was going to deploy it, especially in a production environment, I might call it Pandora with my tongue firmly in my cheek.
Mm-hmm. All right. We'll be back in a second to talk about our next topic, which is kind of related, but I'm going to shift the gear here a little bit.
But if you haven't noticed, everybody and his brother is talking about now, AI agents, OpenClaw, whatever it may be, and suddenly there's a raft of announcements talking about we need runtimes that isolate these AI agents so that everything we just talked about doesn't necessarily happen, or at least we can have some containment around it. And whether it's in a container itself or some sort of runtime in a PaaS from Broadcom's talking about that, or some independent runtime that's from a startup security company that launched one last week, and I suspect there's probably going to be, I don't know, hundreds of these runtimes probably. Every application development environment will be extended to have some sort of way to isolate AI agents.
Tracy, does that make any sense to you? Where are we going? Yeah.
So I think it was Broadcom and Capsule Security, both had some announcements on this. Broadcom kind of positioning it as a AI agent runtime and elevating it to a first-class platform capability. Capsule Security is talking about introducing this open-source pre-invocation checkpoint to evaluate what an agent is trying to do before it uses a tool.
It kind of sounds like a reviewer, right? They're very similar. Mm-hmm.
But overall, I think these announcements reinforce the broader pattern that we're seeing in the industry and rediscovering what runtime visibility is and the missing layer for these AI systems. And it reminds me of the software supply chain, and it also reminds me of SLSA. I think we're having a similar conversation.
A few years ago, we were talking about SLSA, and it emerged so organizations, they started realizing they couldn't trust software unless they could verify how it was built and where it came from. So now we're talking about AI agents and how these runtimes are emerging for the same reason, but at execution time instead of build time, which is kind of worse. So I think as these autonomous agents start to gain access to the different tools and data sets and infrastructure, enterprises need a verifiable control layer that can ensure that these agents behave with policy, use only approved capabilities, don't act or manipulate inputs, kind of like SLSA did for builds.
So it's becoming the control plane for AI agents. And again, these are all great new conversations, and many of them have to do, in a way, with being more secure. And this one in particular is all about being more secure.
And I have said from the very beginning, I hate agents. I know all of you have heard me say that, and these are the reasons why, and so I'm glad that we're starting to have a conversation and we're starting to hear about AI runtime control and governance, kind of operational control over that process. Jeff, is the cart before the horse again?
Because you would think we might have thought some of these things through for runtimes and security and isolating agents, but no, we're just basically rolling these puppies out and seeing what happens as they go along. We hook our wagon to something that's moving, and we find out where we're going. I'm going to do a little- While you're moving ...
experiment here. You remember SBOMs? Did we solve that?
I think yes and no. You can generate an SBOM more easily, but whatever was in the SBOM probably isn't there anymore because it got updated when nobody was looking. Exactly.
In fact, by the time it was delivered to you, it changed. Mm-hmm. And I think that's where we are now, and that's that wagon that we're hooked onto.
And John, I can hear what you're trying to say about that. It's going really fast, and we're all hoping it gets us where we want to be, but we really don't know where it's going to go. And I'm not the harbinger of doom.
I am pro AI, and I like agents. I like driving fast, but I don't do it in a residential street where kids are playing. So look at the situation.
It's all situational awareness. Mm-hmm. Yeah.
In this PIP in particular, when you're passing this kind of data, it's really about prompt injections. Right? At its core, what we're dealing with these runtime agents is prompt injection.
These are the prime vulnerabilities for AI. It's prompt injections. And you can't version prompts right now.
" One is AI bombs. They don't really cover a lot. Mm-hmm.
And you can't really version... If you download something from HuggingFace, you can get an AI bomb, but they're not very accurate. Can you get an AI bomb from ChatGPT?
Not happening. And prompt injections, we have to address versioning prompts and controlling prompts. How else do you solve the problem?
I don't know. I'm not sure either. " Or is this going to be one of those death by a thousand cuts kind of scenarios, and it'll take us two years to figure out that maybe we should do something about it?
Oh, death by a thousand cuts, definitely. It takes a couple of years. I think Adrian Bridgwater wrote this story, and I think one of the things that he mentioned that you just said, that organizations often wait for major cybersecurity incidents before they prioritize new defenses.
And one of the questions I wanted to ask was, is there a clear boundary between platform guardrails and security guardrails? And I'm also wondering, are these agent runtimes going to become part of platform layer, or are they going to be just used as a niche for regulated organizations? It's a platform layer.
I'm betting on the platform layer. I think it has to be a platform layer. And I think what people don't fully appreciate, and maybe Jeff can walk me through this a little bit, but the thing about an AI agent, it seems like they are designed and programmed to accomplish their mission at all costs, regardless of what...
And guardrails are just things to be overcome, which is a lot of the way developers view guardrails anyway. " I think you hit the nail on the head because we're looking for speed, we're looking for productivity, and all that can be great, but the guardrails that need to be there, whether they're security, platform, or data. We haven't talked much about data yet, which by the way, is the end result of all this.
Without those, we are hoping, again, for the right content, and I think it is moving too fast. There's another component of this that I think we're kind of missing. We're making strides, go ahead, just break things fast, and then going back and fixing them.
And when we look at that, there's two huge costs to that that we're really not looking at yet. First, the cost of fixing them. It always costs more to repair a problem than it does to design it correctly in the first place.
We all know that. But the other downstream effect is the more correction we need, which means there's more language models, there's more agents running, there's more data centers, there's more real estate taken, there's more electricity used, there's more water that's polluted, and everything else that comes down for that without-- If we're not-- We need societal guardrails as well, because we will eventually say we can move everything so fast, and we have to fix everything so fast, we need data centers the size of cities just to do it. Well, and part of that has to do with the simple fact that the utilization rates of GPUs are atrocious, and that's part of the secret of the thing.
But on average, the utilization rate of a GPU is about 5%, which means that 95% of the time, it's just basically sitting there doing nothing. But Jeff is right. Data is important, and I think that Broadcom's Tanzu kind of signals that these AI agents are just transitioning from an isolated event or experiment into a production workload that's integrated into our enterprise data.
And that is the key, right? So as you look at all this, and I guess I'll throw this back to, well, Tracy, would you be deploying AI agents in production environments today, or would you just wait for all this to settle out a little bit and continue to experiment? " I think it depends on how isolated it can be and what kind of data that it is actually consuming.
Everything has a risk parameter around it, and if it's low risk, I think I would move forward. But if it's high risk and it's critical data, I would not. And Jeff, do you know what the most sought-after piece of gear is these days as a result of AI agents?
Mac Minis. Why? Yeah.
You cannot get them. One of my other machines here is a Mac Studio, which I really like, which is kind of a Mac Mini on steroids to a degree. But I've had Mac Minis in the past, and they're real useful for this because you can just stack them and stack them, and they work.
So I'm not here to advertise for Apple, but yeah, that's why you can't get them. In the same way that for the end user, for the terminal perspective of it, those Neos are selling out. And I know this wasn't anywhere in what we were going to talk about, but Apple's done a really good job of taking chips that they were going to have to throw away and selling them in new machines.
Does anybody but me think that if the solution to something is stacking a bunch of Mac Minis, perhaps the thing is broken? I'm just saying. It's a way to start, right?
Yeah, it's a way. It's a way to start. We have to start somewhere.
Think about Kubernetes, right? Look how far Kubernetes has come. Kubernetes had similar problems.
It was a way to autonomously manage your production environments. People ran with it. Containers went crazy, microservices went crazy, and we've been cleaning up ever since.
And AI is going to follow the same road, but I think there's more danger in AI, and in particular, agentic AI. So I think it's a larger attack surface. And imagine how many agents we're going to have out there.
Thousands of them, thousands of agents. And how do you control that? It's-It boggles the mind, and I'm looking forward to seeing how this younger generation's going to solve it.
I'm looking forward to the following. I think that as these runtimes come on, we'll have more secure environments for running these AI agents, and we'll run them like grown-ups, and all those Mac Minis will be worth about two bucks on eBay. There you go.
Some of us will do that. All right. We'll see how this plays out.
I'm going to shift to our third topic, which is not surprisingly a little bit related, but there's a report out talking about how our problem is with zero trust and multi-factor authentication and SSO is we create these things, but we don't know how to manage them. We don't have any central control for that, and then it becomes a pain and everybody kind of resents having to get their password changed or find their mobile phone to get their authenticator out, and the whole thing just feels a little too cumbersome. And now we're adding AI agents to that, which I can't tell if these things are an extension of the human identity or will they have their own identity, and are they machine identities, or are they some new type of identity?
Jeff, help me out here. How's all this going to play out? " We're all better.
But this is a huge issue. At IDSA, we're a nonprofit with a bunch of member organizations, many of whom are identity vendors. And they are asking that very question, and they're all seeking the answer for a number of reasons.
First of all, let's talk about MFA. And there is a term, at least in the identity industry for that, I'll give you the PG version, more friction for authentication. You can substitute that middle word for whatever you want.
But how many people like MFA now? And there's still organizations that haven't even done that, and that means you're not even up to 2015. And here we are moving faster past 2026.
And the answer is going to have to be, first of all, from that perspective, we can't continue to try to catch up with MFA because MFA is actually broken. Yeah. Just like every security tool eventually is, either because someone cracked it or it's such a pain people find a way around it.
" I do too. And that really affects- Guilty. Yep.
It affects productivity as well. There are vendors out there now that I think the next answer has to be biometrics because it's the only thing you don't have to make up. And there are tools out there that can give you a pretty streamlined login and authentication without having to actually enter anything, other than finding a way to get your biometrics there.
The price point's under $100 now, which is what it had to be. It's going to drop more, I believe. Right now, it's probably around 80 per unit.
And with that, I think you're going to see the death of both passwords finally and MFA. Single sign-on is fine, but it's just a matter of how do you distribute it. Good single sign-on tool with biometrics, I think, is the answer to this very problem.
Now, for humans. Now let's get over to AI identities. The last survey that I saw on this said that non-human identities, NHI, outnumber humans 250 to one.
That was two weeks ago. I'm sure it's up past 300 now. Mm-hmm.
Jeff, in that survey, it said 89% of applications are not centrally managed via MFA. Correct. And 70% lacked SSO.
Mm-hmm. I feel like it's not just a tooling problem, but it feels like these larger SaaS sprawl and these disconnected applications are the problem. Those are huge numbers.
I was surprised. I had a question about that because in the survey, I think it was like 57% of the leaders rated their confidence at a seven or higher, yet as you mentioned, Tracy, nearly 90% of their applications lack centralized MFA. I feel like- Yeah, a bit of a confidence gap.
Yeah. Let me offer another data point on that. Every year, we do a research survey.
In 2024, we asked a question about how confident are you about deploying AI in your environment? " They were really low. And then in 2025, that completely flipped on its head.
CEOs are saying, "Faster, faster. I want AI everywhere. " And CISOs are saying, "Wait a minute.
" It completely flipped. I have read a million security surveys now, and I'll tell you they all have the same vibe underneath it, and it goes something like this. " Absolutely.
So the takeaway, though, if you're a CISO and you look at this data, so which deficiency would you prioritize fixing first? Would it be the lack of a centralized MFA or the absence of SSO integration? If I can, real quickly, because I'm also hearing from other CISOs on this.
That question eventually needs to be asked, but first of all, the question that has to be answered is: Where are our most important and valuable assets? Which usually relate to data, ignoring people, we're past that, right? It's going to be dataAnd I've done some consulting in the past as well.
" Otherwise, they wouldn't have brought me in, right? " No one knows the answer. Once again, they wouldn't need me if they had the answer.
That hasn't changed. We're still woefully ignorant of what's important and what isn't. And until you do that, you're going to throw money at a problem and never solve it.
All right. Jeff, walk me through this a little bit because I want to make sure I understand this. If I lack the ability to centrally manage all this stuff, it doesn't stop me from using MFA.
I'm going to pretty much in a lot of places have already tried to do that. But this is where the bad experience lies, and this is why everybody starts to hate this stuff, because there's no way to kind of automate the experience and the management of it. And when something goes wrong, it's like you're stuck because there's nobody on the other end of this thing who's automatically going to fix something, and everybody runs into an issue.
So again, is the cart before the horse here and we should automate it, the management on the back end first before we started rolling all this stuff out? Well, yeah, but if you remember shadow IT and being able to do cloud computing pretty much broke that model. I'm not sure it was in great shape before, but that clearly broke it.
So we can't go back in time, that I'm aware of. I would love to. But, since we can't do that, I think trying to put yet another layer on top to say, "Here's how we're going to centralize it," I think adds more cost and administrivia and friction.
I really think there has to be a, "Here's a productivity tool, not a security tool," that will allow you to get to everything. All you need to do is when you get to an application you're using, if it's not asking you for that, tell us. That's it.
Simple as that. We'll make it work. So what you're really saying is identity security has to mature into some kind of continuous discovery, not just like a stronger login controls.
Exactly. It's me and the blended identities that I have in the AI world that I authorize that have to be authenticated. And in that environment, it can't simply be I know my password, or I know my authenticator is six digits.
Does it also get back to Tracy's point earlier, come full circle here a little bit, but don't I also need to know, correlate the identity to the intent of the prompt to understand that the thing that it's trying to do is legitimate, otherwise it's just going to go off and get fooled by some prompt injection attack, and these things all need to converge? I would offer yes. For humans, that's where biometrics come in.
And for agentic identities and non-human identities, there has to be a way for a pre-authorization by a human to occur, and it can't be a checkbox. It still boils down to, in the broader scope, you need to know what your systems are going to do or your successor will fix it. Tracy, are you saying they're fixed by developers as we're building out the applications, or is this like a bolt-on later?
I think it's going to have to be a bolt-on layer. I don't think developers are going to be able to address this. I don't.
Unless they do more security by design, which would be great, but they're not. So and we're asking them to do so much. I do think it has to be some kind of continuous discovery.
There's got to be different kinds of security identity management that can do that. Mm-hmm. John, I'm starting to feel like a reporter who knows that there's going to be a traffic accident three times a day at a specific corner.
Yeah. I pull up my chair and wait for it to happen so I have a story. Yeah, exactly.
I was thinking about that, this kind of theme of this episode. All the things that are going to happen that we can see happening in slow motion, and we're just waiting for them to happen before we address them. True that.
But we're not quite sure exactly how to address them. Well, if I wanted to unify all three of them, I would just say all three of them have one common characteristic: schizophrenic. All of them.
On one hand, yeah. So I would offer, you know what it usually takes to have a traffic light installed at an intersection? An accident.
A fatality. Oh. Wow.
A fatal accident. Yeah. And I think that's where we are.
Yeah. Sorry. That is- I hate to say that- Good analogy ...
but this is why I know, Tracy, why you don't like agents, but I buy into your argument, your thesis, because inevitably there's going to be some things that happen that are going to be painful, whether physically or emotionally or financially. And it's just that we're all kind of blindly moving our way through this. It is true.
Sadly, Jeff, there's a friend of mine I grew up with, and he was killed at an intersection in the old neighborhood. And so that intersection had not had a traffic light for as long as anybody can remember. And then shortly after that, that traffic light went in, and everybody in the neighborhood calls that the X memorial traffic light because they all know exactly how it got there and why it was installed in the first place.
So sad to say, how many traffic lights are we going to need, though? Because there's now millions of AI agents, so I don't know if we can put in a traffic light every five seconds. Well, maybe we start automating the cars a bit more to blend with the human driver.
Ooh. See, I'm trying to bring... We need to end on an up note here.
Yeah. Yeah. The best drivers, I went into San Francisco twice this week, and the best drivers out there are the Waymo by far.
They're the safest. They adhere to all the rules. They're predictable.
They're not swooping in front of you. They're not tailgating you. They're not abruptly changing lanes without signaling.
I find that encouraging, at least. In general, I agree. They work great until they hit someone.
Oh, yeah. But that's how it's going to work, though. Nothing's going to be perfect.
And I'm not trying to devalue a life that might be injured or taken by an accident from a Waymo, but that I think is going to have to be the answer. No matter how good a driver you are, take a look at a new car now. Not only do you have your phone, you have an entire dashboard that can keep you entertained.
Oh, yeah, you're supposed to be driving. John, are you saying that all those people in the left-hand lane that are doing about 25 miles over the speed limit are wrong? I live in California off of Highway 101, which is basically a racetrack.
It's like a Formula One stretch, and I wish I saw more CHP, but when I see a Waymo, I actually relax. I actually feel at ease. And I never felt that way when I first started seeing them early in the morning in San Francisco.
I would avoid them. Now I'm happy to be near them because I find them much more predictable. Anyway, I've changed my mind, and I thought, I changed my mind quickly about it.
All right. To Jim's point, though, we will end on an up note, because the cool thing here is there's just an amazing amount of things that need to be fixed, and there's all kinds of engineering opportunities and things that we got to address, and we're far from done with all this stuff. So it may be another 5 to 10 years before all this finally plays out and, well, I don't think AI agents are going to solve all that stuff on their own.
What do you say, Tracy? I think that all of the topics we talked about really has a kind of a consistent line, and that's operational control, and I believe that's where we're headed right now with AI, and that's a good thing. There you go.
It's not humans in the middle, it's humans on top, and then we'll worry about everything else from there. Hey, everybody, thanks for sharing your thoughts and your insights once again. Thank you all for watching the show.
As usual, please stay tuned for the rest of the Techstrong TV replay lineup. It's an awesome lineup as usual, and we'll see you all again Monday, where we will be recording from Prague at a SUSE conference. So yeah.