How to secure your AI Agents: A CISOs Journey
Description
Transitioning a mature organization from an API-first model to an AI-first model is no small feat. In this episode, Yash Kosaraju, CISO of Sendbird, shares the story of how they pivoted from a traditional chat API platform to an AI agent platform and how security had to evolve to keep up.
Yash spoke about the industry's obsession with "Zero Trust," arguing instead for a practical "Multi-Layer Trust" approach that assumes controls will fail . We dive deep into the specific architecture of securing AI agents, including the concept of a "Trust OS," dealing with new incident response definitions (is a wrong AI answer an incident?), and the critical need to secure the bridge between AI agents and customer environments .
This episode is packed with actionable advice for AppSec engineers feeling overwhelmed by the speed of AI. Yash shares how his team embeds security engineers into sprint teams for real-time feedback, the importance of "AI CTFs" for security awareness, and why enabling employees with enterprise-grade AI tools is better than blocking them entirely .
Questions asked:
Guest Socials - Yash's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Security Podcast
Questions asked:
(00:00 ) Introduction(02:20 ) Who is Yash Kosaraju? (CISO at Sendbird)(03:30 ) Sendbird's Pivot: From Chat API to AI Agent Platform(05:00 ) Balancing Speed and Security in an AI Transition(06:50 ) Embedding Security Engineers into AI Sprint Teams(08:20 ) Threats in the AI Agent World (Data & Vendor Risks)(10:50 ) Blind Spots: "It's Microsoft, so it must be secure"(12:00 ) Securing AI Agents vs. AI-Embedded Applications(13:15 ) The Risk of Agents Making Changes in Customer Environments(14:30 ) Multi-Layer Trust vs. Zero Trust (Marketing vs. Reality) (17:30 ) Practical Multi-Layer Security: Device, Browser, Identity, MFA(18:25 ) What is "Trust OS"? A Foundation for Responsible AI(20:45 ) Balancing Agent Security vs. Endpoint Security(24:15 ) AI Incident Response: When an AI Gives a Wrong Answer(29:20 ) Security for Platform Engineers: Enabling vs. Blocking(30:45 ) Providing Enterprise AI Tools (Gemini, ChatGPT, Cursor) to Employees(32:45 ) Building a "Security as Enabler" Culture(36:15 ) What Questions to Ask AI Vendors (Paying with Data?)(39:20 ) Personal Use of Corporate AI Accounts(43:30 ) Using AI to Learn AI (Gemini Conversations)(45:00 ) The Stress on AppSec Engineers: "I Don't Know What I'm Doing"(48:20 ) The AI CTF: Gamifying Security Training(50:10 ) Fun Questions: Outdoors, Team Building, and Indian/Korean Food




