ABOUT THIS EPISODE
The Security Table is now the AI Security Table, and the first order of business is naming the AI that gets a seat at it. Then Matt asks what a security engineer actually does once agents are writing the code: real security work, or bot herding? Chris Romeo, Izar Tarandach, and Matt Coles detour through who owns AI generated code and what a patent is worth when a model can rebuild your product in five minutes, then dig into agent identity, SPIFFE, least privilege, and whether access control belongs inside the agent harness itself. Izar argues that guardrails living in the context window are suggestions, not isolation, and that anyone who says AI changed their whole job overnight was putting the weight in the wrong place. It all ends on determinism: run the model once and you get one answer, run it again and you get another. Which leaves three kinds: determinism, nondeterminism, and my determinism.
Mentioned in this Episode:
➜ Generative Artificial Intelligence and Copyright Law (CRS Legal Sidebar)
➜ SPIFFE: Secure Production Identity Framework for Everyone
Chapters:
00:00:00 - Cold Open: We Are Broadcasters
00:01:06 - A New Name: The AI Security Table
00:02:17 - Naming the AI at the Table
00:03:02 - Stickers, T Shirts, and the Rebrand
00:03:49 - Matt's Setup: Security Engineers or Bot Herders?
00:04:54 - Does Claude Code Write All the Code Now?
00:05:34 - Who Owns AI Generated Code?
00:08:27 - Who Bothers to Steal Code Anymore?
00:08:47 - What's the Point of Patents?
00:11:33 - What the Law Says About AI Authorship
00:12:24 - Hallucinating: 200 Subagents at Once
00:13:34 - Back on Topic: Bots vs. Agents
00:14:18 - Agents Inherit Human Identity
00:14:49 - SPIFFE and Identity at Scale
00:16:35 - Treat Agents Like Bob From Marketing?
00:17:40 - Why? Why? The Five Whys
00:18:48 - Cryptographic Identity for Agents
00:19:37 - Authority Is Always Derived
00:20:59 - Least Privilege: Agents Request Access
00:21:26 - Read, Interpret, Act: Fine Grained Capabilities
00:24:22 - Access Control Inside the Agent Harness
00:26:17 - I Don't Trust the Box: Sandbox Escapes
00:27:34 - Pulling a Maestro: Guardrails vs. Isolation
00:29:43 - What Should Security Engineers Be Doing?
00:30:38 - Is AI Just a Layer Seven Application?
00:31:34 - Pull the Plug: 2001 and WarGames
00:33:29 - Your Job Didn't Change Overnight
00:34:37 - LLM Code Review and the Determinism Problem
00:35:44 - How Many Runs to Get the Circle?
00:38:16 - The Tightest Box Possible
00:39:09 - Twenty Thousand Feet to the Magnifying Glass
00:39:47 - Give Scanning Agents a Threat Model
00:40:32 - There Is My Determinism
00:41:09 - Outro
Follow AI Security Table:
➜ Home: https://securitytable.ai/
➜ X: https://x.com/SecTablePodcast
➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/
➜ YouTube: https://www.youtube.com/@AISecurityTable