Securing AI at Scale: Why Your Logs Can't Read Agent Intent | Ashish Rajan

Securing AI at Scale: Why Your Logs Can't Read Agent Intent | Ashish Rajan

Ashish Rajan is back on Security Unfiltered, a few years after we last recorded together at RSA. Ashish is a CISO, host of the Cloud Security Podcast and AI Security Podcast, and author of the new Wiley book AI Security Engineering.

We get into how you write a book on a field that changes every month, why agents made him rewrite his plan halfway through, and what actually matters when you have millions of agents in your environment. Ashish makes the case that logs alone can't tell you intent ("is Joe an employee?" and "can I have Joe's password?" both look like plain text), why behavior is where agent security is heading, and why no vendor is going to build the internal context layer your security team needs. We also talk open weight models vs paying for tokens, whether the government had this tech first, and why human life still comes before technology.

Chapters
00:00 Ashish is back on Security Unfiltered
02:40 Joe's dissertation: zero trust for satellites and post-quantum crypto
06:36 Ashish's new book, AI Security Engineering
07:07 Ashish's path: IAM, cloud security, Cloud Security Podcast
08:26 From media company to AI advisory and the AI Security Lab
10:19 Local compute, open weight models, Grok vs Claude
13:35 Build harnesses you can swap out
14:34 How do you write a book on a topic that changes every month?
19:05 When research gets published faster than you can cite it
20:54 Why network security is back in the conversation
21:23 Agents breaking out of a sandbox
22:57 Is the government already ahead on AI?
23:54 The Manhattan Project comparison
25:13 How cyber warfare teams test exploits
26:41 Security for AI is a new field
28:16 Human life over technology: Waymo and surgical robots
29:58 Which agent security capabilities actually work?
31:40 Make the agent explain why it pulled 10 records
32:50 Behavior and intent over logs
35:12 The internal context layer no vendor will build
38:47 Logging is legacy at AI speed
40:20 Horses vs cars: who gets left behind with AI
42:17 Wrap up

Ashish Rajan on LinkedIn: https://www.linkedin.com/in/ashishrajan/
AI Security Engineering (Wiley): https://www.amazon.com/dp/1394387687
TechRiot: https://techriot.io
Cloud Security Podcast: https://www.cloudsecuritypodcast.tv

Subscribe: https://www.youtube.com/@securityunfilteredpodcast
Show site: https://www.securityunfiltered.com
X: @SecUnfPodcast

Affiliates
➡️ OffGrid Faraday Bags: https://offgrid.co/?ref=gabzvajh
➡️ OffGrid Coupon Code: JOE

➡️ Unplugged Phone: https://unplugged.com/
Unplugged's UP Phone - The performance you expect, with the privacy you deserve. Meet the alternative. Use Code UNFILTERED at checkout

*See terms and conditions at affiliated webpages. Offers are subject to change. These are affiliated/paid promotions.

Tesla Referral Code: https://ts.la/joseph675128

Follow the Podcast on Social Media!

Instagram: https://www.instagram.com/secunfpodcast/
Twitter: https://twitter.com/SecUnfPodcast
Ashish Rajan, security unfiltered, joe south, AI Security Engineering, ai security,