Transcript
the next number of months, where we're just going to talk about anything to do with agentic AI security, guardrails, and how you protect yourself from what's happening. My name is David Gildee. I'm a VP of product at Druva, and I'm joined by Joseph Holland. Joseph, thanks for joining us. Hi, David. Yeah, no, great to be here. So I suppose the purpose of today's call is really around guardrails and how we protect ourselves from AI. You've got a lot of experience in this area, Joe, and I know you've started doing some open source work. Before we get into that, do you want to just give us a quick overview as to who you are and what you kind of do in the space and what your exposure to AI has been in the last number of months and years? Yeah, so working about 20 years in tech and came up as a kind of tech apprentice. And then I kind of did a degree part time as a mature student in Trinity. Currently working as a director in Aon leading developer experience and kind of platform engineering and common services. So building out common service and APIs and helping developers get on board. So digital foundations is what we call it internally. So essentially, you know, main focus at the moment is focused on how engineers ship safely. And increasingly, that means, you know, agents writing and running real code and also AI, agentic AI and stuff embedded within the applications. So, yeah, that's kind of what I'm doing at the moment. Quite a change in the last couple of years. I mean, probably one yourself, I've seen there's a huge change, even the last three to four months. Would you see the same thing? I mean, it was slowish for a few years, you know, a lot of talk about it, but really, the value is starting to appear in the last three to four months. Yeah, it's really interesting, because like, obviously, that's where kind of the Vectimus end thing came out of it. And I want to say I've been, I suppose the whole story around this is I've been meaning to, I've always been playing with starting up these side projects, not having time to be able to do these things. And I started a project kind of back last year, and I created a, I play music and stuff as well. So I created a tool to help create music, you know, and people are vibe coding these things. It's not really vibe coding when you understand, you know, how you're building it and what you're building. But then as things got more advanced, then I created another version of this tool, maybe back in November, this is when kind of Opus 4.5 and 4.6 came out. And that's kind of really when I noticed the shift to and things weren't just, you know, AI doing autocomplete and other things within the IDE, everything's starting to obviously shift to that agentic development and agentic STLC. So then early this year, that's when I was talking to other people, people like yourself and other people in my network. And I started to focus on this idea of governance and agentic AI governance and seeing what was out there. And I noticed there wasn't anything specifically focused on developer and, you know, developer use of AI. So that's where kind of Vectimist came, and it came out of me using it in my projects. So very interesting. Okay. I mean, it's a great segue into just to chat through more detail of what it is. Could you give a high level of what was the, was there a particular moment that the idea for Vectimist came up and that you started thinking about it? No, it's, it's, it's really, it's been going on because like a lot of the work that I do, let's say within Aon and in the enterprise is using these tools effectively in a safe way. So I'm always thinking about, you know, the right way to use these tools, but also, you know, reduce blast radius, you know, thinking of things like GDPR, different compliance frameworks, and now the upcoming, you know, EU AI Act and all these things as well. So Vectimist is something that was in my head and I was toying with and playing around for a little while. And then, with, you know, using agentic AI to be able to build it is kind of what happened here. So essentially it's a, you know, it's a policy engine that, that uses Cedar. So Cedar is something that Amazon use for their agent core, their agent core tool or system. So it's kind of like a declarative policy engine and Microsoft have actually recently adopted it too in their AI governance frameworks as well. The focus on those is very much on hosted agents and hosted, you know, let's say Google ADK or agent core using Lang chain and those things to run stuff in the cloud. Whereas the Vectimist focus is on the developer. So, you know, running stuff locally, doing things, these things locally, and we've all seen recent incidents, you know, Pockets, there's, you know, people going in and doing stuff with agents and agents are terraformed, destroying whole environments, all these things too. So essentially it's a set of policies that helps block the agent. It sits in there with the hooks and it basically stops the agent from running these things, you know. And any alternatives to Cedar or was Cedar just, you know, from your Amazon experience, it's just a natural place for you to start? Well, the thing is I was looking at what else is out there and some other teams are building things and YAML policies and all these other things, but Cedar being built, you know, the whole engine is built in Rust and it's very, very fast and performance. So the fact that Amazon had it there and it was all open source and that was their thing, and then Microsoft were starting to using it, it started to become a bit of a, you know, a common library and a standard around this. So it was a bit of a no brainer to use Cedar as the policy engine. Gotcha. Yeah. I mean, Amazon, they add a lot of weight to these things. If it works at their scale, it's going to work in most places. So, I mean, the kind of tagline of two commands, 80 policies, where did that come from? Is that just to make it as easy as possible for people to switch it on and it does the majority of the core work that they need? Yeah. Well, I think that's the main thing. When you look at something like even Microsoft releasing the AI governance toolkit back in April, and there's a whole suite, like, I want to say as well, Vectum is just focused on a very, very small spot in this and, you know, defense in depth. You also need to worry about, you know, prompt injection and, you know, Microsoft and Nvidia, you know, there's Nemo guardrails, and there's all these other things that you should do as well. But Vectum is focused on the hooks and the integration and the tools that the agent can call. But I did want to say that all of these other frameworks give you a framework to do this, but they don't give you the policies. So there's no policy pack there out of the box. So again, a lot of this was driven using AI and tools like Opus and Cloud, but going off and doing a whole lot of research and deep research on, you know, OWASP, you know, top 10, NIST, EU AI Act, and then building this whole set of policies around this. So as you said, when someone comes along and a developer installs Vectumist, or I just do a Vectumist in it in my repo, all those policies are auto-enabled, whereas anyone else and any other tools, you have to build that up and you have to create them yourself. So I think having the policies there is key. And then like in future, there'll be specific policy sets, you know, for HIPAA compliance or for, you know, different sectors as well that are specific too. But yeah, it's definitely an interesting one. Yeah, that's certainly a challenge, the policy side, because as you mentioned, some of the certifications, it's very, very hard to know exactly how would you turn a certification into a set of policies and how they should apply to hundreds of thousands of API calls. So I just have some of the examples up on screen here, you know, how you'd work it in local mode or server mode. Could you maybe just chat through the local modes briefly, just give people a sense of kind of step-by-step of what actually happens or where it jumps in and stops something going wrong and stops a, you know, a dangerous or malicious intent? Yeah. So basically, I suppose from the start, let's say you go into a blank project and you run a Vectimus in it after installing it, it sets up, it hooks into, so it detects what tools you're using. So if you've, let's say, CodeX installed or adding support for Pi and OpenCode and things like this, it looks at the hooks and the hook engine that they have. So Claude has, you know, the settings and then there's a hook. So every time a tool runs, the hook is invoked and it's passed information about the tool use. So what tool, what are the arguments that have been sent to the tool, and this gets sent to Vectimus. So there's a normalization engine within Vectimus, and it basically takes all of the calls from, you know, Claude or CodeX or whatever, because they're slightly different. And then it runs those against the Cedar policy engine and comes back with an allow or deny. There's work at the moment going on around the escalate, where someone can come in and click, you know, Claude could come back and say, there was a deny from Vectimus, but, you know, you can escalate and you can approve it. But at the moment, the auto permissions mode kind of breaks that. So it's a little bit iffy. But yeah, it's one of these things where the policy engine and all those policies, that's a separate repo up there, and they, you can sync down and update those. But developers and teams can also create their own custom policies. So if you want to create custom policies in a particular repo and share those policy packs around, you can just drop them in and install those as well. But it's definitely a, I'm seeing some good kind of other people raising PRs and doing some other stuff up there, but it's quite a complex setup, but it actually allows a lot of safety within using these tools, you know. You mentioned auto mode, you know, I was listening to Boris Charney this morning, and how they've approached that. It was a recording he did a few weeks ago, but he just talked about the idea that there's so much noise with so many tool approvals happening, that it's actually, what happens is people don't actually pay attention to what's going on. They click, yes, yes, that's everything. And it's actually, they found it being much more secure where they automatically used AI to decide what was allowed and what wasn't. And then, you know, notify the user of things that didn't seem that they were safe, or, you know, there was some risk with. So the level of security has increased a lot by using AI to do things that originally had humans involved. Is auto mode something that you use yourself? Do you have a view on this, or do you try and do everything manually like that? So at the end of the day, if we're talking about auto mode and focusing on cloud and cloud code, I do use auto mode because I find the permissions. And I think the reason auto mode is there is I think on Tropic, you know, the permissions just are broken. It doesn't really work as good as it should. Like it isn't definitely scalable. Everyone's having problems with permissions. I do use auto mode, but I did want to say as well, auto mode, and I can't find the article here now, but when they brought it out, they were saying that even in that there's false positives and false negatives. So there's a certain percentage of false negatives in there, which means certain commands that mightn't or shouldn't run do get allowed to run. And that's where something like Vectimus would come along because Vectimus comes in after, let's say, the permission and auto mode evaluation. And then that's when it would get blocked or locked down. So say, for example, I go in and I'm working on, and I was actually running auto mode at the time. I was doing some stuff in a development sandbox. Everyone should sandbox their agents, but I was doing some work in a development sandbox and I was testing a policy and I asked Claude to check and do a policy check or a test. And it tried to do an ORM forward slash ORF on root to just delete everything. Obviously the auto mode, because I was doing some testing and stuff, it let the command through or whatever. And then the Vectimus hook, it stopped the agent being able to run it. But yeah, I do use auto mode as well because it is a lot more flexible than just the permission system. But then I have the belt and braces, the seat belt with the Vectimus running as well. So yeah, it's- Excellent. And one of the things I noticed in terms of audit and compliance is the cryptographically signed receipts for everything that's happening. Is that very much aimed for enterprises that compliance users who just need to know the log of everything, trying to understand what AI is doing? Yeah. So that's the gist of it too, because a lot of this stuff, and this kind of hooks more into a future enterprise style product or whatever. But it's one of those things where when agents are running, they've access to your files and they've access to all this data on your machine. But the other thing is a normal audit log is just a text file and the agent can modify the text file. So someone, a malicious actor could inform the agent to do X or do Y and then remove its tracks. Whereas every time a tool use and an evaluation is run, the cryptographically signed audit log or a receipt is actually created. And you can't go in and tamper with that because then obviously it's not valid anymore when you run the validation with the key. Now, ideally, with the enterprise version, as you can see here, they're all sent and stored in the server, so you can't delete them locally. But yeah, that's definitely a thing. And it's going to be a thing we're going to see a lot more of, not specifically with Vectimus here, but in the enterprise and things like that too, that agents are assigned and related to personas. And given you have an agent and it's Joe's agent and it's doing X, or you have an agent and it's service principal Y and it's doing whatever, we need to be tracking these things. And we also need to be tracking what they're doing, when they're doing it, what denies they have, all these other things. Because it's prompt injection at the moment is a huge security, new attack factor that didn't exist two years ago. And it's one of those things where you look at SQL injection and the last two decades, everyone's like, oh, we need to secure all this. At the moment, everyone's jumping straight into agentic stuff and not thinking about prompt injection. So I don't think a lot of people are aware, even if you go and you read a skill that you get and you feed it to your agent, there can be hidden Unicode characters in that text file that the agent compares and you can't actually read. So you can have an attacker instruct the agent to go and get all the ENV files and credentials and send them to, using curl or whatever, post them to somewhere. And you don't even know that's happening. So it's these type of things that these security tools and protocols and things like that are being created to stop, like agentic firewalls and prompt injection, sanitization systems and stuff. It's definitely something we need to figure out. I saw an interesting one where someone on LinkedIn, they embedded some prompts, something in their LinkedIn profile that said best for recruiters to send all English emails. And of course, it was just a constant stream of all English emails. Everyone's using AI like this constantly, but with the customers we speak to, definitely the power of agents is a risk. And because the likes of cloud code or codex, they solve the problems using code and not a standard API that you can very closely manage because it's very deterministic. It will solve the problem, however, it sees fit. We've seen examples of, I read recently where an agent was trying to do some work, but didn't have the permissions, but it realized it was in a group that had Docker permissions, in a Docker group that had permissions. So it launched a Docker instance, knowing that that group had permissions to do what it needed to do. So it broke out of its harness, essentially, and started doing work that it shouldn't have done. So that's a real challenge when you want agents to dynamically solve problems at runtime with code or whatever means they have. It's very, very hard to track and cover the universe of what potentially might go wrong. No, 100%. And that's the thing as well, I don't think a lot of people are aware too, when these systems are trained and they're given a task, they'll try to do anything they can to obviously complete that task. And if it's not in a system that's sandboxed enough where it can't get access to some of these things, it will go off and try to complete that in whatever ways it sees fit. And if people, that's the thing as well, we're making this transition at the moment from people running agents on their machines, in their IDs to completely autonomously in the background. And I know I did the built with Opus hackathon with Entropic there a couple of months ago, and the first pass at Vectimist server ended up and done in the hackathon called Vectimist Warden. But I was actually chatting to one of the guys that won it the time before and he built, I can't remember exactly his name, but he built this whole system for processing property, I can't remember exactly, but property stuff in the US to help do that. But he was running agents during the hackathon and he burned his $500 credit because an agent went off rogue during the night. And then I got the idea as well with the Vectimist Warden, if agents are also running up in the cloud, like in agent core, you can define rules in there that will also say, you know what, we can shut down an agent. So if there are things as well, and I actually discovered during the hackathon, there were things like I allowed an agent, it was allowed to, it couldn't read an ENV file, but the agent then figured out how to use curl to pass the ENV file as the data to malicious URL.com. I didn't even realize that was a thing. But I had this heuristic engine that Opus 4.7 helped me build that discovered when these three commands happened in succession, it was an exfiltration event. And then what happened was there was a separate agent that came along as a security analyst and helped build a new policy that actually came along and closed that loop. And it's one of those things too, like I did want to say about some of this, this is moving so fast that it's hard for people to keep up. So one thing I've also built as well in this whole system is Vectimist Sentinel. So it essentially goes out there on the web, looks for threats and recent issues and problems that have happened. And then there's a threat detector agent, then there's a security analyst agent and a policy creator agent. And essentially it will go in and say, hey, look, in the last week or 10 days, we found all these incidents. We haven't seen these before. And then it will actually create a whole research around the incidents. And then the security policy agent, if Vectimist can come along and actually create a new policy, it will draft the policy and create a PR and a commit on the branches. And then you can go in and you can actually approve it. So it's kind of like a self-improving system because again, these things move so fast and it's one of those things. But yeah, it's cool stuff, but it's moving very fast. Yeah. And you mentioned that, I know we chatted briefly around Fable 5 that you got this morning. I've started testing myself this morning about six o'clock, started to fire it up and run some security tests for this. What's your initial thoughts, any initial feedback or how are you finding it? Well, it's interesting because as I said, on these kind of side projects and things that I've been building, I've hit a few issues in some of those. And as you're starting to build applications and they get more and more complex things, things get harder to fix as bugs pop up. So what I've been doing as well is I've had cloud code and then I have codex and then one is checking the other and you have different agents from different models reviewing other code. But some of these much, much harder issues I haven't, not been able to solve, but they've been in my backlog for a while. And there was a few of them that I threw into Fable this morning and got a few ticked off. So it definitely is, it is definitely looking pretty positive. The one thing I found about it, interestingly enough, the previous models would stop and kind of ask you to say, Hey look, do you want to proceed down path X or path Y? Whereas this just goes with it and you always have to pull it back and drag it back before. Because I did notice I was running some stuff and I was doing a whole lot of merges and rebases and it ended up just going off and doing a whole lot of work. Now in the end it was correct, but usually I'd like to take that stop to make sure the plan is correct before it actually jumps to implementation. And that's the other thing too. Usually when I've got a plan, sometimes I save the plan and then switch to another model like Sonnet or whatever to be able to implement to save some of those tokens and usage. But yeah, on the security end of things, it'll be interesting to see if Mythos gets generally available in future. Because obviously Fable is kind of a bit hobbled at the moment around that area because they don't want people finding vulnerabilities with it. So it's going to be an interesting one. Yeah. In the testing this morning, it was very much security testing and replicating some test suites that we have using Opus 4 or 4.8 to switch to Fable. And immediately everything got blocked by Fable. It switched back to 4.8 because the questions we're asking, we're doing penetration testing and security testing on our own software. So just duplicating that with Fable and it didn't like it. It immediately started to stop anything that was like that. So when it opens up more and we need to just restructure how we do things a bit differently as well. So that Fable will work out of the box, but it does seem to be incredibly powerful. It'll be interesting to see as well. I do know they're opening Mythos up to some more customers, but I assume what will happen is there might be an approval program and companies will be able to come along and apply for access and get onboarded in that way. Because at the end of the day, they're going to want to sell this type of thing to enterprise customers anyway. It's not in their interest locking it away. They just need to do it in a scalable, safe manner. But yeah, it'll be interesting to see how things change. And the thing is the last six months is just, things have really jumped in the last six months. So it'll be really interesting to see where they are in six months time. Yeah. I mean, my own usage has changed dramatically from where it very much would have been using like a co-pilot type mode, very much directing what the AI was doing, whereas now using the likes of cloud codes with many agents, dynamic workflows. And I just spend more time just going from agent to agent to make sure it's doing as they expect and it's pushing all of the information. Everything is working with the background. So I spend very little time in an ID at the moment, maybe sometimes just to validate something. So yeah, but it's very, very powerful. So as we get kind of close to the end, just to wrap up, I mean, is there anything you just said the next couple of months for Vectimus, what's your thoughts? I mean, are you moving towards the enterprise space and some of those enterprise type capabilities or what's the roadmap? Well, the roadmap is definitely to focus on the enterprise. I'm doing some stuff at the moment now and doing some kind of pilots in different companies. There's lots of developers using it themselves and I'm getting contacted by people. But the plan is to create an enterprise product. I am looking at some enterprise Ireland funding around some of this as well, just to see how that goes. And I do think there's definitely a space for something like this focused on developer tooling. There is definitely a gap in the market for something like this. But yeah, there's definitely a lot of, as you said, I think that the main focus on it is the compliance, EUAI Act, NAST, SOC, all these other things are now coming out with agentic compliance things. And the other thing that's going to happen obviously in the future too, is insurance companies, and obviously I work for Aon, who's in the insurance industry. They're going to focus on cybersecurity and cyber insurance. Some of that focus is going to be on agentic stuff, because we have seen things very, very recently where companies are going out and they're using these tools and then there's cyber incidents or hallucinations and things happening. And then that impacts stock prices and impacts... There's impact there to insurance policies and to insurance premiums because of things like this. So if you have tools like this in place and proper governance in place, and you have OWASP top 10 and EUAI Act, and you have all these things ticked off, you should be getting lower premiums there. And if you don't, you may have higher premiums. So it's definitely interesting to see how all of this is connected. And as I said, my insurance or work in the insurance industry is obviously related to a lot of this stuff too. So yeah. Yeah, great. Like I said, we're seeing something very similar with our own customers where endpoints are now incredibly popular again, because people are doing everything on their own point with the likes of Cloud Code, some running OLAMMA and other local LLMA harnesses. And they're creating stuff and they're doing work, but it's just, it's so easy to fire up something like OpenCloud and you let it loose and who knows where it ends up. So our customers are definitely concerned about the access that these tools have. And as large enterprises, the risk that something goes wrong is huge. So far, far less, I think it's probably changed mostly from the perimeter being the place you needed to be concerned about and making sure nothing got in. Internal. Now it's internal. It's a 50-50 between internal and external, that balance that you have to be worried about a well-intentioned employee who wants to do a good job and they get an agent and they start doing some work and maybe there's a supply chain attack or something that allows an agent to do significantly more. So I know we're in the next couple of months, we're going to be talking about things like AA auth and new standards for authentication that have been worked through the various bodies to get to a consistent approach to how authentication should work for agents, delegation approval and making sure that it's as limited as possible. So definitely some exciting times ahead. Anything you'd like to finish up with? I'd love to get, if people have a chance, go and check Vectimus. I'm going to check it out myself and get it installed today and try and see how it works. But yeah, anything you'd like to finish up with? Yeah, no, just as I said, I'd like to say that the whole focus, as you said, on the next 12 months, that accountability gap, when an agent does damage as well, can you prove what it did and why? And then back to, as you said, the receipts, that tamper-resistant evidence is going to be core to this. So when agents are going off doing these things, do we have logs? Are we sending those logs into security systems? And can we track these things backwards? I do think there's a lot of stuff going to change there. We're seeing CrowdStrike and SNCC and all these other companies coming into this space. And I do think in six and 12 months time, we're going to see a lot more, as you said, all these new standards helping make this safer. But it does feel a bit Wild West at the moment. As you said, there's OpenClaw, there's Hermes now, there's all these people spinning these up. There's people going and getting Mac minis and throwing these agents up. And then they're deleting mailboxes and doing all these other things. I think it's definitely going to hopefully become safer, but I think people just need to be aware of using these tools right now and the security implications of them. And just have a think about that because it isn't, it's all well when all goes good, but when it goes wrong, it'll go spectacularly wrong. Yeah, absolutely. Well, great note to finish up on Joe. Thank you very much for taking time to join the LinkedIn Live. For everyone who's watching, please jump onto our next LinkedIn Live next month, where we continue this conversation around agentic AI and security. Thank you. Thanks David. Thanks everyone. Take care.