Transcript
hey, I want you to go do this for me, from an outcome perspective. This is where that guardrails concept comes in, right? Because a lot of times people just say, hey, go do this for me, but they don't specify like, well, here's kind of how I want you to go do that. And a normal, even if it was like an intern or somebody you hired, they would kind of, you know, before they do certain things, they check in with you and they'd be like, hey, I'm about to go do this thing. Is that okay? Is that aligned with policy, right? And so that's the part where I don't think yet as an industry or even as the world, or even as the AI vendors, we've really figured out what is, how do we actually tell an agent like, please go try to do this thing, but only do it kind of according to this or according to the company's policies, or hey, check in with me before you go do that thing. And I think we're just at the early stages of that. So tying that back to your question about like autonomous identity creation, I think most security people would say, well, that should never happen. But the challenge is now, especially if you think of an attacker, like they actually wanna create new identities, right? As part of that, because it makes it difficult to track, you know, the subsequent activity by each identity. And so I think we're still at the very early innings of what that means. But I think if you look at some of the very, very kind of bleeding edge, cutting edge research that people are doing with swarms of agents, those agents are gonna create their own sub agents that do all kinds of things. And so just like with drones, you know, how it started off, we have one drone and now we have, you know, swarms of drones, same thing with AI, right? It's gonna be to the point where you can't kind of point to each thing and create a policy for it. It's gonna have to be software that goes in and kind of really sets those policies in guardrails.