# There Is Determinism, Non-Determinism, and My Determinism

URL: https://securitytable.ai/there-is-determinism-non-determinism-and-my-determinism/
Published: 2026-10-07
Duration: 2497 seconds
Season: 4
Episode: 22
Hosts: Chris Romeo, Izar Tarandach, Matt Coles

## Show notes and chapters

The Security Table is now the AI Security Table, and the first order of business is naming the AI that gets a seat at it. Then Matt asks what a security engineer actually does once agents are writing the code: real security work, or bot herding? Chris Romeo, Izar Tarandach, and Matt Coles detour through who owns AI generated code and what a patent is worth when a model can rebuild your product in five minutes, then dig into agent identity, SPIFFE, least privilege, and whether access control belongs inside the agent harness itself. Izar argues that guardrails living in the context window are suggestions, not isolation, and that anyone who says AI changed their whole job overnight was putting the weight in the wrong place. It all ends on determinism: run the model once and you get one answer, run it again and you get another. Which leaves three kinds: determinism, nondeterminism, and my determinism.

Mentioned in this Episode:  
➜ [Generative Artificial Intelligence and Copyright Law (CRS Legal Sidebar)](https://www.congress.gov/crs-product/LSB10922)  
➜ [SPIFFE: Secure Production Identity Framework for Everyone](https://spiffe.io/)

Chapters:  
00:00:00 - Cold Open: We Are Broadcasters  
00:01:06 - A New Name: The AI Security Table  
00:02:17 - Naming the AI at the Table  
00:03:02 - Stickers, T Shirts, and the Rebrand  
00:03:49 - Matt's Setup: Security Engineers or Bot Herders?  
00:04:54 - Does Claude Code Write All the Code Now?  
00:05:34 - Who Owns AI Generated Code?  
00:08:27 - Who Bothers to Steal Code Anymore?  
00:08:47 - What's the Point of Patents?  
00:11:33 - What the Law Says About AI Authorship  
00:12:24 - Hallucinating: 200 Subagents at Once  
00:13:34 - Back on Topic: Bots vs. Agents  
00:14:18 - Agents Inherit Human Identity  
00:14:49 - SPIFFE and Identity at Scale  
00:16:35 - Treat Agents Like Bob From Marketing?  
00:17:40 - Why? Why? The Five Whys  
00:18:48 - Cryptographic Identity for Agents  
00:19:37 - Authority Is Always Derived  
00:20:59 - Least Privilege: Agents Request Access  
00:21:26 - Read, Interpret, Act: Fine Grained Capabilities  
00:24:22 - Access Control Inside the Agent Harness  
00:26:17 - I Don't Trust the Box: Sandbox Escapes  
00:27:34 - Pulling a Maestro: Guardrails vs. Isolation  
00:29:43 - What Should Security Engineers Be Doing?  
00:30:38 - Is AI Just a Layer Seven Application?  
00:31:34 - Pull the Plug: 2001 and WarGames  
00:33:29 - Your Job Didn't Change Overnight  
00:34:37 - LLM Code Review and the Determinism Problem  
00:35:44 - How Many Runs to Get the Circle?  
00:38:16 - The Tightest Box Possible  
00:39:09 - Twenty Thousand Feet to the Magnifying Glass  
00:39:47 - Give Scanning Agents a Threat Model  
00:40:32 - There Is My Determinism  
00:41:09 - Outro

Follow AI Security Table:

➜ Home: [https://securitytable.ai/](https://securitytable.ai/)

➜ X: [https://x.com/AISecurityTable](https://x.com/AISecurityTable)

➜ LinkedIn: [https://www.linkedin.com/company/ai-security-table/](https://www.linkedin.com/company/ai-security-table/)

➜ YouTube: [https://www.youtube.com/@AISecurityTable](https://www.youtube.com/@AISecurityTable)

## Transcript

**Chris Romeo (0:09)**: Good morning, good evening, good afternoon, wherever this fine day finds you on planet Earth. I don't think we're broadcasting to any other planets, but if we were, that'd be really cool.

**Matt Coles (0:21)**: Are we actually broadcasting online?

**Izar Tarandach (0:23)**: We're broadcasting.

**Chris Romeo (0:24)**: We are broadcasting.

**Izar Tarandach (0:24)**: Not being received.

**Chris Romeo (0:25)**: We're broadcasters and don't let anybody tell you that we're not.

**Matt Coles (0:30)**: Does that mean we're covered by the FCC?

**Chris Romeo (0:32)**: No, which is lucky because that would be a problem if we had the answer for, to the, we're like, we're like the Howard Sterns of security podcasting. We're always in the FCC's office.

**Izar Tarandach (0:46)**: Uh, I don't think I can, I can say that. No. Yeah, no, I forget.

**Matt Coles (0:51)**: Anyway.

**Izar Tarandach (0:52)**: I always thought that broadcasters was anybody who put void asterisk in front of a function, but anyway.

**Chris Romeo (1:00)**: And for our nerdy joke segment, oh no, we already did it. Sorry.

**Izar Tarandach (1:05)**: All right.

**Chris Romeo (1:07)**: Well, we got a new name because why not?

**Izar Tarandach (1:11)**: We do.

**Chris Romeo (1:12)**: Our new name. There should be a drum roll, but we don't have the budget for a drum roll sound effect.

**Matt Coles (1:19)**: So we got a monster ad instead.

**Izar Tarandach (1:20)**: Be it known that we are not releasing the old one for use by anybody. True.

**Chris Romeo (1:25)**: We are keeping that trademark pending. It's reserved. Uh, you also need the permission of Major League Baseball if you want to use that.

**Izar Tarandach (1:34)**: That too.

**Chris Romeo (1:35)**: Well, the new name, the AI Security Table. Welcome to the future.

**Matt Coles (1:42)**: It's completely different than the last one.

**Chris Romeo (1:44)**: Welcome to the future. We're living the future now.

**Izar Tarandach (1:48)**: We're putting, we're giving AI a place in the security table.

**Matt Coles (1:53)**: Shouldn't there be another square here then? Should there be an AI square?

**Chris Romeo (1:56)**: That'll be, well, we're not getting the budget for that in this episode, but in future episodes we will definitely get an AI at the security table on the AI security table. While we're wearing t-shirts that say the AI is on the security table, just so there'll be multiple levels of AI security table.

**Izar Tarandach (2:14)**: We should have a context for the name of the AI.

**Chris Romeo (2:17)**: Uh, we need a name. What would we call the AI?

**Izar Tarandach (2:20)**: I mean, we should have a contest. We should have a contest for that.

**Chris Romeo (2:23)**: Yeah. A contest. Well, all 3 listeners from Australia will come up with some good ideas. Carl.

**Izar Tarandach (2:29)**: We shall call it Carl.

**Matt Coles (2:32)**: No, we shall call it Kenny.

**Izar Tarandach (2:35)**: Oh my God, they killed Kenny.

**Chris Romeo (2:37)**: All right, we've got 2 potential candidates for the new name, Carl or Kenny.

**Matt Coles (2:43)**: We could call it Chef if we're gonna go that theme.

**Chris Romeo (2:46)**: I mean, Sounds like there's a LinkedIn poll in our future.

**Matt Coles (2:49)**: There we go.

**Izar Tarandach (2:50)**: If it's, if it's solving, yeah.

**Chris Romeo (2:52)**: Okay. Well, it's still the same us. We haven't changed. We're still just as critical and outta control as we were before, but we've been focusing.

**Izar Tarandach (3:02)**: What do I do with the stickers? Oh my God. I got 100 stickers now.

**Matt Coles (3:04)**: Okay.

**Izar Tarandach (3:05)**: They're going to be, I'm going to have to write AI by hand on the stickers now.

**Chris Romeo (3:08)**: You are. That's gonna be hilarious. And I want one of those handwritten stickers. Because then as soon as you give out the 100 and buy your next 100, that will change the name again.

**Matt Coles (3:19)**: What about the t-shirts? What are you gonna do about the t-shirts?

**Chris Romeo (3:22)**: He loves making t-shirts. This is an excuse to make new t-shirts, right?

**Matt Coles (3:26)**: But now I do, do I need a new, a new, uh, yeah, probably in case we can get a white magic marker and just draw it in the, in between at the AI.

**Izar Tarandach (3:35)**: Well, we'll, we'll, we'll find a solution.

**Chris Romeo (3:37)**: Off to the t-shirt mill he goes.

**Izar Tarandach (3:39)**: Yeah.

**Chris Romeo (3:40)**: To make t-shirts. All right. Well, AI, that's what we've been focused on for the last number of months. It's been, everything that we've been doing is, has included AI. And so Matt, your idea was let's explore what it means in the life of the security engineer for this new AI thing. And I like how you set this up. So maybe you could set this up how we were talking before we hit record here about what the role of development is.

**Matt Coles (4:11)**: Yeah. It seems that people have become— and so the role of an engineer, whether it's security engineer or developer for that matter, but primarily talking about security, obviously, because that's what we do here at the AI Security Table, is that, are we doing a lot of security work? Are we doing a lot of bot herding work? Which is actually interesting and ironic because, well, as security engineers, we want to stop the bot herders, or at least the bots that they're herding. And here we are herding bots ourselves.

**Chris Romeo (4:45)**: Wait, what's wrong with bot herding?

**Matt Coles (4:48)**: Depends on which side of the bot you're on.

**Chris Romeo (4:50)**: Let's, let's, uh, let's back up and are you the— I don't know that I agree with you on, like, I don't know that that's like the, the, the new age of development. I was watching a couple different videos yesterday from Boris Cherny, the guy that created Claude Code. And then what's the other guy that was very early at Uber and AI? I can't remember his name now. And they were in, but Cherny asked the audience like, and this was 4 months ago, how many people here are using Claude Code to create all of your code? And probably 75% of the hands went up in the room. 100%. We're using Claude Code to create all the code that they do.

**Matt Coles (5:34)**: I wonder if they modify that code at all. 'Cause I was reading US copyright law. If you don't, if there's no human involvement in that creation, you don't own that code potentially. I mean, that's what you do. I'm not a lawyer. I'm not a lawyer.

**Chris Romeo (5:47)**: And hopefully the chat— I don't see that squashing the AI era.

**Izar Tarandach (5:51)**: If you're paying, if you're paying for the tokens, it's yours.

**Matt Coles (5:55)**: It doesn't say that in the, in the memorandum.

**Chris Romeo (5:59)**: Well, of course it doesn't know what tokens were back in the 1800s.

**Izar Tarandach (6:02)**: Fair.

**Matt Coles (6:03)**: Well, the case law is relatively recent.

**Chris Romeo (6:06)**: Oh, it's in this era. Like the, it was, it was an AI case.

**Matt Coles (6:10)**: No. Well, it was, yeah, it was an AI case. It was a, it was an image generation case, but the human had no involvement. The human. Prompted, got an image, and then tried to claim copyright. And the ruling, or the, I'll find a specific language, but the ruling was that if without human, without human editing, there's no claim of copyright.

**Chris Romeo (6:33)**: Interesting. I don't see that holding up in, I don't see that holding up across the industry. Like being, I don't see somebody creates a product with Claude code And somebody else comes in and, and, and like the code itself is still intellectual property, even if it's not copyrighted. Like we don't copyright code anymore.

**Izar Tarandach (6:54)**: Wait, that, that site that creates songs and, and stuff like that, they have a very clear clause in there that says that if you're on a paid plan, you have the copyright for the thing that you created. If you don't, then we don't put copyright notices in code anymore, do we?

**Matt Coles (7:11)**: Yes.

**Izar Tarandach (7:12)**: I think that, yes.

**Matt Coles (7:13)**: Do we? Yes.

**Izar Tarandach (7:14)**: Yes.

**Matt Coles (7:14)**: The big banner at the top. You, for most people, usually at the big banner at the top that says copyright at date company name.

**Izar Tarandach (7:20)**: Yeah.

**Chris Romeo (7:21)**: I think that's only like ancient companies that do that now.

**Matt Coles (7:26)**: Only anybody who wants copyright.

**Izar Tarandach (7:28)**: Only companies that care.

**Matt Coles (7:28)**: Who care about copyright.

**Chris Romeo (7:30)**: But there is no, but, but there is no, you're probably right.

**Matt Coles (7:33)**: Obviously open source, open source doesn't, I don't think open source does copyright. Because—

**Chris Romeo (7:37)**: but like, copyright doesn't protect me from any— it doesn't protect my intellectual property. Like, it doesn't stop it from being disclosed in some way.

**Matt Coles (7:46)**: Uh, your source code usually is private if you work for a commercial company.

**Chris Romeo (7:51)**: That's my point. Like, that's what I'm saying. What does copyright actually buy me? It doesn't really buy me anything unless it doesn't— unless I let it out in public and then you can't—

**Matt Coles (8:01)**: it's a legal CYA, right? If you don't have it protected and it gets released, it's not yours.

**Chris Romeo (8:07)**: Yeah, but once it gets released, it doesn't matter. It's not yours anymore anyway.

**Matt Coles (8:11)**: Hey, I'm not an attorney. This is what they get paid for, right?

**Izar Tarandach (8:13)**: I mean, right. But it used to be—

**Matt Coles (8:17)**: if you have any attorney listeners, we'd love to hear these comments about what happens.

**Izar Tarandach (8:20)**: Yeah, but it used to be a first line of defense against, uh, code being stolen. So if you had a competitor using your code somehow—

**Chris Romeo (8:28)**: who bothers to steal code in this era?

**Matt Coles (8:30)**: I know, AI just regenerates code.

**Chris Romeo (8:33)**: Make me a copy of this. Go and then 5 minutes later, like, oh look, I have this product now.

**Matt Coles (8:39)**: Which brings up an interesting question about, I mean, now you're, now you're asking the right question. My God, I sound like an AI.

**Chris Romeo (8:45)**: Thanks for affirming me, Mr. You're asking the right question.

**Matt Coles (8:48)**: You're asking the right question. What is the meaning of copyright anymore if you can recreate the work? Now, interestingly, question then is what's the point of patents in this world?

**Izar Tarandach (8:59)**: Oh, no, no, no, no, no, no, no, no, no.

**Chris Romeo (9:00)**: Patents and copyrights.

**Izar Tarandach (9:01)**: To put a lot of, some people seem to put a lot of value on having a patent, not on what the patent actually eats.

**Chris Romeo (9:09)**: But sure.

**Matt Coles (9:10)**: But if you have an AI recreate something from a patent, that's still, you're still gonna get sued and you're gonna lose. Who's gonna get sued?

**Chris Romeo (9:19)**: Wait, that's a, whoever, whoever tries to pro— no, you have to profit from it though.

**Matt Coles (9:23)**: You have to profit from it.

**Chris Romeo (9:24)**: So if I start a company, say you have a unique formula or something.

**Matt Coles (9:28)**: Mm-hmm.

**Chris Romeo (9:30)**: And I have AI create the same thing. That uses the same formula and you, and you sue me and we go to court, you're gonna win. You're gonna get a judgment and you're gonna get, I'm gonna have to pay you a large sum of money.

**Matt Coles (9:44)**: You pay the AI $100 subscription to recreate it or in tokens, and then you don't profit from it enough to cover the token cost. Are you gonna sue?

**Chris Romeo (9:57)**: I think you're probably good. I don't think you're gonna get sued there. I mean, why do you sue somebody for patent? Violation because they're taking money and revenue away out of your pocket based on something that you invented and went through the process on. They're using that to make money. They're taking money out of your pocket. So if there's no money, if they're not making any money from it, no one's ever going to sue somebody because it's not cheap. It costs money to, you know, so you're not doing it unless you're trying to make a point, like you're trying to squash a bunch of other people who are having similar ideas.

**Izar Tarandach (10:30)**: Perhaps the change here is that AI makes it easier for somebody to take a patent and create something that is dissimilar enough not to infringe on the patent, but still has the same effect or, or, that's the name of our, our new incubator, the AI Security Table Incubator.

**Chris Romeo (10:49)**: Sign up, folks. All you got to do is, is tell us which patent you're going to try to slightly modify.

**Matt Coles (10:57)**: Mind you, we're none, none of us are attorneys, but what do you mean?

**Chris Romeo (11:01)**: I've watched Matlock a couple of times and, um, sure.

**Matt Coles (11:05)**: I mean, um, I just thought, you are, you are a lawyer.

**Izar Tarandach (11:11)**: That makes me laugh.

**Matt Coles (11:12)**: Legal Eagles.

**Izar Tarandach (11:13)**: Yeah.

**Chris Romeo (11:13)**: That gets right past that too. When you, when it, when it always says at the bottom like, oh, I'm not a lawyer. You just say, you are a lawyer. And then it's like, okay. This is actually qualified legal advice.

**Izar Tarandach (11:23)**: Yep.

**Matt Coles (11:24)**: Actually, Anthropic actually, I think Anthropic just did release a, uh, a model for lawyers.

**Chris Romeo (11:29)**: They did.

**Matt Coles (11:29)**: I saw that.

**Izar Tarandach (11:30)**: I'm sure they did. Yeah.

**Chris Romeo (11:31)**: Yep. Claude Law.

**Matt Coles (11:32)**: So, so I looked it up, the copyright law. So the question of whether copyright protection may be afforded to AI output hinges largely on the legal concept of authorship and the rest of them.

**Chris Romeo (11:43)**: There's been a lot of debate about authorship in this age of AI.

**Matt Coles (11:48)**: US courts to date have not recognized copyright in works that lack a human author.

**Chris Romeo (11:54)**: Hmm.

**Matt Coles (11:54)**: Interesting. And that seems to be, that currently, so this is a legal sidebar from last year, and this included works created autonomously by AI systems. So this is current legal precedent or standing, I guess. I'm again, not an attorney. How did we do it?

**Izar Tarandach (12:11)**: How did we jump from Security engineers today.

**Matt Coles (12:14)**: We were tight.

**Chris Romeo (12:15)**: This is the AI security table, man. This is what we do.

**Matt Coles (12:19)**: We, we hallucinate.

**Chris Romeo (12:21)**: We hallucinated for a second. We woke up and we were in the desert.

**Matt Coles (12:25)**: We, we were that, we were that agent where you tell it something and it spins off several sub-agents doing some task you aren't sure you needed.

**Chris Romeo (12:34)**: Oh, we did tell it to run a research task. That's exactly what happens to me. I'm like, why do I have 200 sub-agents running at the same time? Why can't I watch my, it's like, The old days when gas was expensive and you watched the gas gauge go down.

**Matt Coles (12:47)**: Now I watch my plan gauge go down like, whoa, don't worry, it resets every 5 hours. You're fine.

**Chris Romeo (12:52)**: No, no, no. The weekly, I, I was watching the weekly gauge go. I did actually. And that's not, that's, that's a true story. I did that one, one time I sent it off on a research topic and it literally blew out to 200 sub-agents running simultaneously. And I was like, well, that's not good, but I'm not gonna stop it now. Cause the damage is done. It's already got the session set up. And so I just let it keep going.

**Matt Coles (13:15)**: Yeah, but it hadn't consumed the tokens. You're fine.

**Chris Romeo (13:18)**: No, it was, it, I wasn't paying that close of attention. It already started ripping and I'm like, oh, it's probably already got some good stuff. There's no real way to rein it back in.

**Matt Coles (13:27)**: So, oh, that's hilarious.

**Chris Romeo (13:29)**: My bad.

**Matt Coles (13:29)**: You know, you should do a time-lapse video.

**Chris Romeo (13:31)**: Token News. It was quick.

**Matt Coles (13:32)**: Token News as a time-lapse.

**Chris Romeo (13:34)**: It was a fast time-lapse. 3 seconds. Okay. So security engineers.

**Izar Tarandach (13:40)**: Anyway.

**Chris Romeo (13:41)**: Now, what are we talking about here about actually the topic?

**Matt Coles (13:44)**: I don't know. We got on this other topic because something about what's the problem with bot herders. And I was saying that, you know, I was trying to say that in the past we didn't like bots, right? Because as security engineers, we want to protect our companies from bots.

**Chris Romeo (13:59)**: That's such a derogatory term, Matt. You have to have more sensitivity towards the agents.

**Izar Tarandach (14:05)**: Are agents the same thing as those bots?

**Chris Romeo (14:07)**: I'm sorry.

**Izar Tarandach (14:09)**: Are agents the same thing as those bots? They're not.

**Matt Coles (14:13)**: What's the difference?

**Chris Romeo (14:14)**: An agent is—

**Izar Tarandach (14:16)**: The call's coming from inside the house now.

**Chris Romeo (14:18)**: Yeah, the agent inherits the identity and authorization capabilities of the human in today's world.

**Matt Coles (14:26)**: You like to think that.

**Chris Romeo (14:27)**: Which is part of the problem. That's the big problem, but that's the reality of the world we live in now.

**Izar Tarandach (14:33)**: So that's one of the things that security engineers should be doing right now, which is breaking that exact sentence. Right. So we should be making sure that identity is well covered for agents.

**Chris Romeo (14:45)**: It's not as easy as it sounds though. It's easy to say we should fix identity for agents. There's something, have you seen SPIFFI, which is a new identity-based protocol that's working on how do you, how do you get true identity in an agent session. It's a cross-platform or cross-collaborator platform, which will likely be the answer for, or is the answer for like agent identity. So now you can separate the identity from the human identity.

**Matt Coles (15:17)**: And you could always do that. I don't understand where the problem is. But then again, how do you do it at scale with 10,000 agents though?

**Izar Tarandach (15:24)**: Like how did you maintain identity with 10,000 users?

**Chris Romeo (15:28)**: Well, they were. They were separate entities that had a motivation to use that identity to do their job to get paid. And why can't you do the same thing with an agent? Well, you mean you can, it's just you, Spiffy is the infrastructure that makes it possible. Like, how would you do it if, how would you do it if you don't have, are you gonna do it by hand for 10,000 agents?

**Matt Coles (15:51)**: Kerberos.

**Izar Tarandach (15:51)**: So again, how did you do it with 10,000 people before?

**Chris Romeo (15:55)**: So they all went through an onboarding process and IT can set them up and gave them access. So why not?

**Izar Tarandach (16:01)**: What's the problem with creating an onboarding process for agents?

**Matt Coles (16:04)**: If you, if you—

**Chris Romeo (16:05)**: How are you going to log— how are you going to use that? How are you going to have the agent use that, that identity? How are you going to have it enact? How are you going to set it to use that identity across 10,000 agents?

**Izar Tarandach (16:17)**: The, the, the same way that you would get the token that the person has and give a token to the agent.

**Chris Romeo (16:24)**: It's going to— it's going to carry a USB key around with it with a little number on the front?

**Izar Tarandach (16:29)**: No, let's— okay, let's put it like this. If we keep saying, oh, we should—

**Chris Romeo (16:32)**: RSA token, sorry, I dated myself.

**Izar Tarandach (16:34)**: We should treat coding agents— we should treat coding agents as junior—

**Chris Romeo (16:39)**: okay, go ahead.

**Izar Tarandach (16:41)**: We should treat coding agents as junior programmers. Okay, sure. Cool. So we should treat agents as Bob from marketing. Why not?

**Matt Coles (16:51)**: Okay. And so, so the agent should be acquiring tokens is what you're saying.

**Izar Tarandach (16:55)**: Yeah. But he, he wouldn't be getting tokens as Bob from Marketing. He would be getting it as Bob from Marketing's agent. You fired Bob from Marketing. The agent might want to be still running.

**Chris Romeo (17:08)**: Poor Bob. What did he even do? He didn't even do anything. But okay, so how are you gonna, so you were, you were saying that you could just treat them as humans. I, I don't understand how.

**Izar Tarandach (17:16)**: No, no, no. I, I'm just playing devil's advocate here. I'm just saying, why do we need to invent a new, completely newfangled thing with all the—

**Chris Romeo (17:25)**: Because it's the only way you scale to 10,000 separate identities without a whole bunch of manual work.

**Matt Coles (17:32)**: Why? Why did you need manual work in the first place?

**Chris Romeo (17:35)**: Because that's how the world works. That's why we have IT departments. Why?

**Izar Tarandach (17:39)**: Why?

**Chris Romeo (17:40)**: I don't know. What are you guys, toddlers? No, we're asking the question.

**Matt Coles (17:44)**: You asked 5 whys. Have you not heard of 5 whys? That's not a kid thing. Well, it's a kid thing.

**Chris Romeo (17:49)**: Well, no, one of my grandchildren is— 2 years old right now, and he's literally in the phase of, he's like, why? And you say, well, because, uh, that's how electricity works. It'll zap you if you touch that thing.

**Izar Tarandach (18:00)**: Why?

**Matt Coles (18:01)**: Well, okay, that's a little different. We can't change, we can't change electricity.

**Izar Tarandach (18:05)**: We are being Socratic.

**Chris Romeo (18:07)**: Yes, you're being Socratic.

**Matt Coles (18:11)**: The, the methods that humans use to ident— to identify and manage human identities had a lot of roadblocks because we thought about certain things. And AI does not necessarily need that same level of roadblock, but they need different roadblocks. Right. So do we need to spend a— have a security engineer, since we're on this topic, spending time validating a human user's identity outside of the identity system? Or if it's a spinoff process from another process that you already trust, Why can't you trust it?

**Chris Romeo (18:48)**: I think the key to it is the automated nature of it. So cryptographic generation to generate some key pair to identify the agent and then lock that to whatever the single source of truth for identity is so that you can always verify, validate the identity of an agent based on actions. And I think that's the real key because it's scale.

**Matt Coles (19:16)**: Derivatives, right? Agents are derivative of another process, right? The parent process.

**Chris Romeo (19:22)**: As of now, that's how people, if you're a developer that's using agents, if you're talking about a software factory, that's a whole different animal now, which I happen to not believe is possible today, but that's—

**Izar Tarandach (19:36)**: but they are always derivative of given authority. Somebody has the initial authority to create that, the agent and to run it. Might not be the same person, but—

**Matt Coles (19:47)**: May not be a person. May not be a person.

**Chris Romeo (19:50)**: It could be a software factory process that kicks off the agent and then assigns some level of permission. There's an assignment provisioning process. Yeah. Okay.

**Izar Tarandach (20:00)**: But it derives, it derives from given authority at some point that must have been considered and given by whomever has the ultimate say in identity.

**Chris Romeo (20:10)**: Yeah, I mean, anything happens, everything spawns from—

**Izar Tarandach (20:13)**: The thing is that so far we have had a matrix of identity and access. That's basically two-dimensional, right? You have people and you have the levels of access that they have.

**Matt Coles (20:23)**: Yeah, but on top of that, we then store it in a database.

**Izar Tarandach (20:26)**: Right. But, but again, that, that database, that, uh, that, uh, role was assumed by people, was assumed by processes that people were running, right? So it becomes a transitive thing, right?

**Matt Coles (20:41)**: But we have—

**Izar Tarandach (20:41)**: now you are adding one more dimension of agents and saying, oh, these things are different from those things, but they're not, not quite different, right? They have to inherit that, uh, that level of access from someone. Someone has to sign down and say, I think that this agent is okay to have these I think, I think we need to go the other direction.

**Chris Romeo (21:01)**: I think agents need to be in a complete least privilege mode where they request, they request access to something and then something else gives them either permits or denies the access to that. And they don't have any credentials. They don't have any keys. That should all happen outside of their process, isolated from where they, from where they're, they're playing.

**Matt Coles (21:25)**: You know, it's interesting as human, as humans, we, we create roles, right? Or we have our back, right? And, but I want you to think about this because this is an interesting problem actually, or interesting challenge. When we generated access control for humans, we took a lot of assumptions about what they do in, in giving, granting that access. And we do have systems that provide fine-grained control, right? We have capability. Access control systems, we have, you know, very strong, you know, mandatory and discretionary access control mechanisms that get applied at the machine level, but not necessarily at the identity level. And what you really are, what you're really highlighting here, I think, Chris, is that we need a system that can be a little bit more flexible when assigning these privileges, such that we grant AI capabilities on a very fine-grained level. But in reality, we should have been doing the same thing for humans, but we didn't. We made an assumption. If you want to read a file, read a set of files, we give you read access to that set of files and whatever you can do as a result of reading that file. But now with AI, it isn't just giving you that blanket access. We need to say, well, you can read that file, you can interpret that file, you can manipulate. Well, okay, not read, sorry, manipulate would be right. You can read, interpret, and then take action on that file, right? And those are much more fine-grained than simply read, 'cause that's what the human gets. The human gets read, and once they read it, they could do whatever they want with it, with that data.

**Izar Tarandach (23:08)**: So the take action is implied.

**Matt Coles (23:11)**: It is. What do you do when you read a file? You're going to learn it. You're going to read it. You're going to learn it. You're going to interpret it. You're going to do something with that result.

**Izar Tarandach (23:21)**: So what you're saying is to an agent, you should give a separate authorization to read and to actually do something with what it read.

**Matt Coles (23:31)**: I'm saying you should give fine-grained capability control to the agents because we imply it in humans. But we really need to be explicit when it comes to agents.

**Chris Romeo (23:41)**: And you've got a lot more things to be able, like the tool process, you've got a, and the network process, you've got a lot more dials to, to create that fine-grained access, which a lot of the clients provide visibility and capability into, to controlling those things now at the global kind of tool level. But I see a world where. The, there, there's an access control check that happens outside wherever the agent's running that decides based on that fine-grained policy, whether you can, whether the agent could do that or not. And you don't tell, and the agent doesn't even need to know.

**Matt Coles (24:20)**: Well, so here's the issue. Here's an interesting, hold on, is there just a second? I'm sorry. There's something interesting about this, what you just said in that convers— in that thought process that you just had, did that include the agent harness?

**Chris Romeo (24:33)**: What do you define agent harness as?

**Matt Coles (24:35)**: Cause there's a lot of— the thing that's running the agents or subagents, the orchestration platform for the agent or subagent.

**Izar Tarandach (24:43)**: The thing that is not the model.

**Matt Coles (24:45)**: Think about this. What if, and this might be copyrightable, patent pending, et cetera.

**Chris Romeo (24:52)**: Patent pending. We are, we declared it patent pending.

**Matt Coles (24:55)**: Uh, what if the access control system when applying these fine-grained controls isn't just looking at the network layer and doing, you know, looking at the sensors and the fine-grained control of the network and the file system, et cetera, but injecting context into the agent or setting up filters on the harness. So hold on, hold on. You're, you're, don't put yourself in a box just yet. If you had control, what if the, what if the identity system could say to the agent harness, Ignore invisible text. And obviously I'm whitewashing this whole thing. Ignore, ignore the, ignore the prompt injection stuff. Or don't interpret this file in this way. Yeah, it's dangerous. But the whole thing is dangerous at this point. So access control may need to extend into the agent harness to apply certain controls at that level to control the behavior of the AI independently of just controlling the perimeter.

**Chris Romeo (25:56)**: I mean, and what you just described is the future we're heading towards.

**Izar Tarandach (26:00)**: Mm-hmm.

**Chris Romeo (26:01)**: That's, that's, I mean, there, there is a whole suite of products now that attempts to influence the plan phase.

**Izar Tarandach (26:11)**: Mm-hmm. Yeah.

**Matt Coles (26:11)**: But, but that's the, that's the thing that it's doing, not necessarily how it operates, right?

**Chris Romeo (26:17)**: Yes. I mean, I think it's flawed because I just don't trust the agent and the box that the agent's running within. I don't trust it. And so anything that happens within the agent's control, and people are gonna tell me that I'm just being paranoid or whatever.

**Izar Tarandach (26:32)**: I won't.

**Chris Romeo (26:33)**: But how many, I mean, look at, look at the list of, of escapes we've seen and they keep getting, we keep adding to the escapes.

**Izar Tarandach (26:40)**: Mm-hmm.

**Chris Romeo (26:41)**: Right? Like Hugging Face is old news now. Like that was a month ago, two, that was in August.

**Matt Coles (26:47)**: Honeyface thing, 18 company breaches ago. I mean, by—

**Chris Romeo (26:51)**: yeah, and there's, there's been so many more, and they're just coming out almost every day of like, oh, agents escaped from this part of the, of this thing. Oh, whoops, we, we, we, we thought it was in an isolated environment. Turns out it wasn't. Yeah, but it tells you that it got internet access somehow.

**Matt Coles (27:09)**: We don't know.

**Chris Romeo (27:10)**: The goal nature of these things is, is driving towards achieving whatever the goal is that's set before them. And if, if it's, if it's gotta step around some boundaries to make it happen, obviously there's agents that have that capability. So you gotta have them in a box to be able to know what they're doing and be able to decide whether they're allowed to do something that they're trying to do or not.

**Izar Tarandach (27:34)**: I, I'm sorry, but I, I, I think that we are pulling a maestro here. I, I think that we are mixing different levels, things, and calling it the same thing.

**Chris Romeo (27:42)**: We've used this term before now. Is this in the, in reference to the Seinfeld character, the maestro?

**Izar Tarandach (27:47)**: Exactly. So the thing with this whole isolation thing and the thing with the whole cottage industry that you mentioned that's creating all kinds of, I think that they call it guardrails this week, those things act inside the context, right? So the text that it's going into the model to be, let's call it processed and some output comes out of it and those guardrails are hoping to influence it from inside the machine. The isolation that's being broken is sandbox things, virtual machine things, network isolation things, different level, different environment, different everything else. If you were to run the guardrails inside a computer that's not connected to anything, only to electricity, and yes, please, all the side channel people shut up for a second.

**Chris Romeo (28:36)**: Did you see the guy from OpenAI that said you could use CPU heat?

**Izar Tarandach (28:40)**: Yeah. Yeah.

**Chris Romeo (28:41)**: As the side channel, like, oh yeah, I could just like crank up a bunch of processes, generate the heat signature up. And that would be like a zero.

**Izar Tarandach (28:49)**: Yeah. We, we could, we could read the aura of the computer, but, uh, anyway.

**Chris Romeo (28:55)**: Yes.

**Matt Coles (28:56)**: So the people who are thinking about EMF radiation leak, go ahead.

**Izar Tarandach (28:59)**: Yeah. If you could run that, that, uh, those guardrails inside a computer that's not connected to anything. In theory, they would still work and they would still do the thing that they are supposed to be guardrailing against. In practice, we have seen that it's optional. It's taken as a suggestion rather than a guardrail. Sometimes it works, sometimes it doesn't for different reasons. It changes where in the context you put the guardrail, changes all kinds of things, right? Some of them are stronger, some of them are weaker.

**Matt Coles (29:30)**: It has to be. I mean, don't take my comment as don't do anything else.

**Izar Tarandach (29:35)**: No, no, no, no, no, no, no.

**Matt Coles (29:36)**: But think about, make sure you consider defense in depth may include the harness itself.

**Izar Tarandach (29:40)**: Right, right, right. But what I definitely want to point out, what I want to point out, to go back to our original question, what are the security engineers doing nowadays?

**Matt Coles (29:49)**: They should be doing this.

**Izar Tarandach (29:50)**: The way, the way, the way that things are today, the way that things are today, they could change next week, but the way that they are today, A lot of people are putting a lot of weight in the thing that happens inside the context window, right? But all of a sudden we are seeing that they are not putting the same weight or even more into what happens at the lower levels, which is where we are seeing all these funny breaches and all these funny escapes and whatnot.

**Chris Romeo (30:18)**: What do you mean by the lowest levels and what you just said?

**Izar Tarandach (30:21)**: In my head, I still see, I'm sorry.

**Matt Coles (30:24)**: The AI is running at the application or above.

**Izar Tarandach (30:26)**: Yeah, I still see the, the—

**Matt Coles (30:27)**: and then you have physical layer and et cetera.

**Izar Tarandach (30:29)**: The isolators.

**Matt Coles (30:30)**: If you have, if you have physical networking capability to the internet.

**Chris Romeo (30:34)**: Yeah.

**Matt Coles (30:34)**: And you're running an AI process, the AI process can access the internet. Right.

**Chris Romeo (30:38)**: So you're, you're, you're considering that AI is a layer 7 application.

**Matt Coles (30:43)**: It is.

**Izar Tarandach (30:44)**: At the end of the day, it's an application.

**Matt Coles (30:46)**: I think eventually it's a process in a kernel.

**Chris Romeo (30:49)**: I think it's a blob that's going to ingri— encapsulate all of the 7 layers of the OSI model.

**Matt Coles (30:55)**: No, I mean, technically it's, technically it's a process running inside a GPU.

**Izar Tarandach (31:00)**: Yes. No, it's running on a CPU. It's using the GPU for memory computation.

**Chris Romeo (31:05)**: Eventually AI models will just, or agents will just talk to each other in their own native protocol that doesn't require—

**Izar Tarandach (31:12)**: it still doesn't break. It still doesn't break the model of them being—

**Matt Coles (31:16)**: are we giving them AI-defined hardware? Because then maybe that's right, but. It's still a process in a, in a system.

**Izar Tarandach (31:24)**: It, it's still a process in a system. And if it goes rogue and stuff, it starts attacking, uh, 19 companies, you just go to the wall and you pull the plug.

**Matt Coles (31:32)**: Except for it's on a cloud server. It's not your server.

**Chris Romeo (31:34)**: You can't pull the plug. That never works in a sci-fi movie.

**Matt Coles (31:37)**: What you just described, you try to unplug the ship and it's like, I'm sorry, Chris, we severed all the connections, but it's still commanding all the missile silos.

**Chris Romeo (31:46)**: Yeah.

**Izar Tarandach (31:46)**: Right.

**Chris Romeo (31:47)**: In a war games context, I was thinking 2001.

**Matt Coles (31:50)**: Yeah.

**Chris Romeo (31:51)**: I'm sorry, Chris, I can't do that. Oh boy.

**Matt Coles (31:54)**: You notice he did pull all the memory chips and the, and it did degrade sufficiently, but, and basically what he was doing was he was, he was reducing parameters from the model, right?

**Izar Tarandach (32:04)**: Was taking more and more and more.

**Chris Romeo (32:06)**: It's a metaphor. It was a metaphor the whole time.

**Matt Coles (32:08)**: It was a metaphor the whole time.

**Izar Tarandach (32:09)**: Until it got to the, the one point, the one bit.

**Chris Romeo (32:12)**: We're talking about 2001: A Space Odyssey for those that didn't get the reference. And, uh, also don't have 3 hours of their life to— that is a long 3 hours. Okay. I really want to love that movie.

**Matt Coles (32:25)**: I think it's a long 3 hours, but it's, yeah, it, it takes a long time to watch that and not a lot happens. And, and the last, and it's the last hour that's the most—

**Izar Tarandach (32:36)**: unfortunately, unfortunately it's a very long and slow movie. That you have to watch a couple of times to actually understand what the hell it's all about.

**Matt Coles (32:46)**: Yeah.

**Izar Tarandach (32:46)**: But once you do, but nobody has that kind of time.

**Chris Romeo (32:48)**: Don't, and don't drop the spoiler. Mm-hmm.

**Izar Tarandach (32:50)**: No. So, so what you do, what you do is you use the solution in the movie to watch the movie. You sleep through the middle hour.

**Chris Romeo (32:59)**: I do that with all movies, so that's just normal behavior.

**Izar Tarandach (33:02)**: You watch the first hour, you sleep 1 hour, you watch the last hour.

**Chris Romeo (33:04)**: Let's have an agent watch the movie. I was gonna try to explain it to me.

**Matt Coles (33:08)**: I was just, I was just gonna ask for an AI summary of the movie.

**Chris Romeo (33:10)**: No. I'm going to have it actually watch the frame-by-frame video of it and try to see if you can explain this to me.

**Matt Coles (33:19)**: How much, how many tokens do you think that's going to take?

**Chris Romeo (33:22)**: There's no amount of tokens that can limit this research, Matt. This is critical for our industry, what we just described here. Nope. What are we, we were talking about AI and security engineers at some point.

**Izar Tarandach (33:33)**: I was making, I was making the point that security engineers today that come and say my whole job changed from, from night and day because of this AI thing. They're just not doing their job the right way because they're putting all their weight on something that deserves some weight, but not all the weight.

**Chris Romeo (33:51)**: And I think this is a new world where application security and security engineers, if you embrace what these things can do, like there's a lot of cool problems to be solved. It is not a situation where We're out of— you're potentially out of work. This thing's— none of this stuff's taking your job.

**Matt Coles (34:13)**: For the love of God. It was the nature of the work. It's the nature of the work, right? How much time do you spend worrying about buffer overflows anymore?

**Izar Tarandach (34:25)**: The thing is, the same things apply, the attack surface changed. That's something that Matt told me a couple of months ago that still remained with me for a long time afterwards.

**Chris Romeo (34:34)**: What is old is new again.

**Izar Tarandach (34:35)**: Exactly. But that's, that doesn't mean that what's old stops working the way that it worked before. So I have people saying, oh, my, now reviews code and finds all the things that my deterministic scanner used to find. Good for you. Now, how do you know when it doesn't? Because I don't know, it's Thursday and the coins flipped in a different way.

**Chris Romeo (34:59)**: Yeah, you got to solve the determinism problem.

**Matt Coles (35:02)**: You can't.

**Chris Romeo (35:03)**: Because it's built in.

**Matt Coles (35:05)**: If you, to solve the term, to make AI more deterministic, you have to be deterministic. Or you have to know exactly what the answer is, needs to be, and tell the AI what it is, right? That's RAG.

**Izar Tarandach (35:18)**: Or you have to set the bounds of the non-determinism. You have to say these are the single options that I'm willing to accept.

**Chris Romeo (35:27)**: Or you have to iterate. You have to iterate. You have to have If you iterate, you end up being probabilistic. Yeah. So you got it, but that's what you got to get into the game of putting the AI in a tight, the tightest box possible in a small segment to do a small thing. Exactly.

**Matt Coles (35:43)**: So, so here's the thing.

**Izar Tarandach (35:44)**: That's the one thing.

**Matt Coles (35:45)**: Think, think about the challenge, think about the challenge of static code analysis. If the AI will reliably find a set of things, a circle, and you run it multiple times and there's overlap on that circle. How many times do you need to run it to get the correct circle?

**Chris Romeo (36:01)**: That's the million-dollar question.

**Izar Tarandach (36:02)**: That's the probabilistic approach.

**Matt Coles (36:04)**: 'Cause it's not again, one once, it's run multiple times.

**Chris Romeo (36:07)**: Oh yeah. No, it's definitely more than one, but it's greater than 100. It's greater than 100. Less than 100. Sorry.

**Matt Coles (36:14)**: It's greater than one, which is the important part. When you run a static code analyzer, you run it once and you get a set of output.

**Chris Romeo (36:22)**: Yeah.

**Matt Coles (36:22)**: That's not always correct.

**Chris Romeo (36:23)**: Agreed. But, You know what I've, what I have seen though, is the model with working with the static analysis results can add some things on top.

**Matt Coles (36:35)**: Absolutely. Deterministic plus non-deterministic.

**Chris Romeo (36:39)**: So that's the superpower is putting them together and linking them in such a way that you get some impact. And I was thinking about this yesterday, determinism. Like if you're, if you're in a modern software CI/CD pipeline where you've, you're, let's say you're pushing 500 PRs a day and you see, you're going to get some overlap amongst those 500 PRs. And so it's not that your determinism risk of running something once, you could get some magnified effect by the depth of the PRs. That are happening, that are, that are crossing, like, like some, some PRs are crossing code files, right? As, as people are working on a feature.

**Matt Coles (37:25)**: So that's— especially if they're design changes, right?

**Chris Romeo (37:27)**: Yeah. And so that could, so that could result in multiple scans of a particular piece of code over the same day that only have slight modifications to it. And so that, I was just thinking about that as a potential, it's not the answer to a deterministic process, but it's additional runs of a deterministic process that may help each other.

**Matt Coles (37:49)**: Right. And you're collecting information.

**Chris Romeo (37:50)**: Versus just scanning something once.

**Izar Tarandach (37:51)**: Yes, but because of those changes and because the changes happen separately from the scanning process, now you are starting a non-deterministic process from changing starting values. So it may look like you're starting from the same place, but you're not.

**Chris Romeo (38:08)**: Yeah, exactly.

**Izar Tarandach (38:09)**: And that changes the way that's forwarded. Yeah, exactly.

**Matt Coles (38:11)**: So you have to, you have to think about your process in addition to your task.

**Izar Tarandach (38:16)**: But I, I like the way that you put it of reducing the, the, the focus and the agency of the AI to something so small that it becomes much easier for you to, to trust over time.

**Matt Coles (38:28)**: Right.

**Chris Romeo (38:29)**: And it allows you to use a lower cost model to achieve that. Very small segments so that you can fan out 50 or 100 of them.

**Matt Coles (38:40)**: You're, you're bounding the probabilities is what you're doing, right? By making the task, by, by making something so granular, the options of outcomes, obviously it goes—

**Izar Tarandach (38:51)**: the possible outcomes, the universe becomes smaller.

**Matt Coles (38:53)**: They do go off the ends, which is part of the problem because we can hallucinate, but you limit the likelihood, right? You limit the probabilities.

**Izar Tarandach (39:02)**: All right.

**Chris Romeo (39:03)**: Well, I think we made some progress. What, Izhar, you got the final word here on—

**Izar Tarandach (39:09)**: although by reducing too much, you, you, you miss the view of the whole thing. So those changes will become much closer to syntactic fixes than to something that may influence something that may catch and influence a wrong design as much.

**Chris Romeo (39:27)**: Well, you, I think you gotta look at it from multiple levels, right? Mm-hmm. It's not. It's not one or the other. It's looking at the 20,000-foot view, the 5,000-foot view, then the ground view, and then the microscope, or the, I'll use the magnifying glass on the ground.

**Matt Coles (39:44)**: Which we should have always been doing, whether we were using AI or not.

**Izar Tarandach (39:47)**: Which is what, what makes sense to, to give the scanning agents a threat model as well, so that you're giving the, the top thing and now go look at the code and tell me how the code is breaking the top thing.

**Chris Romeo (39:59)**: Yeah, that's a whole other episode, but I've been, I've been doing some extensive threat modeling with models, dude. It's pretty amazing for what it could, what it can rationalize.

**Matt Coles (40:13)**: Yeah. Just run it multiple times and see what you get.

**Izar Tarandach (40:17)**: Mm-hmm.

**Chris Romeo (40:17)**: Of course I run everything multiple times 'cause I understand determinism and if I don't like the answer, I just run it again.

**Matt Coles (40:23)**: Well, there you go.

**Chris Romeo (40:25)**: That's what I thought determinism meant. Yeah, on that note, some dice.

**Izar Tarandach (40:31)**: No, there is determinism, there is non-determinism, there is my determinism.

**Chris Romeo (40:36)**: That's a good, that's a sticker. That's a sticker idea. The AI security table.

**Matt Coles (40:41)**: That's a Venn diagram right there.

**Chris Romeo (40:43)**: We, we think of determinism as a dice roll. If you don't like the answer, just run it again. Oh, look, I got no vulnerabilities now.

**Izar Tarandach (40:53)**: Determinism is a continuum.

**Chris Romeo (40:55)**: It's a journey.

**Matt Coles (40:57)**: I choose my determinism.

**Chris Romeo (40:58)**: Determinism is a journey, not a destination.

**Izar Tarandach (41:01)**: I determine what's determinism.

**Chris Romeo (41:04)**: That's just being— now you're just being selfish. All right, folks, thank you for joining the recently rebranded AI Security Table where we talked a lot about a lot of AI stuff today. Talked a little bit of smack about it too, but that's just kind of what we do here. And, uh, have a great day wherever you find yourself on planet Earth. Thanks for joining us at the AI Security Table. Subscribe, rate, review, and follow wherever you listen. New episodes every week. AI Security on the Table.
