Yashvier Kosaraju, who goes by Yash, is the Chief Information Security Officer (CISO) of a16z, 4 months into the job when this was recorded, which by his own measure feels like about a year. The job covers the firm’s corporate environment, its cloud controls and its pitch decks, and the part that makes him useful to this audience is that a16z sits close enough to its portfolio companies that founders bring him their security problems directly. So host Jon McLachlan starts there. When does a startup make its first security hire, and when does that become a head of security? Yash separates the two hard. The first hire is a staff or senior staff engineer who can work independently, someone in the code and the infrastructure rather than someone building a team, and the trigger is a risk decision about what data you hold and what happens if it walks. Headcount has nothing to do with it. Where that person sits matters as much as when you hire them, because an engineer without enough context and access can’t execute. The head of security comes much later, when the company is big enough to need a dedicated leader in the seat. Then the sales version of the same question, which is the one founders feel first. A big client asks for a call with your security leader, or for a named contact they can reach in an emergency. Yash’s answer is that this is the wrong moment to go hire a head of security, and he lays out the 2 routes he’d take instead. Fractional CISOs come up, and he calls them a good resource for jumpstarting a program. The middle of the episode is AI, and he does neither the optimistic version nor the doom version. The security market is saturated with vendors, he says, where every feature of what ought to be one suite is its own company, and for the first time in his career he can’t tell you how long consolidation will take. On offense, AI is good enough at working through known vulnerabilities, the published Common Vulnerabilities and Exposures (CVE) list, to overwhelm a defense, and the cost per exploit is falling for the attacker. His forecast is 12 to 18 months of painful catch-up, after which whole classes of vulnerability and whole categories of tooling stop being necessary. What he wants gone specifically is code security. Static application security testing (SAST) and software composition analysis (SCA) exist because humans write insecure code, and if agents are writing most of it, he’d like them writing it securely by default. His real worry sits outside the valley. The rate of AI adoption here is nothing like the rate anywhere else, and attackers ramping up on AI don’t have to come to Silicon Valley to use it. The companies that haven’t adopted, or that can’t afford the tokens to build a defense, are the ones on the other end of that curve. He puts it plainly. The cost of not adopting AI is higher than the cost of not adopting anything that came before it. Jon takes it to agents, and this is where the episode earns its title. Prompt injection is unsolved. The defense everybody points at is the accept-this-action prompt your coding agent throws up before it does something, and his read is that it stops functioning around the third click, when people click through without reading. So a16z adopts AI fast and scopes it deliberately instead. For an AI tool, the vendor review he cares about starts with what the tool can reach, and whether that connection writes back or only reads. The pen test and the questionnaire still get run, and on an AI tool they aren’t where the risk sits. The other half of that is a rule about how his team answers requests. They don’t say no, because a no costs you twice. Whoever asked stops asking you, and uses the thing anyway. Also in this one. Why the security teams of the next 2 years live much closer to the code, and what changes when a finding stops being a list of packages to upgrade and becomes a pull request one agent opens and another reviews. Where testing goes once the code layer is handled, and why business logic is the part AI is worst at. The return on investment conversation nobody has solved, including his own example of the same task costing wildly different amounts depending on how fast you asked for it. Why he doesn’t expect the frontier labs to be the ones who show you that price. What a16z’s actual AI mandate was, which had nothing to do with spending more. One cryptography course in India that turned into a master’s at Johns Hopkins and 15 years in the field. Why his proudest moments are other people’s promotions, and the correction he makes when Jon calls that giving back. The job he left in under 2 months. And why he’d decline the meeting with his younger self. He’s hiring, and he says so on his way out. Brought to you by YSecurity, the security team that works next to yours. Your first 8 hours with 40+ security engineers are free at ysecurity.io/startups.