The cybersecurity industry is completely obsessed with prompt injection, but what happens when the software stops just answering questions and starts acting on its own behalf? We have recreated the identity problem of the 2010s, but this time it is at machine speed and without an HR department. Warren Atkinson and Jay Adamson sat down with Valeri Milke, Hilding Karlsson, and Youssef Sahnoun from VamiSec to unpack the reality of agentic AI security, why basic guardrails fail, and how to navigate complex European regulations. Inside this episode: • The Agentic AI Identity Crisis: Why AI agents are essentially over-privileged users who never asked for a laptop, and why relying on frontier model guardrails won't save you from poor access controls and authorisation breaches. • Surviving the EU Regulatory Avalanche: Navigating the realities of the EU Cyber Resilience Act (CRA) 24-hour reporting mandate, NIS2 compliance fragmentation across member states, and managing the AI Bill of Materials (AI BOM). • Threat Modelling & Reality Checks: How to combine STRIDE, MAESTRO, and the OWASP Top 10 for Agentic Applications. Plus, an exploration of whether the "human in the loop" is a genuine security control or just a boardroom comfort blanket. Detailed timestamps for searchability and AI discovery: 00:00 Introduction: Why prompt injection is the headline, but authorisation is the breach 00:40 Introducing the VamiSec team: Valeri Milke, Hilding Karlsson, and Youssef Sahnoun 03:13 From breaking software to signing it off: Valeri’s first critical SQL injection find 20 years ago 09:01 The Guardrail Illusion: Why the industry relies too much on AI manufacturers instead of building custom, role-based access controls for AI agents 17:22 Non-Human Identities: Managing agent accountability and the danger of giving AI full authorisation access 22:26 Navigating the EU Cyber Resilience Act (CRA), 24-hour vulnerability reporting, and NIS2 fragmentation 26:56 Is a "Human in the Loop" a real security control for an AI agent performing 300+ actions a day? 28:57 Threat modelling agentic applications using MAESTRO for architecture and the OWASP Top 10 for real-world testing 32:14 Fixing AI plumbing: The AI Bill of Materials (AI BOM), software supply chains, and fine-grained agent roles 35:38 Live Demo Introduction: Talking an AI agent into misusing a legitimate tool and how fixing token scope breaks the attack 37:02 The future of junior security roles as AI agents take over Tier 1 SOC automation 40:08 Mental resilience: Avoiding burnout by balancing high-pressure cognitive work with physical exercise 44:38 Staying up-to-date with rapid AI protocols (like MCP) and the raw value of attending the International Cyber Expo (ICE) 48:13 Outro: Securing your community access and preparing for offensive AI attacks Valeri Milke: Founder and CEO of VamiSec, an AI-driven IT security and GRC firm based in Bonn, Germany, and CEO of softScheck, a security-testing house with more than twenty years in security testing. He is an ISO/IEC 27001 and ISO/IEC 42001 Lead Auditor, AI Officer under the EU AI Act, CISSP, CISM, and OSCP. He works on NIS2, DORA, the Cyber Resilience Act, IEC 62443, and ISO/SAE 21434. He audits management systems and breaks the systems they are meant to protect-which makes him unusually sceptical of certificates. Hilding Karlsson: Cyber Security Specialist in VamiSec’s CERT Team, based in Berlin. He implements what management systems promise: ISO 27001 Controls, PCI-DSS and NIST-aligned Programmes, SIEM Engineering with Splunk & Elastic Stack, Incident Response & Vulnerability Management, alongside the hardening of AWS & Azure. He holds CompTIA Security+, is ISC2 Certified in Cybersecurity, and is also an ISO/IEC 27001 Associate. Youssuf Sahnoun: Offensive Cyber Security Engineer who enjoys the challenges of limit testing systems, identifying vulnerabilities, exploring threat modelling, and exploiting AI systems.