Discussion with Omar Santos, Distinguished Engineer at Cisco. Omar Santos: https://www.linkedin.com/in/santosomar/ CoSAI: https://www.coalitionforsecureai.org/ Summary In this conversation, Omar Santos, a distinguished engineer at Cisco, discusses his extensive background in cybersecurity and the evolving role of AI in security practices. He shares insights on the challenges of network security, the importance of responsible AI, and the impact of open source on vulnerability management. The discussion highlights the dual nature of AI technology, emphasizing both its potential benefits and the pressing challenges it presents in the cybersecurity landscape. In this conversation, Omar Santos and Justin Somaini discuss the evolving landscape of open source security, the formation of the Coalition for Secure AI (CoSAI), and the introduction of Code Guard as a solution to enhance security in AI development. They emphasize the importance of collaboration among organizations to address vulnerabilities and the need for compensating controls in the face of rapid technological advancements. The discussion highlights the significant impact of Code Guard in reducing vulnerabilities in AI-generated code and the straightforward implementation process that can be adopted across various coding agents. In this conversation, Omar Santos and Justin Somaini discuss the evolving role of AI in software development, particularly in code review and vulnerability management. They explore the challenges of human coding practices, the potential of AI to refactor and modernize code, and the importance of eliminating unused features to reduce risk. The discussion also touches on the differences between corporate and production AI adoption, the need for centralized services for secure development, and the call to action for improving open source security practices. Chapters 00:00 Introduction to Omar Santos and AI Security 01:15 Omar Santos' Background and Career Journey 03:13 Challenges in Network Security and Maintenance 06:29 The Role of AI in Security Practices 07:11 Omar's Early Experiences with AI and Machine Learning 10:07 Responsible AI and Its Importance 12:57 Cisco's Exploration of LLMs and AI Integration 17:07 The Dual Nature of AI in Security 19:14 Current Vulnerability Management Challenges 24:40 The Impact of Open Source on Security 28:04 The State of Open Source Security 31:43 Introducing CoSAI: Coalition for Secure AI 37:24 Code Guard: Enhancing Security in AI Development 46:57 Implementation and Impact of Code Guard 53:51 The Evolution of AI in Code Review 55:11 Human vs AI: Coding Vulnerabilities 56:27 Refactoring Code with AI 58:23 Eliminating Unused Features to Reduce Risk 60:28 The Importance of Modernizing Technology 62:00 The Challenge of Unused Features in Software 64:30 Corporate vs Production AI Adoption 66:53 Centralized Services for Secure Development 69:03 The Wild West of AI Experimentation 72:33 Preparing for AI Security Challenges 75:15 Call to Action for Open Source Security Keywords AI security, Omar Santos, Cisco, vulnerability management, machine learning, responsible AI, network security, open source, cybersecurity, incident response Open Source Security, AI, CoSAI, Code Guard, Vulnerability Management, Cybersecurity, Cisco, Machine Learning, Security Best Practices, Software Development Life Cycle AI, code review, vulnerabilities, refactoring, software security, open source, corporate adoption, technology modernization, risk management, coding agents