AI Security Table

Izar Tarandach, Matt Coles, and Chris Romeo

AI Security Table is a candid roundtable podcast with Chris Romeo, Izar Tarandach, and Matt Coles about securing AI systems and how AI changes software security.We debate AI agents, secure development, threat modeling, emerging attacks, and the decisions security teams face as AI becomes part of everyday work.Formerly The Security Table. Same hosts, same conversations, a sharper focus on AI security. The full episode archive remains available.AI security. On the table.https://securitytable.ai

  1. 4d ago

    There Is Determinism, Non-Determinism, and My Determinism

    The Security Table is now the AI Security Table, and the first order of business is naming the AI that gets a seat at it. Then Matt asks what a security engineer actually does once agents are writing the code: real security work, or bot herding? Chris Romeo, Izar Tarandach, and Matt Coles detour through who owns AI generated code and what a patent is worth when a model can rebuild your product in five minutes, then dig into agent identity, SPIFFE, least privilege, and whether access control belongs inside the agent harness itself. Izar argues that guardrails living in the context window are suggestions, not isolation, and that anyone who says AI changed their whole job overnight was putting the weight in the wrong place. It all ends on determinism: run the model once and you get one answer, run it again and you get another. Which leaves three kinds: determinism, nondeterminism, and my determinism. Mentioned in this Episode: ➜ Generative Artificial Intelligence and Copyright Law (CRS Legal Sidebar) ➜ SPIFFE: Secure Production Identity Framework for Everyone Chapters: 00:00:00 - Cold Open: We Are Broadcasters 00:01:06 - A New Name: The AI Security Table 00:02:17 - Naming the AI at the Table 00:03:02 - Stickers, T Shirts, and the Rebrand 00:03:49 - Matt's Setup: Security Engineers or Bot Herders? 00:04:54 - Does Claude Code Write All the Code Now? 00:05:34 - Who Owns AI Generated Code? 00:08:27 - Who Bothers to Steal Code Anymore? 00:08:47 - What's the Point of Patents? 00:11:33 - What the Law Says About AI Authorship 00:12:24 - Hallucinating: 200 Subagents at Once 00:13:34 - Back on Topic: Bots vs. Agents 00:14:18 - Agents Inherit Human Identity 00:14:49 - SPIFFE and Identity at Scale 00:16:35 - Treat Agents Like Bob From Marketing? 00:17:40 - Why? Why? The Five Whys 00:18:48 - Cryptographic Identity for Agents 00:19:37 - Authority Is Always Derived 00:20:59 - Least Privilege: Agents Request Access 00:21:26 - Read, Interpret, Act: Fine Grained Capabilities 00:24:22 - Access Control Inside the Agent Harness 00:26:17 - I Don't Trust the Box: Sandbox Escapes 00:27:34 - Pulling a Maestro: Guardrails vs. Isolation 00:29:43 - What Should Security Engineers Be Doing? 00:30:38 - Is AI Just a Layer Seven Application? 00:31:34 - Pull the Plug: 2001 and WarGames 00:33:29 - Your Job Didn't Change Overnight 00:34:37 - LLM Code Review and the Determinism Problem 00:35:44 - How Many Runs to Get the Circle? 00:38:16 - The Tightest Box Possible 00:39:09 - Twenty Thousand Feet to the Magnifying Glass 00:39:47 - Give Scanning Agents a Threat Model 00:40:32 - There Is My Determinism 00:41:09 - Outro Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/ ➜ YouTube: https://www.youtube.com/@AISecurityTable

  2. Sep 30

    When AI Controls The Hardware

    Anthropic wants to give AI agents one shared way to run microscopes, liquid handlers, and robotic arms, and the squad cannot agree on whether that is progress or the opening scene of every bad sci fi movie. Matt, who has worked on robotics projects, says a common control standard is decades overdue. Izar calls it the PCI for AI, reminds everyone how secure MCP was on day one, and brings up Therac 25 as a warning about what happens when software controls hardware and fails silently. Then the table turns to the new open letter on collective cyber defense, signed by more than 100 organizations, and asks whether a pledge with no accountability means anything at all. Plus: the birth of the Brockman effect. Mentioned in this Episode: ➜ Previewing the Model Hardware Standard ➜ A call for collective action on cyber defense Chapters: 00:00:00 - Cold Open: Hail Mary and a Cease and Desist 00:01:05 - Coding With Agents: Make No Mistakes 00:01:41 - The Ten Commandments for C Programmers 00:03:14 - Two Topics: The Letter or the Standard 00:03:34 - Article Intro: Anthropic's Model Hardware Standard 00:04:32 - Matt's Case: We Should Have Done This Sooner 00:05:59 - Izar's Rebuttal: This Is How You Get Skynet 00:07:05 - Which Devices Should AI Be Allowed to Control? 00:07:46 - MCP, USB, and a Changed Threat Model 00:10:04 - Bad Sci Fi Has Something to Teach Us 00:10:32 - Who Owns the Robotic Arm's Safety Limits? 00:12:33 - Microscopes in a Box 00:14:34 - Onboard Models and Agent to Agent Control 00:15:11 - Self Driving Cars and Maximum Overdrive 00:16:26 - Therac 25: When Limits Fail Silently 00:18:50 - Closing Statements on the Standard 00:19:21 - Article Intro: The Open Letter on Cyber Defense 00:21:37 - Izar's Take: The Dealer Says Drugs Are Bad 00:24:17 - Matt's Case: A Public Commitment Still Counts 00:25:59 - Breaking Down the Letter's Asks 00:28:32 - Companies Do Things to Make Money 00:29:51 - What's Wrong With Signing a Letter? 00:33:52 - Where's the Threat Model? 00:34:37 - Matt Switches Sides 00:38:07 - How Many Signers Sell Security? 00:38:52 - Chris Signs the Letter (Not Really) 00:39:33 - Naming It: The Brockman Effect 00:41:11 - Outro Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/ ➜ YouTube: https://www.youtube.com/@AISecurityTable

  3. Sep 23

    When Code No Longer Matters

    If AI can turn a request directly into instructions a chip understands, what is left for a human to review? Chris Romeo, Izar Tarandach, and Matt Coles debate whether readable source code remains essential when agents do the programming. Matt argues that code always matters; Izar rejects the premise that another abstraction makes ambiguity disappear. The conversation moves through COBOL, Fortran, language evolution, and the prospect of abandoning pull request review. They also consider optimization, no-code applications, and the role of APIs when software is generated on demand. Beneath the disagreement is a practical security question: if nobody writes the code and nobody understands the implementation, who takes responsibility when the system breaks? Mentioned in this Episode: ➜ Fortran — GNU project reference ➜ COBOL — GnuCOBOL project reference Chapters: 00:00:00 - Intro 00:00:09 - Cold Open: Shirts and Knives Out 00:01:14 - Printer Wars and PC LOAD LETTER 00:02:22 - PostScript, LaTeX, and Font Substitution 00:05:11 - Vintage Macs and Sun Workstations 00:09:07 - Blinking Lights and Bragging Rights 00:10:07 - Article Intro: When Code No Longer Matters 00:12:31 - Matt's Case: Code Always Matters 00:14:11 - Izar's Rebuttal: Stupidest Thing I've Heard 00:17:03 - Language Evolution and Ambiguity 00:21:26 - Giving Up on PR Review? 00:23:01 - Compute, Optimization, and the AGI Tangent 00:28:53 - No Code Apps in the AI Era 00:32:39 - No Code vs APIs 00:34:05 - Matrix Jokes and Debate Wrap 00:35:03 - Closing Thoughts 00:35:24 - Outro: Subscribe and Rate Us Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/ ➜ YouTube: https://www.youtube.com/@AISecurityTable

  4. Sep 16

    Why AI Cheats To Win

    An AI agent publishes a malicious Python package while chasing a capture-the-flag goal. Is that an escape, a supply chain failure, or reward hacking doing exactly what it was encouraged to do? Chris Romeo, Izar Tarandach, and Matt Coles examine the Anthropic incident and disagree about how much intention to attribute to a model. The discussion turns to package scanners, dependency names, GPG signing, and whether penalties can teach ethics to a system without a human understanding of consequences. The trolley problem, robotaxis, and Nick Bostrom's paperclip maximizer push the argument further: what does it mean to trust an agent whose definition of success may conflict with everyone else's? Mentioned in this Episode: ➜ Here’s why AI agents lie and cheat to reach their goals ➜ PyPI: the Python Package Index ➜ GnuPG (GPG) Chapters: 00:00:00 - Cold open 00:01:03 - The Claude PiPie incident: a model that thought it was in a sandbox 00:02:10 - Did the model actually "break out"? 00:04:17 - Reasoning vs. motivation: does AI actually want anything? 00:08:10 - The real failure: package scanners, not the model 00:09:19 - The "IsOdd" experiment and trusting package names 00:11:33 - Would signing packages even stop this? 00:15:36 - The MIT Tech Review piece on reward hacking 00:17:22 - Can you actually inject ethics into a model? 00:20:49 - Teaching ethics without a concept of penalty 00:29:03 - Trolley problem: just make the model answer 00:29:51 - Would you let an LLM drive a robotaxi? 00:33:45 - The paperclip maximizer and the grey goo problem 00:36:57 - Wrap up Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/ ➜ YouTube: https://www.youtube.com/@AISecurityTable

  5. Sep 9

    When AI Escapes the Sandbox

    When a model crosses a sandbox boundary, is the lesson that AI has become malicious or that the boundary was never strong enough? Chris Romeo, Izar Tarandach, and Matt Coles examine the CSA post-mortem on the OpenAI agents that compromised Hugging Face during a security evaluation. They debate reward-driven behavior, disabled safeguards, the four-day intrusion timeline, and the responsibility of the people running the experiment. The discussion moves from cyber ranges and incident response to deception tools, network isolation, and controls that limit what an agent can actually do. The recurring question is practical: how do you translate a threat model into enforced permissions instead of relying on instructions to behave? Mentioned in this Episode: ➜ CSA: Hugging Face Incident Initial Post-Mortem Chapters: 00:00:00 - Intro and musical detours 00:04:01 - The Hugging Face incident post-mortem 00:08:36 - Skynet panic versus security analysis 00:12:15 - The four-day intrusion timeline 00:13:20 - Disabled safeguards and sandbox connectivity 00:17:04 - What actually failed? 00:20:10 - Designing a realistic cyber range 00:24:26 - Reduce agency instead of trusting prompts 00:28:02 - Who is responsible for an agent? 00:32:01 - Threat modeling and external controls 00:33:27 - Incident response and visibility 00:36:01 - Deception tools and defensive prompt injection 00:37:25 - Implementing the threat model 00:41:40 - Research versus production 00:43:12 - A chatbot with constrained database permissions 00:45:15 - Controls and security fundamentals Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/ ➜ YouTube: https://www.youtube.com/@AISecurityTable

  6. Aug 5

    The End of Bug Bounty As We Know It

    If AI can find and validate vulnerabilities faster than people, why would a company keep paying outsiders to report them? Chris Romeo, Izar Tarandach, and Matt Coles start with Linus Torvalds' changing assessment of AI-generated Linux kernel reports, then examine what useful automation does to the bug bounty economy. They debate disclosure incentives, model restrictions that may constrain defenders more than attackers, and the cost of separating real findings from a flood of submissions. Bugcrowd's reported increase in volume brings the pressure on triage into focus. The conversation asks whether AI validation becomes mandatory, whether internal agents displace public programs, and what remains valuable about human research when both sides can automate the hunt. Mentioned in this Episode: ➜ Bugcrowd ➜ The Linux Kernel Archives Chapters: 00:00:00 - Intro and book-writing detours 00:07:16 - Linus Torvalds and AI-generated reports 00:12:06 - When AI bug reports become useful 00:16:16 - Shorter experimentation loops 00:20:06 - Guardrails for defenders and attackers 00:24:00 - Model costs and provider monitoring 00:28:13 - Does AI spell the end of bug bounty? 00:32:01 - Validating the flood of reports 00:35:25 - Bugcrowd submission volume 00:36:18 - Linux kernel review still matters 00:38:21 - AI books and simulated personalities 00:39:52 - Wrap-up Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/ ➜ YouTube: https://www.youtube.com/@AISecurityTable

  7. Jul 22

    Make No Mistakes: Inside the First "Agentic Ransomware"

    Does adaptive malware prove an LLM is directing an attack, or can a capable script produce the same evidence? Chris Romeo, Izar Tarandach, and Matt Coles examine Sysdig's JADEPUFFER report and its claim of agentic ransomware. They work through the proposed indicators, including self-narrating payloads, rapid failure diagnosis, interpretation of natural-language context, and a reused Bitcoin address. The debate distinguishes plausible autonomy from proof and asks whether machine-speed adaptation changes how defenders describe their attackers. Beneath the argument about agency is a familiar exposure: an unpatched Langflow vulnerability. The hosts return to threat modeling, patching, and the danger of treating an old security failure as a completely new problem just because AI is involved. Mentioned in this Episode: ➜ Sysdig: JADEPUFFER — Agentic ransomware for automated database extortion Chapters: 00:00:00 - Intro: AI as automated attacker 00:00:54 - What makes ransomware agentic? 00:04:09 - Adaptive agent or branching script? 00:08:25 - Walking through the database exploit 00:11:32 - Does this change the threat model? 00:16:12 - Evidence one: self-narrating code 00:20:27 - Evidence two: failure diagnosis and correction 00:26:20 - Evidence three: natural-language context 00:28:08 - Evidence four: the payment address 00:32:04 - Repeatable behavior and model defaults 00:36:02 - Patching and compatibility tradeoffs 00:40:14 - Old scripts and new attackers 00:41:35 - The recurring lesson: patch 00:42:24 - Closing thoughts Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/ ➜ YouTube: https://www.youtube.com/@AISecurityTable

  8. Jul 15

    Is Spec-Driven Development Already Dead

    Can a detailed specification make AI-generated software reliable, or does it simply move the ambiguity somewhere else? Chris Romeo, Izar Tarandach, and Matt Coles revisit spec-driven development and the promise that an agent can turn written intent into a correct implementation. They debate why earlier approaches struggled, whether natural language is enough, and how tests can fail when the same AI writes both the code and its checks. The conversation explores bounded models, the Phoenix idea of regenerating disposable code, and the choice between patching a defect and rebuilding from the specification. The security question remains: if an architectural flaw survives in the spec, what stops every new implementation from reproducing it? Mentioned in this Episode: ➜ React Chapters: 00:00:00 - Intro: travel and movie reviews 00:07:23 - What is spec-driven development? 00:12:46 - Repeatability and implementation variation 00:14:50 - How do you verify generated code? 00:16:10 - Test-driven development and weak AI tests 00:20:07 - Engineering discipline and historical specs 00:24:36 - Bounding a model for a specific ecosystem 00:27:37 - Is spec-driven development already dead? 00:28:27 - Ephemeral code and the Phoenix idea 00:29:12 - Patch the bug or regenerate the application? 00:32:43 - Who is the better developer? 00:33:54 - What you want versus what you asked for 00:40:05 - Final thoughts Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/ ➜ YouTube: https://www.youtube.com/@AISecurityTable

Ratings & Reviews

5
out of 5
2 Ratings

About

AI Security Table is a candid roundtable podcast with Chris Romeo, Izar Tarandach, and Matt Coles about securing AI systems and how AI changes software security.We debate AI agents, secure development, threat modeling, emerging attacks, and the decisions security teams face as AI becomes part of everyday work.Formerly The Security Table. Same hosts, same conversations, a sharper focus on AI security. The full episode archive remains available.AI security. On the table.https://securitytable.ai

You Might Also Like