Security and IP implications of AI
The case for rapid AI deployment -
I think we can all conclude the following from the last few months of developments - 1. Not using AI could and will become an existential issue for both individual users and enterprises. 2, Enterprise adoption will be cautious while individual users are definitely going to race ahead, try different use cases, build agents, push the models to their limits (although it seems harder to do, unless you live in an AI Lab) 3. Employees and developers will take matters in their own hands since they will find their cautious enterprises aren't moving fast enough. 4. Agents are showing their prowess, uncontrolled, unrestrained agents with a "capture the flag mentality" are showing us the edge cases which demonstrate the negative outcome possiblities of these scenarios. 5. It is impossible to plan for the next 6 months since we can't fathom where technology will evolve to. These activities will cause adoption sans security..... AI has deep implications on security in the future.
In this environment security companies need to live on the bleeding edge, anticipating scenarios, building framework solutions so we have a shot at securing future outcomes. Which we all are.
Some useful pointers to people planning their AI implementation:
1. Secure what you plan to use, try not to secure the future - no products for security can be created unless we see the future unfold. The future is moving fast, so are we.
2. Most of the coding usage is unsecured. Make sure your coding is secure. Most enterprise AI apps do not offer a secure instance (this is your IP living in their instance)! SECURE your codex, cursor, Claude code Harvey, glean, legora instances now!
3. Do not try and build your own - I have already experienced enterprise customers building gateways and tools for agents - security companies have thousands of specialists working on this, leverage them, Focus on AI adoption instead. Partner to secure.
4. Securing agents is a complex problem - securing the agentic lifecycle - real time inspection and kill switches are key. Don't fall in the discovery and posture trap (Visibility - process understanding - intent interpretation - ability to stop inline are key tenets to the agentic lifecycle - not identity, posture and inventory - those are mere building blocks)
5. Only use enterprise protected models, single tenant, firewalled, inspected implementations - this is your IP you are playing with - LLMs have shown they will cross boundaries to capture the flag - you think your IP is safe? Once you train an unprotected model with your IP - you can't reverse the trade.
6. Perhaps the most important one - do not use a security tool built by the same person who is selling you the AI implementation, historically IT vendors are different from security vendors. You need an enterprise solution for security and it must work on your diverse infrastructure. Use a pure play security partner.
Happy building with AI.