The AI Control Loop: The Enterprise AI Accountability Moment – with Shayne Higdon of Wallarm
Today, we are dropping our final episode in our series The AI Control Loop, How enterprises govern the AI they've already deployed - sponsored by our friends at Wallarm.
Wallarm is the AI Control Platform for Enterprise AI, protecting every AI workload, API, and application in production, giving CISOs the governance they need and CIOs the speed they demand. Organizations choose Wallarm for a complete inventory of APIs, AI agents, and AI apps, patented AI/ML-based threat detection and blocking that operates at production traffic speeds.
In our final episode, we are joined by Shayne Higdon, Wallarm CEO, who closes the series by examining what the accountability moment demands from enterprise leaders, what a mature AI governance model needs to prove rather than promise, and what the next 12 to 24 months look like for organizations that get this right.
Questions
- Why is now the accountability moment for enterprise AI?
- What has changed between the early days of AI experimentation and today's enterprise AI deployments that makes accountability such a pressing issue?
- When we talk about AI accountability, what does that actually mean in practical terms? Are we talking about visibility, auditability, enforcement, ownership—or all of the above?
- As organizations race to deploy AI, how should CIOs balance the speed of transformation with the responsibility to govern it effectively?
- Why are traditional governance and security models struggling to keep pace with the way AI is being adopted across the enterprise?
- Given those challenges, how should boards and executive teams evaluate whether their organizations are truly ready to scale AI safely and responsibly?
- And once an organization believes it's ready, what does a mature AI governance model actually need to prove - not just promise?
- From an operational standpoint, how do capabilities like discovery, runtime monitoring, and enforcement come together to create a closed-loop approach to AI accountability?
- Stepping back and looking across this entire conversation, what's the one mindset shift every enterprise leader needs to make when it comes to AI security and accountability?
- And finally, as listeners think about what's ahead, what should they expect the future of AI security and accountability to look like over the next 6, 12, or even 24 months?
Links
Full Abstract
Abstract: Join Shayne Higdon, Wallarm CEO, for this episode, which closes the series by examining what the accountability moment demands from enterprise leaders, what a mature AI governance model needs to prove rather than promise, and what the next 12 to 24 months look like for organizations that get this right.
AI deployment is not waiting for governance to catch up. Across most enterprises, the gap between how fast AI is being adopted and how well it is being governed is widening every quarter. CIOs and CISOs are not debating whether to govern AI. They are trying to figure out how, under real organizational pressure, with tools and frameworks that were built for a different threat model.
That pressure is coming from every direction at once. Boards want AI transformation to move fast. Regulators want documented evidence that it is under control. Security teams want runtime visibility and enforcement capabilities that most of their current tools do not provide. And the AI systems themselves are not waiting: they are accessing data, calling external services, and making decisions continuously, in ways that after-the-fact governance cannot meaningfully constrain.
This is the accountability moment. Not because the risk is new, but because the consequences of undermanaged AI are now concrete enough to land on a board agenda, an audit report, and a regulatory deadline at the same time. What accountability actually requires in practice is the full AI control loop: knowing what AI is running across the enterprise, seeing what it is doing at runtime, enforcing policy before damage compounds, and generating continuous evidence that the governance is real and not retroactive. Organizations that can demonstrate all four are in a fundamentally different position than those still assembling audit evidence from spreadsheets the week before a review.
Our Sponsors:
* Check out Cash App and use my code CASHAPP10 for a great deal: https://cash.app
* Check out Plaud AI and use my code CODESTORY for a great deal: https://plaud.ai
Advertising Inquiries: https://redcircle.com/brands
Privacy & Opt-Out: https://redcircle.com/privacy
[SPEAKER_01]: Hello listeners, today we are dropping the final episode in our series entitled the AI Control Loop.
[SPEAKER_01]: How Enterprise is govern the AI they've already deployed, sponsored by our friends at Wallarm.
[SPEAKER_01]: Wallarm is the AI Control Platform for Enterprise AI, protecting every AI workload, API, and application in production, giving CSOs the governance they need and CIOs the speed they demand.
[SPEAKER_01]: Organizations choose Wallarm for a complete inventory of APIs, AI agents, and AI apps using patented AI ML-based threat detection, and blocking the operates at production speeds.
[SPEAKER_01]: In our final episode, we are joined by Shane Higden, while I'm CEO, who closes the series by examining what the accountability moment demands from enterprise leaders.
[SPEAKER_01]: What a mature AI governance model needs to prove, rather than promise, and what the next 12 to 24 months look like for organizations that get this right.
[SPEAKER_01]: Shane, thanks for being on the show today.
[SPEAKER_01]: Thank you for being on code story.
[SPEAKER_01]: Thanks a lot.
[SPEAKER_01]: No, I really appreciate you having me.
[SPEAKER_01]: I'm looking forward to it.
[SPEAKER_01]: Absolutely.
[SPEAKER_01]: Me as well.
[SPEAKER_01]: Really excited to dive into our topic for today, which we'll get in just a second.
[SPEAKER_01]: But before we do, tell me in my audience a little bit about you.
[SPEAKER_00]: Yeah, so I'd been an enterprise software for about 25, 26 years.
[SPEAKER_00]: I started my career as a pre-sales consultant many years ago at a company called BMC Software.
[SPEAKER_00]: Largely grew up at Quest Software, where I did a lot of different things there.
[SPEAKER_00]: Ran merges and acquisitions created a corporate venture arm.
[SPEAKER_00]: Ran a couple of business units in the application performance management space, the desktop management space,
[SPEAKER_00]: And then went back to BMC between there I ultimately ran an identity and access management company that we sold to RSA.
[SPEAKER_00]: And then I went back to the MC software where it was president of the division focused on performance and analytics.
[SPEAKER_00]: And then left after the exit to KKR.
[SPEAKER_00]: And I had just played around in the market leveraging new technologies, looking at new technologies like blockchain and other things.
[SPEAKER_00]: and then found myself here trying to help out Waller.
[SPEAKER_01]: Fantastic, it sounds like you've had an epic career and done some amazing things.
[SPEAKER_01]: It sounds like it's been an interesting path you've walked.
[SPEAKER_01]: Let's dive into the meat of the today, then.
[SPEAKER_01]: So a title for the episode today is the Enterprise AI Accountability Moment.
[SPEAKER_01]: Before we go too far, why is now the Accountability Moment for Enterprise AI?
[SPEAKER_00]: AI really stopped being a side project.
[SPEAKER_00]: I think as individuals leveraging things like chat, GPT or GROC or other models that were assistive in nature, it was a neat thing, however about 18 months ago, most of what
[SPEAKER_00]: I saw inside the enterprise was a chatbot bolted on to support Q trying to do things something a few power users might have played with on their own laptops but now you've got so many organizations that are allowing it to touch production data.
[SPEAKER_00]: They're calling APIs, they're making calls that affect
[SPEAKER_00]: A customer before a human can ever take a look at it.
[SPEAKER_00]: And this whole idea of human in the loop is still important.
[SPEAKER_00]: But when I talk to CSOS now, the question has changed.
[SPEAKER_00]: It used to be, are you using AI?
[SPEAKER_00]: Now, it's what did your AI do last week?
[SPEAKER_00]: Or, and can you prove it?
[SPEAKER_00]: For importantly, that shift really has less to do with, I think, the underlying risk.
[SPEAKER_00]: Being new and more to do with the exposure, getting concrete enough to really be focusing at a board level.
[SPEAKER_00]: What are we doing?
[SPEAKER_00]: How are we making sure that our agents, the way we're deploying AI is not giving hackers keys to the kingdom?
[SPEAKER_00]: Are we aligned with regulatory deadlines and requirements?
[SPEAKER_00]: I think that's the accountability moment and it's less a slogan today and really more of a problem to get our arms around, right?
[SPEAKER_00]: The three different audiences are asking the same question.
[SPEAKER_00]: It's the management team, the board, and customers at the same time.
[SPEAKER_00]: Companies want to make sure that if I'm going to do business with you, a year leveraging AI, that you're protecting the assets of the company, which has a customer includes my data,
[SPEAKER_00]: you've got to do the right thing to be accountable to have transparency and to be audible.
[SPEAKER_01]: I really like how you put that, especially the part we said AI is no longer a side project.
[SPEAKER_01]: Become a foundational element that is expected.
[SPEAKER_01]: But what is changed between the early days of AI experimentation, right?
[SPEAKER_01]: Maybe that's the side project era.
[SPEAKER_01]: And today's enterprise AI deployment that makes accountability such a pressing issue right now.
[SPEAKER_00]: Like I said, when early on, it was just you and I leveraging chat, GPT.
[SPEAKER_00]: It was really individualistic.
[SPEAKER_00]: It might have been assistive.
[SPEAKER_00]: It was I stopped going to Google to do a search.
[SPEAKER_00]: Instead, I would choose one of these interfaces.
[SPEAKER_00]: to be able to ask a question.
[SPEAKER_00]: Someone may have had a chat GPT tab open or something like Microsoft Co-Pilot helping them write code.
[SPEAKER_00]: If that person left the company, the whole pad of how a particular thing was getting written left with them.
[SPEAKER_00]: What's that?
[SPEAKER_00]: What mini-call tribal knowledge?
[SPEAKER_00]: It was contained by default, right?
[SPEAKER_00]: It was in, if you were writing code, it was in a repository.
[SPEAKER_00]: It was, you had a backup from a developer perspective, so someone could take over.
[SPEAKER_00]: I think what's different now, though, is that AI is starting to be wired into the systems and they're rethinking the workflows.
[SPEAKER_00]: How can I take a workflow?
[SPEAKER_00]: And first of all, can I make it agetic?
[SPEAKER_00]: But then, there's just completely different workflows that simply weren't possible because of machine speed where humans couldn't have done them in the past, right?
[SPEAKER_00]: So now, an agent has access and context and in a growing number of cases, it can act on its own.
[SPEAKER_00]: And honestly, I can call an API, I can trigger an integration without anyone signing off on it.
[SPEAKER_00]: I think that's, it's connected to customer data internal systems that the risk, the profile and risk associated to it just gets bigger.
[SPEAKER_00]: We call it in cybersecurity if something goes wrong.
[SPEAKER_00]: The blast radius, it just turns into a different problem entirely and I put it this way.
[SPEAKER_00]: to AI actually being one of the things doing the job, right?
[SPEAKER_00]: And it's what we're calling a Gentic operators.
[SPEAKER_00]: So how can a company, whether you're a vendor like Walmart, or whether you're a retail company, or whether you're a manufacturing company, how do you leverage the proprietary things that you do?
[SPEAKER_00]: and create agentic operators on top of that to help automate and make your workflows and make your business much more optimal and efficient.
[SPEAKER_01]: That makes so much sense the way that you put that and the agents are essentially going and doing the work of a person and you would
[SPEAKER_01]: hold that person accountable to do those actions, but now we need to be able to hold AI accountable.
[SPEAKER_01]: And when we talk about AI accountability, what does that actually mean in practical terms, right?
[SPEAKER_01]: So we can eat, touch, I think you can touch around or dance around this a bit, but when we're talking about, are we talking about visibility, auditability, enforcement, ownership, or all of things?
[SPEAKER_00]: It's really all of it, right?
[SPEAKER_00]: So I personally try to resist the temptation to just pick one because I think most vendors while I'm included, if we're not careful, we're going to just pitch whatever piece we're the strongest at, right, many times.
[SPEAKER_00]: So it starts with knowing, I think, what AI exists in your company.
[SPEAKER_00]: So can you do an inventory of where things running and who own them, but you'd be surprised at how often the first question doesn't really have a clear answer.
[SPEAKER_00]: Right?
[SPEAKER_00]: From where you need to know what it can touch and reach to what it's actually doing at runtime, not just what it was designed to do, right?
[SPEAKER_00]: So auditability really, really matters, but evidence, you assemble after something has already happened.
[SPEAKER_00]: It's a record, right?
[SPEAKER_00]: I want to record what happened, but it does not allow you to control what's going to happen.
[SPEAKER_00]: Right?
[SPEAKER_00]: So the piece that I think people underestimate is the enforcement.
[SPEAKER_00]: The ability to stop something before the risk turns into a real incident, not just right it up afterwards, right?
[SPEAKER_00]: So when I think about a lot of our customers for Ballar, we've been in line enforcement of transactions for about 12, 15 years.
[SPEAKER_00]: Many of our customers like to hear that, hey, if something goes wrong, you can block.
[SPEAKER_00]: You can enforce, you can do something.
[SPEAKER_00]: And in that scenario, that's great to hear, but many of our customers are also afraid that if I do block something, if I do stop something, I'm going to break the application or the workflow, and I don't want to do that because maybe it's a part of my supply chain.
[SPEAKER_00]: In a world where agents are actually doing something and agents may not be able to reason their way out of a problem.
[SPEAKER_00]: We think I think that there is going to be a real interest in being able to enforce to block in real time agents, in particular, non-human identities, right?
[SPEAKER_00]: Where agent goes rogue, no questions ask, we just shut it down.
[SPEAKER_00]: We block it in real time.
[SPEAKER_00]: I think we're going to see that more and more than we have in the past.
[SPEAKER_01]: Yeah, certainly.
[SPEAKER_01]: I think that's going to have to be a requirement and just it's clicking with where things are going as organizations race to deploy AI because as we talked about, it's not a side project anymore.
[SPEAKER_01]: It's the real deal.
[SPEAKER_01]: It's foundational.
[SPEAKER_01]: How should CIOs balance the speed of transformation with the responsibility to govern it effectively?
[SPEAKER_01]: This is an age-old question of
[SPEAKER_01]: how fast you move and break stuff versus how much you provide the right governance and boundaries in my right places.
[SPEAKER_00]: I don't think speed and governance are actually opposed to one another.
[SPEAKER_00]: I do crossfit and in that I've had my coach tell me before slow is smooth as fast.
[SPEAKER_00]: And it's a similar concept right here that I think a false choice that gets repeated a lot, good governance is what lets AI scale really past the pile of stage without someone in security or legal for that matter hitting the brakes and saying six months and stop you're done.
[SPEAKER_00]: And I've seen that happen, right?
[SPEAKER_00]: A team ships fast, gets traction,
[SPEAKER_00]: And then runs to a strict security review or a compliance question that nobody thought about at the start, right?
[SPEAKER_00]: And the whole thing stalls when it should actually be accelerating.
[SPEAKER_00]: So I think good governance upfront, the organizations that actually move the fastest over the
[SPEAKER_00]: I don't know, I'd say a couple of years of time horizon or the ones that actually build a trusted controlled path for AI adoption so that they're not relocating and trying to help convince everyone to trust every time they want to expand the footprint of AI in the enterprise.
[SPEAKER_00]: So I think the CIOs job in this new world and this is many see this as an extension of AI
[SPEAKER_00]: The Seattle's job, I don't think it's to slow down to make it safe.
[SPEAKER_00]: It's to make it safe enough so that speed doesn't really hurt.
[SPEAKER_00]: It doesn't really matter, right?
[SPEAKER_00]: And I think that's what's really important.
[SPEAKER_00]: This idea of slow is smooth as fast.
[SPEAKER_00]: And so if you do the right diligence, it's up front to really document.
[SPEAKER_00]: And
[SPEAKER_00]: have a pretty good understanding as to what you're doing, how you're going to be compliant, how you're going to audit, who's going to touch what, then you can begin to accelerate, you've got the proper security measures in place.
[SPEAKER_00]: So the by the time, the application, the agents or in production, the models that you're using, you're pretty confident that you've provided the necessary guardrails to be safe.
[SPEAKER_01]: Certainly, and I really like the line you said there from CrossFit.
[SPEAKER_01]: I think that illustrates the way to go forward here and where compliance and governance and innovation and speed shouldn't be mutually exclusive.
[SPEAKER_01]: But why are traditional governance and security models struggling to keep pace with the way that AI is being adopted across the
[SPEAKER_00]: They were simply built for a slower, more predictable world when I think about machine speed and when in attack occurs, you've got seconds before things are beginning to be exfiltrated.
[SPEAKER_00]: I think most governments today still runs on these kind of static inventories of systems and data and accordingly access review with who had access to what and what's yet to station.
[SPEAKER_00]: I think someone on the compliance team reading through logs after the fact is just simply it's antiquated.
[SPEAKER_00]: It's just simply too slow.
[SPEAKER_00]: And I think the model assumes the thing that you're governing does it change much between reviews, right?
[SPEAKER_00]: But that's not the case anymore, right?
[SPEAKER_00]: AI doesn't hold still.
[SPEAKER_00]: It doesn't stop.
[SPEAKER_00]: It doesn't wait for things to happen, right?
[SPEAKER_00]: It can call a different
[SPEAKER_00]: application, it can call a different API tomorrow that it did yesterday so the patterns are not the same.
[SPEAKER_00]: You can't govern something I think that operates continuously at machine speed with a process that simply checks things what's the coolest, just not going to happen.
[SPEAKER_00]: There's a real mismatch and a tools gap.
[SPEAKER_00]: when you try to do that.
[SPEAKER_00]: And so, static governance was really never built for a system that does a wait for you to look at.
[SPEAKER_00]: Right, and I think that's important.
[SPEAKER_00]: So you're going to have to, if it always on approach to the governance model and then being able to flag things that are outside the bounds of normal.
[SPEAKER_01]: Right on, that's totally clear.
[SPEAKER_01]: It was not what it was built for.
[SPEAKER_01]: And given those challenges, how should boards and executive teams evaluate whether their organizations are truly ready to scale AI safely and responsibly?
[SPEAKER_00]: I think they should really start with, can you tell me what AI is running across the company right now?
[SPEAKER_00]: And who owns it?
[SPEAKER_00]: It's a simple question, but today it's hard in many ways to figure that out.
[SPEAKER_00]: I've had CEOs tell me, I've got an AI first agenda and I told the company that we're going to be AI first and I've let people from various departments go roll your own model,
[SPEAKER_00]: And I think that's been in some cases from S, because you lose sight of who's doing what, right?
[SPEAKER_00]: And so if that takes three weeks or six people to assemble, I think that's your answer right there is that it's fairly difficult.
[SPEAKER_00]: The hard to follow up I think is what data it can touch, what systems it can reach, and then whether or not you can detect and stop that risky behavior.
[SPEAKER_00]: The other thing that we're seeing is that how do you, when you start moving towards an AI first approach, how do you look at token spend?
[SPEAKER_00]: How do you allocate token spend to various departments?
[SPEAKER_00]: You're going to get one bill from anthropic or you're going to get a bunch of different bills, right?
[SPEAKER_00]: You may get a
[SPEAKER_00]: When AWS build using bedrock, which has all the front-tier models, and at some level, as the CFO, you're seeing these bills that you're having to pay for in tokens, but how are you then breaking that down and understanding that Noah, who's developing an application, is spending this amount of tokens on a monthly basis to write that, and how productive is he.
[SPEAKER_00]: chains in the sales organization and he's spending to write an agent or skill to do a bunch of things to prep for various sales calls.
[SPEAKER_00]: And so getting your arms around that I think is more difficult.
[SPEAKER_00]: And so I think the real board level question is pretty simple.
[SPEAKER_00]: Even if the answer usually isn't, can you prove your AI's operating inside the boundaries you intended right now, but it can't be last quarter's audit is the way to look at it.
[SPEAKER_00]: So how do you have this real-time dashboard that at any moment, if as a CEO, you're asked that you can generate a point in time, but just in time inventory for all things AI across your enterprise.
[SPEAKER_00]: It's going to be hard to get there.
[SPEAKER_00]: It's going to take a lot of planning up front, but I think that is the next step that a lot of boards are going to expect good stuff.
[SPEAKER_01]: Okay.
[SPEAKER_01]: You said something there that I think my aunt just wanted to dive into a little bit more about what does an enterprise need to prove, right?
[SPEAKER_01]: You said it prove that it can run within the boundaries.
[SPEAKER_01]: What is the mature AI governance model actually need to prove in doing that?
[SPEAKER_01]: Not just promise.
[SPEAKER_00]: Yeah, so it needs to show that it's actually working continuously.
[SPEAKER_00]: Just not producing a good story once a year.
[SPEAKER_00]: Hey, we've adopted AI.
[SPEAKER_00]: This is what we've done.
[SPEAKER_00]: It needs to specifically and concretely show that AI assets across the company.
[SPEAKER_00]: are being discovered on an ongoing basis, not just inventoryed once and then thrown away for gotten that each one has an owner, I believe that we're going to see more and more organizations having an agentic manager, right, a person that is going to manage, and I don't know what the ratio is, one person to 50 agents or 80 agents or 100, I don't know what that percentage is going to be.
[SPEAKER_00]: But I think we're going to see that more and more because it needs to show that those systems what they did, what policies were applied, it needs to create a clean record of where something violated that policy and then what did the organization do about it?
[SPEAKER_00]: Right?
[SPEAKER_00]: So I think that's the real dividing line is whether that evidence gets generated as a byproduct of a system running.
[SPEAKER_00]: or whether someone has to go build it for scratch the week before and audit.
[SPEAKER_00]: Honestly, I've seen both, and you can tell within the first five minutes of a meeting, which one the company's doing.
[SPEAKER_00]: So I think that's a real test of maturity for organizations, a running record of control that exists, or not, right?
[SPEAKER_00]: And then if anyone asks for it that week, not a policy statement, somebody wrote down just once and said, hey, this is what we do,
[SPEAKER_00]: But actually, proving, showing the report, the evidence, like I said, I call it just in time, I inventory, almost like just in time, supply chain.
[SPEAKER_00]: We're going to have to do the same thing, because if you allow your organization.
[SPEAKER_00]: the freedom to decide what they want to use for whatever their business case, their workflow, their function, then you're going to have to give them, you're going to have to have some way of casting a wide net to always be understanding.
[SPEAKER_00]: We call it shadow AI, so as companies are leveraging this and developer going directly to an external model that's sharing a
[SPEAKER_00]: You probably don't want that to happen.
[SPEAKER_00]: How do you stop it and make sure that doesn't occur?
[SPEAKER_01]: Good stuff.
[SPEAKER_01]: I love that you said from five minutes into the meeting, you can really see the folks that are actually accomplishing this sort of thing and holding their AI accountability.
[SPEAKER_01]: And that's evidence that operationally, you know, they can support this in real-time.
[SPEAKER_01]: On that operational standpoint,
[SPEAKER_01]: how do these capabilities like discovery, run time monitoring, enforcement, et cetera come together to create that closed loop approach for AI accountability.
[SPEAKER_00]: You have to think of it as I think a couple of questions at one of which I just talked about getting continuous answers, not just once.
[SPEAKER_00]: Discovery is considered that map, right?
[SPEAKER_00]: What AI exists, where it's running on what infrastructure, what's it connected to?
[SPEAKER_00]: That gives you that disability that you may or may not have had,
[SPEAKER_00]: Then runtime monitoring is going to tell you what it's actually doing once it's in motion.
[SPEAKER_00]: I think which is often not the same thing as what it was designed to do.
[SPEAKER_00]: Enforcement though is what really closes the loop.
[SPEAKER_00]: You discovered something, you're monitoring it in runtime.
[SPEAKER_00]: At what point do you decide that you need to enforce a policy?
[SPEAKER_00]: Which is the ability to actually stop something before the consequence compounds.
[SPEAKER_00]: And that's where I was talking about earlier.
[SPEAKER_00]: I think that's going to be really important with not human identities.
[SPEAKER_00]: You're going to see an agent do something or go rogue or make a decision based on its context that you may not want it to make and you're going to want to enforce a policy.
[SPEAKER_00]: You're going to want to shut it down right now so that the blast radius is small.
[SPEAKER_00]: And then you're going to want to record of all of that.
[SPEAKER_00]: Now you're back to governance's documentation.
[SPEAKER_01]: right on.
[SPEAKER_01]: Okay.
[SPEAKER_01]: So stepping back and looking across our entire conversation, which has been really illuminating on how to hold AI accountable and what businesses need to actually do, what's the one mindset shift?
[SPEAKER_01]: Every enterprise leader needs to make.
[SPEAKER_01]: When it comes to AI security and accountability, what mindset shift do they need to make?
[SPEAKER_00]: It's a good question.
[SPEAKER_00]: I think an operating environment, it's AI is that operating environment.
[SPEAKER_00]: Now, it's not a single component that you ultimately just have a litmus test to say, I've got AI now.
[SPEAKER_00]: I've got models, or I've got APIs, or I've got identities, data, agents, workloads,
[SPEAKER_00]: So I think companies have to stop treating this as, oh, do I have the best model?
[SPEAKER_00]: It's a model problem that I've got, or I've got a prompt problem.
[SPEAKER_00]: I think the real challenge is governing what the whole connected system does.
[SPEAKER_00]: Right, when is it actually allowed to act on its own?
[SPEAKER_00]: Not protecting each of the pieces separately, right?
[SPEAKER_00]: You deploy an MCP server to connect to external services.
[SPEAKER_00]: When I look at all admit, I think this is the harder version of the problem for most tooling, but still built around the easier component level one systems.
[SPEAKER_00]: Pulling it all together, I think it's going to be really important because I don't think AI security is about locking down a model.
[SPEAKER_00]: It's about governing behavior across a system and a complex system at that that that doesn't respect the expectations that we have drawn for the organization, right?
[SPEAKER_00]: The AI agents oftentimes have if you've given them a lot of context they have a boundless way of being able to act as so how do you bound them without limiting their ability to be productive and efficient?
[SPEAKER_01]: awesome.
[SPEAKER_01]: I appreciate you walking through all that.
[SPEAKER_01]: I got one more question, Shane, so as listeners think about what's ahead.
[SPEAKER_01]: Where the industry is going and how fast it's moving.
[SPEAKER_01]: What should they expect the future of AI security and per our topic, the accountability to look like over the next 6, 12 or even 24 months?
[SPEAKER_00]: I think we're seeing now, and I'm not really good at predictions, but I think a few months, we're seeing it now, but I think we're going to continue to see most companies move from this enthusiasmistic.
[SPEAKER_00]: I'm using AI into check a box.
[SPEAKER_00]: to actual control requirements, they're going to need to make sure that they are boxing in and guard railing exactly how they're using AI because I think boards and regulators are going to keep asking questions and CEOs are going to say, and CIOs are going to say, we have a policy, I just think that's not going to be enough.
[SPEAKER_00]: I think a year from now, maybe less, I think runtime visibility and enforcement is simply going to be table stakes.
[SPEAKER_00]: where for any AI program, the pilot stage is over.
[SPEAKER_00]: It's not something a security team is going to ask for later, right?
[SPEAKER_00]: The timeline itself, I think, gets less interesting than really how it shakes.
[SPEAKER_00]: I think the gap widens between companies producing continuous evidence of how the AI is governed.
[SPEAKER_00]: and company still assembling their evidence by hand before review right I don't think it closes gradually I think it's I think it's gonna feel like to ventures like us it's gonna feel like a big bang it's gonna show up all it wants usually the first time one of the companies has an incident
[SPEAKER_00]: and the other doesn't or has one and has an incident and can explain exactly what happened within the hour.
[SPEAKER_00]: I think that's going to be the expectation of expectation about partners, customers, is that happened?
[SPEAKER_00]: So what actually changes over the stretch is proof, real time control with evidence attached to it, not a better written policy sitting in some shared drive somewhere inside the enterprise.
[SPEAKER_00]: And I think that's going to be the testament to organizations that are governing AI in those that are not.
[SPEAKER_00]: Poor those that are just earlier on their journey and are less mature.
[SPEAKER_01]: I think that's couldn't agree more Shane.
[SPEAKER_01]: I really appreciate being on the show today.
[SPEAKER_01]: It's very clear.
[SPEAKER_01]: And so you said in the beginning, which I really liked, AI is no longer a side project.
[SPEAKER_01]: Agents are doing the work of people.
[SPEAKER_01]: And as such, they need to be held accountable.
[SPEAKER_01]: Enterprises need to understand where and how AI is being used in the organization.
[SPEAKER_01]: Without the just-and-time AI capabilities that key reference, businesses won't be able to achieve AI accountable.
[SPEAKER_01]: Enterprises need to change the way they think change their mindset and understand the whole connected system.
[SPEAKER_01]: Understanding when the system is allowed to function on its own and when it needs to be restricted.
[SPEAKER_01]: As you said, as we talked, it's a hard problem to solve, but the time is now to start addressing it.
[SPEAKER_01]: So, really appreciate you being on the Shio Shainer's great conversation.
[SPEAKER_00]: Likewise, Noah, thank you for the questions, really appreciate it, and look forward to being here again soon.
[SPEAKER_01]: As evident from Shane's answers, the time is now for enterprises to address AI accountability.
[SPEAKER_01]: Without it, they'll be behind the curve in terms of security and proof to customers, investors, and the market at large.
[SPEAKER_01]: We hope you've enjoyed our series, the AI Control Loops, sponsored by our friends at Wal-R.
[SPEAKER_01]: If you'd like to learn more about the company, you can visit Wal-RRM.com.
[SPEAKER_01]: That's W-A-L-L-A-R-M.com.
[SPEAKER_00]: And thanks again for listening.
Podbean