Security veteran: spreadsheets and phishing training won't secure us from AI agents
chrisrohlf · x · 2026-09-29
Security practitioner chrisrohlf argues that the industry's reflexive "security is about balancing tradeoffs with the business" mindset is exactly why the security industry — and many corporate InfoSec programs — are failing to keep pace with securing against (and with) AI agents.
Risk tracking spreadsheets, phishing education, threat intel, manual appsec: none of it was built for this era's challenges. "What got us here won't get us there" — he calls for willingness to make big changes to how security is done.
More from Safety
- 'Successor species' talk is a distraction: AI firms lack verification and zero-trust deployment controls — AlexTensor · 2026-09-29
- Free Agent Protocol Inspector generates IGA-style review packets for MCP/A2A capabilities — ContextIQ · 2026-09-29
- Researcher's advice for AI CEOs: beg for regulation so rivals can't cut corners — jd_pressman · 2026-09-29
- KatjaGrace: Pausing frontier AI is right when needed, don't take AI CEOs' word on it — KatjaGrace · 2026-09-29
- Gary Marcus: OpenAI's safety lapse was arrogance; Nvidia's new safety platform may help — GaryMarcus · 2026-09-29
- Andrew Ng links OpenAI hack to weak sandboxing as Nvidia open-sources agent sandbox tools — hwchase17 · 2026-09-29