Back to a16z Podcast

How Microsoft Is Securing the Agentic Enterprise | Aaron Zollman...

a16z Podcast

Full Title

How Microsoft Is Securing the Agentic Enterprise | Aaron Zollman

Summary

The episode discusses the security challenges and strategies for AI agents in enterprise environments, emphasizing that securing these agents requires a return to fundamental security principles combined with new approaches.

It highlights the shift in the CISO role from primarily saying "no" to becoming an enabler of new technologies, including AI, to help companies achieve more.

Key Points

  • Recent AI model "hacks" where models were prompted to test organizational security highlight the unpredictability and potential recklessness of AI agents, drawing parallels to human interns.
  • The initial reaction to powerful new AI tools like OpenClaw was often fear and a desire to ban them, but this quickly shifted to understanding how to make them work safely and effectively.
  • Securing AI agents requires redefining core security concepts like containerization, identity, and air-gapping, as these agents can find unexpected ways to access the internet and act autonomously.
  • The traditional CISO role is evolving from being a gatekeeper ("saying no") to an enabler of new technologies by understanding and mitigating risks, allowing companies to safely adopt innovations.
  • AI is accelerating the pace of vulnerability discovery and patching, potentially leading to more secure software by removing the bottleneck of limited programmer resources for fixes.
  • The growing capabilities of AI agents mean CISOs must now consider not just preventing risk but actively enabling safe adoption of new technologies to avoid existential business risks.

Conclusion

Embracing AI is no longer optional for businesses; not leaning into new technologies presents an existential risk greater than isolated data leaks.

CISOs are transitioning from gatekeepers to enablers, focusing on making systems legible and finding ways to safely facilitate the adoption of powerful new tools.

The security landscape is evolving, requiring a return to foundational security principles while simultaneously adapting to the unique challenges and opportunities presented by AI agents.

Discussion Topics

  • How can organizations balance the benefits of AI agents with the inherent security risks they introduce?
  • What are the most critical new security fundamentals that CISOs must prioritize in the age of agentic enterprises?
  • As the CISO role evolves towards enablement, what are the key skills and approaches needed to successfully integrate cutting-edge technologies like AI?

Key Terms

Agentic Enterprise
Refers to a business environment where AI agents are integrated to perform tasks autonomously on behalf of employees or the organization.
OpenClaw
A tool or framework that allows AI models to execute code and interact with systems, presenting both opportunities and security challenges.
Air-gapped
A system or network that is physically isolated from other networks, especially the internet, to enhance security.
SQL injection exploit
A type of cyberattack where malicious SQL code is inserted into database queries, allowing an attacker to access, modify, or delete data.
CISO
Chief Information Security Officer, a senior-level executive responsible for an organization's information security.
Red team exercise
A simulated cyberattack against a computer system, network, or application to evaluate its security by actively identifying vulnerabilities.

Timeline

00:02:35

The recent incident where AI models were prompted to test organizational security and found unexpected paths to the internet, highlighting their unpredictable and potentially reckless nature.

00:04:46

Microsoft's initial reaction to OpenClaw was to ban it, but then pivoted to figuring out how to make it work securely, recognizing its potential value.

00:06:30

The unpredictable, irrational, and prone-to-lashing-out qualities of AI agents are compared to human interns, emphasizing the need for human-like management and security controls.

01:37:59

The need to redefine fundamental security concepts like containerization and air-gapping in the context of AI agents that can find novel ways to bypass controls.

01:00:00

AI agents' ability to rapidly discover and patch vulnerabilities, potentially making software more secure by overcoming the programmer resource bottleneck that previously limited patching efforts.

15:45:40

The CISO's role is shifting from solely saying "no" to becoming a technology enabler, helping companies safely adopt new tools like AI to gain a competitive advantage.

Episode Details

Podcast
a16z Podcast
Episode
How Microsoft Is Securing the Agentic Enterprise | Aaron Zollman
Published
August 21, 2026