What happens when an AI agent is compromised, manipulated, or simply does something nobody expected, but already has permission to access your most sensitive systems?
In this episode of Tech Talks Daily, I speak with Geoffrey Mattson, CEO of SecureAuth, about why securing enterprise AI requires businesses to think beyond protecting models and start paying much closer attention to identity, authorization, access control, and what AI agents are actually allowed to do.

Geoffrey argues that AI agents present a different security challenge from traditional software. Conventional applications can be tested against relatively predictable behavior. AI models are far less deterministic, particularly when prompt injection, excessive permissions, unexpected behavior, and autonomous actions enter the equation.
His advice is to assume an agent could behave unpredictably and control what happens when it attempts to access a database, execute a financial transaction, call an API, or interact with another business system.
We discuss what this means as companies race to introduce agentic AI. Geoffrey shares examples of employees granting AI tools permissions without fully understanding what they have approved, along with agents gathering information that creates unexpected privacy and compliance problems.
This creates a difficult challenge for CIOs and CISOs. Boards want AI adoption because of its potential competitive value, while employees increasingly depend on AI tools to do their jobs. Simply blocking agents is unlikely to work. Security teams instead need mechanisms that allow innovation while controlling what those agents can access.
Geoffrey explains why Zero Trust becomes particularly relevant here. Rather than authenticating a user or agent once and assuming it remains trustworthy, enterprises need to continually evaluate whether an action should be permitted at that specific moment.
This leads to the concept of continuous authorization. Geoffrey explains how identity security is moving from asking "Who are you?" toward understanding intent, behavior, context, and authority for individual actions. This becomes increasingly important when one AI agent can create sub-agents, which can then create additional agents and pass permissions down the chain.
We also discuss why agentic AI is exposing years of accumulated security debt. Many of the underlying problems are familiar: excessive privileges, inconsistent access controls, incomplete Zero Trust implementations, and systems that trust identities for too long. AI agents amplify those weaknesses because they can operate at machine speed.
Geoffrey describes this as combining the unpredictability of humans with the power of machines.
For CIOs, CISOs, security architects, identity teams, and business leaders deploying agentic AI, this conversation offers practical questions to ask before connecting agents to enterprise resources. What can the agent access? What authority does it have? Can that authority be reduced as tasks are delegated? Is every important action evaluated independently? And can access be revoked immediately when behavior changes?
The goal is not to prevent organizations from using AI agents. It is to create a security layer that gives developers and employees room to experiment while ensuring agents only have the authority they need at the moment they need it.
As autonomous AI becomes part of the enterprise workforce, identity alone may no longer be enough. Businesses increasingly need to understand intent, control authority, and continuously decide whether the next action should be allowed.
Useful Links
Connect with Geoffrey Mattson
Learn more about SecureAuth
[00:00:00] Are you still dealing with agentic AI semantic confusion? Well, Denodo keeps your business harmonized. And by positioning your data platform into a universal semantic layer, everybody can be on the same page. So get back to scaling your business and trusting your AI agents to create proper business decisions. And you can do that by visiting denodo.com to see how. But now, back to today's guest.
[00:00:33] Question for you all, what will happen when the newest threat actor inside your business is actually a member of the C-suite experimenting with AI at the weekend, doing a bit of vibe coding? Well, as AI agents gain access to company data, financial systems, APIs, and business workflows, securing the model itself might no longer be enough. Because my guest today is Jeffrey Mattson. He's the
[00:01:01] CEO of a company called SecureAuth. And he's going to be joining me to explain why AI agents can combine the unpredictability of humans with the speed of machines. Because we're going to explore why identity security is currently facing somewhat of a serious wake up call. And we'll talk about why businesses must control
[00:01:24] what every agent is allowed to do. And do it before thousands of autonomous systems all start acting on their behalf. We're going to have lots of practical takeaways today. And I'm really looking forward to hearing from you at the end on your experiences. But for now, let me introduce you to my guest so we can get this conversation started. So thank you for joining me on the show today. Can you tell everyone listening a little about who you are and what you do?
[00:01:54] Hi, thank you, Neil. My name is Jeffrey Mattson. I'm a serial entrepreneur living in Silicon Valley. And I'm currently the CEO of SecureAuth. Well, it's a pleasure to have you join me today. There's so much I've been reading about you before you join me on the show today. One is that you argue that AI agents themselves are not the biggest security problem. It's what they can access once compromised. And it's so refreshing to hear someone talk about this because we hear a lot around the hype and the noise of agents,
[00:02:23] but not the security conversations that much. So tell me a little bit more why you think the conversation needs to move away just from model security and more towards identity, authorization and access control. It's the real belts and braces of IT, really, isn't it? Yeah, that's a great question, Neil, because our whole orientation in software security is to look at a piece of software as something that we can test.
[00:02:51] And then we know what it does. It's reasonably deterministic and it's well behaved after it's been tested. And so we try to do in software security is just make sure nobody's tampered with it. Right. We have ways to attest that the software hasn't had anything bad injected into it. And then if it has, it is given a certain level of trust.
[00:03:12] And a problem with with it, with models is there's absolutely 100 percent certainty that there's no way to secure a model itself. And my reference for that is, you know, the company Anthropic, you know, which three weeks ago, I believe there was a ban by the U.S. government of foreign nationals using one of their one of their models
[00:03:41] because it was considered to be at heart a very, very powerful model that could be used as a cyber weapon. And what Anthropic had done is they had released that they put some guardrails around it. But what the the administration said is that the guardrails were inadequate and the Anthropic came back and said, look, no guardrail is adequate.
[00:04:07] Right. There's absolutely no way you can stop these things from being hijacked. In LLM, just from a from an intuitive point of view, they want to please whoever is interacting with them. And you can tell them, don't do this, don't do that. But somebody else can phrase do this and do that in another way or even, for instance, in another language. And that will get around whatever you told it not to.
[00:04:32] So unlike a traditional piece of software that's deterministic and predictable, a model is completely unpredictable and non-deterministic and can never have that same trust level that you would assign to to software itself. And so therefore, the real way you have to do is when you're using a model, just assume that it could do anything, anytime.
[00:04:55] And just make sure you put guardrails not within the model, but around it to make sure that if it tries to make a financial transaction, that it's approved and you know exactly what it's doing. If it tries to change a database record, that it is approved and you've recorded that. And you have to monitor them at all times in real time and make sure that they haven't gone rogue at any point, be it from prompt injection or just because sometimes, as you know, they're unpredictable.
[00:05:25] And over the last few months, prompt injection attacks have been getting a lot of attention, filling our news feeds with a lot of horror stories there. But you suggest, actually, this is only part of the story. So just for people outside the tech space listening, what are the real world risks that businesses could be overlooking when autonomous AI agents are connected to their sensitive systems, their data, their workflows? What are they missing here? What do they need to be aware of? Well, yeah.
[00:05:54] So this is a brave new world that we're seeing. And we have, you know, it's interesting. I got a call from a CISO, from a security officer for a major financial institution, one of our customers. And we serve some of the largest banks in the world, among other customers with critical security, identity security needs. Anyway, when he says something really interesting that I'd never heard before.
[00:06:20] He said, I have a new threat actor to worry about, and it's my C-suite. And I said, you know, okay, what are you talking about? And he said, yeah, I have a C-suite member who is vibe coding over the weekend. And they get these consent screens. So when you're coding with these agents, they'll say, can I access this? Can I access that? That's called a consent screen. And, you know, this executive wasn't even familiar with what he was approving, but he just, like, wanted to get through with it.
[00:06:49] And he says, okay, let's push through this nerdy stuff and continue with my amazing vibe coding. And as a result of that, he accessed data that was, you know, publicly leaked, and it was an incident. And so there's threats like that that we've never seen before. And we're also seeing agents trying to do their job collecting data, for instance.
[00:07:12] You know, there was an incident in another company where an agent was trying to determine, you know, who would be absent during different periods of time. But it was collecting information and creating a record of which women it thought was pregnant, which is, you know, in the U.S., I don't know. It's like in Europe, in the U.K., but in the U.S., it's a huge HR violation.
[00:07:35] So there's all kinds of, you know, these new, in addition to the traditional threats we've had with, you know, threat actors compromising software, there's a brand new set of this gray area of agents either doing what they're supposed to do and being over-permissioned or just doing it in a way that's so powerful that, you know, we haven't actually thought about the harm that it could cause.
[00:08:00] And over the last, what, five to ten years, we've heard a lot about zero trust for people and devices. But how does this concept evolve when the workforce starts adding into the mix AI agents that can make decisions, take actions and interact with enterprise systems on their own? It almost feels like blurred lines that we don't fully understand yet. I mean, you mentioned the CEO there that was vibe coding at the weekend, like almost like a small child playing with dangerous toys,
[00:08:27] not knowing that the danger that they were playing with there. But how do you see this evolving? Yeah, that is an excellent question. So for those of your audience who are not familiar with this concept of zero trust, it's a stance within cybersecurity that moves from the old model, the old paradigm of the castle and moat paradigm, which is everyone's familiar with a firewall.
[00:08:53] You know, at an early point in networking history, everyone thought, well, if I just put up a firewall, then whatever is outside the firewall is untrusted, whatever comes in is trusted. Zero trust says no, whatever comes in is still untrusted. You need to assume that you're breached right now. Most large companies and many small ones have threat actors that have already penetrated their defenses that are lurking, looking for opportunities.
[00:09:23] And what you need to do is you need to every time a system tries to access another system or a person tries to access something, you need to make a determination about whether or not they should be allowed to do that. And this is even more true with agentic AI. And that's why it's a little bit of a challenge because agents can do a lot and they can do a lot really fast. But as I said, they're completely non-deterministic and completely unpredictable.
[00:09:50] So they could be doing a lot of things and then suddenly they're fine. And then suddenly they do something that is completely unacceptable and may actually be harmful. So you need to keep up with the agent at very high volume and sort of micromanage it and make sure that every little thing that it does is acceptable. That kind of scale and performance is a bit of a challenge for a lot of security products,
[00:10:16] but it's 100% absolutely necessary if agents are going to be deployed safely within enterprises. And so far this year, the first six months, I've been to 16 tech conferences from Egypt to Vegas and predictably every single one of them had a agentic AI or agent focus about them. And as a result, many organizations are just rushing to deploy AI assistance and agentic workflow. So the question I've got to ask you, there's so much hype there and everyone's selling the solutions.
[00:10:44] What questions should a CIO or a CISO or business leader listening be asking before granting these systems access to their company's resources? Because I think there's maybe a lack of familiarity or not knowing what to ask. But what would you suggest? Yeah, you know, we've noted that we go to agentic AI conferences and there's all kinds of incredibly interesting content about what you can do with agents and new tools built around them. But there's very little focus on security right now.
[00:11:14] And because I understand that it's so much fun and it's so empowering and so delightful to deal with these agents. And then nobody wants to deal with the wet blanket aspect of security. And as you mentioned, you know, it's not, you know, there's just strategic push. There are boards that are telling their CEOs and therefore the CISOs are getting involved that we need to deploy agents as a competitive weapon and to streamline our organization, et cetera, et cetera.
[00:11:43] So there's a push from on high. But there's also a pull from the employees. We're saying from my cold dead hand, will you pry my, you know, co-pilot that I'm using, you know, to do my job? So they're in a position where they have both pressure from above and below to deploy agents. And they look like Dr. No or the biggest Luddite in history if they try to block it. But as I said, there's a lot of very serious challenges for them to deal with.
[00:12:13] And so the biggest one is, I think, is, you know, as you mentioned, this zero trust posture. You know, do they actually have zero trust implemented across the board for all of the applications that the agents will access? In many cases, I'd say, you know, it's fair enough to say right now they probably don't. And, you know, right now they need to start upgrading their security.
[00:12:36] And what we've seen is over the past two and a half quarters, I'd say, this huge surge in interest in deploying this type of solution. You know, I think that the models themselves have gotten much more powerful and respectable in this calendar year. And then there was an event where there was a widely publicized agent, you know, OpenClaw, which captured public imagination. And this thing has just taken on a life of its own.
[00:13:03] So we find security leaders are finding, you know, whatever is left over in their budget to deploy things this year and planning heavily for next in order to deal with this incoming tidal wave of agentic use cases. And before you join me on the show today, I was doing a little research on you looking at your work and what you're doing there. And continuous authorization is a phrase that comes up frequently in your work.
[00:13:29] So, again, for the business leaders listening, what does that mean in practical terms? And how does it differ from a traditional approach of authenticating someone or something once and then trusting them indefinitely? Because there's a slight difference here, isn't there? Oh, there is. Yeah, it's a great question there. You know, traditionally in identity security, there is a simple method where you have a point in time where you decide, is this Neil Hughes?
[00:13:58] You authenticate them once. And once you determine it's Neil Hughes, he can do whatever Neil Hughes is allowed to do. But what we've discovered is the bad guys have figured out that, you know, impersonating Neil Hughes or taking over his session while he's operating is a wonderful way to get access to whatever they want.
[00:14:19] So, continuous authorization, you know, this concept of continuous identity in the industry is to continually, you know, ask for proof that you are who you say you are. Continually make sure that you're not acting strangely to see if you might have been compromised. And, you know, we take this all the way from the first step in the chain, which is authentication, is figuring out who you are.
[00:14:46] And the next step is authorization, figuring out, you know, what you can do. And that joint concept is authority. So, we provide this continuous authority method that in real time makes a decision about for every action you take at this moment in time, should Neil be allowed to do that or not? And to the extent, should Neil's agent be allowed to do that as well, right? And, of course, this isn't your first rodeo.
[00:15:16] And throughout your career, you've led companies across networking, threat detection, critical infrastructure security, identity management. And that list goes on and on. And I'm curious, if you were to look back at that journey, are there any particular lessons from protecting everything for military energy and industrial environments that feel even more relevant now in this new age of AI agents that we find ourselves exploring? They say that history doesn't repeat, but it rhymes. But do you see anything there?
[00:15:45] Yeah, I see. Do I see anything? I see everything, Neil. I think basically, you know, agentic security has not caused any or created any new security issues, but it's taken all the security issues and made them front and center.
[00:16:04] It is basically we've accumulated a lot of tech debt in the industry in terms of, you know, leaving parts of our security posture open and exposed. And agentic is calling that tech debt bill due, right? And so basically, as I said, is it, you know, humans are unpredictable when we're dealing with, when we're managing them, they're unpredictable.
[00:16:31] But they're also, you know, slow relative to software, right? You can, I can give you the right to delete database entries and you can delete some, Neil. And if you're bad, you know, you can delete some important things. But we'll catch you pretty soon, right? Your agent can delete the entire database. It doesn't have what we call biological friction. So they're faster than humans.
[00:16:54] But then software, as I said, most software you could test and you can determine whether it's going to do X or Y. It's somewhat predictable. Agents are completely unpredictable, as we mentioned, right? So you have the unpredictability of humans with the power of machines. You need to just tighten up everything that they have access to. And so you mentioned, you know, working in areas in critical systems and working with, you know, highly targeted customers.
[00:17:23] It's exactly the types of things that we needed to do to tighten up those systems. They need to be applied across the board in the enterprise now. So, you know, Kurs will live in interesting times. Time for a cleanup on R9 and identity security across the industry. And identity has been considered the new security perimeter for some time now.
[00:17:47] And as AI agents inevitably continue communicating with other agents, APIs and business systems, I'm curious, how do you see identity and access management further evolving over the months and years ahead? Because even how we define identity is up for grabs possibly. Yeah, that's a very, very good question, Neil. And I really do think that, you know, the concept of identity, it used to be we figure out who you are or what you are.
[00:18:16] And then we can sort of assume that you'll operate within certain parameters. I think with agents, as I mentioned, they can go rogue anytime, either through prompt injection or some sort of compromise or just because they're, as I said, they're very unpredictable. So identity becomes more of a dynamic feature. We need to determine at any moment in time, are you behaving?
[00:18:46] You know, we move from your identity, your fixed identity to your intent. Right. And then we need to move from access to authority. You know, so so by that, I mean, you know, we've talked about agents, you know, and we've we've really sort of had this conversation about like one level agents, but agents will spawn sub agents, which will spawn sub agents.
[00:19:09] So you need to be able to pass your little bits of your authority down the chain to allow a swarm of agents or a network of agents to be able to accomplish something. But you need to be able to downscope that authority as it moves down the chain.
[00:19:25] So we're moving from, you know, this this idea of this fixed identity to more of a dynamic intent and more from a fixed authorization to more of a more of a transactional authority in the future. So, you know, really interesting. It's probably something that we should have done a long time ago for for conventional systems. But agents are really forcing us to do this.
[00:19:52] And if I was to pull out a virtual crystal ball here and fast forward to a future where every company will inevitably have thousands of agents, hopefully seamlessly operating alongside human employees. What what does that secure enterprise look like? And are there any mistakes you think organization could regret making during the early phases of adoption?
[00:20:15] Yeah, you know, I really think that the security problem, the security challenge with agents is, you know, as we mentioned, it is it requires much more high performance, much more scale and much more granular control than enterprises are used to deploying and many conventional security systems. And and I think that right now, sometimes security controls are meshed within applications themselves.
[00:20:43] And I think a better design model now is to have a complete separation of concerns. So, you know, our vision is we like, you know, model builders and agent builders and and people that work in enterprises that are deploying workflows using these agents. They should have great freedom to go as quickly as possible and do whatever they need to and not have to think about security at all. That should be a separate concern.
[00:21:09] And I think I could see enterprises setting up a completely separate security layer, which is distinct and separate from that agent layer, which protects all the traditional resources from the agents while not getting in their way. Right. So I think this is a very, very clean separation between a well-developed, high performing, zero trust security layer and an agentic layer. It is coming.
[00:21:40] And I think that would be a great evolution for for the industry. I think we'll be able to it will allow us to to create better security and also allow the agent builders and agent deployers to to go wild and to be as creative as they need to be. I think that is a powerful and thought provoking moment to end on.
[00:22:00] So I cannot thank you enough for coming on today and talking about AI security and the real vulnerability, what AI agents can access once they're compromised, especially as traditional guardrails and prompt injection defenses are proving inefficient right now. But lots of solutions we discussed today. So anybody listening and carrying on this conversation with you? Well, do you like me to point everyone? Well, sure. You get in touch with me at secure auth.
[00:22:27] So G Mattson, M-A-T-T-S-O-N at secure auth.com. Or you can look at our website. It's a secure and then auth, one word, dot com. And there's also secure and then auth dot AI. And you can look at our agent registry, which will show you the trust level of the agency you're using and provide recommendations, you know, with or without us for how to secure them. Awesome. Awesome.
[00:22:55] Well, I've loved hearing more about how the enterprise AI control plane needs to shift from just trying to secure the models themselves and start thinking about enforcing continuous authorization on every resource that these agents touch. So many big talking points. I'll include link to the website, your LinkedIn, et cetera, so people can find out more information there. But thank you for starting this conversation. So hopefully we can prevent a few nasty things from happening just by having this chat. But thanks again for bringing it to life.
[00:23:26] Thank you, Neil. I think today's conversation left us. It certainly left me with a memorable warning. Yes, AI agents are calling the cybersecurity industries tech debt due. But my guest explained why businesses cannot assume an agent is trustworthy just because it behaved correctly five minutes ago.
[00:23:46] And it was interesting to hear how continuous authorization could become one of the most important defenses, especially as agents create sub-agents. Access sensitive systems and act at machine speed. And perhaps the biggest lesson is that companies should give people the freedom to build with AI, but not forget to place strong controls around every resource that those systems can touch. But I'd love to hear your thoughts.
[00:24:14] If an AI agent inside your business was compromised tomorrow, do you know exactly what it could access, what it could change or even delete? Let me know. TechTalksNetwork.com. You can leave me an audio message over there. Learn how you can work with me or just browse through 4,000 interviews. Whatever it is, we've got something for everyone. Speaking of which, I'll be back again tomorrow with another guest. Thanks for listening. Bye for now. Heh.
[00:24:46] things for??? too muchこんにちは.

