Giving AI Security Agents the Context They Need With Sola Security
The Business of CybersecurityAugust 17, 2026
41
00:27:2525.12 MB

Giving AI Security Agents the Context They Need With Sola Security

What happens when an AI security agent receives access to eight enterprise systems but cannot understand the relationships between the data inside them?

In this episode of The Business of Cybersecurity, I speak with Guy Flechter, CEO and co-founder of Sola Security. Guy has worked in cybersecurity for 25 years, progressing from operational security roles to the CISO position before moving into entrepreneurship. He previously founded Cider Security, which was acquired by Palo Alto Networks for $300 million.

Our conversation focuses on why adding AI agents to separate security tools may increase speed without improving the quality of the decisions. Cloud, identity, SaaS, code, devices, and networks frequently operate through different consoles and data models. An agent working within one of those systems may answer confidently while missing a relationship that changes the meaning of the risk.

Sola Security’s research examined 50 tasks across eight enterprise platforms. According to Guy, providing structural and relational context improved answer correctness by approximately 34% across the tested models. Under full context, 78% of responses were considered fully correct, around 18% were incomplete, and fewer than 4% were classified as complete failures.

Those results show both the promise and present limitations of AI security agents. Connected context can improve performance significantly, but 78% accuracy does not support fully autonomous action in situations where an incorrect permission change or security response could have serious consequences. Guy believes human involvement will remain necessary until accuracy reaches a far higher level.

We also discuss how companies should vet and onboard AI agents. Guy recommends treating an agent like a new employee by defining its permissions, monitoring its actions, controlling what it can retain, and limiting its authority until trust has been earned.

The episode concludes with a discussion about independent testing. Guy argues that buyers need transparent benchmarks with visible tasks and repeatable methods, rather than vendor accuracy claims based on private evaluations.

Should an AI security agent be allowed to act autonomously if its reasoning cannot be independently tested? Listen to the conversation and share your thoughts with me.