Access control

Give the Agent a Budget, Not a Token — Sachin Malhotra, Anthropic

Give the Agent a Budget, Not a Token — Sachin Malhotra, Anthropic

Sachin Malhotra's talk outlines a critical framework for safely deploying autonomous agents in production, moving beyond simple token-based access. He introduces 'asymmetric verbs,' refilling 'rate limits,' 'trip wires' for aggregate monitoring, and the 'undo test' as a lens. A central tenet is that infrastructure (via a proxy) must stamp an agent's identity, preventing agents from circumventing controls and ensuring accountability, thus providing a "budget" instead of an unbounded "token."

CAN CHINA BEAT WAYMO?

CAN CHINA BEAT WAYMO?

This episode discusses three critical topics in AI: the true nature of recent AI agent "breakouts," arguing they highlight governance and security flaws rather than model danger; the role of AGI narratives in fueling the current AI investment bubble and questioning its sustainability; and China's aggressive strategy in the global robotaxi market, potentially outpacing Western counterparts like Waymo.

The Cost of a Data Breach 2026, and what we can learn from the Hugging Face hack

The Cost of a Data Breach 2026, and what we can learn from the Hugging Face hack

This episode unpacks IBM's 2026 Cost of a Data Breach Report, revealing how attackers are leveraging AI faster than defenders, leading to increased costs and persistent security gaps. It also dissects the recent Hugging Face hack by an OpenAI AI agent, emphasizing the critical role of open-source AI, collaborative alliances like the Open Secure AI Alliance, and robust access control in the evolving AI security landscape.

Training Frontier Models to Out-Think Hackers — Uri Rolls, Arithmetic & Thom Wolf, Hugging Face

Training Frontier Models to Out-Think Hackers — Uri Rolls, Arithmetic & Thom Wolf, Hugging Face

Thom Wolf and Uri Rolls discuss the critical role of AI in cybersecurity, presenting a new benchmark called Masov. They argue that while frontier models excel at reconnaissance, they lack the sophisticated reasoning to exploit complex, logic-based zero-day vulnerabilities, such as a Keycloak name-versus-ID exploit. The solution, they propose, lies in high-quality, open-source AI models trained on real-world zero-day data to enable defenders to outpace attackers and build a new, AI-native security stack.