Why AI agent security is so hard

Why AI agent security is so hard

Source: YouTube · Zack Korman · published Mar 3, 2026 · 38:06

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The speaker argues that AI agent security is not a novel domain but simply the application of established security principles, describing current implementations as a regression from modern standards 0:00-0:23.

Key Takeaways:
• The speaker believes AI security does not introduce fundamentally new challenges, asserting that core security tenets are applied consistently across different fields 0:15-0:23.
• Rather than an evolution, the current state of AI security is viewed as a regression to earlier eras before best practices were solidified 0:26-0:33.
• Modern security standards like the principle of least privilege are often neglected in AI environments, where agents frequently have broad access to everything 0:35-0:40.

Securing AI agents relies on enforcing proven security fundamentals rather than inventing new paradigms 0:26-0:30.

Sources:

  • 0:00-0:15 Introduction to the debate on whether AI agent security is new.
  • 0:15-0:23 The speaker's stance that security principles never change.
  • 0:26-0:40 Comparison to older security models and lack of least privilege.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

There are the people who think that AI agent security is a new area that has a lot of interesting and unique challenges we haven't solved and there are people who think it's nothing new and just normal security applied to AI. Which camp and you have to pick one are you in? I mean nothing ever changes kind of in SEC like it is new but you're just applying the same principles all the time everywhere. So I think like from that perspective it's not actually new. In fact I feel like it's a regression if anything. It's like we're going back to older days before we have figured it out like modern security whatever that is you know like principle of lease privileges now you go back to like everything have has access to to everything okay so it's nothing as new except we've done it poorly reverted …