Feb 4, 2026 · 38m · american-optimist

AI Expert: Agents Will Take Over Everything · Joe Lonsdale

Kevin Mandia · 30m spoken Joe Lonsdale · 4m spoken
0:00 / 0:00
▶ Watch on YouTube →

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

In this episode of American Optimist, host Joe Lonsdale interviews cybersecurity pioneer Kevin Mandia to explore the history of state-sponsored cyber espionage and the urgent security threats posed by autonomous AI agents. Mandia outlines the evolution of cyber warfare from early Air Force investigations to modern enterprise defense, emphasizing why continuous AI-driven red teaming is essential for future protection.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. Joe holds 12.6% of the talking time here. How this is scored →

Joe as informed peer 3.0 Guest teaching 2.9 Guest disagreement 0.4 Joe pushing back 0.0
05100:0010:0020:0030:000:37–3:42 · Joe as informed peer 2/10 Show Title Sequence and Host Background Montage Joe introduces Mandia and connects early internet history to his own 1993 AOL experience. Mandia educates on early classified military intrusions, Cliff Stoll, and the Morris worm.3:42–8:08 · Joe as informed peer 4/10 Decades of Combat: State Actors and Cyber Crime Joe brings relevant domain experience from his early days at PayPal observing Russian cyber syndicates. Mandia validates Joe's observation by naming specific Russian actors and detailing weapons software espionage.8:08–13:30 · Joe as informed peer 2/10 The Founding of Mandiant & Corporate Breach Realities Joe prompts Mandia on founding Mandiant and its acquisition. Mandia explains why traditional antivirus is ineffective and details the harsh reality that private enterprises cannot independently stop targeted nation-state attacks.13:30–19:31 · Joe as informed peer 2/10 High-Stakes Cyber Investigations and Ransomware Crisis Management Joe asks about operational war stories and law enforcement deterrence. Mandia explains shifting Russian tradecraft and why foreign state-sponsored criminals remain untouchable by Western law enforcement.19:31–23:54 · Joe as informed peer 3/10 Scaling Cybersecurity Talent and Re-Entering the Arena with AI Mandia gently corrects Joe's framing that he chose to sell his company, explaining public company buyout dynamics. He details how AI will scale elite brain-surgeon-level cyber talent into swarms.23:54–27:44 · Joe as informed peer 4/10 Offensive AI Agents, Social Engineering, and Asymmetric Threats Joe articulates corporate vulnerability concerns looking forward to 2026. Mandia builds on this with examples of autonomous voice cloning and asymmetric offensive cost advantages.27:44–36:55 · Joe as informed peer 5/10 Protecting Critical Infrastructure and Boardroom Red Teaming Joe exhibits solid technical knowledge regarding safety guardrails and jailbreaking differences across Claude, xAI, and open-source models. Mandia explains why realistic red-teaming beats compliance dashboards in boardrooms.36:55–38:46 · Joe as informed peer 2/10 The Case for AI Optimism and Program Conclusion Joe invites an optimistic closing argument on AI security. Mandia outlines an analogy comparing offensive AI training defensive AI to Tom Brady training a defense.0:37–3:42 · Guest teaching 3/10 Show Title Sequence and Host Background Montage Joe introduces Mandia and connects early internet history to his own 1993 AOL experience. Mandia educates on early classified military intrusions, Cliff Stoll, and the Morris worm.3:42–8:08 · Guest teaching 3/10 Decades of Combat: State Actors and Cyber Crime Joe brings relevant domain experience from his early days at PayPal observing Russian cyber syndicates. Mandia validates Joe's observation by naming specific Russian actors and detailing weapons software espionage.8:08–13:30 · Guest teaching 4/10 The Founding of Mandiant & Corporate Breach Realities Joe prompts Mandia on founding Mandiant and its acquisition. Mandia explains why traditional antivirus is ineffective and details the harsh reality that private enterprises cannot independently stop targeted nation-state attacks.13:30–19:31 · Guest teaching 3/10 High-Stakes Cyber Investigations and Ransomware Crisis Management Joe asks about operational war stories and law enforcement deterrence. Mandia explains shifting Russian tradecraft and why foreign state-sponsored criminals remain untouchable by Western law enforcement.19:31–23:54 · Guest teaching 4/10 Scaling Cybersecurity Talent and Re-Entering the Arena with AI Mandia gently corrects Joe's framing that he chose to sell his company, explaining public company buyout dynamics. He details how AI will scale elite brain-surgeon-level cyber talent into swarms.23:54–27:44 · Guest teaching 2/10 Offensive AI Agents, Social Engineering, and Asymmetric Threats Joe articulates corporate vulnerability concerns looking forward to 2026. Mandia builds on this with examples of autonomous voice cloning and asymmetric offensive cost advantages.27:44–36:55 · Guest teaching 3/10 Protecting Critical Infrastructure and Boardroom Red Teaming Joe exhibits solid technical knowledge regarding safety guardrails and jailbreaking differences across Claude, xAI, and open-source models. Mandia explains why realistic red-teaming beats compliance dashboards in boardrooms.36:55–38:46 · Guest teaching 1/10 The Case for AI Optimism and Program Conclusion Joe invites an optimistic closing argument on AI security. Mandia outlines an analogy comparing offensive AI training defensive AI to Tom Brady training a defense.0:37–3:42 · Guest disagreement 0/10 Show Title Sequence and Host Background Montage Joe introduces Mandia and connects early internet history to his own 1993 AOL experience. Mandia educates on early classified military intrusions, Cliff Stoll, and the Morris worm.3:42–8:08 · Guest disagreement 0/10 Decades of Combat: State Actors and Cyber Crime Joe brings relevant domain experience from his early days at PayPal observing Russian cyber syndicates. Mandia validates Joe's observation by naming specific Russian actors and detailing weapons software espionage.8:08–13:30 · Guest disagreement 1/10 The Founding of Mandiant & Corporate Breach Realities Joe prompts Mandia on founding Mandiant and its acquisition. Mandia explains why traditional antivirus is ineffective and details the harsh reality that private enterprises cannot independently stop targeted nation-state attacks.13:30–19:31 · Guest disagreement 0/10 High-Stakes Cyber Investigations and Ransomware Crisis Management Joe asks about operational war stories and law enforcement deterrence. Mandia explains shifting Russian tradecraft and why foreign state-sponsored criminals remain untouchable by Western law enforcement.19:31–23:54 · Guest disagreement 2/10 Scaling Cybersecurity Talent and Re-Entering the Arena with AI Mandia gently corrects Joe's framing that he chose to sell his company, explaining public company buyout dynamics. He details how AI will scale elite brain-surgeon-level cyber talent into swarms.23:54–27:44 · Guest disagreement 0/10 Offensive AI Agents, Social Engineering, and Asymmetric Threats Joe articulates corporate vulnerability concerns looking forward to 2026. Mandia builds on this with examples of autonomous voice cloning and asymmetric offensive cost advantages.27:44–36:55 · Guest disagreement 0/10 Protecting Critical Infrastructure and Boardroom Red Teaming Joe exhibits solid technical knowledge regarding safety guardrails and jailbreaking differences across Claude, xAI, and open-source models. Mandia explains why realistic red-teaming beats compliance dashboards in boardrooms.36:55–38:46 · Guest disagreement 0/10 The Case for AI Optimism and Program Conclusion Joe invites an optimistic closing argument on AI security. Mandia outlines an analogy comparing offensive AI training defensive AI to Tom Brady training a defense.0:37–3:42 · Joe pushing back 0/10 Show Title Sequence and Host Background Montage Joe introduces Mandia and connects early internet history to his own 1993 AOL experience. Mandia educates on early classified military intrusions, Cliff Stoll, and the Morris worm.3:42–8:08 · Joe pushing back 0/10 Decades of Combat: State Actors and Cyber Crime Joe brings relevant domain experience from his early days at PayPal observing Russian cyber syndicates. Mandia validates Joe's observation by naming specific Russian actors and detailing weapons software espionage.8:08–13:30 · Joe pushing back 0/10 The Founding of Mandiant & Corporate Breach Realities Joe prompts Mandia on founding Mandiant and its acquisition. Mandia explains why traditional antivirus is ineffective and details the harsh reality that private enterprises cannot independently stop targeted nation-state attacks.13:30–19:31 · Joe pushing back 0/10 High-Stakes Cyber Investigations and Ransomware Crisis Management Joe asks about operational war stories and law enforcement deterrence. Mandia explains shifting Russian tradecraft and why foreign state-sponsored criminals remain untouchable by Western law enforcement.19:31–23:54 · Joe pushing back 0/10 Scaling Cybersecurity Talent and Re-Entering the Arena with AI Mandia gently corrects Joe's framing that he chose to sell his company, explaining public company buyout dynamics. He details how AI will scale elite brain-surgeon-level cyber talent into swarms.23:54–27:44 · Joe pushing back 0/10 Offensive AI Agents, Social Engineering, and Asymmetric Threats Joe articulates corporate vulnerability concerns looking forward to 2026. Mandia builds on this with examples of autonomous voice cloning and asymmetric offensive cost advantages.27:44–36:55 · Joe pushing back 0/10 Protecting Critical Infrastructure and Boardroom Red Teaming Joe exhibits solid technical knowledge regarding safety guardrails and jailbreaking differences across Claude, xAI, and open-source models. Mandia explains why realistic red-teaming beats compliance dashboards in boardrooms.36:55–38:46 · Joe pushing back 0/10 The Case for AI Optimism and Program Conclusion Joe invites an optimistic closing argument on AI security. Mandia outlines an analogy comparing offensive AI training defensive AI to Tom Brady training a defense.

speaking balance: gold is Joe, purple is the guest (3 minute bins)

0:00 · Joe 38% · guest 62%0:00 · Joe 38% · guest 62%3:00 · Joe 12.2% · guest 87.8%3:00 · Joe 12.2% · guest 87.8%6:00 · Joe 7.9% · guest 92.1%6:00 · Joe 7.9% · guest 92.1%9:00 · Joe 6.2% · guest 93.8%9:00 · Joe 6.2% · guest 93.8%12:00 · Joe 3.2% · guest 96.8%12:00 · Joe 3.2% · guest 96.8%15:00 · Joe 4.9% · guest 95.1%15:00 · Joe 4.9% · guest 95.1%18:00 · Joe 12.1% · guest 87.9%18:00 · Joe 12.1% · guest 87.9%21:00 · Joe 13% · guest 87%21:00 · Joe 13% · guest 87%24:00 · Joe 15.5% · guest 84.5%24:00 · Joe 15.5% · guest 84.5%27:00 · Joe 20.7% · guest 79.3%27:00 · Joe 20.7% · guest 79.3%30:00 · Joe 9.8% · guest 90.2%30:00 · Joe 9.8% · guest 90.2%33:00 · Joe 8% · guest 92%33:00 · Joe 8% · guest 92%36:00 · Joe 13% · guest 87%36:00 · Joe 13% · guest 87%
Sharpest disagreement ▶ 21:58 Mandia rejects the 'you sold your company' premise

Mandia directly corrects Joe's phrasing, clarifying that public companies are perpetually on the market rather than founders actively deciding to sell.

Hardest push from Joe ▶ 27:17 Joe presses on open-model weaponization risks

Joe challenges the idea that state actors can keep capabilities caged by pointing out how actors in Eastern Europe iterate on open models.

Biggest teaching moment ▶ 12:05 Mandia dismantles the assumption that corporations can defeat nation states

Mandia recounts confronting a financial services client to explain that expecting private enterprises to pitch a perfect defensive game against nation states is fundamentally unrealistic.

Joe holds their own ▶ 5:13 Joe cites PayPal frontline experience with Russian syndicates

Joe injects firsthand domain knowledge regarding Russian financial fraud operations during his time at PayPal, which Mandia immediately validates.

the scores for every segment, with the reasoning behind each
ChapterTopicJoe as informed peerGuest teachingGuest disagreementJoe pushing backWhy
Show Title Sequence and Host Background Montage 2300 Joe introduces Mandia and connects early internet history to his own 1993 AOL experience. Mandia educates on early classified military intrusions, Cliff Stoll, and the Morris worm.
Decades of Combat: State Actors and Cyber Crime 4300 Joe brings relevant domain experience from his early days at PayPal observing Russian cyber syndicates. Mandia validates Joe's observation by naming specific Russian actors and detailing weapons software espionage.
The Founding of Mandiant & Corporate Breach Realities 2410 Joe prompts Mandia on founding Mandiant and its acquisition. Mandia explains why traditional antivirus is ineffective and details the harsh reality that private enterprises cannot independently stop targeted nation-state attacks.
High-Stakes Cyber Investigations and Ransomware Crisis Management 2300 Joe asks about operational war stories and law enforcement deterrence. Mandia explains shifting Russian tradecraft and why foreign state-sponsored criminals remain untouchable by Western law enforcement.
Scaling Cybersecurity Talent and Re-Entering the Arena with AI 3420 Mandia gently corrects Joe's framing that he chose to sell his company, explaining public company buyout dynamics. He details how AI will scale elite brain-surgeon-level cyber talent into swarms.
Offensive AI Agents, Social Engineering, and Asymmetric Threats 4200 Joe articulates corporate vulnerability concerns looking forward to 2026. Mandia builds on this with examples of autonomous voice cloning and asymmetric offensive cost advantages.
Protecting Critical Infrastructure and Boardroom Red Teaming 5300 Joe exhibits solid technical knowledge regarding safety guardrails and jailbreaking differences across Claude, xAI, and open-source models. Mandia explains why realistic red-teaming beats compliance dashboards in boardrooms.
The Case for AI Optimism and Program Conclusion 2100 Joe invites an optimistic closing argument on AI security. Mandia outlines an analogy comparing offensive AI training defensive AI to Tom Brady training a defense.

Statements from this episode (13)

Assertion Supported
Mandia: US Military Began Monitoring Its Networks Around 1993
“I started doing computer security in 1993, and that was about the year we started putting eyes on our network in the military.”
Kevin Mandia Feb 4, 2026 ▶ 2:46
Assertion Not checkable as stated
Mandia: Mandiant and colleagues have responded to Chinese intrusions daily since 1995
“I think by 1995, until now, I would say on a daily basis, either I'm Or someone I work with has been responding to an intrusion from a Chinese actor looking for the government.”
Kevin Mandia Feb 4, 2026 ▶ 3:57
Opinion
Mandia: China matched Russia's elite cyber intrusion capabilities by 2020.
“And I do believe you know, Russia had the crown early, 19 nineties, early 2000, the best intrusions I saw. Was Russian operators on our networks. later in my career, especially around 2019, 20, 20 China, you know, really rapidly graduated to great capabilitie…”
Kevin Mandia Feb 4, 2026 ▶ 4:51
Assertion Not checkable as stated
Mandia: Non-developers can bypass legacy antivirus software in under three minutes.
“We could teach FBI agents in the classroom who were not malware developers how to circumvent antivirus in under three minutes. Compress and encrypt malware. And you got past antivirus.”
Kevin Mandia Feb 4, 2026 ▶ 9:26
Disclosure
Mandia: Mandiant originally aimed to build the endpoint software CrowdStrike perfected.
“Believe it or not, Mandiant was actually an endpoint company. I just executed so poorly on that dream. Nobody knows it, you know, but we were building an endpoint to detect what Symantec and McAfee missed... And since that time George Kurtz and CrowdStrike kin…”
Kevin Mandia Feb 4, 2026 ▶ 10:18
Insight
Mandia: Nation-states will always beat private companies in cyberattacks
“When a nation state targets a company, guess who wins? The nation does, not the company... You cannot expect great blue chip companies that constantly every day pitch a perfect game on defense against nations that are targeting them. It's just an unfair fight.”
Kevin Mandia Feb 4, 2026 ▶ 12:42
Assertion Partly supported
Mandia: Russian SVR doctrine shifted in August 2015 toward data leaks
“I had 20 years of responding to SVR. They never hacked and then released data. They suddenly did that in August, They always hacked for security reasons, and all of a sudden we're responding to them hacking universities. I'm like, oh, they increased scope. And…”
Kevin Mandia Feb 4, 2026 ▶ 15:00
Assertion Supported
Mandia: Uniformed North Korean government agents run cyberattacks to steal Bitcoin.
“Literally government agents in North Korea in uniform are hacking to steal Bitcoin.”
Kevin Mandia Feb 4, 2026 ▶ 17:59
Prediction Open · timeframe Feb 2031
Mandia: Cybercrime and Espionage Will Shift from Human-Led to AI Agent-Led
“You're gonna have AI agents on offense, automating incredibly talented humans, you know, like literally that brain surgeon analogy. AI agents will be that, and you're gonna have swarms of agents that can communicate, and think, and instantiate normal, and lear…”
Kevin Mandia Feb 4, 2026 ▶ 23:13
Prediction Open · timeframe Feb 2029
Mandia: Fully autonomous cyber defense systems will emerge within three years.
“Fast forward two or three years, Joe, you're going to see an autonomous defense crafted, trained by the world's best cyber offense, you know, the hyper attack platform.”
Kevin Mandia Feb 4, 2026 ▶ 26:34
Prediction Held up
Mandia: Good guys will use offensive AI agents to train defensive AI
“There is no question that in the future you'll have AI agents on offense run by the good guys to train the AI on defense run by the good guys.”
Kevin Mandia Feb 4, 2026 ▶ 28:36
Opinion
Mandia: AI-native software developers are over 100 times more productive.
“It's not 10 X. It's more than a hundred X productivity with an AI native developer working on software.”
Kevin Mandia Feb 4, 2026 ▶ 33:05
Prediction Not checkable as stated
Mandia: AI attackers will eliminate the 10-minute human incident-response window.
“The day where a human would break in, and if you were 10 minutes behind the human on defense, you could stop the impact of a breach, is going to end. There's going to be an agent that breaks in, then another agent uploaded because it had remote code access, Re…”
Kevin Mandia Feb 4, 2026 ▶ 35:02
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 150 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.