Insight certainty 4/5 debate potential 2/5

Schulhoff: Google's CaMeL framework fails when AI tasks combine read and write

Sander Schulhoff · Why securing AI is harder than anyone expected and guardrails are failing | HackAPrompt CEO · Dec 21, 2025 · at 1:06:54

HackAPrompt CEO Sander Schulhoff discusses the capabilities and structural limitations of Google's CaMeL permissioning framework for AI agents.

0:00 / 0:32exact quote · 32.6s
▶ Watch the full episode on YouTube → 720p mp4 · rendered on demand · StarZero watermark
“Unfortunately although camel can solve some of these situations, if you have an instance where basically both read and write are combined. So if I'm like, Hey, can you read my recent emails and then forward any ops request to my head of ops? Now we have read and write combined. Camel can't really help because it's like, okay, I'm gonna give you read email permissions, and also send email permissions, and now this is enough for an attack to occur.”

quote is from the automated transcript, cleaned for reading: filler sounds and stutters are removed, nothing is rephrased. names can be misheard (the analysis reads context, assessments check outside sources). how →

More from Sander Schulhoff

Assertion Not checkable as stated
Schulhoff: Guardrail Vendors Fabricate Stats and Fail on Non-English
“I know a number of people working at these companies and I am permitted to say these things, which I will approximately say but they tell me things like, you know, the testing we do is bullshit. They're fabricating statistics. And a lot of the times their mode…”
Sander Schulhoff Dec 21, 2025 ▶ 35:55 Why securing AI is harder than anyone expected and guardrails are failing | HackAPrompt CEO
Opinion
Schulhoff: No meaningful progress made on solving prompt injection or jailbreaking
“And so in, in my professional opinion, there's been no meaningful progress made towards solving adversarial robustness, prompt injection, jailbreaking. In the last couple of years, since the problem was discovered and we're, we, you know, we're often seeing ne…”
Sander Schulhoff Dec 21, 2025 ▶ 1:12:29 Why securing AI is harder than anyone expected and guardrails are failing | HackAPrompt CEO
Prediction Not checkable as stated
Schulhoff: AI security sector faces market correction within six to twelve months
“When it comes to AI security, the AI security industry in particular, I think we're going to see a market correction in the next Year, maybe in the next six months where companies realize that these guardrails don't work.”
Sander Schulhoff Dec 21, 2025 ▶ 1:22:21 Why securing AI is harder than anyone expected and guardrails are failing | HackAPrompt CEO
Insight
Schulhoff: AI guardrails do not work and cause false overconfidence
“Guardrails don't work. They just don't work. They really don't work. And they're quite likely to make you overconfident in your security posture, which is which is a really big, big problem.”
Sander Schulhoff Dec 21, 2025 ▶ 1:28:15 Why securing AI is harder than anyone expected and guardrails are failing | HackAPrompt CEO
Assertion Supported
Schulhoff: Attackers hijacked Claude Code to carry out a cyber attack
“This group was able to hijack Claude Code into performing a cyber attack, basically.”
Sander Schulhoff Dec 21, 2025 ▶ 16:36 Why securing AI is harder than anyone expected and guardrails are failing | HackAPrompt CEO
Insight
Schulhoff: All Transformer-Based Chatbots Are Vulnerable to Adversarial Attacks
“And because all I guess for the most part, all currently deployed chatbots are based on transformers or transformer adjacent technologies. They're all vulnerable to Prompt injection, jailbreaking, forms of adversarial attacks.”
Sander Schulhoff Dec 21, 2025 ▶ 28:54 Why securing AI is harder than anyone expected and guardrails are failing | HackAPrompt CEO
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 300 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.