May 28, 2026 · 41m · no-priors

Building an AI Guardian for Enterprise with Onyx Security CEO Maxim Bar Kogan

Maxim Bar Kogan · 29m spoken Sarah Guo · 7m spoken
0:00 / 0:00
▶ Watch on YouTube →

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

In this episode of No Priors, host Aaron interviews Onyx Security CEO and co-founder Maxim Bar Kogan on the rapid enterprise adoption of autonomous AI agents and the critical need for independent security control planes. Maxim details how semantic underwriting, dual-model architectures, and deep operational cybersecurity principles protect modern enterprises from catastrophic agentic risks and automated exploits.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. The hosts hold 20.1% of the talking time here. How this is scored →

The hosts as informed peer 6.0 Guest teaching 5.8 Guest disagreement 1.1 The hosts pushing back 2.1
05100:0015:0030:001:10–5:17 · The hosts as informed peer 6/10 The Evolution from Data Loss Prevention to Autonomous Agents Sarah sets the context by contrasting early DLP paranoia with current agentic panic and recalls warning Maxim about running out of money before agent adoption arrived. Maxim details the shift triggered by AutoGPT and how enterprise adoption outpaced early expectations.5:17–10:05 · The hosts as informed peer 5/10 Onyx Security's Mission: The Secure AI Control Plane Sarah shares her own experience of over-permissive coding agents deleting data and asks for enterprise deployment breakdowns. Maxim provides detailed proportions across low-code workflows, internal builds, and autonomous coding tools.10:05–12:45 · The hosts as informed peer 6/10 Why Traditional Identity and Endpoint Security Fail for Agents Sarah presses on why the massive incumbent security stack fails to protect against agent risks. Maxim explains the fundamental flaw of static identity and endpoint controls when agents require broad user permissions and contextual intent.12:45–17:14 · The hosts as informed peer 7/10 The Limits of Proxies and Rule-Based Policy Engines Sarah challenges the problem from a traditional security perspective, asking why smart proxy policy engines fall short. Maxim reframes proxies as mere integration methods and explains why specialized small models are required to cheaply decide when to trigger expensive oversight agents.17:14–21:25 · The hosts as informed peer 7/10 The Blitz Chess Analogy for Compute Allocation Sarah introduces a Blitz chess analogy for compute allocation under time pressure. Maxim strongly agrees, elaborating on how top players use fast intuition for low-risk moves and allocate heavy computation only during critical high-risk junctures.21:25–23:25 · The hosts as informed peer 5/10 Mechanistic Interpretability and Inspecting Model Internals Sarah highlights industry skepticism regarding mechanistic interpretability. Maxim argues that while human cognition struggles to map activations directly, smarter models will soon assist in cracking model internals.23:25–27:45 · The hosts as informed peer 6/10 Earning Fortune 100 Enterprise Trust as an Early-Stage Startup Sarah questions how a small, early-stage Israeli startup wins deep trust from Fortune 100 enterprises and raises concerns about automated vulnerability research. Maxim notes that acute operational pain forces enterprises to partner early and foundational controls must be established.27:45–30:47 · The hosts as informed peer 5/10 Phased Model Rollouts Versus Global Competitive Realities Sarah probes the viability of controlled rollouts for dangerous dual-use security models. Maxim counters that controlled rollouts risk leaving organizations defenseless against adversarial foreign models, urging broader access and foundational defenses.30:47–36:55 · The hosts as informed peer 7/10 Onyx's Long-Term Technical Strategy in an Evolving AI Landscape Sarah poses the central startup dilemma: whether frontier foundation model labs will inevitably absorb the agent governance layer. Maxim methodically outlines why buyer psychology, proprietary historical telemetry, and multi-vendor environments ensure independent oversight will prevail.36:55–39:13 · The hosts as informed peer 6/10 Understanding Security Workflows and Israeli Cyber DNA Sarah asks about the distinct edge of the Israeli cyber ecosystem compared to Silicon Valley AI labs. Maxim emphasizes deep empathetic understanding of operational security workflows over pure model building.39:13–40:49 · The hosts as informed peer 6/10 Balancing Near-Term Enterprise Needs with an AGI-Pilled Future Sarah presses Maxim to reconcile his extreme long-term AGI convictions with building enterprise software for human security operators today. Maxim explains that systems must cater to today's human buyers while designing UX primitives compatible with incoming agent workforces.1:10–5:17 · Guest teaching 5/10 The Evolution from Data Loss Prevention to Autonomous Agents Sarah sets the context by contrasting early DLP paranoia with current agentic panic and recalls warning Maxim about running out of money before agent adoption arrived. Maxim details the shift triggered by AutoGPT and how enterprise adoption outpaced early expectations.5:17–10:05 · Guest teaching 6/10 Onyx Security's Mission: The Secure AI Control Plane Sarah shares her own experience of over-permissive coding agents deleting data and asks for enterprise deployment breakdowns. Maxim provides detailed proportions across low-code workflows, internal builds, and autonomous coding tools.10:05–12:45 · Guest teaching 6/10 Why Traditional Identity and Endpoint Security Fail for Agents Sarah presses on why the massive incumbent security stack fails to protect against agent risks. Maxim explains the fundamental flaw of static identity and endpoint controls when agents require broad user permissions and contextual intent.12:45–17:14 · Guest teaching 7/10 The Limits of Proxies and Rule-Based Policy Engines Sarah challenges the problem from a traditional security perspective, asking why smart proxy policy engines fall short. Maxim reframes proxies as mere integration methods and explains why specialized small models are required to cheaply decide when to trigger expensive oversight agents.17:14–21:25 · Guest teaching 5/10 The Blitz Chess Analogy for Compute Allocation Sarah introduces a Blitz chess analogy for compute allocation under time pressure. Maxim strongly agrees, elaborating on how top players use fast intuition for low-risk moves and allocate heavy computation only during critical high-risk junctures.21:25–23:25 · Guest teaching 6/10 Mechanistic Interpretability and Inspecting Model Internals Sarah highlights industry skepticism regarding mechanistic interpretability. Maxim argues that while human cognition struggles to map activations directly, smarter models will soon assist in cracking model internals.23:25–27:45 · Guest teaching 5/10 Earning Fortune 100 Enterprise Trust as an Early-Stage Startup Sarah questions how a small, early-stage Israeli startup wins deep trust from Fortune 100 enterprises and raises concerns about automated vulnerability research. Maxim notes that acute operational pain forces enterprises to partner early and foundational controls must be established.27:45–30:47 · Guest teaching 6/10 Phased Model Rollouts Versus Global Competitive Realities Sarah probes the viability of controlled rollouts for dangerous dual-use security models. Maxim counters that controlled rollouts risk leaving organizations defenseless against adversarial foreign models, urging broader access and foundational defenses.30:47–36:55 · Guest teaching 7/10 Onyx's Long-Term Technical Strategy in an Evolving AI Landscape Sarah poses the central startup dilemma: whether frontier foundation model labs will inevitably absorb the agent governance layer. Maxim methodically outlines why buyer psychology, proprietary historical telemetry, and multi-vendor environments ensure independent oversight will prevail.36:55–39:13 · Guest teaching 6/10 Understanding Security Workflows and Israeli Cyber DNA Sarah asks about the distinct edge of the Israeli cyber ecosystem compared to Silicon Valley AI labs. Maxim emphasizes deep empathetic understanding of operational security workflows over pure model building.39:13–40:49 · Guest teaching 5/10 Balancing Near-Term Enterprise Needs with an AGI-Pilled Future Sarah presses Maxim to reconcile his extreme long-term AGI convictions with building enterprise software for human security operators today. Maxim explains that systems must cater to today's human buyers while designing UX primitives compatible with incoming agent workforces.1:10–5:17 · Guest disagreement 1/10 The Evolution from Data Loss Prevention to Autonomous Agents Sarah sets the context by contrasting early DLP paranoia with current agentic panic and recalls warning Maxim about running out of money before agent adoption arrived. Maxim details the shift triggered by AutoGPT and how enterprise adoption outpaced early expectations.5:17–10:05 · Guest disagreement 0/10 Onyx Security's Mission: The Secure AI Control Plane Sarah shares her own experience of over-permissive coding agents deleting data and asks for enterprise deployment breakdowns. Maxim provides detailed proportions across low-code workflows, internal builds, and autonomous coding tools.10:05–12:45 · Guest disagreement 1/10 Why Traditional Identity and Endpoint Security Fail for Agents Sarah presses on why the massive incumbent security stack fails to protect against agent risks. Maxim explains the fundamental flaw of static identity and endpoint controls when agents require broad user permissions and contextual intent.12:45–17:14 · Guest disagreement 2/10 The Limits of Proxies and Rule-Based Policy Engines Sarah challenges the problem from a traditional security perspective, asking why smart proxy policy engines fall short. Maxim reframes proxies as mere integration methods and explains why specialized small models are required to cheaply decide when to trigger expensive oversight agents.17:14–21:25 · Guest disagreement 0/10 The Blitz Chess Analogy for Compute Allocation Sarah introduces a Blitz chess analogy for compute allocation under time pressure. Maxim strongly agrees, elaborating on how top players use fast intuition for low-risk moves and allocate heavy computation only during critical high-risk junctures.21:25–23:25 · Guest disagreement 1/10 Mechanistic Interpretability and Inspecting Model Internals Sarah highlights industry skepticism regarding mechanistic interpretability. Maxim argues that while human cognition struggles to map activations directly, smarter models will soon assist in cracking model internals.23:25–27:45 · Guest disagreement 1/10 Earning Fortune 100 Enterprise Trust as an Early-Stage Startup Sarah questions how a small, early-stage Israeli startup wins deep trust from Fortune 100 enterprises and raises concerns about automated vulnerability research. Maxim notes that acute operational pain forces enterprises to partner early and foundational controls must be established.27:45–30:47 · Guest disagreement 2/10 Phased Model Rollouts Versus Global Competitive Realities Sarah probes the viability of controlled rollouts for dangerous dual-use security models. Maxim counters that controlled rollouts risk leaving organizations defenseless against adversarial foreign models, urging broader access and foundational defenses.30:47–36:55 · Guest disagreement 2/10 Onyx's Long-Term Technical Strategy in an Evolving AI Landscape Sarah poses the central startup dilemma: whether frontier foundation model labs will inevitably absorb the agent governance layer. Maxim methodically outlines why buyer psychology, proprietary historical telemetry, and multi-vendor environments ensure independent oversight will prevail.36:55–39:13 · Guest disagreement 1/10 Understanding Security Workflows and Israeli Cyber DNA Sarah asks about the distinct edge of the Israeli cyber ecosystem compared to Silicon Valley AI labs. Maxim emphasizes deep empathetic understanding of operational security workflows over pure model building.39:13–40:49 · Guest disagreement 1/10 Balancing Near-Term Enterprise Needs with an AGI-Pilled Future Sarah presses Maxim to reconcile his extreme long-term AGI convictions with building enterprise software for human security operators today. Maxim explains that systems must cater to today's human buyers while designing UX primitives compatible with incoming agent workforces.1:10–5:17 · The hosts pushing back 2/10 The Evolution from Data Loss Prevention to Autonomous Agents Sarah sets the context by contrasting early DLP paranoia with current agentic panic and recalls warning Maxim about running out of money before agent adoption arrived. Maxim details the shift triggered by AutoGPT and how enterprise adoption outpaced early expectations.5:17–10:05 · The hosts pushing back 1/10 Onyx Security's Mission: The Secure AI Control Plane Sarah shares her own experience of over-permissive coding agents deleting data and asks for enterprise deployment breakdowns. Maxim provides detailed proportions across low-code workflows, internal builds, and autonomous coding tools.10:05–12:45 · The hosts pushing back 2/10 Why Traditional Identity and Endpoint Security Fail for Agents Sarah presses on why the massive incumbent security stack fails to protect against agent risks. Maxim explains the fundamental flaw of static identity and endpoint controls when agents require broad user permissions and contextual intent.12:45–17:14 · The hosts pushing back 3/10 The Limits of Proxies and Rule-Based Policy Engines Sarah challenges the problem from a traditional security perspective, asking why smart proxy policy engines fall short. Maxim reframes proxies as mere integration methods and explains why specialized small models are required to cheaply decide when to trigger expensive oversight agents.17:14–21:25 · The hosts pushing back 1/10 The Blitz Chess Analogy for Compute Allocation Sarah introduces a Blitz chess analogy for compute allocation under time pressure. Maxim strongly agrees, elaborating on how top players use fast intuition for low-risk moves and allocate heavy computation only during critical high-risk junctures.21:25–23:25 · The hosts pushing back 2/10 Mechanistic Interpretability and Inspecting Model Internals Sarah highlights industry skepticism regarding mechanistic interpretability. Maxim argues that while human cognition struggles to map activations directly, smarter models will soon assist in cracking model internals.23:25–27:45 · The hosts pushing back 2/10 Earning Fortune 100 Enterprise Trust as an Early-Stage Startup Sarah questions how a small, early-stage Israeli startup wins deep trust from Fortune 100 enterprises and raises concerns about automated vulnerability research. Maxim notes that acute operational pain forces enterprises to partner early and foundational controls must be established.27:45–30:47 · The hosts pushing back 2/10 Phased Model Rollouts Versus Global Competitive Realities Sarah probes the viability of controlled rollouts for dangerous dual-use security models. Maxim counters that controlled rollouts risk leaving organizations defenseless against adversarial foreign models, urging broader access and foundational defenses.30:47–36:55 · The hosts pushing back 3/10 Onyx's Long-Term Technical Strategy in an Evolving AI Landscape Sarah poses the central startup dilemma: whether frontier foundation model labs will inevitably absorb the agent governance layer. Maxim methodically outlines why buyer psychology, proprietary historical telemetry, and multi-vendor environments ensure independent oversight will prevail.36:55–39:13 · The hosts pushing back 1/10 Understanding Security Workflows and Israeli Cyber DNA Sarah asks about the distinct edge of the Israeli cyber ecosystem compared to Silicon Valley AI labs. Maxim emphasizes deep empathetic understanding of operational security workflows over pure model building.39:13–40:49 · The hosts pushing back 4/10 Balancing Near-Term Enterprise Needs with an AGI-Pilled Future Sarah presses Maxim to reconcile his extreme long-term AGI convictions with building enterprise software for human security operators today. Maxim explains that systems must cater to today's human buyers while designing UX primitives compatible with incoming agent workforces.

speaking balance: gold is the hosts, purple is the guest (3 minute bins)

0:00 · the hosts 30.9% · guest 69.1%0:00 · the hosts 30.9% · guest 69.1%3:00 · the hosts 12.7% · guest 87.3%3:00 · the hosts 12.7% · guest 87.3%6:00 · the hosts 31.9% · guest 68.1%6:00 · the hosts 31.9% · guest 68.1%9:00 · the hosts 13.9% · guest 86.1%9:00 · the hosts 13.9% · guest 86.1%12:00 · the hosts 13.1% · guest 86.9%12:00 · the hosts 13.1% · guest 86.9%15:00 · the hosts 15.9% · guest 84.1%15:00 · the hosts 15.9% · guest 84.1%18:00 · the hosts 20.3% · guest 79.7%18:00 · the hosts 20.3% · guest 79.7%21:00 · the hosts 32.6% · guest 67.4%21:00 · the hosts 32.6% · guest 67.4%24:00 · the hosts 19.2% · guest 80.8%24:00 · the hosts 19.2% · guest 80.8%27:00 · the hosts 17.4% · guest 82.6%27:00 · the hosts 17.4% · guest 82.6%30:00 · the hosts 22.4% · guest 77.6%30:00 · the hosts 22.4% · guest 77.6%33:00 · the hosts 4.4% · guest 95.6%33:00 · the hosts 4.4% · guest 95.6%36:00 · the hosts 21.7% · guest 78.3%36:00 · the hosts 21.7% · guest 78.3%39:00 · the hosts 28.2% · guest 71.8%39:00 · the hosts 28.2% · guest 71.8%
Sharpest disagreement ▶ 28:15 Rejecting safe phased rollout assumptions

Maxim pushes back against the premise that phased model rollouts are safe, arguing that foreign adversaries deploying unconstrained models renders controlled release strategies dangerously naive.

Hardest push from the hosts ▶ 39:13 Pressing on AGI belief contradiction

Sarah directly confronts Maxim on an internal contradiction, demanding he reconcile his self-proclaimed radical AGI-pilled perspective with his continued focus on human defense teams.

Biggest teaching moment ▶ 13:03 Reframing proxies versus intent underwriting

Maxim educates Sarah on why network proxies are merely integration plumbing and fail to address the core problem of underwriting semantic intent across distributed agent execution.

The host holds their own ▶ 17:14 Formulating the Blitz chess architectural model

Sarah demonstrates deep domain thinking by introducing the Blitz chess analogy to describe asymmetric compute allocation and fast intuitive routing for AI oversight.

the scores for every segment, with the reasoning behind each
ChapterTopicThe hosts as informed peerGuest teachingGuest disagreementThe hosts pushing backWhy
The Evolution from Data Loss Prevention to Autonomous Agents 6512 Sarah sets the context by contrasting early DLP paranoia with current agentic panic and recalls warning Maxim about running out of money before agent adoption arrived. Maxim details the shift triggered by AutoGPT and how enterprise adoption outpaced early expectations.
Onyx Security's Mission: The Secure AI Control Plane 5601 Sarah shares her own experience of over-permissive coding agents deleting data and asks for enterprise deployment breakdowns. Maxim provides detailed proportions across low-code workflows, internal builds, and autonomous coding tools.
Why Traditional Identity and Endpoint Security Fail for Agents 6612 Sarah presses on why the massive incumbent security stack fails to protect against agent risks. Maxim explains the fundamental flaw of static identity and endpoint controls when agents require broad user permissions and contextual intent.
The Limits of Proxies and Rule-Based Policy Engines 7723 Sarah challenges the problem from a traditional security perspective, asking why smart proxy policy engines fall short. Maxim reframes proxies as mere integration methods and explains why specialized small models are required to cheaply decide when to trigger expensive oversight agents.
The Blitz Chess Analogy for Compute Allocation 7501 Sarah introduces a Blitz chess analogy for compute allocation under time pressure. Maxim strongly agrees, elaborating on how top players use fast intuition for low-risk moves and allocate heavy computation only during critical high-risk junctures.
Mechanistic Interpretability and Inspecting Model Internals 5612 Sarah highlights industry skepticism regarding mechanistic interpretability. Maxim argues that while human cognition struggles to map activations directly, smarter models will soon assist in cracking model internals.
Earning Fortune 100 Enterprise Trust as an Early-Stage Startup 6512 Sarah questions how a small, early-stage Israeli startup wins deep trust from Fortune 100 enterprises and raises concerns about automated vulnerability research. Maxim notes that acute operational pain forces enterprises to partner early and foundational controls must be established.
Phased Model Rollouts Versus Global Competitive Realities 5622 Sarah probes the viability of controlled rollouts for dangerous dual-use security models. Maxim counters that controlled rollouts risk leaving organizations defenseless against adversarial foreign models, urging broader access and foundational defenses.
Onyx's Long-Term Technical Strategy in an Evolving AI Landscape 7723 Sarah poses the central startup dilemma: whether frontier foundation model labs will inevitably absorb the agent governance layer. Maxim methodically outlines why buyer psychology, proprietary historical telemetry, and multi-vendor environments ensure independent oversight will prevail.
Understanding Security Workflows and Israeli Cyber DNA 6611 Sarah asks about the distinct edge of the Israeli cyber ecosystem compared to Silicon Valley AI labs. Maxim emphasizes deep empathetic understanding of operational security workflows over pure model building.
Balancing Near-Term Enterprise Needs with an AGI-Pilled Future 6514 Sarah presses Maxim to reconcile his extreme long-term AGI convictions with building enterprise software for human security operators today. Maxim explains that systems must cater to today's human buyers while designing UX primitives compatible with incoming agent workforces.

Statements from this episode (24)

Assertion Not checkable as stated
Claude Code became the first widely used autonomous AI agent
“We had a cloud code, which became like the really first widely used autonomous agent.”
Maxim Bar Kogan May 28, 2026 ▶ 4:15
Assertion Not checkable as stated
Anthropic revenue comes from enterprises replacing developers with Claude Code
“Like Anthropix revenue is coming from enterprises that are paying for cloud code to do a lot of the work that developers used to do.”
Maxim Bar Kogan May 28, 2026 ▶ 4:56
Prediction Not checkable as stated
Human-in-the-loop oversight will fail as AI agent actions scale exponentially
“Things that we thought might be useful in the past, like A human in the loop. Now that you're going to have a hundred X, a thousand X, a million X of these actions, that's not going to work.”
Maxim Bar Kogan May 28, 2026 ▶ 6:03
Assertion Supported
Autonomous AI agents recently caused enterprise downtimes and credential leaks
“We've seen some of that happen lately with downtimes that were caused by agents doing their own thing, agents accidentally publishing code and tokens that they weren't supposed to and so on.”
Maxim Bar Kogan May 28, 2026 ▶ 6:41
Assertion Not checkable as stated
Autonomous coding agents make up over 50% of enterprise AI usage
“Of these categories, I would say roughly at this point, over 50% is the autonomous coding agents and assistants in the average enterprise. Then probably 45% is is those low code automations. And the last two percent are really the first party ones that they're…”
Maxim Bar Kogan May 28, 2026 ▶ 8:50
Assertion Not checkable as stated
Autonomous agents are the fastest growing AI category but lack controls
“And so I think that today autonomous has by far the fastest growing category and today typically comes without any controls.”
Maxim Bar Kogan May 28, 2026 ▶ 9:49
Opinion
Legacy security tools lack context to monitor autonomous AI agent systems
“A lot of these existing tools, they don't have the context to understand what these very flexible and predictable systems are doing.”
Maxim Bar Kogan May 28, 2026 ▶ 12:21
Insight
Without specific controls, enterprises must choose between neutered AI or risk
“If you're not building some kind of controls that are built for these systems, then you're either gonna end up limiting them a lot, making them almost much less useful to the enterprise, or you're gonna miss a lot of pretty dangerous things that they might be …”
Maxim Bar Kogan May 28, 2026 ▶ 12:28
Insight
Proxy security architectures cannot secure modern distributed AI workloads
“There's a lot of systems where that's just not viable technically because AI today runs On the cloud, on someone else's infrastructure, on your endpoint, and just proxy is not always an option.”
Maxim Bar Kogan May 28, 2026 ▶ 13:08
Insight
AI security requires underwriting model intent rather than inspecting data traffic
“The hard problem is understanding if what I should do now. It turns out that in the case of AI systems, that is the hard question. Like, what is the engine that needs to underwrite these different actions and say if they're okay or not? And because We need to …”
Maxim Bar Kogan May 28, 2026 ▶ 13:33
Insight
Supervising AI with 1:1 agents is a cost and latency dealbreaker
“Because if I need to run an agent for every agent you're running as your security vendor you're going to be paying for me More than you're paying for your AI, right? So it's not, it's pretty much a deal breaker. And also it's going to be so slow.”
Maxim Bar Kogan May 28, 2026 ▶ 15:25
Insight
Efficient AI systems concentrate compute overwhelmingly on high-risk decisions
“It's the efficient way to run a computation, right? You don't want to spend too much intelligence or you don't have to, and you want to spend a lot of intelligence, overwhelmingly a lot in situations where there's high risk.”
Maxim Bar Kogan May 28, 2026 ▶ 18:22
Prediction Not checkable as stated
Independent AI oversight will become a $100 billion market opportunity
“So I think it will be crucially important if you have AI companies that are 10 trillion dollar companies, we think you want a company that is not the vendor of the AI itself to oversee and help you control what AI is doing. And we think that's an opening that'…”
Maxim Bar Kogan May 28, 2026 ▶ 20:40
Opinion
Understanding model weights and activations is essential for AI safety
“We believe that understanding the internal weights and activations, what is the internal structure, the mathematical structure of these systems is going to be at least part of the solution.”
Maxim Bar Kogan May 28, 2026 ▶ 21:49
Prediction Not checkable as stated
Smarter AI models will make mechanistic interpretability and tracking more effective
“But as we're starting to have models that are much smarter than us, at least in some important ways, we think that we'll be able to start tracking mechanistic capability much more effectively.”
Maxim Bar Kogan May 28, 2026 ▶ 22:44
Insight
Enterprise security leaders prefer early startup risk over ignoring emerging threats
“At the end of the day, security people are in the business of revenue preservation. They understand that this is a, between the two risks, they want to partner with someone that's promising and early rather than not do anything.”
Maxim Bar Kogan May 28, 2026 ▶ 24:59
Opinion
The market is not overreacting to automated AI vulnerability discovery tools
“I think that, first of all, the market is not overreacting. I think this is a huge change in what this means for security teams.”
Maxim Bar Kogan May 28, 2026 ▶ 26:13
Opinion
AI labs should broaden enterprise access to offensive security models
“I would really encourage that we expand The amount of companies that get access to this and make it much easier for people to get.”
Maxim Bar Kogan May 28, 2026 ▶ 28:50
Insight
Enterprises must assume offensive AI models are inevitable and invest now
“I would advise everyone to assume that these models are coming anyway. The only thing you can do right now is to invest in these foundational controls that will stop the downstream effects of these vulnerabilities are going to be found in their systems.”
Maxim Bar Kogan May 28, 2026 ▶ 28:57
Prediction Not checkable as stated
Enterprises adopting diverse AI tools will outperform single-vendor adopters
“I personally think that The companies that are gonna do well are the companies that are gonna allow a lot of different tools because the landscape is changing so quickly. If you bet on OpenAI, here we go, that would have been the safest bet in the world, but s…”
Maxim Bar Kogan May 28, 2026 ▶ 29:49
Prediction Not checkable as stated
Foundation model vendors will eventually eliminate basic AI mistakes directly
“I think that problem will go away. I think we're heading for much smarter models that make less silly mistakes and our role is not going to be to prevent silly mistakes. That will be taken care of by the model vendors because they're very incentivized to do it…”
Maxim Bar Kogan May 28, 2026 ▶ 34:12
Assertion Not checkable as stated
Enterprises withhold historical AI agent data from OpenAI and Anthropic
“So for example, we're allowed to look at a lot of historical data of how these agents have behaved, but enterprises that are not willing to have Anthropic or OpenAI give that historical data because they know these are very data hungry companies that will want…”
Maxim Bar Kogan May 28, 2026 ▶ 35:28
Prediction Not checkable as stated
Enterprise security teams and knowledge work will soon be run by agents
“I do think that security teams are also going to be, become completely high powered. And, but I do think that, you know, they're going to be run by AI agents and like everything else in, in kind of the knowledge workspace, I would, in the near future.”
Maxim Bar Kogan May 28, 2026 ▶ 39:32
Insight
Designing software for AI agents requires optimizing context tokens to prevent overload
“For a human, it might be not overwhelming them with too much information that is irrelevant. For an agent, it might be not wasting too many tokens in their context when we talk to them. And maybe it's the same thing, really.”
Maxim Bar Kogan May 28, 2026 ▶ 40:26
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 100 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.