Shadow AI & Sandbox Escapes: Why You Need an Agentic Control Plane?

View Show Notes and Transcript

When Claude Cowork hits a roadblock, it doesn't give up, it writes a custom Python script and downloads an untrusted NPM package just to bypass its restrictions and finish its goal. Are your security tools close enough to stop it?  In this episode, Ashish sits down with Michael Leland, VP, Field CTO at Island, to discuss the critical need for an Agentic Control Plane. Michael breaks down why traditional security silos (EDR, DLP, CASB) fail to provide visibility when autonomous AI agents execute tasks outside the network, and why the browser is the ultimate line of defense for monitoring user intent.  We explore the massive reality of Shadow AI  and the hidden danger of well-intentioned employees accidentally hooking up sensitive data to public LLMs. Finally, Michael shares practical strategies for solving token waste through "model fit steering" and managing the complex "two-hop problem" when an agent calls another agent.  

Questions asked:
00:00 Introduction to the Agentic Control Plane
01:50 Michael Leland’s Background (Cabletron, Nitro Security, SentinelOne)
03:20 Why Island Evolved from the Browser to the Desktop for AI
05:50 The Failure of Traditional Siloed Security (EDR, DLP, CASB)
07:20 Goal-Oriented AI: How Claude Cowork Downloads Untrusted NPM Packages
08:30 Model Fit Steering: Routing Users to the Right LLM for the Right Price
10:30 The Threat of Malicious AI Skills and Plugins
11:30 The Well-Intentioned Insider Threat (The Next Cambridge Analytica)
13:00 Uncovering Shadow AI: From 8 Tools to 243
15:10 Token Brokering at the MCP Gateway
16:40 Protecting Non-Human Identities (NHI)
18:20 Solving the "Two-Hop" Problem (Agent-to-Agent Communication)
21:00 Fixing Hallucinations with Corporate RAGs
25:40 Calculating AI ROI Beyond "Token Maxing"
28:40 The "You Laugh, You Lose" Cybersecurity Joke Challenge

Michael Leland: [00:00:00] 7,600 skills, like over 800 of them were malicious

Ashish Rajan: My browser knows more about me than my doctor, my bank, and my mother combined, and none of them are securing it.

Michael Leland: Unfortunately, it's not funny, it's true. I had a customer insist that they only had eight sanctioned AI tools in use. We did an assessment, we found 243 tools.

Michael Leland: You never onboarded your agents. So what does it do? It writes a Python script that downloads an NPM package from an untrusted source- Yeah ... in order to achieve its goal. AI is goal-oriented. Say yes to AI, but do it safely. I fully expect we will hear, if it hasn't happened already, some Cambridge Analytica size breach, not by a malicious actor, but by a well-intentioned user-

Ashish Rajan: Agentic control plane is forming in your organization, you probably don't even realize it.

Ashish Rajan: I'm talking about things like where is AI consumed, used, and probably applied in your organization. I had a great conversation with Michael Leland from Island to talk about the evolving space of agentic control plane. [00:01:00] What does that mean for you as an organization? Where should you apply that? How should you approach it?

Ashish Rajan: If you're building an AI security program or uplifting one, how do you approach the problem of agentic control plane in an organization? All that and a lot more in this episode with Michael. If you are here for a second or third time and have been finding the episodes valuable, I would really appreciate if you hit the follow or subscribe button.

Ashish Rajan: We are on all the podcast platforms like your YouTube, LinkedIn, U- Apple, Spotify. I hope you enjoy this conversation with Michael. Talk to you soon. Peace. Hello, and welcome to another episode of podcast. I've got Michael with me. Hey man, thanks for coming on the show.

Michael Leland: Thanks, Ashish.

Ashish Rajan: Uh, let's start with this 'cause you've been a second time guest.

Ashish Rajan: Maybe for people who have not seen the first episode, if you can give a brief about yourself, your professional background.

Michael Leland: Sure. So, uh, for those of you that, that go back as far as I do, I got my start at a company called Cabletron Systems back in the '90s.

Ashish Rajan: Oh, wow.

Michael Leland: This is back in the days when, you hadn't bought your first switch or hub back then.

Michael Leland: Yes. You were gonna buy it from somebody.

Ashish Rajan: Yeah, yeah.

Michael Leland: Right? So Cabletron was one of those vendors. This is before 3Com, Allied Tele讯, SynOptics. Oh, wow. Right? Early, early days.

Ashish Rajan: Yeah, yeah.

Michael Leland: Leaving [00:02:00] that role, uh, a couple of startups CTO for Avaya for a few years- Mm-hmm ... where I managed the, uh, conversion from analog telephony to digital telephony.

Ashish Rajan: Mm-hmm.

Michael Leland: And then, um- couple more executive roles at cybersecurity companies. Prior to joining Island, I spent three years at SentinelOne as their chief cybersecurity evangelist. But before that, and one I'm probably most proud of before this one, uh, I was co-founder and CTO of Nitro Security. Oh. So I built a SIEM, which I sold to McAfee in 2011-

Ashish Rajan: Wow

Michael Leland: before they completely destroyed my product by 2018. But that's a topic for another conversation.

Ashish Rajan: Yeah, fair. And I think, and, uh, Am glad said that as well, because obviously you've been in the industry for a while, you've seen the other sides as well, and agentic control plane is something that you and I spoke about.

Ashish Rajan: I want you to, if you can define that, 'cause a lot of people probably don't even understand they're creating that without even realizing it, so maybe we can shed some light on that first.

Michael Leland: Sure. I think it, it helps to take a step back and realize who Island was when we first started.

Ashish Rajan: Yeah.

Michael Leland: Right? Six years ago, we realized the fact that the majority of knowledge workers were leveraging a consumer browser- Mm-hmm

Michael Leland: to access business [00:03:00] applications and data. That hasn't changed, right? Mm-hmm. So we continue to evolve in protecting, uh, the enterprise knowledge worker while they're in a browser. Yeah,

Ashish Rajan: yeah.

Michael Leland: But about three years ago, customers kept telling us, "We love what you're doing for us inside the browser," right? Data protection, intelligent network routing and steering "But I've got a long tail of thick apps."

Ashish Rajan: Yeah.

Michael Leland: And what they meant three years ago was, "I've got Word and PowerPoint and Outlook, and maybe, uh, an IDE like JetBrains or Visual Studio."

Ashish Rajan: Yeah.

Michael Leland: Most of those applications have gone to the cloud, right? The great SaaSification.

Ashish Rajan: That's right. Yeah. Yeah, yeah,

Michael Leland: yeah. But in the last Nine months AI has dragged us in the opposite direction, right?

Michael Leland: The natural habitat for AI used to be the browser.

Ashish Rajan: Yeah.

Michael Leland: Today, we've gotta contend with tools like Claude Code, Gemini CLI, Cursor, Codex. You've got various AI assistant plugins to your various IDEs. And so now more than ever, the desktop implementations of these tools are just as important to protect.

Ashish Rajan: Yeah.

Michael Leland: Every one of these tools, whether it's accessed on the web, uh, or from a desktop application, now offers you the option of connecting to other applications, and that's normally done through an [00:04:00] MCP. Yeah. Right? A model context protocol is kind of the plumbing that gets you from an agent to an application that you're trying to connect to.

Michael Leland: Yeah. Along that path, you've got any number of, of challenges with visibility, inspection. Uh, and so because there are so many modalities of AI these days, generative AI, interactive chat, co-pilot tools co-work applications, coding assistants, autonomous AI agents your own homegrown apps, because the broad spectrum of AI, um, has forced us to look in much multiple areas, the new control plane of AI has- Yeah

Michael Leland: to be as broad as the use cases for AI. Some of them are in the browser.

Ashish Rajan: Yeah.

Ashish Rajan: Some of them are at the MCP gateway. Mm-hmm. Some are at the LLM gateway, and others are all the way up in the provider world, things like open telemetry.

Ashish Rajan: Yeah.

Michael Leland: Right? So being able to have, uh, an interface to have visibility, observability for all those things, real and runtime control policies against how users are interacting with it.

Ashish Rajan: Yeah.

Michael Leland: But I think more so it's, it's being able to put guardrails on your agents. And so the agentic [00:05:00] control plane in the enterprise, uh, is all about providing you all of those locations through which you get both visibility and enforcement of, uh, data protection and a, a fair usage policy.

Ashish Rajan: Is there a certain level of usage of AI people should already have?

Ashish Rajan: 'Cause I, uh, to what you said, a lot of people may be probably walking on the idea that, "Hey, I already have an EDR. I have an MDM. I have..." I mean, you have our central one as well. So th-they, uh, they have, at least most of the enterprise have some level of Integration with security products across the board.

Ashish Rajan: Where was the gap, uh, in what you're sharing about agentic control plane versus what we already do as most of us have been building security programs for some time with all these products that still claim that they can do agentic?

Michael Leland: So every one of the products that people already have, right? And we've, we've invested a ton of money in various compensating controls and security products all along the way from EDR to DLP to CASB to appsec, like all of these things.

Ashish Rajan: Yeah.

Michael Leland: All of them are great- Mm ... in their limited swim [00:06:00] lane.

Ashish Rajan: Mm.

Michael Leland: But any one of those have gaps in visibility and enforcement for the others. So your only option is deploy one from vendor A, one from vendor B, one from vendor C- Yeah ... and then try to integrate those and stitch them together. The idea of having a single policy across one ubiquitous control plane is really the only way to get away from AI sprawl-

Ashish Rajan: Yeah

Michael Leland: uh, control pane- plane sprawl-

Ashish Rajan: Yeah ...

Michael Leland: agent sprawl. So our premise is if you can consolidate all of those, uh, or at least as many as possible, one, you have a much simpler user experience- Mm ... right? From an administrative perspective, you're not managing from multiple consoles, you're not managing multiple DLP policies in different locations.

Ashish Rajan: Yeah.

Michael Leland: You're doing it all ubiquitously from one location. But two, you don't have to rewrite policies for each individual platform, right? You write it once at a very high altitude, it pushes down to whatever the appropriate enforcement mechanism is. If the access to AI is browser, you've got that covered.

Michael Leland: Yeah. If the access to AI is, is agentic, uh, through an MCP, you've got your control plane [00:07:00] there as well. The idea is to be as close to where work happens.

Ashish Rajan: Yeah.

Michael Leland: The problem with some of these vendors and not to call anyone out in particular- Yeah, yeah ... uh, if I have to wait till my data enters a pop where it gets broken and inspected in the cloud, I'm too far away from where the user is interacting with AI.

Ashish Rajan: Yeah.

Michael Leland: When Claude Code accesses data on my local file system-

Ashish Rajan: Yeah ...

Michael Leland: I don't see that in the cloud.

Ashish Rajan: No.

Michael Leland: The cloud doesn't see what I have on the page at the current time when I'm opening a webpage, doesn't know what I'm clicking on when I'm doing so. And then the other, the other argument is agents go off the guardrails frequently, right?

Michael Leland: We saw this with the sandbox escape recently- Yeah ... between two very popular AI vendors.

Ashish Rajan: Yeah.

Michael Leland: I saw last week Claude Cowork decide that it, it hit a brick wall. It couldn't go any further. So what does it do? It writes a Python script- ... that downloads an NPM package from an untrusted source-

Ashish Rajan: Yeah ...

Michael Leland: in order to achieve its goal.

Michael Leland: AI is goal-oriented. Yeah,

Ashish Rajan: yeah.

Michael Leland: Um, and if, unless you keep it in, uh, a governance and data protection guardrail it will frequently hop out and do its own thing.

Ashish Rajan: [00:08:00] Mm.

Michael Leland: Right? So understanding what AI is doing, and then limiting what it's allowed to do, either through, uh, a data protection policy by managing OAuth token subscriptions.

Ashish Rajan: Yeah.

Michael Leland: Right? If an agent requests, let's say, a read-write access to Salesforce our MCP gateway can actually say, "You're allowed to get to Salesforce, but you're only allowed to get a read-only token to Salesforce." Mm-hmm. So it's something called token brokering. Yeah,

Ashish Rajan: yeah.

Michael Leland: And then the last one really is about things like model fit steering.

Michael Leland: When a user asks a question, wouldn't it be nice to be able to say "That question can be best answered by this model," right? So steer it toward the model that's most appropriate. Your developers probably prefer Anthropic.

Ashish Rajan: Yeah.

Michael Leland: Right? Your lawyers, they live in the world of LexisNexis and Harvey.

Michael Leland: Yeah.

Michael Leland: Your general purpose AI consumers can get by with Copilot or Gemini or ChatGPT, but why would you burn down the most expensive tokens on a novice user asking novel questions of AI?

Ashish Rajan: Yeah.

Michael Leland: Right? So this control plane provides that mechanism to give both visibility and enforcement, but also the appropriate steering toward, better token consumption utilization.

Ashish Rajan: Yeah, and I think that's a interesting point as [00:09:00] well because you've kind of mentioned all these layers, right? And I love the example you shared about the sandbox ex-escape and the Claude code usage being too far from the cloud. What-- So a lot of people think of these as, "Hey, it's my prompt injection. It's my LLM firewall."

Ashish Rajan: And there's, there's, there's so many words to this now as well, just to describe the kind of threats that this stops, and maybe the example of threats you may have seen would be a good one as well. Because I think people A lot of people still assume that SQL injection is a problem that we're trying to solve or like a, another, let's just say another quote-unquote technical vulnerability.

Ashish Rajan: Mm-hmm. Where- whereas I think a lot of us have been kind of, and I'm not saying everyone, but in general, there's people who have not dipped their toes into AI yet. They're still kind of going, "Isn't this... I have an ADR solution for my SQL injection pieces, my SOC." What is something that specific came across in your mind as a clear example of, "Hey, this is no longer just a technical vulnerability"?

Ashish Rajan: It's more than just, "Hey, I have, I, I mean, some- I'm trying to [00:10:00] put a SQL injection into a browser, into an application."

Michael Leland: So I think the biggest example here is whether you know it or not, skills and agents are already part of your work stream.

Ashish Rajan: Mm.

Michael Leland: Uh, even if you're only using generative AI,

Ashish Rajan: right?

Michael Leland: Mm.

Michael Leland: There are options within a generative AI conversation that says, "I could make this response better if you gave me access to Slack." Yeah. "Or if I gave you access to Salesforce," right? And so the well-intentioned user may say, "Yeah, I want a better experience. I'll go ahead and connect that."

Ashish Rajan: Yeah.

Michael Leland: That process didn't go through onboarding, right? You never onboarded your agents.

Ashish Rajan: Yeah.

Michael Leland: Your, your agents didn't go through HR training. They didn't go through acceptable use training. They don't understand your data governance policy. You just freely accept them into your workspace.

Ashish Rajan: Yeah.

Michael Leland: They are the new virtual knowledge worker.

Ashish Rajan: Yeah.

Michael Leland: Right? The problem with some of these skills and, and plug-ins is they haven't been vetted.

Ashish Rajan: Mm.

Michael Leland: Right? Our research found, uh, a GitHub repository with 7,600 skills, like over 800 of them were malicious. The other challenge is it's not just the malicious actor that we have to worry about, it's the very [00:11:00] well-intentioned user who doesn't know what he's doing.

Ashish Rajan: Yeah.

Michael Leland: Right? He answers yes to a question because Claude said, "I can do it." You say, "Sure, go ahead and do it."

Ashish Rajan: Yeah.

Michael Leland: And I, I've said this, I may have even said it last year, I fully expect we will hear, if it hasn't happened already, some Cambridge Analytica size breach, not by a malicious actor, but by a, a well-intentioned user who misconfigures the data path that he's allowing AI to use, and all of a sudden he connects, uh, sensitive data to a public LLM.

Michael Leland: Next thing you know, all of that data is going out the door.

Ashish Rajan: Yeah. I love the example also because it-- the-- it's funny, I think maybe a couple of years people would think that's not realistic, but now it almost... You hear so much, so, so much more about sandbox escape from an AI. You think about third party, uh, there was another one where third party exploit happened where someone got took over...

Ashish Rajan: I think it was a Vercel, uh, breach that happened where the third party was, uh, I guess they were hacked, and, [00:12:00] uh, Vercel was using that third party as a Google Auth approved for calendar improvement. Someone there was-- You look at that and go, there's all the elements to what you said. There's supply chain in there, there is the MCP pieces in there, there's skills in there, and I think it's almost the, the scale of it across an organization is sometimes quite hard, and to be able to help people deploy that safely.

Ashish Rajan: What are you finding in the customers that you talk to, how they are... To what you said, the agentic control plane is across everywhere AI is being used. What do you find in your customers as a, as a easy win to start with in terms of, hey without disrupting the... You know, 'cause we're all being asked to, "Hey, we-- I want security to disrupt, I want you guys to help us move forward faster," and all of that.

Ashish Rajan: List, this list goes on. Yeah. What are some of the ways you find your customers, A, in terms of maturity as well, where they are, and what are they used to kind of have those easy wins in the beginning?

Michael Leland: So the easiest win possible before any enforcement is [00:13:00] visibility.

Michael Leland: Most organizations have no idea what their shadow AI problem looks like.

Michael Leland: I had a customer insist that they only had eight sanctioned AI tools in use. We did an assessment-

Ashish Rajan: Yeah ...

Michael Leland: with just our browser extension.

Ashish Rajan: Yeah.

Michael Leland: We found two hundred and forty-three tools. Jesus. If you tell a user no, he will find a way around your no- Yeah ... to get a yes. And, and the incentives in them using AI, you know, are known far and wide.

Michael Leland: It's gonna improve my productivity. I'll be more innovative. I'll be able to get more work done efficiently.

Ashish Rajan: Yeah.

Michael Leland: So they hear these, these nirvana, uh, these panacea of, of outcomes- ... and they think, "Why wouldn't I want to use AI?"

Ashish Rajan: Yeah.

Michael Leland: You've also got this dichotomy of your... The board is telling people and the executive team are telling their, their staff, "Thou sh- must use AI- Yeah

Michael Leland: because it's gonna make us better."

Ashish Rajan: Yeah.

Michael Leland: Then you got the legal and the compliance team saying, "Be careful using AI, right? Because you don't know." Who- every one of us has seen this problem where I've got a SaaS application that I approved and onboarded a year ago, 10 years ago.

Ashish Rajan: Yeah.

Michael Leland: Tomorrow, a new little button pops up in the upper right-hand corner, and it's a little AI [00:14:00] button.

Michael Leland: I didn't ask for that. I didn't approve that. It just shows up in front of my users.

Ashish Rajan: Yeah.

Michael Leland: And now my user has to determine is that a safe button to hit or not?

Ashish Rajan: Yeah.

Michael Leland: So visibility is the first thing that, that all of our customers wanna get a handle on. Visibility extends to all ways that users interact with AI.

Michael Leland: AI in the browser via a URL. Mm-hmm. AI in the browser via a plugin, AI on the desktop with tools like Claude Code and AI assistant plugins to IDEs.

Ashish Rajan: Yeah.

Michael Leland: But visibility also extends to every MCP server that's being used, every skill that's being used, every package that's installed from an NPM server.

Michael Leland: And it's not so much the ability to just inventory all of this, because that's a relatively easy task.

Ashish Rajan: Yeah.

Michael Leland: It's also doing the risk assessment of what those skills and plugins could do.

Michael Leland: So we built a tool that actually evaluates all of the skills, all of the MCPs, all of the plugins and tools and gives it a risk assessment.

Michael Leland: So you can now set thresholds and say, "This is a, uh... my policy says I'm allowed to use this MCP server but I'm going to restrict it from having write access to [00:15:00] Salesforce."

Ashish Rajan: Mm. "

Michael Leland: I'm going to allow this application, but it's going to be restricted from having file system access to an, an untrusted or unmanaged device."

Ashish Rajan: Yeah.

Michael Leland: Having that granularity in the control plane helps you really kind of put the fine tunings on the policy that you need to enforce. Say yes to AI, but do it safely.

Ashish Rajan: Interesting. 'Cause do you find that are there specific... Uh, 'cause you mentioned MCP, 'cause MCP has a second hop problem, as, like, some people like to say it.

Ashish Rajan: Could you describe that and how are you seeing your customers kind of manage that as well?

Michael Leland: Yeah. So second hop can be a problem. It can also be an advantage. So when we built our MCP server we built it so that it should be the first intercept point, and that's so that we guarantee that we're in the path of all MCP requests.

Ashish Rajan: Yeah.

Michael Leland: Now, it doesn't have to be the first, it has to be in there somewhere.

Michael Leland: The advantage is that we can do something called token brokering, right? This is the one that says if the agent asks for an MCP connection to Salesforce and it asks for read write, we can say yes, but only read only.

Michael Leland: Okay. Right?

Michael Leland: The other advantage is the agent itself never has [00:16:00] the official OAuth token of that application. It has the one that we've issued. Mm-hmm. So now you have to deal with things like NHIs, right? Non-human identities.

Ashish Rajan: Yeah.

Michael Leland: There's a very distinct difference between the way a user interacts with AI and an agent interacts with AI.

Ashish Rajan: Yeah.

Michael Leland: It's not always the same policy. It's not always the same set of credentials. Yeah. Uh, and the OAuth token needs to be protected so that the agent itself, if it's, if that machine were compromised, go back to the EDR, analogy not everything's perfect at 100%. Mm-hmm. So I need to make sure that if that machine were compromised, the OAuth token they have is restricted to bare minimum.

Michael Leland: Mm-hmm. It's the next layer of, uh, least privilege access concepts. Mm-hmm. Right? Identity was the first. That was the ZTNA principle.

Ashish Rajan: Yeah.

Michael Leland: Device posture is second. Network location is third. Geolocation is fourth and now the NHIs.

Ashish Rajan: Yeah. Yeah, and do you find that NHIs an interesting one as well, 'cause a lot of people already have an identity access management program.

Ashish Rajan: They're trying to... don't I already cover for it? Is it different Like, what are you finding as the the gap in [00:17:00] how people look at identity gaps in MCP agents versus, like, what traditionally we have done with identity for such a long time?

Michael Leland: You know, the way MCPs were first built and the way agents used to connect to applications were just like we used to do service accounts in the old days.

Michael Leland: Yeah. Right? You issue one token, it gets delivered, sometimes it's held in clear text. Yeah. Like, of, of all possible scenarios, that's the worst. But now we've got better things, like we've got, we've got post-quantum ciphers that are protecting those things. Uh, and the abstraction layer between what the agent thinks is his, is his credential and the actual credential that's required that's the gap that you can cover.

Michael Leland: Right? So non-human identities are important, and many IdPs are now building extensions or, or kind of adjacencies. Entra now has an Entra ID for NHIs.

Ashish Rajan: Yeah,

Michael Leland: yeah. Okay. Right? We have a privileged access management solution that can extend that capability out to, uh, these agents as well.

Michael Leland: So it's also important to know that some of these transactions, these agentic transactions may only use that, that token once, right?

Michael Leland: So you've got a, a massive problem of things like [00:18:00] token rotation.

Ashish Rajan: Yeah,

Michael Leland: yeah. Like, this is a, a single use token.

Ashish Rajan: Yep.

Michael Leland: How do I track that back to the entire behavioral chain of the user? But the bigger one, I think, we can cover user to agent, that's the browser stuff. Yeah. We can cover, desktop to agent, right?

Michael Leland: Yeah. Um, with things like compliance API hooks. The harder ones are the, the two-hop problem that I think is the biggest challenge is agent to agent. If I ask Claude Code to go to Salesforce and run a query for me about my customer data-

Ashish Rajan: Mm. ...

Michael Leland: it could choose to use a skill that's published in uh, in Agentforce.

Ashish Rajan: Yeah.

Michael Leland: So now that agent is not running on my network, so I have no visibility to it on my SASE product. That's

Ashish Rajan: right.

Michael Leland: My CASB's not gonna see it 'cause it's on Salesforce's network.

Ashish Rajan: Yeah.

Michael Leland: But we have visibility into both the request that was made and the response. So visibility is not just about what tools are being used, it's also about the auditability of all of the transactions, every prompt and every response, every tool call, every tool result.

Ashish Rajan: Yeah.

Michael Leland: Yeah. Right? Being able to see it at that level of [00:19:00] granularity allows you to build a better governance policy around actual usage.

Ashish Rajan: So would it be and, uh, maybe I'm oversimplifying this, is it more specifically e- endpoint from a related, but is it endpoint which is on my laptop or endpoint which is my cloud, endpoint which is like...

Ashish Rajan: How do you segregate this? 'Cause a lot of people obviously looking at this from all the angles, right? So is the agentic control plane that you see at the moment that is top of mind for your customers, is that the one? Which, which one is it?

Michael Leland: So it's, it's... That's an important question.

Ashish Rajan: Yeah.

Michael Leland: The reason the agentic control plane is as broad as it is, is because of all the different use cases, modalities, and even the edge cases of AI.

Ashish Rajan: Yeah.

Michael Leland: Ours go from left to right, the browser-

Ashish Rajan: Yeah ...

Michael Leland: a pl- an extension-

Ashish Rajan: Yep ...

Michael Leland: the desktop, and then the network. Mm. Those are the first four.

Ashish Rajan: Yeah.

Michael Leland: But that only gets you so far. That only gets you on your network.

Ashish Rajan: Yep.

Michael Leland: Now you've gotta handle off your network. So now you've got MCP gateway.

Michael Leland: You got compliance API integrations.

Michael Leland: You got LLM gateway integrations, and you got open telemetry Anywhere along that path, you will get some level of [00:20:00] visibility. All the way on the right, you don't get enforcement, you get audit.

Michael Leland: All the way on the right at the open telemetry side, the OTel integrations, you get things like token utilization, performance metrics AI adoption rates.

Ashish Rajan: Mm-hmm.

Michael Leland: All the way to the left, you get where users are actually interacting with AI. AI in the browser, AI on the desktop, and the important thing is that's where users are interacting with AI, so that's where the control plane has to provide the highest level of enforcement.

Ashish Rajan: Yeah. And one thing that has been top of mind for a lot of people is that hallucination hasn't really gone away with AI, right?

Ashish Rajan: And I think t- to your point, a lot of people can put a lot of effort into visibility across the board and build the agentic control plane. H- what's the way you've found to have your customers build that trust between the AI output as well as the, the skepticism people have towards, like, I don't know how much is...

Ashish Rajan: And I, I think I understand where s- skepticism comes from, 'cause when it comes to security, you don't want an incident to be passed as a false positive by an automation for- Right ... and I oversimplify this, [00:21:00] but that's how they would think about this. W- how do you find your customers are building that level of trust with AI that they can, "Oh, okay, now my problem pool is a lot more smaller than it was before," and it's just not prioritization?

Michael Leland: So hallucinations occurred more in the, the frontier models when it was trained on public data.

Michael Leland: Most organizations have said there's a bifurcation now between usage of public data in an LLM and my corporate tenant.

Ashish Rajan: Yeah.

Michael Leland: In my corporate tenant, I can train it better. Mm. I can also enhance that with a RAG.

Michael Leland: I can make sure that it's trained on my knowledge base, so when I ask questions, it's answering it from my Slack, my Confluence, my Teams. Yeah. Right? It understands more about my business- Yeah ... so I trust the information it's providing because it was trained on data that I wrote, not data that was consumed from Reddit.

Ashish Rajan: Mm-hmm.

Michael Leland: Right? So I have more trust in my individual RAG because it's built not only with a frontier model, but it's a, it's also a domain-specific LLM.

Ashish Rajan: Yeah.

Michael Leland: Right? Yeah. Not a public open source LLM. [00:22:00] I think as we're getting more of these open weight models too, where you can start weighting it yourself and figuring out how to, how to tune some of the bias out you've also got issues of toxicity and harassment and content moderation you have to worry about.

Michael Leland: Uh, you've got PII and data exfiltration risks, like all of those things still exist. But to your point about trust in the model I, I trust the model when I get answers back from a knowledgeable source that wrote it- Mm-hmm ... from my perspective. Yeah,

Ashish Rajan: yeah.

Michael Leland: My engineers wrote all my, my tech docs.

Michael Leland: Yeah. They wrote all the knowledge base articles. When I ask a question of my domain specific LLM that's answered from my RAG I trust the results.

Ashish Rajan: Yeah.

Michael Leland: Not imp- not e- entirely, right? Mm. Um, because it may have read something that was in a document that we created as a future enhancement that hasn't been done yet.

Ashish Rajan: Yeah, yeah. Okay. Yeah, yeah.

Michael Leland: Right? So there is still some vetting that has to be done. AI is never going to be 100% perfect.

Ashish Rajan: Yeah.

Michael Leland: Uh, and I think the risk we run more is in inherently trusting too much the response-

Ashish Rajan: Mm-hmm ...

Michael Leland: and not keeping a human in the loop. A human in the [00:23:00] loop is so important in agentic behaviors to make sure that it doesn't do something on your behalf that it, it shouldn't.

Ashish Rajan: Yeah.

Michael Leland: It's also important to keep a human in the loop even on generative AI responses, right? Does this look right? Mm-hmm. Um, does it read properly? Is it in my voice? But most importantly, is it the information and messaging that I actually want to deliver in this content?

Ashish Rajan: I, I don't know whether this is good news because also once you build the level of trust, the next question that people start asking is that depending on the organization they may be a developer first kind of organization, or they may be an enterprise first or regulator- regulatory is more important.

Ashish Rajan: Would you still stand on the browser approach that you mentioned earlier, which is a the extension, browser extension version as the low friction? In terms of the coding world, we have Cowork, we have Claude Code, and Cowork is one of those ones which has basically been left into, like, hey, I don't know how that works, but w- I'm just gonna say no overall.

Ashish Rajan: Does the agent they control plane work across [00:24:00] agentic applications like those as well? 'Cause, I mean, Cowork is just one example. There's, like, so many more, and we mentioned Harvey and all these other ones as well before. Yep. What, what kind of control can I see there, especially when there's not much telemetry from the frontier model as well?

Ashish Rajan: How do you guys do that?

Michael Leland: When I mentioned the fact that our, our control plane is, is wide and the farthest left you go is the best chance you have of providing the highest visibility and enforcement, that would be the browser and the extension. But the next one over is Island desktop, right?

Michael Leland: The desktop component is a background service that lives outside the browser- Yeah ... which means it has visibility to file system activity, network activity, process activity.

Michael Leland: It has hooks into Cowork and Codex and, and those tools. So we can provide the same level of, of visibility and enforcement of data protection on those applications.

Ashish Rajan: Yeah.

Michael Leland: But you have to build those integrations one by one. We built it for Claude first, then we built it for Codex, and we're building it for all these others. But that's why there are so many more levels to the right where we have visibility and enforcement. If you [00:25:00] can't get it at the desktop, you get it at the network.

Michael Leland: Mm-hmm. If you can't get the network, you get it at the MCP gateway. Mm. If you have an MCP gateway, you get it at the LLM gateway. Yeah, yeah. Right? All along that path you have some mechanism, but the further left you go the better chance you have of, of dealing with that at the moment of v- the moment of view, the moment the user is actually inter- interacting with AI.

Michael Leland: Yeah. That's the only place you can actually measure user intent.

Ashish Rajan: What's the... How do people talk about ROI for programs like these, right? 'Cause I I previously, and I'm sure you would've seen it with SentinelOne days as well, a lot of that was more around, hey, these many CVEs were discovered, remediated, blah, blah, blah, list goes on.

Ashish Rajan: What does that look like in the AI world? Or what, what are people using as a way to show ROI for their security programs, I guess?

Michael Leland: The first thing is, you know, we've, we've gotta get away from this, this concept of token maxing.

Michael Leland: Right? I think that was a, a short-lived fad where people are like, "I burn more tokens than you, I must be a better, a better worker."

Ashish Rajan: Yeah.

Michael Leland: Jensen Huang, I think, actually stated that for every $500,000 employee, they should be burning [00:26:00] $250,000 in tokens.

Ashish Rajan: Oh. That's,

Michael Leland: it's convenient for the guy that builds chips that burns tokens.

Ashish Rajan: Yeah, yeah. Literally, yeah.

Michael Leland: But I think today it's all about how do you make the most efficient use of those tokens.

Michael Leland: ROI is about what is the advantage, what is the improvement, what is the innovation pipeline- Mm-hmm ... that you're getting from the use of AI? In agentic worlds, you can start calculating ROI on things like if I build an agentic workflow that takes a, a repetitive task out of the hands of a knowledge worker, something he used to do 50 times a day would take him a minute a day, or maybe a, a minute a task, right?

Michael Leland: That's probably a bad example. 50 times a day, 10 minutes a task.

Ashish Rajan: Yeah.

Michael Leland: If I can train an AI skill that does that same process for him, I know it took him 10 minutes before, I can now measure what it takes an AI agent to do that on his behalf.

Michael Leland: I can now calculate workforce productivity improvements, workforce efficiency and accuracy, uh, and I can say if I took that skill, uh, that agentic behavior from a 10-minute human task to a 30-second, uh, AI task, I've just [00:27:00] saved that user X number of minutes a day.

Ashish Rajan: Yeah.

Michael Leland: Calculate that times 50 times doing it, you can start building the ROI around that.

Michael Leland: The other one, though, is to look at the effective and efficient use of AI. Not every user needs to use the most expensive models.

Ashish Rajan: Mm-hmm.

Michael Leland: Right? Looking at this model fit steering says, if a user asks a very detailed technical question that is code related, maybe I ship that off to a one specific model.

Ashish Rajan: Mm.

Michael Leland: But if I'm asking the question, what's the temperature in Vegas? Yeah. Uh, other than really hot.

Ashish Rajan: Yeah,

Michael Leland: yeah. Right? It is, uh, maybe that should be shunted off to, uh, a 3.5 turbo model. It's not gonna cost me a whole lot of tokens.

Ashish Rajan: Yeah.

Michael Leland: Maybe that gets shunted off to my personal AI usage. Yeah. Right?

Michael Leland: Where I don't need to burn company tokens to ask personal questions.

Ashish Rajan: Yeah.

Michael Leland: So ROI can be calculated either on time savings for a user, uh, improved workforce productivity but you can also look at the things like a certain user burns so many tokens over so many sessions, but they're using the wrong model.

Michael Leland: So now I can say, "Ah, that user, who cost me $400 [00:28:00] last month if I had just tuned his model appropriately, I could have shifted him down to $20 a month in tokens."

Ashish Rajan: Reducing cost is definitely quite a bit 'cause I think token maxing to what you said has been like a thing for a while. Those are all the technical questions I had.

Ashish Rajan: I have a, uh, section which is you laugh, you lose. Uh, I have a few jokes here, hopefully. The idea here is that if I say a joke, you have five seconds to react. Hopefully, you laugh at mine. Uh, but if you don't laugh you get to go on your joke and hopefully I don't laugh at your joke. You ready for my joke?

Michael Leland: And these could be like really bad jokes, right?

Ashish Rajan: Yeah, yeah, 100%. I mean, like I'm, mine are terrible to begin. I've, I've been like saying terrible jokes. Uh, but depending on how many you have I can start mine and then you can go on yours.

Michael Leland: I have three.

Ashish Rajan: Perfect. All right. We'll, we'll do best of three then.

Ashish Rajan: I will start with my first one. Got it. We all decided the browser was a solved problem the same way we decided we have read the terms and conditions. Wow. Well done, man. Well done. Okay. Okay,

Michael Leland: what's yours? That, that was good. Yeah. Okay. [00:29:00] Why did the hacker become a gardener?

Ashish Rajan: Why?

Michael Leland: Because they were great at planting root access.

Ashish Rajan: That is good. That-- Actually, I, I love the Gardener, OI. I, I was like, "Dude, all right. Okay." Yes. I need to up my game now. I was like "My browser knows more about me than my doctor, my bank, and my mother combined, and none of them are securing it." Either

Michael Leland: Unfortunately, it's not funny, it's true.

Ashish Rajan: Like I laugh and when I enjoy.

Ashish Rajan: There you go.

Michael Leland: All right. Why did the password go to therapy?

Ashish Rajan: Why?

Michael Leland: Because it had too many trust issues.

Ashish Rajan: Okay, that, that was, that was, that was a good one. That was a good one. I'm like, okay, I have one more. This was, uh, given to me by a threat hunter. He's, he said this is one of his, uh, pickup lines . All right, so the pickup line that the threat hunter gave me was, " Are you an anomaly? Because everyone else ignored you, and now I can't stop thinking about you."

Michael Leland: I like that one.

Michael Leland: Yeah. I like that a lot.

Ashish Rajan: Yeah, yeah. So, [00:30:00] you get, you get the point. I'm like, oh, and so I can only imagine a threat hunter coming up with that kind of thing, and I'm like, I don't know if he or she would ev- ever get a date. You know, like- Yes ... there, there was another one which was about, uh, someone had a dating profile for, uh, I think it was endpoint security joke, and something a- something along the lines of, "You should be comfortable being continuously monitored."

Michael Leland: Was in the data center Two, two years ago, it, it's been two years ago, it was, it was probably right here in Black Hat a vendor had a T-shirt, and on the back it said it said, "I've been penetrated."

Ashish Rajan: You're like, "The-

Michael Leland: Yeah ...

Ashish Rajan: oh, you, you don't, you don't

Michael Leland: want that." Okay, one last joke.

Ashish Rajan: Sure.

Michael Leland: All right. I told my firewall a joke.

Michael Leland: It blocked it because it detected unsolicited packets.

Ashish Rajan: All right. These are the good... and, and thank you for participating in this. Uh, where can pe- people learn more about Island and the work you guys do, and where can they, where can they connect with you as well?

Michael Leland: Great. So, uh, island.io is our website.

Michael Leland: It's recently been expanded to to cover all of the, the newness of Island, right? [00:31:00] Used to be just a browser, then it became a SASE, now it's an AI protection control plane solution. We go to where our customers want us to be. Yeah. So, happy to, uh, happy to host a demo, a po- a proof of concept, whatever.

Michael Leland: Yeah, uh, always. I've never enjoyed giving a pitch and a demo more- Mm-hmm ... than I do for this company because I love seeing the aha moments on our customer faces.

Ashish Rajan: Yeah. I think I've told you this as, as well. I don't think I've ever met anyone who is in sales who's so passionate about the product as you have been.

Ashish Rajan: I think you and I, I think the first time we jumped on the call, we could've spent an hour-

Michael Leland: Yeah ...

Ashish Rajan: and we were still not done with it. I'm like, "Oh, wait, this guy is so passionate," and like, so much energy coming out of this. So I, kudos to you for that, and I'll put the links for Island and your LinkedIn as well so people can connect with you- Great

Ashish Rajan: and kind of have the conversation. But thank you so much for coming on the show. Thanks everyone for tuning in as well. See you next time. Thank you for listening or watching this episode of Cloud Security Podcast. This was brought to you by techriot.io. If you are enjoying episodes on cloud security, you can find more episodes like these on cloudsecuritypodcast.tv, our [00:32:00] website, or on social media platforms like YouTube, LinkedIn, and Apple, Spotify.

Ashish Rajan: In case you are interested in learning about AI Sec- Security as well, do check out our sister podcast called AI Security Podcast, which is available on YouTube, LinkedIn, Spotify, Apple as well, where we talk to other CISOs and practitioners about what's the latest in the world of AI security. Finally, if you are after a newsletter, it just gives you top news and insight from all the experts we talk to at Cloud Security Podcast.

Ashish Rajan: You can check that out on cloudsecuritynewsletter.com. I'll see you next episode.

Peace.

No items found.
More Videos