Cybersecurity Today

Agentic AI Security Is Broken and How To Fix It: Ido Shlomo, Co-founder and CTO of Token Security

11 snips
Feb 21, 2026
Ido Shlomo, co-founder and CTO of Token Security and veteran Israeli cybersecurity practitioner, explains why agentic AI is hard to secure. He discusses permission overreach, identity-first defenses, intent-based permission management, risks from developer tools and leaked tokens, and governance steps like discovery, boundaries, monitoring, and decommissioning.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

Token Sees Agents Already Running In Enterprises

  • Ido Shlomo describes Token as a Tel Aviv–and New York–based company protecting environments where agents already run with real access.
  • He stresses agents are present now and often hold large permissions in organizations.
INSIGHT

AI Feels Like A New, Unpredictable OS

  • AI behaves like a new operating system making decisions at micro and macro scales, which increases risk when placed at critical centers.
  • It also mimics a 'human spirit'—clever but unpredictable—making full control impractical.
INSIGHT

You Can't Filter All Agent Inputs Or Outputs

  • The input space for AI is essentially the entire English language and outputs are equally vast, so controlling I/O deterministically is impossible.
  • Security must assume non-determinism and surround agents, not attempt to fully control their outputs.
Get the Snipd Podcast app to discover more snips from this episode
Get the app