
Coffee, Chaos and ProdSec Ep 22 - Part 1 - AI Security Foundations, Visibility, Governance, and the Risks Nobody Owns
Jan 28, 2026
They dig into discovering shadow AI and hidden agents before policies are written. Conversation covers practical visibility tools and low-cost ways to detect unsanctioned AI. They talk about building enabling governance, fast approval flows, and cross-functional councils. The hosts explore AI agent identities, token risks, browser DLP limits, and how to inventory and monitor rapidly changing AI tools.
AI Snips
Chapters
Transcript
Episode notes
Endpoint Logs Revealed Hundreds Of AI Tools
- Kurt pulled endpoint logs and found about 400 AI services in use at his org.
- Many were one-off tools that surprised the security team with unexpected usage.
Make Your AI Inventory Proactive
- Build a proactive, public-facing AI inventory with intake, approval, and status visibility.
- Feed detection data into the inventory so you can pre-approve or remediate shadow tools.
Transparency Nudges Better Behavior
- Publishing inventory and detection data shames risky behavior and nudges proper requests.
- Transparency reduces shadow AI by making usage visible to teams.
