Coffee, Chaos and ProdSec

Ep 22 - Part 1 - AI Security Foundations, Visibility, Governance, and the Risks Nobody Owns

Jan 28, 2026
They dig into discovering shadow AI and hidden agents before policies are written. Conversation covers practical visibility tools and low-cost ways to detect unsanctioned AI. They talk about building enabling governance, fast approval flows, and cross-functional councils. The hosts explore AI agent identities, token risks, browser DLP limits, and how to inventory and monitor rapidly changing AI tools.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

Endpoint Logs Revealed Hundreds Of AI Tools

  • Kurt pulled endpoint logs and found about 400 AI services in use at his org.
  • Many were one-off tools that surprised the security team with unexpected usage.
ADVICE

Make Your AI Inventory Proactive

  • Build a proactive, public-facing AI inventory with intake, approval, and status visibility.
  • Feed detection data into the inventory so you can pre-approve or remediate shadow tools.
INSIGHT

Transparency Nudges Better Behavior

  • Publishing inventory and detection data shames risky behavior and nudges proper requests.
  • Transparency reduces shadow AI by making usage visible to teams.
Get the Snipd Podcast app to discover more snips from this episode
Get the app