The Hidden Cost of BlackBox AI: Bridging Cloud and Code Security
Jul 9, 2026 · 42m
Summary
Host Court speaks with Harry Weatherold, CEO of Maze, about using AI to unify cloud and application security. They discuss distinguishing reachability from exploitability, the high costs and false positives of unoptimized AI tools, and why specialized vendors outperform generic frontier models. The conversation highlights the need for transparent, cost-efficient agents that bridge the gap between code and infrastructure.
Topics discussed
Introduction: AI in cloud and app security with Harry Weatherold
Defining reachability and exploitability in security
Challenges of building custom AI agents for security
Bridging the gap between cloud and code security
Generalist vs. specialized AI models for security
AI accuracy, false positives, and developer trust
Evaluating AI security vendors and avoiding black boxes
Architecture of AI-native security products
Cost optimization and efficiency in AI security
Automating remediation with AI agents
The evolution of 'shift left' in an AI world
Future of development teams and coding agents
Building an AI-native AppSec program and conclusion
Listen ad-free on Castria