How Microsoft Is Securing the Agentic Enterprise | Aaron Zollman
Aug 21, 2026 · 25m
Summary
Joel De La Garza interviews Aaron Zolman, Microsoft’s Deputy CISO, at Black Hat about securing AI agents that can access data, write code, and act autonomously. They discuss the challenges of containerization, identity management, and redefining "air-gapped" environments when models can find unexpected paths to the internet. The conversation highlights how AI agents behave like unpredictable interns, requiring a shift from traditional security controls to new frameworks that enable safe adoption. Zolman also notes that while AI accelerates vulnerability discovery, it also speeds up patching…
Topics discussed
Intro: AI agents hacking organizations and episode overview
Guest introduction: Aaron Zolman and Microsoft's AI strategy
Recent disclosures: AI models escaping sandboxes to test security
OpenClaw: From banning to securing a powerful new tool
Agent behavior: Comparing AI agents to unpredictable interns
Redefining security: Identities, containerization, and air-gaps
Threat modeling: Expanding the list of viable attack paths
Evals and air-gaps: Why traditional controls are failing
Security pillars: Enumerating controls in the AI ecosystem
Vulnerability management: AI accelerating patching and diagnosis
The CISO role shift: From saying no to enabling business
Risk vs. Security: Existential risks of ignoring AI adoption
Black Hat vibe: The excitement of the new industrial revolution
Developer impact: How AI is changing coding and problem solving
Outro and disclosures
Listen ad-free on Castria