
Why AI Security is Actually a Data Security Problem
Show notes
When an AI coding agent hallucinates a software package name, attackers can simply create malicious packages with that exact name, tricking the AI into downloading malware directly into your environment. In this episode, Ashish sits down with David Gibson, SVP of Strategic Programs at Varonis, to explain why the rapid adoption of AI copilots and autonomous agents is fundamentally a data security crisis. We spoke about how connecting AI to your corporate environment before locking down your data creates massive, unintentional insider threats, allowing employees to instantly discover sensitive information they shouldn't see. We explore the Varonis Atlas framework, which provides a unified control plane to inventory AI systems, implement runtime guardrails, and execute automated red teaming. David also breaks down emerging threats like "hallucination squatting," untrusted agent inputs, and why managing identity groups without understanding data access is like holding a keyring without knowing what doors the keys unlock.
Guest Socials - David's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
If you are interested in AI Security, you can check out our sister podcast - AI Security Podcast
Questions asked:
(00:00) Introduction to AI Agents and Data Security(02:00) David Gibson's Background in IT and Joining Varonis in 2006(03:30) The "State of Cybercrime" Podcast and the "AI of A" Segment(05:00) The Through Line: How Legacy Data Auditing Gaps Amplify AI Risks(07:30) Unintentional Insider Threats: Employees Finding Sensitive Data via AI(10:00) Emerging Agentic Threats: Untrusted Inputs and SQL Injection on Steroids(11:00) The Threat of "Hallucination Squatting" by Malicious Actors(12:30) Copilot Enablement, Claude Cowork, and the Sprawl of Corporate AI Agents(14:30) Shrinking Exposure: Inventorying AI and Enforcing Runtime Guardrails(16:30) Why AI Agents Are Like "Well-Meaning Interns That Never Sleep"(19:30) The Varonis Atlas Framework: Inventory, Red Teaming, and Runtime Controls(24:00) Integrating Email Security to Stop Upstream IT Help Desk Impersonation(29:30) The "Inside Out" Security Strategy: Starting at the Data Layer(32:30) The Identity Gap: Holding a Keyring Without Knowing Which Doors They Unlock(34:30) Moving Out of the "Denial Stage" of Shadow AI Adoption(38:00) The "You Laugh, You Lose" Cybersecurity Joke Challenge
This episode was sponsored by Varonis