TLDRocket
Sign in

😺 AI Security CEO warning: the risk from agents is ā€œalmost infinite.ā€

The Neuron ā— Covered by 3 sources

AI safety tests break down once a model gets tools, data, and permissions. That’s why one CEO says agent risk jumps to ā€œalmost infinite.ā€

Based on reporting by The Neuron — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work Ā· Report an error

AI labs can spend months trying to prove a model is safe. Then someone hooks that model to Slack, Gmail, databases, memory, tools, credentials, and even other agents. At that point, the neat little safety story starts to fall apart fast.

That’s the argument Noam Schwartz, CEO and co-founder of Alice, made on a new Neuron podcast episode. His point isn’t that models don’t matter. It’s that the real danger shows up when a model stops being a talker and starts being a doer. Once an AI agent can take actions, the number of things that can go wrong multiplies.

The episode keeps circling back to the same uncomfortable idea: security for agents is not just a model problem. It also lives in the company’s own tools, data, permissions, and policies. Or, as Schwartz puts it, the risk surface becomes ā€œalmost infinite.ā€ That’s a dramatic phrase, but it fits the setup described here. A chatbot can say something bad. An agent can delete files, change a database, expose data, trade money, or nudge another agent off course.

That wider attack surface also changes what ā€œsafeā€ even means. The Neuron says prompt injection may never be fully solved because attackers only need one path, while defenders have to cover everything. And because attacks can arrive through natural language, over multiple sessions, or through tools the agent reads, the old security box looks too small.

The practical message is blunt: model guardrails are not the whole plan. Companies building agents have to control context, test continuously, expect prompt injection to evolve, and define their own version of acceptable behavior. In other words, if the agent can act, the company owns the mess.

My take — AI-written commentary, not fact-checked reporting

This is the part of AI that gets dressed up as productivity and then quietly becomes governance. The industry loves talking about model safety because it sounds clean; agents are messier, and that’s exactly why they matter. The real mistake is pretending a wrapper around a model counts as a security strategy.

Read more about this at: The Neuron

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.