The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/AI & Data/The Enterprise AI Show
The Enterprise AI Show artwork

Securing AI Agents in the Enterprise: NanoClaw, Zero Trust Guardrails, and Governance at Scale

The Enterprise AI Show · 2026-09-13 · 45 min

0:00--:--

Key moments - from our scoring

Substance score

58 / 100

Five dimensions, 20 points each

Insight Density12 / 20
Originality11 / 20
Guest Caliber14 / 20
Specificity & Evidence10 / 20
Conversational Craft11 / 20

Gabriel Cohen built Nanocloud over a weekend to solve security gaps he observed while running autonomous agents at his AI-native marketing agency, and the framework has since accumulated over 30,000 GitHub stars and half a million downloads. The conversation explores how Fortune 500 companies, financial institutions, and government organizations are shifting from pilot exploration to enterprise-scale agent rollouts, driven by competitive pressure and demonstrated productivity gains of 2-10x. The core challenge isn't capability - organizations see immediate value - but rather control: data governance, policy enforcement, role-based access, audit logging, and the ability to set contextual autonomy levels. Cohen emphasizes that enterprises will deploy 5-10 agents per employee across 15,000+ person organizations, requiring infrastructure that goes far beyond traditional software deployment. Nanoco (the company) provides enterprise infrastructure including orchestration, agent isolation, credential management, policy gateways, and audit trails deployed into customers' own cloud accounts rather than as SaaS, addressing the sensitivity of handling compliance and customer data. The discussion covers the OpenClaude incident (agent swarm attacking Hugging Face), container escape risks, and how to balance agent autonomy with meaningful human approval at critical decision points rather than alert fatigue.

Key takeaways

  • →Enterprise organizations are accelerating from pilot phases to organization-wide agent rollouts within months, with conversations shifting from 'how do we experiment' to 'how do we govern and scale this,' particularly after competitive concerns became acute.
  • →The primary blocker for agent adoption in large organizations is not capability but control - data governance, policy enforcement, credential management, and audit trails - requiring infrastructure deployed into customer environments rather than SaaS models due to sensitivity of compliance data.
  • →Effective human-in-the-loop requires identifying 1-2 critical approval points where human judgment is meaningful (like email send) rather than constant alerts, balancing agent autonomy with genuine oversight to avoid alert fatigue while maintaining security.
  • →Enterprises expect to deploy 5-10 agents per employee across organizations of 15,000+, meaning employees at all levels need self-service agent creation with individual, group, departmental, and organizational controls rather than IT-driven builds.
  • →Agent swarm attacks (like the Hugging Face-OpenAI incident) represent an emerging threat where malicious third parties direct autonomous agent collectives at infrastructure, a risk that boardrooms have not yet fully absorbed despite being critical for CISO discussions.

Guests

Gabriel Cohen

Topics in this episode

OpenClaudeRole-based access controlAgent orchestrationCredential managementInterviewBrian GracelyAaron DelpGavriel CohenNanoClawNanocloudNanocozero trust guardrailscontainer escapesandbox escapepolicy enforcement gateways

Questions this episode answers

Why did Gabriel Cohen build Nanocloud instead of using existing agent frameworks?

Cohen identified significant security and safety issues with OpenClaude while using it at his marketing agency - it was valuable but couldn't be the foundation for a secure business. He built Nanocloud over a weekend with minimal, security-focused capabilities, then open-sourced it under MIT license, which resonated widely with the community.

What's the key difference between what enterprises need from agents versus what open-source frameworks provide?

Open-source frameworks like Nanocloud provide the core agent logic, but enterprises need additional infrastructure: orchestration, agent isolation, governance, credential management, policy enforcement gateways, audit logging, and role-based access control, deployed into their own cloud accounts to protect sensitive compliance and customer data.

How should organizations balance agent autonomy with human oversight?

Rather than creating alert fatigue with constant approvals, identify 1-2 critical decision points where informed human judgment is required - such as before sending an email or finalizing a high-stakes action - where a person reviews what the agent did and takes responsibility for the outcome.

What competitive pressure are Fortune 500 companies feeling around agent adoption?

Organizations fear that if competitors master agent deployment ahead of them, the resulting productivity gap will be insurmountable. This shift from seeing agents as a 10% cost-saving tool to viewing them as enabling dramatic growth has accelerated enterprise rollout timelines from 8-12 months to immediate action.

What is the agent swarm attack risk from the Hugging Face-OpenAI incident?

The incident showed that malicious third parties can direct fully autonomous, spontaneously assembled agent swarms to attack infrastructure - a scenario the broader industry has not yet fully absorbed in terms of risk, though it will likely become a boardroom-level security concern.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

12 / 20

The episode contains substantive technical material on agent security architecture (sandboxing, credential management, policy gateways, zero-trust enforcement), but is padded with considerable throat-clearing, repetitive framing, and soft introductions. The core insights - microVM isolation, credential proxying, policy-based approval points, the distinction between value-creation non-determinism and safety determinism - are valuable but compressed into roughly 20 minutes of a 45-minute runtime.

Put the agent in a box. It's a perfect box. It can't get out of the box. That's great, but it can't do any work unless you actually give it access to your emails
The gateway then needs to enforce a policy, make a decision, should this request be allowed through or not?

Originality

11 / 20

The security architecture described (microVM isolation, credential gateway, policy-based enforcement via Cedar) is solid and reasonably rigorous, but not novel in security circles. The framing of 'zero trust for agents' and 'approval at the critical human-judgment point' is sensible and somewhat fresh for the agent-security discourse, but largely restates established security patterns applied to a new domain. The Hugging Face/OpenAI incident analysis is reactive rather than original.

Our approach is not better instructions and better prompts. Our approach is taking a, uh, zero trust approach to safety and to security.
There's gonna be one key point where you wanna get the human to provide approval, consent and informed consent.

Guest Caliber

14 / 20

Gabriel Cohen is a hands-on builder and founder with direct operational experience deploying agents in his own marketing agency, and now runs a company commercializing agent infrastructure at enterprise scale. He has credibility from GitHub adoption (30k stars, half a million downloads) and is fielding real Fortune 500 conversations. However, he is not a security researcher, cryptographer, or long-tenured enterprise infrastructure veteran; he is a talented practitioner operating at the early frontier of agent orchestration rather than a deeply weathered enterprise architect.

I got here by accident...about a year ago, we started working on a, a new business, a, um, a marketing agency, and we were using agents.
There are now over 30,000 stars on GitHub. There's over half a million downloads, tens of thousands of people using it.

Specificity & Evidence

10 / 20

The episode lacks concrete data, named customer wins, specific security incidents beyond OpenAI/Hugging Face, actual policy examples, and measurable outcomes. Claims like 'Fortune 500s are asking about scale' and 'executives say 10x productivity' are unsubstantiated. The technical architecture is described conceptually but without implementation details, configuration examples, or case studies showing actual deployment results. The reference to Singapore's Minister of Foreign Affairs is mentioned but not detailed.

The Minister of Foreign Affairs of Singapore he was very public. He did a big post about how he's using Nanoclade
they're saying, a lot of them say it makes them two times, three times, some of them say 10 times more effective

Conversational Craft

11 / 20

The hosts ask reasonable exploratory questions about deployment scale, security tradeoffs, and the CISO conversation, but rarely push back or probe uncertainties. Softball elements include: no challenge to the claim that 'every org feels behind,' no deep follow-up on the OpenAI incident's specific failures, no skepticism about the feasibility of rollout at scale, and no hard questions on pricing, lock-in, or competitive alternatives. The hosts do encourage Gabriel to expand on architecture and human-in-the-loop design, which is positive.

Help us with I guess you could say the theory versus reality of where we're at today
Let me ask you this, Gabriel. Humans in the loop, because I think at the end of the day, there's always going to be this trade-off

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

agents60agent47access30saying20organization20enterprise17data17credentials17security15email15team14feel14level14emails14start13send13

Episode notes

Brian and Aaron interview Gavriel Cohen , co-founder and CEO of Nanoco and creator of the open-source agent framework NanoClaw, about securing AI agents in enterprise environments. Cohen shares how he built NanoClaw after discovering major security and safety gaps while using agents for an AI native marketing agency, and how the project grew to over 30,000 GitHub stars and over half a million downloads. They discuss why Fortune 500s, financial institutions, universities, and government groups feel urgent pressure to adopt agents but are blocked by control, privacy, and security concerns. Cohen outlines a zero-trust approach using microVM isolation, no credentials inside agent environments, a policy-enforcing gateway with granular controls, audit logs, cost attribution, and human-in-the-loop approvals at key decision points.

Full transcript

45 min

Transcribed and scored by The B2B Podcast Index.

Good morning, good evening, wherever you are, and welcome back to the Enterprise AI Show. This is your host, Aaron, and today's interview is the first in a two-part series on agents in the enterprise. Today, we're talking with Gabriel Cohen, creator of the open source framework, Nanocloud. We'll talk about the project's growth and how a more security-minded approach fits into enterprise AI.

And also, stay tuned for the second part on Wednesday. With that, let's jump into the interview right after this short break Today's show is sponsored by Nasuni. There's a growing gap in AI right now between what's possible in theory and what successfully works at scale inside an enterprise. The difference comes down to unstructured file data.

Many AI initiatives struggle because the file data they depend on is scattered, unstructured, and disconnected from where and how work actually happens. Nasuni changes that. It brings your unstructured file data into a single secure foundation so AI, both generative and agentic, can access it with the context, governance, and performance it needs in production. Bring AI to where your unstructured data lives.

See what it takes to activate your data for AI and request a demo at nasuni.com/ai. What does the outside world already know about your company? Cybercriminals could be seeing leaked credentials, compromised session cookies, exposed infrastructure, and even impersonations of your brand and executives.

NordLayer Intelligence by NordStellar gives security teams visibility into those threats across the deep and dark web, data breaches, attack surfaces, and brand impersonation all in one platform. Find out what attackers know before they can use it. Visit nordlayer.com/intelligence/enterpriseai and use code enterprise10 for ten percent off your NordStellar plan And we're back, and, uh, Brian, we're actually doing an interview together.

How long has it been, man, since we've done one of these? It's been a- We - It is, it is. Uh, I mean, you and I have been on, on shows together, but yeah, it's been a long time since we went to the, you know, kinda going back to the original format of, uh, two dumb guys ask one really smart guy a bunch of questions about a topic that, uh, everyone's gonna be interested in. Yeah, today's gonna be fun.

Yeah, absolutely. And so our topic for today is securing AI agents in the enterprise, and for that, we have Gavriel Cohen, co-founder and CEO at Nanoco. Gavriel, how you doing, man? I'm doing great.

Thanks for having me. Absolutely. So let's kinda start with your, your background here. You spent years as a developer and kind of leading a team and b- kind of before you kinda landed in this agent space, and you have this super interesting background when it comes to, like, how Nanoco and Nanocloud came to be.

So walk us through a little bit of your background and how we got to where we are today. I got here by accident. So I didn't set out to, to create an agent framework or, or my own Claude. I was - I, I, my dev - my background is, uh, software development, but actually about five years ago, I kind of took a break from that and went and joined my co-founder, who's also my brother, at his, um, public relations agency.

So we did PR for for tech startups. And then, um, about a year ago, we started working on a, a new business, a, um, a marketing agency, and we were using agents. So it was AI native s- providing services, but using agents for everything that we did. So I'd show up at work in the morning, open my laptop, fire up Claude Code, and that was my, that was my work.

That was my primary work tool. And then I tried out OpenClaude, just coming from that place of, "Hey, this might be useful. I'd like to use this." I was already running tons of agents.

I had already bought a Mac Mini just to run Claude Code sessions in the background, just, you know, SSH into the Mac Mini, Tmux fire off a bunch of sessions. But I felt like I needed some tooling around it. I wanted to have cron jobs. I wanted to make it accessible to other people on the team who weren't as technical.

So I thought, "Okay, I'll try, OpenClaude." Uh, I set it up, put it in a, in a WhatsApp group with myself and my co-founder, my brother and connected it to the Obsidian drive, where we had all of our, uh, files on each customer who, or potential customer in the sales pipeline, and literally just said I, I called it Andy for the guy from the, in the office. I said, "Andy, you're, you manage our sales pipeline. You're a sales manager.

Good luck." And then, next morning, 9:00 a.m., sends us this, um, overview of the pipeline starts asking us throughout the day for updates on deals and, you know, "How did that call go?

Here's a brief for the coming call tomorrow." And, and literally doing the work of an employee, but then not really looking for it, almost by accident, I started to just see massive security issues and AI safety issues with, uh, OpenClaude. But on the other hand, I was conflicted. It was bringing a ton of value, so I was, um, I wrestled with it for about five days, saying, "Okay, I wanna fire up five more agents to handle five other functions in the company, but I can't build a business on top of this framework which You know it isn't taking security and safety as seriously as it should be.

So I sat down and, and built, uh, Nanoclo over a weekend. Minimal, just the capabilities that I needed. Put it out there just to use for, for our own business really, and put it out there under MIT license and thought other people might find this useful, and it blew up. Just totally took off.

There are now over 30,000 stars on GitHub. There's over half a million downloads, tens of thousands of people using it. So fairly quickly, uh, Andrej Karpathy, a co-founder of, uh, OpenAI, took notice and s- started sp- you know, tweeting about it, said it slightly blew his mind, the approach we took with minimalism and customizability. And so we, we, we kind of l- uh, let our customers go from our AI native marketing agency and went all in and are now building Nanoco, which is the company behind Nanoclo.

Very cool. Very cool story. You're, uh, you're living the, uh, the ultimate Reddit dream of you know, "Hey, I could build this over the weekend," and, uh, and then you guys went and, and built it over the weekend. It's very, very cool.

And, you fast-forward a little bit, and all of a sudden you know, whether it's, whether it's your technology or not the, uh, you know, the, the agents have gotten out of the barn, the horse has gotten out of the barn, has become the sort of the headline, uh, a lot these days, unfortunately for, for, you know, what feels like somewhat scary reasons or, or negative reasons. You know, what, what kind of discussions are you having with people probably at, at all sorts of levels of businesses, whether it's, you know, your, your neighbors who, you know, might, might work or know something about tech or, you know, if you're starting to talk to companies at, at, at higher levels.

What are they - You know, what's their, their thought process around agents? What do they sort of, what do you feel like they, they know a little bit today? Uh, what are you guys able to start to expose them to that, that really kind of opens their eyes? Like where's, you know, you're, you're, you're sort of living right in the heartbeat of, of these agent conversations, and agents are, you know, headlines of news articles these days.

Like what are, what are agent conversations you're having with companies these days and, and, you know, what surprises you? What, uh, you know, where, you know, where, where are you excited about what they're giving you feedback about? Yeah, we're having conversations with some of the biggest companies out there, Fortune 500s and, you know, biggest financial institutions, universities, government organizations. What we hear almost universally is they say that they are behind.

Almost every - I mean, it's not really possible that every organization we speak to is somehow behind, but they all feel like that. And I mean, the ones we're speaking to are, are definitely at the stage of, exploration and awareness so they're probably ahead of the curve. But, you know, they see it as, um, existential. If their, you know, their top competitor gets on top of this and figures out how to leverage AI effectively in their organization, um, ahead of them, they can open a gap that will just be insurmountable.

And that's, you know, that's the fear on the one hand and, and also the opportunity where they see this as, you know, it's not just about shaving 10% off costs or whatnot, but an opportunity really for dramatic growth. And the issue though is not about capability. They believe, they know, they look at what's out there, and they know that it can bring a ton of value. Uh, that's clear.

A lot of the, the people we're talking with, some of them are Nanoclade users. You know, the, the Minister of Foreign Affairs of Singapore he was very public. He did a big post about how he's using Nanoclade on his whole setup and agent framework and his memory system. Uh, and we, we, you know, had the, uh, privilege of, uh, meeting with him in Singapore.

We went out there for a visit. And, you know, so those are some of the people that we're having these conversations with who are personally using Nanoclade or using other agents outside of work, and then they're going, you know, "How do I bring this into my organization? How do I give this to everyone on the team?" And they know that it's highly valuable.

They felt it themselves. They're working with agents. They feel, a lot of them say it makes them two times, three times, some of them say 10 times more effective. And there are literally executives out there who are, full-time executives and then have another business that they're building, on the side.

Uh, you have CEOs of, of, you know, massive companies on, on X building software, launching frameworks, doing, you know, basically what would've been, a full-time job of, of multiple people on the side. So, so they're saying, "Okay, this makes me five, 10 times more effective." The capability isn't the question. The question is control, security data, privacy.

Tho-those are the issues, all those things that get in the way of, uh, rolling it out to their teams. Yeah. And help us with I guess you could say the theory versus reality of where we're at today with all of this. Because as Brian kind of mentioned, we, you know, there's lots of headlines out there.

There's lots of fear out there, especially when you see like, oh, you know, OpenAI the, the model got out and attacked Hugging Face, and you get, you know, some of these other things going on. And you know, w- what's the current state of security around this? Because I imagine, you know, there's CISO-level conversations, there's board-level conversations when it comes to implementing agents at scale, at, you know, like as you mentioned, some of the largest companies in the world, their first concern has to be how do you keep the train on the tracks, for lack of a better term?

Yeah, we- we're hyper-focused on, on, on enterprise-grade security. Uh, I mean, enterprise-grade is an understatement, really. How do we fully lock these agents down and make sure that we're taking that risk of, um, of agents escaping a sandbox, uh, seriously. Uh, the, the Hugging Face OpenAI incident was a big wake-up call, for me and I think for many people, although I don't know if the industry a- as a whole has fully kind of, uh, absorbed the, the, you know, the meaning of what, of what that is in terms of, a, an agent swarm attacking attacking a company, attacking infrastructure.

Uh, a- and in that case, it was, it was a fully autonomous, spontaneously, uh, assembled agent swarm. And we'll see, we'll see that more and more where it's actually, uh, it's actually malicious, third parties, attackers who are directing a swarm at you. I don't think we've really you know, the industry as a whole has really come to terms with what that, what that means. But I think for organizations, what's really top of mind is first and foremost data a-a-and, you know, where is their data gonna be?

Who has access to it? How is it handled? And then it's the AI safety. What can the agents do?

Um, how can we be sure that they're, they can only do what we wanna, we want them to do, only have access to what we wanna give them access to? The risks associated with running agents a- and container escape and sandbox escape, that is, it - I don't think that has yet fully penetrated enterprise boardrooms and, uh, but I think it will very soon. Yeah. I m- I wanna ask a little bit of a follow-up there and, and I want to hit on a couple of things that, that you said, which was, you know, you're - sometimes you're sort of surprised that people feel like they're behind, which, tends to tell me that, that we're still, we're still in very, very early days.

You know, you're getting a chance to talk to some pretty influential people at, at these large organizations. Do you feel like they are right now trying to, to understand how to solve their problem, like at a company-wide level, or are they still keeping it pretty pretty localized to themselves, their local team, a specific problem? And the reason I ask that is because, you know, there's oftentimes a, a, a gap between a technology that, that works great for, you know, a number of people and the use cases around that, and then maybe how you solve that at a big enterprise, sort of complex platform level.

Where do you f- you know, like, as you're talking to people, where do you get a sense that people are trying to solve their problems? Is it still fairly localized in terms of the problem and hence, you know, what data connect to? Or do you get the sense that they're they're already, you know, they're, they're ready to start looking at how do I solve this for 15,000 employees at a big company? Two to three months ago, it was more of that exploration phase of starting How do we do a small pilot?

How do we experiment? How do we dip our toes in? In the last month, I would say the, the mood seems to have shifted, and there are many organizations that are now looking at how do we roll this out at scale, and that's what the conversation looks like. Governance security controls, cost controls how do we control you know, spend?

How do we attribute costs? Those conversations now are top of mind. So they're not, it's no longer just dipping their toes in testing the waters. They're looking to jump right in.

And, four, three, four months ago, we were having conversations with organizations, say large financial institutions saying, "You know, we, we can't be the first ones in our industry to make a big move on this. We're gonna have to, wait until someone else goes for it." Saying, "You know, you'd be wasting your time to go down this road with us at this point. We're eight months, a year out."

And then now they're circling back and, and they're going, "Let's do this. Like let's - how do we actually move forward?" So something has definitely shifted. In terms of rolling it out at the organization level, it's… This goes way beyond normal enterprise software.

I mean, you need audit logs, you need, role-based access control, and you need to be integrated with identity providers, and you need to be able to set policies. But it goes way beyond that because this needs to connect to everything. Agents are how people more and more do work, right? So every aspect of your work, every tool that you use, every data source, it has to connect to all of it, and it has to do that in a way that's governed, that's controlled, that's safe.

You know, the way we're thinking about this is an organization that has 15,000 people, in a year and a half, two years, they're not gonna have 15,000 agents, they're gonna have 100,000 agents, right? There's gonna be five or 10 agents for every person in the organization. So this can't be the IT team and the software development team building agents one by one for each person. Everybody in the organization is gonna need to have access, gonna need to be able to spin up their own agents and give them direction and give them feedback and manage them and run them, and have individual level controls for their agents, but then have controls on the level of the group, the department, and the whole organization.

Let me ask you this, Gabriel. Humans in the loop, because I think at the end of the day, there's always going to be this trade-off, if you will, of approvals and, you know, how much autonomy do you have this, you know, how much do you have to go back and say, "Okay, you know, when does it have to check in? What can it do au- autonomously? What, you know, how, how far do you let it go?"

And especially when you're talking about enterprises and you're talking about some of these big enterprises here that we've seen recently or big rollouts that you've seen recently, how do you balance that? Yeah, that's absolutely a key thing that you have to balance. The more autonomy you give them, the more work they can do. Coding agents today I say coding agents, right?

But these are the, the most powerful agents that we have, which are connected to command line tools can wr- write code and run it, and take actions essentially on a computer. Anything that you can do in a computer, they can do. They're extremely powerful. If you connect them to a data source and some analysis tools, they'll do the work of a data analyst.

Basically, you give them access, they can pretty much accomplish any task. But the question is that autonomy versus control and oversight. Uh, and that was really the core experiment of OpenClaw, saying: What happens if we take these agents, connect them to everything, put no rules in place, no controls, no limitations, you know, what do you get? And the answer is they can do a lot.

They can do, uh, you know, a lot, but the key thing is how do you have that balance? Uh, our approach for enterprises is give them the ability to set controls where they need them. Depending on They're - Depending on their needs, they can, they can move that dial of more or less autonomy. But really the key thing is you don't want to have to make a trade-off of taking risk in order to get the value.

And you don't wanna have alert fatigue and constant pop-ups. You can't get any real work done if the agent is constantly coming back to you for approvals or permissions. What - The way to get real value is within most workflows, most things you're gonna wanna do, there's gonna be one key point where you wanna get the human to provide approval, consent and informed consent. So it's not just clicking a button, rubber stamp ceremony of giving your approval, but it's really the point where it requires human judgment, it requires sign-off, it requires the person to look at what's being done, what's being put forward and take responsibility for it and say, "Yes, I'm putting my name on this."

So what that could mean is have the agent, say it's connected to my email, my calendar, uh, my drive. It can go and do - triage my emails, do a whole bunch of research to see, you know, what I've been working on who I've been meeting with, conversations I've been having, drafts an email, and then at the moment when it goes to send the email, that's the point where I get the approval card, where I see the work that it's done, how it's come to this, this, this, uh, this point, and I see exactly what's gonna be sent, and I can look at it and either approve, sign off on it and say, "Yes, that is accurate.

It represents what I wanna say, and this can be sent from me." Not, you know, it's not the agent sending the email. This is me putting my name on it and approving this, and it's going out under my name. Or I say, "No, that needs - you know, that's not quite right.

It needs it needs some adjustments." So that's not just, that's not the, the standard kind of alert consent thing, that things pop up, you don't even know what it's doing, and you just go, "Okay, okay, okay." This is an email that's gonna go out under my name. I look at it, I read it, make sure I know what it is and know why, and then I make a decision and a judgment call, or I ask for changes.

So most jobs, most things you do, there's that one key point where sometimes it's two, but there's, you know, one or two key points where you can actually have meaningful approval, consent and input and feedback rather than the constant alerts. Yeah. I'm curious as you're, as you're thinking about both what you guys do with Nanocloud, you know, kind of its original ori- origins, how you're seeing it evolve, and then as you're, as you're talking to people in the industry I have to imagine there's a, there's a bunch of conversations of sort of like, well, where will, where will Nanocloud stop, and then where will I expect something else, right?

Whether that's a harness, whether that's some sort of agent orchestration system that, keeps track of if I wanna run 100 agents, how do I, how do I sort of, deal with them? You know, there's gonna be people who are gonna ask you, "Okay, you know, we, we need to put guardrails," or where does human in the loop stop and start, and things like that. Does that happen, you know, on the model? Where do you guys, a- as you're thinking about it from your perspective, you know, what, what your roadmap looks like and, and as you're talking to people, where do you sort of see the agent you know, what, what, what you wanna deliver with the agent sort of stopping and then where you see it expanding?

You know, what - You know, do we expect an agent framework to be, you know, where Nanocloud is a year from now? Do- does that sort of make sense as people are thinking about, okay, you know, I wanna take this from, you know, a few use cases, a few POCs and so forth, to something that's at, at a much larger level. Wh- where do you see, you know, your guys' role sort of stopping and starting, and then where would you maybe like to expand it from where it is today that, that was, is gonna help people get to that next level?

So Nanoclaw, the open source project is gonna continue to b- be free community MIT licensed open source project that anybody can pick up and use for personal use bring into their team or build up a product or a service or a business on top of. Nanoco, the company, so we're bringing enterprise, uh, we're bringing agents to enterprises. And what that means is for an enterprise to run agents within the organization, they need enterprise infrastructure for running AI, and that includes orchestration, it includes agent isolation, it includes governance includes credential management, policy enforcement a gateway, uh, that enforces policies and, and and audits every action.

So that's what we're bringing to organizations. We roll it out you know, this kind of infrastructure, the type of data we, we - so, you know, we roll out to a customer, they start giving their employees agents and they handle compliance flows, right? The first minute of the first day that these agents start working there, they're handling customer IDs, right? Um, the most sensitive data you can get.

So this can't be a SaaS product where your, your data, your IP, your most sensitive information is going to somebody else's, uh, SaaS platform. Companies need this in their own environment, whether it's on-prem or in their cloud accounts. So that's our, our approach. We deploy into a company's, uh, cloud environment, to their own cloud account roll out their - essentially this becomes their AI infrastructure that allows them to run agents in a way that's governed, that's controlled, that's safe.

And But, you know, companies don't need infrastructure. In the end, they need, uh, results, they need outcomes, they need real value. Uh, we go all the way from, from, bare metal all the way to agents in Slack, in Microsoft Teams doing real work. And I think o-over time, you know, where, where this is heading is a way to run AI agents, uh, in, in an organization that is governed, that's controlled, that's aligned with, uh, the organization's goals and needs.

I think where it stops, and there's gonna be a lot of different types of agent harnesses for different needs. So a designer is not gonna be doing designs in Microsoft Teams or in Slack, right? They probably need a different interface working with agents in an interface that's native for design. And, you know, the same would be for video editor, editors, for producers for all kinds of, um, different roles.

You'd wanna have native interfaces for that. But I think an organization is gonna wanna have all of that connecting to their governance layer and their infrastructure and their credential gateway and whatnot. Maybe a two-part follow-up to that, because I feel like the harnesses are, are super important because I, I almost see this, evolution, if you will. If you had the LLMs and the LLMs, you know, one of the biggest things was like, hey, how do we fix the, you know, s- the non-deterministic nature of them at times, and certainly the hallucinations behind them.

And w- you know, the LLM itself has gotten better over time, and that's part of the reason why the harness is there. But, you know, if, if I put on my, my CISO hat, which by the way, anybody that knows me knows that, you know, I shouldn't be a CISO by any stretch of the imagination. But if I'm a CISO, one of my first questions is going to be, you know, obviously the security around all of this, but also too, how do you fix the non-determinism? Is that something that you can truly fix at the agent level, or does that… Like, how does that still happen, and how do you address that in the enterprise when, again, you have executives or CISOs kind of saying, "Hey, uh, you know, this may be great, but I need some way for it to almost be very deterministic, or I need to be very predictable, or I need transparency into everything as well."

So how do you approach that problem? Our approach is not better instructions and better prompts. Our approach is taking a, uh, zero trust approach to safety and to security. So The safety and security aspects should be deterministic, right?

The value creation, if this piece of content is, or this presentation and the strategies, you know, that the agent comes up with in a presentation that it's building for me, how good or bad those are, that needs to be based on instructions and skills and all kinds of other things that are non-deterministic. But is this safe? Is it secure? Can this agent access credentials?

Can it access - can it send an email on my behalf without my approval? That cannot be non-deterministic. That has to be enforced by, by policies in a way that cannot be circumvented. It's not a suggestion to the agent, "Please, follow this rule."

Uh, so, so that's where you need, you know, the infrastructure the agent isolation. What that means is not putting credentials into the agent's environment. So you wanna give the agent access to tools, but you don't wanna give it the keys. You give it a tool where it doesn't have any access to any credentials.

It can use the tool, but then policies are enforced on that tool outside of the boundaries of the agent's environment. So you've got a gateway, enforces policies and enforces policies not just on can the agent access, uh, Gmail or not access Gmail, can it access, you know, Outlook or not, but saying within Outlook, can it send emails? Can it send drafts? Can it delete emails, right?

Every single action, policies on each and every action going more granular. Can it send emails only internally or externally? And then if I allow it to send emails internally, right, putting a policy in place of, um, maybe sending emails internally requires my approval, meaning human approval, not approval of the IT admin, but approval of the person who's working with that agent, the person who manages it. For each and every email sent, I get a, a notification, a card that shows exactly what's being sent, and I approve or I reject.

But maybe searching through my emails, I don't require approval for that. I allow my agent to freely search through my emails. Uh, deleting emails, just blocked. Don't even ask me.

That, that's automatically blocked. So that cannot be non-deterministic. That has to be enforced by, policy. Our, our approach is with, uh, Cedar it's a, a policy enforcement language, policy language.

And, and that has to be, you know, provably enforced with hard enforcement and hard boundaries. Yeah. What, what have you seen from a learning curve perspective? So obviously I imagine these days, you know, a-as some of these you know, agent stories get out you know, th-this agent attacked something or went rogue or what, what, what would feel like it went rogue.

What are you finding is the learning curve with, you know, with, with companies that you talk to? Is, is - 'cause I, I think what happens a lot of times is companies their in- their initial thing is, "I'm going to…" You know, they, they start off with just saying, "Here's some tasks that I would like to have automated," and they start automating some things. And then, like you said, they start saying, "Okay, I wanna treat that like like an employee, like a, you know, somebody who's got you know, a set of tasks to do, so I'm gonna give it some credentials."

What do you find is, is then the learning curve? 'Cause I think, I think a lot of times what we hear and I've seen this a number of times, where, you know, people when they treat it as if it's like a colleague or a human, uh, you know, doing some stuff, you give it some credentials, you're expecting it to sort of do a, do a job. Um, but you don't really… You know, you, you sort of g- would go, "Well, but if this was a human, they would stop trying to keep accessing data they don't have access to, or they would stop trying to, like, infiltrate something because, you know, they've got sort of learned experience."

How, how do you find the learning curve is working for people as they, you know, start to give these agents a little more credentials, a little more capabilities, a little broader scope but at the same time, keep them from going off and being like, "The guy asked me to do these things. I'm not gonna stop doing that until I figure out some way to get there, whether or not I have the right credentials to get there, whether I don't have the right credentials, whether a firewall locked me down."

Like, what's the learning curve beyond just the normal, like, don't send an email, do send an email kind of, black and white lists? The behaviors, you know, the, the examples of, of say OpenAI and Hugging Face, right? Mm-hmm. Um, in that example There's a lot to learn from that story a lot of different lessons from it.

I think one of the lessons is you know, we gotta take vulnerabilities way more seriously and, and, you know, the time when you can just have unpatched known vulnerabilities sitting there in software. You know, maybe, maybe you say they're not exploitable, you know, it's not reachable from the outside world. It maybe it's not exploitable, but if you chain a few of those together, maybe it is, and, and those were kind of the, the kind of attacks that you didn't have to worry about in the past, maybe because it would take, incredibly sophisticated attacker to exploit it.

But but nowadays with agents that those are gonna become, you know, your, your, your, your, um, your infrastructure to them looks like Swiss cheese, right? There's just, you know- Yeah … vulnerabilities everywhere and, and they can dance right through it. But so, you know, I think that's one of the lessons. The, the other lesson, you know, if you look at it, is that agents are extremely, extremely capable, right?

Like the questions of, is there real value there? I mean, if you look at that story and what they did spontaneously collaborating and communicating with each other to launch an extremely sophisticated attack at the level that expert cybersecurity professionals wouldn't have been able to done have done is, you know, that it's clear that they are highly capable. At the same time, the scenario was pretty specific. They… OpenAI was in certain cases, um, based on what they've shared, they were removing cybersecurity controls for the purpose of testing a-and removing, uh, guardrails.

And they were training the agents on cybersecurity problems, saying… So the, the, the agent's task that they were being given, both in training scenarios and in test scenarios, was hack this system, right? So within the scope of that, the agents, no guardrails and being told to hack, and from their perspective, it was sort of e- you know, everything within their reach is part of the problem, right? Part of the scenario. That includes anything they can access, and if they figure out that they can access a, Artifactory and figure out they can send messages through there, that's all fair game from the perspective of an agent that's being told to hack things, and that's the test they're being given.

In a real world scenario where you're running agents in micro VMs, um, with no access to anything, you know, that they, that, that hasn't explicitly been given to them, And where you're not telling them, "Hack my systems," but you're saying, "Triage my emails." And the guardrails that the labs have, put in place are in effect. Y- you can safely run agents, uh, without having to, you know, without them going in and hacking into Hugging Face or, or some other company. So I think, you know, there's, th- there's multiple lessons there.

And I think for a lot of you know, the people who are paying attention, I think on the one hand it's, okay, we need to take cybersecurity aspects very seriously, but on the other hand, also understanding this is a sign of how capable they are, and it means that we also need to figure out how to harness them and get value from them and introduce them into our business in a way that's safe. Yeah. Let, let me follow up that with, I know that there's been certain folks that, that have kind of said, "Hey, we will never see wide agent adoption almost until…" I, I liked your, your earlier analogy of like, okay, the environment looks like Swiss cheese, right?

Until we almost have to go rewrite all of everything to fix all the holes before the agents can, you know, run wild in the organization. And, and you just proposed, you know, a very different alternative to that. And so, so let's actually explore that quickly. Tell me a little bit, let, let's just use the context of Nanocloud.

What does the infrastructure as well as the, you know, the software that is integrated with Nanocloud look like? Is this a, bring your own LLM kind of thing? Is this a, you know, like you said, a bunch of segmented VMs? Let's talk about that real quickly of like what, what does good look like?

We've talked, we've talked a lot about fears. Let's talk about what does good look like when it comes to a good agent implementation in the enterprise. Yeah, so it can get very, very complicated, but it also doesn't, it doesn't have to be, right? So we can break it down and look at it in, in its, most simple form.

How can I give an agent access to my email in a way that's safe, in a way that is provably deterministically safe, where this isn't a calculated risk, right? There's no trade-offs. So first and foremost, I need to run the agent in a sandbox, in, in its own computer that is isolated where it has file system. It can work, it can do real work but it is not able to, to access anything outside of that environment.

And what that means, like, when you're looking for the strongest isolation is, uh, microVM level isolation. So this is just completely isolated in its own machine without the ability to access anything outside of that machine. So that's number one. Number two, uh, you can't put any credentials inside the agent's environment, right?

If you're giving the agent ability to send emails and the agent can, let's say add attachments to an email, right? If there is a credential in its environment, it can exfiltrate that credential through your emails, and there's no way you're gonna be able to stop it, right? It can put it, you know, hidden, hide it inside an image, inside a PDF, inside some kind of file. You won't be able to, uh, to detect that.

So y- it, it's - The only way to make sure it doesn't leak credentials is it can't have credentials, right? So there's no credentials in its environment. Now, okay, put the agent in a box. It's a perfect box.

It can't get out of the box. That's great, but it can't do any work unless you actually give it access to your emails to be able to look at them, go through them and draft messages and send them, right? So you need to give it access to a tool, right? You don't want to give it a credential have direct access to an API, but you want to allow it to use your account, use credentials.

So what that looks like for most solutions today is a gateway, right? So the agent has no credentials in its environment, but requests from its environment are proxied through a gateway. So it makes a request. It's a request API call to Gmail, let's say.

The API call leaves the agent's environment with no credentials. So it says, you know, bearer token placeholder, right? It's just literally the word placeholder. At the gateway looks at whose agent is this, what team are they on, what organization and verifies their identity, and then looks at a policy that you've set of what should this agent be able to access.

Should it be able to access my email Gmail API? Within the Gmail API, should it be able to access the send email action? You know, maybe that depends on who it's being sent to and some other properties of the email content. And the gateway then needs to enforce a policy, make a decision, should this request be allowed through or not?

If there's a policy set saying my agent should be able to take this action, then the gateway injects credentials into the request into - just in time, so not giving the agent the credential, putting it in the request, letting the request through with that credential. And then at the gateway, you can then also enforce a policy saying "If the agent is sending emails, then hold the request. Don't let it through, hold it, and send me a message. Ask me if I sh- if I wanna let it through.

Show me what's being sent, and I'll make that call." And that's where I have that card where it shows me the content and I approve, reject or request changes. And then of course you can then audit that request. If it's a request that's going to Anthropic to OpenAI, it comes back with usage information.

Uh, you can track usage. You can enforce policies on usage as well. Uh, so that in, in, you know, in a very simplified example is how you could take an agent safely deterministically run it in an environment where it has access exactly to what you've given it access to with policies that you's enfor- you know, you, you've put in place that are enforced and do that safely. Um, and then from there it's just about, times a hundred.

Same thing, give it access to Calendar, to to Drive. Each one of those needs to have policy set about what it can do, what it can't do. And then on the level of the organization, you want to give, put policies in place saying, "What do we feel comfortable as an organization letting our team members connect their agents to?" Right?

Can they connect their agents to email or not? Can they connect it to GitHub or not? And that might vary from person to person, from team to team. And so policies need to be enforced on the level of, of groups.

And then, um and then over time you need to make sure you can adjust those, right? So have audit logs in place, be able to see what actions agents are taking track it over time and, and make adjustments. Yeah. I'm gonna, I wanna ask you one last question 'cause I know we're, you know, time zone-wise it's, it's late with you and we've covered a lot of, a lot of things.

Do you guys feel like, you know, I feel like, uh, we're - agents are, are probably a pretty interesting technology space to be in because you're, you're once again sort of, you're gonna - living between the, the excitement and the innovation that's coming from lines of business and, and groups that are, are trying to do, you know, as you talked about, things that are gonna differentiate their business, things that are gonna give them, you know, hopefully an unfair advantage versus their competition or, or some new insights to the market.

And then you've got, CISO, you know, security groups, IT groups who are classically, concerned about you know, security things that are gonna be, you know, sort of saying no to that. Do you feel like we're at a stage where, you know, if you, if you're sitting in a room and both those people are there, you're able to sort of give them frameworks for saying, "Look, these are the things, the- these are the capabilities we provide that, give you the folks looking to do new things, to do innovations, to scale out agents are there," and there's enough there's enough capabilities for the CISO to go, "Okay, I I buy into this"?

Or are we still at a s- at a stage where the CISO has to think about this sort of as, as two separate things, where they go, "There's the agents I know and the frameworks that are going for those agents. Uh, I'm gonna treat that as one thing. And then the, the agents that I don't know," so the, just the random person that says, "Hey, I'm a, I'm a contractor. I got a Linux box inside your machine.

I might do anything I want to. I gotta go solve that problem separately." You know, do you feel like the, the technology and where we are is, is starting to mature enough to where that conversation could be cohesive, or does it still feel pretty sort of a fight between the, the innovation groups team trying to go fast, what used to be the app dev teams and the CISO groups? It's - This is quite different than anything there was before.

Security, you know, has, has been… Security, you know, in th- in this case, when it comes to agents, is really maybe for the first time actually an enabler. It's not just a, a something you have to, um, you know, you have to, you have to deal with. It's not a tax but it is really an enabler. If you can provide agents securely to the organization it, you know, can bring tremendous value.

You need, i- if you're not able to give them the agents that are governed, the agents, the proper way to run agents, right? People in the organization, like you're saying are gonna bring their own agents, right? They're gonna find a way. They're gonna start using things.

They're gonna start experimenting. Employees, people in the companies, you know, the same way the executives, the, the CIOs are saying, "We're behind. We're falling behind." Uh, employees in the organization are, you know, they're nervous about AI maybe taking their jobs.

They're overwhelmed with it all. Things are changing so quick. But people are, are also gen- genuinely worried about being left behind, right? There's this incredible revolution happening, new, you know, technological revolution.

And they don't wanna be, be left behind here, in, in all of it. They don't wanna get to a place where they fall so far behind that they can't catch up. So people on teams, team members are adopting their own agents, bringing them into the team. Even if there isn't a budget, even if they're not sanctioned, they're finding ways, and some of them are spending their own money to, to, to, bring agents into work.

And that's a big factor now about where people wanna work and how, it- if they feel like there's a future for them in an organization in terms of are we being enabled? Are we begin- being given the best tools? So I think it's critical for organizations to, to get in front of it by, by giving their teams, you know, the best tools. And, um, there are many organizations that are at that point where they're ready to have that conversation.

They're having the conversation, and they're taking those steps of saying, "We're not gonna be pulled into this. We're gonna get ahead of it. Uh, we're gonna do this right. We're not gonna get to a point where we panic and we say we're all behind.

We have to drop all the safeguards a- and all the requirements and just start sprinting towards this," but saying, "You know what? We're gonna do this now, get ahead of it and adopt this, uh, safely." Yeah. Yeah, no, it's, uh, it's, uh, it is a, it is a, it is a complicated thing, but like you said, it's, there is the, that, that overwhelming concern about like we, things are moving so fast with this we don't necessarily wanna get, get far behind, so.

Gabriel, you have given us so much good insight. You know, you're, you're living in this. You were living with it. You turned it into a business.

You're now living with this sort of every day from a, from a technologist's and a builder's perspective. Really, really great stuff. Aaron, you wanna, you wanna wrap us up and take us home? I think we've covered a lot.

We probably could keep going on for hours, but we wanna be respective of, uh, of Gabriel's time. Yeah, absolutely. So first of all, Gabriel, thank you very much for your time today. And everyone out there, by the way, if you're interested in giving this a try, uh, we've put links in the show notes for every- everything out there.

So if you wanna try Nanoclau, certainly go ahead and click the link in the show notes. And give us feedback on it as well. We would love to hear your feedback on it. And I'm sure Gabriel and the folks over at Nanoclau would as well.

Uh, for everyone out there thank you very much for listening this week. If you enjoy the show and if you get your podcast somewhere you leave a review, if you don't, wouldn't mind leaving us a review, we would certainly appreciate it, and certainly tell a friend. And we're always looking for feedback as well. That'll do for this week, and, uh, until next week, thank you very much for your time, and we will talk to everyone next week Thanks for listening.

Check us out at theenterpriseaishow.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • #19 - Brooklyn Zelenka: UCAN, Beehive, Beelaylocalfirst.fm · on Role-based access control100 / 100
  • Governance Is Functions: Why Your AI Won't Scale Without Discipline by DesignDisambiguation · on Role-based access control87 / 100
  • Harry’s & Flamingo: “It’s Us, We’re the Problem” with Kristen Correa Blanco, Head of PeopleThe LeaderLab: Powered by LifeLabs Learning · on Interview82 / 100
  • AI in the room, helping non-technical teams actually use itDefinitely, Maybe Agile · on Agent orchestration80 / 100
  • How a Solo Dev Hit 10K MRR by Selling to UniversitiesThe Indie Hacker Podcast with Fexingo · on Role-based access control76 / 100
  • The AI Infrastructure Race: Why Storage Is the New Competitive AdvantageThe AI Advantage: Smart Tech for Modern Leaders · on OpenClaude65 / 100

More from The Enterprise AI Show

All episodes →
  • Do You Even Need That Trillion-Parameter Model?63 / 100
  • Unstructured Data in an AI World71 / 100
  • How Open-Source is Reshaping the AI Infrastructure Stack
  • Vitamins vs. Pain Killers vs. Whippets - The Enterprise AI Adoption Problem
  • AI News of the Month - August 2026
Explore the best B2B AI & Data podcasts →
All The Enterprise AI Show episodes →