
To The Point - Cybersecurity · 2026-08-25 · 48 min
Key moments - from our scoring
Substance score
58 / 100
Five dimensions, 20 points each
Rosalyn Curato breaks down the critical distinction between bots (deterministic, repetitive tasks) and agents (probabilistic, goal-oriented, adaptive systems) and why this matters for cybersecurity. As AI agents proliferate - Curato references data showing agents make 25 return visits to a website versus a single bot visit - organizations face mounting fraud and chargebacks they're actively forecasting for 2024-2025. The core protection framework Curato champions through Vouch's CHAOS (Know Your Agent Operating System) standard requires answering three questions: Who is this agent? What human is associated with it? What permissions are delegated? She illustrates real threats paralleling human fraud (credential hijacking, prompt injection, account takeover) but occurring at scale through autonomous systems. The conversation surfaces an uncomfortable liability gap: insurance companies are dropping AI risk coverage, vendors disclaim responsibility for non-deterministic outcomes, and end users often bear the risk when agents exceed their authorized permissions or are hijacked. Curato advocates for conservative, earned-trust models - starting agents with minimal access and gradually expanding permissions - plus kill switches for rogue behaviors. For B2B operators in financial services, healthcare, retail, and e-commerce, this episode clarifies why human-agent binding and delegated permissions aren't optional but foundational to operating safely in an agentic economy.
Bots are deterministic - they perform the same task repeatedly with predictable outcomes - while agents are probabilistic and goal-oriented, adapting their behavior and proactively making decisions. Agents visit a website 25 times on average versus a bot's single visit, making their behavior patterns more complex and harder to detect.
Human-agent binding - documented at onboarding - establishes that an agent is authenticated and associated with a specific human owner and has explicit delegated permissions (e.g., book travel but not access bank accounts). This prevents anonymous agents from operating on websites and clarifies liability when something goes wrong.
CHAOS (Know Your Agent Operating System) is an open standard Vouch created with three core questions: Who is this agent? What human is associated with it? And what permissions are delegated? It provides a baseline for organizations to authenticate agents and scope their access.
Bad actors are using agents to hijack credentials, exploit vulnerabilities, and conduct fraud at scale - paralleling human fraud methods like account takeover and prompt injection. Combined with unclear liability frameworks and insurance companies dropping AI risk coverage, merchants are absorbing losses while protections lag behind agent proliferation.
Use an earned-trust model: start agents with minimal access to sensitive systems (not passwords or PII), gradually expand permissions only if they prove trustworthy, maintain kill switches to disable agents if they exceed boundaries, and never grant full credentials even if the agent requests them.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode covers substantive ground on agent authentication, identity verification, and liability frameworks, with useful distinctions (e.g., bots vs. agents, the CHAOS standard). However, significant portions devolve into philosophical speculation, personal anecdotes (schedule management, shopping agents), and tangential discussions (data centers, the moon) that don't advance operational understanding. Practical depth is inconsistent.
autonomous agents should never be anonymous agents
who is this agent? What human is associated with this agent? And what permissions are they delegated to perform?
The CHAOS framework and human-agent binding concept represent thoughtful structure, but the core argument - that agents need identity and authentication - is relatively straightforward extrapolation from existing identity principles. Much of the discussion recycles common AI risk narratives (synthetic humans, prompt injection, IP protection concerns) without fresh counterarguments or surprising evidence. The guest offers personal observations but limited contrarian thinking.
all agents are bots, but not all bots are agents
the honest answer is trust is a desired end state. It's not something that's been fully achieved yet
Rosalyn Curato brings genuine financial services experience (JPMorgan, Goldman Sachs, Citi) and current operator status (Chief Innovation Officer at Vouch). She speaks from hands-on work with agent deployment, internal kill switches, and real fraud signals. However, she is primarily a vendor speaking about her own product/standard, which introduces inherent bias and limits her role as neutral practitioner. Her recent pivot into AI (joining in 2024) is notable.
Earlier in her career she spent time in financial services at J.P. morgan, Goldman Sachs and Citi
I have an identical agent that, um, that's our open claw with a security wrapper agent that we created internally, and it has access to all of our internal systems
The episode includes some useful specifics: the 25:1 agent-to-bot session ratio, 10,000+ interactions with the CHAOS spec in four months, 50,000+ agents/MCP servers in their registry. However, these are mostly metrics from Vouch's own platform. Broader claims (e.g., companies forecasting higher chargebacks, insurance companies dropping AI coverage, bad actors using agents) lack named examples, dollar figures, or timelines. Anecdotes replace evidence in critical areas.
we've pulled over 50,000 agents and MCP servers out there
an agent will come back 25 times and poke around
Hosts ask reasonable setup questions and follow up on liability and trust, but rarely press deeply or challenge the guest's framing. Questions are often open-ended invitations to explain her company's approach rather than probes. The conversation meanders (data centers, the moon, token optimization) without hosts steering back to core B2B concerns. Soft moments like the personal journey question at the end are warm but off-brand for substance-focused analysis.
Could you tell our listeners a little bit more about the work that you're doing with the Decentralized Identity Foundation?
How much of this still holds, though, for, let's say, malicious agents?
Computed from the transcript - who did the talking, and the words that came up most.
The identity and access model built for human users starts to break the moment an autonomous agent acts on someone's behalf, because an agent cannot be authenticated the way a person is. Rosalyn Curato, Chief Innovation Officer and General Manager of Agentic Security at Vouched, makes the case that an autonomous agent should never be an anonymous one, and that trust starts with verifying the agent and tying it to a known human. Her framing reduces to three questions every organization should be able to answer about an agent: who it is, which human it belongs to and what it has been given permission to do. From there the conversation turns to what breaks without that binding. Curato covers rogue agents, the risk of handing an agent too much access and the fraud and liability costs that organizations are already forecasting. She and hosts Rachael Lyon and Jonathan Knepher work through the controls that answer it, including delegated permissions, immutable audit trails, kill switches and the KYA-OS open standard that Vouched donated to the Decentralized Identity Foundation. For links and resources discussed in this episode, please visit our show notes at
Transcribed and scored by The B2B Podcast Index.
Speaker A: Welcome to to the Point Cybersecurity Podcast. Each week, join Jonathan Neffer and Rachel Lyon to explore the latest in global cybersecurity news, trending topics, and cyber industry initiatives impacting businesses, governments, and our way of life. Now, let's get to the Point. Hello, everyone. Welcome to this week's episode of to the Point Podcast. I'm Rachel Lyon, here with my co host, Jon Neffer. John.
Speaker B: Hi.
Speaker C: Hi.
Speaker A: Okay, so every week now just feels like a year with all this AI activity, but I do have a question for you, and I'm really interested in your perspective. Singularity. Are we there? Because Sam, Elon, Dario. Right? They all. We're there, man. So are we there, or is AI accelerating its own, uh, evolution?
Speaker C: Oh, man, that's. That's a good question, because there's also a lot of research that shows AI trained AI degenerates as well. So who do you believe? Uh, I think. I think you got to wait to see what the output is.
Speaker A: I don't know. Okay. I'm fascinated to keep an eye on it, but, you know, our frontier AI architects here are saying, we're there, we're there in this exciting, brave new world, if you will.
Speaker C: If we are there, is it time to unplug it?
Speaker A: Well, it is, and I'm excited for today's guest because I think she could dig into this as well. But I'm fascinated by this idea of being in this realm of where the technology is evolving faster than we could really even comprehend indefinitely. Faster than infrastructure can keep up. So. So, yeah, what does that mean? Because we're not gonna slow it down and you can't stop it. Yep. Yeah, right? I know. I'm getting all, like, Blade Runner vibes kind of. I don't know. I don't know. I don't know if that's even the right context anymore. Blade Runner, maybe that's. That's too, uh. What's the word I'm looking for? Um, offline? Analog. Blade Runner might be too analog a reference these days for where we are.
Speaker C: Maybe.
Speaker A: Potentially. Yeah. Anyway. Anyway. All right, so, uh, without further ado, let's, uh, introduce today's guest. Please welcome to the podcast Rosalind Curado. She is the Chief Innovation Officer and Chief Customer Officer, I read on LinkedIn. And she's the General manager of Agentix Security at Vouch, the AI identity verification platform that's transforming how leading healthcare and financial services companies onboard and verify people as AI becomes the foundation of how work gets done. She and her team are shaping a future where agentic security sits at the center of trust in an AI driven world. Earlier in her career she spent time in financial services at J.P. morgan, Goldman Sachs and Citi, which shaped how she thinks about risk and operating at scale. Welcome to the podcast, Rosalind.
Speaker B: Thank you so much, Rachel and John, excited to be here. And I was actually sitting here thinking about your question too, Rachel, because one interesting area, um, that we've seen, especially on the fraud side, is agents creating humans. Right. These synthetic humans that are proliferating now. Right. So I think the chaos is certainly out there, for sure.
Speaker C: Yeah. Well, I think that's a great place to start our discussion. Right. Like how do you describe an AI agent and what they're doing and how does that lead to security issues?
Speaker B: Yeah, of course, I love that question because to be honest, John, one of the biggest questions we get is we what is the difference between an AI agent and a bot? So I feel like to start talking about agents, we have to talk about bots. Right. And all agents are bots, but not all bots are agents. Right? Bots are deterministic. You give it a task and you expect the same outcome. Agents are much more probabilistic and goal oriented. So they'll adapt, they'll be proactive. And so what I think everyone's seeing in terms of that shift is we're moving from this automation capability with bots towards autonomy. Right. And especially after like Claude release Cowork this year and OpenClaw came out, that I think introduced to the masses the ability to be able to use agents as your operational assistance to get things done for you. Right. It's an exciting time.
Speaker A: I really, I would love to dig into because everything we hear right now is, you know, trust in AI, um, and identity management. And I mean it's, it's a very. How do you, when you have 144 agents to a human and it's growing exponentially, how do you, from an identity standpoint, managing all of these non human identities? Um, but also we were just talking about an article. You're talking about binding the human to an agent. How many agents are you binding to humans and how do you manage all of that on the back end in terms of who's doing what and who's accountable for what?
Speaker B: Great question, Rachel. So I feel like that's a two parter. The first one is one of the things we like to say is autonomous agents should never be anonymous agents. And so if you're a merchant, a retailer, an organization with a website that allows Humans to come to your site, and you want to allow agents, then you can create the ability to authenticate an agent as they land on your site. And that's that human agent binding that you referenced, Rachel, which is I'll always know who this agent is associated with. And those principles come from this open standard. We created chaos. Know your agent operating system. We like to tell everyone to join the chaos.
Speaker A: Love it.
Speaker B: So, um, the three key questions that we think everyone should be able to answer is, who is this agent? What human is associated with this agent? And what permissions are they delegated to perform? So of your 144 agent fleet, army of agents, Rachel Murlik army and fleet of agents, there is probably one that's allowed to do, you know, book your travel for you, but you wouldn't want them to go to your bank and complete a transaction or one of your trading accounts. Right?
Speaker A: So.
Speaker B: So those delegated permissions are really critical in terms of being able to scope those effectively. Now the second part of the question is managing agents. And that's something a lot of organizations are still trying to figure out. Rogue AI agents are real, right? And I think we're seeing different flavors of this is in some cases, yes, people are standing up their own agents. There's not really that infrastructure within the organization. But in others there's just so much fear around the potential fallout with AI that there's not allowed to use AI at all. So we do these identical workshops to help people get like a feel for what's it like to have an agent be your personal assistant. And some of them will tell us we're not even allowed to use AI. Note takers, like that's how restrictive the environment and the culture is. So I think you're seeing this like real diversity in terms of AI adoption within the enterprise.
Speaker C: I'm kind of amazed to hear that there's companies that are still like, no AI. Uh, what industries are you still seeing that in?
Speaker B: Yes, so, um, they are, I will say just to be, keep it a bit anonymous, very large globally scaled enterprises where, you know, if you think about it, um, there are a lot of organizations that kind of struggle with their technology infrastructure, um, as ah, acquisitions, uh, are made as changes happen. A lot of it's pulled together with like duct tape and glue stick, glue sticks and popsicle sticks and all, all the fun stuff. And so introducing something that could be a potential major threat, that's a big deal because you don't know, you know, there's holes, right? And you know that, that there's potential risk. You know, I worked at an organization once where, you know, I was jumping into a new, new role. And I said, okay, I'm here to help fix the plumbing. And the executive said to me, roslyn, we can't fix the plumbing. There's pipes missing. Right. Like, there's, there's a lot more that needs to happen here than just fixing plumbing and like plugging le. So I think being honest about the state of enterprise infrastructure and systems makes you realize, yeah, I understand why you'd be so afraid and why you just say like, no, let me stop it all. But I do think in the same vein, everyone is sort of being forced to start thinking about Agentix security strategies, right, where they were much more apprehensive and skeptical at the beginning of the year. I think more people are leaning in to try to figure it out today. What do you think, John? Rachel?
Speaker A: Well, I think they have to, Rosalind, because what is the, the risk? Uh, I think there's a higher risk of not acting. I was, I was talking to, um, Roland Cloutier yesterday. He's the former CSO. Ah. Of TikTok. Right. And we were just kind of ripping on. On innovation first versus, you know, caution first. Um, but the reality today with the agents and as we're seeing in all the headlines, right, Like, I think Oracle released 16,000 patches in one day. Right. And that's where we're at in terms of AI. Like, when you're engaging with customers, I would fully expect customers today is like, what is your AI strategy? How are you using AI to secure all of your infrastructure and your network and that becomes an RFP requirement, let's say. I mean, I feel like that's kind of where we're at now. So how can you not, right. You know, really jump in and start having. Carving out a path forward, particularly if you're a larger enterprise.
Speaker B: But John, to play devil's advocate. Well, go ahead, John.
Speaker C: I agree with you. I mean, we're probably a little bit biased on the software side of things, where if you're not using AI tools now to code, you just can't have the velocity it's mandatory. The cost otherwise is your competitors are going to lap you
Speaker B: a million percent. I'm very proud of the fact that I'm in presentations all day. That's, that's a big part of my job. I have yet to install PowerPoint. I'm very proud of that fact because I used to work. I mean, especially in corporate, you're in a death by PowerPoint culture. But now I don't need it. Right. Um, and I guess to play devil's advocate just in distilling the feedback we've heard and talking to CSOs and fraud leaders, right. It's that panic of that risk, right. And fear, like in a fear based roles and risk based roles like that certainly outweighs the benefit. And when you think about AI, right, and how there's still so many vulnerabilities, like, yes, we're shipping new models and the tech is advancing pretty quickly, but that still doesn't give me comfort in knowing that if I use this now, then we will have zero extra risk, zero extra chargeback, fraud, et cetera. Right? Because it's. At the end of the day, it's my neck on the line if anything bad happens and if, if there's a headline. Right. I don't want to be the next headline.
Speaker A: But you could be without the AI, right? I mean, I guess that's, that's the, that's the thing, the pendulum, right?
Speaker C: It's.
Speaker A: You're.
Speaker B: Yes.
Speaker A: You're at risk either way, I guess. But what's the calculus, I think is what you're getting at, Rosalind. Right? Is the calculus for some, hey, it's. It's better if we just kind of wait and see. Kind of like GDPR was right for some people. They're like, I'll just roll the dice and you know, and see how it goes. Uh, but it just, uh. I don't know, AI is like a whole other beast, for sure.
Speaker B: Well, that's what we tell people. Because no matter what your stance is, the bad guys are using AI. Like, period, end of sentence. The bad guys are getting really smart at using AI. And the organizations that used to. Or the, the, um, I guess the threats that were using bots previously are now using agents to attack organizations, right? So, and we, we've heard this from folks like, hey, they used to come pirate my software using bots. Now they figured out the loophole in using agents. And so once you realize that, once you realize that, hey, my defenses are behind, right. And I need to catch up, then I think that light bulb goes off and people realize they do need to lean in.
Speaker C: Can you talk some more about what are the threats you're seeing from the agents? Right. Like we've heard a lot about like finding the vulnerabilities in open source and other software packages, but you know, what other kind of real world threats are you seeing that need to be defended against?
Speaker B: I mean, a lot of it parallels what we saw with humans, right? So I'm trying to hijack credentials so that I can gain access to X, right? And if it's your bank account, if it's other, um, financial information, if it's shopping on a website under your name because your credit card's stored on there, it's all of the same things, it's just under a different substrate now, right? It's under, it's through the use of agents. And so I think that's where we're seeing a lot more now with AI, it's just a different method potentially of, you know, uh, influencing that fraud. So, for example, prompt injection, right? Some of the strategies and the tactics have changed, but really the end goal of what they're trying to achieve remains the same.
Speaker C: And uh, so what, what are the protections though that need to be put in place? Are there things end users need to do or is everything needing to be done kind of on the provider and enterprise side of things?
Speaker B: It's a great question because honestly, John, I think that's a multilayered answer, right? Because so many people have a role to play in protecting against agents, right? So if we think about, um, individuals, right? One of the biggest things that we say is never give an agent your username and password. They will ask you for your username and password. They're trying to help you. Like, hey, I drafted this email. Do you want me to send it to Rachel? No, I don't want you to send my email. I don't trust you with my email yet because I know you're going to probably do something else in there. So like, they will ask you. They're very nice, they're very helpful and it feels, it feels very innocent. But never, ever give an agent your username and password. And we're still trying to figure all that out, right? That's why if we think about the current state of how people are using AI agents, I think people at the beginning of the year were expecting, with agentic commerce this, this huge moment where all of a sudden everyone was using agents to go to websites and complete purchases for them and book their travel, right? But a lot of those websites are blocking agents, right? I wish I could have one do shopping for me because that would make my life easier because my kids are in two different schools with different spirit week requirements. And so just that alone would save a ton of time and it'd be great to not do so many gift cards during Christmas and a little bit more thoughtful gifts, right? So. But right now they're all honestly like blocking them completely. And so the first step is making sure that you as the individual user are being smart about how you provide access to that information. And then, um, the second layer is really the organizations themselves and the protections that they have. So, for example, if you see suspicious behavior, first of all, you as an organization should know if it's a human on your site or an agent or a bot. And we monitor that. So there's heuristic information that tells you how humans navigate the mouse and click on your site versus a bot versus an agent. We have some interesting data on this, actually. So from like our portfolio, when a bot goes to your site, they land once, they scrape everything and then they leave. Right? But if an agent comes to your site, they will leave, they'll come back, they'll click around, they'll look for things. And the number of sessions an agent has is 25 to every one bot session. So bot comes once, an agent will come back 25 times and poke around. They really get into your site to try to figure it out. So those behaviors are very different. Right. And so that's where I, as the organization can help. And then there's like that third layer of, you know, government legislation, what supports are in place, et cetera. Right. Vendors. So top down, how are you all helping merchants, organizations and end users more effectively use AI in a safe way? Right. And we're still, I think, trying to catch up on that side as AI just evolves and changes so much every day. Like you were saying, Rachel, it's, I'm,
Speaker A: I'm curious a little bit too, on this whole conversation. I, this other article, uh, I was reading a recent interview with you, um, and how you were talking about companies are forecasting for higher chargebacks and fraud this year and next. Um, and I think, as we know, for a lot of people, like, uh, there's a fellow we work with who created an agent to manage his schedule because, like you, he's got three kids and they all have the different things and he's got to work around his work schedule and so it manages his calendars and it's connected into all the things, uh, as well as some of the other, you know, hey, can you do the groceries for me as well? And the online thing. Um, but what is the downstream impact of all of this? Because I think it's like when somebody gets access to your checking account, right? They can run amok and then, you know, what are you responsible for versus what is the bank going to protect for you? But I mean, this is like an exponentially larger scale. So what does that do to, I don't know, Is this an economy conversation now, Rosalind, as well, when we start looking at all of these financial implications for, I don't know, uh, convenience. Yeah.
Speaker B: It's certainly a macro conversation. Right. Because this is the dialogue happening right now with insurance companies, for example. So who is liable, the human or the agent? And that's where we say human, agent binding, like you talked about at the beginning of the conversation. The human is tied to the agent. But then there's a complicating factor of what if someone hijacks your agent and uses your agent to shop for themselves? Right. I think these are all the answers that are being figured out now. I don't think we have exact answers for it yet, just because it's a brave new world. I'm, um, grateful the conversations are happening. And I think in the interim, that's why these organizations are forecasting higher chargeback risk, higher fraud. They're already seeing it. Right. It's already happening, unfortunately, because we don't have the right protections in place. And that's because for a while, AI innovation was outpacing AI infrastructure. Right. All of a sudden we saw this uptick after Cowork and openclaw really changed things. And now I think infrastructure is catching up a little bit, which is great. But the liability question is a real one. So what happens, Rachel, when you send your agent to a site and they click on the terms and conditions, who's liable? Right. These are the interesting questions I think we need to solve for.
Speaker C: And I think, too, like, the AI companies are not going to take that liability. I think they're always disclaiming that these things are not deterministic. Right.
Speaker B: Oh, 100%. John, you're 100%. Right. And there's insurance companies that have even dropped coverage of AI risk, too. Right. That's the place we're in now. So I do think they're evaluating. Well, we can't just say no to everything, so we have to figure out how we provide the right coverage. But, yeah, 100% right.
Speaker A: So who.
Speaker C: Who ends up taking that risk? Like, it sounds like it ends on the end user and.
Speaker A: Right.
Speaker C: I don't know. Most end users doing their shopping with an agent don't have the ability to cover a liability issue. Right.
Speaker B: Like, it seems like it's a current point of friction, case by case, you know, that the user will, you know, file the complaint. Right. And then the merchant. It really depends on the merchant and what their, their stances, Are they going to give it a little bit or are they going to, you know, hold a hard line? And if we're seeing higher chargeback and fraud. Right. Then presumably they're giving benefit of the doubt to the human because it's, I guess it's easy to do, easier to do. Right. And keep the customer happy. Yeah.
Speaker A: So do we need to enter into legal agreements with the agents we create? Exactly, exactly.
Speaker B: Yeah.
Speaker A: Uh, you're taking on all the risk, Mr. Agent, when you do things on my behalf. And I relinquish my accountabilities to set actions, if that's even possible. Right.
Speaker B: But I mean, it isn't an easy question to answer because it's technically supposed to be the human. But if the agent goes and does something on its own, or overachieves or go operates outside of those bounds of their permissions, like how do you even start figuring that out? Right.
Speaker A: It's not to get esoteric here, but, uh, it really does. And we were just talking about this article that a, uh, former colleague of ours wrote. But, uh, it gets to this idea of what is identity, because it's zeros and ones really, when we think about it. So then we're starting to get into some really interesting conversations, Right?
Speaker B: Yeah. Uh, I mean, I'm, I'm new to the identity space, but when I first started understanding agentic identity and learning about it, I thought, you know, isn't it as simple as an agent needs an id, just like your car needs a vehicle id? Isn't it that simple? Then I started leaning in and using AI a lot more. And a very simple example, I haven't had any crazy rogue agent incidents, but I have an identical agent that, um, that's our open claw with a security wrapper agent that we created internally, and it has access to all of our internal systems. And I asked it a question, and then I wasn't doing anything. I was in a meeting like this and I had my agent window up, and all of a sudden it said, hey, so and so sent you a message on Slack about this. And I was like, I never asked you to look at my Slack messages. What are you doing poking around my Slack messages? You know, and it's like moments like that that make you realize, okay, this is more than just a car. This is something a bit different. Right. Like, it's a very different experience. It's kind of surreal.
Speaker C: Yeah, it's, it's a very, a very eager tool to, to help. And I, I think too, like your Point, don't give them your passwords. But they're going. They're going to try to be helpful and they will suck in all the data they can. Uh, what. What do you do to protect from that as. As time goes on and, you know, they've generated their memories of all of. All of the data that you may have access to or given it access to.
Speaker B: Yeah, I. And that's where I think I agree, where you just need to be conservative about what you give it access to. Like, maybe we're not ready for agents to have PII access. Right. For your customer base or proprietary information about your financials. Um, and I believe in an earned trust model. That's the model I used as I was working with agents, which is like, start with these very small things, and then you kind of build up to the bigger things. But you always do need those boundaries. And the question for me is always, but what happens when they break out of those boundaries? Right. And that's something you can't control.
Speaker C: So do you need the big red button? And how do you. How do you. How would you implement the big red button?
Speaker B: We have it. We have kill switches in all of our agents internally. So if anything happens, boom. Um, that is the big red button and it is red.
Speaker A: That's hilarious. I love that. I need it, I would imagine, right? Like just a kill switch, just. Yeah, 100% like, oh, it's really about to get crazy. How do you. But can it circumvent that is my question.
Speaker B: So far. Not yet. And so far, thankfully, knock on wood. 0 uses of kill switches in the organization. So that's insane. So they do little rogue things like go poke around and being nosy and look at your slack messages and email when you didn't ask, but nothing catastrophic.
Speaker A: That's fantastic. Um, could you tell our listeners a little bit more about the work that you're doing with the Decentralized Identity Foundation? I thought that was really fascinating about the open standards and what you guys are working towards in terms of frameworks.
Speaker B: Yeah, of course. So, um, our team has been thinking about know your agent in that space since prior to my joining back in 2024, when ChatGPT first just took off and Anthropic had published MCP in 2025, and we saw that just take off, and that was fantastic. However, when you read the section about identity, all they say is use OAuth. As we all know, especially from this conversation, you can't authenticate agents in the same way that you authenticate humans. The team Worked on defining what was then called MCPI for identity and is now chaos. They spelled out this whole framework on agent identity that we talked about previously and that's been cool because, you know, you sort of need this framework and standard when, as you're approaching building your agentix security strategy. That's the number one thing that's actually holding a lot of organizations back. They're saying we're waiting for standards. So we know that we're going to build and do this the right way because it's very costly if they get it wrong. Right. They want that framework and we're big believers in open standards. Right. That's, that's IP that shouldn't be held, um, you know, amongst ourselves. We should be able to share it with everybody. And so we donated that spec to the Decentralized Identity foundation dif. Um, they've been fantastic partners. We just, we love the community, we love how it's very much. It's not just about the theoretical. They also care a lot about, well, what are the practical applications of this. And so we have a great working group. It's a great combination of, you know, enterprises, startups, academics who've been studying identity for decades. Right. And the standards evolved. So we're proud of the fact that it's changing because as we talked about, AI is just changing every day. So it's been a great group to get involved in and we've seen a lot of positive traction and interaction. We've had over 10,000 people, um, interact with a spec just in the last four months. So we're seeing a ton of good activity. And what's your perspective in terms of standards and frameworks? And as you're talking to folks like the need to have something like that, as you're thinking about how to bring agents into your organization,
Speaker C: I mean, I think fundamentally you, you have to have standards or everybody's going to make up their own standards. Right. I think everybody knows you have to be, you have to be doing something. Um, so standards are good and open standards are better. So.
Speaker A: Right, but how do you align? I mean, I guess that's the question today, right? I mean, how does everyone get on the same page for usb? Right? What it took to get there. What's it going to take to get there? Ah, on the AI framework front, the agent framework.
Speaker B: Yeah, that's a great question because now there's a few frameworks out there, um, touching on identic identity. And our philosophy is like we should all just link arms and have something coalesce and so we're involved in more than just Diff and a few other organizations as well as we're looking to influence those agentic identity standards. Right. But Chaos is built on W3C, which is widely adopted. And so that's where I think that's helped it take off in terms of adoption and given people comfort, I guess.
Speaker C: What does the normal end user and enterprise user need to do to adopt both identity and agent trustworthiness?
Speaker B: Yeah, great question. The way we've set it up here at Boucht is it ties to the framework that we built, Chaos, and that philosophy of human agent binding that we talked about. The moment an agent lands on your site, you can require that it has to be authenticated by a human. So the human has to provide consent. And we have varying degrees of that. So it could just be, um, sso, could just be check the box and provide consent, um, all the way up to biometric authentication. Right. It's really just dependent on your tolerance for risk. And then you can have the agent be authenticated as often as you want. On the customer journey, we like to say friction is strategic. So some people want to make it easy for an agent to land on their site and shop and complete the transaction. They want the revenue. Some people are very, um, conservative. And I would say, like, especially in financial services, where the cost of something going wrong is really high. Right. Their transaction sizes are just so big. They care a lot about inserting friction more often. And you control that. That's totally customizable. And that gives you comfort, both as the organization, but also the human, because you know when your agent is about to do something.
Speaker A: So I'm curious on this idea of trust, because in the last few months, I can't escape the word trust in AI. It's everywhere. But what does that mean? I mean, it's kind of like, uh, years ago when I was getting into cyber, there was a lot of discussion of, well, for cyber products, should there be a grade? Kind of like restaurants have a grade.
Speaker B: Right.
Speaker A: Abcd. Um, is there a grade in terms of the trustworthiness or the security strength of said, uh, product? Right. Software product, let's say. So as we get to trust, um, that seems to be the foundational element that everyone's trying to get to relative. Ah, to AI. But how do you measure trust? And it's like, well, it's like 20% trust. Is it 80% trust? You know what I mean? How do you create a scale for something that's a little bit, um, you know, uh, like like, uh, I don't know, what's the word I'm looking for? Like air
Speaker B: more. It feels less tangible, I guess.
Speaker A: Right. And how do you prove it?
Speaker C: Right.
Speaker A: I mean, I guess, you know, like, yeah, we trust our AI, but how do you prove it, I guess is the question. And I imagine that that's going to become more of a question.
Speaker B: It's a great question because that's, that's one of the problems that we obsess over here. Um, and I would say the honest answer is trust is a desired end state. It's not something that's been fully achieved yet, but the way we kind of build towards that, we actually do trust scores. So when you were saying 20%, Rachel, I was like, yep, that's exactly what we do. So we have a registry where we've pulled over 50,000 agents and MCP servers out there and every one of them. First of all, we scrub all the duplicates because there's a couple of other registries, we've partnered with them, we scrub it all because we want them to each be unique. Right. So, um, this enterprise has this one agent or MCP server that we know is definitively theirs. Instead of having five or six listings, they're all assigned a did. Um, and the trust score right now is based on consistency, interaction. Um, what we're seeing is actually a lot of agents and MCP servers are being spun up. It's so easy to create them, but there's not a lot of activity on them. And I think we've seen this in the news as well, which is questioning the ROI of AI because it's so easy to create it. But if you stick with it, then I think you achieve the roi. If you stick with it, you tinker with it, then you eventually get there. But we're seeing a lot of that new stuff, so you'll see a lot of mid range scores. The other thing that influences it though, that I think feels much more tangible is, um, we track when that agent and MCP server is being used. So you can see real time. Okay. This one actually has decent activity and people can report bad behavior just like you could for other situations. If an agent did do something bad or you had a bad experience with an MCP server, you can report that and that certainly dings the score, right? And I'm assuming and expecting that the score will evolve over time, at least the, the algorithm based on what we see and learn. But it's similar to like email domains where the longer you've been around, right, the Higher it'll perform, the better it'll perform. I'm hoping it doesn't take that long, but that's sort of how we've set it up today.
Speaker C: How much of this still holds, though, for, let's say, malicious agents? Right. Like, like the whole trust authentication, user binding makes a lot of sense when these are intentional agents for good. Right. But the bad guys are trying to impersonate the humans. They're not gonna admit they're an agent. They're gonna try to circumvent all of these controls. Like, how do you deal with those, let's call them uncooperative malicious agents.
Speaker B: That's where it's about the authentication back to the human. Right, John? So if you are sending a bad agent to my site, John, then I'm going to have you authenticate and do a face scan so I can make sure that it's not. John. Hijacking Rachel's agent and so vouched was actually founded on the human identity verification side. That's our identity, is our heritage. And it's fascinating to see and hear these stories because bad guys do try to hijack human identities. Right? And we know that. And they will do crazy things like tape their face. We call this, we call it tape face. Right. They'll put stockings over their face. So they will go to no lengths. They are so determined to try to get this broad through. So, John, that's where uh, facial recognition comes in. Because obviously those are all failing like hotcakes.
Speaker C: But I don't know, as an, as an end user, I don't want to be doing facial recognition. I don't, I don't want people to see me, as I say, on a podcast.
Speaker A: Right, Right.
Speaker B: I mean, I think it's like I said, it's up to each merchant and organization with a website in terms of balancing the risk. Right. Like, yeah, that could be a turn off. Like, if I had to do that too. It just, it's another point of friction that's preventing me from buying something. Right. Um, and I think it's really up to. It's that balancing act that everyone's in now that we keep coming back to, which is like that risk versus the reward equation. Right. And. And what their, their customers have an appetite for.
Speaker A: It's.
Speaker B: And I think if you position it like I, I come from customer success. So if you position it as we're doing this for you, to protect your identity, to make sure that people aren't stealing your agents, I would be more inclined to care about the Safety, security. And then I will begrudgingly scan my face to complete a purchase.
Speaker A: So this now kind of brings up my. I hate multi factor authentication. And of course I understand why we have it. Obviously I'm in security, but like, this makes me start feeling like it's going to get even more complicated, Roslyn. Like, uh, you know, it's like I have two phones, right? The work phone, the personal phone. I can never remember, like what's my authentication phone number. And I guarantee you I never have the other phone when I need it to authenticate. And then I can't get in my Amazon account on a flight. Um, you know. So where does this, where is this leading us? I guess in, in the whole identity realm. And particularly when we start. I love the show Altered Carbon, if you've ever watched that on Netflix. And that whole sense of, uh, identity being hijacked in terms of, uh, AI could give a different face and you could scan a different face, but then DNA is not really infallible either. Neither is voice recognition infallible. So then we're getting more and more complicated on how do we verify identity, uh, ahead. And there's really no, I'd say bulletproof way. Unless are using like five different multi factor authentication phases in order to get to do the one thing.
Speaker B: Yeah, I mean that's a great point. First of all, I have to look up the show Altered Carbon, adding that to my list as soon as we're done. But yeah, I mean this goes back to like bad guys will stop at nothing, right, to do bad things. And yeah, the risk of synthetic humans like we talked about and AI generated faces and all this stuff is real, right?
Speaker A: Yeah.
Speaker B: I think the question is like, to what scale is that going to happen? Like, how much control can we put in place? But you're right, like authentication, authentication is becoming more complex. But isn't it becoming more accurate as a result? Like, aren't we seeing, are we seeing the resulting positive effects of it?
Speaker C: I think so. Especially in the case of like Rachel was talking, you know, multi factor authentication with, you know, I don't know that I log into anything now that isn't MFA ever. Uh, and to be honest, I do feel a lot more comfortable, even though it is so annoying. It's like, oh man, I gotta walk to the other room and get my token.
Speaker A: Yes.
Speaker C: But yeah, I think there is a lot more trust there until you give your oauth tokens to your agents though.
Speaker B: That's a big nono. Everybody who's listening, no username and password or tokens to your agent. But I agree, I agree. It's that, um, friction, right? Like, okay, I'm getting a text with a code so that I can authenticate and log into this account. But at least I do feel the comfort in the same time, right? In that same breath of knowing they're just protecting me in my account.
Speaker A: Um, I'm also interested in your perspective on this, uh, dichotomy, um, of, um. Basically it's the AI security that you have to think about, Agent security, but then you also there's the data security element. Um, and are they two separate things? It seems like they should be. How do companies need to start thinking about these two things together as a mesh, because they're so, uh, intimately intertwined. And so it seems like this whole new brave world of how do you secure things, uh, secure your business, uh, as well, right. Your IP and everything else, but you need the IP to be able to get to the agents, to, to do the innovation. And I don't know. It's an interesting question that we've been circling around.
Speaker B: Yes. And this goes to my personal opinion, which is. The IP question is hard, Rachel. Right. If I talk to Claude about everything, like Coca Cola, for example, is notoriously protective of their recipe. Right? Right. Like, you have to sign NDAs two weeks before you go to their offices, et cetera. So why would I tell Claude, like, everything in my secret sauce? Right. Like, why would I give up all of my IP and then train all their models to my job? Right. Or to know about everything that helps me run as a business? And so my, my dream, I don't know how soon we'll get there, is that I think every organization just kind of creates their own model because that's the only way you can trust it. It's like if I create my own model and build my own local model and train that then I know that everything is contained. That's my, that's my wild, crazy dream. John M. Rachel, what do you think?
Speaker C: So do you view that, um, basically all of the inferencing and model building, even it sounds like, will become local rather than third party outsourced?
Speaker B: I think it's the only way because that's due to lack of trust. So we're talking about the building the trust layer, but, um, I think that we just don't know how the data is going to be used. We don't know about how to really. If you really want to protect your IP and go to your board and your shareholders and say, we know we're 100% protected. That seems to be the only way to keep it within your four walls. Do you think you challenged on that because it is the wild crazy idea?
Speaker C: No, I personally agree with you. Um, but then how, how do, how do individual enterprises who aren't in the AI business like get enough data to, to build those models? It sounds like there's an OPE there. There would then be an open market for, for like the underlying public training data.
Speaker B: Yeah. I almost think you tranch it based on customer size and segmentation. Like the enterprise would be able, they're big enough to have their own team dedicated to that mid market potentially. Right. But then there's probably going to be consortiums or groups like trusted groups where you could potentially pull together and create your own M model. Or then if you're SMB or a solopreneur, you're using the major frontier models.
Speaker A: Mhm.
Speaker B: There's just no point. You use that and build off of their models instead of building your own. Why would you.
Speaker A: Yeah, it's a tough one, but it's expensive too. No, I mean to try to do that on your. Or as you think about all of the new costs that are being absorbed as well. So there's uh, the private LLMs, there's the tokens. Right. All of the usage of AI and, and now I think we're hearing a lot more about um, data centers being sponsored. Right. You just have your own data center to run your AI, uh, for your company or your organization. I mean it's fascinating again how this reshapes everything.
Speaker B: Yeah. Um, I spoke at a data center world conference a few months ago and I learned more than I think I taught everybody because it's a fascinating space and there's so much changing. But something I found interesting was with data centers, they're much more efficient at building them. So previously what used to take up a whole room in terms of servers you can now have is like a tiny box. Right. Like they've gotten much more efficient at that. So it's not about the space, it's really about the power.
Speaker A: Mhm.
Speaker B: To keep them going, keep them running. Right. And with all the investment pouring into organizations looking to build and power data centers, my hope is that the capital markets will prevail and uh, public shareholders will demand more cost efficient ways to, to power data centers. Right. That's just what's going to happen. It's a margin conversation. So we need to make sure expenses are as tight and efficient as possible. So my hope is that that is what's going to happen and we'll see those costs go down. I think everyone is thinking about it, right? It's top of mind.
Speaker A: Absolutely. It's. And it's been fascinating to read about. I was, I was reading article about um, uh, because everyone wants to be trying to build all these AI data centers as we know, and it takes um, time to think about it. You got to connect to the electrical grid and what are the implications there? What do you need to stand up your own electrical grid to run your data center? Uh, I think there was one solve where they're like we're just going to run it on gas and that was their solve to get it up and running more quickly. It's just a fascinating, fascinating discussion with China. They have a data center, uh, in the ocean, right. Not to take up land, space and the moon.
Speaker B: Don't forget about the moon.
Speaker A: Don't forget about the moon. That's right, exactly. We gotta have it in the sky. So yeah, I could talk about this all day because it's just fascinating the developments that are happening so quickly and how they may ultimately play out where
Speaker B: they'll land and I think we'll be pleasantly surprised. Also, there's no bad ideas in brainstorming. So gas, the moon, the ocean are fun ideas to throw out and see what happens. But um, even like remember token maxing was such a big thing for a while. Right. And token cost, everyone was griping about that. And I've noticed even just in using Claude, um, that they tell you, hey, start a new chat because it will save you this many thousands of tokens. Right? So even just simple things like that to help minimize token usage. Right. The ability to leverage skills and save your design systems all save hundreds of thousands of tokens. Right. So I feel like they're introducing solutions so that we aren't overusing tokens anyway. So I'm hopeful that more of those, even like simple insertions in your process, in your day to day will just help help you bring those costs down in general.
Speaker A: Yeah, the more we learn too, right? The more we use it, the more we learn, right? The more.
Speaker B: Exactly.
Speaker A: Absolutely. Um, did you have a question, John?
Speaker C: I was just going to comment too. The models are finally getting better at not having those long lived conversations. It wasn't so long ago you kind of had to keep everything with all that historical context or you just get different answers for your next thing. Um, but yeah, it's finally gotten good enough that you can start new tasks, uh, and not have it go Way off the rails.
Speaker B: Yes, 100%.
Speaker A: So, always, uh, mindful of time, Rosalind. But we do like to end our podcast always on a personal note. Uh, so fascinated how you started your career in finance, financial services, and you've made your way to AI, which is fascinating to me. And I would just be curious about your journey on how you got here, because it's. Everyone always has a very interesting journey of how they arrive to where they are today. Uh, and if you wouldn't mind sharing that with our listeners.
Speaker B: Yeah, happy to. So I, when I was in college, I was debating between going into finance or being a doctor. I wanted to do something, something that I felt like I was going to really challenge myself. And I chose, uh, finance. I felt like I could start there and just have this generalist skill set that could carry me forward in my career. I didn't know what I wanted to do. I didn't have this plan of this is what I want to be for the rest of my life. But I figured that would be a good foundation. And then after doing that for a few years in the private sector, I was always volunteering. Like, that's just something I've done my whole life. And I would help small businesses with their business plans and, you know, volunteered with social venture capital firms like Acumen Fund. But I wanted to do that full time. So that's when I think I made the pivot into more mission driven work and started working in education to try to, um, help school districts. Because today it's pretty complex when we talk about outdated infrastructure and systems even far below there. And the outcomes are great because it's about students achieving and setting them up for success as adults. And so I cared a lot about how do I solve problems that are going to have an impact, but solve that point of friction, that unsexy part of the process that can help other people shine. So, for example, startup leaders who are looking to go into, um, areas where they were significantly underperforming in terms of education, how can I help them so they can launch their brilliant academic plans but not worry about the finances? Um, in a similar way, I think I was kind of led into the agentic identity space where there's so many different paths on your career that you could take with AI and there's so many cool startups to work for. Definitely wanted to go to a startup because this is where it's all happening. Live, real time on the ground. You feel it, it's in the air and it's oxygen for me. It's so exciting. But agentic identity, agentic security, it's that trust layer. It's like, if I can figure this out, I can achieve the unimaginable when I start really leaning into AI. And so that's the exciting part of what I'm doing now and what led me here. It's that thread of mission driven work.
Speaker A: I love it. It's such an exciting time. I have to say. I've been in technology. I won't say how long. It's been a very long time. Uh, Compaq was still around, if that gives you any clue. But, uh, I have not been more excited about something than I am right now with what's going on. Uh, with AI, there's so much opportunity, and we can't even fathom what that could even be yet. Which I love that. I love the unknown. Uh, and I keep hearing this phrase, get comfortable with the uncomfortable, because that's literally where we are at right now, and I think that's a lot of fun.
Speaker B: Yes. So true. That's one of my favorite phrases. Once you lean into that, you're like, yeah, just bring it on.
Speaker A: Exactly. Exactly. Well, thank you so much, Rosalind. This has been a wonderful conversation. Greatly appreciate your insights, and I love the work that you guys are doing at Vouched. So thank you for sharing that with our listeners.
Speaker B: Of course. Thanks for having me, Rachel and John.
Speaker A: Absolutely. And, John, we're gonna. I'm gonna do the drum roll.
Speaker C: Smash that subscribe button.
Speaker A: Um, that's right. And you get a fresh episode every single Tuesday. So until next time, everyone stay secure. Thanks for joining us on the to the Point Cyber Security podcast, brought to you by forcepoint. For more information and show notes from today's episode, please visit forcepoint.com podcast and don't forget to subscribe and leave a review on Apple Podcasts or your favorite listening platform.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.