Cloud Security Podcast

How to secure your AI Agents: A CISOs Journey

Dec 9, 2025
Yash Kosaraju, CISO of Sendbird, shares insights from transforming the company from a chat API platform to an AI agent powerhouse. He introduces the concept of 'Multi-Layer Trust' as a more pragmatic approach than the traditional 'Zero Trust.' The discussion spans critical topics like securing AI interactions, the blurred lines of incident response when AI agents operate across boundaries, and the benefits of embedding security directly into development teams. Yash also emphasizes the importance of empowering employees with enterprise AI tools while maintaining a robust security culture.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

Rapid Pivot From Chat API To AI Agents

  • Sendbird pivoted quickly from a mature chat-API to an AI-agent product built from the ground up.
  • Yash described embedding security engineers into sprint teams to give real-time feedback during fast experiments.
INSIGHT

AI Apps Change Attack Surfaces

  • Attack paths, issue types, and data security models change when apps shift to LLMs.
  • Securing AI applications requires a different mental model than traditional web app security.
ADVICE

Ask Vendors About Data And Training

  • Always ask AI vendors how they use and retain your data, including for model training.
  • Require deletion guarantees and lifecycle controls if customer data could be used in training contexts.
Get the Snipd Podcast app to discover more snips from this episode
Get the app