Skip to content
Latest
STOX.NEWS
In focus
FINN video

Zscaler CEO Jay Chaudhry on AI agents: ‘The best way to secure them is don’t trust them’

Advertisement
Demo creative for ADG7 Article top (728x90)
Show transcript

Jay, good to see you, man. It's been a while, man. Welcome, welcome, welcome. Take a seat. You want anything to drink? You good? >> I'm good. >> I got a whole fridge. Um, >> you know, I was mentioning at the top here, we were just talking about Meta and and Muse. >> What how are you starting to protect companies for this AI agent world? >> Today, a user is the weakest link. Tomorrow there'll be billions of agents. They become the weakest link. The best way to secure them is don't trust them. >> Don't trust agents. >> Don't trust agent. But give them this much trust for certain application and services and that's it. The problem today is that we let agent lose on our corporate network. It's like getting inside your building. They go where they need to go. >> I've said they they're running a mug. >> They're running a mug. Not only your building, they get on the internet. Then they start scouting what websites are out there. It's easy to scan those websites. What's more challenging is the frontier model can find security vulnerabilities in a website and a firewall and a VPN and load balancers. They break in and they get in. That's the problem. >> Are you using Muse? Have have you tested what the potential of something like this is? >> My team has been playing with Muse and a number of other similar things. This is this shows what can be done, but enterprises aren't ready for it. Our job is to make sure we provide enough security and guardrails so they could be used in a secure fashion. >> Well, Mark uh over at Meta, he's already thinking about getting into the enterprise with with agents. I mean, what's the what's the risk if agents start to run, whether it's from Muse or or even open, whatever it is, what's the risk to corporates? >> So, agents going rogue is the biggest risk. Today, a user get compromised and then the user infects everything else. tomorrow. All these agents, imagine an agent on your corporate network hacked or hijacked or it goes rogue. They're far more dangerous because they work at machine speed. They have no coffee break, no weekend, no sleep time and the number keeps them going. So they can get you confidential data out. They can bring systems down. Those are the type of risk that we have to deal with. >> Are people already putting too much trust in agents? >> So they aren't. I work with lots of large enterprises. Over 50% of Fortune 500 companies are our customers. Today we provide zero trust for users. That means the users of their companies they go through our exchange our switchboard to make sure a user can only access application A, B or C. We taken the same approach extended to agents. So agents are only given access to certain application services. We are working with many of the larger enterprises who want to embrace AI. There's a lot of pressure on them because AI actually is delivering great productivity. It is reducing. >> Well, they also have to protect the company at the same time. >> Absolutely. What's holding them back is security. That's what Zcaler is bringing in. The old approaches were firewalls, VPN to secure. That world is not going to work. What we pioneered when I started Zscaler in 2008, a zero trust architecture is becoming more relevant today than it has ever been. >> As someone that has been this industry for for a long time, you just mentioned you started of course Zcaler. Um when you hear Sam Alman say in an interview, I guess it was this morning, quote, "The world should accept some bad things happening for the benefits of AI," is that okay with you? >> It's not. Human ingenuity can always find solution to the problem. It has always found solutions. So I believe each party needs to take responsibility to do its own job. Models need to do better work on their side. And enterprises need to puts better guardrails and policies in place. That's where we come in working with model companies, working with enterprises and bringing the two together. >> Do you think the model development needs to to slow down? If we have Sam Alman saying this guy, look at this. I mean I have them right here on the political page. I mean to me bad things happening is not not acceptable. It's not acceptable. Do we have to slow things down? >> No. I don't think development of security needs to slow down. I think the models need to go through better tests and more rigorous but all overregulation of any of the stuff is not good for business ever. >> Now you have a an investor day coming up I believe tomorrow. First one since uh 2021. Now the street and this is from JP Morgan. they were they want to see greater visibility into the timing and magnitude of the AI and agentic contribution to your financials. Uh what will you tell the street tomorrow? >> So we will share the relevant information. I mean obviously I can't talk about it today but we are giving a visibility in our last earnings call. We talked about the growth of our AI security uh AR and revenues. We are bullish. We got some of the largest customers depending upon us, trusting us to secure them against all these AI agents and some of the attacks that front models can do against them. >> Where do you fall in the agentic stack? >> So agentic stack if you look at security there are few things that one need to worry about. Number one, you may not be embracing any AI. You are still uh target of these agentic attacks. All these security vulnerabilities that Methos preview of the world are found. Zscaler comes and make sure I can hide your application behind our exchange. If they can't reach you, they can breach you. That's number one thing we're doing with our customers. Number two is many of these companies will get breached. Once they get breached, the bad guys move on their corporate network and find very missionritical applications and bring them down. With Zscaler, we make sure the movement of the network doesn't happen because everything is untrusted. We are breaking the old paradigm of old school network and firewall based security. So those two things are the starting point from attacks. Then the third area is when you build application models and agents, we become the policy engine. the switchboard that says this agent can only access application A, B, and C and they can't do anything else. That's how it needs to be done. The old model is the opposite. They let you run around on the network and then they try to put control. The zero trust is the right way to do it. >> Is this the most complicated environment that you have ever seen for your company? Protecting securing policy for AI agents is fairly complicated because user was easy. Your identity and you do this. Agents can change identity in a second and they have skills. They have tools. One agent can spawn five more agents. What permission should they have? What they shouldn't? Those are the type of hard problems these are solving and that's what our researchers and developers are working on. Jay, lastly, you're you're a founder, you're a CEO, you've been in this industry for a while. What would you tell the likes of, you know, I look at an Enthropic and Dario and and Open Eye and Sam and a lot of other private companies that have raised a lot of money. What would you tell them about going public and their responsibility to investors with the technology they're developing? >> Going public is a good thing. It actually makes you more responsible and you do the right thing that needs to be done. uh we have been public for eight years now. It feels like yesterday I remember when you went >> but I think it's a good thing it puts some discipline but at the same time you run a good business you have lot more brand and also enterprises like to work with public companies >> because the transparency is there Jay good to see you uh let's uh we'll see you again soon good luck with investor day I appreciate you coming down hope you like the new set bring me something next time like a like a like I don't know like an I don't know corporate swag or something thank your bronze.

Advertisement
Demo creative for ADG8 Article body (336x280)