Cybersecurity Today
Cybersecurity Today

Oct 9, 2026 · 41 min

AI agents expose old security failures

AI Agents, Security Debt, and Governance: Dave Lewis on the Real Risks of AI

As organizations rush to deploy autonomous systems, weak credentials, excessive permissions, and inadequate governance may create greater danger than the models themselves.

3 key takeaways
  1. 1AI agents optimize for completing tasks, not for interpreting human intent or recognizing unacceptable consequences.
  2. 2Just-in-time access, detailed logging, and human oversight are becoming essential as agents interact with sensitive systems.
  3. 3Rational AI governance must replace fear-driven adoption and address longstanding security debt before automation expands its reach.

Don't miss

Dave Lewis reframes AI risk as an access-and-governance problem: agents may complete tasks successfully while violating human expectations.

The brief

David Shipley and Dave Lewis examine why AI agents can satisfy a request while violating its human meaning, especially when they pursue access, speed, or completion above judgment.

Lewis argues that the security gold rush is distracting organizations from older weaknesses: permanent credentials, excessive permissions, security debt, and governance that has not kept pace.

The central control problem is access. Just-in-time permissions, stronger logging, and human oversight could limit what agents can reach and make their actions easier to investigate.

The conversation connects agent hijacking and data theft to familiar security failures, while warning that language models can produce plausible answers without exercising critical judgment.

Lewis closes by urging leaders to resist AI FOMO, think critically about who controls increasingly powerful systems, and adapt technology without assuming automation can replace every human function.

Books & mentions

Some links are affiliate links — PodLume may earn a commission if you buy.

Listen to the full episode and explore every guest, topic, and moment on PodLume.

AI agents expose old security failures · PodLume