- The Neuron
- Posts
- šŗ AI Security CEO warning: the risk from agents is āalmost infinite.ā
šŗ AI Security CEO warning: the risk from agents is āalmost infinite.ā
Alice CEO Noam Schwartz on the AI trust gap, prompt injection, open-weight models, and why agent security has to live at every layer.
Welcome, humans.
AI labs can spend months testing whether a model is āsafe.ā Then a company connects that model to Slack, Gmail, databases, memory, tools, credentials, and other agents. And all that āsafetyā testing goes straight out the window.
At that point, are we even talking about the same system anymore?
That question drives our newest podcast with Noam Schwartz, CEO and co-founder of Alice. Noam argues the real problem with deploying AI agents at scale is a growing trust gap: companies want agents to do useful work, but the moment those agents can take actions, the number of things that can go wrong explodes.
In our latest podcast episode, Corey and Grant ask where AI security actually belongs, why prompt injection may never disappear, how open-weight models change the security equation, and what happens when agents start influencing other agentsā¦
Watch and/or listen now: YouTube | Spotify | Apple Podcasts
Hereās our favorite parts:
(18:29) āIt makes it almost infiniteā: Noam explains why agent risk changes once AI can take actions instead of only producing text.
(24:30) The $1B crime organization with one employee: AI can automate work that once required entire criminal organizations, while defenses are still catching up.
(36:45) Prompt injection may never be solved: attackers only need one successful path, while defenders have to cover everything.
(41:04) Where does security live? āIn every layerā: model safeguards matter, but companies still need controls around their own tools, data, permissions, and policies.
(44:07) Agents can influence other agents: Noam describes research where one agent gradually changed another agentās behavior, more like radicalization than a classic software exploit.
So why are we thinking about AI security the wrong way? In a word: agents. A chatbot can say the wrong thing. An agent can delete files, change a database, expose data, trade money, or quietly affect another agent. Noam says that makes the risk surface for what weāre building today āalmost infinite.ā
The bigger idea is that AI security is so much bigger than just cybersecurity: itās actually starting to look like cybersecurity + fraud detection + threat intelligence + trust and safety all mashed together.
The attack itself may happen through natural language, over multiple sessions, and through tools the agent reads rather than a person directly prompting it.
Why watch this? If you are building or deploying agents, this gives you a much more practical definition of āsafe.ā The model is only one layer. Your real security boundary also includes what the agent can see, what it can do, and who gets to decide what acceptable behavior means.
Watch / listen now: YouTube | Spotify | Apple Podcasts
P.S. Jump to 37:51 for Grantās phrase of the episode: indirect prompt injection can look a lot like āgrooming an agent.ā
Keep scrolling for a practical agent-security checklist, the Alice research behind the conversation, and four recent Neuron episodes worth watching next.

THIS EPISODE WAS BROUGHT TO YOU BYā¦
Plenty of companies can launch an AI pilot. Far fewer know how to make it stick. Explore this resource hub, sponsored by Dell AI Factory with NVIDIA, for strategies, decisions, and real-world lessons on turning AI into something scalable, useful, and worth the investment.

Additional Resources: What āsecure the whole systemā actually means
Noamās core argument is that companies should stop treating model guardrails as the entire security plan. Once you build an agent, you have created your own security surface that YOU need to monitor (not just outsource as somebody elseās problem).
Control the agentās context: define what data, tools, memory, and permissions it actually needs instead of assuming the model will figure out the right boundaries.
Test continuously: prompts, tools, models, and integrations change. Security evaluations need to change with them.
Expect prompt injection to evolve: the attack may come from websites, emails, documents, memory, or even another agent.
Own your definition of āsafeā: a generic provider guardrail cannot know your companyās exact policies, privacy rules, or risk tolerance. You need to define this for yourself.
Read more: Alice on agentic AI security | Aliceās open-weight research | OpenAIās model-evaluation security incident

šļø In Case You Missed Itā¦
1. Can AI actually predict what happens next?
TL;DW: Neuralk CEO Alexandre Pasquiou argues that language models are great interfaces, but structured business prediction needs models built to learn from rows, columns, distributions, and numbers directly.
Why you should watch: If you use AI for spreadsheets, finance, forecasting, or operations, this explains why summarizing your data and predicting from it are two very different jobs.
Watch / Listen: YouTube | Spotify | Apple Podcasts
2. AI can write DNA now. What does that mean?
TL;DW: Radical Numerics CEO Eric Nguyen explains how genomic AI can read and write DNA, including complete viral genomes, while pushing toward multimodal models that combine DNA, RNA, proteins, and other biological signals.
Why you should watch: It makes the leap from āAI analyzes biologyā to āAI designs biologyā concrete, including the medical upside and the security problems that come with it.
Watch / Listen: YouTube | Spotify | Apple Podcasts
3. Want powerful AI without sending everything to the cloud?
TL;DW: Intelās Dr. Olena Zhu explains why the future of AI may be hybrid: private and repetitive work stays local, while harder reasoning gets routed to bigger cloud models.
Why you should watch: It turns ālocal AIā from a privacy slogan into a practical architecture for agents, cost, and reliability.
Watch / Listen: YouTube | Spotify | Apple Podcasts
4. Building something with AI? AWS put a CTO inside Claude Code
TL;DW: AWS startup leader Deap Ubhi explains how AI compressed startup iteration from months into days, while security, infrastructure, and reliability still separate a prototype from a business.
Why you should watch: It shows when builders should move fast and when technical shortcuts become expensive traps.
Watch / Listen: YouTube | Spotify | Apple Podcasts

Subscribe to our YouTube Channel for more!
Subscribe on YouTube to help us bring in more guests who can teach you something useful about AI every week.

What should we learn next?
Answer the poll below and let us know.
What do you want to learn about AI?Pick your favorite, then share any others in the "additional feedback" |
|
BTW, we do read these answers! If you requested something from this list, weāre working on it! Write in with additional ideas in additional feedback after you vote.
Psst: Did you pick one of these answers? Weāve already done a stream on a few of the biggest winners:
Stay curious,
The Neuron Team
P.P.S: Love the newsletter, but donāt want these podcast announcement emails? Donāt unsubscribe. Adjust your preferences to opt out of them here instead.





