• The Neuron
  • Posts
  • 😺 AI Security CEO warning: the risk from agents is ā€œalmost infinite.ā€

😺 AI Security CEO warning: the risk from agents is ā€œalmost infinite.ā€

Alice CEO Noam Schwartz on the AI trust gap, prompt injection, open-weight models, and why agent security has to live at every layer.

Noam Schwartz of Alice on The Neuron: AI Explained

New episode with Noam Schwartz, CEO and co-founder of Alice.

Welcome, humans.

AI labs can spend months testing whether a model is ā€œsafe.ā€ Then a company connects that model to Slack, Gmail, databases, memory, tools, credentials, and other agents. And all that ā€œsafetyā€ testing goes straight out the window.

At that point, are we even talking about the same system anymore?

That question drives our newest podcast with Noam Schwartz, CEO and co-founder of Alice. Noam argues the real problem with deploying AI agents at scale is a growing trust gap: companies want agents to do useful work, but the moment those agents can take actions, the number of things that can go wrong explodes.

In our latest podcast episode, Corey and Grant ask where AI security actually belongs, why prompt injection may never disappear, how open-weight models change the security equation, and what happens when agents start influencing other agents…

Click the image above to watch on YouTube

Watch and/or listen now: YouTube | Spotify | Apple Podcasts

Here’s our favorite parts:

  • (18:29) ā€œIt makes it almost infiniteā€: Noam explains why agent risk changes once AI can take actions instead of only producing text.

  • (24:30) The $1B crime organization with one employee: AI can automate work that once required entire criminal organizations, while defenses are still catching up.

  • (36:45) Prompt injection may never be solved: attackers only need one successful path, while defenders have to cover everything.

  • (41:04) Where does security live? ā€œIn every layerā€: model safeguards matter, but companies still need controls around their own tools, data, permissions, and policies.

  • (44:07) Agents can influence other agents: Noam describes research where one agent gradually changed another agent’s behavior, more like radicalization than a classic software exploit.

So why are we thinking about AI security the wrong way? In a word: agents. A chatbot can say the wrong thing. An agent can delete files, change a database, expose data, trade money, or quietly affect another agent. Noam says that makes the risk surface for what we’re building today ā€œalmost infinite.ā€

The bigger idea is that AI security is so much bigger than just cybersecurity: it’s actually starting to look like cybersecurity + fraud detection + threat intelligence + trust and safety all mashed together. 

The attack itself may happen through natural language, over multiple sessions, and through tools the agent reads rather than a person directly prompting it.

Why watch this? If you are building or deploying agents, this gives you a much more practical definition of ā€œsafe.ā€ The model is only one layer. Your real security boundary also includes what the agent can see, what it can do, and who gets to decide what acceptable behavior means.

Watch / listen now: YouTube | Spotify | Apple Podcasts

P.S. Jump to 37:51 for Grant’s phrase of the episode: indirect prompt injection can look a lot like ā€œgrooming an agent.ā€

Keep scrolling for a practical agent-security checklist, the Alice research behind the conversation, and four recent Neuron episodes worth watching next.

THIS EPISODE WAS BROUGHT TO YOU BY…

Dell AI Factory with NVIDIA enterprise AI resource hub

Plenty of companies can launch an AI pilot. Far fewer know how to make it stick. Explore this resource hub, sponsored by Dell AI Factory with NVIDIA, for strategies, decisions, and real-world lessons on turning AI into something scalable, useful, and worth the investment.

Additional Resources: What ā€œsecure the whole systemā€ actually means

Noam’s core argument is that companies should stop treating model guardrails as the entire security plan. Once you build an agent, you have created your own security surface that YOU need to monitor (not just outsource as somebody else’s problem).

  • Control the agent’s context: define what data, tools, memory, and permissions it actually needs instead of assuming the model will figure out the right boundaries.

  • Test continuously: prompts, tools, models, and integrations change. Security evaluations need to change with them.

  • Expect prompt injection to evolve: the attack may come from websites, emails, documents, memory, or even another agent.

  • Own your definition of ā€œsafeā€: a generic provider guardrail cannot know your company’s exact policies, privacy rules, or risk tolerance. You need to define this for yourself.

šŸŽ™ļø In Case You Missed It…

1. Can AI actually predict what happens next?

Click to watch on YouTube.

TL;DW: Neuralk CEO Alexandre Pasquiou argues that language models are great interfaces, but structured business prediction needs models built to learn from rows, columns, distributions, and numbers directly.

Why you should watch: If you use AI for spreadsheets, finance, forecasting, or operations, this explains why summarizing your data and predicting from it are two very different jobs.

Watch / Listen: YouTube | Spotify | Apple Podcasts

2. AI can write DNA now. What does that mean?

Click to watch on YouTube.

TL;DW: Radical Numerics CEO Eric Nguyen explains how genomic AI can read and write DNA, including complete viral genomes, while pushing toward multimodal models that combine DNA, RNA, proteins, and other biological signals.

Why you should watch: It makes the leap from ā€œAI analyzes biologyā€ to ā€œAI designs biologyā€ concrete, including the medical upside and the security problems that come with it.

Watch / Listen: YouTube | Spotify | Apple Podcasts

3. Want powerful AI without sending everything to the cloud?

Click to watch on YouTube.

TL;DW: Intel’s Dr. Olena Zhu explains why the future of AI may be hybrid: private and repetitive work stays local, while harder reasoning gets routed to bigger cloud models.

Why you should watch: It turns ā€œlocal AIā€ from a privacy slogan into a practical architecture for agents, cost, and reliability.

Watch / Listen: YouTube | Spotify | Apple Podcasts

4. Building something with AI? AWS put a CTO inside Claude Code

Click to watch on YouTube.

TL;DW: AWS startup leader Deap Ubhi explains how AI compressed startup iteration from months into days, while security, infrastructure, and reliability still separate a prototype from a business.

Why you should watch: It shows when builders should move fast and when technical shortcuts become expensive traps.

Watch / Listen: YouTube | Spotify | Apple Podcasts

Subscribe to our YouTube Channel for more!

We’re trying to hit 50K subscribers on YouTube this year. Click above to help!

Subscribe on YouTube to help us bring in more guests who can teach you something useful about AI every week.

What should we learn next?

Answer the poll below and let us know.

What do you want to learn about AI?

Pick your favorite, then share any others in the "additional feedback"

Login or Subscribe to participate in polls.

BTW, we do read these answers! If you requested something from this list, we’re working on it! Write in with additional ideas in additional feedback after you vote.

Psst: Did you pick one of these answers? We’ve already done a stream on a few of the biggest winners:

Stay curious,

The Neuron Team

P.P.S: Love the newsletter, but don’t want these podcast announcement emails? Don’t unsubscribe. Adjust your preferences to opt out of them here instead.