There Is Determinism, Non-Determinism, and My Determinism
The Security Table is now the AI Security Table, and the first order of business is naming the AI that gets a seat at it. Then Matt asks what a security engineer actually does once agents are writing the code: real security work, or bot herding? Chris Romeo, Izar Tarandach, and Matt Coles detour through who owns AI generated code and what a patent is worth when a model can rebuild your product in five minutes, then dig into agent identity, SPIFFE, least privilege, and whether access control belongs inside the agent harness itself. Izar argues that guardrails living in the context window are suggestions, not isolation, and that anyone who says AI changed their whole job overnight was putting the weight in the wrong place. It all ends on determinism: run the model once and you get one answer, run it again and you get another. Which leaves three kinds: determinism, nondeterminism, and my determinism. Mentioned in this Episode: ➜ Generative Artificial Intelligence and Copyright Law (CRS Legal Sidebar) ➜ SPIFFE: Secure Production Identity Framework for Everyone Chapters: 00:00:00 - Cold Open: We Are Broadcasters 00:01:06 - A New Name: The AI Security Table 00:02:17 - Naming the AI at the Table 00:03:02 - Stickers, T Shirts, and the Rebrand 00:03:49 - Matt's Setup: Security Engineers or Bot Herders? 00:04:54 - Does Claude Code Write All the Code Now? 00:05:34 - Who Owns AI Generated Code? 00:08:27 - Who Bothers to Steal Code Anymore? 00:08:47 - What's the Point of Patents? 00:11:33 - What the Law Says About AI Authorship 00:12:24 - Hallucinating: 200 Subagents at Once 00:13:34 - Back on Topic: Bots vs. Agents 00:14:18 - Agents Inherit Human Identity 00:14:49 - SPIFFE and Identity at Scale 00:16:35 - Treat Agents Like Bob From Marketing? 00:17:40 - Why? Why? The Five Whys 00:18:48 - Cryptographic Identity for Agents 00:19:37 - Authority Is Always Derived 00:20:59 - Least Privilege: Agents Request Access 00:21:26 - Read, Interpret, Act: Fine Grained Capabilities 00:24:22 - Access Control Inside the Agent Harness 00:26:17 - I Don't Trust the Box: Sandbox Escapes 00:27:34 - Pulling a Maestro: Guardrails vs. Isolation 00:29:43 - What Should Security Engineers Be Doing? 00:30:38 - Is AI Just a Layer Seven Application? 00:31:34 - Pull the Plug: 2001 and WarGames 00:33:29 - Your Job Didn't Change Overnight 00:34:37 - LLM Code Review and the Determinism Problem 00:35:44 - How Many Runs to Get the Circle? 00:38:16 - The Tightest Box Possible 00:39:09 - Twenty Thousand Feet to the Magnifying Glass 00:39:47 - Give Scanning Agents a Threat Model 00:40:32 - There Is My Determinism 00:41:09 - Outro Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/ ➜ YouTube: https://www.youtube.com/@AISecurityTable