
← David Bombal26 Aug · 26 min
#598: AI Can’t Understand Intent. That’s a Security Problem
Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal
AI is changing cybersecurity, but simply using more AI to defend against AI attacks may not be the answer.
David Bombal sits down with Danny Jenkins, CEO of ThreatLocker, to discuss the security risks created by AI, autonomous agents, zero-day vulnerabilities, ransomware, and the rapidly expanding attack surface businesses now have to deal with.
Danny explains one of the fundamental problems with AI security: AI can understand what something does, but it may not understand the intent behind it. The same action could be performed legitimately by an administrator or maliciously by an attacker.
They also discuss how AI is giving attackers capabilities that previously required significantly more expertise and resources, including vulnerability discovery and
sophisticated phishing attacks.
But AI creates another problem inside organizations. Autonomous agents can potentially access files, upload data, perform actions, and make mistakes extremely quickly. Every new piece of software adds attack surface, and powerful AI agents can dramatically increase that risk. Danny argues that the answer isn't simply AI versus AI.
Instead, organizations need to rethink trust itself.
The discussion covers deny by default, application control, restricting what software and AI agents are allowed to access, and why AI should be used as an additional
security layer rather than becoming your primary defense.
Topics include:
• AI security risks