The Shared Security Model for AI Agents: Diana Kelley, CISO of Noma
Diana Kelley · CISO at Noma
We sit down with Diana Kelley, CISO at Noma, who has spent years on the front lines of enterprise security across IBM, Symantec, and Microsoft and now helps write the rulebook for the agent era. Diana makes the case that the cloud shared responsibility model does not translate to AI. In the cloud there were roughly two responsible parties and your data was always your data, but with agents there are at least three, the frontier model provider, the platform or developer building on it, and the user, and the trust boundary has moved from storage to decision-making and action. We open on the PocketOS incident, where a coding agent used an over-scoped Railway token to delete a production database and its backups in nine seconds, and use it to trace where responsibility actually lives. Diana then walks through AARM, the runtime security specification she co-chairs at the Cloud Security Alliance, why authorization needs five decisions instead of two (allow, deny, modify, step-up, and defer), how much context an agent can actually trust, and why the most useful question a CISO can ask a vendor is not where does your responsibility end but can you sit down and explain how you threat modeled this.
Listen on