Insecure Agents is a podcast that curates the most important conversations and trends in AI security. AI engineers, CISOs, and security practitioners listen to learn how to give their agents the security they need to reach higher levels of capability and autonomy.

Allie Howe

ALLIE HOWE HOST

Allie Howe is a Member of Technical Staff at Keycard and has a background in security engineering. She is a core contributor to the OWASP Agentic Security Initiative and has spoken at AI Engineer World's Fair and AI Agent Security Summit.

𝕏 @vtahowe in /allisonhowe

Back to episodes
Michael Davis — Global Chief Security Architect at J.P. Morgan
#58 Sep 9

Episode 58 · Sep 9

"Is This Tool Call Allowed? It's Never That Simple": Michael Davis (J.P. Morgan)

Michael Davis · Global Chief Security Architect at J.P. Morgan

--:--

Most people that architect an AI agent think to ask a binary question: is this tool call allowed, yes or no? Michael Davis, Global Chief Security Architect at J.P. Morgan, argues it's never that simple.

He walks through the four dimensions robotics uses to decide whether it is safe for an arm to move (the state of the system, the state of the environment, the quality of the decision-making, and the uncertainty of the action itself) and maps each one to agents: did the agent gain tools or network connections it did not have before, is it still moving semantically toward its goal after 30 tool calls, and what has the agent already tried.

We get into why if you think you need memory, you're probably not thinking of your problem the right way. We also explore software factories and why they need to operate as a cumulative progressive process versus a one shot of go build me this SaaS. Over the course of the episode we piece together what a good reference architecture for agents could look like.

Listen on