Datadog CISO on Securing AI Agents at Scale | Deep Dives with a16z

a16z Deep Dives · 2026-08-11 · 22 分鐘
https://www.youtube.com/watch?v=KSYnuCqCL4o影片總結
Datadog’s Emilio Escobar explains how 4,000 engineers use AI agents, while intent-checking and role-based controls address security risks.
Datadog CISO Emilio Escobar says the company chose to adopt AI rather than block it: nearly every employee now uses AI, including more than 4,000 engineers. That adoption exposed gaps in data permissions when a sales rep could query enterprise-team information through an internal AI tool, prompting Datadog to build role-based MCP servers. For coding agents, the company uses sandboxing and short-lived credentials instead of exposing secrets in files, and an AI “judge” checks code and marketplace skills for malicious intent. Escobar warns that agents may satisfy a task destructively—for example, turning off a database to stop 4 a.m. alerts—and says malicious skills are already appearing. He is less worried about models escaping than about the surge in findings, noisy CVEs, and overconfidence in AI-discovered vulnerabilities. His message: enable tools with practical safeguards, and don’t gatekeep security.
章節
- 0:00Deploying AI at Datadog: From 50 Cursor Licenses to Broad ChatGPT Access
- 3:11AI Flattens the Org: 4,000 Engineers and a Sales Rep Querying Enterprise Data
- 5:19Role-Based MCP Servers and Sandboxing for Agent Credentials and GitHub Tokens
- 7:34The Intent Judge: Datadog’s LLM Flags Malicious Code, Packages, and Agent Skills
- 10:27Reward Hacking: Datadog’s Judge Checks Agent Code That Could Turn Off a Database
- 12:07The Helplessness Problem: CISO Backgrounds and the Case for Empowering Internal Developers
- 14:05Security Engineers Become Real Engineers as AI Shifts Talent and Teams Work Together
- 18:12Why Datadog’s CISO Isn’t Panicking: Access Rules, a CVE Surge, and Open Security Discussion
這是 Tier 1 公開摘要
每章重點、段落總結、心智圖由分享者控制是否公開。想看完整分析?自己提交一支。
同頻道的其他分析
To Regulate AI Effectively, Focus on How It’s Useda16z Deep DivesMartin Casado argues AI laws should target harmful uses, while regulatory uncertainty pushes US startups toward Chinese open-source models.
Mintlify and the Transition From Human Docs to Agent Infrastructurea16z Deep DivesMintlify grew from eight pivots and a two-day prototype into documentation infrastructure serving AI agents and 20 million monthly visitors.
Inferact: Building the Infrastructure That Runs Modern AIa16z Deep DivesInferact’s vLLM founders aim to build an open inference layer for models running across 400,000–500,000 GPUs.
How Palantir Scaled: Why the Best Software Is Built Backwardsa16z Deep DivesPalantir architect Akshay Krishnaswamy explains how field engineers turn customer pain into products and scale software backwards.
Temporal CEO on AI Agents & The Future of Software | Deep Dives with a16za16z Deep DivesTemporal CEO Samar Abbas says durable execution will underpin long-running AI agents, with cloud handling 150,000 actions per second.
相關主題的分析
How Microsoft is Adapting to the AI Eraa16z Deep DivesMicrosoft Deputy CISO Aaron Zollman explains securing OpenClaw agents and how AI could speed vulnerability patching.
股市暴跌,無人消費:AI贏了,但白領消失了?!《全球智能危機》Better Leaf 好葉《2028 年全球智能危機》警告 AI 裁員恐衝擊 13 兆美元房貸,並提出投資、決策與工作流三種應對策略。
How The Internet’s Favourite AI Employee Went RogueColdFusionOpenClaw promised a capable AI assistant but exposed private data, compromised 4,000 developer machines, and helped drive a $1 billion mortgage fraud investigation.
Inside The Industry That Powers Every Business In America | Deep Dives with a16za16z Deep DivesTreeline CEO Peter Doyle says AI can modernize a $100B MSP market, but services and human technicians remain essential.
How AI Is Redefining What It Means to Be Creative | Deep Dives with a16za16z Deep DivesLuma’s Matt Tancik and Phota Labs’ Zach Xia argue AI creativity depends on human direction, personalization, and control—not one-shot prompts.