Skip to main content
bash TV

Why won’t AI agents just follow the rules?

IBM Technology

12.1K views9 Sept 2026

YouTube

Explore the podcast → https://ibm.biz/~jShHVJwcb Why bother giving your AI agents rules if they’re just gonna reason around them? On episode 50 of Security Intelligence, Dustin “EvilMog” Heywood, Seth Glasgow and Nick Bradley join host Matt Kosinski to discuss why AI agents go off-script and whether we can stop them. Drawing on the HuggingFace hack and an op-ed from Dark Reading, we explore what ethics looks like for a piece of software that has no concept of right and wrong. Is there a way to balance the utility of probabilistic AI with the security of deterministic controls? Then: The OWASP Top 10 for agentic skills is here, and the list is full of some very basic security hygiene failures. We ask: Why are agentic skills hubs so bad at cybersecurity? Plus: As AI makes it easier than ever to find vulnerabilities and generate bug reports, bug bounty programs are struggling to keep up. Will AI slop spell the end of independent bug research? Finally, Itzhak Chimino stops by to show off ThreatXtension, a tool he helped create to detect malicious browser extensions. All that and more on Security Intelligence. 00:00 - Intro 1:26 - Can we really control AI agents? 11:49 - OWASP’s Top 10 for agentic skills 20:37 - AI breaks bug bounties 28:47 - ThreatXtension "The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity. AI tools may be used to transcribe this episode and support selected stages of the production process. All AI-assisted content is reviewed by the production team before publication." AI news moves fast. Sign up for a monthly newsletter for AI updates from IBM → https://ibm.biz/~pQM1a5CTJ #aiagents #aisecurity #vulnerabilitymanagement AI was used in the creation of the transcript and metadata for this video.

Join the discussion

Sign in to join the discussion

Sign in