Skip to main content

How do we secure applications when anyone can code?

07 мая 2026 г. · 24 min

Featured guest

Ashish Rajan headshot

Ashish Rajan

CISO, Author, Podcast Host, Trusted Advisor on AI & Cloud Security

Hosts

Johnny Hand

Johnny Hand

Global CISO · TrendAI™

Dustin Childs

Dustin Childs

Head of Threat Awareness · ZDI

Available wherever you get your podcasts

Available wherever you get your podcasts

AI Security Brief Episode 2 with guest Ashish Rajan

About the episode

Ashish Rajan doesn’t sugarcoat what it means to be a security leader in the AI era. This is a moment where innovation is outpacing control. Where AI is being embedded into everything, often faster than organizations can understand, govern, or secure it. Ashish is a CISO, trusted advisor, and host of both the Cloud Security Podcast and AI Security Podcast. He is also the author of the book AI Security Engineering - which he describes as a framework for building and monitoring secure AI systems. ‌

What you'll learn
  • What happens to your risk posture when non-technical employees start committing code
  • Why the built-in guardrails from your LLM or cloud provider aren't enough, and why assuming they are is your biggest blind spot
  • What most incident response playbooks are completely missing when it comes to AI
  • Practical advice for both security leaders and practitioners on how to get ahead of this

Episode chapters

  • 00:00 — Building an internal AI security harness
  • 02:22 — The messy middle of enterprise AI adoption
  • 05:18 — Managing risk when anyone can build applications
  • 08:08 — Is there a future for traditional SaaS?
  • 11:06 — Writing security guidance for a fast-moving AI landscape
  • 13:59 — What AI security engineering looks like
  • 15:58 — Why organizations cannot blindly trust AI tools
  • 18:53 — What security leaders should do now
  • 20:04 — Integrating AI into your organization’s context

"If you are using AI today, you’re already exposed. You just don’t realize it."

— Ashish Rajan, CISO, Author, Podcast Host, Trusted Advisor on AI & Cloud Security

Hosts

Johnny Hand

As the Global CISO for TrendAI™ and veteran of enterprise security, Johnny brings a security leader’s lens to every conversation, separating exploitable risk from theoretical noise. Johnny is the person you want explaining AI-era threats before your board asks about them.

Johnny Hand
Dustin Childs

Dustin Childs

As Head of Threat Awareness for the TrendAI™ Zero Day Initiative (ZDI), Dustin brings a vulnerability researcher's eye to the AI security conversation. He’s dedicated to making sure the industry understands exploit development before it becomes a crisis.

More episodes

  • AI Security Brief Episode 10 with guest Zach Evans

    Episode 10 · 27 авг. 2026 г.

    What does hospital downtime teach us about building AI-native organizations?

    Is your organization truly AI native, or did you just bolt AI onto existing infrastructure? Your answer could be an indicator to how much risk you’re carrying without realizing it.

  • AI Security Brief Episode 9 with guest Tom Kellermann

    Episode 9 · 13 авг. 2026 г.

    What do AI-driven ‘bank heist’ attacks mean for defenders?

    Attackers aren't just using AI to steal data; they're using it to fight back while you investigate them in real time. And once an adversary is inside, why would they ever want to leave?

  • AI Security Brief Episode 8 with guest Mark Houpt

    Episode 8 · 30 июл. 2026 г.

    Is AI security actually a physical problem?

    While AI might seem abstract, something that lives in "the cloud" is concrete. The AI applications we use every day run on GPUs in physical buildings, and Mark Houpt secures them.

  • AI Security Brief Episode 7 with guest Sundari Parekh

    Episode 7 · 16 июл. 2026 г.

    Who governs your AI agents?

    Your team spent a decade maturing privileged access management. Then AI agents arrived and they don’t log in like humans.

  • AI Security Brief Episode 6 with guest Rob Bair

    Episode 6 · 2 июл. 2026 г.

    Is the next frontier model your biggest threat or your best defender?

    If you think the recent wave of AI-discovered vulnerabilities is a problem, Rob Bair of Anthropic has a reframe for you.

  • AI Security Brief Episode 5 with guest Valentina Palmiotti

    Episode 5 · 18 июн. 2026 г.

    Can agentic AI really find zero-days? Ask the hacker who won Pwn2Own Berlin 2026

    At Pwn2Own Berlin 2026, a security researcher used agentic AI to help her win. The AI surfaced real, verified bugs, then wrongly called her winning bug “not unexploitable in practice.”