ATRIUMsearch → argument graph
AnecdoteVideo · 33:38 — 35:08

An organization that believed it had only three or four agents deployed discovered through an audit that it actually had 250 agents running.

Dev Rishi describes a leader who assumed his organization had just a handful of agents deployed, only to find via an audit that the real number was 250, illustrating how quickly and invisibly agent adoption spreads. ✦ AI generated

Dev Rishi · The TWIML AI Podcast · 2026-06-16 · original ↗

starts at this moment · 33:38

Elicited by

how often are you seeing things that otherwise would have just been shocking, but you know, you're able to identify and and stop those things. Is it rare or is it like

Then I got dinner with them a few months ago and they're like, you know what? I think I was wrong. Um we did an audit. Guess how many agents were deployed? And I was like, it wasn't two or it wasn't three or four, was it? And he was like, nope, it was 250.

verbatim transcript · starts at 33:38

Transcript · around this moment

33:20other things like in terms of credentials and others like pretty like I I don't want to say like all the time, but it feels like it's all the time. And I think in general kind of reflects what I hear when I speak with leaders at large enterprise organizations which is they're always surprised when they get like an audit report of what's actually happening with AI in their ecosystem. I

33:38spoke with somebody who told me like, you know, last year I don't think I need the agent security governance thing because I think right now we have like three or four agents that are deployed. Then I got dinner with them a few months ago and they're like, you know what? I think I was wrong. Um we did an audit. Guess how many agents were deployed? And I was like, it wasn't two or it wasn't

33:54three or four, was it? And he was like, nope, it was 250. And I said, okay, got it. Like it's just surprising I think how at the rate at which these tools can get adopted internally. >> And when they reported that number, was that like a was that two or 250 people using Cloud Code or are these agents that are like, you know, 24/7 living on some infrastructure in the organization

34:16or >> Mix of them, but it was a lot of like agents that were actually basically autonomous background agents people had built like in the cloud like on Copilot Studio is one example as a way to be able to just start to run tasks. >> I I'm trying to form a question around it. I think that's essentially like pinging or pushing back on like, you know, AI only as a

34:38as a means of securing, you know, these agent interactions and you know, I you know, I could ask it from like an enterprise perspective like it you know, are they going to is an enterprise going to feel like they have enough control, you know, or even from my perspective like you know, I'm a little bit old school and I feel like, you know, I want to say

34:59okay and in fact it surprises me. I was looking at co-work, you know, and trying to connect a a tool to co-work just the other day and I was like, why doesn't it just give me the ability to say read only and not, you know, you know, everything and it it it's hard to come to terms with, you know, not having that degree of control for people of a certain age.

35:23>> No, no, I think it's hard to come to terms with this for honestly everyone which is like I'm going to end up trusting you're telling me I'm going to end up trusting AI model to help me do my security and governance posture. What I think is like one of the things you pick up as an AI for insecurity is there's this concept of defense-in-depth which is you're usually going to layer

Related moments