ATRIUMsearch → argument graph
ClaimVideo · 8:17 — 9:47

Legacy rules-based systems and human-in-the-loop approval cannot keep pace with how fast agents operate, so oversight itself must shift to AI-in-the-loop systems.

Dev Rishi argues that because agents move far faster than humans can review, relying on rules-based guardrails and human sign-off is fundamentally inadequate, and governance needs to move to 'AI in the loop.' ✦ AI generated

Dev Rishi · The TWIML AI Podcast · 2026-06-16 · original ↗

starts at this moment · 8:17

My fundamental view is we can't use the legacy approaches for this. We can't rely on rules-based systems. And human in the loop is like something that feels good, but it's not actually going to work at the pace that we're going.

verbatim transcript · starts at 8:17

Transcript · around this moment

7:57faster than I can. If it can operate 10 times faster than I can, I can't realistically do 10 times the level of review. And so the argument that the engineer was making back is, "Hey, is this actually becoming less secure because I don't have the opportunity I'm signing off on this almost without having a good appreciation for like what exactly I'm doing every point?" Because it's like

8:17the iTunes like um you know, terms of service essentially. Now, I for one read that diligently, line by line, but not everyone will. And so I think that the uh you know, the trick is how to be able to manage that. My fundamental view is we can't use the legacy approaches for this. We can't rely on rules-based systems. And human in the loop is like something that feels good, but it's not

8:38actually going to work at the pace that we're going. So my view is we actually need to Look, I'm an AI person by background. We started an AI infrastructure company. What did I arrive at? My view is we should use AI and throw AI at the problem. And so go from human in the loop systems to AI in the loop systems. I talked about how I wish someone was watching

8:55over my shoulder. I think essentially that needs to be a really smart and highly specialized trained domain-specific cybersecurity agent. And that's what we've been building internally. >> Since you're a security person now, I'll ask you this. Like in in the you know, the days when we were just worried about distributed systems and um you know, connecting systems to the internet and things like that, we came up with this you know, this term and set

9:21of practices, you know, called zero trust, which is like in the older days, you know, you would establish trust with the other system and then connect it fewer, you know, gates between because you accept you uh assume that the systems were trustworthy. And then we moved to this model where yeah, let's just not trust anything and and force policies and things like that, you know, around the

9:45things that we care about. And I'm paraphrasing cuz I'm not a security person. Uh but it strikes me that the world you're describing is, you know, one of, you know, not only am I going to not trust external things, but I'm not going to trust this agent that's here sitting on my desk, you know, on my computer or wherever working on my behalf. My behalf, it's it's

10:07um you know, I'm wondering if that resonates with you and if you, you know, think or talk about this idea of zero trust extending to agents and what what are the implications of that? >> Yeah, I I like to think of myself as an AI infra person now masquerading uh and working on the uh challenges in security. But um I spent a lot of my time now

Around this claim