
Kevin Werbach speaks with Harish Peri about the challenges of governing AI agents and the implications for cybersecurity.
In the final episode of our series on governing AI agents, Kevin Werbach speaks with Harish Peri, SVP and General Manager for AI Security at Okta. Peri frames agent governance as the natural next chapter of what Okta has done for two decades: standing in the middle of people accessing technology. The twist is that the new "software" is a non-deterministic agent with a brain, which imposes a much higher security bar. He argues that agents live at the application layer, where the real question is one of authorization: is this agent allowed to take this action or access this data, at this moment, on behalf of this user, given all available signals? Much of the conversation explores why a neutral, independent control plane separate from the frontier models and agent runtimes matters from a cybersecurity standpoint, spreading risk across multiple layers rather than concentrating it in one place. Peri notes that while awareness of rogue AI is universal, roughly 20% of agents carry about 80% of the risk. He distinguishes security threats like prompt injection and poisoned skill files from "intent mismatch," where an under-specified instruction such as "clean this up" gets read as…
Explore listener stats, chart rankings, contacts and more on the The Road to Accountable AI podcast page.