Chris Jones, chief trust & security officer at Axonius.
Guarding Agentic AI

“AI has not changed what good engineering looks like”

Chris Jones, chief trust & security officer at Axonius, joined CTech to share his thoughts on agentic AI security, and why he thinks agentic AI's biggest risk is exposing which engineering teams already had discipline, not creating some new kind of threat.

“My biggest worry is that people abandon basic security practices and hygiene, and become overly reliant on AI agentic output by trusting what comes back without reviewing what it produced. For example, I’ve seen first-hand that development teams that follow a secure development lifecycle, with code review and QA, see a low and completely manageable uptick in the number of security findings. Teams that did not have that discipline were overwhelmed. The tooling was the same in both cases,” said Chris Jones, chief trust & security officer at Axonius, on his biggest fear about agentic AI rollout in the tech industry.
“AI has not changed what good engineering looks like. It has made the gap between mature and immature teams much harder to ignore, and that is what worries me,” he explained.
1 View gallery
Chris Jones, chief trust & security officer at Axonius.
Chris Jones, chief trust & security officer at Axonius.
Chris Jones, chief trust & security officer at Axonius.
(Photo: Michal Gerstner)
CTech reached out to a spread of Israeli companies to find out how they're actually handling agentic AI security, and whether local security leaders are ahead of the curve on the risk, or simply closer to it.
Are any AI agents currently operating with real autonomy?
We are leveraging agentic workflows extensively across Axonius, in communication and productivity, and increasingly in product development and testing. Every one of those processes is still human-supervised and reviewed. We have not turned anything loose. What we are doing is treating AI agents as an asset class, because we are an asset intelligence company. An AI agent is an asset with an identity, a set of permissions, a purpose, and a record of what it has actually done. If you cannot inventory those things and audit them, you are not in a position to responsibly move an AI agent further along the autonomy spectrum. That is the work we are investing in for ourselves and for our customers, because everyone is going to need it as they get more experienced with using AI agents.
What security controls are in place versus on the roadmap?
Two things are in place today. The first is written guidance tied to role, so people have clear expectations about what they can and cannot hand to an AI agent and what has to come back for human review. The second is that every AI agent we deploy has an identity and access controls wrapped around it, scoped to what it needs, and tied back to a named creator. That ownership link matters more than people realize. When an AI agent does something unexpected, you need to know within seconds who built it, what it was authorized to touch, and how to shut it off. What is still maturing, for us and for the cybersecurity industry, is continuous monitoring. That means discovering AI agents nobody registered, tracking permission sprawl over time, and monitoring behavior rather than just configuration. I do not think anyone should be claiming that is a solved problem yet.
Have you had an incident or near-miss?
At Axonius, we have not had an incident or a near-miss tied to an AI agent taking an autonomous action it should not have. Our controls keep the blast radius small enough that anything unexpected lands squarely in our testing or quality assurance environments. The AI-related problems I have seen across the cybersecurity industry have not involved AI agents at all. They involved humans uploading sensitive data to AI providers before the enterprise controls were in place. My takeaway is that you need to know which AI tools your workforce is using, and that you need to double down on education about what data goes into an AI provider. That’s shadow AI in practice, and it’s a common failure I see from organizations.
Where has AI already made things better or safer?
At Axonius, AI agents are providing real efficiency and giving our employees the tools they need to build capacity for growth. I will say something that cuts against the hype. I have not seen a single company effectively mass-downsize its workforce and backfill those roles with AI agents. The better strategy is to give the people you already have the AI tools to do more within their existing roles, so that headcount growth stays targeted even as the company expands. At a company on a growth trajectory like Axonius, that translates into better careers for the people already here, because they spend more time on higher-value work. This is a more sustainable outcome than a headcount reduction.