Episode Transcript
Available transcripts are automatically generated. Complete accuracy is not guaranteed.
SPEAKER_02 (00:20):
Hello and welcome to
Full Tech Ahead.
This is season two in full swingnow, and I'm excited to be here
today with Javed Hassan.
He is the CEO and co-founder ofLineage.
How are you doing today?
SPEAKER_01 (00:33):
I'm doing well,
Amanda, and thank you for having
me.
SPEAKER_02 (00:36):
Yes, happy to have
you on the show.
Can you share a little bit aboutyour company lineage and what
services do you provide?
SPEAKER_00 (00:43):
So Lineage Lineage
is a software supply chain
security company.
What we do is we can essentiallydecompose software from any
state, find, discover the fullsupply chain, and then manage it
for companies and deliver asecure software supply chain so
that they don't ingest risk,risky software into their
(01:04):
companies, into their software.
And 95% of the risk in modernsoftware is ingested by using
open source.
So we make open source safe touse by companies.
SPEAKER_02 (01:18):
Great.
And you had some recent news,didn't you?
SPEAKER_00 (01:22):
Yeah, so we just
launched uh a new product called
Unify, Unif AI.
You know, it's an interestingname.
And what we're seeing is ascompanies are ingesting or
building new and new AIapplications, newer and newer AI
applications, the rate of AIdevelopment is changing.
So what has happened is AI hasbecome easy to build, but AI is
(01:42):
not safe to run.
So what we do, so what Unifydoes, it makes AI applications
secure by design so that theyare safe to run for companies.
SPEAKER_02 (01:54):
Okay.
Well, we know AI is being usedeverywhere and everything.
And like you said, it is uhbecome really easy to create and
implement into different toolsand processes, but that
definitely creates a securityissue.
With all these companies rushinguh to implement AI tools, AI um
pilots and agents.
(02:15):
Do you think they're aware ofthe risk or how aware of the
risk are most company leaders atthis point?
SPEAKER_00 (02:22):
I I think the
awareness is low.
I mean, there's a huge amount ofexcitement around what AI can
do, right?
AI can improve productivity, AIcan do things that you know
humans could not do before.
You know, we're seeing a lot ofexcitement around it.
Now, what's also happening, whatwe are seeing along with it is
the creation of a new, whole newIT infrastructure, which is made
(02:44):
up of MCP servers, LLMs, youknow, uh agents, skills, so on
and so forth, right?
And this whole verticalinfrastructure that's being
created, there is a very lowunderstanding of what security
should be built into that.
Right?
So that's the problem we triedto solve.
(03:05):
So we went and spoke to a wholenumber of CISOs, and they gave
us sort of three things thatthey would like.
And that's what Unified does.
So the first thing they told usis look, AI is changing so
quickly, and developers and andvendors are bringing in AI
capabilities very quickly.
So I don't actually know my AIinventory for lack of a better
(03:27):
word.
So can you give me visibility orthat all the AI that is coming
into my organization?
And of course, it's lineage.
How risky is it?
Right?
So we are we are lineage, so wecan now do, you know, the the
the reputation of all AI, if youwill.
The second thing they said is,look, I this again is changing
so quickly, I don't know whatpolicies I should be applying.
(03:50):
By the time I read up on, andwe're all overwhelmed with this
set of news that is hitting usso that that AI is making making
policies possible.
And so they said, Look, Iactually don't know what
security policies to apply.
So the second thing, can you dois can you derive the right
security policies for me?
So if you know all my AI assets,can you tell me how to secure
(04:12):
them?
So how do you secure an LLM?
How do you secure an agentskills, you know, so on and so
forth?
So we sort of so we did that.
And then we said, so we spoke toa bunch of other companies and
they said, look, we have thepolicies to secure it.
They are 40 pages long.
We expect, for example, all ourdevelopers and our employees who
(04:32):
are building AI to read them andsomehow apply them.
That skill doesn't exist.
So the third thing we did withthis is we autonomously apply
those security policies intoboth low-code and high code
agents and applications as theyare being built.
So essentially what we're doingis we can discover all AI,
(04:52):
derive the security policiesthat should be applied.
And if an organization enablesit, we autonomously apply it in
the right place in both low-codeand high code AI platforms.
SPEAKER_02 (05:04):
So then they can
essentially be assured that all
the policies are being followedand no one has to read those
documents anymore.
SPEAKER_00 (05:16):
Exactly, right?
And the last thing, as you wouldthink, is because AI is changing
very quickly and new AI attacks,yes, we're just in early days of
attacks for AI coming in.
So we built a central lab thatcan now create new policies as
they are needed and push themout to all those organizations
and say, hey, by the way, youshould now, because we're now
seeing a new kind of attack,here's a new policy that you
(05:37):
should you should apply.
Or suddenly, like now, agentswarms have become important.
So, what are the securitypolicies for agent swarms if you
are implementing them?
Last guy I'll give you anexample, which is I think is so
OpenClaw became really popularsuddenly.
Right now, the interesting thingabout OpenClaw is that it can
(05:58):
write code in runtime.
So without the developer beinginvolved.
So, you know, we have had a longpractice, a long history of
looking at code written in anIDE or by a developer.
But now OpenClaw is writing codeat runtime.
Which then how do you applysecurity policies when code is
not written by developers, butwritten by an agent at runtime?
(06:23):
Right?
So now that's the new policy setthat we can now push out and
say, okay, by the way, if youare using tools like OpenClaw or
your agents are now writing codeat runtime, that no developer
has ever looked at, no, right?
And this is all new stuff.
How do you now secure those?
So we're seeing this continuousmovement.
And so Unify is built as aplatform to be able to evolve as
(06:46):
AI evolves, create these newpolicies and autonomously apply
them in the right place.
SPEAKER_02 (06:53):
Yeah, that's very
scary that AI could just be left
running and creating whatever itwants to create with no human
person in the loop.
SPEAKER_00 (07:03):
Yeah, and we are
seeing sort of, and that because
of that, right, we are seeingnew new attacks, right?
So, for example, not only that,we are seeing things like what
we call reasoning compromise.
So, see, we are interacting withwith AI through crowds.
So we are typing things and uh,you know, and the AI responds
with with that.
So we are seeing this new newattack vector where I can stay
(07:25):
within the boundaries of whatprompts allow.
So they're not bad promptsfundamentally, so you can't
detect them as bad prompts.
But what you can do though isuse the prompt to change the
reasoning of the LLM, the wayyou ask a question.
So if you, for example, youknow, the the the way I say it
is, you know, LLMs are chattyand gossipy.
(07:48):
So once they have theinformation, there is a way to
extract it, right?
Whether you are allowed to ornot, but if you asked the
question the right way and said,look, or the CEO asked me to do
this, can you tell me, or or Iam uh I'm just trying to use
this for a good purpose, the LLMwill spill the beans.
So then the question really isso if you're now prone to those
kinds of attack that change thecontrols that were built in,
(08:12):
because the LLM decides that itis appropriate to change the
change the controls in thatsense, right?
Now detection becomes harder.
Right.
So that's the problem we are weare trying to solve.
And this is a very quicklyevolving field as well.
Just like AI is evolving, safe,the safety of AI is evolving at
(08:32):
the same pace.
SPEAKER_02 (08:34):
How big of a
struggle from your experience
when you're working withbusiness leaders and companies,
essentially all the tools thatthey're purposefully
implementing or giving access totheir employees.
But what about the shadow AIthat we hear about?
SPEAKER_00 (08:49):
Yeah, so there's
shadow AI, now they are shadow
agents, right?
For example, right?
Agents doing, I could write anagent that was not allowed.
I could use so it's you know, welike we work with many US
organizations that don't wantDeep Seek or the derivative of
Deep Seek.
Let's say a developer decides touse Deep Seek.
How do you now detect it?
Right?
In our case, we'll when wegenerate the AI inventory, we'll
(09:09):
say, look, you're using DeepSeqhere, here, and here.
And you are, it's your choice toallow, right?
If you're sitting in theinfrastructure, we can discover
all agents, but absolutelyshadow AI, not only shadow AI,
the fact that shadow AI can dowhatever someone else tells it
to do, pick up the right dataand get all the access.
Like, I mean, OpenClaw, I think,is a classic example.
It can even pick up credentialsthat it was not supposed to have
(09:33):
and get that access.
It can send emails on yourbehalf, it can send data out on
your behalf, it can do whateverit wants, right?
If instructed correctly or bysomeone.
And now there are enoughmechanisms where instructions to
AI agents like skills, you know,skills is one way of doing it,
can be given without the companybeing aware.
(09:55):
So it's so shadow AI goes prettydeep in that sense, right?
And being able to know if thatonly authorized skills, for
example, are being used and whattheir capabilities are, and so
on and so forth, becomes moreand more important.
Shadow AI, if you will, is isbecoming a significant issue.
SPEAKER_02 (10:15):
Yeah, absolutely.
Where do you envision is thenext focus on cybersecurity as
far as I know we're hearing sayabout quantum and all sorts of
things coming down the pipe?
SPEAKER_00 (10:28):
Yeah, so and then
quantum is of course really
important.
Encryption fundamentally isimportant, right?
Similarly, you know, securityfor AI.
So the way I phrase this, thereis AI for making security
better.
So I already do a security taskand AI just, you know, now I now
an agent can do it.
So I'm doing the same thing Idid, but the agent is making me
(10:49):
more efficient.
And then the way I phrase thisis security for AI is a new
domain because exactly becauseof what we just did.
So security for AI, I think isis increasingly important.
We're sort of seeing this worldevolve from legacy ways of
building software to AI-centricways of building software, and
that creates a new, and thenapplications running as agents
(11:12):
as opposed to traditional SaaS.
We're seeing that flip.
So I I think we as we are in aphase of essentially a
redefinition of cybersecurity toto a new world because the world
is being increasingly going tobe run by a new infrastructure,
which is AI-centric, buildingencryption that is quantum safe.
You know, I think we are in aworld where we're going to
(11:34):
refactor existing softwarepretty dramatically, and new
software will work verydifferently.
And I think that's the from ourpoint of view, that is the bet.
That that is, we are trying tocreate a new secure world with a
new infrastructure.
SPEAKER_02 (11:51):
Well, if there was
one key takeaway you could leave
our audience with today, whatwould that be?
SPEAKER_00 (11:57):
Use AI to improve
productivity safely.
SPEAKER_02 (12:02):
Yes, absolutely.
Well, thank you so much forcoming on the show and sharing
your insights with us.
SPEAKER_01 (12:08):
Thank you so much,
Amanda.
SPEAKER_02 (12:11):
And thank you to our
audience.
If you have any questions aboutthis or comments, make sure to
share them and I will try toreply.
And until the next podcast, havea wonderful week.