23 juli 2026
28 min
Sergey Burykin, Senior Software Engineer on Uber's AI Security team, joins us to explain the agent identity crisis and how Uber solved it while running roughly 1,000 agents in production.
Sergey helped write Uber's article "Solving the Identity Crisis for AI Agents," and his core argument is that an agent should be authorized on the intersection of user permissions and agent permissions, never just one. Use only the user's permissions and a hallucinating agent can make calls the user never intended. Use only the agent's identity and any user who reaches the agent inherits access to sensitive business and customer data.
We get into the infrastructure Uber built to enforce that (a secure token exchange service and an MCP Gateway as the policy enforcement point), why AI security depends on identity, authorization, runtime guardrails, and observability, and why static OAuth scopes break for non-deterministic agents that need dynamic, least-privilege access.
Lyssna på fler avsnitt från
Insecure Agents
Visar 1–10 av 54 avsnitt
27 augusti 2026
32 min
25 augusti 2026
41 min
20 augusti 2026
49 min
18 augusti 2026
35 min
14 augusti 2026
34 min
12 augusti 2026
29 min
5 augusti 2026
51 min
28 juli 2026
27 min
21 juli 2026
27 min
17 juli 2026
28 min