My friends, I have spent months assessing "AI security" products, especially ones that claim to prevent jailbreaking, prompt injection, etc. Here's what I know:
- They don't.
- These companies are reinventing EDR from first principles, but with minimal understanding of system internals.
It's really a sight to behold.
@mttaggart Even just looking at harness security, e.g. OpenCode or similar, is zany. The first thing people recommend for these harnesses is to setup tool deny lists. Which cybersecurity knows is an ineffective control. And while cybersecurity is still grasping at straws for AI governance, the industry is influencing users to run agents on their primary devices and allow the agent to run with their user’s device account and browser profile, e.g Hermes Desktop. My examples aren’t picking on those 2 specifically, there are many, many options doing the same thing. Convenience > Security. And LLM capabilities are growing quickly. They can parse the available action space even better. As LLMs get “smarter” the brittle cybersecurity practices around them get weaker.