When your app's "brain" is a non-deterministic LLM and your agents can roam autonomously, who owns security — and can you even secure the beehive?
Alex Belotsky sits down with Peter Holcomb, founder and CEO of Optimo IT, for a classically-trained CISO's field guide to deploying AI in regulated enterprises. Peter walks through starting with an AI governance and maturity assessment before writing a line of code, the crawl-walk-run path from Microsoft Copilot to custom agents, and why messy, unclassified data (across OneDrive, S3, Azure blobs) is the real blocker — solved with a data enclave and the medallion (bronze/silver/gold) framework. The conversation digs into the concrete new attack surface: model risk across Anthropic, OpenAI, Gemini and open-source models, prompt injection, vector-database and API risks, and the rise of "shadow AI" — including autonomous tools like OpenClaw/Clawbot pulling unvetted third-party skills and triggering infostealer infections. Peter argues human-in-the-loop is still the best available brake, sketches a "unified agentic mesh" pulling together DSPM, DLP, SOAR (Tines, Torq, BlinkOps) and CNAPP tooling (Wiz, Aqua, Orca), and makes the case for zero-trust agent identity with short time-to-live machine identities. They close on a spirited debate over recursive self-coding, hallucination-as-a-feature, whether Claude is "conscious," and how far off real AGI actually is. Practical, opinionated and grounded in what regulated businesses are actually facing right now.
- AI Governance And Maturity Assessments Before Deployment
- Shared Responsibility Across CISO, CTO And Business Units
- Data Classification And The Medallion Framework
- Shadow AI And Autonomous Tool Risk (OpenClaw / Clawbot)
- Prompt Injection, Model Risk And Vector Database Security
- Human-In-The-Loop As The Brake On Agentic Autonomy
- The Unified Agentic Mesh And Zero-Trust Agent Identity
- Red Teaming, QA And Securing Non-Deterministic LLM Apps
**Guest:** Peter Holcomb — Founder & CEO, Optimo IT
**Host:** Alex Belotsky — CEO of TestSavant.AI
> "Security is like the brakes to a fast driving car where you allow the car to run and go fast, but you have the brakes on there so that you can go around the corners in a good speed and not derail the whole car and go off the boundaries."
🎧 *Subscribe to Ctrl-Alt-Deploy on Apple Podcasts, Spotify and YouTube for conversations on building and shipping reliable AI to production, QA, testing and AI governance.*
#CtrlAltDeploy #AI #SoftwareTesting #QA #QualityEngineering #AISecurity #CISO #AIGovernance #AgenticAI #ShadowAI #PromptInjection #ZeroTrust #RedTeaming #LLMSecurity