AI now arms both sides of the security fight. In 2026, AI-service secrets exposed on public GitHub jumped 81% year over year, per GitGuardian's State of Secrets Sprawl 2026 report. GitGuardian co-founder and CEO Eric Fourrier joins host Arthur Loris, Director of Platform Security at Pax8, to unpack agentic AI's impact on attack and defense.
- Treat every AI agent as untrusted: Never give agents direct secret access, and enforce least privilege at every tool and sandbox boundary.
- Protect the king before anything else: Borrowing a chess strategy, circle the crown jewel, like production, before building outward.
- AI can now defend against AI: Hugging Face used the open source model GLM 5.2 to investigate a breach after a commercial model refused.
- Shadow AI agents are the new shadow IT: Non-engineering employees now spin up agents that build unmanaged apps with access to sensitive systems.