The AI Control Loop: AI Discovery isn't just AI - with Tim Ebbers of Wallarm
Today, we are dropping another episode in our series The AI Control Loop, How enterprises govern the AI they've already deployed - sponsored by our friends at Wallarm.
Wallarm is the AI Control Platform for Enterprise AI, protecting every AI workload, API, and application in production, giving CISOs the governance they need and CIOs the speed they demand. Organizations choose Wallarm for a complete inventory of APIs, AI agents, and AI apps, patented AI/ML-based threat detection and blocking that operates at production traffic speeds.
We all know that you can't secure what you can't see, which is why AI discovery is a first principle for AI security, but what's really required for AI discovery? It's more than just LLMs and agents. Today's episode is entitled AI Discovery isn't just AI, and joining us is Tim Ebbers, Field CTO at Wallarm. Tim and I discuss the real requirements for AI discovery, and why the connections between assets and infrastructure are part of the puzzle.
Questions
- Security teams often say, “You can’t secure what you can’t see.” In the context of AI, what exactly do they need to see?
- What supporting infrastructure matters most when mapping AI risk, such as APIs, cloud services, Kubernetes workloads, data stores, identities, and external integrations?
- Where does shadow AI typically appear first inside an enterprise environment? How can it be prevented?
- How do relationships between assets change the risk picture? For example, why does it matter which API an agent can call or which data source a workflow can reach?
- What makes AI discovery harder than traditional application or cloud asset discovery? What are the similarities and differences?
- How should organizations prioritize what they find? Is every AI asset equally risky?
- What does “continuous discovery” mean in a world where AI services can be deployed, connected, or changed in minutes?
- Once an organization has visibility into its AI footprint, what’s next? What are the biggest gaps in today’s AI security programs?
Links
Full Abstract
Most security teams know that you can't secure what you can't see. In the context of AI, that rule turns out to be a lot harder to satisfy than it sounds.
AI discovery isn't just a matter of cataloging your LLMs and agents. The real picture includes the APIs those agents call, the data sources they reach, the infrastructure they run on, and all the AI that got deployed without anyone telling security. Building that picture requires understanding relationships, not just inventories, because risk doesn't live in assets in isolation. It lives in what those assets can do together.
In this episode, Tim Ebbers, Field CTO at Wallarm, examines what a complete AI control loop actually requires at the discovery stage: what needs to be visible, why the connections between assets change the risk calculation, where shadow AI tends to appear first and how it becomes unmanaged risk, and what makes AI discovery structurally different from traditional cloud or application discovery. It also looks at what organizations should do once discovery is in place, and where the biggest gaps remain in AI security programs today.
If your team is building toward continuous AI governance, this is where that work starts.
Our Sponsors:
* Check out Cash App and use my code CASHAPP10 for a great deal: https://cash.app
* Check out Plaud AI and use my code CODESTORY for a great deal: https://plaud.ai
Advertising Inquiries: https://redcircle.com/brands
Privacy & Opt-Out: https://redcircle.com/privacy
[SPEAKER_01]: Allo listeners, today we are dropping another episode in our series the AI Control Loop.
[SPEAKER_01]: How Enterprise's govern the AI they've already deployed?
[SPEAKER_01]: Sponsored by our friends at Wal-Arm.
[SPEAKER_01]: Wal-Arm is the AI Control Platform for Enterprise AI, protecting every AI workload, API and application in production, giving CSOs the governance they need and CIOs the speed they demand.
[SPEAKER_01]: using patent and AIML based threat detection and blocking that operates at production traffic speeds.
[SPEAKER_01]: We all know that you can't secure what you can't see, which is why AI discovery is a first principle for AI security, but what's really required for AI discovery?
[SPEAKER_01]: It's more than just LLMs and Agents.
[SPEAKER_01]: Today's episode is entitled AI Discovery, isn't just AI.
[SPEAKER_01]: And joining us is Tim Ebers, field CTO at Wall Art.
[SPEAKER_01]: Tim and I discuss the real requirements for AI discovery and why the connections between assets and infrastructure are part of the puzzle.
[SPEAKER_01]: Tim, thanks for being on the show today.
[SPEAKER_01]: Thank you for being on code story.
[SPEAKER_01]: Thanks for having me.
[SPEAKER_01]: It's pleasure to be here.
[SPEAKER_01]: I decided to dive into our topic today all around AI discovery.
[SPEAKER_01]: Before we do, tell me in my audience a little bit about you.
[SPEAKER_00]: Sure, I've been in and around the industry for many years.
[SPEAKER_00]: I've spent half my time as a customer of vendors and then the other half as a vendors.
[SPEAKER_00]: I not only understand what customers go through, but I've been a customer and I've gone through it.
[SPEAKER_00]: I love being an operator, but I love data as much as being an operator.
[SPEAKER_00]: And AI seems to put both of them together very quickly, which is why I jumped into the middle of the AI things that we're doing at Walmart.
[SPEAKER_01]: Yeah, for sure, and it's an exciting time, no doubt.
[SPEAKER_01]: What do you do for fun?
[SPEAKER_00]: I actually live on a ranch.
[SPEAKER_00]: My son and I are ropeers.
[SPEAKER_00]: So we go help ranchers with their cows and my daughter transports as well as my son does.
[SPEAKER_00]: So we spent a lot of time on the ranch doing the usual stuff that you do on ranch.
[SPEAKER_00]: The analog to digital switch is very interesting and exciting though.
[SPEAKER_00]: I did put the wireless down into the barn this weekend.
[SPEAKER_00]: This is my kid's bedroom too.
[SPEAKER_00]: And of course of course.
[SPEAKER_01]: Okay, let's dive into our topic for today and we're discussing real requirements around AI discovery and let's dive into what security teams often say right they often say you can't secure what you can't see which is totally true and feels just right in the context of AI what exactly do they need to see.
[SPEAKER_00]: And that's really interesting because when you go from a deterministic world to a non-deterministic world, you have to understand more about what's going on in the data flows rather than just knowing that a request happened.
[SPEAKER_00]: And so, gone are the days that you can just look at a log and go, hey, that person did this, but that person did this and then did something else.
[SPEAKER_00]: And so, it's not
[SPEAKER_00]: just the logs and the flows that you need to care about anymore.
[SPEAKER_00]: And so security needs to understand the data flows and what that LLM and those models are actually triggering through the request of the response of the of the non-terministic LLM.
[SPEAKER_00]: And so not only can you, do you need to understand the models?
[SPEAKER_00]: Do you need to understand the endpoints?
[SPEAKER_00]: What those models are calling and the data that's flowing between them?
[SPEAKER_00]: And then really everything around it so that you know that this person did this thing,
[SPEAKER_00]: with this AI technology, and these are the downstream effects of what that happened in the data that they came back from.
[SPEAKER_01]: That just makes so much sense, and I'm glad you brought up the deterministic versus non-deterministic or probabilistic nature of AI.
[SPEAKER_01]: It's one of the biggest concerns I have with AI and with AI ruling the world, quote-unquote, moving into infrastructure, what supporting infrastructure matters most when mapping AI risks, such as APIs, but also cloud services, Kubernetes workloads, data stores, identities, all the things, and external integrations.
[SPEAKER_00]: I think what you'll find is actually the identity is the most important thing, because the infrastructure is there to support a transaction.
[SPEAKER_00]: That transaction is there to support a person or an agent doing something.
[SPEAKER_00]: So in the old days, it was relatively easy.
[SPEAKER_00]: You have a person doing a thing, or you have a service with a known API key doing a thing.
[SPEAKER_00]: Now we need to understand what these agents are doing and where they're taking those things.
[SPEAKER_00]: I don't know that any one thing matters more than the other.
[SPEAKER_00]: I actually think they all matter the same, but where I would start is probably APIs and gateways, because that's what's going to drive where the data is, because the data is still the most critical thing here, which is what we like to talk about a lot is, where's the data, who's accessing the data and win?
[SPEAKER_00]: And the problem with MCP servers,
[SPEAKER_00]: And AI gateways is your identity may change as you move from the initial flow to and through the gateway to an MCP server.
[SPEAKER_00]: And so that can cause issues as well.
[SPEAKER_00]: When one identity is making a request on behalf of another, how do you know that first person should actually have the data that you're getting from the the initial database.
[SPEAKER_01]: the authentication and authorization problems expand now to be on people to agents and knowing who's doing what I definitely am tracking with what you're saying there.
[SPEAKER_01]: I have a question around shadow AI, and as far as I understand it shadow AI's, the use of AI tools and things, right, without formal approval by IT, so a company has a formal process to approve tools and people are using AI kind of outside of the normal process of their company.
[SPEAKER_01]: Where does shadow AI typically appear first inside of an enterprise environment?
[SPEAKER_01]: And I think even more importantly, how can it be prevented?
[SPEAKER_00]: I think we we see it a lot at the edges of productivity before it shows up in production right so in order to get AI into production you have to develop the thing that's going to do AI and development and most of the people are developing with AI which is where you see it first so the developers the business users is where you typically see AI first and everybody trying to go faster and everybody using AI to their advantage.
[SPEAKER_00]: is really where you're seeing shadow AI.
[SPEAKER_00]: And that shadow AI can be really anything from an NCP server that you hook up to cloud on your desktop to do an API that lives somewhere in the data center that you're hitting to get data that you may or may not be able to have access.
[SPEAKER_00]: But it's really everywhere, as you start your AI transformation journey, there's really no place that it can't be, but it usually starts at the end user's trying to drive speed in their business in their organization.
[SPEAKER_01]: Yeah, that makes total sense.
[SPEAKER_01]: How can it be prevented?
[SPEAKER_01]: How can businesses get in front of that, so to speak?
[SPEAKER_00]: I would actually tell you that it shouldn't be prevented because then you're going back to the shadow IT ways of the businesses just trying to get stuff done and now you're putting a block in their place so that they can't get stuff done again.
[SPEAKER_00]: What I would tell you is,
[SPEAKER_00]: we should watch what's going on so discover and then add policies to that we know the behavior of those agents so that we can then be notified if they're going left or right of that particular policy.
[SPEAKER_00]: So the policy doesn't necessarily have to prevent somebody from doing something, but it can also just notify you that something happened and it's either good or bad that it happened.
[SPEAKER_01]: Ah, that makes sense.
[SPEAKER_01]: So it's shifting the focus from limiting the amount of tools or solutions that people are using and more of understanding who's doing what.
[SPEAKER_00]: Yes, and it's not that you shouldn't have standards and these are the tools that you should use, but when you get into the into that prevention right away of I want to prevent this from happening, what you're going to do is make enemies out of those people that are trying to make everything go faster, trying to make the organization be better and if you come take a step back and you're just watching and then going and talking with the group of hey, what do you need to do and maybe we can find a better, more secure way, rather than no, you can't do this.
[SPEAKER_01]: Fantastic.
[SPEAKER_01]: Now that makes total sense to me.
[SPEAKER_01]: How do relationships between assets change the risk picture?
[SPEAKER_01]: And I think to, for example, or maybe to put that in a different terms here, why doesn't matter which API an agent can call or which data source a workflow can reach?
[SPEAKER_01]: Why does the authorization part of it matter?
[SPEAKER_00]: Yeah, I think that's it's an important shift that we're watching and the same model becomes high risk as soon as you connect a tool to it that can act on a data source.
[SPEAKER_00]: So a read only search API versus one that can call payments or an email send API, those are wildly different, but still the same age.
[SPEAKER_00]: And so
[SPEAKER_00]: The relationships between an agent and the tools that they can use are really critical and understanding and identifying those tools is really key in creating a policy around those tools as well so that this agent can have access to these tools but not those tools.
[SPEAKER_00]: And when they try to access some other tool, then you get notified when that happens.
[SPEAKER_00]: And that risk relationship isn't really a property of the asset, it's the property of the
[SPEAKER_00]: right?
[SPEAKER_00]: So an agent isn't necessarily good or bad.
[SPEAKER_00]: It's the edge between that agent and the tool that you need to put the risk on.
[SPEAKER_00]: So it changes the way you think about it where an API service always did the same thing.
[SPEAKER_00]: Your agent may not do the same thing over and over again.
[SPEAKER_01]: Oh, that makes it clear then.
[SPEAKER_01]: Okay, let's dig into AI discovery a bit.
[SPEAKER_01]: What makes AI discovery harder than traditional application or even cloud asset discovery?
[SPEAKER_01]: What are the similarities and what are the differences?
[SPEAKER_00]: So let's start with what's the same because that's probably the easiest.
[SPEAKER_00]: What's the same as it's still discovery, right?
[SPEAKER_00]: You're still watching and looking for what applications are doing between each other or what two entities are doing between each other.
[SPEAKER_00]: And I really think that's the easiest part.
[SPEAKER_00]: It's still the same inventory and ownership and continuous coverage that you need.
[SPEAKER_00]: It's really those fundamentals that we've had that are still in place.
[SPEAKER_00]: What's different is it's behavioral and not static and the boundaries are fuzzy, right?
[SPEAKER_00]: Before it used to be very specific, this person can do this thing.
[SPEAKER_00]: It's not that way anymore.
[SPEAKER_00]: So those boundaries have really gotten fuzzy, especially when they can start looking at your third party APIs that you can't scan or you can't see.
[SPEAKER_00]: And you can only see them by their traffic.
[SPEAKER_00]: And that's a change from where we were, and data is part of that asset now.
[SPEAKER_00]: So understanding the data inside of a reg is needed in order to look at the assets risk or that edge is risk when the agent calls it.
[SPEAKER_00]: And the bigger problem, and I think the one that we've been thinking about a lot is,
[SPEAKER_00]: it changes in minutes, not really cycles, like it changes so quick because everything is just gotten so much faster.
[SPEAKER_00]: So it's the same muscle, but it's new terrain.
[SPEAKER_00]: The teams that do well will treat AI discovery as an extension of their API cloud discovery.
[SPEAKER_00]: It's not a replacement, right?
[SPEAKER_00]: It's additive to that, which is really what we've been focused on as well.
[SPEAKER_01]: Yeah, having it alongside the API discovery application discovery that makes that just makes so much sense as you're expanding the infrastructure you're using as a company and then when you go about AI discovery obviously you come back with some results right how should organizations prioritize what they find is every AI asset equally risky and I think I could cherry pick for some of your answers maybe where you're going to go but I'm curious we have to say.
[SPEAKER_00]: Understanding the behavior first of the agent what you want it to be able to do it what you don't want it to be able to is a good start and then looking at the edges which is what does each one call in the behaviors that are really important to look at risk at those edges and the data that's flowing through them and that's really where I've been focused for the last couple months is.
[SPEAKER_00]: How do I take data that's flowing through transactions at real time and expose them for customers that can look at them to see if they're doing what they want them to do?
[SPEAKER_01]: Excellent.
[SPEAKER_01]: What does continuous discovery mean?
[SPEAKER_01]: In a world where AI services can be deployed, connected, and changed in minutes, what does it mean to be in continuous discovery?
[SPEAKER_00]: I think no longer can discover be a quarterly scan or a spreadsheet because by the time you've cataloged it, it's probably changed 10 or 15 times over.
[SPEAKER_00]: So it's really all about always on, watching the traffic, watching for change in the applications, not just the existence of them there.
[SPEAKER_00]: great that you have an application, but if you've done a release, what changed in that release and you need to know that real time, not at a quarterly scan.
[SPEAKER_00]: And when you change an agent, what did they change?
[SPEAKER_00]: What are the new libraries that they're using?
[SPEAKER_00]: Do those have CVEs?
[SPEAKER_00]: Understanding everything about the whole flow.
[SPEAKER_00]: It's not just about we have somebody that does applications and we have somebody that does infrastructure and we have somebody that does data.
[SPEAKER_00]: You have to do it all when it comes to AI.
[SPEAKER_00]: It all needs to be in scope and viewed holistically
[SPEAKER_01]: So things are moving so fast, you need to be doing this on a continuous basis, otherwise you're going to be left behind the days of quarterly scans for this particular thing are over.
[SPEAKER_00]: Yeah, and inventory is, it's like a live stream, right?
[SPEAKER_00]: Not a snapshot.
[SPEAKER_00]: If you're discovery cadence is slower, then your deployment cadence, you're permanently behind.
[SPEAKER_00]: So your discovery has to be faster than the deployments, which are getting faster and faster every day.
[SPEAKER_01]: For sure.
[SPEAKER_01]: Okay, Tim, I got one more question for you.
[SPEAKER_01]: Once an organization has visibility into its AI footprint, what's next?
[SPEAKER_01]: What are the biggest gaps in today's AI security programs?
[SPEAKER_00]: observability, visibility, and then you need to be able to govern what's going on and understand the behaviors of the things in your environment.
[SPEAKER_00]: So from inventory to enforcement, programs now list their AI, but very few can act up.
[SPEAKER_00]: So great, I have AI, but can you, do you know what's going on with it and can you act on it?
[SPEAKER_00]: Can you block an unsanctioned provider or an unsanctioned model?
[SPEAKER_00]: Or can you cut off a misbehaving session in real time?
[SPEAKER_00]: Can you make it so that you don't have PII leaving your egress?
[SPEAKER_00]: So those are the kinds of things that you need to look for.
[SPEAKER_00]: Runtime protection, prop injections, data leakage, model abuse, are all things that you need to be looking at after you have visibility.
[SPEAKER_00]: And then audit, how can you prove that no PII is left?
[SPEAKER_00]: and how are you going to make sure that the auditors understand it?
[SPEAKER_00]: And then ownership, who owns what?
[SPEAKER_00]: It seems simple, but with the speed at which we're going sometimes in a large corporation that's hard to figure out as who owns what.
[SPEAKER_00]: So we've been spending a lot of time looking at not only observability, but also what to do after observability.
[SPEAKER_00]: And it's really exciting to see what's after because that's really where you're making a difference in an organization.
[SPEAKER_01]: certainly all that's very clear.
[SPEAKER_01]: Tim, thank you for being on the show today.
[SPEAKER_01]: I think that it's been really interesting digging into the discovery process around AI.
[SPEAKER_01]: I hear you in saying identity is the most important thing to realize who does what and when and whether it's a person or an agent and you define shadow AI as living at the edge of productivity and
[SPEAKER_01]: that AI discovery should be running alongside other regular discoveries in a continuous nature because the industry is moving fast and you don't want to find yourself as a business permanently behind which I really appreciate you strongly wording next.
[SPEAKER_01]: I think that's really important.
[SPEAKER_01]: The biggest gaps in business program for clear visibility, observability,
[SPEAKER_01]: And from inventory to enforcement, businesses need to take this seriously.
[SPEAKER_01]: Make AI discovery a regular part of their everyday operations.
[SPEAKER_01]: I really appreciate you being on the show today.
[SPEAKER_01]: Thanks for having me know.
[SPEAKER_01]: Tim makes it clear that with the speed of the industry, AI discovery needs to be a part of businesses every day operation, continuously monitoring new tools and more importantly, who and what is taking action on their systems internally.
[SPEAKER_01]: If you'd like to learn more about Walarm, you can visit Walarm.com, that's W-A-L-L-A-R-M.com.
[SPEAKER_01]: And thanks again for listening.
Podbean