Navigating the Future of AI Agent Security
In this episode of the Overcommitted Podcast, Erika and Brittany sit down with Dan Moore (Senior Director of CIAM Strategy at FusionAuth) to tackle a fundamental shift in software engineering: moving from securing human users to securing autonomous code.
As AI agents move into enterprise systems, we have to ask: Who are you, and what are you allowed to do?
Inside the Episode:
- The "Lethal Trifecta": Understanding the specific risks posed by agents with access to private data, exposure to untrusted content, and the ability to communicate externally.
- Non-Deterministic Challenges: Why unpredictable AI behavior creates a new threat model that traditional deterministic code doesn't face.
- The MCP Specification: A look at the Model Context Protocol (MCP) and how OAuth standards are evolving to provide agents with verifiable identities.
- Granular Permissions & Sub-agents: Why the "separation of concerns" is the best defense against agentic security breaches.
"The non-determinism is the joy and the pain of agents... it can maneuver its way toward a goal, but others can bend the agent away from the goal we set." — Dan Moore







