Insecure Agents is a podcast that curates the most important conversations and trends in AI security. AI engineers, CISOs, and security practitioners listen to learn how to give their agents the security they need to reach higher levels of capability and autonomy.

Allie Howe

ALLIE HOWE HOST

Allie Howe is a Member of Technical Staff at Keycard and has a background in security engineering. She is a core contributor to the OWASP Agentic Security Initiative and has spoken at AI Engineer World's Fair and AI Agent Security Summit.

𝕏 @vtahowe in /allisonhowe

Back to episodes
Sergey Burykin — Senior Software Engineer on the AI Security team at Uber
#47 Jul 23

Episode 47 · Jul 23

Solving the Agent Identity Crisis, with Sergey Burykin (Uber)

Sergey Burykin · Senior Software Engineer on the AI Security team at Uber

--:--

We sit down with Sergey Burykin, Senior Software Engineer on Uber's AI Security team, to explain the agent identity crisis and how Uber solved it while running roughly 1,000 agents in production. Sergey helped write Uber's article Solving the Identity Crisis for AI Agents, and his core argument is that an agent should be authorized on the intersection of user permissions and agent permissions, never just one. Use only the user's permissions and a hallucinating agent can make calls the user never intended. Use only the agent's identity and any user who reaches the agent inherits access to sensitive business and customer data. We get into the infrastructure Uber built to enforce that, a secure token exchange service and an MCP Gateway as the policy enforcement point, why AI security is a multilayer cake of identity, authorization, runtime guardrails, and observability, and why static OAuth scopes break for non-deterministic agents that need dynamic, least-privilege access.

Listen on