#599 AI Agents Are the New Attack Surface. Security Teams Are Already Behind | Jason Remillard  episode artwork

EPISODE · May 18, 2026 · 45 MIN

#599 AI Agents Are the New Attack Surface. Security Teams Are Already Behind | Jason Remillard

from The CTO Show with Mehmet Gonullu · host Mehmet Gonullu

In this episode of The CTO Show with Mehmet, Mehmet sits down with Jason Remillard, Founder of Data443. Jason brings more than 30 years of cybersecurity, data security, infrastructure, and enterprise risk experience. The conversation focuses on the gap between AI adoption speed and the security operating models still built for slower systems.The episode reframes AI security as an execution and visibility problem, not only a model risk problem. Jason argues that security teams lose when they only block users, rely on slow approval workflows, or assume old SOC models can handle AI agents, MCPs, SaaS sprawl, and machine-speed data movement.If you are leading cybersecurity, enterprise IT, AI adoption, or digital infrastructure strategy, this conversation gives you a practical lens for where the real exposure is forming.About the GuestJason Remillard is the Founder of Data443, a data security company focused on securing data across systems, users, and enterprise workflows. His career spans more than 30 years, from early systems operations and ISP infrastructure to enterprise security and regulated environments.Jason has worked across cybersecurity, data protection, ransomware recovery, threat intelligence, DLP, attack surface management, and AI-related security challenges. His perspective is grounded in the operational reality of how users, security teams, and business units behave when controls create friction.LinkedIn: https://www.linkedin.com/in/jremillard/Website: https://data443.com/Key TakeawaysAI agents expand the attack surface faster than security teams can govern with manual workflows.End users bypass controls when security becomes a blocker to legitimate business execution.DLP cannot solve data loss when users can photograph, move, and re-enter information elsewhere.Security teams need to enable safer decisions, not only enforce binary allow-or-deny rules.Inference can reduce AI security costs when models are trained for specific enterprise use cases.Threat intelligence must track agents, connectors, APIs, and machine actions as risk-bearing actors.Post-quantum risk matters because encrypted data can be stored now and decrypted later.Cyber resilience starts with assuming breach, not assuming the perimeter still holds.What You Will LearnThe reason cultural failure still sits behind many enterprise security failures.How AI agents change visibility across SaaS, APIs, Shadow IT, and enterprise data flows.Why traditional exception management breaks when AI decisions happen in milliseconds.How inference can help security teams operate faster without relying only on GPUs.What MCP and agent-to-agent workflows mean for API governance and connector risk.Why post-quantum security is already relevant for long-lived sensitive data.The practical starting point for cyber resilience when attacks cannot be fully prevented.Episode Highlights00:00 — Jason Remillard frames three decades in cybersecurity04:30 — Security failure starts with not-my-job thinking08:30 — DLP breaks when users bypass friction12:00 — AI agents change enterprise visibility13:30 — Approval workflows cannot match AI speed17:30 — Non-human actors create identity risk20:30 — AI defense depends on trained inference27:00 — Multimodal input changes user behavior28:30 — MCP turns APIs into hidden risk31:00 — Attackers gain the same AI velocity35:00 — Quantum risk makes stored data vulnerable39:00 — Resilience starts by assuming breachListen NowAvailable on all major podcast platforms and YouTube.Connect with the ShowFollow The CTO Show with Mehmet for more conversations at the intersection of technology, startups, and venture capital.

Episode metadata supplied by the publisher feed · Published May 18, 2026

Embed this episode

NOW PLAYING

#599 AI Agents Are the New Attack Surface. Security Teams Are Already Behind | Jason Remillard

0:00 45:43

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The CTO Show with Mehmet Gonullu?

This episode is 45 minutes long.

When was this The CTO Show with Mehmet Gonullu episode published?

This episode was published on May 18, 2026.

Can I download this The CTO Show with Mehmet Gonullu episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!