AI is rapidly changing not only how employees work, but where work happens and who—or what—is doing it. AI that once lived primarily inside the browser is moving onto desktops, into development environments and across a growing ecosystem of applications, plugins, agents and machine-to-machine connections. At the same time, vibe coding is making it possible for employees with little or no development experience to create applications in minutes, often without the security, access controls and governance traditionally built into enterprise software.
In a recent interview with Tech Channels, Michael Leland, Field CTO at Island, which just hit the $6.4 billion valuation mark this week, says agentic AI has raised the stakes further. Leland describes agents as a new class of “virtual knowledge worker”—one that may be entrusted with enterprise data and systems without going through anything resembling the onboarding, compliance training and acceptable-use requirements applied to human employees. Organizations therefore face a fundamental question: How do they extend identity, data protection, least privilege, visibility and governance to AI systems that increasingly act on a user's behalf?
Leland explains how the enterprise security model is evolving in response. He also discusses the risks created by vibe-coded applications and autonomous agents, the importance of controlling AI close to where work actually occurs, the growing need for AI inventory and telemetry, the shift from token maximization to cost accountability, and why AI is drawing CIOs and CFOs deeper into security and technology decisions. Looking ahead to post-quantum security, Leland expects many Q Days on the horizon. And he notes the growing challenge of protecting enterprise data in an environment where risk increasingly extends beyond malicious attacks to include misconfiguration and unintended actions.
Q. How has the enterprise AI environment changed over the past several months?
A. In the last nine months, AI has dragged us in the opposite direction. The natural habitat for AI used to be the browser. Now we've got to contend with tools like Quad Code, Gemini CLI, Cursor, various AI plugins to IDEs. So, we needed to expand our footprint outside the browser.
Q. How is vibe coding changing who can build enterprise applications?
A. The other thing that's happened in the last several months is this age of vibe coding. You can now, without even being a developer, go to a tool like Replit or Lovable, and if you can describe an application in natural language, a couple minutes later, you have a fully reactive application built.
Q. What security risks arise when employees can build applications without going through IT?
A. It’s very cool. Except, you now have the responsibility of hosting that application somewhere, which used to be the job of IT to vet and provide that service. That application that was just built by some vibe-coding tool has no understanding of your role-based access control, doesn't understand your authentication principles, your business context, or your data governance policy.
Q. How can organizations prevent AI-built applications from giving users capabilities they shouldn't have?
A. If you asked Replit to build an application that scrapes all of the customer data out of Salesforce and publish it to PasteBin, it would honor that request and it would build that app. But if the user who's running that application doesn't have the ability himself to move data from Salesforce to PasteBin, neither will the app that's running on their behalf.
Q. How should enterprises think about AI agents?
A. Agentic has also become the big, the big buzzword. An agent today is your new virtual knowledge worker. We are ceding so much trust to these applications without understanding the implications.
Q. What's missing when organizations give agents the same kind of access they give employees?
A. You're deploying an agent that was never onboarded by human resources. It never went through compliance training. It didn't read your acceptable use policy.
Q. Is the risk of agents operating outside expected guardrails still theoretical?
A. What we've seen recently is it is more than willing to go off the guardrails and do things behind [the scenes]. And it has happened twice this week already (in incidents with Claude and OpenAI).
Topic 4: AI Is Expanding the Enterprise Control Plane
Q. Why is AI forcing organizations to rethink where security controls need to operate?
A. We're contending with that as well, because AI has so many footprints now. AI in the browser via a URL. AI in the browser via an extension. AI on the desktop. We had to expand our control plane into what we're now calling the enterprise agentic control plane.
Q. Where is the most effective place to enforce controls over AI use?
A. On the far left, as close to the user as you can get, is the safest and most effective way of providing both visibility and enforcement to what that user is doing or is allowed to do, because that's where work happens with AI.
Q. Why can traditional network-based inspection miss AI activity?
A. All of a sudden, there's a percentage of your traffic—the industry average is between 30 percent and 50 percent—that can no longer be inspected at the point of termination because there is no visibility into the traffic and clear text. If it's a user leveraging Claude code who's accessing data on my local file system, that is blind to the SASE vendor because that's never even hit the network yet.
Q. How has Island extended security beyond browser-based AI?
A. Island Desktop is a background service that lives outside the browser. It is at the kernel level, which means it has visibility to network activity, file system activity, process activity. It can be used to hook into tools like Quad Code and Cursor and Gemini. So now we can take that same data protection and zero trust network steering outside the browser only environment and extend that to thick apps as well.
Q. Why is giving an AI agent a user's actual access token risky and how does Island address that?
A. If you're giving the actual OAuth token from Salesforce to the agent, that's a risk. And if the token that's being issued is a read-write token, but I I want to build a policy that says you should only have a read-only token, our MCP broker is going to do things called token brokering, so that the MCP gateway has the only legitimate token to Salesforce, and then we issue a reduced privilege token to the agent. So, the agent never has the real token, and we can now enforce variable policies in that MCP gateway.
Q. What should organizations be measuring in their AI environments?
A. Otel (OpenTelemetry) allows us to hook at the cloud level into these frontier models and AI providers, and pull telemetry, token utilization, token cost per user per session per skill. It gives us performance metrics about how effective your agents are running and what their success and failure rates are, and it gives us AI adoption metrics.
Q. How significant can the gap be between sanctioned AI and actual AI use?
A. We had a customer who insisted there were only eight sanctioned AI tools across this environment. We did a one-week assessment. where we deployed the browser to about 15 users, and we deployed the extension to the other 8,500. We found 243 [AI tools].
Q. Where does an organization start with AI governance?
A. Visibility is your first step of governance. Understanding what your risk profile is all starts there.
Q. What needs to be included in a comprehensive AI inventory?
A. It’s all about auditing. We built the capability to inventory everything about AI, every AI application, every AI skill, every MCP server, every plugin to an IDE, and then we built a facility to risk score all of those.
Q. What kinds of risks should organizations evaluate at the AI skill level?
A. This skill has network access. This skill can read and write files. This skill has the potential for privilege escalation, and now you get to decide if that's a risk posture you're willing to accept.
Q. Does governance also require visibility into what agents are actually doing?
A. The other side of auditing is the interaction. We collect and store optionally every prompt, every response, every skill call, tool call, and tool response.
Q. Is the speed of AI creating challenges for narrowly focused security vendors?
A. If you've been here at Black Hat multiple years, you notice that half the vendors out there weren't here last year and half won't be here next year. They either have a too narrow scope, which means they're looking to get acquired by a vendor that needs to expand their footprint, or the technology changes so fast that their niche implementation is no longer relevant a year from now.
Q. What problems can arise when security platforms are assembled through acquisitions?
A. I've worked for portfolio vendors in the past. I was co-founder and CEO of Nitro Security before I sold my company to McAfee in 2011. I watched them try to force our tech into their existing tech stack. And they did a decent job in some areas, but the user experience always suffered. And when you assemble it through multiple development teams, you never have cohesivity.
Q. Why does fragmented security tooling create problems for security teams?
A. The biggest challenge is you've now got multiple agents, multiple policies, multiple control planes and multiple user consoles. When I was building a SIEM, our buzz phrase all along was “single pane of glass.” That never happened. I used to do a presentation that said the vendor community promised you a single pane of glass and what it delivered you was a single glass of pain.
Q. What does that fragmentation mean for SOC analysts?
A. The bane of a SOC analyst's existence is bouncing around between multiple consoles, multiple policies, and deploying across multiple control planes.
Q. How has the enterprise conversation about AI usage changed?
A. The spend. We've seen so many interesting things. We went from no one uses it to the concept of token maxing. Everyone should be using it so much.
Q. Are organizations reconsidering assumptions about AI replacing employees?
A. We went from people losing their job because they thought AI would take over to them hiring those people back because the AI is either not doing what it should, or they need somebody to manage that infrastructure.
Q. Why are AI cost metrics becoming more important?
A. Token maxing is gone, but the cost metrics are so much more relevant to customers now because they can't just throw it out there willy-nilly.
Q. Does the growth of AI spending resemble the earlier move to cloud computing?
A. We had the same problem with cloud migration. Everyone thought that giving up the brick-and-mortar data center and moving everything to cloud would save money. It didn't. It just moved the model from a CapEx to an OpEx model. But then costs exploded because people found it so easy to spin up instances. When you grant that control to anybody and everybody, you start seeing your cost explode.
Q. Who is becoming involved in AI and security technology decisions?
A. We have many stakeholders that will find value in our solution. Cybersecurity, of course, governance and compliance is in there. End user compute. Network infrastructure. All these teams now are looking at us saying that's great from a persona perspective. CISOs were the primary originally, and now CIOs and CFOs.
Q. How soon should organizations be thinking about the post-quantum threat?
A. I think there's going to be multiple Q days, by the way. The ultimate one is probably still out around 2030, but there's probably that some are going to hit us sooner. And the idea of harvest now, decrypt later, is a real thing.
Q. Where is sensitive data potentially at greater risk today?
A. We live in the world of post decryption. We're the browser, or we're the desktop, which means it's already been decrypted, and you're interacting with it in clear text. There's a bigger risk there than in the transport side of things because that's where the data is leaking today.
Q. Does AI-related data loss always require a malicious actor?
A. It’s no longer always an adversarial conversation. It's not always a malicious activity. It could be a misconfiguration. It could be a user who didn't realize that by clicking on that connect to Salesforce button—that I allowed to happen without authorization or approval process—that all of a sudden they're potentially creating a path of data exfiltration that was not intended.
Q. Are we likely to see a major AI-related data exposure event?
A. There will be one of those very soon announced. I guarantee you.
Q. What role are industry groups playing in maintaining public-private cybersecurity collaboration?
A. The ISACs are keeping that together privately, and when CISA gets its act together again, I think they come back into the fold. I hope that tribal knowledge and collaboration doesn't fall apart at the ISAC level.
AI's impact on the enterprise is extending well beyond the chatbot. It is moving into development environments, desktop applications, user-built software and autonomous agents that can access data and act on behalf of employees. That expansion challenges security models built around more predictable boundaries between users, applications and networks. As Leland puts it, an agent is becoming a “new virtual knowledge worker,” but one that never went through HR onboarding, compliance training or an acceptable-use process.
That makes visibility foundational. Organizations first need to know what AI applications, skills, agents, plugins and MCP servers are actually operating in their environments—an increasingly difficult task as sanctioned and unsanctioned AI proliferate. Leland’s example of an organization that believed it had eight sanctioned AI tools only to discover 243 illustrates the potential scale of that gap. From there, governance must extend into risk scoring, access, agent interactions and the actions AI systems are permitted to take.
The economics are changing as well. The early push to maximize AI use is giving way to greater scrutiny of token consumption, infrastructure requirements and business value. Leland compares the shift to the early cloud era: ease of adoption can be an advantage, but when everyone is given the ability to consume resources without sufficient controls, costs can quickly escalate. That helps explain why the AI conversation is expanding beyond CISOs to include CIOs, CFOs, governance teams and other enterprise stakeholders.
Ultimately, the challenge is broader than defending against malicious AI. Risk can emerge from an agent exceeding its intended role, a vibe-coded application operating without enterprise context, an overly privileged token, an employee connecting an application without realizing the implications, or simply an organization that does not know how much AI is already being used. In this environment, securing AI increasingly means extending familiar principles—least privilege, visibility, data governance, policy enforcement and accountability—to a new generation of applications and autonomous workers.
.png?width=1816&height=566&name=brandmark-design%20(83).png)