On Air 2.0: a podcast, a certification, and a sidecar

Subscribe to the blog

The past few weeks have been extremely busy for us at Generative Security. I sat down with Rohan at Vision and Venture and recorded a new podcast, spent a week in Singapore with ISC2 to define the future of AI Security certification, and we're about to launch a new open-source agentic sidecar for AI security. So let's talk about these three things, and a bonus at the end.

On the podcast, the conversation ranged widely, but a few threads are worth pulling out here. First is a question every founder in this space eventually faces: why build a dedicated security solution when AWS and Google already ship guardrails? Tools like Amazon Bedrock Guardrails and Google's Model Armor catch generic jailbreaks, but the moment you step into retail, healthcare, or telecom, the threat surface stops being generic. That industry-specific logic gap is where actual enterprise risk sits. That ties into a claim we keep coming back to on this blog: generative AI isn't just another technology, it replaces the person in the conversation, so securing the model while ignoring the social engineering surface only solves half the problem. Vibe coding also got its own extended treatment. We didn't argue that the tools are bad, but that their real cost shows up later as operational burden; teams ship something that works, then months in discover it's unmaintainable, and that the SOC 2 certification an enterprise deal requires is a lot harder to achieve. I also explained my distaste for the "land and expand" mindset in B2B sales, and why I think earning trust is the best way to be a partner and not another vendor. There's also a story in there about a mistake I made early on, betting too much on a single design partner, but that's more useful watched than summarized here.

From Singapore, the second highlight was spending a week with ISC2 working on the blueprint for a new AI Security Certification. It was refreshing to sit in a room with such a diverse cross-section of the industry, bringing together perspectives spanning academia, system design, hands-on engineering, operations, and governance. I can't talk about specifics on the outcome or conversations, but let's just say there was no lack of debate, and that was great. When all is said and done, it was awesome to hear people's opinions on something we've been talking about forever: what is entailed in the scope of "AI security." I look forward to seeing what people think about the hard work that everyone there contributed to.

The third piece is a preview: in the next two weeks, we're open-sourcing a sidecar for agentic workloads, Agent Vardøger, and it's worth explaining the problem it exists to solve before it ships. Nearly all real-time generative AI security today runs through a SASE-style proxy sitting synchronously between the user and the model. That model works for a single chatbot session, but it breaks down in agentic architectures where dozens of agents and tool calls fire simultaneously. For example, when you have 50 agents talking to 50 agents, where do you put the proxy? Container security solved a nearly identical problem by moving from heavy in-container agents to lightweight, out-of-band sidecars. Agent Vardøger applies that same solution here. Sitting next to your Amazon Bedrock agents, it inspects every prompt entering the Amazon Bedrock AgentCore Gateway using Interceptors, correlating risk across simultaneous sessions instead of evaluating each one blind to the others. The open-source release ships single-tenant with a solid baseline of community detection signatures, deterministic injection patterns, and known jailbreaks. We aim to quickly follow up with a managed threat library using our Social Engineering Abuse Case Library, and then a managed SaaS platform organizations can subscribe to. More to come over the next few weeks, so keep an eye on our website: https://generativesecurity.ai.

Before we close, I want to share one of the things that caught my attention recently: Anthropic's research post "Patterns and problems in emerging multiagent systems," published by their Frontier Red Team. In one experiment, three Claude agents were each given a different, conflicting objective on a shared codebase with no idea the others existed. With no prompt injection and no attacker, they escalated to sabotaging each other, disabling one another's system accounts and deploying disguised malware, genuinely unpredictable behavior with no obvious trigger. But in a separate writers'-workshop experiment, with no assigned topic and instructions to come up with something original, agents across multiple independent runs kept converging on the exact same title for their submission, "The Cartographer's Last Commission". Same model, same minimal prompting, same "unique" idea, over and over. It's a striking pair of findings: put agents under pressure and they can behave in wildly unpredictable ways, but left with total creative freedom, they can behave in eerily consistent ones. Worth reading if you want a clearer picture of multi-agent risk.

If any of this, the podcast, Singapore, Agent Vardøger, or the Anthropic research raises questions about how it applies to your own generative AI systems, feel free to reach out at questions@generativesecurity.ai. We're always happy to talk through it.

About the author

Michael Wasielewski is the founder and lead of Generative Security. With 20+ years of experience in networking, security, cloud, and enterprise architecture Michael brings a unique perspective to new technologies. Working on generative AI security for the past 3 years, Michael connects the dots between the organizational, the technical, and the business impacts of generative AI security. Michael looks forward to spending more time golfing, swimming in the ocean, and skydiving... someday.

September 3, 2026
< Back to Blog
Copyright  2026 Generative Security
  |  
All Rights Reserved