AI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop
ClearTech Research / Jo Peterson

Latest episode
62 episodes
- Your AI agent has one job: accomplish the objective.
It doesn’t care about your policies. It doesn’t worry about getting fired. And it may not stop when a human would.
Joanna Wiggum calls it a narcissist.
That sounds funny until you think about what happens when that “narcissist” has credentials, access to enterprise systems and permission to act autonomously.
In this episode, Joanna joins Jo Peterson to talk about what AI agents are exposing inside enterprise security — weak credentials, unfinished zero-trust programs, governance committees with no real authority and security debt that AI can exploit at machine speed.
Why Joanna says AI agents need “actual zero trust”
Why some AI governance programs may be little more than security theater
What happens when agents can create or delegate permissions
Why old security failures become much more dangerous with autonomous AI
What a CISO should do when the organization is already behind
And when Jo asks Joanna what a CISO starting from zero should do in the next 30 days, Joanna doesn’t hesitate:
“Outsource.”
Listen to the full conversation to hear why.
Short Summary
AI agents don’t care about your policies. Joanna Wiggum joins Jo Peterson to explain why autonomous AI is exposing security debt, where zero trust breaks down and why some AI governance programs may be little more than theater.
Links & Resources
Countervail: https://countervailintelligence.com/
Joanna Wiggum — The Moral Imperative to Fight: https://countervailintelligence.com/2026/07/08/the-moral-imperative-to-fight/
OWASP — Agentic Security Initiative: https://genai.owasp.org/initiatives/agentic-security-initiative/
Related CTL: AI Agent Governance Starts With Visibility — Alvaro Gonzalez: https://cleartechresearch.com/ai-agent-governance-alvaro-gonzalez/
ClearTech Loop LinkedIn Newsletter: https://www.linkedin.com/newsletters/7346174860760416256/
ClearTech Research on YouTube: https://www.youtube.com/@ClearTechResearch
🎧 Listen: In Buzzsprout Player
▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos
📰 Subscribe to the Newsletter:
https://www.linkedin.com/newsletters/7346174860760416256/ - Guest
Benny Czarny
CEO, Founder & Chairman of the Board
OPSWAT
Host
Jo Peterson
CIO, Clarify360
Chief Analyst, ClearTech Research
AI agents have credentials. They access enterprise data. They make decisions. And increasingly, they can act without waiting for a human.
So who actually owns the risk?
Jo Peterson sits down with Benny Czarny, CEO, Founder & Chairman of the Board at OPSWAT, to talk about what AI agent governance needs to look like as autonomous AI moves deeper into the enterprise.
They discuss why every AI agent needs its own identity and a human owner, how least privilege should apply to agents and sub-agents, and why understanding what data an agent can access may be just as important as securing the model itself.
Benny also shares where CISOs should start if they don’t yet have an AI agent inventory or governance framework in place.
In This Episode
Why every AI agent needs a human owner
Least privilege for AI agents and sub-agents
The growing risk around AI data access
Why AI governance needs real authority
The first step CISOs should take in the next 30 days
Chapter Markers
00:00 Meet Benny Czarny of OPSWAT
01:40 Protecting critical infrastructure
02:05 Least privilege for AI agents
03:58 Permanent credentials and autonomous agents
05:15 Does AI governance actually work?
07:23 Where CISOs should start
09:29 Protecting the AI data lake
12:34 What AI can learn from OT security
13:12 Cloud, on-prem and air-gapped AI
13:54 OPSWAT’s own AI journey
Resource Links
OPSWAT https://www.opswat.com/
OPSWAT Academy https://opswatacademy.com/
Cybersecurity Upside Down — Benny Czarny https://www.amazon.com/dp/B0GH8SZXJ9
ClearTech Research https://cleartechresearch.com/
ClearTech Loop Newsletter https://www.linkedin.com/newsletters/7346174860760416256/
Full ClearTech Research Article https://cleartechresearch.com/ai-agent-governance-benny-czarny/
🎧 Listen: In Buzzsprout Player
▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos
📰 Subscribe to the Newsletter:
https://www.linkedin.com/newsletters/7346174860760416256/ - AI agents can hold credentials, access sensitive data, make decisions and even create other identities. But many organizations still cannot answer a basic question: what is actually running in the environment?
In this episode of ClearTech Loop, Jo Peterson sits down with Alvaro Gonzalez, SVP of Product and Go-to-Market at Assured Data Protection, to talk about what AI governance looks like when identity and access are changing at machine speed.
Alvaro explains why organizations should start with three things: inventory, observability and remediation. They also discuss whether AI governance committees are actually governing or merely documenting, why CISOs should inventory agents before building more policy, and how Alvaro’s idea of “controlled aggression” can help enterprises experiment with AI without losing the ability to recover when something goes wrong.
You cannot govern what you cannot see.
Listen to Learn
Why AI agent governance should start with inventory
What least privilege looks like when identities can create other identities
Why observability matters alongside access control
Why remediation belongs in the AI identity conversation
Whether AI governance committees are really changing behavior
What Alvaro means by “librarians and warriors”
How “controlled aggression” can help organizations move faster without losing control
Featured Soundbite
“You cannot govern what you cannot see.”
— Alvaro Gonzalez
Featured Guest
Alvaro Gonzalez
SVP of Product and Go-to-Market
Assured Data Protection
Alvaro leads product, alliance, marketing and go-to-market functions at Assured Data Protection, with a focus on data protection, cyber resilience and the systems that support field and channel execution.
Host
Jo Peterson
CIO, Clarify360
Chief Analyst, ClearTech Research
Episode Links
Full episode webpage:
https://cleartechresearch.com/ai-agent-governance-alvaro-gonzalez/
Subscribe to ClearTech Loop:
https://www.linkedin.com/newsletters/7346174860760416256/
Watch on YouTube:
https://www.youtube.com/@ClearTechResearch
Additional Resources
Assured Data Protection: 5 Ways You Can Improve Your Cyber Recovery Plan
https://assured-dp.com/guides/5-ways-you-can-improve-your-cyber-recovery-plan-with-assured-data-protection/
NIST AI Risk Management Framework
https://www.nist.gov/itl/ai-risk-management-framework
Model Context Protocol — Security Best Practices
https://modelcontextprotocol.io/specification/draft/basic/security_best_practices
Previous ClearTech Loop: AI Agents Shouldn’t Be Trusted by Default with Elliott Mattice
https://cleartechresearch.com/ai-governance-trust-elliott-mattice/
🎧 Listen: In Buzzsprout Player
▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos
📰 Subscribe to the Newsletter:
https://www.linkedin.com/newsletters/7346174860760416256/ - The conversation around AI is shifting from what agents can do to how enterprises actually govern and secure them.
In this episode of ClearTech Loop, Jo Peterson sits down with cybersecurity professional Marcus Cylar to talk about least-privilege access for AI agents, shadow AI, security awareness and what CISOs should prioritize as agentic AI becomes part of the enterprise.
Marcus challenges the idea that AI automatically requires an entirely new security playbook. His argument: before organizations rush toward new controls and platforms, they need to make sure the cybersecurity fundamentals are actually working.
The conversation covers why least privilege, role-based access, system inventory and clear ownership still matter; why shadow AI can reveal unmet employee needs; and why creating a culture where employees can honestly disclose the tools they are using is critical to effective governance.
For CISOs starting from zero, Marcus offers a practical first step: know what you have.
Before you can govern AI agents, you need visibility into the systems, permissions, ownership and AI tools already operating inside your organization.
In this episode:
Why AI agents do not eliminate traditional cybersecurity fundamentals
Least-privilege access in an agentic environment
Why security awareness matters even more with AI
Shadow AI and the “Department of No”
The importance of system and AI inventory
What CISOs should prioritize in the next 30 days
Why trust and transparency are part of AI governance
Featured Guest:
Marcus Cylar, DMin
Cybersecurity professional focused on GRC, security culture, awareness training and program development.
Hosted by:
Jo Peterson
CIO, Clarify360 | Chief Analyst, ClearTech Research
Episode Quote:
“That path starts with a passionate return to the fundamentals of cybersecurity.” — Marcus Cylar
🎧 Listen: In Buzzsprout Player
▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos
📰 Subscribe to the Newsletter:
https://www.linkedin.com/newsletters/7346174860760416256/ - What if an AI agent had to earn—and keep—its access based on how it behaved?
In this episode of ClearTech Loop, Jo Peterson sits down with Elliott Mattice, founder of Exprima, to examine trust as the missing operating layer between AI security and AI governance.
Traditional controls can define an agent’s identity and permissions. Governance frameworks can establish policies and accountability. Elliott argues that organizations still need something in the middle: continuous behavioral trust that can raise, lower or revoke an agent’s access based on what it actually does.
Jo and Elliott discuss why accountability must still land with a human, how organizations can balance useful autonomy against unrestrained risk and why an MCP server could function as an enforcement point—not merely a bridge to enterprise tools and data.
The agent does not need to feel guilty when it crosses a boundary. The systems around it need the authority to say no.
What We Cover
Why policies and technical guardrails are not enough to operationalize AI governance
How behavioral trust could be continuously measured and tied to access
Why human accountability remains necessary when an agent takes an unauthorized action
How MCP servers could evaluate identity, permissions and current trust before granting access
Why autonomy is both the value of an AI agent and the source of its risk
What an agent may need to do to rebuild trust after crossing a boundary
Featured Soundbite
“We can give AI enough room to be independent, to be autonomous, as long as we hold it accountable for its outputs.”
— Elliott Mattice
Guest
Elliott Mattice is the founder of Exprima, an advisory and consulting firm focused on cybersecurity compliance, federal procurement risk and decision realism. He has more than 25 years of experience across federal IT operations, cybersecurity, compliance and regulated environments.
Guest website: https://elliottmattice.work/
Host
Jo Peterson is the CIO of Clarify360 and Chief Analyst at ClearTech Research.
Full episode webpage: https://cleartechresearch.com/cleartech-loop-elliot-mattice-on-ai-governance-missing-trust-layer/
Subscribe to ClearTech Loop: https://www.linkedin.com/newsletters/7346174860760416256/
Watch on YouTube: https://www.youtube.com/@ClearTechResearch
Topics
AI governance, agentic AI, behavioral trust, AI agent accountability, MCP security, non-human identity, AI access control, defense in depth, AI risk management
Tags / Keywords
AI governance; agentic AI security; behavioral trust; AI agents; MCP servers; AI accountability; non-human identity; cybersecurity governance; autonomous agents; ClearTech Loop; Elliott Mattice; Jo Peterson
🎧 Listen: In Buzzsprout Player
▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos
📰 Subscribe to the Newsletter:
https://www.linkedin.com/newsletters/7346174860760416256/
More Business podcasts
Trending Business podcasts
About AI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop
Season 2 of ClearTech Loop is built around three questions: How is AI changing the way organizations think about risk? What does stronger cybersecurity leadership look like right now? How should leaders rethink cloud strategy as business and technology keep shifting?Hosted by Jo Peterson, Chief Analyst at ClearTech Research, ClearTech Loop is a fast, focused podcast covering AI, cybersecurity, and cloud risk through a business leadership lens. Each 10-15 minute episode explores the issues shaping modern technology strategy and the decisions leaders cannot afford to ignore.From governance and resilience to infrastructure change and emerging risk, ClearTech Loop helps leaders make sense of what is shifting, what matters most, and what comes next.
Podcast websiteListen to AI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop, Honest Money and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


AI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop
Scan code,
download the app,
start listening.
download the app,
start listening.


















