Categories
Artificial Intelligence Reading Material Security

Security leaders we surveyed feel pressure to secure their AI, and almost none of them feel ready

Here’s a fun little contradiction to start your week with: NetFoundry asked 200 CISOs and CTOs whether they feel pressure to secure the AI they’re deploying. Unsurprisingly, and to my considerable relief, every single one said “yes”.

We then asked how confident they are that their current tools can actually handle the new risks, and 15% said “very.” 15% is very slightly less that the odds for rolling six on a 1d6. More specifically, among the CISOs, whose entire job is to be the professional pessimist in the room, that figure dropped to 10%.

That’s the current situation: Universal pressure, near-universal doubt.

If you just want to get to the report, it’s here. But if you’d like to know more, read on…

Disclaimer and where the survey comes from

I work at NetFoundry as a developer advocate, and NetFoundry commissioned this report. So yes, this is a vendor survey, and you’re correct to raise an eyebrow. (I’d be worried if you didn’t).

In our defense, we did the thing you’re supposed to do: the survey itself was run by an independent research firm (Global Surveyz), the respondents were 200 US-based security and technology leaders at companies with 1,000+ employees, and it was fielded this past May and June.

I’m going to try and separate what the survey found from what I think it means. The first category is data. The second category is me, a guy on the internet, having opinions, which won’t always be the same as NetFoundry’s Marketign department (it happens). I’ll flag which is which.

The number that reframed the whole thing for me

Of everything in here, this is the one I keep coming back to:

Security leaders are nearly 10x more likely to worry about securing machine-to-machine workloads than human access to applications.

Specifically: 69% said machine workloads (service-to-service, API-to-API, agent-to-whatever) are where they’re least confident today. Just 7% said human user access. The remaining 24% said “both equally,” which I read as “please don’t make me pick.”

That tracks perfectly, and it’s a compliment to the last decade of security work. Think about what we spent the 2020s doing. COVID sent everyone home, remote access became the whole ballgame, and the industry poured an enormous amount of money and brainpower into VPNs,  Zero Trust access, and all sorts of security measures for a world that was suddenly more online that ever. It worked, and hman access to applications is, comparatively, a solved-ish problem. We got good at authenticating people. (I should know; it was during that time that I worked at Auth0!)

The issue of identity

The catch is that all of that machinery is built on one quiet assumption: that the thing connecting to your app is a human being with a unique identity. You authenticate the person, then you grant the access.

My late former coworker, Vittorio Bertocci, has forgotten more about identity than I will ever learn, and he was starting to look very deeply into identity in the age of AI.

Agents and models don’t work like that. They don’t have identities the way humans do. So the tooling we built for the last problem doesn’t cleanly transfer to this one, and the volume is going the wrong direction, fast. Machine traffic is now growing several times faster than human traffic year over year. We got really good at guarding a door that fewer and fewer of the visitors are actually using.

A few more stats worth your attention:

  • 100% agree their attack surface is growing. Not a plurality. Not a strong majority. Everyone. The average projected increase was 14% over the next 12 months, and that figure only counts AI deployments already underway or planned. 14% is probably the minimum.
  • 93% are concerned about the new risks AI introduces, but only 15% are highly confident their current tools can handle them. That’s the gap I opened with. When the level of concern and the level of confidence are that far apart, something structural is going on.
  • 99% admit they don’t have full visibility into their own AI deployments. That remaining 1%, which would have to be one respondent? I would like to buy that person a coffee (or beer! or bourbon!) and ask them a lot of questions.
  • 90% are worried about shadow AI, the unsanctioned tools employees adopt on their own because the approved options don’t cut it. This is not a technology problem, it’s a human-nature problem. I will neither confirm nor deny my own contributions to the shadow AI at previous organizations, but in my defense, I was getting things done! When a tool is genuinely useful, people use it, memo or no memo.
  • Only 8% call their current identity systems “very sufficient” for non-human workloads. 85% are now actively evaluating or exploring new approaches. That second number is the tell. When five out of six organizations are shopping for a new approach at the same time, that’s teh surest indicator that the industry is collectively coming to the realization that the existing tools weren’t built for this.
  • Oh, and it’s slow. 55% cited risk and compliance review as a top contributor to delays in the network changes AI deployments need, and those changes add an average of 8 days from request to implementation. And that’s now, while AI-specific scrutiny is still warming up.

My read (this part is me, not the data)

In this section, I’m switching from reporting to speculating.

I think almost every number above traces back to one root cause: machines don’t have real identities. They have internal names so that developers and devops people can talk about them, but when it comes to having reasonably canonical identities like we humans do (full name, usernames, an email address, a government-issued unique ID number), we haven’t really created these for machines.

In the absence of machine identities, we have workarounds. On the less secure end, we have IP addresses; on the (relatively) more secure end, there are shared secrets, API keys, long-lived service-account credentials. As with most workarounds, they quietly rot. The credentials we give machines tend to carry more permission than they need. They rarely get rotated. After a while nobody’s entirely sure which agent a given key even belongs to, or why it exists.

Once you’re in that world, everything downstream gets harder. Visibility is hard because you can’t tell one agent’s actions from another’s. Access control is hard because a secret isn’t an identity, it’s some piece of data that happens to belong to a robot (and all too easily duplicated). Auditing is hard for both of those reasons at once. The identity gap is the root problem of most of the other security problems in the AI age.

NetFoundry — who are made of some very smart people, a few of whom are literal greybeards! — obviously has opinions about how to close that gap, and the report gets into them. That’s the vendor part, and you can take it or leave it.

In case you saw the em-dashes in the paragraph above and thought “Aha! AI!’, I assure you that I typed them in myself, because this is my relationship with AI:

Entering em-dashes is dirt simple on macOS: option-shift-minus. On Windows it’s a little more work: alt+0151. On Linux: control-shift-U, then release and type 2014, then return/enter.

Let me have just a couple of em-dashes in my article. Please.

But strip the logo off and the underlying observation stands on its own: we spent a decade giving humans strong identities and largely ignored the machines, and now the machines are the fastest-growing thing on the network. That bill was always going to come due. It’s just arriving faster than most people planned for.

The stat I want ask you about

That 14% attack-surface increase feels low to me. If you’re actually running agents in production right now, watching them spawn sub-agents and reach across cloud boundaries and pick up new tool integrations every sprint, does 14% over a year match what you’re seeing, or is it wildly optimistic?

(That’s a genuine question, not a rhetorical one. I’d rather hear it from people living it than trust my own gut.)

Read the full 2026 State of Secure AI Access report!

Download it here. (You have to provide a little info to get it.)

Categories
Developer Relations Hardware Reading Material What I’m Up To

Stuff that arrived over the weekend

A few goodies I’d ordered all arrived nearly at once on Saturday, and I thought I’d share them here.

Business card

A snapshot of Joey de Villa’s desk, showing two boxes of his business cards. One business card is raised so it is readable. Beside the boxes are a mechanical keyboard and a steel mug with a stciker on it that reads “Punch today in the face”.
New business cards! Tap to view at full size.

It’s been a while since I’ve had an honest-to-goodness business card, but since NetFoundry makes them available to employees and since a good chunk of my job is about making myself available to the public, I placed an order and received two boxes containing a few hundred cards in total.

These days, I tend to simply display my LinkedIn QR code on my phone when exchanging contact details with people, but I still like the old-school feel of giving someone a card (which just so happens to contain my LinkedIn QR code).

Book: Developer Relations Activity Patterns

Joey de Villa, smiling and holding up a paperback copy of the book Developer Relations Activity Patterns.
It arrived! Tap to view at full size.

Another thing that arrived on Saturday was my copy of Developer Relations Activity Patterns, written by Ted Neward, Scott T. McAllister, David Neal, and Chris Woodruff, and published by Apress, which is now an imprint of Springer Nature.

I know a couple of the authors. Way back in 2016, Ted reached out to me after I’d landed a developer relations job with SMARTRAC and wanted to see how they did developer relations. I also know David from my time at Auth0, because shortly after I joined, Auth0 merged with Okta, where David worked. In fact, to prepare for my technical interview with Auth0, my primary resource was David’s 2019 article in the Okta Developer blog, An Illustrated Guide to OAuth and OpenID Connect.

Since I’m now pretty much Supreme Developer Advocate at NetFoundry (I’m the only one; it’s a small, scrappy company that punches above its weight class), I figured the book would be useful.

Also, I have a policy of buying books written by people I know, as illustrated in the meme below:

Meme with title “When you tell someone about your book and they say ‘oh cool’ instead of buying it immediately.” Below the title is a cat wearing cool sunglasses and a gold chain necklace saying “That wasn’t very cash money of you”.
I try to be cash money all the time. Tap to view at full size.

You may have noticed that I bought the dead-tree edition instead of an electronic one. This also follows a rule of mine:

  1. If the content is ephemeral or likely to be outdated in a couple of years (or a couple of months, given the pace of change these days), get the electronic version.
  2. If the content is likely to be longer-lasting or seems timeless, get the paper version.

Also, it’s nice to get away from screens from time to time. I’ve carved out a little time each day to sit on the rocking chair on our front porch and read paper books, and  Developer Relations Activity Patterns will be one of them.

Teeny-weeny hard drive

Joey de Villa holding up his Lexar external drive side-by-side with his NetFoundry business card. Viewed from the top, they’re the same size.
Nice and compact! Tap to view at full size.

Between the RAMpocalypse brought about by AI data centers hogging all the storage chips and the war in Iran blocking off access to a large chunk of the world’s helium (it’s a key part of making high-end chips; see my earlier article for an explanation), SSD prices are climbing.

Fortunately, there was a very short-time deal for a two-pack of 2TB Lexar SL500 SSDs for about $400, so we placed an order so that Anitra and I could each have one. They arrived on Saturday, and they’re about the size of my business card!

Joey de Villa holding up his Lexar external drive side-by-side (and on its side) with his NetFoundry business card. The drive is quite thin!
Skinny! Tap to view at full size.
Categories
Artificial Intelligence Programming Reading Material

More notes

Because some people asked, and because I’m going to be busy for the next day (I’ll explain later), here are more shots from recently-added pages to my notebook. These are notes on RAG and LangChain, taken and condensed from a couple of books, a couple of online sources, and my own experimenting with code. Enjoy!

Categories
Artificial Intelligence Current Events Reading Material What I’m Up To

Where Cory Doctorow’s line, “When life give you SARS, you make sarsaparilla,” comes from

Lately, a lot of friends have been telling me that they were listening to an interview with Cory Doctorow about his latest book, Enshittification, and heard him attribute this quip to me:

“When life gives you SARS, you make *sarsaparilla*.”

The YouTube short above tells the story behind the quote (which also appears in this old blog post of mine), which also includes a tip on using AI to find specific moments or quotes in videos, and a “This DevRel for hire” pitch to hire an awesome developer advocate.

Categories
Artificial Intelligence Reading Material

Humble Bundle deals for aspiring AI developers!

Here’s what I consider to be a pretty good deal for the aspiring AI developer: for $18, Humble Bundle’s The A-Z of Machine Learning provides 19 video courses from Packt Publishing on all sorts of machine learning topics:

  1. Python – Complete Python, Django, Data Science and ML Guide

You may have had the expression pictured above when you saw that The A-Z of Machine Learning comes from Packt, of all places. Given their reputations for “shovelware” books, I’d be suspicious too, and I was even a technical reviewer for one of their books:

My new gig doing developer relations for HP’s ZGX Nano AI station will require me to create a lot of tutorials, so I purchased The A-Z of Machine Learning as well as the Humble Bundle below to get a better feel for the sorts of AI tutorials that are out there.

Having gone through a couple of the courses in The A-Z of Machine Learning and skimming the others, I can say that it’s not bad. I’d feel robbed if I paid full price for all 19 courses, but at 18 bucks — less than a buck each — it’s a pretty good deal, and an inexpensive way for the beginning AI/ML developer to get started.

(While I generally only buy Packt’s stuff when it’s on Humble Bundle, there are exceptions. The iOS books by Tampa’s own Craig Clayton are quite good, and I paid full price for them.)

At the time of writing, The A-Z of Machine Learning will be available for 14 more days.

Also worth checking out is the Create the Future Now bundle, a set of 21 books and online courses from Manning’s Early Access Program (or MEAP for short) for $25:

This one’s a little pricier that the Packt offering, but it’s from Manning, which has a stronger reputation than Packt’s, and goes beyond just Python and AI. If you’re looking for a mix of books and online lessons and want to be a little more well-rounded, this Humble Bundle is for you!

I also purchased this bundle. At the time of writing, the Create the Future Now bundle will be also be available for 14 more days.

 

Categories
Artificial Intelligence Reading Material

Get 18 O’Reilly books on AI and machine learning for just $25 at Humble Bundle!

Would you like ALL THE BOOKS pictured below for just $25?

You can get all 18 of these O’Reilly books on AI and machine learning for a mere $25 at Humble Bundle — but only for the next 13 days (at the time of writing)!

Find out more and get the deal here.

Categories
Deals Programming Reading Material

Humble Bundle’s great set of computer science books for $2 each!

For the next four days — until 2:00 p.m. EDT on Monday, March 24, 2025 — Humble Bundle’s Computer Science the Fun Way bundle will be available, giving you 18 books for as little at $36, which puts the cost of each book at a mere two bucks!

All the books come from No Starch Press, a publisher of some great books, and the folks behind my current favorite books for my Python courses.

Check out their page, and if you want 18 useful computer science books for as little as two bucks, get them now!