The Hidden Cost of BlackBox AI: Bridging Cloud and Code Security

The Hidden Cost of BlackBox AI: Bridging Cloud and Code Security

🎙 Cloud Security Podcast 👥 39K 📅 July 9, 2026 ⏱ 42 min 👁 9K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

reachabilityexploitabilityfalse positivesAI-native securitymodel optimization

Summary

In this episode of the Cloud Security Podcast, host Ashish Rajan interviews Harry Wetherald, CEO and co-founder of Maze, a series A security startup focused on building AI agents for security. The conversation centers on the application of AI to application security (AppSec) and cloud security, addressing key concepts such as vulnerability reachability versus exploitability. Harry explains that reachability indicates whether code is active or an asset is network-accessible, while exploitability considers the full context needed for an attacker to trigger a vulnerability. They discuss the build vs. buy dilemma for AI security tools, noting that while building with LLMs offers flexibility, it requires significant investment in validation, monitoring, and cost optimization to achieve reliability. Harry highlights the historical problem of false positives in AppSec, where traditional SCA/SAST tools flag nine out of ten alerts incorrectly, and contrasts this with unoptimized AI products that may be more accurate but inconsistent. The episode also covers the convergence of AppSec and cloud security teams, facilitated by AI acting as a translator between domains. Harry advises on red flags when evaluating AI vendors, particularly the danger of ‘black box’ products that lack transparency. He emphasizes the importance of model optimization to reduce costs by up to 100x, and the need for a ‘security brain’ to orchestrate investigations across code and cloud. The episode concludes with the launch of Maze Code, a tool for deep cloud and code investigation.

235 words

Critical Evaluation

Value of the Information & Strength of the Argument

The episode provides valuable insights into the practical application of AI in security, particularly the distinction between reachability and exploitability, which is often misunderstood. The argumentation is coherent and grounded in the speaker’s experience, with concrete examples such as the cost extrapolation of $4 million per week and the false positive rates of traditional tools. However, the discussion is largely anecdotal and lacks empirical data or case studies to substantiate claims. The speaker’s perspective as a vendor introduces potential bias, and the argumentation would benefit from more balanced viewpoints.

98 words

Title / Content Match

The title accurately reflects the core themes of hidden costs of AI and bridging cloud and code security, though it emphasizes 'BlackBox AI' which is only one of several topics discussed.

Quality & Reliability

7/10

The episode features an expert interview with the CEO of a security startup, providing practical insights and specific examples. However, it is largely opinion-based with limited verifiable data or references, and the sponsor relationship may introduce bias.

Chapters

Cited Sources

Concurring Sources

  • OWASP Top 10 — Provides a standard for web application security, relevant to AppSec discussions.
  • MITRE ATT&CK — Framework for understanding attacker behavior, relevant to exploitability.

Contribution & Novelties

The episode offers a nuanced perspective on the application of AI to security, particularly the distinction between reachability and exploitability, and the practical challenges of building AI-native security tools. It provides actionable advice for security leaders on evaluating AI vendors and optimizing costs. The discussion on the convergence of AppSec and cloud security teams is forward-looking.

Pour aller plus loin :

93 words

Radar Profile

The radar profile shows balanced scores across information quantity, quality, technical level, and reliability, with reliability slightly lower due to the opinion-based nature and lack of citations. The episode is informative and technically sound but relies on anecdotal evidence.

Reliability 6/10

💬 No comments were provided for analysis.