The Future of AI Security is Scaffolding, Agents & The Browser

The Future of AI Security is Scaffolding, Agents & The Browser

🎙 AI Security Podcast 👥 20K 📅 September 9, 2025 ⏱ 84 min 👁 9K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

prompt injectionscaffoldingagentsbrowserincident response

Summary

In this episode of the AI Security Podcast, hosts and guests Jason Haddix and Daniel Miessler discuss the current state of AI security in 2025. They emphasize that the focus has shifted from the model itself to the surrounding ecosystem, including scaffolding, agents, and tools like MCP. Prompt injection remains an unsolved and fundamental problem, with new bypass techniques like Bjection emerging. The conversation covers the challenges of incident response and logging, especially when privacy regulations restrict observability. They also touch on data poisoning, which they see as less prevalent in practice, and the potential of autonomous AI in hacking, referencing the DARPA AI Cyber Challenge. The discussion highlights the importance of threat modeling and understanding the architecture of AI systems. Finally, they explore the race for AI to control the browser as the next frontier, and the implications of using AI to generate content.

145 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information is high, as it provides practical insights from experienced offensive security professionals. The argumentation is solid, based on real-world observations and specific examples. The speakers do not rely on hype but offer a realistic assessment of current capabilities and challenges. They effectively argue that the security of AI systems depends more on the surrounding infrastructure than on the model itself, and they stress the importance of threat modeling and understanding the attack surface.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate; the discussion is expert opinion rather than peer-reviewed research. The sources mentioned are primarily anecdotal, such as the DARPA AI Cyber Challenge and specific tools like MCP. The title accurately reflects the content, focusing on scaffolding, agents, and the browser. The podcast’s own website and newsletter are mentioned, but no external citations are provided. The lack of formal references limits the ability to verify claims independently.

164 words

Title / Content Match

The title accurately reflects the main themes discussed: the importance of scaffolding, agents, and the browser in AI security.

Quality & Reliability

8/10

The discussion features two recognized offensive security experts with extensive practical experience. They provide concrete examples and reference real-world incidents, but the content is largely anecdotal and opinion-based, lacking formal citations or peer-reviewed sources.

Chapters

Cited Sources

Concurring Sources

  • OWASP Top 10 for LLM Applications — Provides a list of common vulnerabilities in LLM applications, including prompt injection and data poisoning.
  • MITRE ATLAS — Adversarial Threat Landscape for Artificial-Intelligence Systems, a framework for AI security threats.

Dissenting Sources

  • Some researchers argue that prompt injection can be mitigated with better model training — The speakers argue that prompt injection is unsolvable, but some academic work suggests that future models may be more robust.

Contribution & Novelties

The episode provides a current, practitioner-driven perspective on AI security, highlighting the shift from model-centric to ecosystem-centric attacks. It offers unique insights into the challenges of incident response and logging in AI systems, especially with privacy constraints. The discussion on the role of scaffolding and agents in both attack and defense is particularly valuable.

Pour aller plus loin :

98 words

Radar Profile

The radar profile shows high scores in information quantity and quality, reflecting the depth of the discussion. The technical level is also high, but the reliability score is slightly lower due to the lack of formal citations. Overall, the episode is strong in providing practical insights but relies on expert opinion rather than empirical evidence.

Reliability 7/10

💬 Sur les 0 commentaires analysés, aucune tendance n'a pu être dégagée.