Ambient and Autonomous Security: Building Trust in the Agentic AI Era

Ambient and Autonomous Security: Building Trust in the Agentic AI Era

🎙 Vasu Jakkal, Corporate Vice President, Microsoft Security, Microsoft; H.E. Dr. Mohamed Al Kuwaiti, Head of Cybersecurity, UAE Government 👥 101K 📅 March 24, 2026 ⏱ 24 min 👁 2K 📄 expert opinion 🧭 2026-08-13
Available in: English (current) Français

Keywords

agentic AIambient securityautonomous securityAI threatszero trustgovernanceobservabilityidentitydata securitythreat intelligence

Summary

In this keynote at RSAC 2026, Vasu Jakkal, Corporate Vice President of Microsoft Security, outlines a vision for the future of cybersecurity in the age of agentic AI. She argues that as AI-powered attacks become more sophisticated, security must become ‘ambient and autonomous’—embedded in every layer of the AI stack and operating continuously at machine speed. She highlights the rise of AI-powered attacks, citing Microsoft Threat Intelligence and Anthropic’s report on Claude performing 80-90% of attack tasks autonomously. To counter these threats, she proposes a framework for securing AI agents, focusing on identity, threat protection, data security, and governance. She emphasizes the need for observability, continuous evaluation, and the extension of zero trust principles to AI. The talk also features a video message from H.E. Dr. Mohamed Al Kuwaiti of the UAE Government Cybersecurity Council, who discusses the UAE’s ambition to build one billion AI agents and the concept of ‘National XDR’ for country-level threat detection and response. The presentation concludes with a call for collaboration and the importance of building trust in AI through security.

176 words

Critical Evaluation

Value of the Information & Strength of the Argument

The talk provides valuable insights into the emerging threats posed by agentic AI and the strategic direction for security. It effectively argues that traditional security approaches are insufficient and that a paradigm shift towards ambient and autonomous security is necessary. The argumentation is coherent and well-structured, supported by references to real-world examples such as North Korean threat actors and Anthropic’s Claude. However, the talk is primarily a high-level vision statement rather than a detailed technical analysis. It lacks specific technical details, implementation strategies, and empirical evidence to substantiate the claims. The argumentation is persuasive but relies heavily on Microsoft’s corporate perspective, which may introduce bias.

Scientific Rigor, Source Quality, Title Accuracy

The talk demonstrates a moderate level of scientific rigor. It references credible sources such as Microsoft Threat Intelligence and Anthropic, but these are not independently verified. The talk does not provide citations or links to specific reports, making it difficult to verify the claims. The title accurately reflects the content, and the talk stays on topic. The inclusion of the UAE government’s perspective adds a real-world application, but it is presented as a promotional video rather than a critical analysis. Overall, the sources are relevant but not exhaustive, and the talk would benefit from more transparent referencing.

217 words

Title / Content Match

The title accurately reflects the content, focusing on ambient and autonomous security in the context of agentic AI.

Quality & Reliability

7/10

The talk is an expert keynote from a Microsoft executive, presenting a corporate vision for agentic AI security. It references specific threat intelligence (Microsoft Threat Intelligence, Anthropic's Claude use case) and industry projections (IDC, Fortune 500). However, it lacks detailed technical depth, verifiable data, and independent sources, making it more of a strategic overview than a rigorous scientific analysis.

Key Moments

Cited Sources

  • Microsoft Threat Intelligence — Referenced as the source for observations on AI-powered attacks and threat actor tradecraft.
  • Anthropic's report on Claude — Cited as an example of agentic AI being used in attack workflows, with Claude performing 80-90% of tasks autonomously.
  • IDC projection — Mentioned as the source for the prediction of 1.3 billion agents by 2028.

Concurring Sources

Dissenting Sources

  • Critique of AI hype in cybersecurity — Some experts argue that the emphasis on AI-driven attacks may be overstated, and that traditional security measures remain effective.

Contribution & Novelties

The talk contributes to the discourse on AI security by proposing a comprehensive framework for ‘ambient and autonomous security’ specifically tailored to agentic AI. It emphasizes the need for continuous, embedded security across the entire AI stack and introduces concepts like agent identity, observability control planes, and the extension of zero trust to AI. The inclusion of the UAE’s National XDR initiative provides a real-world example of scaling security to a national level. However, the talk is largely a strategic vision rather than a novel technical contribution, and it does not present new empirical data or detailed methodologies.

Pour aller plus loin :

144 words

Radar Profile

The radar profile shows high scores in quantity and quality of information, reflecting the talk's comprehensive coverage of the topic. The technical level is moderate, indicating that the content is accessible to a broad audience but lacks deep technical detail. The overall reliability is moderate, as the talk relies on corporate sources and lacks independent verification.

Reliability 6/10

💬 No comments were provided for analysis.