Skip to content
Artwork for David Bombal
David Bombal · August 26 · 26 min

#598: AI Can’t Understand Intent. That’s a Security Problem

Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal AI is changing cybersecurity, but simply using more AI to defend against AI attacks may not be the answer. David Bombal sits down with Danny Jenkins, CEO of ThreatLocker, to discuss the security risks created by AI, autonomous agents, zero-day vulnerabilities, ransomware, and the rapidly expanding attack surface businesses now have to deal with. Danny explains one of the fundamental problems with AI security: AI can understand what something does, but it may not understand the intent behind it. The same action could be performed legitimately by an administrator or maliciously by an attacker. They also discuss how AI is giving attackers capabilities that previously required significantly more expertise and resources, including vulnerability discovery and sophisticated phishing attacks. But AI creates another problem inside organizations. Autonomous agents can potentially access files, upload data, perform actions, and make mistakes extremely quickly. Every new piece of software adds attack surface, and powerful AI agents can dramatically increase that risk. Danny argues that the answer isn't simply AI versus AI. Instead, organizations need to rethink trust itself. The discussion covers deny by default, application control, restricting what software and AI agents are allowed to access, and why AI should be used as an additional security layer rather than becoming your primary defense. Topics include: • AI security risks • Autonomous and agentic AI • Why AI struggles with intent • How hackers are using AI • AI-powered vulnerability discovery • Zero-day vulnerabilities • Ransomware • AI attack surfaces • Application control • Deny by default security • Why AI alone can't solve AI security • Securing AI inside businesses // Danny Jenkins’ SOCIAL // LinkedIn: / dannyjenkinscyber // ThreatLocker’s SOCIAL // LinkedIn: https://www.linkedin.com/company/thre... X: https://x.com/threatlocker Instagram: / threatlocker Website: https://www.threatlocker.com/ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:34 - Introduction 0:46 - Why Businesses Are Afraid of AI 02:17 - AI Can Be Used for Good or Bad 03:29 - The Race to Adopt AI 05:02 - AI Gives Attackers Nation-State Capabilities 06:09 - Why AI Can't Be Your Primary Defense 07:59 - How AI Is Expanding the Attack Surface 08:53 - Solving AI Security With Limited Access 11:04 - The Deny-by-Default Security Model 14:12 - AI-Powered Vulnerability Hunting 17:29 - How ThreatLocker Actually Uses AI 20:01 - Why Deny-by-Default Beats Chasing Zero-Days 21:15 - What Cybersecurity Customers Are Most Worried About 22:16 - AI Hype, Jobs & Closing Thoughts 24:55 - ThreatLocker Advert Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #threatlocker #bhusa2026 #blackhat

0:00-26:02

transcript

No transcript — this publisher did not publish one.

show notes

Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal


AI is changing cybersecurity, but simply using more AI to defend against AI attacks may not be the answer.


David Bombal sits down with Danny Jenkins, CEO of ThreatLocker, to discuss the security risks created by AI, autonomous agents, zero-day vulnerabilities, ransomware, and the rapidly expanding attack surface businesses now have to deal with.


Danny explains one of the fundamental problems with AI security: AI can understand what something does, but it may not understand the intent behind it. The same action could be performed legitimately by an administrator or maliciously by an attacker.


They also discuss how AI is giving attackers capabilities that previously required significantly more expertise and resources, including vulnerability discovery and

sophisticated phishing attacks.


But AI creates another problem inside organizations. Autonomous agents can potentially access files, upload data, perform actions, and make mistakes extremely quickly. Every new piece of software adds attack surface, and powerful AI agents can dramatically increase that risk. Danny argues that the answer isn't simply AI versus AI.

Instead, organizations need to rethink trust itself.


The discussion covers deny by default, application control, restricting what software and AI agents are allowed to access, and why AI should be used as an additional

security layer rather than becoming your primary defense.


Topics include:

• AI security risks

• Autonomous and agentic AI

• Why AI struggles with intent

• How hackers are using AI

• AI-powered vulnerability discovery

• Zero-day vulnerabilities

• Ransomware

• AI attack surfaces

• Application control

• Deny by default security

• Why AI alone can't solve AI security

• Securing AI inside businesses

// Danny Jenkins’ SOCIAL //

LinkedIn: / dannyjenkinscyber


// ThreatLocker’s SOCIAL //

LinkedIn: https://www.linkedin.com/company/thre...

X: https://x.com/threatlocker

Instagram: / threatlocker

Website: https://www.threatlocker.com/


// David's SOCIAL //

Discord: discord.com/invite/usKSyzb

Twitter: www.twitter.com/davidbombal

Instagram: www.instagram.com/davidbombal

LinkedIn: www.linkedin.com/in/davidbombal

Facebook: www.facebook.com/davidbombal.co

TikTok: tiktok.com/@davidbombal

YouTube: / @davidbombal

Spotify: open.spotify.com/show/3f6k6gE...

SoundCloud: / davidbombal

Apple Podcast: podcasts.apple.com/us/podcast...


// MY STUFF //

https://www.amazon.com/shop/davidbombal


// SPONSORS //

Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com


// MENU //

0:00 - Coming Up

0:34 - Introduction

0:46 - Why Businesses Are Afraid of AI

02:17 - AI Can Be Used for Good or Bad

03:29 - The Race to Adopt AI

05:02 - AI Gives Attackers Nation-State Capabilities

06:09 - Why AI Can't Be Your Primary Defense

07:59 - How AI Is Expanding the Attack Surface

08:53 - Solving AI Security With Limited Access

11:04 - The Deny-by-Default Security Model

14:12 - AI-Powered Vulnerability Hunting

17:29 - How ThreatLocker Actually Uses AI

20:01 - Why Deny-by-Default Beats Chasing Zero-Days

21:15 - What Cybersecurity Customers Are Most Worried About

22:16 - AI Hype, Jobs & Closing Thoughts

24:55 - ThreatLocker Advert


Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!


Disclaimer: This video is for educational purposes only.

#threatlocker #bhusa2026 #blackhat