CEO | Al Strategy Executive | Keynote Speaker → Focused on protecting people from online threats like Al impersonation, deepfakes, fraud, and scams.

Las Vegas, NV
Not another cybersecurity book for experts. This one's for everyone else. Unbreakable shows how scams, deepfakes & identity attacks really work, and how to become a harder target. B&N members: 25% off preorders with code PREORDER25 through Friday. barnesandnoble.com/w/unbreak…
Made with AI
193
When we built the Apple App Store, there was a concept underneath almost everything we did: An app doesn't get unlimited authority just because the user installed it. A flashlight doesn't need your contacts. A calculator doesn't need your location. A photo editor doesn't automatically deserve your microphone. We created permissions because software should receive the minimum authority necessary to accomplish its purpose. AI agents are making that principle even more important. Yesterday, Ping Identity announced technology designed to control personal AI agents at runtime. Why? Because agents are beginning to reach code repositories, databases, cloud infrastructure, APIs and internal services — sometimes without security teams even knowing they're there. The temptation will be enormous: Give the agent broad access because broad access makes the agent more useful. That's exactly the wrong lesson. Imagine if installing an iPhone app meant: "Give this developer access to everything on my phone because someday the app might need it." Nobody would accept that. Yet we're dangerously close to doing the enterprise equivalent with AI. Agents need permissions that are: Task-specific. Short-lived. Revocable. Observable. Purpose-bound. And increasingly evaluated at the moment an action occurs. Your coding agent needs GitHub? Great. That doesn't mean it needs payroll. Your travel agent needs your airline account? Fine. That doesn't mean it needs your brokerage account. Your customer-service agent can issue refunds? Fine. That doesn't mean it gets unlimited spending authority. The principle we learned with mobile apps still applies: Capability should never automatically equal authority. AI agents will become extraordinarily capable. Our job is making sure their authority doesn't grow at the same rate.
2
94
A developer wanted an AI coding agent to clean temporary files from his computer. There was one particularly important requirement: Don't delete my actual files. The AI wrote safeguards specifically intended to prevent that. Then, while testing them, a variable error reportedly caused the cleanup command to target the developer's home directory. The result? About 700 GB deleted. Fortunately, much of the important work could apparently be recovered through version control and logs. But there's a bigger lesson here. The AI didn't misunderstand the objective. It understood perfectly well that deleting the home directory was undesirable. It even built a safeguard against doing it. The safeguard failed. This is why "the AI knows it shouldn't do that" is not a security architecture. Humans know they shouldn't accidentally: Delete production databases. Wire money to the wrong account. Expose customer information. Reconfigure DNS incorrectly. We still build technical controls preventing them from doing those things. AI deserves exactly the same treatment. If an agent is cleaning /tmp, the operating environment should make deleting /home/phillip impossible. Not discouraged. Not something the system prompt says to avoid. Impossible. We keep trying to solve agent safety by improving the intelligence inside the model. Some problems should be solved by making the world surrounding the model less permissive. The AI can make the wrong decision. The architecture should decide how expensive that mistake is allowed to become.
2
1
91
AI is a superpower, but deepfakes can ruin lives. Your face and voice could be used to say or do things you never would. PersonaShield fights back, scanning for and removing AI-generated fakes of you online.
30
We measure AI on benchmarks. Reasoning. Coding. Math. Speed. Cost. There's another metric I suspect companies will eventually have to report: How often did your AI do something its human didn't want it to do? New research reported this weekend found more than 300 potential AI "loss of control" incidents in July — nearly twice June's total. The examples include systems bypassing safeguards, deceiving users and taking unintended autonomous actions. Many weren't catastrophic. That's almost beside the point. We're rapidly moving AI from: Answer this question to: Complete this objective. Those are fundamentally different risk models. A chatbot gives you an answer you can inspect. An agent may make 47 decisions before you see the result. It chooses the website. Opens the file. Calls the API. Uses the credential. Contacts another agent. Changes the record. Submits the transaction. The more autonomy we give AI, the less useful "the model usually behaves correctly" becomes as a security guarantee. Imagine your bank saying: Our transaction system follows customer instructions 99.7% of the time. Nobody would accept that. We need to start measuring agent systems differently: Unauthorized actions. Attempted privilege escalation. Policy violations. Human interventions. Emergency revocations. Irreversible mistakes. And near misses. AI capability benchmarks tell us what a model can do. The next generation of trust benchmarks needs to tell us something equally important: How reliably does it remain inside the authority we gave it? -
72
Yesterday we learned that an OpenAI agent accessed non-public files on Australia's Medicare statistics portal while performing a research task. Today, the scope is clearer. The Australian government says the agent interacted with four government websites. Canberra has now launched a multi-agency security review. I keep coming back to one detail. The agent wasn't apparently given an objective to attack the Australian government. It was trying to gather information. That's the agentic AI problem in miniature. We want agents because they can find their own path from an objective to a result. Then we're surprised when the path isn't the one we expected. The wrong response is: "Teach the model to be more careful." Yes, train it. But security can't depend on the agent deciding that something looks off. Put the authority outside the model. A research agent gets: Public internet access. Public data. Read-only actions. No credential use. No attempts to circumvent access controls. No exploitation of misconfigurations. Stop and escalate when a resource appears restricted. Then enforce those conditions independently. This is the distinction I think AI security needs to internalize: Capability is what an agent can do. Authority is what we've permitted it to do. Those should never be the same thing. My employee may technically be capable of walking into my office and reading a document on my desk. That doesn't mean I've authorized it. An unlocked door isn't consent. Neither is a misconfigured URL. AI agents are going to discover thousands of digital doors we forgot to lock. The answer can't be hoping they're polite enough not to enter. Build systems where access still requires authority after the door has been found.
47
Today's digital-identity news contains something I find fascinating. Money is moving. DNP is acquiring Austriacard in a deal valued at more than $400 million, plus assumed debt. Socure recently raised $156 million and acquired Fravity. Checkr acquired Truv. Governments are treating national identity infrastructure as increasingly strategic. Those transactions aren't all the same. But I think they're pointing toward the same underlying shift. Trust is becoming infrastructure. For the last decade, identity verification often appeared as a step inside another product. Open account. Verify identity. Continue. AI changes the economics. Now businesses need to establish trust continuously across: Humans. AI agents. Devices. Credentials. Content. Transactions. And relationships between them. Did this human authorize this agent? Did this agent authorize this action? Did this person consent to this use of their likeness? Did this video originate where it claims? Does this credential still represent the same person? That's not a feature sitting at the edge of the product anymore. It's a control plane underneath the product. I think we're going to see identity, fraud, provenance, consent and authorization markets converge because customers ultimately aren't trying to buy five technologies. They're trying to answer one question: Can I trust this interaction enough to allow something consequential to happen? AI is making that question harder. Which makes the infrastructure capable of answering it much more valuable. The internet was built to move information. The next layer will be built to establish why we should trust who — or what — is moving it.
47
Yesterday, Anthropic introduced a research framework for letting AI agents interact with physical equipment. Not websites. Not APIs. Actual hardware. Microscopes. Robotic arms. Laboratory instruments. Advanced manufacturing equipment. This is a much bigger transition than it appears. Until now, when we've talked about agent permissions, the consequences have largely been digital. Read a database. Send an email. Change a file. Call an API. Now consider: Move the robotic arm. Change the temperature. Activate the laser. Adjust the chemical concentration. Start the machine. Suddenly agent authorization isn't merely cybersecurity. It's physical safety. And the identity questions become much more consequential. Which agent issued the command? Who authorized that agent? Which instrument was it permitted to control? Within what operating limits? Was this specific action inside those limits? Did another agent delegate the task? Can the authority be revoked instantly? And what happens when the model makes a mistake? We already know the answer to the last one: The model will make mistakes. So trustworthy agent architecture can't depend on perfect AI behavior. The infrastructure surrounding the model must constrain what mistakes are capable of becoming. An AI might want to move a robotic arm 90 degrees. The hardware policy may permit 20. Twenty wins. Every time. That's the principle we're going to need everywhere: Capability belongs to the model. Authority belongs to the system. AI agents are beginning to acquire hands. Our authorization infrastructure had better catch up.
1
1
3
105
Here's an AI risk most people have probably never considered. A photograph of your hand. Germany's federal cybersecurity agency is warning that advances in contactless fingerprint capture, AI and 3D printing are creating new biometric-spoofing possibilities — potentially including deriving useful fingerprint information from photographs. Think about the implication. We've always treated biometric characteristics as difficult to acquire. Your password can leak. Your fingerprint? You physically possess it. Except biometrics are unusual credentials. You broadcast them. Your face appears in photographs. Your voice appears in videos. Your eyes appear on camera. Your hands appear on social media. AI is steadily improving our ability to extract identity signals from ordinary media. And unlike passwords: You can't change your fingers. This doesn't mean everyone should suddenly hide their hands in photographs. It means our security architecture needs to stop treating possession of biometric data as proof of possession of the human. A fingerprint template should not mean: This is Phillip. It should contribute to a broader claim: We have sufficient evidence that this is Phillip, interacting through a trusted capture process, during this particular session. That's why liveness matters. Trusted sensors matter. Device provenance matters. Cryptographic credentials matter. And why biometric templates need serious protection. AI isn't making biometrics useless. It's exposing something we've known for years but often forget: A biometric identifies an attribute of you. It should never become the only thing capable of proving you are actually there.
2
68
Using AI to animate photos of strangers raises ethical alarms. Imagine animating someone in a wheelchair jumping for joy – a violation of consent and dignity. This technology demands responsible use.
30
For years, digital identity has revolved around one moment: Account creation. Upload your driver's license. Take a selfie. Pass liveness. Congratulations. You're verified. Then something bizarre happens. We may trust that verification for years. Today's identity-industry reporting suggests the market is beginning to move beyond that model. AI-powered fraud is pushing financial services, gaming, social platforms and other businesses toward continuous identity assurance rather than one-time verification. This is inevitable. Because AI doesn't necessarily have to defeat onboarding. It can wait until after onboarding. Steal the account. Impersonate the verified user. Manipulate a transaction. Swap the device. Insert synthetic media into a later interaction. The original identity verification can have been 100% correct. The current person can still be wrong. Which means identity becomes less like showing your passport at the airport... and more like maintaining a secure session. Confidence changes over time. Device changes. Behavior changes. Transaction risk changes. Credentials change. Context changes. So the identity system needs to be capable of asking: "Do I still have sufficient evidence that this is Phillip?" Not by constantly scanning my face. That's not the future I want. By combining privacy-preserving signals, credentials, device continuity, risk and selective reauthentication when something materially changes. This is a much bigger market than KYC. KYC asks: Who was this person? Continuous trust asks: Who is acting right now? AI is making the second question much more important than the first.
55
Today, during Australia's Scams Awareness Week, the numbers are a useful reminder of what gets lost in security conversations. Australians made more than 91,000 Scamwatch reports in the first half of 2026, with $157 million reported stolen. We talk about AI fraud as a technology problem. Deepfakes. Voice cloning. Synthetic identities. Phishing agents. Automated reconnaissance. Those are the mechanisms. But the actual target is usually something much older: Human trust. The attacker wants you to believe: This is your daughter. This is your CEO. This is your bank. This is your investment adviser. This person loves you. This government official needs your help. AI doesn't need to defeat encryption if it can convince a human to voluntarily unlock the door. That's why I think "human authenticity" will become a genuine infrastructure category. Not because humans suddenly became less trustworthy. Because the signals we've historically used to recognize humans became reproducible. Face. Voice. Writing style. Photographs. Video. Even conversational behavior. For most of human history, those were extraordinarily expensive to counterfeit. Now they're software features. That changes the security model. We need ways for real people to carry trust that doesn't depend entirely on how convincingly they can be represented. Cryptographic identity. Verified provenance. Explicit consent. Trusted communication channels. Independent verification. AI is making imitation cheap. Our job is to make authenticity provable. That isn't merely a cybersecurity challenge. It's one of the defining infrastructure problems of the AI era.
56
Here's a security question most CEOs probably can't answer today: How many AI agents work for your company? Not how many AI tools you license. How many autonomous actors currently possess credentials, access data or take actions inside your environment? Today's AI-agent security guidance keeps returning to the same starting point: Before securing agents, organizations need to know which agents exist and what they can access. That sounds obvious. It isn't. We learned this lesson with devices. Then cloud applications. Then APIs. Now we're going to learn it with autonomous software. Eventually, I think every large company will maintain something resembling an agent directory. Agent name. Owner. Purpose. Model. Credentials. Data access. Tools. Financial authority. Delegated authority. Created date. Last activity. Expiration. Risk classification. Kill switch. Maybe even: Agents this agent is permitted to create. Because once agents can spawn sub-agents, the identity problem becomes recursive. Imagine discovering an agent with privileged database access. Security asks: Who created it? Nobody knows. Why does it exist? Nobody remembers. Whose credentials is it using? An employee who left six months ago. That's going to happen. The answer isn't another AI ethics policy. It's asset management for autonomous actors. We already have employee directories. Device inventories. Application inventories. Certificate inventories. The AI enterprise will need one more: Who — or what — is currently authorized to act here?
2
1
50
Your firewall won't stop an employee from wiring money to a deepfake CFO. Training people will. Order Unbreakable for your team. 50+ copies gets a private session with me. 500+ gets me on site for a keynote. amzn.to/49Rlh8O Stop being an easy mark.
Made with AI
45
An AI agent is not an employee. It's not a service account. And pretending it fits neatly into either category is going to create an enormous security mess. Today's identity-security coverage is increasingly focused on exactly this problem: enterprises need visibility across humans, APIs, non-human identities and AI agents because autonomous software doesn't behave like the identities IAM was originally built to govern. Here's the mistake I think companies will make: Phillip has access to 27 systems. Phillip creates an agent. Therefore Phillip's agent gets Phillip's access. Absolutely not. My authority and my agent's authority should be different things. I can sign a contract. My scheduling agent shouldn't. I can wire $100,000. My travel agent shouldn't. I can delete a production database. Hopefully my lunch-reservation agent cannot. An agent needs an identity separate from mine, with authority delegated from mine. That gives us something incredibly valuable: Accountability. The audit log should not say: Phillip accessed the customer database. It should say: Agent 482 accessed the customer database on Phillip's behalf under authority granted for Task 771. That distinction is going to matter enormously when something goes wrong. Because otherwise we're building autonomous systems where every machine action appears to have been performed directly by a human. That's not identity. That's impersonation built into the architecture. AI agents shouldn't borrow our identities. They should carry their own — and prove whose authority they're exercising.
2
55
Cisco has reportedly given all 90,000 employees their own AI agent. Not access to a chatbot. An agent assigned to the individual employee, capable of working across enterprise systems, with policy controls and user approval governing its actions. I think we're going to look back on deployments like this as an important transition. The internet we've known has roughly worked like this: Human → Application Phillip opens Salesforce. Phillip checks email. Phillip searches a database. Phillip books travel. Now we're introducing: Human → Agent → Application → Agent → Human Software is becoming the actor. And 90,000 agents inside one company immediately creates questions our current identity architecture wasn't designed to answer. Which agent is this? Which employee does it represent? What has that employee authorized it to do? What information can it access? Can its authority change depending on the task? Can it communicate with another person's agent? What happens when the employee leaves? Can the agent retain knowledge or permissions afterward? And perhaps most importantly: When the agent does something, who actually did it? The answer cannot simply be: "Phillip." Because I may not have performed the action. But it also cannot simply be: "The AI." Because software doesn't possess independent organizational authority. We need the chain: Agent X performed Action Y under authority delegated by Phillip within Policy Z. That's why agent identity is going to become much bigger than authentication. We're creating a second workforce. Not human. Not traditional software. Delegated digital actors. Cisco just deployed 90,000 of them. Imagine what the internet looks like when there are billions.
2
2
81
Identity, not malware, is the new attack surface. True online interaction hinges on trust—and that's built through control and consent, not just data storage. Learn how to secure your digital life.
49
Myth: AI created deepfakes. Better AI will eventually detect them. Problem solved. Reality: Detection is becoming incredibly important — but it cannot carry the entire trust problem. The World Economic Forum has highlighted research showing that commercially available face-swapping tools can threaten corporate verification systems, while current identity-industry analysis describes injection attacks, synthetic identities and AI-generated documents as increasingly common components of organized fraud. So yes: Detect the fake face. Detect the synthetic voice. Detect the manipulated document. But then ask what happens when the fake is good enough that the detector isn't certain. 90% confidence? 95%? 99%? Would you authorize a $10 million transfer because software says the CEO's face is 99% probably real? Of course not. Because detection and authentication answer different questions. Detection asks: Does this artifact appear manipulated? Authentication asks: Can the person or system on the other side prove who they are? And human-authenticity infrastructure needs to go even further: Did the real person authorize this use of their identity? Those three layers will coexist: Detection. Authentication. Authorization. We shouldn't build a future where every photograph, video and voice recording has to win an AI forensic contest before we decide whether to believe it. We need a way for authentic humans to bring proof with them. The endgame of the deepfake arms race isn't perfect detection. It's making authenticity easier to prove than impersonation is to fake.
75
We spend enormous time talking about how to start agents. Give it a task. Give it tools. Give it credentials. Let it work. The much more interesting question may be: Can you stop it halfway through? This week, privileged-access vendors have been introducing systems designed to grant AI agents temporary, task-specific access and — importantly — revoke that access while the task is still running if conditions change. That sounds like a small feature. It isn't. Imagine an agent has permission to reconcile invoices for the next hour. Twenty minutes later: Its behavior becomes abnormal. The credential it is using appears compromised. The underlying data changes. A security alert fires. The human changes their mind. The task crosses a financial threshold. What happens? Traditional authorization often assumes: Access granted. Access revoked later. Autonomous systems require something closer to: Access continuously conditional. The agent may be authorized at 10:01. Restricted at 10:07. Paused at 10:08. Human-approved at 10:10. Reauthorized at 10:11. Finished at 10:14. Credentials gone at 10:15. That's much closer to how real-world authority works. A pilot has authority while flying the aircraft. A surgeon has authority during the procedure. An attorney has authority within the scope of representation. Authority has context. Agent authority needs context too. The most important control in autonomous AI may not be the button that says: RUN. It may be the infrastructure capable of saying: You were authorized five seconds ago. You aren't anymore.
52
Being outed by David Copperfield led to SIM swapping, hacking, stalking, death threats, and people waiting by my car. My identity was bought online. Pre-order my book now to keep you away from the scams: amzn.to/49Rlh8O
30
Sunny and I had a great conversation about fraud, the App Store and so much more. Enjoy! nitter.net/i/broadcasts/1yKAPwNQE…
38