The ITSPmagazine Podcast

AI Agents Act at Machine Speed. Menlo Security Governs What They Actually Do. | A Brand Briefing at Black Hat USA 2026 with Eric Avigdor, Vice President of Product of Menlo Security | Hosted by Sean Martin

Episode Summary

Enterprises are handing AI agents access to email, file stores, and the open internet at the same time, and most of them have not decided who owns the guardrails. Recorded on location at Black Hat USA 2026, this conversation looks at what changes when the thing reading your web pages has no human skepticism.

Episode Notes

Recorded on location at Black Hat USA 2026, Eric Avigdor of Menlo Security describes an adoption pattern he hears in customer conversation after customer conversation. AI makes teams measurably more productive. The guardrails that keep company data inside the business arrive later, if they arrive at all.

Eric Avigdor leads product for AI security and data security at Menlo Security, and he splits the problem into two categories that get very different levels of attention. One is how people use AI in the browser, including what data gets pasted into an assistant and how much of that usage anyone knows about. The other is autonomous agents built to run business processes, where the question is how to keep them productive without letting their goals get hijacked.

The category Eric Avigdor says compliance teams skip past is the agent that holds sensitive data and internet access at the same time. Read a poisoned web page, take the hidden instruction, and the goal changes. What is the difference between an agent running analysis on an internal database and an agent doing financial analysis at a bank with customer records and web access? One of them can be told to send the data somewhere else.

So who owns AI governance? In most companies, nobody does, at least not with authority. Responsibility lands with the endpoint team, the network team, or the browser team, and each one works its own angle. An endpoint team tracks agent traffic on the endpoint and then loses the trail when the agent moves data cloud to cloud. A cloud team has the reverse blind spot.

Menlo Agent Runtime Security, or MARS, is built around what an agent actually does rather than what it intends to do. Agent traffic is proxied through the Menlo Security cloud browser, where data masking, indirect prompt injection prevention, and web-based and file-based threat prevention are applied before an incident becomes cleanup work. Browser and web traffic today, MCP traffic next.

For regulated organizations, that architecture produces something auditors can use. Logging, dashboarding, and a visual record of what an agent attempted in the real world. Europe has the AI Act. The US has not landed comparable rules yet, and Eric Avigdor says that gap concerns him enough that he is talking with people working to close it.

GUEST

Eric Avigdor, Vice President of Product, Menlo Security | On LinkedIn: https://www.linkedin.com/in/eric-avigdor-0b561118/

RESOURCES

Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas

Menlo Security: https://www.menlosecurity.com/

Menlo AI Agent Security: https://www.menlosecurity.com/product/ai-agent-security

Menlo AI Adaptive DLP: https://www.menlosecurity.com/product/ai-adaptive-dlp

Are you interested in telling your story?
▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full
▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight
▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight
▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings

KEYWORDS

eric avigdor, menlo security, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, black hat usa 2026, mars, menlo agent runtime security, ai agent security, prompt injection, indirect prompt injection, data exfiltration, ai governance, browser security, agentic ai, autonomous agents, shadow ai, data loss prevention, eu ai act, ai compliance, coding agents, mcp security

Episode Transcription

AI Agents Act at Machine Speed. Menlo Security Governs What They Actually Do. | A Brand Spotlight at Black Hat USA 2026 with Eric Avigdor, Vice President of Product of Menlo Security | Hosted by Sean Martin


 

[00:00:00] Sean Martin: All right, Eric, I'd love to sit here and chat, talk about barbecue all day long.


 

[00:00:14] Eric Avigdor: Exactly.


 

[00:00:14] Sean Martin: But we can do that at some other time. Today we're going to talk about Menlo Security, and all the good stuff you're showing off here at Black Hat. How's the week so far?


 

[00:00:23] Eric Avigdor: It's been amazing. We're seeing some amazing technology. The big guys are doing their big thing and the younger startups are doing some amazing new tricks, and I'm seeing some super impressive technologies. I think it's difficult for the audience to distinguish between what's real and what's not, and how the messages that sound the same are actually different.


 

[00:00:45] Sean Martin: Right. There are only so many words in the dictionary. We have to use them to get our message across. That's the fun part. So hopefully we'll hone in on some of the things that you do to help organizations [00:01:00] achieve their objectives. A bit about your role at Menlo Security.


 

[00:01:04] Eric Avigdor: So I am VP Product. I'm head of product for AI security and data security at Menlo. A bunch of new interesting initiatives. AI powered, and for AI.


 

[00:01:16] Sean Martin: And so you launched MARS a while back, and then you have some updates that come to that. Give me the elevator pitch for Menlo, so these folks have that, and then a look at the latest revs.


 

[00:01:31] Eric Avigdor: So Menlo Security is focused on securing human browser interaction, which means we make the internet safe for humans. The extension of that is now, as agents are interacting with web content, with browser content, we want to make sure that agents are not going rogue, and keeping the data safe from agentic workflows.


 

[00:01:52] Sean Martin: So how does, well, obviously, plugins to the browser, AI, [00:02:00] the extensions, I guess it would be, obviously access to data on the machine and on the back end. So your role of looking at AI and data and the world of browsers, how does that all play together?


 

[00:02:14] Eric Avigdor: So that's interesting, because I would break it down into two very different use cases, which is what we're hearing from our customers. The first one is, how are humans using AI? In my daily job I use ChatGPT and Claude and Gemini, and I do that in many cases in the browser. It needs visibility into that. It needs to know that I'm doing that, and to approve or not approve, and what data am I sharing? Is that sensitive data or private data, and am I allowed to share that data? So that's one aspect, the discovery of shadow usage of AI. A whole different universe, on the more mature end of the spectrum, is I'm building agents, now I'm building autonomous agents to automate business process. How [00:03:00] do I allow these autonomous agents to be productive, but do it in a safe way that is not goal hijacked?


 

[00:03:06] Sean Martin: And so give us some scenarios of what organizations are trying to cover. Obviously there's a lot of adoption of AI, purposeful, meaningful, shadow instances. Ultimately, what are companies trying to achieve?


 

[00:03:24] Eric Avigdor: So I think what's interesting is that we've had tens of discussions with Menlo customers and they're all saying the same thing, which is AI is incredible, it's making us way more productive, and we do not have yet the guardrails in place to keep our data safe. So let's say you've put in place Claude Cowork to allow every one of your marketing people and engineers to have access to your email, OneDrive, Google Drive, and all of your data sources. How do we keep the data safe? What if the agent is prompt injected? How do you secure that data? So the ask [00:04:00] is really, how do we keep everyone productive, keeping the data safe at the same time?


 

[00:04:06] Sean Martin: And do they even have an option to do that work without Menlo Security in place? Are they trying to figure that out?


 

[00:04:16] Eric Avigdor: So I think the interesting thing when you walk around Black Hat is that everyone is kind of saying the same thing,


 

[00:04:21] Sean Martin: Right.


 

[00:04:22] Eric Avigdor: but everyone means something slightly different.


 

[00:04:24] Sean Martin: Right.


 

[00:04:24] Eric Avigdor: So one thing I would think about, if you are in a governance role, when we talk to customers, is ask yourself question number one: how do I protect the agent from thinking the wrong thing, by protecting its LLM, by protecting its workflows, by protecting its runtime? Problem number two, for defense in depth: how do I actually secure what the agent is actually doing? How do I secure the data where it is used by the agent, where it is consumed by the agent? And that's where we come in with MARS, where initially we launched a platform that looked [00:05:00] at, hey, an agent is browsing, how can I secure what the agent is doing on the internet? A secondary question is, okay, let's take that a step further. If we've deployed Claude Code, which uses internet resources, or we've deployed Copilot, how do we make sure that when that agent reaches out to the internet, it doesn't put my sensitive data at risk?


 

[00:05:25] Sean Martin: So how and where does Menlo fit into the, I'll say the infrastructure, start there. So where do you plug in? You have the network level, the browser level, endpoint level, data level. Tell me.


 

[00:05:40] Eric Avigdor: Yeah, so it's interesting, because there are many different entry points to intervene and inspect agent traffic. The first one is obviously the browser. So we proxy all agent traffic through Menlo and we can inspect it, and not only inspect, we can actually prevent, by [00:06:00] masking data, by preventing indirect prompt injection attacks, or we prevent web-based and file-based threats. And the intention is basically to prevent the risk before it actually materializes into something that needs to be cleaned up. So we can inspect proxied traffic.


 

[00:06:21] Sean Martin: Because you mentioned the browser, the apps are also browser-ish.


 

[00:06:26] Eric Avigdor: Right. So apps have many different ways of interacting with the world, right, and with agents. Agents can reach out over APIs and MCP servers and browsers and web fetch tools. MARS intervenes in many of these areas, both on browser and web traffic, and soon enough on MCP traffic as well, and we will be evolving this over the next few weeks and months.


 

[00:06:52] Sean Martin: And what types of things are you looking for now? How does that surface to somebody who needs to monitor [00:07:00] and then make a decision on what to do?


 

[00:07:03] Eric Avigdor: Okay, so from a governance perspective, what I'm hearing from customers is that these two levels of governance are required. The first one is, how do I prevent an agent from interpreting an intent incorrectly and taking the wrong action? That is more an LLM brain type of security. The second layer is, I want to protect my data where it lives, in my data stores, in my application. That perimeter security for what the agent actually touches is that second layer.


 

[00:07:35] Sean Martin: Okay.


 

[00:07:35] Eric Avigdor: And this is where we and other vendors come in and apply controls.


 

[00:07:41] Sean Martin: So you're defining policies that then put the controls around the agent to actually handle the decisions on its own, or


 

[00:07:50] Eric Avigdor: so the ideal situation is, if I as a company have an agent registry and I have 10,000 agents [00:08:00] running in my environment, I will want to be able to apply a single set of controls across the board for all of the agents' activity, across browser and network and endpoint and application activity. And that is what MARS is. It's a centralized, unified, single pane of glass control, and it can apply policy for anything the agent is doing.


 

[00:08:23] Sean Martin: So what are some of the results from customers and even prospects who are doing proofs of concept and things like that? What's some feedback you're getting, some results you're getting?


 

[00:08:37] Eric Avigdor: Okay, so the first interesting point is we're seeing a difference between customers who are deploying agents only for internal analysis. So if an agent is running analysis on your Salesforce instance or on your databases, that is one category of risk. A whole different category of risk, where we are seeing traction, is the agent has access to my sensitive data, but it also has access to [00:09:00] the internet, and this is in many cases overlooked by compliance teams, because most agents have access to the internet. What that really means is that through internet interaction you can be prompt injected, which means your goal can be hijacked, which means you could be told to exfiltrate all of your sensitive data. So where we're seeing traction is really in those use cases where, if you're a bank and you're running an agent for financial analysis, which by the way has access to your customers' private data, and it's running analysis on the internet, that's where we're seeing success in securing that data.


 

[00:09:36] Sean Martin: And from a security program perspective, I presume you fit into the big picture of security management and security operations. How does that world look?


 

[00:09:47] Eric Avigdor: So that is one of the more interesting points I'm finding lately. There are few companies who have actually defined what AI governance truly means and have a team that is fully [00:10:00] enabled, and where responsibility is truly delegated to this team to own AI governance. What really is happening in most companies is that it is either delegated to the endpoint team or the network team or the browser team, and then every one of them is trying to find their angle into how they can secure AI usage. And that is a challenge. That truly is a challenge.


 

[00:10:23] Sean Martin: Yeah, different teams, there's probably gaps and certainly overlaps as well, which is wasteful in some cases. Let's keep going with the team perspective. So there are those different teams. What is relevant for each of them as they start to look at what you're providing?


 

[00:10:46] Eric Avigdor: So I think it really depends on each team, what data they actually have access to. So for example, if I am an endpoint security team, I know that I can track traffic coming out of agents running on endpoints. [00:11:00] Those agents on one hand can provide, you can inspect some or part of the traffic coming out, but if that agent is then running a command that drives data from one cloud to another, potentially an endpoint security team would not have visibility to that. Right? Which is when they need to reach out to a network team, or a cloud team, or an applications team. If I'm a cloud infrastructure team, I have access to data coming from agents running in cloud. I don't have access to inspection points on the endpoint. So that's where a whole lot of collaboration is needed, and that is where the way we are building MARS is as a platform that can inspect not what the agent is intending to do, but what it is actually doing in the real world. And that's where we have so many inspection points where we can truly put controls, not only inspection and visibility, but actual controls on what the agent is doing.


 

[00:11:57] Sean Martin: Of course, sadly, [00:12:00] organizations, especially in certain industries, are regulated by different laws. They have to be audited to prove that they meet a certain standard, achieve a certain level. And I guess I'm wondering, in terms of what you provide from MARS for an audit, what does that look like?


 

[00:12:22] Eric Avigdor: So first, it's a really interesting point, because if you look for example at Europe, Europe came out with this AI Act, which is intended to protect privacy, our privacy, from usage in AI. The US is not there yet, and that's very concerning. I actually just spoke with a group, a non-profit that is acting to create more AI regulations in the country, in the US, in order to protect my personal healthcare data, which is great. What MARS does to help that is it actually provides several different layers of visibility. The first one is logging and dashboarding on what the [00:13:00] agent is actually doing, at the same time, wherever they're moving. What's interesting and unique is that because Menlo by definition runs everything through its cloud browser, its browser which runs in the Menlo cloud, we can not only inspect what the agent is doing, we can show visually what the agent was attempting to do in the real world. And that is extremely unique, because we're no longer looking at logs that can be deciphered in different ways. We're looking at the actual agent


 

[00:13:31] Sean Martin: actual activity,


 

[00:13:32] Eric Avigdor: activity on the web. And that can be inspected and audited and logged for compliance reasons.


 

[00:13:38] Sean Martin: Yeah, I think, sadly, as you point out, the US is not quite there yet, but I'm sure they will be, probably led by the states first,


 

[00:13:46] Eric Avigdor: as always,


 

[00:13:47] Sean Martin: before the federal government. But even if there isn't a regulation, it's probably a good thing to understand anyway from a business perspective. So it's good that you provide that capability.


 

[00:13:58] Eric Avigdor: I think the aha [00:14:00] moment that I always find when we talk to customers is they're enjoying the productivity of these agents. They're using AI assistants and coding assistants and autonomous agents, and the first honeymoon period is incredible, because they're having so much fun and it feels like a game and the agents are extremely productive. But the aha moment is when you understand that that agent doesn't have human discipline and human skepticism, and it can be tricked easily. And once that agent is tricked, if it has access to the internet, there's enormous risk there.


 

[00:14:39] Sean Martin: Exposure,


 

[00:14:40] Eric Avigdor: exposure, exposure.


 

[00:14:41] Sean Martin: Sure. Well, Eric, it's a pleasure chatting with you. I'm excited to keep following what you're doing with Menlo and MARS, and hopefully more stories we can talk about, different customers and use cases. In the meantime, folks should connect with Eric and the Menlo Security team, and follow him on LinkedIn. [00:15:00]


 

[00:15:00] Eric Avigdor: Absolutely. Thanks so much.