{"id":4626,"date":"2026-07-22T13:12:04","date_gmt":"2026-07-22T13:12:04","guid":{"rendered":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/07\/22\/agentic-ai-needs-guardrails-not-guesswork\/"},"modified":"2026-07-22T13:12:04","modified_gmt":"2026-07-22T13:12:04","slug":"agentic-ai-needs-guardrails-not-guesswork","status":"publish","type":"post","link":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/07\/22\/agentic-ai-needs-guardrails-not-guesswork\/","title":{"rendered":"Agentic AI Needs Guardrails, Not Guesswork"},"content":{"rendered":"<p class=\"wp-block-paragraph\"><em>What does it take to secure AI agents without slowing developers down? A recent panel explored the answer\u00a0<\/em><\/p>\n<p class=\"wp-block-paragraph\">I recently joined <a href=\"https:\/\/www.linkedin.com\/in\/zachlloyd\" rel=\"nofollow noopener\" target=\"_blank\">Zach Lloyd, founder and CEO of Warp<\/a>; <a href=\"https:\/\/x.com\/Gavriel_Cohen?lang=en\" rel=\"nofollow\">Gavriel Cohen, co-founder and CEO of NanoCo and creator of NanoClaw<\/a>; and moderator <a href=\"https:\/\/www.linkedin.com\/in\/moriah-hara-a18b84\" rel=\"nofollow noopener\" target=\"_blank\">Moriah Hara, founder of a community of more than 3,000 CISOs and a three-time Fortune 500 CISO<\/a>, for a discussion on one of the biggest challenges facing enterprise security teams today: how to safely unlock the productivity of agentic AI.<\/p>\n<p class=\"wp-block-paragraph\">The rapid rise of agentic AI in the enterprise is putting CISOs in a tough spot. On one hand, business leaders are clamoring to run with the new technology, which promises a productivity revolution like no other. On the other, setting AI agents loose without rigorous guardrails creates severe vulnerabilities.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Moriah put the dilemma facing CISOs like this: <em>\u201cThe business wants AI agents everywhere, developers are already using them, sometimes without approval, oftentimes without security. <\/em><em><br \/><\/em><em>\u2026CISOs are left in this uncomfortable middle where we\u2019re tolerating some tools, we\u2019re praying that nothing breaks, we\u2019re buying some time until we can get some governance beyond policy in place to have better visibility.\u201d<\/em><\/p>\n<p class=\"wp-block-paragraph\">The panel explored the role of the CISO in balancing this tension between productivity and security. Here are some highlights.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Isolate, control, observe<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">They came at it from different angles, but the panelists agreed on one imperative: running AI agents safely requires an isolated environment with trusted control boundaries. For Zach, Warp\u2019s <a href=\"https:\/\/www.warp.dev\/oz\" rel=\"nofollow noopener\" target=\"_blank\">Oz<\/a> platform provides that isolation. It\u2019s a cloud agent infrastructure for secure and automated deployment of coding agents that allows centralized management, access controls, and visibility into what agents are doing across the organization.<\/p>\n<p class=\"wp-block-paragraph\">Zach said you can<em> \u201cliterally pull up the Oz web app and see what every agent across your company is doing at all times\u2014which is a way better situation than the world we\u2019re in right now, where someone on your marketing team is running <\/em><a href=\"https:\/\/cloud.google.com\/code\" rel=\"nofollow noopener\" target=\"_blank\"><em>Cloud Code<\/em><\/a><em>, someone on your sales team is running <\/em><a href=\"https:\/\/openai.com\/index\/introducing-codex\/\" rel=\"nofollow noopener\" target=\"_blank\"><em>Codex<\/em><\/a><em>, and you just have no idea what\u2019s going on, what tools they\u2019re installing.\u201d<\/em><\/p>\n<h2 class=\"wp-block-heading\"><strong>NanoClaw\u2014a personal AI agent<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">At Docker, our answer to the challenge of running AI agents safely is to run them in disposable, isolated, local sandboxes. <a href=\"https:\/\/www.docker.com\/products\/docker-sandboxes\/#credentials\">Docker Sandboxes<\/a> give agents the freedom and autonomy they need to do their best work, safely. Call it YOLO mode with guardrails. As Moriah noted in our discussion, agentic speed should be encouraged\u2014 <em>\u201cit\u2019s the ungoverned speed that is the problem.\u201d<\/em> When agents are allowed to run fast without running wild, speed and safety are no longer a tradeoff.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Of note here: In March, we announced the <a href=\"https:\/\/www.docker.com\/blog\/nanoclaw-docker-sandboxes-agent-security\/\">integration of NanoClaw with Docker Sandboxes<\/a> to deliver secure-by-design agent execution. The integration allows every NanoClaw agent to run inside a disposable, MicroVM-based Docker Sandbox that enforces strong operating system-level isolation. The stack takes advantage of NanoClaw\u2019s minimal attack surface and fully auditable open-source codebase to meet enterprise security standards.\u00a0<\/p>\n<h2 class=\"wp-block-heading\"><strong>Laptops as the new prod<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">A key focus of the discussion was where to run agents safely. With vibe coding exploding, and agents and Claws (a new class of agents) already in production, the laptop today is the most powerful node in the enterprise. <a href=\"https:\/\/www.docker.com\/blog\/ai-coding-agent-horror-stories-security-risks\/\">It\u2019s also the most exposed<\/a>. As a colleague of mine <a href=\"https:\/\/www.docker.com\/blog\/docker-ai-governance-unlock-agent-autonomy-safely\/\">recently put it<\/a>, laptop and agent environments are the new prod, and they need to be governed like prod.<\/p>\n<p class=\"wp-block-paragraph\">Zach stressed the need to get agents off people\u2019s laptops and desktops and into a controlled, cloud-based environment where CISOs can see what every agent across the company is doing at all times.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Portability\u2014from laptop to cloud<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">My position is that, if you run agents in a sandbox, it doesn\u2019t matter where the box sits. It could sit on a marketing or finance person\u2019s laptop, or on a DevOps engineer or cloud admin\u2019s machine. As long as the trust boundary is established and you know what\u2019s getting piped in and out of it, you\u2019re locked and loaded for rapid prototyping, experimentation, and innovation.<\/p>\n<p class=\"wp-block-paragraph\">By the way, this view syncs with Docker\u2019s vision, which has always been about portability. Our vision was never everything is local. We start in the local environment, then lift off into distributed environments, Kubernetes clusters, public clouds, whatever. It\u2019s the same with agents. Eventually they\u2019ll lift off, be decoupled from human operators, and be able to run fully autonomously wherever needed\u2014always in the same portable environment.<\/p>\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-9-16 wp-has-aspect-ratio\">\n<div class=\"wp-block-embed__wrapper\">\n<\/div>\n<\/figure>\n<p class=\"wp-block-paragraph\">\n<h2 class=\"wp-block-heading\"><strong>When agents build the supply chain<\/strong><\/h2>\n<\/p><p class=\"wp-block-paragraph\">The supply chain today is a revolving door for opportunistic attackers like TeamPCP and ShinyHunters who exploit transient dependencies and other vulnerabilities, often needing only a short window of time to filch credentials and information.<\/p>\n<p class=\"wp-block-paragraph\">How are CISOs to combat these risks when AI agents themselves are pulling base images, choosing dependencies, and assembling code\u2014autonomously and without human oversight? After all, in an autonomous supply chain, traditional methods of scanning and patching after building are no longer feasible.\u00a0<\/p>\n<h2 class=\"wp-block-heading\"><strong>Keeping humans in the loop<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">The panelists shared several best practices. Zach urged keeping humans in the loop for picking clean, secure dependencies, especially upstream libraries, and setting up blessed images for agents to choose from. Gavriel recommended setting a minimum release age of seven days for images and minimizing dependencies\u2014even safe ones.<\/p>\n<h2 class=\"wp-block-heading\"><strong>A training-wheels approach<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Gavriel also suggested a training-wheels approach to experimenting with agents, starting out using unpermissioned data to build skills and avoid sensitive data issues. \u201c<em>Unlocking the value today is important,\u201d <\/em>he said, <em>\u201cbut even more important is having people build the skills of working with agents, because what\u2019s going to be coming in the coming months and years is going to totally exceed anything that we have today. So, it\u2019s really about building the muscle memory, building the skills.\u201d<\/em><\/p>\n<h2 class=\"wp-block-heading\"><strong>Layer security to limit the blast radius<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">My take? Opportunistic attackers are simply exploiting an ecosystem that\u2019s inherently flawed and broken and that unfortunately won\u2019t get fixed within the next six to 12 months. Until then, developers should assume these attacks will continue and prepare for them by layering security to limit the blast radius. That means reducing privilege, reducing third-party access to their environment, and using immutable tags, digests, and SBOMs (Software Bill of Materials) to lock manifests and enable rapid detection of poisoned images. And, yes, outsourcing the risk to a trusted build environment like Docker that provides clean, hardened images so you\u2019re starting from a clean foundation.\u00a0<\/p>\n<h2 class=\"wp-block-heading\"><strong>MCP\u2014the new shadow IT?<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">The panelists rounded out the discussion with a focus on the security implications of using MCP in developer environments. MCP (Model Context Protocol) is a standard\u00a0that allows LLMs to access external data and use tools, potentially making AI more powerful and reliable.<\/p>\n<p class=\"wp-block-paragraph\">The consensus was that centralized, secure governance is crucial for productivity and risk management. Gavriel stressed the importance of proper version control, credential management, and a \u201cgolden repository\u201d of verified tools. Zach advocated for centralized management to avoid individual tool dependencies and ensure minimal access.\u00a0<\/p>\n<h2 class=\"wp-block-heading\"><strong>Making it safe and easy to run MCP servers<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">And Docker? About a year ago, we introduced an open source <a href=\"https:\/\/www.linkedin.com\/pulse\/docker-mcp-gateway-open-source-secure-infrastructure-agentic-ai-b2gvc\/\" rel=\"nofollow noopener\" target=\"_blank\">MCP Gateway<\/a> that serves as a chokepoint between agents and external tools. Routing every tool call through this enforcement point, where it can be authenticated, authorized, and logged before it reaches the external system, enables a wide range of agents to access trusted catalogs of MCP servers. While it\u2019s not clear to me how long MCPs will remain useful, given the exponential speed with which AI is evolving, Docker MCP Gateway solves an important challenge today. Like Docker Sandboxes, it makes enforcement strict instead of advisory.<\/p>\n<h2 class=\"wp-block-heading\"><strong>A once-in-a-generation opportunity\u2014and challenge<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Enabling dev environments to take advantage of agentic AI is a once-in-a-generation opportunity, and CISOs are accountable for making sure the rush to do so doesn\u2019t devolve into the Wild West.<\/p>\n<p class=\"wp-block-paragraph\">Moriah closed the panel with a provocative thought: <em>\u201cSix months from now, enterprises are all going to be running agents at scale. The one key success factor will be whether governance was present from day one or got bolted on after the first major incident.\u201d<\/em><\/p>\n<p class=\"wp-block-paragraph\">In the choose-your-own-adventure reality of agentic AI today, what kind of security leader will you be?\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\n<\/p>","protected":false},"excerpt":{"rendered":"<p>What does it take to secure AI agents without slowing developers down? A recent panel explored the answer\u00a0 I recently [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":94,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[4],"tags":[],"class_list":["post-4626","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-docker"],"_links":{"self":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/4626","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/comments?post=4626"}],"version-history":[{"count":0,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/4626\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media\/94"}],"wp:attachment":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media?parent=4626"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/categories?post=4626"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/tags?post=4626"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}