
Why I Dont Trust Your AI Agent | Kane Narraway, Canva
With over 200 AI security vendors in the market, how does an enterprise CISO decide whether to build a custom solution, buy an off-the-shelf product, or just wait out the hype? In this episode of the AI Security Podcast, Ashish and Caleb are joined by Kane Narraway , Head of Enterprise Security at Canva, to debate the realities of AI security in modern enterprises. Kane breaks down why simply sandboxing AI agents doesn't work for workforce productivity, explaining that an overly restrictive sandbox renders an agent useless because it inherently needs access to external files and databases to do its job. We dive deep into the "Confused Deputy" problem, the struggle of granting granular least privilege to AI tools (like letting a bot summarize only Caleb's emails), and whether the old-school concept of network proxies is about to make a massive comeback as the ultimate control layer for AI routing and authorization. Finally, Kane shares why he believes the scariest near-future threat isn't malware, but contractors utilizing "Bring Your Own Agent" (BYOA) in enterprise environments. Questions asked: (00:00) Introduction to AI Agents in the Enterprise(01:50) Kane Narraway’s Background (Digital Forensics, Atlassian, Shopify, Canva)(02:50) The Build vs. Buy Debate in the Era of 200+ AI Security Vendors(09:00) Using Wrappers and Harnesses to Control Vendor APIs (Island Browser Example)(11:00) Why GitOps and PRs are Better for AI Configuration than MCP Deployments(13:00) The "Confused Deputy" Problem: Single-Player vs. Multi-Player AI Bots(16:50) How to Handle Agent Identity: "On Behalf Of" (OBO) vs. SPIFFE / NHI(22:50) Why Sandboxing AI Agents Fails for the General Workforce(28:20) Intent-Based Security and the Lack of Granular Access Controls(29:40) Are Proxies the Next Gen Firewall for AI Agents?(34:00) The Terrifying Future of "Bring Your Own Agent" (BYOA)(38:50) The "Gravel Road" Strategy for Managing Shadow IT and Vibe Coding(42:00) Dealing with Vendors Trying to Exploit Shadow IT Land Grabs(49:30) What Security Leaders are Over-Indexing On (Discovery vs. True Access)(50:40) The "You Laugh, You Lose" Cybersecurity Joke Challenge


