You Can't Secure an AI Agent with Software
Failed to add items
Add to cart failed.
Add to wishlist failed.
Remove from wishlist failed.
Follow podcast failed
Unfollow podcast failed
-
Narrated by:
-
Written by:
Charles Guillemet is CTO of Ledger and the founder of the Donjon, Ledger's internal offensive security lab whose job is to break the company's own products before attackers do. He spent a decade in cryptography and hardware security before Ledger, including designing secure integrated circuits.
His argument is blunt: you cannot secure an AI agent with software alone. As agents start moving real money, API keys and trust scopes leave no physical verification layer, and Charles makes the case that hardware has to sit in the loop.
This one turned into a wide-ranging thought piece (and some debate) on what the agentic economy actually looks like, and how to stay safe inside it.
We cover:
- Why Charles thinks "securing an AI agent" with software permissions and API keys is a false promise
- The economic asymmetry between attackers and defenders, and how AI is collapsing it
- How a policy engine plus a hardware-enforced signature can delegate rights to an agent safely
- Why Charles thinks the agentic economy settles on blockchain rails over Visa and Mastercard
- Secure elements, HSMs, and zero-knowledge proofs as execution-integrity guarantees
- How Ledger uses hardware authorization internally for passkeys, signed releases, and multisig
- A practical way to classify assets by threat model and match security to value
(0:00) Why securing an AI agent in software alone is impossible
(0:30) Delegating execution power inside your security perimeter
(2:28) The attack-defense asymmetry AI is erasing
(6:00) The alignment problem and delegating rights to agents
(9:24) Policy engines, intents, and hardware-enforced signatures
(13:19) From developer experience to agent experience
(15:12) Secure elements, HSMs, and execution integrity
(20:00) Zero-knowledge proofs, proving without revealing
(27:24) Convincing the skeptics on agent-driven payments
(34:49) Why Ledger bet on dedicated hardware
(36:15) Hardware as a determinism layer for agents
(38:52) How Ledger uses hardware authorization internally
(43:42) Classifying assets by threat model
(46:55) When attack and defense become symmetric
(48:44) Deepfakes, voice cloning, and the scam wave
(50:04) Closing thoughts on staying safe in the agentic economy
Connect with Charles Guillemet:
- LinkedIn: https://www.linkedin.com/in/charles-guillemet/
- Twitter/X: https://x.com/P3b7_
- Ledger: https://www.ledger.com
Connect with Chain of Thought host Conor Bronsdon:
- Newsletter: https://newsletter.chainofthought.show/
- Twitter/X: https://x.com/ConorBronsdon
- LinkedIn: https://www.linkedin.com/in/conorbronsdon/
- YouTube: https://www.youtube.com/@ConorBronsdon
More episodes: https://chainofthought.show