Episode Summary
Executive Summary: Maxim Barkogan argues that AI agents are rapidly creating a new security surface: enterprises are adopting autonomous coding and workflow agents faster than existing controls can handle, making agent oversight a foundational need. ONIX trains specialized models to watch other agents, using lightweight, high-precision systems to decide when to escalate to smarter review, with the broader goal of governing advanced AI behavior and building trust in an increasingly agentic enterprise stack.
Main Topics: Why ONIX was founded around agent actions (Priority: 5/5): The company’s thesis emerged from AutoGPT and the intuition that autonomous agents would eventually perform complex, high-stakes actions in enterprise environments, requiring new oversight beyond chatbot DLP. ONIX’s product: AI to oversee AI (Priority: 5/5): ONIX trains models and builds a security control plane that monitors autonomous agents, flags illegitimate actions, and helps enterprises hook all AI systems into a governance layer. Enterprise adoption is shifting toward autonomous agents (Priority: 5/5): Maxim says most enterprise AI usage is now autonomous coding agents and assistants, with low-code automations second and first-party agents a small minority, and that autonomous agents are the fastest-growing category. Why existing security tools fall short (Priority: 5/5): Identity, endpoint, network, and API security were designed for more deterministic software; they lack the context to understand what flexible agents intend to do and cannot adequately constrain them without crippling usefulness. Specialized models and selective escalation (Priority: 4/5): ONIX argues that a naive approach of having a large agent monitor every action would be too expensive and slow, so it instead trains smaller models to identify the moments that warrant deeper scrutiny—analogous to blitz chess intuition. Mechanistic interpretability and long-term AI control (Priority: 4/5): Beyond enterprise security, ONIX believes understanding model internals, weights, activations, and reasoning patterns will be part of controlling advanced AI systems over time. Israel’s security + AI talent advantage (Priority: 3/5): Maxim describes ONIX’s team as blending cyber and math-heavy AI expertise from Israeli intelligence and argues Israel is catching up quickly as an AI infrastructure and frontier-model hub.
Key Arguments: Autonomous agents are creating exponentially more actions, so human-in-the-loop review will not scale for enterprise deployment. Enterprises cannot simply stop adoption; they need controls that reduce the probability of illegitimate or incorrect agent actions. Traditional security tools are insufficient because they do not know what an agent is thinking or planning to do. A proxy/policy-engine approach is only an integration method and does not solve the core problem of judging intent and legitimacy. Running a powerful model for every agent action would be too costly and too slow, so specialized lightweight models are needed. A security vendor must be independent of the AI vendor; buyers do not want the same company that makes the model also certifying its safety. Large labs are unlikely to fully solve this alone because enterprises use many vendors, many models, and do not want model providers training on sensitive historical behavior data. Mechanistic interpretability and internal model understanding will likely become part of the long-term solution for controlling advanced AI.
Data Points: Typical enterprise AI usage mix: Over 50% autonomous coding agents and assistants - Maxim’s estimate of the average enterprise’s current AI deployment mix Typical enterprise AI usage mix: 45% low-code automations - Second-largest category in typical enterprise deployments Typical enterprise AI usage mix: 2% first-party agents - Smallest category; enterprise-built custom agents remain rare Scaling concern: 100x, 1000x, a million x - Illustrative scale increase in agent actions that makes human review impractical Company age: Two-year-old company - Used to explain why Fortune-scale customers might initially seem unlikely to trust ONIX Market size view: $100 billion plus opening - Maxim’s estimate of the opportunity for independent AI control and governance Large AI companies: $10 trillion companies - Hypothetical scale of future AI companies that would need independent oversight
Pivotal Quotes: "As you're exponentially doing more things with the eyes, you're gonna start having really bad actions happen." — Host / transcript opener: Sets up the central risk thesis: more autonomous actions create more opportunities for dangerous mistakes "We train models and build agents that can oversee other agents." — Maxim Barkogan: Core description of ONIX’s product and technical approach "If you're a security vendor, you're not going to trust the vendor of a product to tell you that this product is not going to mess your environment." — Maxim Barkogan: Explains why independent AI security/governance is needed rather than self-certification by model vendors
Implications: AI adoption is moving from chat interfaces to autonomous action, forcing enterprises to add independent controls, not just permissions. Security buyers should expect a new category of AI governance tools, while vendors and labs will need to coexist with independent overseers.