Episode Summary
Executive Summary: This episode argues that AI discovery must go beyond finding LLMs and agents to include identities, APIs, data flows, infrastructure, and downstream effects. Tim Ebers explains that AI risk is dynamic, behavioral, and edge-based, so organizations need continuous discovery, policy-driven governance, and runtime enforcement rather than static inventories or quarterly scans.
Main Topics: AI discovery must include more than AI assets (Priority: 5/5): The conversation reframes AI discovery as a broader visibility problem that includes models, endpoints, connected services, and the data moving between them—not just LLMs and agents. Identity as the central control point (Priority: 5/5): Tim argues identity is the most important element because transactions are performed by people or agents on behalf of someone else, making authentication and authorization foundational to AI governance. Shadow AI emerges at the edges of productivity (Priority: 4/5): Shadow AI typically appears first among developers and business users trying to move faster, often before it reaches formal production environments. Risk lives in the relationships and edges (Priority: 5/5): The same agent can be low-risk or high-risk depending on which tools it can call and which data sources it can reach; authorization and tool relationships shape exposure. Continuous discovery is required in fast-changing environments (Priority: 5/5): AI systems can change in minutes, so discovery must be always-on and traffic-based rather than quarterly or spreadsheet-driven. Visibility must lead to governance and enforcement (Priority: 4/5): Once AI assets are discovered, organizations need observability, policy, runtime protection, auditability, and ownership to actually govern misuse and data leakage.
Key Arguments: AI discovery cannot be limited to models and agents; it must also cover infrastructure, APIs, gateways, data stores, and the connections between them. Security teams need to understand data flows and downstream effects because AI is non-deterministic, unlike traditional systems where logs alone were often sufficient. Identity is the most important control layer because AI actions increasingly occur through agents acting on behalf of humans or services. Shadow AI is usually driven by productivity pressure, especially among developers and business users, so blocking it outright can create resistance and push behavior further underground. Policies should be used to watch and notify on behavior rather than immediately prevent all activity, enabling safer collaboration with users. Risk is not a fixed property of an AI asset; it depends on the edge between the agent and the tool or data source it can access. A read-only search API is materially different from a payment or email-send API, even if the same agent uses both. Continuous discovery is necessary because AI deployments, dependencies, and permissions can change faster than quarterly scanning can detect. After visibility, organizations need enforcement capabilities such as blocking unsanctioned models, stopping misbehaving sessions, and preventing PII egress. Audit and ownership are major gaps: organizations must prove what happened and determine who is responsible for each AI system. AI discovery should be treated as additive to existing API and cloud discovery, not a replacement for them.
Data Points: Discovery cadence vs deployment cadence: Quarterly scans are no longer sufficient - Tim says AI environments change so quickly that quarterly discovery leaves organizations behind Change frequency: 10 to 15 times - He notes that by the time an environment is cataloged, it may already have changed 10 or 15 times over Time horizon of change: Minutes - AI services can be deployed, connected, and changed in minutes, requiring always-on discovery Scope of discovery: AI, APIs, applications, infrastructure, data, identities - The episode repeatedly emphasizes that AI discovery must span the entire ecosystem
Pivotal Quotes: "AI discovery isn't just AI." — Host: Episode theme and central framing for the discussion "The risk relationship isn't really a property of the asset, it's the property of the edges." — Tim Ebers: Explaining why authorization and connectivity matter more than the AI asset alone "The days of quarterly scans for this particular thing are over." — Tim Ebers: On the need for continuous, always-on discovery in rapidly changing AI environments
Implications: Enterprises need continuous, identity-aware AI discovery tied to policy and runtime control. Static inventories are obsolete; organizations must monitor behavior, protect data, and govern AI at the edges to avoid blind spots and shadow AI risk.
About Code Story
Code Story is a podcast featuring startup founders, tech leaders, CTO's, CEO's, and software architects, reflecting on their human story in creating world changing innovation, disruptive digital products. Their tech. Their products. Their stories.