Post B6tYq3qaYTSRh75qEa by neurovagrant@masto.deoan.org
 (DIR) More posts by neurovagrant@masto.deoan.org
 (DIR) Post #B6tYq3qaYTSRh75qEa by neurovagrant@masto.deoan.org
       1 likes, 0 repeats
       
       I'm just a SecOps and Threats guy, not selling a damn thing, so whenever you talk about AI "democratizing" capabilities to the average enterprise employee, I want you to keep in mind for me that short of herculean new spends and deliberate frameworks, you're democratizing some software capabilities but without the development, QA, monitoring, and responsibility offload. We've been working with the concept of Third Party Risk Management for years and are barely in its infancy - yet even so, none of the lessons TPRM has taught us so far have been natively incorporated into AI products, and especially not executive or board mandates demanding employees increase AI use or agentic deployment.Simply put, none of the forethought or structure that real software development requires, little of the centralized administration or visibility for defenders to work with, but all of the consequences. Whenever someone in your presence starts talking about how employees should script Gems or Projects or Skills or gizzards or whatever the customized agentic buzzword of the day is, and give it trusted access to their email or calendar or, god forbid, customer data, remember that it has precisely zero of the attention and accountability that Third Party Risk Management involves. And TPRM is a critical path.