AI Agents Need Better Security | St. Luke's Associate CISO Krista Arndt | Recorded Live at AI4 2026 artwork

AI Agents Need Better Security | St. Luke's Associate CISO Krista Arndt | Recorded Live at AI4 2026

The CAIO Connect Podcast (Chief AI Officer Connect Podcast)

August 9, 2026

How do you secure AI agents without slowing innovation? Recorded live at AI4 2026 in Las Vegas, Sanjay Puri speaks with Krista Arndt, Associate CISO at St.
Speakers: Krista Arndt, Sanjay Puri

Topics: Technology, Business, Management

**Krista Arndt** (0:00)
Data loss prevention isn't just a tool, it is a program. Identity is not just a tool, it's a program. And so I think if you get those core acumen correct, because data loss prevention and identity are two really core critical controls on this, and build that from the, again, core traditional controls and then layer the non-traditional controls on, like contextual data loss prevention, for example, and tighter rails around agentic chains and non-human identities, I think that that is the way that I would explain good hygiene to a Chief AI Officer.

**Sanjay Puri** (0:43)
So welcome to AI4, Krista. It's such a pleasure to have you here.

**Krista Arndt** (0:46)
Yeah. Thank you for having me. I'm excited for our conversation.

**Sanjay Puri** (0:49)
Wonderful. Krista, you, within your organization, obviously use AI agents to provide security, as well as you monitor agents that are kind of running around in the organization. And AI agents right now, for our Chief AI Officers, for CIOs, CTOs are a very important thing.
How do you manage this duality of using them yourselves, but also monitoring? Is there a little bit of a conflict issue there?

**Krista Arndt** (1:20)
So I think one of the most important things is to have a really solid core hygiene around your identity space. And so with AI, non-human identity is really important, and to get a handle on security for non-human. And a lot of organizations have a lot of technical debt around non-human identities as it is. Service accounts, for example, no owners, you don't know what it's going to break if you change the password, what they're really doing, because your organization has been around so long. So I will tell you that if you had a good core hygiene foundation and limit and use the least privileged principles, and you do it in an environment that is secured, so if you dedicate an environment or part of your environment, you implement things like micro-segmentation, for example, to make things more secure.
I don't really think it is a conflict. I think that we are being good stewards and showing folks how to use it safely, and really showing the organization that you can use it safely and not be afraid to usher in new technology, especially in institutions like health care, where they are focused on serving patients, and this technology totally upends what they are used to day to day.

**Sanjay Puri** (2:37)
For Chief AI Officers who are working in a regulated environment, what are some basic principles of good hygiene?

**Krista Arndt** (2:47)
I would say a CMDB or an asset inventory, I know you hear the term CMDB a lot, and I don't really like to throw that around as a control. I like to say know your assets, know what your hardware is, your identity assets, really. And so in AI, we're focusing on identity assets and what they have access to, so what kind of data.
I would say good hygiene includes a good data loss prevention program. Data loss prevention isn't just a tool. It is a program. Identity is not just a tool. It's a program, and so I think if you get those core acumen correct, because data loss prevention and identity are two really core critical controls on this, and build that from the, again, core traditional controls, and then layer the non-traditional controls on, like contextual data loss prevention, for example, and tighter rails around agentic chains and non-human identities, I think that that is the way that I would explain good hygiene to a Chief AI Officer.

**Sanjay Puri** (3:47)
The Chief AI Officer and the CISO role, do you see the CISO people associated with being Dr. Noh? The Chief AI Officer wants to implement a lot of exciting projects because they're under pressure, do AI.
Do you see any conflict or is there a good complementary relationship here?

**Krista Arndt** (4:09)
There can be a good complementary relationship. I think to be a successful Chief AI Officer, you have to be security minded to do it effectively.
So having an AI control plane as a Chief AI Officer also gives you a really desirable telemetry that you can use from a business perspective to say what are my agents doing, how can I use them more efficiently and more effectively. So I think as long as both folks have the right mindset, I think it is a powerful partnership between an AI Officer and a Security Officer. Really, I see a lot of Security Officers who have helped build AI programs and organizations now moving over into the Chief AI Officer role, or I just met a Chief AI Security Officer dedicated to AI because they used so much in an organization yesterday. And so for us, for example, I have to give kudos to my CIO, my Chief Medical Information Officer and my CISO, my leader have really worked tightly together with myself as the Associate CISO and our architect to build it out together. And so there needs to be a desire for that partnership and an understanding that everybody's knowledge and everybody's perspective is complimentary to each other.

17 more minutes of transcript below

Thousands of transcripts fetched by people building searchable podcast archives

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire. Prices exclude VAT, added at checkout for EU customers. Not what you expected? Email us within 14 days with 20 or fewer credits used and we refund the pack in full.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/YOUR_EPISODE_ID