AI Security & the Agent-Ready Web: Experts Weigh In artwork

AI Security & the Agent-Ready Web: Experts Weigh In

The AI Native Dev - from Copilot today to AI Native Software Development tomorrow

June 16, 2026

What does it mean to build securely when agents can negotiate their own guardrails? And what happens to the web — CLIs, frameworks, even the browser itself — when the primary user is no longer human? At AI Native DevCon London, Simon Maple sat down with two panels of experts to find out.
Speakers: John Groetzinger, Liran Tal, Joseph Katsioloudes, Dana Lawson, Maximiliano Firtman, James Moss, Simon Maple
**John Groetzinger** (0:00)
I mean, it's really an unsolved problem, largely, you know, because a lot of times, people have way too much confidence in the agent, and they get very lazy, and that's what concerns me the most.

**Liran Tal** (0:07)
Imagine a skill or something that does an action, but then to fetch more information, to fulfill that, they get that from an authoritative source, which could have been prompt-injected. That is the invisible part, where that's not entirely obvious how that works.

**Joseph Katsioloudes** (0:22)
At the end of the day, the agent is going to be able to negotiate the guardrail. Eventually, this access is going to get breached, and that's the hard truth we have to accept.

**Dana Lawson** (0:33)
The dependency on the GitHub workflow is going away, because your code is just not that precious.

**Maximiliano Firtman** (0:41)
An agent will actually find a way to get into your website, but if you want to make things easier, cheaper and faster, well, WebMCP lets you do that.

**James Moss** (0:52)
We don't need to apply the last 25 years of software engineering to the tools of the next 25 years.

**Dana Lawson** (0:58)
You will be left out. You will be replaced.

**Simon Maple** (1:03)
The AI Native Dev is a podcast for developers and engineering leads at the cutting edge of AI and agentic coding. Join your hosts, Guy Podjarny and me, Simon Maple, every week, as we chat with the most exciting voices in AI and tackle the biggest questions facing developers today.
This is the AI Native Dev.
Hey everyone, hope you're enjoying the episode so far. Our team is working really hard behind the scenes to bring you the best guests, so we can have the most informative conversations about agentic development. Whether that's talking about the latest tools, the most efficient workflows or defining best practices. But for whatever reason, many of you have yet to subscribe to the channel. If you're enjoying the podcast and want us to continue to bring you the very best content, please do us a favor and hit that subscribe button. It really does make a difference and lets us continue to improve the quality of our guests and build an even better product for you. All right, back to the episode. Hi, Simon Maple here. Welcome to another episode of the AI Native Dev. We've just wrapped up another amazing AI Native DevCon in London. And while we were there, we got some really smart people together to talk about some of the most interesting topics around agentic development today. Coming up, we have my conversation with Netlify's Dana Lawson, author and educator Max Firtman, and Tessl's very own James Moss, talking about the future of AI development for web applications. But first, the subject is security. And I sat down with Sneaks Liran Tal, Joseph Katsioloudes from GitHub, and John Groetzinger from Cisco. Enjoy.
All of you, welcome. How are you all doing?

**Liran Tal** (2:44)
Great. Thank you for having us.

**Simon Maple** (2:46)
Absolutely. Enjoying DevCon?

**Liran Tal** (2:47)
Of course.

**Joseph Katsioloudes** (2:48)
Fantastic energy here today.

**Simon Maple** (2:50)
It's good fun, isn't it? So why don't we just do a very, very brief intro. Tell us a little bit about yourself, 10, 15 seconds. Let's start left to right.

**John Groetzinger** (2:57)
Sure. John Groetzinger, Cisco. That's largely background in firewall.
But recently, the last couple of years, more focused on agentic development and AI solutions.

**Simon Maple** (3:07)
Liran?

**John Groetzinger** (3:08)
Yeah.

**Liran Tal** (3:08)
I've been doing Dev turned into security and DevRel, thanks to Simon who has had that influence on my life. Thank you. I've been doing some AI security research recently, so that's been fun.

**Joseph Katsioloudes** (3:20)
Similar background to all around, security turning more into DevRel, helping developers to ship secure code.

**Simon Maple** (3:26)
Awesome. Well, actually, Liran, you mentioned a little bit around the NPM securities and vulnerabilities and things like that. Why don't we start there and let's talk a little bit about, I guess, vulnerabilities from a typical traditional software space to what we're looking at now.
I know you, Snyk and others are disclosing MCP CVEs as well. Is MCP security and AI security generally now, where NPM was like 15, 20 years ago, where dependencies coming out and people just using them because they feel like there's a massive performance increase, but they're just lacking in security skills?

**Liran Tal** (4:11)
Yeah, I think there is an aspect of that to an extent somewhat. It's the same issues and somewhat somewhere new.
Whether the MCP server, for example, that you're using is actually vulnerable or not. It's the aspect of the security of the MCP server itself. Then there's the consumer side of it. Whether the MCP server you're using, are you taking it from official places, is it trusted? When MCP came out, it was very high-pitched and like, let's use the latest so people would just run it off as command strings with UVX or NPX, and then the MCP server at latest. So they'd get the latest thing and you could rug pull them, and they would just get new dependencies or whatever with code in there. So from that aspect, we haven't learned to instill the right practices when we're consuming MCPs.

57 more minutes of transcript below

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/1000772960427