Why Social Engineering Now Works on Machines artwork

Why Social Engineering Now Works on Machines

AI + a16z

December 2, 2025

Ian Webster built PromptFoo after watching 200 million Discord users systematically dismantle his AI agent—now Fortune 10 companies pay him to break theirs before customers do.
Speakers: Ian Webster, Joel de la Garza
**Ian Webster** (0:00)
This year was all about spinning up AI and some of those initial use cases. I'm on board with 2026 as the year of the agent.

**Joel de la Garza** (0:08)
It's just absolutely mind-blowing to me that we have computers that persuasion can work on.

**Ian Webster** (0:12)
A lot of security teams were scrambling to catch up with these initiatives and initial prototypes.

**Joel de la Garza** (0:18)
Every new platform cycle, security always lives at the end, because everybody's going too fast to think about security.

**Ian Webster** (0:23)
If you take an untrusted user input, if you have access to sensitive information or PII, and if you have some sort of outbound communication channel or exfiltration path, then your agent is fundamentally insecure. I think it's going to be pretty exciting year ahead.

**SPEAKER_3** (0:43)
Every company is racing to deploy AI agents. Almost none of them are ready for what happens next. Here's the problem. We spent a decade learning how to secure deterministic systems, SQL injections, buffer overloads, access controls. But AI agents don't work like that. You can't patch persuasion. You can't firewall social engineering. And the attack surface isn't code, it's conversation. Ian Webster saw this firsthand at Discord, building an agent for 200 million users. Most of his team's time wasn't spent on features. It was spent on security, trust and safety. Because when you give an AI access to data and the ability to take actions, you've created what's now called the lethal trifecta and traditional security tools are useless. That's why he built PromptFoo, not as a security person, but as an engineer who hit a wall. Now, Fortune 10 companies use it to simulate thousands of adversarial conversations, testing whether their agents will leak data, break access controls, or get socially engineered by a well-crafted emoji. In today's conversation, Ian sits down with a16z's Joel De La Garza to discuss if 2026 is really the year of the agent and whether enterprises can secure them before something breaks spectacularly.

**Joel de la Garza** (1:58)
Today, I'm pleased to be speaking with Ian Webster, the founder and CEO of PromptFoo, AI agent testing company that focuses on security. And this whole series of conversations we've been having with founders has been really focused on what we're seeing in the market, which is that every corporate customer, every corporate CIO, every corporate CTO we talk to, has some sort of agentic thing that's being built. Now, it could be a customer service agent that a large airline is building, or it could be a gaming company building something to replace the NPCs, right? There's all sorts of stuff that's happening. And it's great to have you on because we know that you are an expert in agent and agentic security, having done a ton of work in this space. And we'd love to maybe just get your really quick take on what do you think an agent is and how are people thinking about agents at the current time to maybe frame the discussion.

**Ian Webster** (2:52)
Yeah. I think the way that I would start out, just very simply, an agent is what you get when you have an LLM and allow it to take actions. So if you're hooking up APIs to it or anything where it can interact with the outside world. And in terms of why that's important and where it's going, I mean, at PromptFoo, we work with some of the largest companies in the world, Fortune 10s, Fortune 50s. And what I have been hearing very consistently is, this year was all about spinning up AI and some of those initial use cases around internal chatbots and RAG. But without fail, everyone on their roadmap has like, we're going to start hooking it up with Salesforce or with other internal systems. And that's the plan for next year. So, I definitely think, or like I'm on board with 2026 is the year of the agent, in the sense that's what we keep hearing whenever we work with folks on the corporate side.

**Joel de la Garza** (3:52)
Well, and you've been incredibly busy and it was hard to schedule this podcast. So, I assume that's an indicator that people are really engaged in this sort of stuff.

**Ian Webster** (3:59)
Yeah, we are working hard for sure. And yeah, I mean, we saw like a big step up at the beginning of this year, as some of the like AI initiatives and budgets kicked in. I think we're going to see another probably even bigger step next year, just in terms of like the amount of activity and as well as what needs to be tested and secured.

**Joel de la Garza** (4:17)

20 more minutes of transcript below

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/1000739269923