SE Radio 733: Max Corbridge on Securing AI Agents

SE Radio 733: Max Corbridge on Securing AI Agents

Author: SE-Radio Team August 14, 2026 Duration: 1:00:09
Max Corbridge, an ethical hacker and red teamer who is co-founder and CEO of Secure Agentics, speaks with SE Radio host Amey Ambade about how AI agents get attacked and what engineers can actually do to defend them. Drawing on years of offensive security work, Corbridge frames agents as a new and largely undefended attack surface: the industry has handed AI systems autonomy and the ability to act in the real world while carrying forward prompt injection, a flaw the frontier labs themselves describe as effectively unsolvable. He likens the moment to the early, lawless days of the web, when SQL injection was everywhere and adoption ran far ahead of security. The conversation builds from first principles as Corbridge explains what separates an agent from ordinary software and why three properties make them hard to secure: they are non-deterministic, their language-model core can be coerced, and they are increasingly interconnected through MCP servers, other agents, databases, and email. Turning to the attack surface, Corbridge lays out his "lethal trifecta" (a vulnerable core, dense interconnection, and security tooling that has not caught up) and contrasts the decades of layered defenses protecting an ordinary email inbox with the thin protection around agents that take autonomous actions on critical systems. The heart of the episode is defense. Corbridge orders practices by leverage: least-privilege access and privilege separation, sandboxing where feasible, imperfect-but-useful guardrails as one layer of defense in depth, and human-in-the-loop for irreversible actions (which he notes is contentious and does not scale). The discussion closes on detecting a compromised or drifting agent, the value of watching an agent's chain-of-thought reasoning alongside its actions, the open-source tooling landscape (including Corbridge's own project, Adrian), and his central advice: build security in proactively, define what good agent behavior looks like up front, and avoid bolting it on after agents have already spread across the business.

For developers who think deeply about their craft, Software Engineering Radio-The Podcast for Professional Software Developers offers a steady, thoughtful conversation about building software. This isn't about chasing headlines or quick tips; it's a deliberate exploration of the principles, patterns, and hard-won insights that define lasting work in the field. The SE-Radio Team creates each episode as original, standalone content, ensuring you get focused depth rather than recycled conference talks. Every ten days, a new installment arrives, alternating between detailed tutorial-style deep dives on specific technologies or methodologies and candid interviews with influential voices and practitioners from across the industry. Tuning in means joining a continuous learning journey where complex topics are broken down with clarity, from system architecture and language design to team dynamics and career development. This podcast serves as a reliable educational archive, a resource you can return to as your experience grows, always anchored in the realities and challenges faced by professional developers every day.
Author: Language: en-us Episodes: 50

Software Engineering Radio - The Podcast for Professional Software Developers
Podcast Episodes
SE Radio 738: Milan Milanovic on the Laws of Software Engineering [not-audio_url] [/not-audio_url]

Duration: 47:28
Milan Milanovic, Microsoft MVP for Developer Technologies and author of the book, Laws of Software Engineering, joins host Giovanni Asproni for a conversation based on the content of his book—a collection of 53 empirical…
SE Radio 737: Owen McGirr on Software Accessibility [not-audio_url] [/not-audio_url]

Duration: 51:09
Owen McGirr, creator of SayIt!, Switchify, and an entrepreneur who builds inclusive technology, speaks with SE Radio host Gavin Henry about software accessibility. For this episode, Gavin emailed the questions to Owen, w…
SE Radio 736: Sahil Walia on Apache Iceberg [not-audio_url] [/not-audio_url]

Duration: 51:27
Sahil Walia, Senior Technical Architect at Snowflake, joins host Robert Blumen for a deep dive into Apache Iceberg. The conversation covers OLAP, data formats, data lakes and lake houses, Iceberg as a data format, column…
SE Radio 735: Vivek Yadav on Regression Testing Microservices [not-audio_url] [/not-audio_url]

Duration: 59:06
Vivek Yadav, an engineering manager at the payment company Stripe, speaks with host Adi Narayan about building regression testing for microservices. Drawing on his work estimating network costs for card payments, Vivek e…
SE Radio 731: Sonali Varde on AI and the Engineering Manager Role [not-audio_url] [/not-audio_url]

Duration: 50:50
Sonali Varde, Senior Software Engineering Manager at LinkedIn, joins host Kanchan Shringi to discuss how AI is changing the role of the engineering manager. They explore how AI is showing up in day-to-day management work…
SE Radio 730: Birgitta Boeckeler on Harness Engineering for AI Agents [not-audio_url] [/not-audio_url]

Duration: 54:14
Birgitta Boeckeler, a Distinguished Engineer and consultant focused on AI-assisted software delivery at Thoughtworks, joins host Priyanka Raghavan for a deep dive into harnesses for AI agents. The episode begins by unpac…
SE Radio 729: Garth Mollett on AI Supply Chain Security [not-audio_url] [/not-audio_url]

Duration: 48:17
Garth Mollet, Senior Principal Product Security Engineer and Technical Advisor for Product Security at Red Hat, joins host Robert Blumen for a discussion of AI supply chain security. They start with the basics of supply…
SE Radio 728: Clare Liguori on AWS Strands SDK for AI Agents [not-audio_url] [/not-audio_url]

Duration: 1:08:39
Clare Liguori, a Senior Principal Engineer who works on developer tooling and agentic AI at Amazon Web Services, speaks with host Sri Panyam about the Amazon Strands Agents SDK. This episode explores the philosophy, desi…