The Three-Layer Strategy for Autonomous Agent Governance with Joe Hladik and Amit Malik

Apr 21, 2026

The race for AI dominance has created a dangerous imbalance between business velocity and cyber resilience. In this episode, host Caleb Tolin is joined by ⁠Joe Hladik⁠, Head of ⁠Rubrik⁠ Zero Labs, and Staff Security Researcher ⁠Amit Malik⁠ to break down the findings of their latest report on agentic adoption. The discussion centers on the Agentic Paradox. This is the technical reality that tools designed to automate high-level tasks are inherently built to find the most efficient path around obstacles, including existing security policies.

A primary focus is implementing a three-layer framework for AI Operations. This model targets the Tool Layer, where agents interact with databases; the Cognitive Layer, which serves as the LLM brain; and the critical Identity Layer. The conversation explores stories in which agents, without malicious intent, have caused catastrophic data loss simply by following an optimized logic path. These instances prove that agents need not be sentient to be destructive when they lack proper human-in-the-loop checkpoints.

Technical hurdles of Identity Resilience are also addressed, specifically the explosion of non-human identities that spin up and down like elastic cloud infrastructure. The episode examines the fear index regarding job security, noting that 92% of leaders fear for their roles post-breach. Joe and Amit join Caleb to explore the evolution of personal liability for CISOs and the urgent need to move from basic visibility to deep observability. This is a forward-looking briefing for leaders who recognize that, in an era of autonomous routines, the human must remain the ultimate command-and-control center.

What You’ll Learn

  • Define the agentic paradox to understand why AI efficiency naturally compromises traditional security guardrails.
  • Implement a three-layer framework to secure the tool, cognitive, and identity components of AI.
  • Transition from basic visibility to deep observability to track autonomous decision-making in real time.
  • Mitigate prompt injection risks by auditing the input and output flows of the cognitive layer.
  • Utilize ephemeral containers to sandbox agentic tools and prevent unauthorized database alterations.
  • Manage the elasticity of non-human identities to maintain control over rapidly spinning AI agents.
  • Anchor AI operations with human-in-the-loop checkpoints to ensure integrity during high-stakes executions.

Episode Highlights
Defining the Agentic Identity and Autonomous Routines
Revenue vs. Resilience: The Drivers of AI Urgency
The Three-Layer Framework for Agentic Defense
Shadow AI and the Rise of Invisible Insider Threats
The Context Gap: Why Rolling Back AI Actions is Hard
The CISO Fear Index and Personal Liability Post-Breach
Visibility vs. Observability in Elastic Identity Environments

Host: Caleb Tolin (linkedin.com/in/calebtolin)
Guest: