AI agents are running on developers' machines with the same access as the people who use them. Recent attacks have shown attackers exploiting exactly that, hijacking trusted developer tools to steal credentials and secrets straight off people's laptops.
In this episode of ClearPoint Unlock, Chief Operating Officer Paul Scott sits down with Lead Engineer Will Verland to unpack why AI security has become everyone's problem, not just engineering's. They walk through real-world attacks on agentic AI tools, showing how attackers have learned to turn trusted developer workflows against the people using them.
Will introduces the four rings of attack surface for agentic AI, from the model itself through to sandboxing, network controls, and code base hygiene, and explains why the principle of least privilege is the single most effective control available right now. Paul brings the risk owner's perspective, connecting the conversation back to ClearPoint's ISO 27001 programme and the questions clients are increasingly asking about data confidentiality, IP protection, and model training.