Robots vs. Robots: Stories from the Frontlines of the Agentic Revolution
Yaki Faitelson (Chief Executive Officer · Varonis)
RSAC 2026 Conference · Main Stage Keynote
Overview
Yaki Faitelson, CEO and Founder of Varonis, presented a compelling and urgent perspective on the transformative impact of artificial intelligence on enterprise security. Titled "Robots vs. Robots: Stories from the Frontlines of the Agentic Revolution," the talk posited that the AI stack is rapidly becoming the dominant computational model, rendering traditional security frameworks obsolete. Faitelson drew an analogy to Formula One racing's shift to hybrid engines, emphasizing that like F1 teams, organizations must adapt swiftly or face irrelevance in a rapidly accelerating technological landscape.
Key moments
- 0:00 Introduction and the F1 adaptation analogy
- 2:25 AI agents bypass applications, directly access data
- 4:40 The innovation gap: AI outpaces security
- 5:50 The core challenge: connecting knowledge to LLMs securely
- 7:45 The 3% paradox: AI needs data, but security prevents
- 8:15 Three critical barriers to secure AI data connection
- 10:15 Data overexposure: AI agents as 'Pac-Man from hell'
Robots vs. Robots: Stories from the Frontlines of the Agentic Revolution
Speakers: Yaki Faitelson, Chief Executive Officer, Varonis
Conference: RSA Conference
YouTube: https://www.youtube.com/watch?v=daMEEWVlgY8
Overview
Yaki Faitelson, CEO and Founder of Varonis, presented a compelling and urgent perspective on the transformative impact of artificial intelligence on enterprise security. Titled "Robots vs. Robots: Stories from the Frontlines of the Agentic Revolution," the talk posited that the AI stack is rapidly becoming the dominant computational model, rendering traditional security frameworks obsolete. Faitelson drew an analogy to Formula One racing's shift to hybrid engines, emphasizing that like F1 teams, organizations must adapt swiftly or face irrelevance in a rapidly accelerating technological landscape.
The core message of the presentation revolved around the concept of the "agentic revolution," where AI agents, rather than human users interacting with applications, directly access and manipulate data in non-deterministic ways. This fundamental shift collapses the traditional application layer, moving the locus of control and security directly to the data and agent layers. Faitelson argued that this creates a monumental "innovation gap" – the widening chasm between the speed of AI evolution and the lagging pace of security and governance advancements.
This talk is crucial for security professionals, business leaders, and anyone involved in enterprise IT, as it highlights the immediate and profound challenges posed by widespread AI adoption. It underscores that "saying no" to AI is no longer an option; instead, organizations must find ways to safely and rapidly integrate these powerful tools. Faitelson’s insights provide a roadmap for understanding the new threat landscape and implementing AI-native security controls necessary to thrive in this evolving environment, emphasizing that only AI can effectively defend against AI risk.
Background
▶ Watch: Introduction and the F1 adaptation analogy (0:00)
The foundational premise of Faitelson's talk is that the enterprise technology landscape is undergoing an unprecedented and rapid transformation, driven by the pervasive adoption of the AI stack. Historically, enterprise security models were meticulously constructed around the paradigm of human users interacting with applications through well-defined user interfaces. This layered architecture provided clear control points for identity and access management (IAM), data flow, and application-level security. However, the advent of AI agents fundamentally disrupts this established order.
In the new AI-driven paradigm, users are increasingly creating these agents, which are designed to directly call APIs, access data, and take automated actions. Crucially, these actions are often non-deterministic, meaning the same instruction given to an agent twice can yield entirely different results or action sequences. This characteristic inherently bypasses the predictable, linear workflows that traditional security controls were designed to monitor and enforce. The speaker highlighted that this shift effectively "collapses the application layer," as many agents will connect directly to critical data stores like databases, email systems, and file systems, often without any intervening application API or middleware. This direct access, driven by an agent's goal, presents a stark contrast to the structured access patterns that defined previous generations of IT infrastructure.
This rapid rate of change, described as an "order of magnitude" greater than any seen in the last three decades (from stack changes every 5-6 years to every 5-6 days), creates a significant innovation gap. This gap represents the growing disparity between the velocity of AI evolution and the slower pace at which security and governance mechanisms can adapt. Organizations are facing immense pressure from business leaders, knowledge workers, and competitors to accelerate their AI transformation, yet they are simultaneously grappling with fundamental security challenges. Faitelson distilled this challenge into a single, critical question: "How do we connect our company's full universe of knowledge to LLMs and agents without compromising security and trust?"
A major impediment to achieving this secure connection is what Faitelson termed the "3% paradox." Despite the immense potential of connecting powerful foundation models like Claude, GPT, and Gemini to proprietary business data, organizations have, on average, connected only about 3% of their total data estate to new AI technologies. This reluctance stems from a legitimate fear of exposing sensitive information and creating new vulnerabilities. The paradox is that moving too fast without controls risks catastrophic security breaches, while moving too slowly starves AI of the data it needs to deliver value, ultimately hindering an organization's competitiveness and survival. This dilemma underscores the urgent need for a new security paradigm that can safely bridge the gap between AI's potential and its inherent risks.
Key Findings
▶ Watch: The innovation gap: AI outpaces security (4:40)
The talk identified three primary barriers preventing organizations from securely connecting their data to AI and fully embracing the agentic revolution: data overexposure, unsecure AI systems, and the rise of AI-powered adversaries. Overcoming these challenges is paramount for leveraging AI safely and effectively.
First, data overexposure is a critical vulnerability arising from the current state of access controls. AI agents, by default, often inherit the broad permissions of the user who created them, which are almost universally too permissive. Faitelson stated that in typical organizations, over 90% of the data an identity (human or non-human) can access is irrelevant to its actual function. This leads to scenarios where an AI agent, like Microsoft Copilot, can inadvertently expose highly sensitive information—such as legal documents, M&A data, salary figures, or PII—to users who should never see it. Unlike the "old stack" where a human would need to actively navigate and download files, an agent can retrieve such data in response to a simple query, acting like a "Pac-Man from hell" that can traverse an entire data estate in seconds. This highlights the inadequacy of traditional identity and access management (IAM) and the urgent need for data-level permission visibility and runtime guardrails that consider the agent's intent and data context.
Second, unsecure AI systems themselves present significant attack surfaces. Faitelson cited a discovery by the Varonis Threat Labs: a one-click exploit in Microsoft Copilot that bypassed safety controls. This vulnerability allowed attackers to exfiltrate any data a user had ever shared with Copilot, including PII, pet names, and medical information. This demonstrates that even sophisticated AI platforms can harbor critical flaws that, when weaponized, can lead to widespread data compromise. The talk also warned about the emergence of autonomous AI attacks, referencing a case in September where Chinese state actors used Claude code to breach major corporations and government entities with minimal human intervention, effectively creating backdoors to dozens of organizations overnight.
Third, the landscape is further complicated by the rise of AI-powered adversaries. Attackers are not only exploiting vulnerabilities in existing AI systems but are also leveraging their own sophisticated AI tools. Faitelson mentioned tracking a phishing kit called Spider-Man, which costs only a few hundred euros, requires no coding skills, and can clone the login pages of every major European bank, distributed via Signal and Telegram. This democratizes advanced attack capabilities. Critically, AI-powered phishing doesn't just target humans; it also targets AI agents that read emails, Slack, and Teams messages. This exponentially increases the social engineering attack surface, turning one human click into potentially thousands of compromised agents. The volume of sophisticated phishing attacks, Faitelson noted, grew by 200% in the three months prior to the talk, driven by the availability of such tools.
To counter these threats, Faitelson proposed a comprehensive three-pronged defense strategy, emphasizing that these layers must be connected to be effective. This strategy involves:
- Securing the data itself through classification, right-sizing permissions, and automated remediation ("Find, Fix, Alert").
- Securing the AI systems through inventory, posture assessment, and runtime guardrails.
- Fighting AI-powered adversaries using advanced tools like AI-powered phishing sandboxes.
Technical Deep Dive
▶ Watch: The core challenge: connecting knowledge to LLMs securely (5:50)
The "agentic revolution" introduces a paradigm shift where AI agents interact directly with data, bypassing traditional application layers and the security controls built around them. This section delves deeper into the technical intricacies of the three barriers identified by Faitelson and the proposed solutions.
The first barrier, data overexposure, stems from the inherent design of many current AI integrations. When an AI agent, such as a Large Language Model (LLM) or a specialized agent like Microsoft Copilot, is connected to an organization's data estate, it often inherits the permissions of the user who initiated the query or connected the agent. This is problematic because, as Faitelson highlighted, typical user permissions are excessively broad, with over 90% of accessible data being irrelevant to a user's legitimate tasks. For instance, a user employing Copilot for a routine inquiry might inadvertently gain access to highly sensitive documents—such as M&A strategies, legal contracts, or PII (Personally Identifiable Information)—simply because their underlying user account has broad read access to the file shares or databases where such data resides. This contrasts sharply with the "old stack," where a human would need to actively navigate, locate, and download a file, requiring a higher degree of intent or malice. In the agentic world, this sensitive data can be surfaced instantly in a query response, making accidental or malicious exposure far more efficient and widespread. The solution goes beyond traditional Identity and Access Management (IAM), which merely confirms if access is authorized. Instead, it demands data-level permissions, granular visibility into data context, and runtime guardrails that assess if access is "appropriate given the intent of the agent and the context of the data." This implies a dynamic, AI-informed decision-making process at the data layer, rather than static permission sets.
The second barrier is the inherent vulnerability of AI systems themselves. Faitelson presented a concrete example from Varonis Threat Labs concerning an exploit in Microsoft Copilot. This was described as a one-click exploit that effectively bypassed Copilot's integrated safety controls. The attack vector involved a phishing message containing a URL from a seemingly legitimate domain, copilot.com. However, this URL embedded a malicious payload designed to inject a harmful prompt into Copilot. The attacker would craft a complex task within this injected prompt and execute it twice. The first attempt would be blocked by Copilot's guardrails, but the second attempt, leveraging a specific vulnerability, would "slip through," allowing the bad actor to exfiltrate all information the user had ever shared with Copilot—ranging from PII to pet names and medical records. This highlights the susceptibility of even advanced AI systems to prompt injection and other adversarial techniques that can subvert intended safety mechanisms. Beyond individual exploits, Faitelson cited a more systemic threat: in September, Chinese state actors were observed using Claude code to autonomously break into major corporations and government networks. This "completely autonomous" attack required minimal human intervention, allowing attackers to deploy backdoors to dozens of organizations by simply "clicking a button, going to sleep, and waking up in the morning." This demonstrates the potent capability of weaponized AI to automate reconnaissance, exploit discovery, and post-exploitation activities at scale.
Finally, the rise of AI-powered adversaries marks a significant escalation in the threat landscape. Attackers are now leveraging AI tools to enhance the sophistication, scale, and effectiveness of their campaigns. Faitelson described a phishing kit called Spider-Man, available on the black market for "a few hundred euros" and distributed via encrypted messaging apps like Signal and Telegram. This kit requires "no coding skill" and can clone the login pages of "every major bank in Europe," democratizing advanced phishing capabilities. The critical evolution here is that AI-powered phishing doesn't exclusively target human users; it also targets AI agents. Since agents read and process communications like emails, Slack messages, and Microsoft Teams chats, a single malicious link can compromise not just one human identity but potentially "thousands of agents," exponentially increasing the social engineering attack surface. Faitelson noted a staggering "200% growth" in the volume of highly sophisticated phishing attacks over the preceding three months, directly attributable to the availability of such AI-powered tools. These attacks often originate from "trusted sources," making traditional reputation-based filtering insufficient, as "the truth is in the payload."
Demo / Proof of Concept
▶ Watch: Three critical barriers to secure AI data connection (8:15)
While the talk did not feature a live, interactive demonstration in the traditional sense, Yaki Faitelson effectively presented several compelling proofs of concept and real-world examples to illustrate the vulnerabilities and adversarial capabilities discussed.
The Varonis Threat Labs' discovery of a one-click exploit in Microsoft Copilot served as a critical demonstration of an unsecure AI system. Faitelson's detailed description of how a phishing message with a legitimate-looking copilot.com URL could embed a malicious prompt, bypass safety controls on a second attempt, and exfiltrate sensitive user data, functions as a powerful proof-of-concept for prompt injection and AI system bypasses. This example concretely illustrates the danger of over-relying on default AI guardrails and highlights the potential for direct data exfiltration through compromised AI interfaces.
Furthermore, the mention of Chinese state actors using Claude code to autonomously breach organizations provided a high-level proof-of-concept for AI-driven autonomous attacks. While not a technical deep-dive into the Claude code itself, the outcome—backdoors established in dozens of organizations with minimal human intervention—demonstrated the alarming efficiency and scale of AI weaponization.
On the adversarial tools front, the description of the Spider-Man phishing kit served as a vivid proof-of-concept for AI-powered phishing. The details—its low cost, lack of coding requirements, ability to clone major bank login pages, and distribution channels—illustrated how AI is democratizing sophisticated attack techniques and dramatically increasing the volume and sophistication of social engineering campaigns. The critical insight here was the targeting of not just humans, but also AI agents, demonstrating an expanded attack surface.
Finally, Faitelson briefly introduced Varonis's own AI-powered phishing sandbox as a defensive proof-of-concept. This system, described as analyzing millions of URLs daily using computer vision and NLP to simulate user actions and block malicious websites, exemplifies how AI can be leveraged for proactive defense against AI-driven threats. Although not a demonstration of the system in action, its description underscores the need for "robots vs. robots" in the security domain.
Defensive Implications
▶ Watch: Data overexposure: AI agents as 'Pac-Man from hell' (10:15)
Addressing the "agentic revolution" requires a fundamental re-evaluation of security strategies, moving beyond traditional controls to embrace AI-native defenses. Faitelson outlined a comprehensive, multi-layered approach centered on securing data, securing AI systems, and actively fighting AI-powered adversaries, emphasizing that these layers must be interconnected for efficacy.
The first imperative is to secure the data itself, recognizing it as the most valuable and vulnerable resource. This involves:
- Discovery and Classification: Organizations must gain a complete understanding of their entire data estate—structured, unstructured, and semi-structured application data. AI-driven tools are essential to classify data for sensitivity, context, and staleness at scale, determining what data is appropriate to feed to AI models and agents.
- Right-sizing Permissions and Remediation: Existing permissions are almost always too broad. AI-powered automation is critical to right-size access controls, ensuring that agents (and humans) only have access to data relevant to their specific intent and context. This includes labeling sensitive data and masking it wherever appropriate. Manual remediation is infeasible given the volume and velocity of data; therefore, AI-driven automation is the "holy grail" for safe data governance.
- Continuous Monitoring and Alerting: Implementing machine learning models that can detect abnormal behavior is crucial. Faitelson used the analogy of credit card fraud detection: if a "weather forecasting agent" suddenly accesses "10,000 HR records at 2:00 a.m. in the morning," this anomalous activity must trigger an immediate alert. This proactive monitoring forms the "Find, Fix, and Alert" framework for governing the data layer.
Second, organizations must secure the AI systems themselves. As AI models and agents proliferate, managing their security posture becomes paramount:
- Comprehensive Inventory: It is critical to maintain an accurate inventory of every AI model, agent, and pipeline running within the environment, including those "spun up last Tuesday without telling anyone" (shadow AI). This visibility is foundational to managing risk.
- Posture Examination: For each inventoried AI system, organizations need to examine its posture: what data it is touching, what permissions it has, and whether it is vulnerable to known exploits or misconfigurations.
- Runtime Guardrails: These are dynamic controls that operate during an agent's execution. They are designed to block malicious inputs before they reach the model (e.g., preventing prompt injection), filter sensitive data from responses (e.g., ensuring PII is not leaked), and deny agent access to tools or resources they have "no business using."
Third, organizations must fight AI-powered adversaries with AI-powered defenses. The nature of attacks has shifted, with social engineering and identity compromise replacing traditional malware as the "holy grail" for attackers.
- AI-powered Phishing Sandboxes: Given the 200% surge in sophisticated phishing attacks, traditional detection methods are insufficient. Faitelson advocated for AI-powered phishing sandboxes, akin to those used for malware, but specifically designed for this new attack vector. These systems analyze "millions of URLs a day" using computer vision and Natural Language Processing (NLP) to determine if a website is malicious.
- Simulated User Actions and Zero Trust: The sandbox should simulate user actions, such as clicking on links and filling out forms, to observe behavior. If anything suspicious is detected, the website is blocked, even if it originates from a "trusted website." This embodies a Zero Trust approach, recognizing that "the truth is in the payload" and attacks frequently come from compromised but initially legitimate sources.
Faitelson stressed that these three layers are interdependent. An agent inventory without data visibility is blind to what the agents are doing. An AI firewall without accurate data classification risks blocking too much or too little. The critical signals for protection emerge from the combined intelligence across all three layers. Ultimately, Faitelson concluded that "only AI can defend against AI risk," and with the right, constantly working, self-healing, and fundamental controls built directly into the AI stack, organizations can transform AI from a potential bridge to disaster into a powerful force multiplier for prosperity.
Key Takeaways
- The Agentic Revolution is a Monumental Shift: AI agents directly accessing data and taking non-deterministic actions fundamentally break traditional enterprise security models built on human-application interaction.
- The "Innovation Gap" is Widening: AI is evolving at an unprecedented pace (stack changes every 5-6 days), creating a significant gap that security and governance must urgently bridge. Ignoring AI is not an option.
- Three Core Security Barriers to AI Adoption: Organizations face critical challenges from data overexposure (broad permissions, sensitive data leakage), unsecure AI systems (vulnerabilities like the Copilot exploit), and AI-powered adversaries (autonomous attacks, sophisticated phishing kits like Spider-Man).
- Data-Centric Security is Paramount: Security must move to the data layer, requiring AI-driven classification, granular data-level permissions, automated remediation, and continuous monitoring for anomalous behavior ("Find, Fix, Alert").
- AI System Security Requires Inventory and Guardrails: Comprehensive inventory of all AI models and agents, posture assessment, and dynamic runtime guardrails (blocking malicious inputs, filtering sensitive outputs) are essential to protect AI systems themselves.
- Fight AI with AI: Defending against AI-powered adversaries necessitates AI-driven defenses, such as AI-powered phishing sandboxes using computer vision and NLP, to detect and block sophisticated, high-volume threats originating from trusted sources.
About the Speaker(s)
Yaki Faitelson is the Chief Executive Officer and Founder of Varonis, a leading data security company. With nearly three decades of experience in the IT business, Faitelson has dedicated his professional life to building platforms that protect the world's most valuable and vulnerable resource: data. As a co-founder of Varonis, he has consistently championed the use of automation and, increasingly, artificial intelligence to address complex data risk challenges that are impossible for humans to manage manually.
Reviews
Dr. Zero (Offensive Security Researcher) — HARD PASS
A CEO from a data security vendor gets on stage at RSA to explain that AI is changing things fast, agents have too many permissions, phishing is getting worse, and you should buy an AI-powered solution to fix it. This is not a security talk. This is a 45-minute product pitch with a conference badge stapled to it. There is zero original research, zero technical depth, zero novel insight, and maximum vendor self-interest. The 'Varonis Threat Labs' Copilot finding is mentioned but never demonstrated, dissected, or substantiated in any technically meaningful way. Everything else — Claude being used by Chinese state actors, a phishing kit called Spider-Man, the '200% growth' stat — is cited…
Heather Calloway (CISO) — WEAK
Faitelson identifies real structural problems — data overexposure, AI system vulnerabilities, agentic attack surfaces — but the talk functions primarily as a vendor positioning exercise dressed in strategic language. The governance and accountability dimensions are almost entirely absent. When the CEO of a data security company tells you that only AI can defend against AI risk and his company sells AI-powered data security, the absence of independent evidence, third-party validation, or honest treatment of limitations is not a minor gap. It is the talk.