Opening Words (Day 2)
Gadi Evron (CEO · Knostic)
[un]prompted 2026 — AI Security Practitioner Conference · Day 2 · 1

Key moments
- 1:00 850 active online attendees plus 700 in venue — scale of AI security community gathering
- 1:59 Citizen coder risk: finance and HR using Claude Code creating ungoverned shadow infrastructure
- 3:00 Real incident: finance employee bypassed SSO in production, bypassing enterprise security
- 3:59 Red ocean startup warning: AI security space crowding fast, enter anyway for the excitement
- 4:29 Call to action: CEO/CISO/everyone should be on Claude Code now — one day late is too late
Opening Words (Day 2): Citizen Coders, Fragmented IT, and the Red Blue Ocean
Speaker: Gadi Evron, CEO, Knostic
Conference: [un]prompted 2026 — The AI Security Practitioner Conference
Date: March 4, 2026, San Francisco
Watch on YouTube: https://www.youtube.com/watch?v=S9lsiFQFmfo
Reading time: ~4 minutes
TL;DR: Gadi Evron opened Day 2 of [un]prompted 2026 with a sharp warning: non-technical "citizen coders" using AI coding tools are fragmenting corporate IT in ways that security teams are only beginning to grasp. His message — embrace these tools immediately or be left behind — set the tone for the day's deep-dive into offensive AI.
850 Online, 700 in the Room — and a Conference Still Being Vibe-Coded
▶ Watch: Opening remarks and conference stats (0:00)
Evron opened by sharing a number that underlined the moment: roughly 850 people were active in the online component of the conference at peak, with around 700 in the physical venue. But the online experience, he noted, was far more than a livestream. "There are hosted sessions where speakers just drop in and people chat for a while without all the noise in the background — it's just insane what's going on over there." When Europe went to sleep, numbers dropped, but the videos were already being captured for YouTube.
He thanked the committee, staff, and volunteers — a group spanning professors, researchers, CISOs, billionaires, and students alike — and gave a special nod to Ida, managing the event remotely, and to two speakers stuck in Israel with the airspace closed.
The Citizen Coder Problem Is Already Here
▶ Watch: Citizen coders and fragmented IT (2:00)
The central security concern Evron raised wasn't a future threat — it was already landing on enterprise desks. A customer conversation a few weeks earlier had surfaced what he called the "Citizen Coders" problem: finance and HR staff, not developers, are now building applications with tools like Claude Code, Cursor, Lovable, Replit, and Base44.
The risk is layered. It's not just about incident response losing auditability or traceability when AI writes the code. It's not only the known incidents, like the one where a finance employee bypassed SSO and embedded their own authentication credentials — a move developers have done for decades, but now spreading beyond engineering. And it's not just the dependency and vulnerability problem, where applications exist that nobody in IT even knows about, let alone patches.
"The deeper issue," Evron said, "is that when everybody is running their own infrastructure, IT is fragmented. How do we deal with that?"
The Reddest Blue Ocean He's Ever Seen
▶ Watch: Startup landscape and teams (4:00)
On the startup opportunity in AI security, Evron was characteristically blunt: "I truly believe this is going to be the reddest blue ocean I have ever seen in my life. Think twice before you enter this space — and then enter it anyway, because it is so exciting."
For teams and leadership, he issued a direct challenge. It had been exactly one day since his Day 1 remarks urging everyone to get on Claude Code and Cursor immediately. "Are your CEO and CISO on Claude Code already? If not, you're behind. You had a day to change your lives." And for those already on these tools: are you checking the Claude Code changelog every week? Because the ecosystem moves that fast.
Questions Are Not Comments
In a tradition carried over from Day 1, Evron closed his opening remarks with a public service announcement about Q&A etiquette, citing journalist Jelani Cobb's definition: "A question is an interrogative sentence generally denoted by an inflection at the end. A question differs from a statement in that a question requests information and a statement provides it."
The point landed with the audience — and served as a reminder that the conference's signal-to-noise ratio is something the organizers actively protect.
Notable Quotes
"The faster they go, the more they confess." (previewing the day's theme on AI-assisted attacks)
"Think twice before you enter this space — and then enter it anyway, because it is so exciting."
"Are your CEO and CISO on Claude Code already? If not, you're already behind."
Key Takeaways
- The "Citizen Coder" threat is not theoretical — non-technical employees building AI-assisted applications are already creating fragmented, untracked IT infrastructure in enterprises.
- The core risk is not individual incidents but systemic: when everyone runs their own infrastructure, IT visibility collapses.
- Leadership and security teams need to be active users of AI coding tools now, not observers — the gap between early adopters and laggards is widening weekly.
- The AI security startup market is both extremely crowded and extremely important; the opportunity is real but so is the competition.
Slides reference: No slides PDF was listed for this session. The transcript PDF (2026-04-04-Day2-Stage1-Evron-txt.pdf) provided the cleaned content used in this article.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
Conference opening remarks dressed up as a talk. Evron is sharp and the citizen-coder observation has real teeth, but this is five minutes of throat-clearing with a quotable line attached. The actual content — non-developers building shadow IT with Claude Code and Cursor — is a real problem, but it needed thirty more minutes to be a talk.
Heather Calloway (CISO) — WEAK
Evron names a real and underappreciated governance problem — non-technical employees building applications that nobody in IT knows exist — and then mostly gives a pep talk. The citizen coder problem deserves a full talk, not a warm-up act.
→ Top-rated talks at [un]prompted 2026 — AI Security Practitioner Conference
All talks from [un]prompted 2026 — AI Security Practitioner Conference