Thyaga Vasudevan 著 - 製品担当EVP
September 15, 2026 5 Minute Read
This weekend, the AI industry had an unusual conversation about speed.
To summarize, Anthropic CEO Dario Amodei argued that frontier AI capabilities are advancing faster than the mechanisms needed to understand and control them. OpenAI CEO Sam Altman has also expressed a willingness to slow development of advanced AI systems under the right conditions.
I don’t want to speculate about why they are taking these positions. However, the risks they describe deserve to be taken seriously. As such, I believe the broader discussion points to a different conclusion:
We should not build our AI security strategy around the assumption that innovation can be slowed. We should build a security architecture that allows innovation to continue safely and securely.
There is simply too much value waiting to be unlocked; AI has the potential to transform medicine, science, software development, education, manufacturing, cybersecurity and virtually every knowledge-intensive industry. When I speak to customers in Fortune 100 organizations in some of the most regulated markets and regions and spanning multiple industries, each and everyone of them is already seeing this firsthand. For instance, employees are using AI assistants, developers are embedding models into applications, companies are building private AI environments and their business processes are becoming increasingly agentic.
As such, we can’t put the genie back into the bottle.
The organizations that respond primarily by restricting AI may create another problem: employees and developers move toward tools security teams cannot see. The objective should therefore not be slower AI adoption. Rather it should be safer AI adoption.
There is another practical challenge with slowing the frontier: everyone would have to slow together. I think this is like a Formula 1 problem.
Lets say, you are racing at extraordinary speed and discover that part of the track may be unsafe, so you lift off the accelerator. This could be the responsible thing to do, but your competitor might think differently. They may believe they have better brakes, they may choose another racing line or they may choose to accept more risk.
Also, note that in AI, there is another factor: open source. Innovation is increasingly global and distributed. It’s not that these Frontier labs compete with each other – the Nations compete. Enterprises are building their own custom models based on open source.
Hence, organizations will need to assume that AI capabilities will keep advancing rapidly, regardless of whether every participant agrees on the pace.
Just like in Formula 1, the answer is not simply to drive slower. The answer is to build safer cars, better brakes, stronger barriers, better telemetry and better rules. Similarly, AI needs the equivalent. Security must become the guardrail for innovation.

AI security is sometimes reduced to protecting a prompt or securing an LLM. That is far too narrow. Enterprise AI now stretches from employees experimenting with public AI tools to autonomous agents accessing applications, APIs and enterprise data. Organizations therefore need a comprehensive AI security architecture, not another point product.
At Skyhigh Security, we think about this through five steps of a maturity model progression.
1. Discover
You cannot secure what you cannot see. Organizations first need visibility into sanctioned AI, shadow AI, private AI and the expanding universe of LLM-powered applications. They need to understand who is using AI, which applications are being accessed, what risk they introduce and where sensitive data may be flowing.
2. Govern & Prevent
Visibility must lead to policy. Not every employee should have the same access to every AI service, and not every AI application should receive the same data. This is where Security Service Edge (SSE) + Zero Trust plays and becomes essential. Also, the architecture needs to allow for local enforcement to ensure security does not introduce any performance and latency in the end-user experience
Identity, application risk, device posture, data sensitivity and context can determine whether an AI interaction should be allowed, blocked, restricted or routed differently.
3. Protect the Data
The value of enterprise AI increasingly comes from its access to enterprise data. That is also where much of the risk resides. Organizations can leverage Data Security Posture Management (DSPM), DLP and Secure Browser Controls working together to discover sensitive information, protect it as it moves and control what users can upload, download, copy, paste or expose to AI applications.
AI security without data security is incomplete.
4. Secure AI Interactions
The next layer protects the conversation itself. Prompts can contain sensitive information. Models can be manipulated through prompt injection. Responses may contain unsafe or inappropriate content. Organizations need prompt security + content moderation + controls for bespoke LLMs to apply dynamic guardrails around human-to-AI interactions.
The question evolves from: “Can this user access this AI application?”
to: “Should this user, in this context, send this information to this model?”
5. Secure Agentic AI
This may ultimately become the most important layer. AI is moving from answering questions to taking actions. Agents can access systems, invoke tools, call APIs, retrieve data and communicate with other agents at machine speed. Protocols such as MCP make these connections increasingly powerful. Organizations therefore need Agent Identity Zero Trust + MCP Security so autonomous machine-to-machine interactions have identity, permissions, policy and continuous authorization.
We spent decades building identity and zero trust architectures for humans. Now we need them for machines acting autonomously.

In conclusion, the debate is not between innovation or safety. That is a false choice. The challenge for the cybersecurity industry should be to enable safe and secure innovation.
AI will get faster. It will become more autonomous. It will access more enterprise data. And it will take more actions on behalf of humans. Organizations cannot base their AI strategy on the hope that the entire ecosystem will collectively slow down.
Their security architecture needs to assume the opposite. The winners of the AI era will not necessarily be the organizations that move the slowest. They will be the organizations that figure out how to move fast but with the right guardrails.
著者について

Thyaga Vasudevanは、Skyhigh Securityの製品担当エグゼクティブバイスプレジデントとして、製品管理、デザイン、製品マーケティング、GTM戦略を統括する、エネルギッシュなソフトウェアプロフェッショナルです。豊富な経験を持ち、SAASベースのエンタープライズソフトウェア(Oracle、Hightail – 旧YouSendIt、WebEx、Vitalect)とコンシューマーインターネット(Yahoo! Messenger – 音声およびビデオ)の両方で製品開発に成功裏に貢献してきました。彼は、根本的なエンドユーザーの問題とユースケースを特定するプロセスに専念しており、リスクと機会の間の微妙なバランスを組織が乗り越えるのを支援することを含め、これらの課題に対処するためのハイテク製品およびサービスの仕様策定と開発を主導することに誇りを持っています。
Thyaga Vasudevan September 15, 2026
Sanjay Castelino August 6, 2026