The CISO Playbook for AI Agents | Datadog

11 Aug 2026 · 23 min · 11 chapters

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

How Datadog’s CISO Emilio Escobar manages enterprise risk from AI coding agents, focusing on permissions/credentials, software supply chain threats, and scaling vulnerability/intent detection without “department of no.”

Guests

Joel De La Garza (A16Z) interviews Emilio Escobar (Datadog CISO). Escobar is responsible for security at a public tech company and has been central to Datadog’s AI adoption, including engineering and non-engineering rollout.

Key claims

Blocking AI tools doesn’t work; adoption is high (nearly all employees). AI “flattens” org access, so row/table permissions can be bypassed via SQL. Agents can’t be trusted with static credential files; use ephemeral, injected tokens. Don’t panic about “AI hackers escaping,” but do worry about vulnerability volume, hypersensitive triage, and weak regulatory/criteria for access.

Notable examples

Early rollout with Cursor; internal BI tool where sales reps used an agent to query data despite intended permissions; Datadog judge that evaluates code intent (not CVEs) and found malicious skills in marketplaces; sandbox/MCP servers with role-based governance for SDRs.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Chapters

Tap a time to open that second in VO

AI's Impact on Security Risks

0:00 to 1:06

Explore the implications of AI on security and the potential risks involved.

“The number one story on Bloomberg right now is that AI has gone wild.”

Adapting to AI in Security

1:50 to 3:47

Understanding how organizations can adapt to AI tools without sacrificing security.

“You're here to go to Black Hat, and it's good to catch up.”

Deployment of AI in Organizations

3:47 to 5:54

Discussing the deployment of AI, including license distribution and usage.

“So now we have over 4 ,000 engineers using them.”

Challenges of Data Management

5:54 to 7:42

Investigating the challenges AI presents for data management and permissioning.

“So we have an MCP server for SDRs and things like that.”

Guarding Against Malicious Code

7:42 to 9:51

Learn about techniques to guard against malicious code and vulnerabilities in AI.

“So we actually have built hooks into the agents.”

Evaluating Code Intent with AI

9:51 to 11:22

Discover how evaluating code intent can enhance security in software development.

“I don't think we have to justify it, but the judge does a good job at it.”

The Future of Security Roles

11:22 to 13:15

Exploring the evolving roles in security and the need for creative problem solvers.

“So the cool thing is that we do this internally because we have to, and then the product team goes like, wait a minute, that might actually become a thing.”

Evolving Role of Engineers in Security

14:00 to 17:08

Learn how AI adoption is shifting the perception and responsibilities of engineers in security.

“and they were saying that sort of like with AI tool adoption, they don't need to write as much code manually anymore.”

Challenges in Developer-Security Communication

17:08 to 19:59

Explore the disconnect between developers and security teams, and how it affects coding practices.

“And I just think, yeah, security people tend to have an issue, a blind spot around some of that stuff.”

AI's Impact on Security Concerns

19:59 to 21:31

Discuss the implications of AI on security protocols and the evolving threats faced by companies.

“What I worry about is the volume of things that are going to get discovered.”
Show all 11 chapters

The Importance of Open Discourse in Security

21:31 to 21:42

Understand why open discussions are crucial for improving security practices.

“throughout my entire career is that any attempt to gatekeep security fails.”
Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:00The number one story on Bloomberg right now is that AI has gone wild. We seem remarkably calm. The way I see it is, if it's not an AI model, it's going to be somebody or something with actual malicious intent doing it. I do worry about what can the agents do, what tools can they call, what binaries can they pull, and also how do they get access to credentials. If a code is meant to solve the bug, but it gets rewarded on that, but it doesn't care if it's actually doing something else. The tree is sick, so to make it healthy, it cuts it down. Out of necessity, my team built a judge that evaluates the intent behind a piece of code.

0:34Like, is this thing meant to do harm or not? And we actually find quite a bit of malicious skills in all these marketplaces. Engineers now, security is very much front of mind for them. Developers have always cared about security. Their problem has been that the version of security that we want them to do is just crappy. My thesis 10 years ago was that security engineers have become real engineers, so maybe now is the time. AI is changing the security landscape on both sides. Attackers have more capable tools, but security teams are also figuring out how to use those same capabilities to their advantage.

1:06In this episode, A16Z's Joel De La Garza sits down with Datadog CISO Emilio Escobar to talk about what he's seeing as AI adoption spreads across the enterprise, including thousands of engineers working with coding agents. They discuss how AI changes assumptions around permissions, credentials, and software supply chains, why simply blocking new tools doesn't work, and how security teams can adapt without becoming the department of no. And as models get better at finding vulnerabilities, Emilio explains why he's less worried about AI hackers themselves than a more practical problem. What happens when the number of vulnerabilities we can find suddenly explodes?

1:48Thank you so much for joining us. I know you're not here to see us. You're here to go to Black Hat, and it's good to catch up. And it's been a really crazy week. So you are a CISO at a public company, tech company, one of the House of Innovation, driven a lot of really cool technology out of it. And we've been talking to everyone about these models escaping, these models hacking. And I know you've been central to kind of the adoption of AI at Datadog and would love to maybe talk a little bit about how are you thinking through the risks? How are you deploying this stuff? And I know you're very close to the product team and you're kind of enabling it.

2:20So we'd maybe start off there and around. For us, it was like, we have to do it like any other software company. If we're not, we're going to be in the medieval ages real quick. And I like being a CISO. I don't like having my own goat farm. And we started real small. I remember our first install, we started with Cursor. And I remember getting like 50 licenses. And it was more of putting out there and see who bit. And then it's not surprising, it bloomed from there. So now we use every other coding agent that's out there. and some of the things that we're worried about as we deploy, well, first you start with the data.

2:54What are we worried about the data? And I never subscribed to the idea of, oh, if I block these things, nobody's going to use them. That's never worked. So on the non-developer side, like we just got ChatGPT licenses for everyone and it was like, whoever wants it gets it, I don't care. And you sure use it to find a recipe for pot roast, I don't give a crap. And because then I avoided the all oops moment. And this was back, ironically, this wasn't that long ago. This was two years ago, and it feels like things have moved 20 years since. But I remember having a lunch with a bunch of CIOs at RSA where everyone was asking me, like, how am I not blocking these things, right?

3:30And I was like, well, A, we can't because we do that, the company that we are. But B, luckily, we can just buy our way out of that problem and zero data retention and all those things. Well, it's probably the inverse of Hey, Let's Block It turned out to be correct, which is the people leaning into it the earliest and the most. are the ones that you actually want to reward enough. Right, exactly. Yeah, yeah, yeah. So now we have over 4 ,000 engineers using them. I mean, actually, we have every employee in the company adopting some sort of AI, whether it's coding agent or Gemini, cloud desktop, JATGPT, or what have you.

4:01And so I have two, we have two verticals. We have the engineering side, which Alexi is deeply involved, our CTO is deeply involved in, and then I'm involved on the non-engineering side for how do we get marketing sales and everyone else to use AI. And the adoption is, I think we were at like 98 % adoption rate, something like that. It's one version of AI or the other everyone is using. On that side, on the IT corporate side, the data becomes more the paramount issue, permissioning and all those things. One thing that AI is going to do is you think you have proper controls of who get access to what Google file or what have you.

4:38AI is going to find a way to get it. All you have to do is prompt it. It flattens the organization, right? It flattens the organization quite a bit. So we actually had a moment where internally we built this business intelligence tool. It's really neat. And it was starting to show some data that I was like, it wasn't anything like a fire alarm, but it was like, should we? And the data was probably always available to everyone. They just never took the time to work. So yes, so it's data that is in a data warehouse and we thought we had the right table and row permissioning and all of that. but there was always a way to get access to the data if you knew the SQL well enough.

5:16Well, then what happened is that you went from only people who really know SQL are using this to now having a sales rep telling, asking like, hey, what are, what is, I'm a commercial sales rep. I'm just coming up with an example. I'm a commercial sales rep. How is the enterprise deal, enterprise tier team doing? Yeah. Which normally you want to keep those things separate and what have you and the agent just took out the SQL to do it. Yeah, yeah, yeah. And then it tells them what the comp plan is. Right. So what is not always find a way around the permissioning and all that is like we had the right permissioning for the right time.

5:47And then the age. So we've been obviously improving all of that. And then luckily my IT group is what we've done is now we're at the point where we have role based MCP servers as well. So we have an MCP server for SDRs and things like that. So we control and govern that data. And then we're like, let them have it with whatever tool they want to use. on the engineering side, obviously in the coding agent, like when my security team is worried about, similar to what you were just talking about is on what can the agents do, what tools can they call, what binaries can they pull, what dependencies can they use, and also how do they get access to credentials.

6:22So for that, we have a few things going on where we've contributed to this open source sandbox and expanding on that where the agent doesn't actually get access to any sort of credential file. so even if you have a file in your home directory that has your AWS secret, your NPM published secret or what have you the agent on the sandbox can't touch it the credentials get injected into the agent the moment he needs it and the beauty of it is we already have CLI tool that will give you these ephemeral tokens to these things we just have the agent not know how to call it so it's like oh I'm Emilio I'm an engineer on this team I want to authenticate to GitHub for example I call this tool auth GitHub and it gives me a credential that's valid for I don't know how long and it gives me my access to GitHub but now it's the agent getting my access to GitHub.

7:13But not just a static token written in a file. The second thing is we know the threat has expanded. Developers are now the main target for attackers. Absolutely. Because if I get one of these tokens I can then build a worm that attacks packages or I can just escape or do whatever or access your production environment. The other ways that we see how these agents can do it is via skills. We track a few of these marketplaces. Yeah, how do you control the skills? That's a really hard problem. So we actually have built hooks into the agents. And then one of the things that, which we can talk about is my team built out of a necessity, a judge that evaluates using AI LMS, that evaluates the intent behind a piece of code.

8:01I'm not talking CVEs, vulnerabilities, or anything like that. It's like, is this thing meant to do harm or not? Harm being a vague term on purpose. It actually does really well at scanning markdown files as well. Nice. So we built it because for the longest time, Datadog, for those who don't know, we have a Datadog agent. We take third-party code contributions to it, things like integrations and what have you. So code written by other people. we had this process for the longest time that required a security engineer and an engineer on that agent team to revaluate the code and then approve it and then merge it so I'm like well this thing can't scale so then we built this judge by we I mean my team I don't do anything that got really good at it and then the software supply chain hijack started happening and ID extensions started happening and then we threw this thing at those packages and it was actually able to identify the malicious piece of code that was injected or introduced during the hijack.

8:58So we're like, huh, I wonder how it would do with markdown files. And it actually does pretty well. So then internally, what that means is we have hooks into the agents. We know what skills they're getting pulled. I've never believed in a security program that just restricts everything because the pain, innovation and all that. It's the empire of no. It's the empire of no. But also it's like, we don't want to be free willy either. So what we do is now we put this judge in front of every skill that wants to get introduced. We actually find quite a bit of malicious skills in all these marketplaces.

9:33We're working with a few of them, partnering to see if they want to use this judge, but also like, hey, giving a heads up of, hey, we found this one, we found that one, we found that one. And they do a pretty good job at taking those down. The other thing we worry about is what dependencies it can pull, what binaries it can pull. So I think it's plenty of it out there right now. I don't think we have to justify it, but the judge does a good job at it. and then evaluating the code output of the agents against malicious intent. I think intent, and it's funny how this industry works, and this is maybe where I can get a little cheeky here, if you allow me, is...

10:06I have no control. You can say whatever. Yeah, yeah. Apparently intent now is one of the must-have in any AI security type of solution. But the interesting thing is, like, it happened after we've had conversations about intent. But then, anyways, but apparently that's a big deal, right? It's like the fact that these agents, obviously they're trained on existing data, on existing code. And they have a reward structure. And they have a reward structure. So if a code is meant to solve the bug, but it gets rewarded on that, but it doesn't care if it's actually doing something else outside of that.

10:44So we were worried. The tree is sick, so to make it healthy, it cuts it down. Right. So we were worried about the typical thing that we read about of an agent producing code that either would have, oh, your database isn't scaling and it's paging people at 4 a.m., so the best thing I can do is just turn it off. And therefore, I solve the problem of paging people at 4 in the morning. So you have to be careful how you prompt these things, but also how it actually interprets your prompt and executes on that. So we have this judge now evaluating the code output of the agents to then make sure that we're doing this.

11:22So the cool thing is that we do this internally because we have to, and then the product team goes like, wait a minute, that might actually become a thing. Let's explore, and then we evaluate it with customers and all of that. But I mean, I get to say I'm lucky that the team can do it. One of the things that surprises me is I did a roundtable last week about agentic security. And the sense that I got from a bunch of the security leaders who were on that call was a sense of helplessness, of just waiting for a commercial solution to come in and solve it all. Well, yes. I think that the profession is interesting in that there are a number of different CISO profiles.

12:05And I think, you know, I say this as someone who is relatively technical for a CISO. So, like, before maybe just the generation above us, like, there were no tech. I mean, the first CISO was Steve Katz, right? So that's, like, pretty recent. Yeah. You know, and I think that there was just a lot of, like, sort of, like, CFOs becoming CISOs or CTOs. Not really security people, right? So, like, I think, and then what happened, I think, is that security teams got quite big, and you needed a manager, right? Not necessarily a leader or a thought leader. And so I think there's just a lot of that right now in the industry where there's very much a, you know, if you're a large industrial company and software is not your competitive advantage, you're probably going to buy most of your product.

12:50Versus like Datadog. We're like, you better be the best of the best. It's totally fine, right? But I still believe, even in those scenarios, you may have one or two people on that team that if you give them creative license, they could do something. But the fact that that wasn't even a thought process worries me a little bit because this thing is moving really, really fast. Naturally, a lot of the companies that are solving this are new companies. I think it's really hard. I think the talent shortage is still a problem and I'm generally bullish on security jobs because of it. But I think for some of the bigger programs, it's really hard to get technologists in there because they are shops.

13:36Well, here's my kind of argument. do you really need a security person to do it? No, and I think some of the best security people didn't start as security people. Yeah. You know what I mean? It's like the developer that found their way into security. Right. But also in these companies, I'm sure there's a developer somewhere in there that they can be like, hey, how about we have you solve this problem for us in the meantime? I think that a realignment is kind of happening. So I was talking to a family member at a big, big American corporation, and they were saying that sort of like with AI tool adoption, they don't need to write as much code manually anymore.

14:08They still need engineers. But they're basically saying, hey, look, we don't need this many tier one engineers and the security team needs them. And so I think maybe you're starting to see some of that cross-pollination where you'll see that talent find their way into security. Because it was always the case that if you're a developer or an engineer, you would just make more money on the software development side. So I think those are equalizing in maybe, I mean my thesis 10 years ago was that security engineers will become real engineers so maybe now is the time. Yeah, I mean we pay them the same as software engineers.

14:44Now we do, yeah, I mean in the Valley especially. I think it's narrowing in large corporates. I think it's still software engineers have the advantage there. But that'll probably narrow over time. So that's how we'd be thinking about identity security is like what are the things that we actually worry about and then what can we build, what can we use and then where do we find more synergies there and I know that's a very buzzy term but what that I mean is our DevEx team is also interested to understand what's happening in the agents because they want to monitor developer experience so why can't we just all together work on it so that's how we that's how this thing has grown because it's not just a security tool for the sake of security it's also serving other purposes and I've noticed with engineers especially over the last decade like engineers now security is very much front of mind for them.

15:36If only because they don't want to have to keep fixing things. And so I've noticed that there is this front of mind security thing for engineers, which is great. I think we've made a lot of progress in that regard. Yeah, well, I actually have a little bit more of a

15:55maybe a fiery take on that. I think developers have always cared about security. I think the problem has been that the version of security that we want them to do is just crappy. Which is like, go fix this thousand of things that none of them are actually relevant to what you're building. But the scanner told me they're critical, so you have to fix them. Yeah, there is a lot of like the, you guys have sent me so much junk. You've lost all credibility. So one of the things that I get to do at Datadog is actually I get to meet a lot of the engineering side of the equation. talking to us about our security platform and products and how do we get their security team to use it.

16:36And they told me the same stories that I'm sure you've heard of. Like, I get a thousand tickets, none of them are relevant. Security doesn't know what we're doing. There's no intent to even understand the systems. And the number of times I hear a security person telling me that their developers write crappy code, it's just mind-boggling. I'm like, well, then you do it. Yeah, exactly. See how good you can do it. Probably no better. Yeah, exactly. Or maybe it's good code, but they're not fixing your noise vulnerabilities, and therefore you think it's crappy code. Yeah. I mean, oftentimes, right, with code bases, this was the learning experience for me, was that, like, you'll find these, in isolation, you'll find these issues in code, but then, like, there's a framework, a layer up, that's actually mitigating any potential fallout, and so it's like, whatever, it doesn't matter.

17:24Yeah. And I just think, yeah, security people tend to have an issue, a blind spot around some of that stuff. Yeah. I guess sort of like as we sit here, you know, the number one story on Bloomberg right now is that AI has gone wild and the world is over and everything is getting hacked. You seem remarkably calm. So maybe before we go, like we'd love to get your take just on sort of like, you know, supposedly there's this great white shark cruising out there just eating people without them knowing. but in general I just haven't noticed a sense of panic from CISOs what's your take on all of this?

18:02I mean the way I see it is if it's not an AI model it's going to be something with somebody or something with actual malicious intent doing it so therefore I don't panic I do I do worry about our access to those same capabilities I do worry about the lack of regulatory framework that's deciding who gets access to these capabilities. Yeah, yeah. I feel you on that. It's sort of like, it's really interesting who's getting access to this. Yeah, yeah. And it's sort of like, hmm, what's at play here? But then it's clear that it's, or communicated in a way that makes it, or portrays it as clear that it's outside of the frontier lab's hands.

18:51And so we have to put our company name on the list and then we're supposed to wait. And then when I ask, what's the criteria for how these things are evaluated? I get jazz hands response. But then you come to a conference and you talk to your buddies and they've had it for nine months. Yeah. And they're making stuff that's way less critical than your product. Yeah, so the argument was like, hey, some of these companies are using our stuff. Yeah. Wouldn't it make sense for us to get access so we can protect the stuff that you're using? Exactly. Yeah, I'm sure there's a lot of government agencies running Datadog software.

19:24And vice versa, right? We have a lot of also companies that provide services to the company. Yeah, yeah, yeah, of course. So, yeah, so I'm not worried necessarily about the models escaping sandbox and finding old days. Like, I think, actually, I actually think inherently it makes things better for us. Mm-hmm, 100%. Because, guess what, we're talking about it. Bloomberg is talking about it, you just said, right? So before, it was like, well, nobody's talking about it, so who cares? But am I worried about one of those things hitting Datadog and something happening? is like, well, it's either a model or somebody else, right?

19:54Like if we have a gap, we have a gap. At some point, it's going to get discovered. So I'm not too worried about that. What I worry about is the volume of things that are going to get discovered. And the things that are telling us how to handle that volume are not up to par. Yeah, 100%. So you must fix every CVE that's in your environment to now you're going to get 1 ,000x more CVEs in your environment. well those things two things don't necessarily align well so i'm hoping that side also changes to the current day of things that's what i worry and then the sorry and lastly like the other thing that i worry is the hypersensitivity to the security of these findings because of the fact that it was found by a model rather than a human and i'm already seeing some of that where like oh uh model x found this so it must be extremely critical and true and then you're looking at it and you're like, it's actually not.

20:52But it's kind of hard to argue that it's us arguing against this thing because just because a Greek godfound, it doesn't mean it's actually a critical thing. But I think that the third-party risk management game is going to get really crappy, even more so than it is because of this thing. So I hope eventually those things I do worry about. but I'm not always gaping and hacking companies and all that. It's like, well, I mean, they were going to get hacked no matter what. Yeah. There's always been hackers. Right. There's two more now and whatever. Yeah, yeah, yeah. There are two really good ones but hopefully they make us better rather than like making us worse.

21:30Well, and I think the lesson that I have learned throughout my entire career is that any attempt to gatekeep security fails. Right, yeah. And it only makes things worse and that an open and free discourse on these things is the only way to get better. Yeah, yeah, yeah. Yeah, exactly. Thank you for joining us and having that discourse, man. It's been awesome. Yeah, thanks. Enjoy your time at the conference. Thank you. thanks for listening to this episode of the a16z podcast if you like this episode be sure to like comment subscribe leave us a rating or review and share it with your friends and family for more episodes go to youtube apple podcast and spotify follow us on x a16z and subscribe to our substack at a16z.substack.com thanks again for listening and i'll see you in the next episode As a reminder, the content here is for informational purposes only.

22:18Should not be taken as legal business, tax, or investment advice, or be used to evaluate any investment or security, and is not directed at any investors or potential investors in any A16Z fund. Please note that A16Z and its affiliates may also maintain investments in the companies discussed in this podcast. For more details, including a link to our investments, please see A16Z.com forward slash disclosures.

22:47Thank you.

From the publisher

a16z's Joel De La Garza is joined by Emilio Escobar, Chief Information Security Officer at Datadog, to discuss what it takes to secure a company where nearly every employee is using AI and more than 4,000 engineers are working with coding agents. Rather than trying to block new tools, Emilio explains why Datadog chose to embrace AI early and build the security infrastructure needed to use it safely.

They unpack how AI changes traditional assumptions around data permissions, credentials, developer access, and software supply chains. Emilio shares how Datadog uses role-based MCP servers and ephemeral credentials, as well as an AI "judge" built by his security team to evaluate the intent behind code and agent skills before they enter the environment.

They also discuss why security teams can't afford to wait for commercial solutions to every new AI threat, how the relationship between developers and security teams needs to change, and why Emilio is less concerned about an AI "escaping" than he is about the sheer volume of vulnerabilities AI could uncover.

 

Resources:

Follow Emilio Escobar on LinkedIn: linkedin.com/in/emilioesc

Follow Joel De La Garza on LinkedIn: https://www.linkedin.com/in/3448827723723234/

Follow Datadog on X: https://x.com/datadoghq

Stay Updated:

Find a16z on YouTube: YouTube

Find a16z on X

Find a16z on LinkedIn

Listen to the a16z Show on Spotify

Listen to the a16z Show on Apple Podcasts

Follow our host: https://twitter.com/eriktorenberg

 

Please note that the content here is for informational purposes only; should NOT be taken as legal, business, tax, or investment advice or be used to evaluate any investment or security; and is not directed at any investors or potential investors in any a16z fund. a16z and its affiliates may maintain investments in the companies discussed. For more details please see a16z.com/disclosures.


Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

More from The a16z Show

All 489 episodes
The CISO Playbook for AI AgentsThe a16z Show · 23 min
Listen in VO