←imeto insights imeto conversations about...

Securing AI Agents

Andrew Millward, Spotify

Spotify operates on a massive global scale. When you’re rolling out AI features to millions of users, what is the one security challenge that keeps you up at night, and how do you tackle it?

“The scale itself is the challenge. We have a culture of high autonomy, so having security manually review every feature would become a bottleneck and slow down innovation.

Instead of acting as a gatekeeper, we focus on 'paved roads' (Golden Paths).

We build security into the platform itself - secure defaults, pre-approved libraries, and automated guardrails. If a team stays on the paved road, they inherit security automatically. This allows us to focus our human expertise on the highest-risk areas while the platform handles the baseline at scale.”

What is your 'number one' piece of advice for building secure agentic workflows from day one?

“Build with the assumption that the agent will be compromised. Because at some point it will - either maliciously or through the non-deterministic nature of the LLMs powering it.

Make all design decisions from that basis, such as when to include human-in-the-loop, sanitizing all inputs/outputs and giving the agent least privilege access.“

From a security perspective, what is the biggest difference between securing a standard chatbot versus securing an autonomous agent that can actually execute tasks?

“Security professionals often use the CIA triad (Confidentiality, Integrity, Availability) when thinking about security risk. Chatbots are heavily skewed toward Confidentiality risks, i.e. preventing data leakage.

With Agents, the risk profile shifts aggressively to Integrity and Availability. Because agents can execute tasks, they aren't just reading data - they can change it. A hallucinating chatbot is embarrassing but a hallucinating agent that deletes a production database is catastrophic. That’s why we need to focus heavily on human-in-the-loop controls and limiting the 'blast radius' of what an agent is allowed to touch.”

Is there an AI agent or tool that you personally use in your daily life that you can't live without?

“Cursor! It’s been incredibly useful at understanding complex codebases, consolidating knowledge across internal sources, doing security analysis of complex codebases and developing scripts that automate audit evidence collection. As a security person, I also appreciate its security features like privacy mode, rules, agent sandboxing and MCP allowlisting. ”

More insights

All stories→