Securing Agentic AI at Scale: Identity, Guardrails, and Incident Response with Scott Roberts

The Blast Radius Podcast

Securing Agentic AI at Scale: Identity, Guardrails, and Incident Response with Scott Roberts

Scott Roberts has spent his career at the center of some of tech's biggest security moments: he joined Microsoft's security team in the middle of the Blaster worm, ran roughly a third of the world's Ethereum and Solana staking infrastructure as CISO of Coinbase Cloud, and now leads security for UiPath, where autonomous agents run inside some of the most regulated enterprises in the world. In this episode of The Blast Radius, Scott joins host Diana Kelley (CISO, Noma) to get specific about what it actually takes to secure agentic systems at scale.

They cover why annual compliance pen tests are considered "security theater" by some (and what could be more useful instead), the two guardrails Scott treats as non-negotiable for every agent, and how to enforce trust boundaries in a shared responsibility model where customers configure their own agents. Scott also walks through how his team has actually grown to support agentic AI, what machine-speed incident response looks like in practice, and the board metrics he's dropped in favor of ones that show real business impact, including one self-critical metric many CISOs would never put in a deck.

If you're trying to figure out what your own security program needs to look like as agents take on more autonomy, this is a rare look at how one CISO is actually building it.