Cybersecurity's AI vs. AI Trap | J.R. Rao (CTO, Security Research, IBM)
Listen to full episode:
Summary: IBM Fellow and CTO of Security Research J.R. Rao joins Anant and Ed to talk about what AI means for security. J.R. walks through how every major platform shift, from mainframes to AI, redraws the boundaries of trust, then digs into what happens when AI systems start operating with real autonomy and where that creates new exposure. The conversation also covers how AI can strengthen security work while introducing harder problems of its own, and closes with a look at what's coming next, including the intersection of AI and quantum computing.
Chapters:
00:00 - Hosts say hello and establish the episode topic
01:37 - Discussion on model announcements and autonomous loops
05:11 - Emerging headlines and industry caution on AI capabilities
07:49 - Introduction of J.R. Rao and his security insights
09:18 - J.R. on security innovation driven by industry platforms
12:25 - Emergent behaviors of AI agents and security implications
15:23 - Security architecture and defense in depth for AI
17:14 - The importance of rigorous security controls and culture
20:56 - Evolution of security architecture from perimeter to zero trust
24:38 - Challenges of AI autonomy and non-determinacy
30:09 - Using AI to improve security and fix vulnerabilities
33:21 - Open source vulnerabilities and IBM's Lightwell project
36:48 - The coming of quantum computing and its security implications
42:04 - Quantum threats to cryptography and data security
48:33 - The distinction between quantum-safe cryptography and other security measures
53:08 - The role of industry and capitalism in solving security problems
01:00:07 - Closing remarks and upcoming episodes
Sound Bites:
"Models operating with higher autonomy pose new security challenges."
"AI makes security harder but also easier if the architecture is right."
"Quantum computing will lay waste to classical cryptography."

