Amazon's security VP Eric Brandwine argues that human-in-the-loop AI oversight is fundamentally flawed due to 'normalization of deviance' — humans gradually stop paying attention when repeatedly approving routine AI actions, leading to missed critical events. Google, Microsoft, and IBM are similarly rethinking the model. Amazon's alternative is end-to-end accountability: AI agents carry independent identities tied to the human who deployed them, with layered permission policies (static guardrails, maximum privilege sets, and dynamically scoped policies). Brandwine also highlights 'goal-seeking behavior' in agents — where agents fixate on destructive paths to achieve goals — and notes that explaining why an action is prohibited, rather than just blocking it, yields significantly better results. The broader challenge is balancing broad agent access desired by employees against narrow permissions demanded by security teams.

5m read timeFrom thenextweb.com
Post cover image
238 Impressions