MP

Max Pollard

Things Max Says on Podcasts

Works at Kotool, and on the a16z Podcast explains how AI safety guardrails block security defenders as well as attackers after the OpenAI/Hugging Face hacking incident.

Where to Find Them

Max Pollard writes a16z Podcast . They have also been a guest on Insecure Agents .

Recently: “Blue Team at Machine Speed: Max Pollard (Cotool) on Agentic Defense” on Insecure Agents (September 2026); “How Do You Defend Against AI That Can Hack?” on a16z Podcast (August 2026); “How Do You Defend Against AI That Can Hack?” on a16z Podcast (August 2026).

What They Said

“Model providers have great reason to establish guardrails, safeguards, because these are super capable systems. The unfortunate side effect of that is, as a defender, I may not be able to respond effectively.” — Max Pollard, a16z Podcast

Max Pollard of Kotool explains a strange twist from the OpenAI/Hugging Face hacking incident: the same safety guardrails that stop attackers from misusing AI models also stop security defenders, who need to ask the model the same kinds of questions an attacker would.

a16z Podcast · 2026-08-18 Permalink → Listen →
a16z Podcast Around 00:27 into the episode
Joel de la Garza

One of the interesting things in the OpenAI hugging face breach has been the difficulty that Hugging Face actually had responding to the incident.

Max Pollard

Model providers have great reason to establish guardrails, safeguards, because these are super capable systems. The unfortunate side effect of that is, as a defender, I may not be able to respond effectively.

Nick Warner

The challenge with the existing security tools that are out there is they really were built to tackle two things. The first being people and the second is malware. And AI and AI intergentic processes are neither one of those things.

Max Pollard

Even some of the more modern techniques like deception, they

Nick Warner

work really well. And it's sort of ironic. We're defending AI and we're also defending from AI. 50% of enterprise apps will be agentic by the end of this year. And the average enterprise has something like six or seven thousand unique pieces of software within their environment. The problem's going to get more complex and more challenging.

Speaker names from our own diarization · position estimated from where the line sits in the episode

Collections They Appear In