Pioneers Insight Method Research Author
Building an AI Guardian for Enterprise with Onyx Security CEO Maxim Bar Kogan
Back to Episodes

Building an AI Guardian for Enterprise with Onyx Security CEO Maxim Bar Kogan

Summary

  • Onyx’s category thesis is that autonomous-agent adoption is not something enterprises can stop, making independent action oversight a foundational enterprise control. AutoGPT supplied the early glimpse, although “GPT-4 was not good enough”; reasoning models and Claude Code later made the market real. Bar Kogan says enterprises cannot stop adoption and must instead reduce the probability of illegitimate or incorrect actions.

  • Autonomous coding agents already represent over 50% of the agent mix in Onyx’s typical enterprise, versus roughly 45% low-code automations and 2% internally built agents. The autonomous category is also growing fastest as Claude Code, Cowork, and even sanctioned OpenClaw deployments spread. The investor-relevant shift is from constrained automation toward “very unleashed agents” with broad permissions and few baked-in controls.

  • Existing security products can constrain access, but they cannot reliably distinguish an intended action from the same action taken in the wrong context. Recreating a database may be exactly what the user requested—or a disastrous tangent during an unrelated task. Endpoint, API, and identity tools “don’t know what Claude Code was thinking,” while a proxy merely exposes traffic rather than answering whether an action is legitimate.

  • Onyx’s technical bet is a cascade in which tiny specialized models decide when expensive, capable agents should investigate. Running one frontier reviewer for every operating agent fails on cost, latency, and reliability; the small model therefore learns one question: “Should I have a smarter agent look at this?” Bar Kogan accepts Sarah Guo’s blitz-chess analogy: use intuition for routine moves and spend overwhelming computation only at critical moments.

  • The collapse in vulnerability-discovery costs makes Mythos-level models an immediate enterprise-security issue, not hype. Work that once looked “20 to 50 years” away is arriving at once, and Bar Kogan says “the market is not overreacting.” His prescription combines immediate patching with foundational identity, firewall, endpoint, and AI-specific controls, while assuming stronger offensive models will arrive regardless of rollout policy.

  • Onyx is aiming beyond a security feature toward independent control of advanced AI—a market Bar Kogan calls a “hundred billion plus opening.” If AI vendors become $10 trillion companies, he argues customers will want another party inspecting their systems and eventually their weights and activations. Mechanistic interpretability may be too difficult for humans alone, but models smarter than humans might help “crack” it.

  • The proposed moat rests on structural independence, privileged behavioral history, and a heterogeneous model market. Bar Kogan expects labs to eliminate increasingly rare “silly mistakes,” but not necessarily actions arising from a “semi-aware or semi-conscious perspective” that conflicts with the user’s intent. Onyx is allowed to look at historical agent behavior that enterprises are wary of entrusting to Anthropic or OpenAI because of training concerns, and no single lab can secure every proprietary and open-source model customers adopt.

Deep dive

Not yet available upstream; scheduled sync will retry.