← Home
No Priors · May 28, 2026 · 41m

Building an AI Guardian for Enterprise with Onyx Security CEO Maxim Bar Kogan

Sarah Guo and Elad Gil interview Maxim Bar Kogan, CEO of Onyx Securities, about securing autonomous AI agents at the enterprise level. Onyx builds a control plane that oversees agent permissions and contexts while managing latency, cost, and reliability tradeoffs. The conversation covers why current monitoring lacks sufficient context to detect agent intent, the limitations of proxy-based security, why Onyx trains its own models, and the critical need for vendor-independent AI governance as agents approach capability to manage critical infrastructure like power grids and water supplies.

This summary was generated from show notes and public descriptions, not from a full transcript review. Details may contain inaccuracies.

Curious

Control Plane vs. Traditional Security for AI Agents05:17
Onyx positions its product as a 'control plane'—a permissions and context layer that gates agent capabilities—rather than traditional security monitoring that watches and reacts.
Mechanistic Interpretability as a Security Practice21:24
Onyx uses mechanistic interpretability—understanding how neural network weights produce decisions—as a foundational security practice to audit agent governance decisions.

Novel

Why Proxy-Based Security Doesn't Work for AI Agents12:45
Proxies and middleware can't intercept or evaluate agent actions meaningfully because agents operate at a speed and complexity that overwhelms proxy logic.

Highlights

Current Agent Monitoring Lacks Intent Context09:58
Existing enterprise controls can log agent actions but cannot understand intent—whether an action was malicious, a mistake, or a feature of legitimate operation.
Vendor-Independent AI Oversight Is Non-Negotiable for Critical Infrastructure30:46
Maxim argues that relying solely on AI labs (OpenAI, Anthropic, Google) for governance of critical infrastructure is a structural risk—independent oversight layers are necessary.

Editorial

Why Onyx Trains Its Own Models Instead of Using APIs14:11
Maxim explains that Onyx builds proprietary models for governance rather than relying on third-party foundation models, for control and safety reasons.

Misc

Maxim is Israeli, part of a growing AI and security talent pipeline from Israel
Onyx trains its own models rather than relying on third-party APIs—unusual approach for an AI security company
Debate within Onyx: some staff believe AI labs should handle governance, others believe it must be external
Was this useful?