No Priors: Artificial Intelligence | Technology | Startups

Building an AI Guardian for Enterprise with Onyx Security CEO Maxim Bar Kogan

Brief

Onyx Security CEO Maxim Bar Kogan framed the episode around one urgent problem: as enterprises adopt autonomous agents, the volume and autonomy of machine actions is exploding and existing security controls cannot reliably judge intent or stop dangerous behaviors. Maxim said his company formed around the auto‑GPT moment and the subsequent emergence of "Cloud Code" and similar agent platforms; he estimates Onyx was founded roughly two years ago and now operates with a predominantly Tel Aviv team drawn from Israeli cyber and intelligence backgrounds. Onyx's product is a "secure AI control plane" that finds enterprise AIs and hooks oversight into their workflows so actions such as accidental token leaks, data deletion, or agent‑caused downtime can be detected and mitigated.

Maxim described three deployment categories he sees in customers: over 50% autonomous coding/assistant agents, ~45% low‑code SaaS automations, and about 2% first‑party agents. He argued proxies and standard identity tools fall short because enterprises must give agents broad permissions to be productive, and those legacy tools lack the context to interpret agent planning or intent. Technically, Onyx trains purpose‑built, small models to act as fast sentinels that flag suspicious actions; only when those sentinels trigger does Onyx escalate to costly, high‑capability reviewers. This design is meant to balance cost, latency, and coverage. Maxim also discussed the security landscape — automated vulnerability discovery has become dramatically cheaper, increasing attack risk — and recommended enterprises invest in foundational defenses (identity lockdown, firewalls, endpoint detection) while adopting AI‑native oversight. He expressed support for mechanistic interpretability research and argued that independent third‑party overseers will remain necessary because model vendors are unlikely to provide the full historical behavior data or unbiased attestations enterprises need.

Why it matters

Maxim Bar Kogan (co-founder & CEO, Onyx Security) said Onyx builds and trains models and agents to oversee other AI agents and packages this as a 'secure AI control plane' to discover and hook enterprise AIs into oversight.

Key details

  • Onyx categorizes deployed agents in enterprises into three buckets: >50% autonomous coding/assistant agents, ~45% low-code/drag‑and‑drop automations, and ~2% first‑party custom agents (Maxim's estimate of current customer mixes).
  • Maxim traced Onyx's founding thesis to auto‑GPT and the rise of 'Cloud Code' and other autonomous agent platforms; he started the company ~two years ago (around 2024) anticipating long‑horizon, high‑impact agent actions.
  • Technical approach: Onyx trains lightweight specialist models to act as fast sentinels that decide when to escalate to expensive, slower 'smart' agents — reducing cost, latency, and false positives compared with running a heavy guardian agent for every worker agent (Maxim).
  • Maxim argued traditional controls (identity, proxies, endpoint/API security) are often insufficient because enterprises give agents broad permissions and existing tools lack the context to judge agent intent or plans.
  • Security risks cited include agents accidentally publishing tokens or deleting data and a rapid drop in cost for automated vulnerability finding; Maxim advised foundational defenses (identity lock‑down, firewalls, endpoint detection) plus AI‑native controls.
Reader · no content

No body text on file.

Open the original to read the full piece.