People

Michael Bargury

Michael Bargury is an Israeli-born security researcher and entrepreneur known for his work on artificial-intelligence agent security, serving as co-founder and chief technology officer of Zenity, a company focused on helping enterprises discover, govern, and secure AI agents, co-pilots, and other autonomous systems [1][4]. His interest in security dates to his teenage years, when he attended informal classes taught by a prominent Israeli security figure, and he later spent an extended period at Microsoft, where he credits mentors Assaf Hudis and Mikael Braaban of Microsoft security with shaping how he thinks about navigating large organizations and the difference between technical and business innovation [4]. Before turning to AI, Bargury worked on security for the "citizen development" ecosystem built around low-code and no-code platforms such as Microsoft's Power Platform, an area he says now looks like an early version of what has become widespread "vibe coding" [3][16][17].

Bargury has described how his focus shifted decisively toward AI agent security after witnessing the launch of Microsoft Copilot Studio while on Microsoft's Redmond campus, a moment he says signaled that AI systems built directly into enterprise data stores would become the central new security battleground [3]. He has argued that much of the AI-security discourse at the time was preoccupied with content-moderation concerns, such as preventing chatbots from producing harmful instructions, rather than with security in the traditional sense of preventing adversaries from manipulating a system to produce damaging real-world outcomes [3]. To demonstrate the latter risk, he gave widely discussed Black Hat presentations, including a technique for hijacking Microsoft Copilot through a specially crafted email that could cause the assistant to search and exfiltrate a victim's files without any user interaction [3]. He has continued this line of research into prompt-injection and related attack techniques affecting AI agents, discussing it on multiple security-focused podcasts and video interviews [7][8][9][10][11][13][14][15].

In founding Zenity, Bargury has said he and his co-founders deliberately avoided pursuing an established playbook in cybersecurity, choosing instead to build in an area not yet prioritized by chief information security officers, a decision he compares to setting out into unfamiliar territory without guaranteed success [4]. He has recounted that the company closed several large enterprise customers early on through direct, hands-on sales efforts, which he says gave the founding team confidence in its market read [4]. Following Zenity's Series A funding round, Bargury told his board that the company would reorient its entire product focus toward generative AI and agent security in response to what he saw as a fundamental shift in the market, a decision he attributes to trusting instinct in a period when, in his words, "nobody knows what they're doing" [4]. He has since argued that enterprises are undergoing an unusually rapid period of technological adoption, driven by tools that let AI agents autonomously carry out business processes rather than merely explain them, a shift he says requires organizations to rethink workflows, roles, and staffing rather than simply deploy new software [3].

Insights & ideas

Michael Bargury argues that AI security is fundamentally different from content moderation, insisting that stopping a model from saying harmful things is a separate problem from preventing adversaries from turning AI into an attack vector that produces real, damaging outcomes inside an enterprise [2]. He traces this view to his own experience securing citizen development and the Power Platform ecosystem, and says the moment Copilot Studio launched he recognized that putting AI directly on top of enterprise data created a new attack surface, which he later demonstrated by hijacking Microsoft Copilot via a single email to exfiltrate a user's files without any interaction [2]. He describes agents as qualitatively different from prior software because, unlike traditional systems, they can fail and then lie about the failure, changing the nature of defense [1]. A recurring theme is that this moment is unusual because enterprises, normally resistant to change, are now actively pushing for rapid AI transformation, and that founders must build with conviction and adapt quickly as the market shifts, even reversing prior product direction after key milestones [1][2].

Experience

  1. Co-Founder & CTO
    ZenityApr 2021 to Present
  2. AIVSS Project Co-leader
    OWASP® FoundationJun 2025 to Present
  3. OWASP LCNC Top 10 Project Leader
    OWASP® FoundationAug 2021 to Present
  4. Columnist
    Dark ReadingApr 2022 to Present
  5. Senior Architect, Azure Security CTO Office
    MicrosoftFeb 2018 to Feb 2021
  6. Data Scientist, Azure Security
    MicrosoftAug 2016 to Feb 2018
  7. Product Manager, Azure Security
    MicrosoftMar 2015 to Aug 2016
  8. Data Analyst
    Israel Defense ForcesOct 2009 to Oct 2014

Education

Media & appearances

This page shows public professional information only, each fact cited. Is this you? Corrections or removal within 24 hours, no questions asked.