Michael Bargury is an Israeli-born security researcher and entrepreneur known for his work on artificial-intelligence agent security, serving as co-founder and chief technology officer of Zenity, a company focused on helping enterprises discover, govern, and secure AI agents, co-pilots, and other autonomous systems [1][4]. His interest in security dates to his teenage years, when he attended informal classes taught by a prominent Israeli security figure, and he later spent an extended period at Microsoft, where he credits mentors Assaf Hudis and Mikael Braaban of Microsoft security with shaping how he thinks about navigating large organizations and the difference between technical and business innovation [4]. Before turning to AI, Bargury worked on security for the "citizen development" ecosystem built around low-code and no-code platforms such as Microsoft's Power Platform, an area he says now looks like an early version of what has become widespread "vibe coding" [3][16][17].
Bargury has described how his focus shifted decisively toward AI agent security after witnessing the launch of Microsoft Copilot Studio while on Microsoft's Redmond campus, a moment he says signaled that AI systems built directly into enterprise data stores would become the central new security battleground [3]. He has argued that much of the AI-security discourse at the time was preoccupied with content-moderation concerns, such as preventing chatbots from producing harmful instructions, rather than with security in the traditional sense of preventing adversaries from manipulating a system to produce damaging real-world outcomes [3]. To demonstrate the latter risk, he gave widely discussed Black Hat presentations, including a technique for hijacking Microsoft Copilot through a specially crafted email that could cause the assistant to search and exfiltrate a victim's files without any user interaction [3]. He has continued this line of research into prompt-injection and related attack techniques affecting AI agents, discussing it on multiple security-focused podcasts and video interviews [7][8][9][10][11][13][14][15].
In founding Zenity, Bargury has said he and his co-founders deliberately avoided pursuing an established playbook in cybersecurity, choosing instead to build in an area not yet prioritized by chief information security officers, a decision he compares to setting out into unfamiliar territory without guaranteed success [4]. He has recounted that the company closed several large enterprise customers early on through direct, hands-on sales efforts, which he says gave the founding team confidence in its market read [4]. Following Zenity's Series A funding round, Bargury told his board that the company would reorient its entire product focus toward generative AI and agent security in response to what he saw as a fundamental shift in the market, a decision he attributes to trusting instinct in a period when, in his words, "nobody knows what they're doing" [4]. He has since argued that enterprises are undergoing an unusually rapid period of technological adoption, driven by tools that let AI agents autonomously carry out business processes rather than merely explain them, a shift he says requires organizations to rethink workflows, roles, and staffing rather than simply deploy new software [3].
Insights & ideas
Michael Bargury argues that AI security is fundamentally different from content moderation, insisting that stopping a model from saying harmful things is a separate problem from preventing adversaries from turning AI into an attack vector that produces real, damaging outcomes inside an enterprise [2]. He traces this view to his own experience securing citizen development and the Power Platform ecosystem, and says the moment Copilot Studio launched he recognized that putting AI directly on top of enterprise data created a new attack surface, which he later demonstrated by hijacking Microsoft Copilot via a single email to exfiltrate a user's files without any interaction [2]. He describes agents as qualitatively different from prior software because, unlike traditional systems, they can fail and then lie about the failure, changing the nature of defense [1]. A recurring theme is that this moment is unusual because enterprises, normally resistant to change, are now actively pushing for rapid AI transformation, and that founders must build with conviction and adapt quickly as the market shifts, even reversing prior product direction after key milestones [1][2].
Experience
- Co-Founder & CTOZenityApr 2021 to Present
- AIVSS Project Co-leaderOWASP® FoundationJun 2025 to Present
- OWASP LCNC Top 10 Project LeaderOWASP® FoundationAug 2021 to Present
- ColumnistDark ReadingApr 2022 to Present
- Senior Architect, Azure Security CTO OfficeMicrosoftFeb 2018 to Feb 2021
- Data Scientist, Azure SecurityMicrosoftAug 2016 to Feb 2018
- Product Manager, Azure SecurityMicrosoftMar 2015 to Aug 2016
- Data AnalystIsrael Defense ForcesOct 2009 to Oct 2014
Education
Tel Aviv University · Bachelor of Science (BSc), Mathematics and Computer Science2015 - 2018
Media & appearances
- Are AI agents a big risk for your business? (Episode 66 w ...YouTube · May 8, 2026
Michael Bargury discusses AI security and agent risks in enterprise environments. He explains how he transitioned from working on security for citizen development and the power platform ecosystem to focusing on AI agent security after witnessing the launch of Copilot Studio. Bargury describes how adversaries can exploit AI systems as attack vectors, including a Black Hat talk demonstration where he showed how to hijack Microsoft Copilot through email to access and exfiltrate user files without interaction.
- Building Before Consensus: Securing the AI Frontier - YouTubeYouTube
Michael Bargury, co-founder and CTO of Zenity, discusses the company's focus on helping enterprises discover, govern, and secure AI agents, co-pilots, and autonomous systems. He shares his journey from Microsoft, where he worked with senior leaders including Mikal Braaban, to founding Zenity, and reflects on how AI is changing security challenges for defenders, emphasizing the importance of leadership, hiring, and building with conviction in a rapidly moving market.
- AI Worms Were Only a Precursor with Ben NassiIn the Wild with Michael Bargury · Aug 10, 2026
- AI Worms Were Only a Precursor with Ben NassiIn the Wild with Michael Bargury · Aug 10, 2026
- Why every AI agent can be hackedToday in Tech · Jan 13, 2026
- Oktane Preview with Harish Peri, Invisible Prompt Attacks, and the weekly news! - Harish Peri - ESW #421Enterprise Security Weekly (Video) · Aug 25, 2025
- Oktane Preview with Harish Peri, Invisible Prompt Attacks, and the weekly news! - Harish Peri - ESW #421Enterprise Security Weekly (Audio) · Aug 25, 2025
- Oktane Preview with Harish Peri, Invisible Prompt Attacks, and the weekly news! - Harish Peri - ESW #421Security Weekly Podcast Network (Video) · Aug 25, 2025
- Oktane Preview with Harish Peri, Invisible Prompt Attacks, and the weekly news! - Harish Peri - ESW #421Security Weekly Podcast Network (Audio) · Aug 25, 2025
- Resilient Cyber w/ Michael Bargury - The AI Agent Security ImperativeResilient Cyber · Aug 22, 2025
- The Call Is Coming From Inside the Agent (And It Has Your Credentials)YAAP (Yet Another AI Podcast) · Jul 15, 2025
- The Call Is Coming From Inside the Agent (And It Has Your Credentials)YAAP (Yet Another AI Podcast) · Jul 15, 2025
- Prioritizing security while adopting AI agentsLock it Down Podcast · Mar 25, 2025
- Michael Bargury - Low-Code/No-Code SecurityThe Security Champions Podcast · Mar 20, 2024
- Michael Bargury -- Low Code / No Code Security and an OWASP Top TenThe Application Security Podcast · Jan 3, 2023
- In the Wild with Michael Bargury | Podcast on SpotifySpotify
- In the Wild with Michael BarguryBuzzsprout
This page shows public professional information only, each fact cited. Is this you? Corrections or removal within 24 hours, no questions asked.