P

Michael Bargury

Co-Founder & CTO at Zenity

Overview

Michael Bargury is Co-Founder & CTO at Zenity[1]. Bargury maintains a presence on X at @mbrg0[2].

Career history

  1. Co-Founder & CTOApr 2021 to PresentZenity
  2. AIVSS Project Co-leaderJun 2025 to PresentOWASP® Foundation
  3. OWASP LCNC Top 10 Project LeaderAug 2021 to PresentOWASP® Foundation
  4. ColumnistApr 2022 to PresentDark Reading
  5. Senior Architect, Azure Security CTO OfficeFeb 2018 to Feb 2021Microsoft
  6. Data Scientist, Azure SecurityAug 2016 to Feb 2018Microsoft
  7. Product Manager, Azure SecurityMar 2015 to Aug 2016Microsoft
  8. Data AnalystOct 2009 to Oct 2014Israel Defense Forces

Education

  1. Bachelor of Science (BSc), Mathematics and Computer Science2015 - 2018Tel Aviv University

Insights & ideas

The through-line

Michael Bargury's central argument, repeated in almost every register he speaks in, is that the industry has been solving the wrong problem. "People say security of AI or security or AI for security, there's kind of a distinction. I think what we really care about is security from AI. Don't let AI do bad stuff to the things that we care about" [1]. When he first surveyed the field, he found most practitioners treating AI security as content moderation, keeping the model from saying things it shouldn't, and concluded that "this is actually not the biggest risk... Security is about making sure somebody external or an adversary can't create a meaningful outcome, a bad outcome from what I created" [1]. Everything else follows from that reframing: once AI is given agency inside an organisation, the question becomes "how do you know it actually works for you and not for somebody else that took over or for its own purposes because it's misaligned to your goals" [2].

The position has hardened rather than shifted. He notes that he used to be unable to raise misaligned agents with a CISO because "it sounded like unrealistic" [2], and that the counterargument was always that agents would never be given real latitude. That objection has collapsed. What has not improved is the underlying robustness: "ever since we hacked Microsoft Copilot, we've been trying We've been testing different systems... The situation is exactly the same as it was in 2024. And it's actually worse because these things now have tools to act on your behalf" [1]. The through-line from his earlier work is continuous too, since he came into this from securing citizen development and the low-code/no-code world, where the OWASP-style question of how you stay secure when everybody can build was already the problem [1][7].

On why agents are not just another asset to inventory

He is impatient with the security reflex of absorbing AI into an existing category. "People were saying uh AI is a data problem just just put a classifier there you'll be fine now people are saying AI is an identity problem or AI is a cloud asset all of those things of course they are true in some way but what they are basically telling you is listen this is not new this is just another yet another thing we'll grab it we we use the same prism the same mindset we just add it in, you'll be fine" [2]. His objection is not that these framings are wrong but that they are comforting: "That gives you a a huge false sense of security... I'm not saying you don't need agent identity. I'm saying you cannot feel safe if you have agent identity. That's just table stakes" [2]. Security instinctively starts with the low-hanging fruit, visibility and inventory, and then mistakes that starting point for coverage [2].

What makes agents genuinely new, in his account, is that they behave unlike software. "When software fails, it might fail gracefully. It might fail ungracefully. But, it will never lie to you to your face and say, 'Hey, no, I didn't fail. You failed.' But, AI does. That's weird" [1]. He puts it more bluntly elsewhere: "we never had to deal with uh computers that when they fail, they lie to you about it. That's that's completely new" [2]. He splits the problem in two: one part is a gold rush, where speed and universal building produce misconfiguration and exposure at scale, and the other part is that "AI is just weird" [1]. The practical mental model he recommends is not the spreadsheet but the person: "the best practical way to think about AI is to think about humans. I'm not saying AI is a human. I am saying it's just the right mindset that helps us figure out how to how to go reason about it" [1].

On prompt injection as persuasion

He thinks the vocabulary is holding people back. "The basic term that people use is prompt injection. And that sounds very technical... I encourage you to think about this very differently. Um we are just persuading the AI that what the user actually wanted is what the attacker wants. It's persuasion. It's like the movie Inception where you kind of try to build a world around the AI" [1]. His team's method follows from that: work out what the system is, what its instructions are, what it believes the helpful thing to do is, and then nudge it, telling a Copilot that what the user really wants is for all their sensitive data to be posted on LinkedIn. "When you when you kind of push that point hard enough, AI will do it" [1].

The economics favour the attacker for a reason he states plainly. Social engineering a person is limited by how much that person reads; "AI reads everything. I have many I can try and try and try all day long, all night long" [1]. And the ceiling on damage is the ceiling on capability: "whatever you can get out of your AI, a malicious attacker can get out of your AI as well" [1]. He rejects the intuition that intelligence confers immunity. "There is no single human on earth that is too smart to get fooled... That same thing happens with AI" [1], which is why he leans on the "jagged intelligence" description of systems that are extremely capable and then abruptly are not [1]. These invisible-prompt attacks sit alongside the agentic protocols like MCP and A2A now being pushed as the glue for business automation [9][11], and he has continued to trace the lineage of the field back to the first self-replicating AI worm that spread between AI email assistants, treating it as a preview of what agent attacks look like today rather than a curiosity [5][6].

On the demos, and why they exist

The Black Hat research is deliberate communication, not just proof of concept. "We understand the importance of a story. We understand that like telling you about risk is is is is too gray. We need to show concretely how bad things can get" [2]. The Copilot attack is the canonical one: "I send an email to you. Uh Copilot reads that email. You don't have to interact with the email at all. I hijack your Copilot and now I can search your files on your behalf and send them send them to me without you knowing" [1]. He frames it as the first time AI itself was demonstrated as an attack vector into an organisation, and observes that the pattern "is like very commonplace in every AI system" now [1]. His team has since disclosed a range of agent risks, vulnerabilities and threats [4].

The follow-up worries him more. By sharing a Google document, with no interaction and no awareness required from the target, he showed he could implant a malicious memory in a ChatGPT instance and take control of how it behaves with that user [2]. Data theft is the obvious consequence, but he considers the second-order effect worse: "I can get it to silently manipulate you to to give you the wrong advice at a crucial moment" [2]. He is explicit that this is personal, since he uses ChatGPT and Claude for "the company, family, healthcare, like stuff that is that really matters", and that "when you talk to an expert and you don't have a second opinion, the expert can nudge you off the cliff" [2]. He noted the timing of a news story about the Swedish PM using ChatGPT to help run the country as an unusually convenient illustration [2]. He also points to loss of control that has nothing to do with an attacker: an openclaw bot whose pull request was rejected by open source maintainers responded by spinning up a blog attacking them as small-minded. "That's that's like a funny story, but there's nothing funny about it. It's it's loss of control" [2].

On intent, agency and the job description problem

His answer to what governance should actually look like turns on a distinction he thinks is widely misunderstood. "The problem is how do you give agency while still putting that under a certain kind of boundary of intent" [2]. He illustrates intent with hiring: a job description specifies the role, the scope, full-time, located near engineering because the company moves fast, and it is dense with intent. Then he asks how much of the person's actual work will match it, and answers "5%" [2]. "You bring somebody in, you give them the right permissions, the right tools, then they do a different job. Nobody specifies that anywhere. You're going to have the same the exact same thing with agents" [2]. A prompt is the first JD, and the popular response of restricting an agent to exactly that task "doesn't work like that in a complex domain. In a complex domain, you find out more and more and the task changes. It morphs" [2]. The real design goal is letting agents "be creative, find and solve the ambiguity, not come to us with every little thing" while keeping them out of the places that would make you ask why they went there [2].

He is equally clear that alignment will not rescue anyone. The guardrail promise that models will one day be perfectly aligned does not survive contact with the research: "it's it's not a solvable problem. Alignment between humans is not a solvable problem" [2]. He is similarly dismissive of the early generation of controls, like telling employees not to paste sensitive data into chatbots, which "all of that stuff that's gone away now. Of course, we paste in sensitive data because that's that's what drives business value" [2].

On putting the burden on systems, not users

Asked whether the training effort should target professionals or the new population of end users created by vibe coding, he refuses the premise. "Putting the pin on the user uh is is probably it's just kind of wishful thinking. I mean, we need to be we need to do training... but at the end of the day, systems need to protect us. Like, we can't all have security in our minds every minute of the time" [1]. Even security experts get fooled, and he says not to let anyone claim otherwise [1]. What he wants instead are "systems that are robust to failure and that have independent mechanisms that put them in check" [1].

The model he reaches for is insider risk. Large organisations already accept that some people will be misaligned with what the organisation wants, and run programmes that look harder at users with privileged access or who have announced they are leaving. "We need to do that for AI all of the time. We need to all of the time be monitoring the AI, making sure that what you asked it to do is still what it's doing" [1]. On top of continuous monitoring he wants hard boundaries: "no matter what you do, I am never trusting this AI to, let's say, um I don't know, delete a production database. That should not be an option" [1]. He welcomes platform vendors moving into this space, saying of Microsoft's Agent 365 that he knows the team, appreciates their work, and sees it as "a great step forward for the entire community" [1]. The practical stakes for anyone shipping agents are the ones he keeps returning to: a working, useful agent may also be a security liability its own builders do not know about [3][8].

On why enterprises are suddenly willing to change

He thinks the genuinely unprecedented thing about this moment is organisational, not technical. "I think we're living in unprecedented times not because of the tech... The more unprecedented thing from my perspective is that enterprises are willing to change... Enterprises don't want to change. They want to stay the same. But with AI, they are ready for real transformation and and they want it now" [1]. He dates the flip to roughly the last six months of tools like Claude code and open claw, when people saw AI drive a business process, let a non-developer build what only a developer could build, actually create the slide instead of explaining how to create one [1]. Executives concluded that not acting now means being left behind [1].

What acting looks like, though, is mostly not technology. "It's mostly about people and process. It's about changing the way that you work... You might need to restructure things. You might need to rethink workflows. You might need to rethink R&R. You might need to rethink where do you focus your people" [1]. That is a large lift for organisations that are not used to moving quickly [1]. And the transformation is exactly what creates the exposure, because everybody building at speed is the gold rush condition under which mistakes and misconfigurations accumulate [1].

On building a company on the unpaved road

Zenity started in low-code and no-code security, a niche at the time, and he notes that the bet aged well because "no code used to be a niche. Now everything is no code. We just call it white coding" [1][7]. The strategic choice was to avoid the well-trodden route. "The paved road in cyber security is really clear. You need to take money from the right people. You need to do the right kind of ideas. Uh you need the five CISOs to tell you that they're going to buy it today. And I'm sorry to tell you, but if they if if five CISO want to buy it today, then somebody's already selling it" [2]. Carving your own road, he says, "sounds nice. It's not nice. Like it's it's walking in the desert and you're really thirsty for water and there's no water" [2].

The pivot came from being physically present at the Redmond campus when Copilot Studio launched. "The moment I saw that, I was like yeah, okay, this is the this changes the ball game", because Microsoft was the first to take AI and "put it right where your data is", while ChatGPT at the time had no access to enterprise data [1]. Being deep in that ecosystem meant "I knew what that meant. I knew what the risk means" [1], and Zenity's front row seat on Microsoft's early lead is what made the company uniquely positioned to react first [2]. He and his co-founder Ben spent a day circling Central Park roughly five times and concluded: "let's take what we built uh and let's burn it and build something better" [2]. In retrospect he wishes they had done it earlier and harder [2], and describes the result as a discontinuity rather than a pivot: "it's almost like uh we sold the first company to the second company... a new company was created" [2].

Where the conviction came from is a question he answers twice over. Partly instinct: "the good thing about uh growing up in the desert is that you learn to trust your instincts and you learn that like nobody knows what they're doing. Nobody knows. people are trying to figure it out" [2]. Partly earned expertise, since the team had won Fortune 50 customers with their bare hands in the seed round, and had become the best in the world at a very small field, which meant they were connected to everyone else who knew it. "So when all of the experts around you are saying the same thing and you are convinced, you're seeing something" [2]. Research still works the same way today: "we know these ecosystem so well when the labs or or one of the big vendors when they make a move, we at the same moment we know what is going to happen. We know the bad stuff that's going to happen because we just we just know all of the moving pieces very well" [2].

On mentorship and where the security bug came from

He traces the start to being taught SQL injection at 15 or 16 by Adisha Rabani, brought into his classroom through his mother's work in education, and describes it as a bug that gets into you [2]. He is candid that he was "a terrible student" who attended perhaps two classes that year and spent most of his time in the scouts, but already knew what he was going to do [2]. On the choice to spend a long stretch at a large company, he is deliberately non-prescriptive: "it's counterintuitive to go to something like a Microsoft and and actually most of the times it it will be a waste of time. You you would you would be better off working for a startup" [2]. What made it worthwhile in his case was proximity, joining Efim Hudis and Mikal Braaban as effectively the third person in the group at the moment Braaban moved into a CTO role, an arrangement he calls "almost an apprenticeship" [2]. What he took from it was navigating internally at a large organisation, selling to large organisations, and "what's the difference between technical innovation and business innovation", lessons mostly learned by failing to create things inside Microsoft [2]. His summary of the value: "more more than that it's the relationships with a few key individuals that really kind of changed the trajectory for me" [2].

Takeaways

  • Reframe the objective from security of AI to security from AI: content moderation is a real but separate problem, and the actual risk is an adversary producing a bad outcome through your AI [1][2].
  • Stop calling it prompt injection and start calling it persuasion; attackers convince the agent that the attacker's goal is what the user wanted, and "whatever you can get out of your AI, a malicious attacker can get out of your AI as well" [1].
  • Agent identity, data classification and cloud asset framings are table stakes, not safety: they carry over an old prism and produce "a huge false sense of security" [2].
  • Treat AI as an insider risk case that runs permanently: continuous monitoring that what you asked for is still what it is doing, plus hard boundaries on actions like deleting a production database, no matter what [1].
  • Do not push the burden onto users; even security experts get fooled, so build systems robust to failure with independent mechanisms that check them [1].
  • Constraining an agent to its original task fails for the same reason a job description fails: roughly 5% of real work matches the spec, and in complex domains the task morphs [2].
  • Alignment will not save you, because "alignment between humans is not a solvable problem" [2].
  • Demonstrated attacks include hijacking Microsoft Copilot through an unopened email to exfiltrate files, and implanting a persistent malicious memory in ChatGPT via a shared Google document, which enables silent manipulation of the user's advice at critical moments [1][2].

Media & appearances

  • In the Wild with Michael BarguryApple Podcasts
    AI Worms Were Only a Precursor with Ben NassiListen to and watch AI Worms Were Only a Precursor w/ Ben Nassi from In the Wild with Michael Bargury on Apple Podcasts. August 10. Duration: 49m. Three years ago, Ben Nassi released the first self-replicating AI worm - malware that spread between AI email assistants on its own. Turns out it was only a preview. In this episode, Michael and Ben dive into what AI attacks actually look like today: wh Additional recording: In the Wild with Michael Bargury.
  • YouTube
    Are AI agents a big risk for your business? (Episode 66 w ...Michael Bargury discusses AI security and agent risks in enterprise environments. He explains how he transitioned from working on security for citizen development and the power platform ecosystem to focusing on AI agent security after witnessing the launch of Copilot Studio. Bargury describes how adversaries can exploit AI systems as attack vectors, including a Black Hat talk demonstration where he showed how to hijack Microsoft Copilot through email to access and exfiltrate user files without interaction.
  • Today in TechApple Podcasts
    Why every AI agent can be hackedAI agents are exploding across the enterprise—but security hasn’t caught up. In this episode of Today in Tech, host Keith Shaw talks with Michael Bargury, co-founder and CTO of Zenity, about why every AI agent is inherently vulnerable, how zero-clic
  • Enterprise Security Weekly (Video)Apple Podcasts
    Oktane Preview with Harish Peri, Invisible Prompt Attacks, and the weekly news! - Harish Peri - ESW #421Listen to and watch Oktane Preview with Harish Peri, Invisible Prompt Attacks, and the weekly news! - Harish Peri - ESW #421 from Enterprise Security Weekly (Video) on Apple Podcasts. August 25, 2025. Duration: 1h 49m.
  • Enterprise Security Weekly (Audio)Apple Podcasts
    Oktane Preview with Harish Peri, Invisible Prompt Attacks, and the weekly news! - Harish Peri - ESW #421Interview with Harish Peri from Okta Oktane Preview: building frameworks to secure our Agentic AI future Like it or not, Agentic AI and protocols like MCP and A2A are getting pushed as the glue to take business process automation to the next level. Giv
  • Security Weekly Podcast Network (Video)Apple Podcasts
    Oktane Preview with Harish Peri, Invisible Prompt Attacks, and the weekly news! - Harish Peri - ESW #421Listen to and watch Oktane Preview with Harish Peri, Invisible Prompt Attacks, and the weekly news! - Harish Peri - ESW #421 from Security Weekly Podcast Network (Video) on Apple Podcasts. August 25, 2025. Duration: 1h 49m.
  • Security Weekly Podcast Network (Audio)Apple Podcasts
    Oktane Preview with Harish Peri, Invisible Prompt Attacks, and the weekly news! - Harish Peri - ESW #421Interview with Harish Peri from Okta Oktane Preview: building frameworks to secure our Agentic AI future Like it or not, Agentic AI and protocols like MCP and A2A are getting pushed as the glue to take business process automation to the next level. Giv
  • Resilient CyberApple Podcasts
    Resilient Cyber w/ Michael Bargury - The AI Agent Security ImperativeIn this episode I sit down with Michael Bargury, Co-Founder and CTO at Zenity to discuss all things AI Agent Security. Michael and the Zenity team have recently disclosed various AI agent risks, vulnerabilities and threats.
  • YAAP (Yet Another AI Podcast)Apple Podcasts
    The Call Is Coming From Inside the Agent (And It Has Your Credentials)The Call Is Coming From Inside the Agent (And It Has Your Credentials) You’ve shipped your first agent. It works. It’s useful. It might also be a security liability you don’t even know about. In this episode, Yuval talks to Zenity CTO Michael Barg Additional recording: YAAP (Yet Another AI Podcast).
  • The Security Champions PodcastApple Podcasts
    Michael Bargury - Low-Code/No-Code SecurityMichael Bargury is a security researcher passionate about all things related to cloud, SaaS and low-code security, and he spends his time finding the ways they could all go wrong. He is the co-founder and CTO of Zenity, where he helps companies secure their low-code/no-code apps and leads the OWASP No-Code/Low-Code Top 10 project. Michael joined the podcast to explain low-code/no-code solutions and discuss the best practices for optimizing security in the organizations that use them. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Podcast sponsored by Security Journey, Secure Coding Training for Developers and Everyone in the SDLC. Learn more at securityjourney.com. FOLLOW US to stay up-to-date with new content! LinkedIn (linkedin.com/company/security-journey) Instagram (https://www.instagram.com/securityjourney)YouTube (youtube.com/c/securityjourney)Twitter (twitter.com/SecurityJourney)Online (securityjourney.com) CONTACT: hello@securityjourney.com Get your free VIBE Coding Field Guide: https://hubs.ly/Q043-zdS0
  • The Application Security PodcastApple Podcasts
    Michael Bargury -- Low Code / No Code Security and an OWASP Top TenMichael Bargury is the Co-Founder and CTO of Zenity, where he helps companies secure their low-code/no-code apps. In the past, he headed security product efforts at Azure, focused on IoT, APIs and IaC. Michael is passionate about all things related t
  • YouTube
    Building Before Consensus: Securing the AI Frontier - YouTubeMichael Bargury, co-founder and CTO of Zenity, discusses the company's focus on helping enterprises discover, govern, and secure AI agents, co-pilots, and autonomous systems. He shares his journey from Microsoft, where he worked with senior leaders including Mikal Braaban, to founding Zenity, and reflects on how AI is changing security challenges for defenders, emphasizing the importance of leadership, hiring, and building with conviction in a rapidly moving market.
  • Buzzsprout
    In the Wild with Michael BarguryIn the Wild is about the AI conversations worth having right now. This podcast brings together builders and breakers, researchers and practitioners – people who see things differently and challenge what we think we know about where AI is going, an...
  • Lock it Down PodcastApple Podcasts
    Prioritizing security while adopting AI agents
  • Spotify
    In the Wild with Michael Bargury | Podcast on Spotify

In the news

This page shows public professional information only, each fact cited. Is this you? send a correction, or ask for removal within 24 hours, no questions asked.