Video wird geladen...

Video konnte nicht geladen werden

Zur Startseite

This new AIUC-1 "AI agent compliance standard" is a massive grift. Everyone involved is taking something for themselves. The "losers" here are the companies that might rely on this thinking it means something and the startups that will have to pay to get audited.

27,289 Aufrufe • vor 5 Monaten •via X (Twitter)

44 Kommentare

Profilbild von Brandon ッ
Brandon ッvor 5 Monaten

I see new Zack video, I watch new Zack video

Profilbild von Zack Korman
Zack Kormanvor 5 Monaten

Holy shit at some point I just need to have you on the channel for a video, this is dedication

Profilbild von Brandon ッ
Brandon ッvor 5 Monaten

A goal, but I know nothing, I learn through you 😂

Profilbild von Zack Korman
Zack Kormanvor 5 Monaten

Tbh that could be interesting still. Some of the best content I have is me explaining stuff based on questions I’ve gotten

Profilbild von Brandon ッ
Brandon ッvor 5 Monaten

I guess one question I've had, is there a specific work flow you go through when poking these agents and stuff? Or just normal install and then try to break out of their "bulletproof sandbox"? (silly question)

Profilbild von Zach Bovaird
Zach Bovairdvor 5 Monaten

Launch a competitive start up at delve-quality. I’ll send you a couple hundred bucks, you send me a certification on the back of a Chuck E Cheese menu.

Profilbild von Zack Korman
Zack Kormanvor 5 Monaten

Hahahaha, this is a great idea. I’m a little tempted to find a way to make that as a joke.

Profilbild von Zach Bovaird
Zach Bovairdvor 5 Monaten

Do it and I could probably get HR to include it in job posts “Must be familiar with Korman-Agentic compliance standards”

Profilbild von Zack Korman
Zack Kormanvor 5 Monaten

That would be my life’s greatest and most pointless accomplishment at the same time

Profilbild von Ethan Troy
Ethan Troyvor 5 Monaten

Did you see the the spreadsheet "informational purposes" only 😅

Profilbild von SecInterviewHub
SecInterviewHubvor 5 Monaten

Agreed. Plenty of other companies will have to suffer implementing useless controls, and will add more load instead of addressing things that actually count.

Profilbild von Muratcan Koylan
Muratcan Koylanvor 5 Monaten

i love your videos man, keep em coming

Profilbild von Zack Korman
Zack Kormanvor 5 Monaten

Thanks so much! I really appreciate it

Profilbild von Prismor
Prismorvor 5 Monaten

compliance is a comfort created for people with no technical background, like sales reps who can slap AIUC at anyone who speculates on free will, anyone can audit everything for a company, they can even start social media vetting of companies The right evaluation would be to find risk vectors and cover that in priority than overlapping compliance standards which doesn't move the needle

Profilbild von Zack Korman
Zack Kormanvor 5 Monaten

Sales is gonna love aiuc-1 so much

Profilbild von Zach Bovaird
Zach Bovairdvor 5 Monaten

Not to spam the chat, but I see CSA on there. Willing to bet it maps to MAESTRO, which is the worst, most least prescriptive framework I’ve ever seen in my life. A video diving into the AI security frameworks is warranted at this point.

Profilbild von Zack Korman
Zack Kormanvor 5 Monaten

It seems they went with the CSA AI Controls Matrix instead. But wow they got a lot in there

Profilbild von Lennie Budgell ❇️
Lennie Budgell ❇️vor 5 Monaten

*Mic drop*

Profilbild von Zack Korman
Zack Kormanvor 5 Monaten

Doing my best to call this shit out

Profilbild von 🏞️
🏞️vor 5 Monaten

I know you pointed to fedramp, but in the comparators they noted hitrust which, is something to be strangely openly proud about as they are the poster children of this approach. Is the underlying thesis just compliance frameworks should be non profit and organically adopted?

Profilbild von Zack Korman
Zack Kormanvor 5 Monaten

Yea I mean I saw they used hitrust but I’m just not familiar with it because I’m not in healthcare. And basically yes. All of the shenanigans I point to in the video are downstream of the original sin of this being an inherently profit seeking enterprise from day 1. The goal is to serve these participants first and foremost

Profilbild von Br*an
Br*anvor 5 Monaten

Thanks for spending the time on this

Profilbild von Zack Korman
Zack Kormanvor 5 Monaten

Thanks for watching!

Profilbild von cbro
cbrovor 5 Monaten

using a company logo because one of the investors works there is absolutely insane work

Profilbild von Zack Korman
Zack Kormanvor 5 Monaten

Yep. I wonder how many of these orgs really are okay with their logos being used here

Profilbild von Hank Yeomans
Hank Yeomansvor 5 Monaten

The grift of failing legacy orgs too.

Profilbild von Rohit Ganguly
Rohit Gangulyvor 5 Monaten

This is “Show me the incentives and I’ll show you the outcome” in its fullest form

Profilbild von Zack Korman
Zack Kormanvor 5 Monaten

Yea now I’m wishing I said that in the video hahah

Profilbild von Rohit Ganguly
Rohit Gangulyvor 5 Monaten

My prior background was with agents, not security - you can tell who actually understands agents in agent security vs blanket applies security patterns to this new problem It results in this performative stuff with deception as a huge incentive unfortunately

Profilbild von angel.apt
angel.aptvor 5 Monaten

Great work, solid education for the space overall

Profilbild von Zack Korman
Zack Kormanvor 5 Monaten

Thank you!

Profilbild von Tyler Jolly
Tyler Jollyvor 5 Monaten

Can we stop chasing frameworks and focus on what actually matters, like security best practices, strong governance, and safeguards that reduce real risk? Compliance should follow from that, not replace it.

Profilbild von Mike
Mikevor 5 Monaten

not to mention they just released an "update" so the framework is a moving goalpost... how is the audit approach supposed to keep up

Profilbild von Venture Fellow aka J VC
Venture Fellow aka J VCvor 5 Monaten

Thanks for being vulnerable and sharing real authentic thoughts. Saying something if you see something off is beneficial for the ecosystem. 🙏

Profilbild von Jesse Jr Lim (林振燊)
Jesse Jr Lim (林振燊)vor 5 Monaten

While I do agree with you I do think there should be an alternative perhaps ISO which was passed last year..

Profilbild von Zack Korman
Zack Kormanvor 5 Monaten

Sure, if we have to have a standard I want it to come from a body that isn’t very clearly profit seeking

Profilbild von Jesse Jr Lim (林振燊)
Jesse Jr Lim (林振燊)vor 5 Monaten

Totally agree with this. I've dealt with compliance (EU type and SEC type they have to come from governmental or non profit). Companies can also create and enforce their own standards there's nothing stopping them doing this.

Profilbild von Rob Terrin
Rob Terrinvor 5 Monaten

Ok, but putting it next to FedRamp might not be as absurd as you think... "Federal cyber experts thought Microsoft’s cloud was 'a pile of sh*t,' yet it was authorized because the government had already made itself too dependent to say no."

Profilbild von Zack Korman
Zack Kormanvor 5 Monaten

I would be okay with it if they said “Don’t worry the us government is corrupt just like us”

Profilbild von Agus 🔸
Agus 🔸vor 5 Monaten

Sorry, why is it a problem for it to be a for-profit certifying body? AFAIK their technical work has been good, they have a competent team, and a lot of this was built on @Miles_Brundage's really good work on AI standards as a safety strategy (

Profilbild von g
gvor 5 Monaten

Agreed

Profilbild von Chaitanya
Chaitanyavor 5 Monaten

All theatrics, why am I not surprised

Profilbild von bob🐢
bob🐢vor 5 Monaten

Great breakdown followed

Profilbild von Zack Korman
Zack Kormanvor 5 Monaten

Thanks! Doing my best to expose this stuff

Ähnliche Videos

David Sacks: America needs “a single national standard” in AI to beat China and avoid Woke AI Sacks on E245: “There's a regulatory frenzy happening at the states right now.” “Everyone just seems to be motivated by the imperative to ‘do something’ on AI, even though no one's really sure what that something should be.” “So you've got 50 different states each with their own reporting regime, which is going to be a trap for startups. They've all gotta figure this out about what they're supposed to report on, what the deadlines are, who to report to.” “A single federal standard is the best way to make sure that we do not have Woke AI, that we do not have insanely burdensome regulations that allow China to basically get ahead of us in this AI race, and it's to ensure that we actually have truthful, unbiased AI instead of highly ideological AI.” – According to Polymarket, chances of a National AI Bill in 2025 are VERY LOW, despite a regulation frenzy at the state level. – At the time of taping, there was a ~20% chance. Today it’s significantly lower at 5%. “Here's the good news, it doesn't really matter what I think. The important thing is what President Trump thinks.” “And in his July 23rd speech on AI, he was really clear that there needs to be a single national standard for AI.” “I think the administration ultimately will support this, and I think more Republicans will come on board as they realize what the blue states are doing here is not helpful for conservatives. It's not helpful for having an unbiased information environment.”

The All-In Podcast

103,113 Aufrufe • vor 1 Jahr