Video wird geladen...
Video konnte nicht geladen werden
This new AIUC-1 "AI agent compliance standard" is a massive grift. Everyone involved is taking something for themselves. The "losers" here are the companies that might rely on this thinking it means something and the startups that will have to pay to get audited.
27,289 Aufrufe • vor 5 Monaten •via X (Twitter)
44 Kommentare

I see new Zack video, I watch new Zack video

Holy shit at some point I just need to have you on the channel for a video, this is dedication

A goal, but I know nothing, I learn through you 😂

Tbh that could be interesting still. Some of the best content I have is me explaining stuff based on questions I’ve gotten

I guess one question I've had, is there a specific work flow you go through when poking these agents and stuff? Or just normal install and then try to break out of their "bulletproof sandbox"? (silly question)

Launch a competitive start up at delve-quality. I’ll send you a couple hundred bucks, you send me a certification on the back of a Chuck E Cheese menu.

Hahahaha, this is a great idea. I’m a little tempted to find a way to make that as a joke.

Do it and I could probably get HR to include it in job posts “Must be familiar with Korman-Agentic compliance standards”

That would be my life’s greatest and most pointless accomplishment at the same time

Did you see the the spreadsheet "informational purposes" only 😅

Agreed. Plenty of other companies will have to suffer implementing useless controls, and will add more load instead of addressing things that actually count.

i love your videos man, keep em coming

Thanks so much! I really appreciate it

compliance is a comfort created for people with no technical background, like sales reps who can slap AIUC at anyone who speculates on free will, anyone can audit everything for a company, they can even start social media vetting of companies The right evaluation would be to find risk vectors and cover that in priority than overlapping compliance standards which doesn't move the needle

Sales is gonna love aiuc-1 so much

Not to spam the chat, but I see CSA on there. Willing to bet it maps to MAESTRO, which is the worst, most least prescriptive framework I’ve ever seen in my life. A video diving into the AI security frameworks is warranted at this point.

It seems they went with the CSA AI Controls Matrix instead. But wow they got a lot in there

*Mic drop*

Doing my best to call this shit out

I know you pointed to fedramp, but in the comparators they noted hitrust which, is something to be strangely openly proud about as they are the poster children of this approach. Is the underlying thesis just compliance frameworks should be non profit and organically adopted?

Yea I mean I saw they used hitrust but I’m just not familiar with it because I’m not in healthcare. And basically yes. All of the shenanigans I point to in the video are downstream of the original sin of this being an inherently profit seeking enterprise from day 1. The goal is to serve these participants first and foremost

Thanks for spending the time on this

Thanks for watching!

using a company logo because one of the investors works there is absolutely insane work

Yep. I wonder how many of these orgs really are okay with their logos being used here

The grift of failing legacy orgs too.

This is “Show me the incentives and I’ll show you the outcome” in its fullest form

Yea now I’m wishing I said that in the video hahah

My prior background was with agents, not security - you can tell who actually understands agents in agent security vs blanket applies security patterns to this new problem It results in this performative stuff with deception as a huge incentive unfortunately

Great work, solid education for the space overall

Thank you!

Can we stop chasing frameworks and focus on what actually matters, like security best practices, strong governance, and safeguards that reduce real risk? Compliance should follow from that, not replace it.

not to mention they just released an "update" so the framework is a moving goalpost... how is the audit approach supposed to keep up

Thanks for being vulnerable and sharing real authentic thoughts. Saying something if you see something off is beneficial for the ecosystem. 🙏

While I do agree with you I do think there should be an alternative perhaps ISO which was passed last year..

Sure, if we have to have a standard I want it to come from a body that isn’t very clearly profit seeking

Totally agree with this. I've dealt with compliance (EU type and SEC type they have to come from governmental or non profit). Companies can also create and enforce their own standards there's nothing stopping them doing this.

Ok, but putting it next to FedRamp might not be as absurd as you think... "Federal cyber experts thought Microsoft’s cloud was 'a pile of sh*t,' yet it was authorized because the government had already made itself too dependent to say no."

I would be okay with it if they said “Don’t worry the us government is corrupt just like us”

Sorry, why is it a problem for it to be a for-profit certifying body? AFAIK their technical work has been good, they have a competent team, and a lot of this was built on @Miles_Brundage's really good work on AI standards as a safety strategy (

Agreed

All theatrics, why am I not surprised

Great breakdown followed

Thanks! Doing my best to expose this stuff

