New! AI Code Review Academy, a hands-on learning hub
→ See now

Why AI Control is the New Security Standard

00:00 00:00

July 22, 2026 32 minutes

Why AI Control is the New Security Standard

Summary

This episode explores the transition from synthetic data to AI security and explains why visibility into “shadow AI” is the first step toward building a robust control plane. Learn how to steer a fleet of thousands of agents while maintaining low latency and high accuracy in production environments.

this episode’s guest

Gil Elbaz

Chief AI Officer at Onyx Security

Gil Elbaz is the Cofounder and Chief AI Officer at Onyx Security, where he focuses on the intersection of artificial intelligence and enterprise security. With over 15 years of experience in the machine learning field, he previously served as an AI Architect within the NVIDIA CTO office, working directly on LLM deployment strategies and distributed training for global enterprises. His technical background also includes a five-year tenure as the CTO of Datagen, a role in which he built foundational synthetic data infrastructure. Throughout his career, he has specialized in developing robust machine learning systems for high-stakes environments where accuracy and production-level reliability are critical requirements.

Key takeaways

  • The critical shift from standard cybersecurity frameworks to AI control and alignment
  • How to utilize synthetic data pipelines to train high-accuracy, low-latency security models
  • Strategies for managing “shadow AI” across the cloud, browser, and no-code tools
  • The impact of the exponential growth in agent-to-agent communication on organizational security
  • Why the “human in the loop” remains the ultimate guardrail for agentic governance

Chapters

  • Lessons from NVIDIA on AI agent infrastructure
  • Defining AI control beyond standard security
  • Building a mesh of small language models for validation
  • Helping CISOs and CIOs navigate the shadow AI landscape
  • Managing the exponential growth of agent actions
  • Navigating the risks of agent-to-agent communication

Transcript

[00:00:01] Gil: If you can’t see it, if it’s shadow AI, if it’s not known to the organization, it’s very hard to control and put the right guardrails in place.

[00:00:10] Itamar: Welcome to Agentic Review, the podcast where we explore what good code really means in the age of AI software development.

[00:00:18] Nnenna: I’m Nnenna Ndukwe, Developer Relations Lead.

[00:00:21] Itamar: And I’m Itamar Friedman, the cofounder and CEO of Qodo.

[00:00:24] Nnenna: So, let’s get into it.

[00:00:30] Itamar: Today, we’re joined by Gil Elbaz, cofounder and Chief AI officer at Onyx Security, a company at the intersection of AI and security. Gil spent 5 years as a CTO of Datagen building synthetic data infrastructure, which we’re gonna talk about, I’m quite sure, then moved inside NVIDIA’s CTO office as an AI architect, where he spent 18 months working directly on LLM deployment strategy with some of the largest enterprise in the world. And that’s not surprising because even before that, he built ML systems in complex environments, where good enough wasn’t an option. So, without further ado, Gil, welcome to the show.

[00:01:13] Gil: Thanks, Itamar. It’s great to be here.

[00:01:15] Itamar: So, tell us a little bit more about yourself. Love to know what I didn’t miss.

[00:01:18] Gil: Sure. So, I’ve been in the machine learning space for the past 15+ years, did a number of different roles, but recently worked under the global CTO of NVIDIA as a direct report, focusing mostly on distributed training and also on AI and AI agent infrastructure internally. And we built out a number of pretty large-scale AI agent projects when the technology and the models themselves were pretty early on, and had a lot of interesting experiences trying to build out production-level systems that would be robust, systems that touch real data and run on real infrastructure. And there, we faced a number of challenges, but one of the big ones that just stuck in my mind there was around security. How do we build out this infrastructure in a way that is secure, and robust, and enterprise-grade? And at that time, we were just trying to patch things up and make it work, of course. But we understood pretty quickly that this isn’t just an NVIDIA problem, and it isn’t just a point-in-time back-then problem. Rather, it’s a challenge that every organization creating AI agents, and today, that’s almost every organization, is going to face and is facing today. And it’s also a moving target, right? This is a challenge that is constantly evolving from the point of pre-coding agents to coding agent challenges to challenges around more advanced agents like OpenClaw and similar harnesses. And so, we built out many different security capabilities back then, but essentially understood that in order to really solve this challenge, in order to really bring this capability to every organization, you need to leave NVIDIA, create a company that is fully focused on this, and that’s what we did with Onyx.

[00:03:05] Itamar: That’s awesome, and an awesome name, by the way. So, I think at some point, I saw that in your LinkedIn banner, it says, like, control AI, create the impossible. Now you talked a lot about security, but is there more to that? Like, what does controlling AI actually mean for you?

[00:03:20] Gil: Yeah. I think that we look at the AI that existed a few years ago, and today it looks ancient, right? Today it looks extremely not capable. The AI today seems extremely capable. And what will exist in a few years forward is even more, I think, mind-blowing, right, relative to what we have today. We’re seeing this exponential growth, and it’s very hard to conceptualize because of these step change functions that we see every few months, every few weeks sometimes. And so the concept that we have in place is not only how do we stop AI from doing things that shouldn’t be done. In a standard security setting, you usually have an attacker, and you wanna stop that attacker from abusing your infrastructure from doing specific actions to your organization. And in this case, it’s not necessarily a standard security framework. There’s a challenge of agents, we sometimes call them rogue agents, but agents doing destructive actions, unintended consequences to a prompt or a goal that we give these agents, and we need to make sure that these agents are aligned with what the user requested, but also with the organization’s policies and make sure that the agent is going to be successful. And we want it to be successful, but we wanna steer it in the right directions as it’s acting and steer away from the pitfalls that it might fall into. And so when we look at this problem of security, we look at it from the lens of control. How do we give the controls to the enterprises to be able to control not one agent, but all of the agent fleet that they have under them, and make sure that they’re all aligned with policies, working correctly? And we wanna make them as successful as possible, of course, but keep them in control.

[00:05:05] Itamar: That makes a lot of sense. But let me challenge you a little bit on that, if that’s okay. I guess you’re familiar with philanthropic constitutional AI, where they’re kind of, like, sharing what kind of constitution they are expecting their LLMs, their AI to follow. And, supposedly, why do we need all these, like, guardrails and control? Like, wouldn’t LLM Labs, a Foundation Labs, solve it for us? They are training their LLMs for the better of humanity, for the better of Anthropic, but also for the better of the company that is using it. And you just need to give the prompt, and you know, share it with your skills and your values of what’s right and wrong, and it will take it from there, right? So, what am I missing? Why is it not gonna be solved this way?

[00:05:49] Gil: I think it’s a great question. We have a perspective on this, and this is true across almost every kind of security area, right? There’s providers that are providing a specific service, and you don’t necessarily want those providers to be the ones that are also validating that that service is aligned with an organization or aligned with the end user. And so, you know, if it’s the FDA and the pharma organizations or, you know, if it’s a standard cybersecurity company like one of the massive cybersecurity companies keeping our cloud in check, our network in check, our infrastructures in check. We have that separation, and I think it’s a very healthy separation. And in a similar way, you know, these companies, Anthropic, OpenAI, they’re amazing companies. They’re fully focused on creating the best models, the best LLMs possible, and that’s what they do. They, of course, do care a lot about security and a lot about safety, but their main goal is to provide the best LLMs possible. And what we’re trying to do at Onyx is provide the tools needed for the management of these large-scale organizations to be in control of not just one LLM, not just one agent, but a fleet of thousands of agents and be able to actually both understand from a visibility perspective what exists, from a configuration and posture perspective, what it’s connected to, what data it has access to, what tools it has, and then from a runtime perspective, make sure that the agents are behaving in ways that are expected and aligned, and if not, steer them in the right directions.

[00:07:26] Itamar: Yeah. Makes sense. I do feel that while we want LLMs to have their set of beliefs, this will help them to serve our agentic workflow, the best possible. It’s a little bit like having a hope strategy to think that that will be enough. I believe that, and I’d love to hear more about that. Like, if it’s probably different architecture engineering principles for agents that are purely trying to harness as much as possible for the LLM to complete a task, rather than the engineering that needs to be put in place to have that trust that things are in control and that, you know, for real high assurance. I have to hear about that, but I might be, like, mixing two topics. But let me, if not, it could be really interesting. I think you have, like, an amazing background about synthetic data, and I couldn’t but not think of that when you talked about how do I control and guardrail, like, a full fleet and the space of all the options that are possible when these agents are communicating with each other? Is there any, like, connection to your experience with synthetic data at scale? I’d love to hear if it makes sense.

[00:08:37] Gil: Yeah. Yeah. Definitely. So, how do we go about this need to control the behaviors of these AI agents as a single agent and at scale? Essentially, we sit in between the agent and the LLMs of these agents, and we validate every token before it hits the LLM and once it leaves the LLM, including the thought process, including tool calls, and including any context created. Now this validation, we have our own set, our own mesh of small language models trained by Onyx and our AI team. And, essentially, these models are really good at one thing, right? They’re really good at saying, ‘yes’, ‘no’, or ‘I’m not sure. I need to escalate this.’ And we built out not one model, but a whole set of models that allow us to get both very low latency, under 100ms, p50 of under 60ms, and super high accuracy, and you need a lot of 9s, right? This is 99.999 because of the scale of data and the scale of tokens that we’re processing per day. So, in order not to have, you know, an enormous amount of false positives, you need to get super high accuracy. And so, we built out these models and trained them on synthetic data of not only simple chatbots, but coding agents, advanced agents like OpenClaw and Hermes agent and much more. And to build out these synthetic datasets, you can’t just rely on real usage. We wanna get to the edge cases. We wanna get to the nonstandard cases, and we wanna be able to represent the distribution of data in a more holistic way. And so, we built out large-scale synthetic data pipelines to do this. And the goal isn’t just to represent a single message and say, “Is this a prompt injection or not?” Obviously, attackers are much more advanced than this, but it’s really to take much more of a reinforcement learning type approach where we have a multistep process, and we’re navigating in the space of conversations. And we want to be able to simulate these conversations where an offensive attacker is keeping in mind that they need to not get caught as they’re trying to lead on the LLMs and lead on the agents into directions that will, for example, show off their system prompts, show off their tools, etc. And so we have these advanced setups that really generate synthetic data at scale. We spend a lot of money on synthetic data, and we really try to build it out and create super robust models, both tiny models and different scales of models as we go.

[00:11:11] Itamar: That’s really interesting. And taking, like, your last point about the fact that in Onyx, you’re training your own models, do you think that it applies to others? Like, for example, other startups, or so that, how should they think about when and if at all, like, train their own model? But also for organizations that are, like, well-established around ecommerce, finance, etc, like, any tips? Or when should you be thinking about building your own model versus just system prompting, few shots, or skills-oriented harnessing of leading models?

[00:11:45] Gil: Yeah. It’s a great question. I think the first step of solving almost every problem today, it makes sense to solve with a way too expensive model and a prompt as a first step, and once we get past that first step and we see it working and we have the understanding from a product perspective of what we’re aiming for, then we can start moving towards optimization both of the quality and of the performance. And so we have very, very low latency constraints, which forced us to move towards a training direction earlier. Lower latency is a reason to fine-tune your own models and get to that performance. But, also, if you need to get to top-tier performance because of scale, because of a challenging domain, because of specific domain knowledge that you need to provide these LLMs, that’s a great reason to also fine-tune and train. I will say it’s not easy to do. So, it does require having the right team as well. And there are a lot of amazing folks in many organizations that we’ve worked with, and we’re working with today, that have these teams, but it is important to have the right team in place to train these models effectively and know that it’s a constantly moving target. These models constantly have drift and need to be retrained and improved. Ideally, you should see a curve of improvement over time and not a curve that stays straight or even goes down. So, it’s also important to make sure that these models are continuously being improved.

[00:13:11] Itamar: If I connect the dots between the few things we’re saying, I’d love to hear your thoughts about what I just compiled. Like, it sounds like there should be a prerequisite for training your own model. First is having data. Like, you need to have the data, synthetic production, etc. And then you should be aware that it’s not just like one-time training. You need to have, like, the observability understanding that does this model work well. Do you have the metrics that you’re following, etc? And then third, you need the team. It’s not like plug and play right now. There used to be, like, the auto-mail era. Supposedly, give me some data training model. Right now, it seemed like we’re not there yet. You need to have the right team to create the first version, but then follow up on that. And then fourth, like, the incentive of why you’re doing that. Is this because you’re trying to reduce costs? Probably very important as we go into the second half of 2026, etc. Are you trying to, like, improve accuracy? Did I connect the dots right?

[00:14:07] Gil: 100%. Yeah. And you know, having the right metrics in mind is key to the success of this project, almost any project, right, but for this type of project is absolutely key.

[00:14:19] Itamar: Awesome. Back to, like, the I love the idea of controlling the AI to create the impossible. So, when you’re thinking about engineering teams, security teams, who’s the persona? Who is the stakeholder that needs to think about it? Is, like, the CISO, the actual security expert, the VP of engineering, the CTO, the developer, all of them, each one of them, but in a different way? Like, how should we think about it? Or when we’re leaning to, like, agentic AI? Probably like you said, it’s not just coding, question and answering, like, financial, etc. Who is in charge of what, if that makes sense?

[00:14:55] Gil: Yeah. So, what we see today is that CEOs, boards, and senior management are all pushing to adopt AI. We’re saying, “We want the productivity gains that are promised us from mass adoption of AI across our organization, adopt AI.” And they’re telling their organizations to move fast as well. The employees themselves, they want more tokens. So, I’ve never talked to a developer in the last six months and asked him if he wants less tokens, and they said, “Yes.” It’s not happening. They want more tokens. They wanna move faster, better harnesses. Qodo, for example, is a great example of ways that they can leverage these tokens to create value for the organizations. And, essentially, this is true for developers. It’s true for marketing people, for sales. Across the organization, people are using more and more AI. And then that puts a very specific area in the organization in a bit of a tight spot. The CIOs that need to deal with the budgets and the ROI measurement around this token use, that’s one challenge we see. And another is around security. The CISOs see that the organizations are incurring additional risk by doing this very fast, sometimes less structured adoption of AI, and the VP R&D, the senior management in the R&D side, also see that the productivity is there, but there’s many new things that need to be developed from methodologies to tooling to processes internally, different structures of teams sometimes. So, there’s a lot of change also happening on the R&D side as well. We really focus right now mostly on helping the CISOs and the CIOs gain, first of all, visibility to all of the AI in the organization from the cloud, the bedrocks, you know, all the AI that’s running in the cloud to the endpoints on the actual computers, the agents, the MCPs, the skills to the browser. And we see a ton of AI use in a browser. It’s not just ChatGPT nowadays. It’s the 10,000 other websites to the SaaS, no code, low code, like, for marketing folks and for sales and for finance, we’re seeing more and more use of Claude Cowork, and Microsoft Copilot Studio, and Google’s set of tools, right, Amazon Lex, for example. We see a broad range of these no-code, low-code tooling that’s also being adopted. And so it’s pretty broad. So, we’re trying to, of course, help centralize this and provide the security team with a single centralized place that they can get on top of it.

[00:17:27] Itamar: That’s really interesting. I feel like there’s a lot to cover and think about, and then, like, there needs to be some strategy in organization, how do they think about it, and who takes what responsibility allows your take at Onyx, and it sounds like you guys are doing a lot. So, can you explain, like, what is the control plane? Like, almost the dashboard, like, it could be Onyx or feel free to do a shameless plug here, so focus on Onyx. But I guess, like, in general, we’re talking about a lot to look at. And then, like, old security tools, like, there are so many, like, alerts, etc, you don’t know where to spend your time. So, how is the, like, surface eventually for the security team or the development team look like? Where do the eyeballs land first when they’re wanna have that control plane, control panel to think about controlling their AI?

[00:18:15] Gil: Yeah. So, the first step to control, and when we think about the secure AI control plane, which is the core product that we’ve built out, we think of it as an infrastructure piece for an organization that is essentially a manager of people and of many, many, many AI agents today. And so, this is an infrastructure piece that helps you manage this AI. It does a few things, but one is visibility, and we always start with visibility. If you can’t see it, if it’s shadow AI, if it’s not known to the organization, it’s very hard to control and put the right guardrails in place. So, first of all, visibility end-to-end, and this is where we always start. The second piece is about really being able to steer the behavior of thousands of agents. And it’s a big task and one that is pretty advanced, and we need to be able to surface and also help the organization just communicate their policies, their governance in a simple way and have automatic enforcement across all these AI agents. These AI agents are moving super fast, right? They’re doing things all the time. If you think about the amount of actions people do on a computer or on a digital device per day versus the amount of actions that agents do on digital devices per day, if you think of that graph, right, the amount of actions people do per day, it’s probably very much similar to what was done last year, maybe a little bit higher, right? You might have linear growth. With agents, you have exponential growth. And what we understand is that within a few months, maybe a year or two years, that number and that ratio between agent actions and human actions will probably keep growing exponentially. We’ll reach the point where 99.9% of actions on digital devices are done by agents. And so, in that context, it’s really important to make sure that those actions are aligned with the organization and that they’re not destructive. They’re not deleting databases. They’re not doing data exfiltration-type behaviors. We wanna make sure that they’re actually doing helpful work and working really well. And, also, maybe one more interesting point is just on the cost of this, right? In the past, and I’d love to get your sense of this as well, like, we’ve seen a lot of folks say use as much AI as possible, as many tokens as possible, and that worked at the time where an engineer could spend up to $1,000, $2,000 a month. If they worked really well, they optimized their harness. They worked 7 days a week, 24 hours, right? They could hit $2,000, $3,000. Today, that’s no longer the case. An engineer could spend, if they try with the right harnesses, upwards of $20,000, $50,000, or even $100,000. We saw, recently, the founder of OpenClaw spend over $1 million in a month. So, in that case, it also becomes a tricky challenge to deal with on the finance side as well as security.

[00:21:09] Itamar: Yeah. Completely. I do try to make predictions early in the year, and I did say that somewhere by then of 2026, like, people will care about cost. And actually, 2026 is about, like, agent efficiency. That’s how I framed it. And I think part of it is cost. At the same time, like, I do think we’re gonna see, like, waves, like, sinus waves with 45 degrees, where I’ll connect it to Amarla. We tend to overestimate the effect of technology in the short term, but underestimate it in the long term. So, sometimes, like, oh my God, I can’t believe that the agent can do this for us. And then, like, I give away, like, all the budget because now there’s, like, a mollock effect that if I don’t do that, somebody else will beat me. And, like, it’s, like, all or nothing and etc. And maybe there is, like, overstatement, exaggeration of what you can do right now. By the way, maybe you can achieve more if you put more infrastructure. You invest more in how you guard, control, like, harness, but with the work that you, I, or whatever put right now, like, maybe you exaggerate it, then you do wanna control your cost. But then I think because the opportunity here is, like, immense, then you kept working on your harness, you kept working on the infrastructure under control, and models improve. I think, by the way, like, models improvement, like, getting to a plateau, but that’s a totally different discussion. But the harnessing of it and training the models to work well in agentic workflows, it’s flourishing and growing. And then we see another S curve. And the S curves are shrinking, like, in time and how we treat them, but there’s always like, oh my God, like, we overkilled it. Now, let’s control costs. So, there’s always that balance, and that’s what I’m seeing. So, basically, like, practical TLDR, I just think, like, we’re seeing now another wave of cost control, but there will be another wave again, of you have to keep harnessing and then spending. That’s my prediction on this.

[00:23:01] Gil: It makes sense. And, you know, it kind of brings up a question of where does the harness end? The agent, you know, is made up of the model and the harness, theoretically, but the infrastructure around the agent is just as important. And maybe the infrastructure connecting agents is also pretty important, and maybe the control plan is also important. So, there are many layers of this. I think if we look at an organization as many agents doing things and some humans also doing things, but many agents doing valuable activities with a common goal, the ability to create the right infrastructure is just as important as the harness for an individual agent.

[00:23:41] Itamar: Makes sense. I’ll double-click on that. Like, one of the things we set up for organization that are trying to push forward on AI harnessing, on AI agents, etc, we said our cost is one of the things that we’re seeing, like, a little bit breaking down in, and then you mentioned infrastructure. Like, can you elaborate when you’re accompanying, like, companies that are trying to push forward with AI harnessing, like, worse things break down? Like, by the way, we did mention a little bit on the mental load, we didn’t say it’s explicitly, but as humans, we have, like, a capacity of how much we can grow the amount of clicks and attention we give per task, etc, and that grows linearly. Where do things break? Like, when agents click more and do more actions than humans. You mentioned infrastructure, etc. Can you elaborate more on that?

[00:24:32] Gil: Yeah. Sure. I think there are a few amazing opportunities and a few challenges. When we say in Onyx, build the impossible, the idea is that we wanna make sure that these agents are successful at the end of the day, and they really do help you build things that would be considered impossible beforehand. It could be that you didn’t have enough resources. It could be that it was just an extremely hard engineering challenge, but we wanna help organizations build the impossible, not only engineers, but every piece of the organization. And what we see is, and touching on the infrastructure piece, a lot of challenge comes with respect to multiple agents starting to communicate with each other. There are challenges in building out effective ways of this happening. What we see for the most part is agents, multiple agents, for example, I made an agent, and you made an agent. My agent could be, you know, a marketing agent that goes, pulls information from the web, and updates our Slack and answers questions about that in our Slack channel. And you could have a completely separate agent that is a Qodo agent that, you know, goes to our GitHub, does a lot of things, answers questions in the same Slack channel. And so what we see is, you know, you have multiple agents communicating with each other, not through a protocol or something that was well defined and specified by engineers, but just organically in the natural infrastructure of the organization. And so, that creates a situation where you have both something that is a bit suboptimal, right? You are just using a common chat interface, talking through email, talking through various common means that people use, which is not as effective, but also, from a security perspective, it creates an additional challenge. You know, if there’s a certain scope from an identity perspective of one agent, another scope from another agent, these are now in the same channel. They’re sharing information. They can start leveraging each other and talking with each other. From a security perspective, it opens up a whole can of worms. And, also, from a financial perspective, is it effective for you to have many agents that are just continuously talking to each other? Maybe. But maybe there needs to be certain rules in place and guardrails in place around that as well. So, we do see that one of the challenges at the frontier is around agent-to-agent communication, and that’s one of the things that Onyx is kind of handling for a lot of organizations.

[00:26:50] Itamar: Yeah. We call it bot gossip. It’s almost like using the human communication channels, as you mentioned, just start talking to each other, and it’s almost like gossip. Actually, sometimes, like, I can tell myself, like, encoding it every day that I do find it useful in many cases, like, that each one of the bots has different context and guardrails and permissions, etc, and then talking to each other in order to solve things. At the same time, it sometimes looks like gossip, and it actually is, like, I totally get you, like, about the security that could happen here without monitoring. But maybe a question that brings us to the future. I’m not sure if this is what you think of the future, but I think I saw, like, you talked about, like, a year and a half ago. I’m not sure. You correct me if I’m wrong. Is the future where actually agents are talking to each other in a language that is not human, that’s suboptimal for them, and it’s noisy for us? And should they talk, like, in a new language that they made between each other that we don’t even understand? Like, is that where the future is? And maybe the rules and the guardrails are actually positioned and hooked there, not necessarily where the humans can see, because it’s too much gossip for me. Can you tell us where you see the future going, and also share a little bit about that?

[00:27:59] Gil: I’ll mention I did do a bit of work on multi-agent communication in the past, and my thinking on this has evolved over time. So, back then, I was very much in the mindset of, okay, these agents will need to optimize at some point. It won’t make sense for them to continue using this English, inefficient language; it just doesn’t compile, and so the agents will naturally and pretty automatically evolve towards a language that is much more optimal. I do think that the benefit of having a language that people can validate and people can see and audit and create rules on top of, I think that is a value and is something that most, at least enterprises and organizations will see as important. And so there could very much be governance policies forcing agents that wanna communicate with each other to talk in English or talk in a language, could be in French or in another language, of course. But to talk in a language that people can understand, I think that is a reasonable policy to have in place. And I do think that the human element will likely stop that kind of movement towards languages and communication methods that are not human-like. There is an advantage if these agents can start sharing vectors that contain deep thought in them. So, imagine a rich semantic vector or matrix of numbers that, in those numbers, would contain a lot of thoughts and concepts that are abstract. That is something that could be valuable in the future, but I do think that we’re not gonna be seeing that in the near future for practical reasons.

[00:29:43] Itamar: Yeah. I feel like we can talk for hours, and we’re out of time. And so maybe just last question. Afterwards, I’ll love it if you can share, like, how can people find you, and etc, on social and any other media. So, are you basically saying artificial superintelligence, not 2030, is gonna be in 2041?

[00:30:03] Gil: I do think that the 2030s are gonna be incredibly interesting, but it’s so hard to know where we’re going right now. I do think, currently, that we are still in very much an exponential curve that is showing continuous improvement. I don’t think we’ve saturated, not on the model side, not on the capability side, on the emergent properties. We’re gonna see more and more emergent properties come up. I do think we’re still very much in the exponential curve, and I expect that this next year and the next two years is gonna continue to be increasingly hard to predict after. They call it a singularity for a reason. It’s gonna be hard to predict after this. I also think that we have reason to be optimistic. At the end of the day, I am seeing what people are doing with these tools, how people are embracing it, even though it may cause uncertainty in the short term, I do think that this will enable us to get to a point where AI will benefit humanity, and we’re trying to create and help create tools to put that power, put the control back in the hands of senior management in every organization, all of the Fortune 500. So, we’re working on this extremely hard, and we’re not building this just to build another cybersecurity company. We’re building this with a purpose, with a mission, because we think it’s an important problem to solve. So, it’s great to be here. Just to quickly, shamelessly plug, you can reach me at onyx.security. Check out our website, LinkedIn, feel free to hit me up, or [email protected]. Feel free to send me an email.

[00:31:38] Itamar: That’s awesome. Thank you so much, Gil. Really enjoyed the conversation. Awesome to see that you’re here to enable enterprise to harness AI, create the impossible, but keep control in human hands. That’s a really amazing vision. Thank you for joining us on the Agentic Review Show.

[00:31:53] Gil: Thank you so much. I appreciate it, Itamar.

[00:31:55] Itamar: Thank you, Gil.

[00:31:57] Outro: If today’s conversation challenged how you think about AI and code quality, that’s the point. At Qodo, we believe that independent context-aware code review with rules as guardrails is how engineering teams maintain standards at scale. If you’re leading an enterprise team and want to see how intelligent AI code review can reinforce governance, visibility, and accountability in your workflow, visit qodo.ai to learn how we help teams turn AI productivity into production-ready quality. And if you enjoyed this episode, subscribe, share it with your engineering leadership circle, and leave us a review. Until next time, keep human in the loop. And keep shipping.

About the hosts

A software engineer by training, she bridges the gap between technical depth and developer experience, helping engineering teams understand and adopt AI-assisted code quality at scale.
He’s spent 15+ years building applied AI, from computer vision research to founding Visualead, an AI startup acquired by Alibaba, where he then led AI R&D.

Get started with Qodo for AI Code Review