NEW EPISODE EVERY MONDAY — FREE ON APPLE, SPOTIFY & YOUTUBE

EPISODE 419 • OCTOBER 8, 2026

Is Your AI Agent an Employee Nobody Is Managing? with T.J. Marlin

Is Your AI Agent an Employee Nobody Is Managing? with T.J. Marlin
38 min  •  with T.J. Marlin

Or listen on: Apple • Spotify • YouTube

T.J. Marlin spent most of his career investigating corporate crises — the kind that end up on the front page of the Wall Street Journal — and the pattern he found was not the one people expect. Across those global investigations, the overwhelming majority of the harm was not caused by external attackers. It was caused by helpful employees who did not know better, making assumptions nobody could see. Now CEO of Guardrail Technologies, he argues an AI agent is exactly that employee: a junior hire with no training, making real decisions on loans, power and infrastructure, who nobody would dream of onboarding with "never show me your work and do whatever you want." Jonathan Green talks with him about why mobile is the wild west, why MCP servers deserve the same scrutiny as any supplier, and the uncomfortable fact that you cannot train people to care about security — but you can constrain an agent.

Key Takeaways:
• An agent is a digital employee making decisions, not a process running a script. Your physical staff have an org chart, a job description and someone accountable for them. By default, agents have none of that — so nobody can say who let this one in the front door, or what came in behind it.
• The threat is mostly not the villain. Looking back across a career of corporate crisis investigations, the harm overwhelmingly came from well-meaning employees whose choices were invisible to management — which is exactly the shape of the shadow AI problem now.
• You cannot train people to care about security, and the industry keeps trying. Billions go into quarterly phishing simulations where most people click, take the training, and change nothing. Agents are different: you do not have to make them care, you constrain them with controls around and inside the thing.
• MCP servers are suppliers, so vet them like suppliers. Procurement exists to check who you are doing business with. Is this running in somebody's garage? Is the data landing in a geography you never approved? A client once sent a basic security questionnaire to a platform they wanted to connect and got complete silence back.
• Treat output like a magic eight ball and build the security cost in up front. Nobody is doing quality control — major consultancies have published cybersecurity reports containing falsehoods and handed them to governments. Secure by design costs more, and it costs far less than the liability.

Notable Quotes:
"It wasn't the bad actors externally that caused the harm. It was helpful employees that didn't know better." — T.J. Marlin
"AI is not secure by default." — T.J. Marlin

Connect with T.J. Marlin:
LinkedIn: https://www.linkedin.com/in/toddmarlin
Company: Guardrail Technologies — https://www.guardrail.tech

Enjoyed this? Follow The Artificial Intelligence Podcast and send it to whoever just connected an MCP server without asking anyone.

Connect with Jonathan Green