The Application Security Podcast

Steve Wilson--OpenClaw and Advanced AI Agents

Chris Romeo and Robert Hurlbut Season 13 Episode 1

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 49:30

OpenClaw makes always-on personal AI agents feel inevitable—and exposes how poorly prepared most organizations are for their autonomy. Steve Wilson, Chief AI and Product Officer at Exabeam and founder of the OWASP GenAI Security Project, returns to explain how advanced agents differ from chatbots and why their permissions, memory, and ability to act create a radically larger blast radius. He and the hosts explore source-code exposure, prompt injection, supply-chain risk, and the uncomfortable gap between rapid adoption and meaningful oversight. Steve also discusses the OWASP Agentic Security Initiative, emerging guidance for builders, and the limits of treating an agent like an intern. The episode closes with a practical challenge: learn how these systems work before trusting them with consequential access.

Connect with Steve Wilson:
Steve Wilson on LinkedIn
OWASP GenAI Security Project

Mentioned in this episode:
OpenClaw
Peter Steinberger
Lex Fridman Podcast — Peter Steinberger on OpenClaw
NVIDIA NemoClaw
Claude Code source leak
Tay
OWASP GenAI Security Project — Get Involved
OWASP Agentic Security Initiative
The Developer's Playbook for Large Language Model Security
OWASP Top 10 for LLM Applications
Claude Code
The Security Table

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Meet Steve Wilson
02:34 A fifth visit to the podcast
04:21 What is OpenClaw?
07:03 From chatbot to always-on agent
10:16 Why personal agents feel different
13:16 The expanding blast radius
16:29 Permissions, memory, and persistent access
18:43 Security catches up to agent adoption
21:28 New tension between security and development
24:09 When an agent exposes source code
26:12 Understanding consequential failures
29:59 Threats that keep defenders awake
32:41 Agentic security guidance from OWASP
35:45 Why the intern metaphor falls short
38:18 Supervision and human accountability
41:41 Where advanced agents are headed
45:28 The one thing practitioners should do now
48:48 Closing thoughts

Follow the Application Security Podcast:

➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast

People on this episode

Podcasts we love

Check out these other fine podcasts recommended by us, not an algorithm.

The Security Table Artwork

The Security Table

Izar Tarandach, Matt Coles, and Chris Romeo