# You Can't Secure an AI Agent with Software Page: https://stenobird.com/podcast/chain-of-thought-ai-agents/you-can-t-secure-an-ai-agent-with-software Text version: https://stenobird.com/podcast/chain-of-thought-ai-agents/you-can-t-secure-an-ai-agent-with-software.md Podcast: [Chain of Thought | AI Agents, Infrastructure & Engineering](https://stenobird.com/podcast/chain-of-thought-ai-agents) Published: 2026-07-01T10:30:00+00:00 Episode link: https://share.transistor.fm/s/bbbcbe24 Audio file: https://media.transistor.fm/bbbcbe24/2f4bd8d3.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/chain-of-thought-ai-agents/episodes/you-can-t-secure-an-ai-agent-with-software Duration seconds: 3166 ## Resource Charles Guillemet, CTO of Ledger, runs the offensive security lab that breaks Ledger's own products before attackers can. He explains why software permissions can't secure AI agents that move money, and why hardware has to be in the loop. ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/chain-of-thought-ai-agents/episodes/you-can-t-secure-an-ai-agent-with-software/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/chain-of-thought-ai-agents/you-can-t-secure-an-ai-agent-with-software.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.