Cybersecurity News & Analysis by Cyber Sidekicks - Your Weekly Update’ · Christina Richmond | Rory Duncan - Cybersecurity Experts | Richmond Advisory Group

AI Agent Governance 101 - with RSAC Innovation Sandbox Top 10 Finalist Geordie.ai

·34 min·2 clips
Hannah Darley says agentic AI keeps her up at night and wakes her up in the morning.
1. Cyber Sidekicks focuses this episode on AI agent governance and Geordie.ai’s selection as an RSA Conference Innovation Sandbox top 10 finalist. 2. Rory Duncan and Christina Richmond host the show as principal analysts at Richmond Advisory Group, and guest Hannah Marie Darley is Geordie.ai’s Chief AI Officer and a founder. 3. The episode asks what agentic AI means for security teams when agents make independent decisions, use tools, and operate across changing contexts. 4. Christina says RSA C runs from 23rd to 26th of March and that the hosts plan to cover trends, innovations, M&A activity, and show-floor developments. 5. Darley describes Geordie.ai as an agentic security and governance platform built to help businesses adopt AI agents safely while managing risk. 6. She says AI agents are “the future of work” and compares the current moment to being “on the ground floor of innovation.” 7. Darley argues that agent behavior matters because agents can make independent decisions rather than just execute pre-decided software instructions. 8. She says identity remains an unsolved problem for human users, and that AI adds behavioral observability and governance as separate security concerns. 9. Darley explains that human reasoning and agent reasoning are not the same, because humans use multiple brain processes while most market agents are an LLM plus a tool. 10. She says agents become more effective when they are narrow and task-focused, while general assistants and broad copilots tend to lose consistency. 11. Darley warns that context can overload an agent’s context window, even when its tools are not malicious. 12. She gives the example of shared agents, where multiple people can access the same agent with different permissions and different needs. 13. She says security teams need contextual governance because “agents change minute to minute” and broad benchmark risk models are too static. 14. She says the right approach is to govern through context, with interventions based on specific evaluations of agent scenarios. 15. Darley says Geordie.ai maps frameworks like OS Top 10, EU AI Act, and ISO 4001, but does not stop at broad “high risk” labels. 16. She argues that human-in-the-loop controls are not automatically better because the industry rarely specifies which human, which skills, or which task. 17. The conversation repeatedly returns to “context,” “behavior,” and “minute by minute” updates as the practical basis for AI governance. 18. Rory and Christina keep the format conversational, using direct follow-ups, devil’s advocate questions, and analogies from human access control. 19. Listeners interested in AI governance, security operations, and enterprise risk management will get the most from it. 20. Listeners wanting a light news roundup rather than a technical AI governance discussion may skip it.

As heard by us

A grounded look at why agent behavior, context, and access are becoming central governance questions.

The discussion is about what agentic systems mean in practice: identity, context, tool access, memory, knowledge access, and why non-human identities may need to be judged by behavior and risk.

Read the full review in PlayNext →

Why you'd press play

Press play if you want the security case for governing AI agents like actors, not features.

Read the full recommendation in PlayNext →
Listen to the show on