TechviCast Episode 7: Your Agent Is a Target

Your AI agent can call tools, access data and take action on its own. So what happens when something on the other end of that API has been compromised? In this episode of TechviCast, Brenn Hill and David Ho get real about what it takes to secure autonomous AI agents before they reach production, and the risk direction most engineering teams never think to guard.
Our Guest: Brenn Hill
Brenn is a Senior Manager: Data Science, Data Engineering, ML and AI based in Berlin. Over more than 15 years he has built and scaled global engineering and data science teams at Delivery Hero, the DAX-listed group where he leads data science, data engineering and ML & AI for AdTech, and at VNG / ZaloPay, Vietnam's first tech unicorn. He has served as a startup CTO and most recently drove over $140M in incremental ARR through production AI/ML and data science systems. He is the author of The Delivery Gap: Why AI Adoption Fails and How Engineering Leaders Fix It, and the creator of BRACE, an open, vendor-neutral AI security and governance framework for autonomous AI agents. His work has been featured by AWS and Okta.
Our Host: David Ho
David is Chief Technology Officer at Techvify, where he also leads AI transformation and trains teams across every department to adopt AI in practice. He hosts TechviCast with a focus on what enterprises actually have to control before AI reaches production: what data a system can access, what work it is allowed to do, and who can prove it afterwards.
Key Highlights from the Conversation
- Why agentic security does not work like traditional security
- The BRACE framework: five checks before production
- Why every API your agent calls is also a risk to the agent
- Blast radius and when to keep a human in the loop
- What GDPR and the EU AI Act actually require
Episode Timeline & Detailed Breakdown
Jump straight to the parts that matter. David and Brenn move from why agent security breaks every model enterprises already trust, to the five BRACE controls, the risk direction most teams never think to guard, and what EU regulation now demands. Pick a chapter and dive in.
0:00 - Introduction and Brenn's Background
2:29 - From Copilots to Agents That Take Action
3:16 - Why Agents Need Their Own Security Framework
7:18 - Inside the BRACE Framework
10:18 - Ecosystem Risk and the Two-Way Street
12:18 - Blast Radius and Limiting Agent Access
14:19 - When to Keep a Human in the Loop
17:07 - Audit Trails and What to Actually Log
22:29 - GDPR, the EU AI Act, and Real Incidents
24:20 - Final Takeaways