Francesco Cipollone - Agentic AI Manifesto
with Francesco Cipollone
Audio hosted by Buzzsprout. Nothing loads until you press play.
Francesco Cipollone, the CEO of Phoenix Security, shares his extensive experience in AI and security, discussing the crucial difference between true AI agents and glorified chatbots. Learn why Phoenix Security utilizes six different LLMs instead of a single super agent. Understand the sobering economics behind AI implementation and the importance of adopting AI responsibly. Get practical advice on integrating AI agents to enhance, not replace, human capabilities, while touching on the Agentic AI Manifesto’s key principles. This conversation is perfect for anyone navigating the AI landscape both cautiously and optimistically.
Mentioned in this episode
Enjoyed this one? Get Reasonable AppSec, the newsletter with new episodes and picks from the archive.
Transcript
5,071 words · assemblyai
0:00Chris RomeoFrancesco Cipollone, a seasoned entrepreneur and CEO of Phoenix Security, a contextual-based vulnerability management platform. His credentials run deep, from leading application and cloud security at HSBC to serving as a senior security consultant at AWS, plus authoring several books and keynoting at global conferences. Today, we're exploring what separates true AI agents from glorified chatbots, why Francesco's Phoenix Security uses 6 different LLMs working together instead of one super agent, and the sobering economics behind AI implementation. Whether you're navigating AI hype or seeking practical guidance on implementing agents responsibly, this conversation offers the pragmatic perspective our industry needs right now.
0:43Francesco CipolloneThe Application Security Podcast is brought to you by Security Journey. Security Journey is an enterprise-class solution with lessons that are built on learning science principles to deliver long-term measurable results. Learn more at securityjourney.com.
1:08Chris RomeoHey folks, welcome to another episode of the Application Security Podcast. This is Chris Romeo. I am a VP at Security Compass and a general partner at Curve Ventures, joined as always, not by an AI agent, but by Robert Hurlbut in the flesh.
1:24Robert HurlbutThat is true. Hey, Chris. Yeah, Robert Hurlbut, and I am a principal product security architect and threat modeling trainer at Torion. And yes, as you said, I'm here.
1:34Chris RomeoIt's, it's not my AI agent, but I'm trying to think of a question I should ask you to confirm you're actually real. You're just an AI agent that's somehow figured out how to do video in a window.
1:46Francesco Cipollone2 plus 2. Yeah.
1:49Chris RomeoYou gotta say 5 too, 'cause that's the correct— throw off the AI answer.
1:53Robert HurlbutSo throw it off. Yeah, throw it off.
1:55Chris RomeoOh, we're, we're joined by, uh, a friend who's been on the show a couple of different times in the past. Francesco is always on the cutting edge of a lot of stuff that's happening in AppSec, and I know he's been diving deeply into the world of AI and agents, and he's here to, to educate us some about that. But first, Francesco, before we start talking about geek stuff and security and bits and bytes. Our audience is generally aware of my Get Outside and Play initiative, where people in cybersecurity need to put down the keyboard and go into the real world and do something else that's not technology-related. So, what do you like to do that gets you away from work and gets you away from a keyboard?
2:36Francesco CipolloneYou haven't asked me if I was a bot or not.
2:39Chris RomeoWell, I know you are.
2:43Francesco CipolloneUm, I think I have 3 answers for that. I have 2 healthy ones and an unhealthy one.
2:49Chris RomeoYeah.
2:51Francesco CipolloneOn the healthy one, I started getting the podcast out in the street. So I started doing walk and talks, um, like 5 to 10 minutes by, um, we're all remote with Phoenix. So we tend to work silly hours. So I tend to encourage all my team and myself to get out at least 3 times a day. So at least that keeps a pace. And because during those breaks I usually record stuff, I think I said, why not taking the walk and talks as a podcast? And that started the, uh, Cyber Walk and Cyber Talks. So I can hit 2 birds with a stone. And then on the more well-known one, I'm a runner.
3:38Chris RomeoGotcha.
3:39Francesco CipolloneAnd apparently I'm hiring more runners as sales guys. So we are on a healthy unhealthy trend of pushing each other to run more. So I am going back on runs at least 3 times a week and running a couple of half marathons. I think that's a sane measure of running. And on the unhealthy one, you can see in the background, I have quite a big collection of whiskey. So, uh, we have done also with Phoenix, in the spirit of security, as events with mini bottle whiskey and mini casks. So that's my unhealthy kind of—
4:17Chris RomeoWell, you know, anything in moderation, anything in moderation is fine.
4:22Francesco CipolloneThat's why we do the small bottle.
4:23Chris RomeoYeah, that's good stuff. It's fun whiskey. I enjoy whiskey once in a while. Not often, but not afraid to try a little bit and learn more about it. But so that's our get outside and play moment on the Application Security Podcast. Robert, where are we going from here?
4:41Robert HurlbutYeah, so diving into our topic today, Francesco, what is the Agentic AI Manifesto and what motivated you to create it?
4:51Francesco CipolloneThat's a really good question. So, I'm a geek, so I got super excited about applying AI everywhere. And immediately I realized, hold on a second, this is a blockchain moment again. It's technology trying to find a problem rather than a problem trying to be solved with technology. And then I saw the adoption of AI everywhere, plastered everywhere. Uh, where I was puzzled as well by some technology acquisition that didn't make sense at all just to have AI in their portfolio. And then of course with Phoenix, we've been on an intense journey on deciding where to apply AI logically because we've been pushing for an AI second initiative or agent that works for you. And I think the pivotal moment was when I saw an advert of agents don't get tired, replace your human with agent. And I think that's the worst message you can send out. So we wanted to send something that helped and promote a good use of AI. So AI second was maybe a too harsh movement because I think I am AI keen, but not AI everywhere. So we created this manifesto of agent that work for you, not instead of you. And hence we created the manifesto to define kind of the guideline of logic really. Where can you apply AI? Where shouldn't you apply AI? How do you apply safely AI? And I didn't want this to be in conflict as well with other initiatives like LLM security initiative from OWASP. So I didn't want this to be yet another security guideline, but also hinting at, you know, there are privacy concerns, there are security concerns. So consider those as well. But this is really use AI in a logical sense and apply AI second, use human first, because In the end, you can't fire an AI.
7:08Chris RomeoWell, let's, let's talk about a definition then of agentic AI. And then, because I've, I'm, I've been following along in the world of AI, but I don't know that I've been in the deep end of the pool. And so I'd love to just get a perspective on when we talk about agentic AI, what is that? And then how is it different from the part that I understand better, which is LLMs and kind of the ChatGPT side of the world or all the competitors of it?
7:37Francesco CipolloneYeah, that's a, that's even a more tricky question. I don't think we have a good definition of what defines an agent or what defines an autonomous agent. In my head, and what we applied as well with Phoenix, is something that can live and breathe and does more than just a wrap or a prompt in front of ChatGPT. So it needs to be autonomous. It needs to perform by itself. You need to double-check its work and you need to deliver something to the user and ideally chaining with other agents. So it needs to collaborate with other agents and be reactive. I think for me, the best example of an agent is Cursor, where you have the agent that checked his work and then sent prompt back. Uh, and it's kind of self-healing and self-repeating. That for me was the best definition of agent and what we applied as well with Phoenix. Well, I've seen the word being abused by a glorified chatbot, uh, or a glorified AI agent that by no means those are AI application, but they can't be called agent. But right now everything is an agent. Everything has an agent. As long as you have a function that is performed by an LLM, is called an agent. For me, an agent should be autonomous, have some memory, be trained ideally, or having a RAG or having some level of customization that deliver a brain with an opinion, not just an LLM with a prompt.
9:17Chris RomeoBut the LLM is still the heart of—
9:21Francesco CipolloneCorrect.
9:21Chris RomeoThe agent, right? So, The agent, just to make sure I understand this, the agent is, is not the LLM. The agent is like a communication layer or communication that's talking to the LLM, but yet has its own memory to store things and perhaps have a task list or something that it's working on. Is that a fair assessment?
9:43Francesco CipolloneYeah. So probably the best example that I can get is our researcher. That is our first agent that we published. That is basically 6 LLM that operate one against each other and check each other's work from a single prompt. So you ask, hey, I have this set of vulnerabilities. Can you give me more detail? Can you research all of the threat intelligence? And you have the first agent that goes crawl all the web, scrape the web, understand if those are blogs, if those are just marketing articles, that's a first agent, then send it to another agent that basically scrapes and creates a vector analysis of the vulnerability, and then send it to another agent with memory that was trained by us and Google, and that then gets passed to another agent to get a description based on the other one. So it's a series of agents that deliver a set of actions and then deliver it back to you, and then you can interact with the agent saying, can you give me more detail about this? Or can you understand how using this information in my context something changed? So it's an— that's the interaction part. But in itself, the agent is not just, hey, this is a prompt, send it to ChatGPT, give me an answer, but do something with that. And then if needed, send it back to an LLM. And you can also use— we use different LLMs to get different answers. For example, we use the original version of the scraper was with the very early model of ChatGPT. Then we use Google Gemini because it's way more precise on a RAG-based retrained model. And we use the same version but non-trained because it's better at creating inference. So it's also using different models and different things while And that's state of the art in a way. But by no means like cursor use, recursive action, and some local engine like launching a prompt or launching a thing based on a reasoning model that is Claude or any other model. So those are good examples, I think, of agents that think, do action, recheck their work, take their inputs, refeed that input inside, re-ask some other different question. and get to an outcome that is more than just, here's a question, gimme an answer.
12:10Robert HurlbutHmm.
12:12Chris RomeoSo you, you described one of the advantages of the agentic AI approach is being able to use different models potentially in different spots. Is there also a performance, like why not just have one super agent? Like why have 6 individual agents? I mean, that would be the Terminator from Arnold Schwarzenegger's favorite famous movies, that would be the super agent. But why not have, why not have just one super agent that does everything? Why break it into 6 chunks?
12:40Francesco CipolloneI think, well, long story short, um, I think it's cooler and more performant to have multiple agents doing different things. Second, the more you feed into a chat history, the more any agent or any LLM lose context or tend to hallucinate more. So the more the context grows, the more the token grows. So having micro prompt, I found, gives you better answer than a massive context, uh, on one specific one LLM. Then you have multiple LLM that have— that are start specializing, like OpenAI start specializing in giving the biggest and the widest answer overall, while Gemini is specializing in giving you the more precise answer. So when you retrain a specific agent, and then there are other like, gone. My memory has been reset, but there are other like the O1 model, open source model.
13:51Chris RomeoYeah.
13:52Francesco Cipolloneor the Hugging Face, uh, um, or the model on Hugging Face or LLaMA that are more generic and more trainable. So I think we are seeing the second generation of LLM, and then that will make agents using different LLM and even adversarial LLM more useful. And then it's a technology, so it depends on your use case. Sometimes over-engineering this might not be needed. And using one LLM with one prompt will give you the answer. Sometimes, like when you need to do research, especially when you need to do inference on a graph, when you have a series of logic elements where you need to jump between nodes in a graph, one LLM is generically very bad. I went into the geek mode. I spent, enormous amount of time understanding the, uh, kind of the advantage and disadvantage of different models. But sometimes I talk about it and I don't realize that, uh, I lose some part of the audience.
14:57Chris RomeoAnd no, I wanted to unlock that knowledge. So you did all the research. Now I'm just gleaning it in a 3-minute segment. So I like that.
15:05Robert HurlbutYeah, definitely. So, uh, what are some of the key principles or pillars of the manifesto? that are important here to, to talk about?
15:15Francesco CipolloneYeah, so the, the very first one, as I said before, was very important for me, is to not demonize LLM, not demonize agent, but also using it as a technology. So using people and process first, and then agents to augment people and their reasoning. So doing the boring stuff faster and If there is a better process, just leave it as a process. And then security by design, but again, not doing a whole manifesto about security, but referencing already the other manifestos that are there. Again, privacy by design, not doing a whole manifesto on privacy, but referencing to other existing one. But the core of the manifesto is really to use agents or in general LLM as a technology aiding the human, not replacing the human. And it's trying to stress that concept. It's like we need to 10x with this technology, human and removing boring process or stale process that can be enhanced by this technology. But by no means, We need to obsess about this technology to then fix everything. Like some things are already fixed and they don't need enhancement by AI. And I always think about the toasts that are internet and IoT connected and what that can cause to the security of an IoT or a house basically, or why the kettle or why the fridge need to be connected. Some technology are good to be left as they are.
17:01Chris RomeoYeah, that's true. Like the toaster, do I really need my phone to send me a notification that my toast is done? Like I can just sit, I can just stand there and enjoy 15 seconds of staring at the ceiling or the wall and thinking about something amazing. But I, I, Francesco, I tend to—
17:19Francesco CipolloneHow many internet-connected toasters have you seen in your life, Chris?
17:23Chris RomeoI have never actually seen one, but I haven't gone looking. I'm sure Amazon has them somewhere and somebody will send me a link. But, uh, Francesco, I, I agree with where your, your stance. That's the same tack that I've been taking in regards to threat modeling and just in, in general as well, that AI agents, LLMs, these are things that can enhance the capabilities of the human being behind it. They're not a replacement. And so, there's so many people saying, these are a replacement, you know, be afraid you're gonna lose your job because you're gonna be replaced by AI. It's just not the reality of the technology right now. I mean, and maybe these people are just, they want to be super visionaries and they want people to think they're, you know, have the best possible ideas and they see the future. But I just don't see that future where, at least in the short term, an AI agent can problem solve like a human being can. Because I always come back to the fact, no LLM has ever had an original thought.
18:27Francesco CipolloneNo.
18:27Robert HurlbutThey haven't.
18:28Chris RomeoThey're, they don't make original thoughts. They can't create original thought inside of the, you know, our, our human brains is where original thought comes from. And so that's—
18:39Francesco CipolloneI, I think about it as programming. Like programming helped us doing boring stuff way faster. Like laptop have helped us doing the same thing over and over. But I think we are going back in time because I've been vibe coding and I've been super excited about that, but I find myself needing to think more instead of less. So going back from agile back to waterfall, because now I need to think about what the things that I wanna write need to do, what are the guardrails, what are the exact instruction. And that made me think that an agent can replace a human because if you give cropping crop out. Sorry for my French, but basically a silly input will deliver a very bad output. And we've seen basically the first vibe-coded application being completely wiped out. So an LLM just stitched things together in a very fast way, but a human empowered that knows how to use prompt engineering on a cursor will write so much more code so much faster. than any other thing. So I think we need to train the next generation of developers to use this technology securely rather than saying you're never going to have a job or you're going to be replaced. Like, we need to embrace and adopt this technology and understand how to use it and how to 10x people. And ultimately, you will need less people to do the same things. And that's a fact that nothing will change. Like with cloud, we needed less data center, but then those data center became cloud data center. And I think we are facing this kind of second stage of the revolution where we said we don't need a developer anymore. And then we start realizing actually we need senior developer and more than what we had. And now we're realizing if we don't train the junior developer, of the next generation, we're not going to have enough developers tomorrow that know how to use LLM. So I think as any technology, we got super excited. We've gone overboard because this is kind of a dot-com bubble or a pivotal moment where we say cloud, dot-com, now this is the next technology revolution, if you want, where everything will be impacted by AI. We got super excited. Now we are slowly rationalized and coming off the hype of excitement, as Garner says.
21:15Chris RomeoYeah.
21:17Robert HurlbutYeah.
21:17Chris RomeoI mean, potentially there's a future role for an AI coach where all they do is teach how to, how to do. I guess they'd be a prompt engineer, but I was trying to find a unique marketing flair for it, calling them. It's not you're not a life coach or a fitness coach. You're an AI coach and I'll help you to 10x your output at work so that you can be the best, all for $995 a week. The off— that'll be an offer that we have later. So, okay, what do we, what are the risks if we don't adopt this, Francesco? What if we just say, forget this whole AI second thing that Francesco's talking about, this manifesto about how we need to focus on the human being in the loop, in the center. What if we just say, forget it, we're not doing it? What are the potential damage risks, challenges, threats we could have?
22:08Francesco CipolloneI mean, it's not just a hypothesis, it's a reality. We've seen, um, Coinbase saying, if you don't adopt technology and AI, you're fired. And then all of a sudden, 2 months later, had to backpedal it. Um, We're seeing an overexcitement about technology. And as a CEO, I am pushing for vibe coding because I see the advantage of human empowered by technology, but using it as a tool, not having people becoming the tool of a technology. And I think that's the risk that we're facing where skipping the AI second or or agent that work for you, we will smash things that works really well, replacing with things that are half-baked and having to backpedal. And that's what business will face. And I think I was very surprised with one of the latest articles from McKinsey that is in general one that push for technology first. It actually caution on using AI everywhere and push organization to be careful and think, is this process really needing AI or are we trying to push another digital transformation for the sake of digital transformation?
23:37Chris RomeoI laugh every time I hear those words now, digital transformation. It's like, what? What are we thinking? Like, what was somebody thinking? Like, I don't know. I mean, I guess I missed a meeting or something. Maybe there was a meeting and I just didn't show up. And then we went with digital transformation and it became a whole cottage industry. And it's like, I don't know. Every time I can't, I can't wrap my head around it.
24:00Francesco CipolloneWell, it was, was the, was the kind of a free-for-all for consultancies to actually go and sell something new and it became digital transformation, but it became almost a, kind of feeding themselves, like digital transformation that was done for the purpose of doing digital transformation. And, and I see the danger here.
24:23Chris RomeoIt's a recursive— you just described a recursive recursion problem. Where does it end? When does the transformation end? Never. You're still—
24:31Francesco CipolloneWell, it, it's fueled by money, and I think AI and LLM are fueled by money. And right now, definitely, I think we are seeing most of the LLM being subsidized. But if you take an N2000, an NVIDIA 2000 machine box, it costs $128,000 to run on a monthly basis. Just to run? Just to run on a monthly basis.
24:57Chris RomeoTo operate, not to buy.
24:58Francesco CipolloneNo, no, just the bare metal. That's just the bare metal to run. If you load on top of it a model or if you need to retrain a model, Throw in another couple of million just to throw a model with AI engineers costing half a million each one. Right now we're seeing cursors subsidized for $20. Like at a certain point, there will be a reckoning of AI will cost so much and will consume so much power. Um, and I've seen somewhere that VCs are running out of cash to actually fuel this mega valuation of AI technology. So I don't know if it's gonna be a bubble, but AI is expensive. Models are expensive. We run experiment and in a couple of days we spend probably 10 grand just on an experiment.
25:54Chris RomeoWow. I hadn't thought of it. I hadn't thought of this angle to it. You, you're, you're expanding my mind here. Like, making me think we are in an AI bubble that will eventually pop because at some point you can't just throw away money to try to build market share. There's got to, like you said, there's a day of reckoning where there just isn't any more money to throw to try to get a $20 customer that's costing you $200 a month or something.
26:25Francesco CipolloneIf you're lucky, $200. I would suspect probably is 2,000 to 20.
26:32Robert HurlbutWow.
26:34Francesco CipolloneBut it's the lock-in, you know, once you lock in in that workflow, it's really hard to get unlocked. So you end up spending more on the extra, and I've seen it happen with my team. So you get locked in in a methodology, and I think that's kind of the model, but I've seen other organizations completely blowing up because of the cost of token or the cost of running local LLM. The, the financial model that you in SaaS used to be second with LLM needs to be first. You need to think about how are you gonna charge and how are you gonna recuperate that money because you're gonna run out of cash very, very quickly.
27:14Robert HurlbutYeah.
27:15Francesco CipolloneWith H100 or H200 and QWENT, that's the model that I was thinking about. That is the coding agent. It's going to cost you probably 4 H200. That's kind of $128,000 a month multiplied by 4, just to run a coding agent or a helper. That's expensive, very expensive, very quickly.
27:46Robert HurlbutYeah. Wow. So we've been talking about how everybody is racing to make the next great AI thing. What are some challenges of AI agents with vulnerability remediation?
28:02Francesco CipolloneThat's my favorite question. Thank you, Robert. I think if we reconnect to what we've been discussing so far, AI is extremely intelligent, but for specific action. If you throw a lot of things to an AI agent, it's going to cost you a lot of money. So there are already methods of contextualizing, prioritizing that don't need AI agent. Where AI comes really in handy is the best path to remediation is looking at an enormous corpus of information and giving you kind of a, between this, this, and this, and this context, what is the best path to remediation? How do you auto-fix a build file? How do you fix a series of build files? How do you auto-fix some code? Like, that's the good things that AI can do, but it needs to act on an already very selected number of What I see a lot of AI-first company and initiative that are just saying we're going to fix everything with AI, and I'm pretty sure they're going to run out of cash before they even blink the first customer. Now, I might be pessimistic, but I also saw the numbers, and I also run a company as a CEO, so I'm trying to make economy work. So I know that nothing can. Like, I know that we can't throw everything to an LLM and expect it to get us an answer, but there are already existing process that works really well. And then using specific agent for micro functions so that the number of tokens that you burn are fairly low, or you can even run locally with LLM with maybe not GPU but CPU. So you can optimize the work with specific model. And just using for specific function, like for us doing scraping and doing inference and analysis of an enormous amount of corpus of text, we couldn't find a traditional AI that could fix that. So we defaulted on LLM because that was the best application for that because we couldn't find any other technology solution and that was the fastest and more intelligent solution. Other things like prioritization, we have already probably a state-of-the-art model that does prioritization where we already achieved 98% reduction of vulnerability on certain of our customers. So we don't need to apply LLM in there. But on the remaining one, yes, absolutely. We can find the best path to remediation on 100, 200 vulnerabilities, but it's not millions of tokens or hours and hours of running an LLM, but it's minutes. I can get you an answer in minutes already on a refined amount of text. So I think just long story short, there is an application of AI agents in vulnerability management. We are a big champion of 3 agents, that is the remediator, the analyzer, and the fixer. But also there are problems that should not be solved by agents or are very expensive If sold by agent.
31:27Chris RomeoWell, this has been, uh, been very enlightening, Francesco. This, this knowledge, this, this class you're teaching about AI agents, you just didn't know it, that it was gonna be a 30-minute class where I was gonna learn a bunch, but I did. Uh, when you think about kind of a key takeaway or a call to action coming out of this Agentic AI Manifesto and all that we talked about in regards to agents and LLMs. What, what do you see as a key takeaway for our audience?
31:56Francesco CipolloneI use my favorite sentence for this. Use technology as a tool, otherwise you'll become the tool. Use a tool as a tool, otherwise you become the tool. Okay. And I've been using this for my whole life.
32:11Chris RomeoSend that to our mutual friend of all of us, Isar Tarendas. He'll make it into a t-shirt. He's been, He's been, he bought a t-shirt machine and he's creating all these t-shirt, uh, AI-related t-shirts. And that's a, that'd be a good one for his collection. So yeah, that's true though. I mean, it's, and it fits into everything that you just, you just described here. So it makes perfect sense. So Francesco, thank you for, yeah, go ahead.
32:35Francesco CipolloneIt's, it's, it's the blockchain moment. It's the blockchain moment. It's the cloud moment. Not everything needs to go in the cloud. Not everything needs to have a blockchain. Not everything needs to have an LLM. So, use technology as a technology and always rely on humans because you can't fire an LLM, you can't fire an agent, but you can fire a human that use or misuse an agent.
32:57Chris RomeoWell, now I'm gonna go delete all my blockchain stuff I was working on. I finally thought I was at the forefront of something, but Francesco, thank you for joining the Application Security Podcast, educating us, enlightening us on this topic, and, uh, we'll definitely talk again in the future. Uh, when I need to learn something else, I'll let you know.
33:16Francesco CipolloneThank you so much for having me. It's been a pleasure.
More on AI and LLM Security
- Steve Wilson -- OWASP Top Ten for LLMs
How do we do security in the world of AI and LLMs? A great place to start is with an OWASP project tasked with creating a standardized guideline for…
- Steve Wilson and Gavin Klondike -- OWASP Top Ten for LLM Release
Steve Wilson and Gavin Klondike are part of the core team for the OWASP Top 10 for Large Language Model Applications project.
- Steve Wilson--OpenClaw and Advanced AI Agents
In this episode of the Application Security Podcast, Chris Romeo and Robert Hurlbut welcome back Steve Wilson, a global leader in AI security and Chief AI…