All points of view
04 of 07
Security by design.
Build safety into AI systems from the start — not as a rule written six months later.
In plain words
When AI agents can read company data and take actions, safety cannot be a policy document added later. It has to be part of how the system is built: where passwords and keys are kept, what each agent is allowed to touch, and a record of everything it did.
Why Jenks thinks this
- At Babylon Labs he put security, credential handling and audit records into the AI architecture from the start, rather than as a later policy layer.
- On the Hall for Murrumbeena campaign platform he built, AI agents can prepare actions, but a person approves them.
- He follows AI-agent security closely: agents that never see secrets, tools that run in a sandbox, and gateways that control what agents can reach.
What he does about it
- Keeps keys out of prompts, and gives each tool the least access it needs.
- Keeps an audit trail, and tests before rollout.
What it means for you
Ask any AI vendor or internal team three questions: Where are the credentials? What can the agent do on its own? Can we see a record of what it did?