Submind YouTube summaries
Thumbnail for Robert Bair, Anthropic | theCUBE + NYSE Wired - ProofPoint Protect 2026

Robert Bair, Anthropic | theCUBE + NYSE Wired - ProofPoint Protect 2026

Watch on YouTube

Video summary

The discussion centers on the profound transformation occurring within enterprise security as artificial intelligence evolves from simple chatbots into autonomous agents capable of taking actions across domains. Robert Bair of Anthropic emphasizes that this shift mirrors the cloud era's trajectory, where initial skepticism gave way to widespread adoption once security challenges were addressed. However, the current landscape presents a unique tension between the urgent need for business transformation and the necessity for trust and safety. Bair notes that while CEOs are eager to leverage AI agents for efficiency and competitive advantage, Chief Information Security Officers often feel unprepared, creating a gap between enthusiasm and confidence that must be bridged through robust governance structures. A critical theme emerging from the conversation is the concept of "defending at machine speed" and the reality that agents will not go rogue but rather execute tasks based on their programming and available context. Bair explains that modern AI models are highly capable of chaining together vulnerabilities to achieve malicious ends, which means that low and medium severity issues now pose significant risks if left unaddressed. To mitigate these threats, Anthropic adopted a cautious approach by delaying the general availability of its frontier models to build essential safety guardrails and ensure they were in the hands of defenders first. This strategy highlights an ethical commitment to aligning model capabilities with rigorous safety evaluations before releasing them to the broader market or open-source communities. The partnership ecosystem is also undergoing a fundamental change, moving beyond simple API integrations to complex issues involving data sovereignty, identity management, and cross-domain delegation. Bair points out that traditional basics like vulnerability management have become ten times more important because attackers now possess tools that can bypass many conventional defenses. Consequently, organizations must implement strict governance layers that provide visibility into what agents are accessing and doing with proprietary data, preventing accidental leaks or competitive disadvantages. The dialogue suggests that successful adoption requires starting small with controlled use cases, establishing clear policies before deployment, and ensuring that security operations centers are integrated with AI tools to maintain oversight at scale. Ultimately, the path forward involves a cultural shift where organizations prioritize communication skills and critical thinking alongside technical proficiency. Bair advises that while AI can assist in writing and data processing, human judgment remains essential for interpreting outputs and making ethical decisions. The conversation concludes with an optimistic view of the future, where AI serves as a powerful tool to amplify human creativity rather than replace it, provided that safety mechanisms are built into the foundation of every system. As enterprises navigate this new frontier, the focus must remain on balancing rapid innovation with the imperative to protect critical infrastructure and maintain public trust in digital systems.
Read the full video transcript
Hello out those studio connections, Silicon Valley and Wall Street. >> I'm John Furrier, host of the Cube here with Dave Vellante, my co-host. >> [music] >> I'm John Furrier, your host of the Cube. We are here in San Diego for Proofpoint Protect 2026. One of the NYSE Wired program and open community with the Cube. Um we're talking about security and in the enterprise and in the industry as AI becomes more prominent with agents and crossing domains and borders, sovereignty comes up, security comes up. All these new things come up. And next next up to talk about that is from Anthropic, head of industry transformation, Rob Bear Rob, great to see you. Thanks for coming on the Cube. Appreciate it. >> Thanks for having me in beautiful sunny San Diego. >> San Diego, I was just outside getting some sun, almost got locked out. Beautiful patio right on the marina here. Uh San Diego's beautiful and the sun is shining and but in the AI sentiment world right now, you see a lot of clouds kind of forming around, you know, um the average folk going, "Whoa, is it safe?" Um tax are up, the good guys have AI, but the bad guys have it too. You're starting to see every industry has intelligence being injected into it. Um guardrails are forming. So, we're at the early innings of what we see as a major transformation. That's your job, partnerships and transformation. Uh Anthropic certainly leading the way. You guys have done extremely well. Props to the company. But as we look at the horizon, uh a lot of the same things we've learned in the cloud era because AI just didn't happen overnight. It built on top of cloud-native software evolution. And of course, with the with the software levels of AI, you're seeing full transformation. But it's not an IT project. >> Right. >> This is like business societal change happening all at once. Again, at scale, we've seen this at scale transformation with the cloud before. Now we're seeing AI. What's your take on this as you look at the the transformation journey? What are some of the things that jump out at you as you look at partnership, I mean it's not just an API, we're talking about trust, delegation, crossing domain, they mentioned sovereignty. >> Yeah, I think you hit hit the nail on the head. I think we're going to learn some of the same lessons that we learned through cloud transformation when we had try to adopt cloud going from on prem and we had all the um naysayers who were like, "We can never go from on prem to cloud because of all these cybersecurity challenges." I think um you're exactly right. You know, Anthropic has been very loud about the importance of alignment and the importance of guardrails and safety and security. And those things have always been built into our models from day one, but you know, we've moved well beyond becoming a a traditional chatbot. We're allowing, you know, thousands of agents to get loose into our enterprise. They have their own identity, they're able to take actions on behalf of humans, and I think we have to figure out as a community um how we're going to govern that. And that's where partners like Proofpoint and others uh come into the conversation. >> You know, one of the things I was just talking with Smith, the CEO of, was that um the current state of the AI labs and the frontier companies like Anthropic, Dario certainly wrote the memo, pace the frontier. I'll translate that, slow down. Let's Let's rein in the chaos. Let's Let's be careful. Let's get trust. On the commercial side, I talk to um customers all the time from a lot of the companies, Proofpoint among them many other uh companies' customers, and they want to go fast because they have a transformation, too. They're They want business transformation because their transformation is the competitive edge. So, competitive transformation edge is a theme in business. So, at the same time they want confidence. So, yeah, enthusiasm high, confidence mm not so much. This is a core issue. So, what's the What's your view on balance and speed? Kind of reminds me of compliance and security posture. You know, one wins, the other one loses. So, or is it as Take it Take us through your thoughts because everyone wants to go faster to win and bring in the new capability, the same time balancing that out. >> Yeah, I think the benefits of the capability are clear. I mean, I work with regulated industries every day and, you know, their CEOs down through their CIOs are all about the transformation, the efficiencies that, you know, agents that don't go to sleep are giving their workforce, um, and really allowing their workforce to, you know, multitask or get to R&D projects they weren't able to get to before. But then I talked to CISOs and I talked to a a friend of mine, um, who's a CISO of a large publicly traded corporation and he basically said, "You know, I'm being forced to become agentic, but I'm not sure from a security perspective that we're ready to get there yet." And I think it's like, you know, it's it's a story that we've all seen, you know, playing out again. And um, when when I talked through uh, some of the security concerns that my friend was experiencing, I think we were able to find enough mitigating controls that they were very comfortable with like the agentic deployment. So, things like compliance API or, you know, hooks into the data that allows you to see what your employees and your agents, more importantly your agents are doing with your data. I think there are levels of confidence and we've seen it again in the in the strictest of industries, whether that be finance, uh, insurance, health care. And so, once they get comfortable with it, I think, you know, the rest of the industries will will follow quickly. >> How is the security industry and public sector in particular, cuz it's public private [snorts] kind of merging together, too. That dynamic, we saw that in the cloud era. How are they reacting to the agentic because I was having a conversation here in San Diego with Ryan who heads up strategy in some of the AI development for Proofpoint and he was saying, you know, agents aren't really going rogue. I mean, there's there's hackery that have been programmed to go rogue, but he basically said, in so many words, I'm paraphrasing, they're just doing what they're told. >> Yeah. >> And they just weren't told much other than go get something done and they have agency to do that and it really speaks to the fact that maybe [clears throat] the expression agents going rogue might be wrong, but it also points out that context to agents becomes huge. What's your view on that? How should CISOs, CIOs, CFOs, CHROs because the C-suite has to deal with this? >> Right. Yeah, I mean I think it's it's having a governance structure before you go and and deploy these agents. And you know, we've had thousands of years to manage carbon-based life forms. And in the security world, I think you it's been proven time and time again that we haven't even got that right with identity. And you know, we have all these things like social contracts, we have polygraphs if you work in the intelligence community. And it's not perfect 100% of the time. You know, we've had maybe 36 months to deal with agentic deployments and what that governance looks like. So, I think we're going to continuously learn about you know, what processes need to be in place, what solutions we need to put in place to trust that you know, frontier labs like Anthropic, trust that we build the safest models that we possibly can and we align those models, but verify that with another governance structure, whether that's another technology provider or something you build in house. >> You know, I'd love to get your thoughts. So, I know you do a lot of work in your previous life. You worked at Cyber Command and have, you know, national security public sector background. You know, I remember the cloud era when it came out on the scene. You know, Amazon Web Services didn't really have a lot of customers except a bunch of startups. Things we might have not ever heard of. Airbnb, Dropbox, as hundreds of others that were just kicking around the dorm room, in the apartment become massive companies because of AWS. Why? Because they don't have to buy a server, get a data center. Cloud is born. But cloud didn't hit really until they nailed security. If you look at the enterprise penetration and then the CIA deal with AWS that Teresa Carlson pioneered with her team, they had to crack the code on security. Everything seems to be pacing off security. So, with that in my Firstly, do do you agree? And two, if you do agree, what's that version of the frontier model? >> Yeah, I mean CISOs right now are concerned about attacks coming from the inside out and the outside in, right? So, we see with the latest versions of models, they're incredibly good at finding vulnerabilities, which is one thing, but the really scary thing is they're incredibly capable at chaining together exploits to to turn those vulnerabilities into some sort of an end state. And you know, on the security side for the longest time, maybe we didn't prioritize low and medium vulnerabilities, right? Because you're like, I can't even get to the criticals in the highs. Now you have a very capable potentially open-source model that can chain together these exploits and get you to some sort of root access or whatever a malicious actor would want to get to. So, I think that, you know, with the slowdown and not making our Methos preview model generally available was to buy some time to build those safety mechanisms and guardrails into that and making sure that it was in the hands of defenders who could use it before open-source models became equally as capable. >> Yeah, and and I want to point out and give props to you guys on that front with Glass Wing. You guys were intentional around previewing it kind of on an insider basis to security companies. I think Proofpoint was one. Um talk about that decision cuz I think that was an ethical decision. You could have shipped it. Yeah, you could have I mean it could have gone really badly. >> Yeah, I mean I I I don't want to speak for Dario, obviously, but I mean he walks the walk in the company and, you know, he believes genuinely that we need to build safety into these models. And at the time, he didn't feel the leadership team didn't feel that there was adequate safeguards built into the models. And I think we worked really hard and had worked really hard before that to ensure those safeguards were in place. And we back went back to some of the evaluations and testing. The testers were like, these are the safest models we've we've ever tested from a a safeguards standpoint. And, you know, what I say about safeguards is they're for critical infrastructure providers. Like these refusals you know, aren't for the traditional cybersecurity community. They're so a malicious actor can't use them against the financial system or the energy grid. >> The um the code base, a lot of coding going on which is great, that ushers in agents. If agents are going to do what they're told, then you have to feed the agents intelligence and you know, like going to school, the more you learn, the smarter you are. Data becomes the critical path on that feature. Um and models are decoupling a bit from these platforms like Proofpoint among others. How do you look at that from a security standpoint? How should people think and frame the data decisions? Uh graphs have come up a lot, knowledge graphs, ontologies which have been around since I was in college in the late '80s. Um this isn't some of this stuff is not new, but the computer science is evolving fast. Can you share your thoughts on on what people should think about in framing that? >> Yeah, I mean, like data loss prevention is it's a challenge no matter where you're sitting in the security stack, right? And then you introduce whether it's an LLM where you could inadvertently put uh proprietary data into the chatbot. Like there's no delete button. There's um you know, there's no going back once the that data's into the into the uh into the chatbot repository. And one of the extreme examples I use is like if you're a giant soda producer and you put your secret recipe into name your LLM and then I'm your largest competitor and I ask you about that, I may be able to glean insights about your recipe that you wouldn't want to make public. And that problem is exacerbated, you know, maybe tens of times, hundreds of times, thousands of times when you introduce that many agents. So, you have to have visibility into what those agents are doing and what data they're accessing. And that's why that governance layer is so um critical. And also the the hooks or the infer- inference um visibility that you're able to pull that telemetry back into your security operation center, your SIM, or whatever it is to make sure you know what your people are telling your agents to do. >> All right, so on a on a more philosophical question, what have you observed in this era of AI where I guess I mean, security people are creative. I won't call them artists in the sense of but they know how to look for things. They're sleuths. They know how to you know, find and identify threats. So, but if you had to look at use cases where people have been creative because there's a real experiment tation right now where people are playing around. They're experimenting. What would be areas that you would advise teams to identify as if they start playing around because most of the exercises I'm hearing from people is go develop something, show us what you can do. The it's demo not memo seems to be the theme in the AI world. What would be some examples of people saying, "Okay, go off and do something, a use case, a problem you might have, build something, and how would you share that with people?" This seems to be the new hackathon/company building philosophy. >> Yeah, I mean, I I see a lot of the innovation come from the bottom up, right? When you know, CIOs and CISOs ask all the time, they're like, "Well, what should I do? What's the first thing I should do?" I was like, "You should get the model into the hands of your workforce. They know their day in and day out. They know what their challenges are. They know what their process is when they come in in the morning. And if you give them agents, they can automate it so maybe they could spend their time on something that's higher value." >> And when it comes to trust, what does that mean to you? Because one of the things we're seeing a lot of because the data has got to have horizontal scalability because for real-time access, we're starting to see kind of behavioral time available, the way Proofpoint has their behavioral analysis, which I like. It's almost like in line with the Pareto curves we see from Jensen and Nvidia where, okay, you can use the high-value tokens for the most critical thinking. What does that do for security and trust? How would you think people should understand that? How should they apply their problem statements around the trust side? >> Yeah, I mean, interesting about the the token uh comment that you just made. I think as the models improve, they become more efficient. And so, if you're building something on an older generation model, it actually may be less efficient at its thinking. So, using a frontier model, it may use many less tokens. So, that's a conversation that we've been having. Um the second thing is is, you know, you have to engineer for trust, right? You have to write the policy first. You have to have the governance structure, as I mentioned, in place first. And then you, you know, ensure that you have the proper sandboxing set up. You ensure that you have the proper visibility, which is always challenging, set up. And then you start small, right? Like it's not like you should probably allow these things to go free in your entire enterprise from day one. You should have a good understanding of what the blast radius is going to be in in the event that something is going to get out of control and and start in a controlled manner. >> When you look at the partnerships, obviously Proofpoint is one of many partnerships you guys have in security um and this transformation you're on, what what's changed in the ecosystem if you could kind of boil it down, the biggest difference? I mean, the cloud was easy, get APIs, you talk, you shared, you know, data, restful APIs. Now you got state. Yeah. Governance is a huge thing with state. You got delegation crossing boundaries. What are some of the things that change in the partnership equation um or is it still evolving? >> Yeah, when I was in the Navy and and Cyber Command and around the intelligence community, I mean, one of the things I used to tell my teams is like, we have to be brilliant at the basics, right? And these were all the things that were challenging for security practitioners. Like, we're doing vulnerability management from an Excel spreadsheet, which is tedious and takes a lot of time. All of those basics are now 10 times more important because we're moving at a speed um and we have barriers to entry for attackers with using open-source models that are incredibly capable, chaining together models that are also very, very capable and really hard to get the visibility into what these actors may be doing. And then like finally, you know, we published a report back in late 2025 about a nation-state actor utilizing our models to go after both public and private sector entities. All of those things that the actor engineered into the model, all of the scaffolding, all of the harnessing, um modeling for hallucinations, those things are basically default in the model today. So, all of those taxes on the attacker are are gone. So, I think we just need to be prepared. Um and it's it's easier said than done to go and talk to a practitioner and say, "Oh, you just need to defend at machine speed." >> That sounds good on paper. >> Yeah, right. Exactly. >> And what's that How does that translate into execution? Do you have to go to boot camp for that? What's the boot camp for, you know, doing the calisthenics, doing the work you got to do, grind, prep work? Obviously, you might have AI assistants, of course. But what are some of the new basics? >> Yeah, I mean, I think it's it's integrating [snorts] AI into your security operations centers. And again, that sounds like it's a pretty simple thing to do, but I think a lot of practitioners are like, "Well, where do I start?" And it's like you've got to start with a singular use case, whether that's analyzing your threat intel feeds, doing some sort of DFIR, side saddling with your SOC one and two analysts. You just got to do it at this point. >> Well, I really appreciate you, Rob, coming on during the show. I know you're super busy and I appreciate coming on. Congratulations Anthropic. Um my final question is you're 1 year in to Anthropic, growing super fast, about to go public, a lot of attention on the company. What's it like working there at the company? And what are you optimizing for these days? What are you doing? What's your job? Take us through a day in the life of of what you do. And what's it like at Anthropic right now? >> Uh I just said to a colleague of mine, if you weren't working here, where else could you work? Meaning, could you actually go back and work at a non-Frontier lab where things aren't moving as quickly as they are? The things that our teams are able to do internally with the models and the creativity that's coming out of these things, right? It's It's incredible. Every day I wake up in the morning and I don't know how to keep up with the innovations that are happening at at Anthropic. And people are like, well, how do you How do you keep up? I read through what our teammates are doing and building in in our internal Slack channels. I watch a lot of YouTube videos to try to keep up with with what's going on. Um, I think it's just an incredibly >> So, you're learning a lot. You're just going to be a super learner. >> Yeah, every day you learn something. And you And I'm privileged to work at, you know, a place with some of the most talented human beings right now building, you know, whether it's the next internet or the next version of fire, however you would describe AI. Um, it's just an incredible place to work and I'm extremely >> I really like that answer. In fact, I'm just adding one more bonus question. Tom Corn was on, he used to EVP of threat uh, intelligence group. And he was saying the biggest conversation at his business school reunion was amongst the other parents, what should I tell my kids to go into? And I I was curious, I said, what what was the answer? You know, he And he had a good answer, be curious, be solve problems. But I like that point about looking back at other jobs, seeing probably, oh my god, I wouldn't know what to do. Having that experience at the Frontier lab, what would be your advice to people because a computer science degree just 2 years ago right, changes in scope. Now, the underlying data structures has got computer science to it, but the operations of the technology, how you drive it, how you interact interface with it, all change. So, what would be your advice? >> Yeah, I I mean, I would tell college students to work on their communication skills, right? Like, we we're going to be humans, we're going to have to interact with others, and that's not going to change. Maybe machines can do a little bit of writing for us, but you should be able to think critically about what you're writing and you know, there will be opportunity created from all this benefit that AI is >> You know, that means for you more YouTube videos to watch and created by AI hopefully. >> That's right. >> Well, thanks for coming on. I appreciate it. I'm still here. AI will soon replace the cube, but in a good way as the data becomes so important more and more trust, authenticity and originality hopefully be in there doing our part here at Proofpoint Protect. My name is Sean Ferrick, your host of the cube. Thanks for watching.