ClearTech Loop: In the Know, On the Move

AI Security: Gerald Auger on Shadow AI, NHIs, and AI Defense

June 10, 2026

Download Transcript (pdf)

ClearTech Loop features Gerald Auger of Simply Cyber on shadow AI, non human identities, AI defense, AI governance, over-permissioned agents, and why organizations need a manager in the loop.

AI Security: Gerald Auger on Shadow AI, NHIs, and AI Defense 

In this episode of ClearTech Loop, Jo Peterson speaks with Gerald Auger, Chief Content Creator of Simply Cyber, about three issues shaping enterprise AI security: shadow AI, non-human identities, and what AI defense means in real environments. 

Gerald brings the lens of a cybersecurity educator, GRC practitioner, and practitioner-community builder to the conversation. He has a PhD in Cyber Operations, teaches cybersecurity, and has built Simply Cyber around practical education, daily threat briefings, and helping cybersecurity professionals understand what is happening in the field.  

As AI becomes easier to access and more embedded in everyday tools, organizations are being pushed to rethink visibility, governance, identity, and defense. This conversation explores why shadow AI is difficult to contain, why over-permissioned agents create real risk, and why AI governance may become its own security discipline. 

Episode Highlights

Shadow AI is easy to adopt and hard to see

Gerald frames shadow AI as the use of AI inside the corporate environment in a way that is unknown, unidentified, unapproved, or unauthorized. 

The challenge is how easy AI has become for everyday users. AI features are being built into SaaS tools, productivity platforms, and familiar workflows. Employees do not have to be technical to use them. 

That creates a visibility problem. A user can upload sensitive documents, ask for a summary, or use AI to analyze internal information without realizing where that data may go or how it may be used. 

Gerald’s view is practical: organizations cannot put AI back in the bottle. They need to educate users, provide approved tooling, segment environments where needed, and build governance that can move while the technology continues to change. 

Non-human identities need oversight before they scale out of control 

The conversation then moves into non human identities, AI agents, and over-permissioning. 

Gerald points out that non human identities need to be folded into identity and access management, but AI agents create a different challenge. They can scale quickly, they can be over-permissioned, and they can execute an objective without the same human instinct to stop when something looks wrong. 

That makes permissions and oversight critical. 

With human users, organizations have managers, onboarding, offboarding, reviews, and lifecycle processes. With AI agents, the lifecycle is less clear, and the scale can grow quickly. 

Gerald introduces the idea of a manager in the loop: a person or function responsible for watching what AI agents are doing, identifying anomalies, and stopping action when something needs review. 

AI defense means guardrails, detection, and fast response  

When asked about AI defense, Gerald brings the answer back to practical guardrails. 

AI defense can include using AI in the SOC to improve effectiveness. But Gerald’s broader point is that organizations need to make sure AI systems are doing what they are expected to do, in the way they are expected to do it, and that misuse can be detected quickly. 

Speed matters. 

AI systems can act at machine speed. If they are over-permissioned or poorly governed, the impact of a mistake or misuse can move quickly too. 

That makes AI defense less about one tool and more about guardrails, detection, orchestration, automation, and response. 

About Gerald Auger 

Gerald Auger, PhD, is Chief Content Creator of Simply Cyber. He is a cybersecurity educator, GRC practitioner, community builder, and creator of the Simply Cyber Daily Cyber Threat Brief. 

He has a PhD in Cyber Operations from Dakota State University and teaches cybersecurity at The Citadel. His work focuses on cybersecurity education, GRC, career development, daily threat briefings, and helping practitioners understand real security issues in practical terms.  

Through Simply Cyber, Gerald has built a large practitioner-focused community around accessible cybersecurity education, threat intelligence, and professional growth.  

Why this Episode Matters

AI security is moving faster than many traditional control models were designed to handle. 

Shadow AI is easy for users to adopt. AI agents can scale quickly. Non human identities can be over-permissioned. And AI defense now requires organizations to detect misuse and respond at machine speed. 

This episode is especially relevant for CIOs, CISOs, security leaders, IT leaders, GRC teams, and enterprise technology teams trying to understand how AI is already changing risk inside their environments. 

The conversation makes one thing clear: enabling AI and letting AI run loose are not the same thing. The difference is governance. 

Key Takeaways 

  • Shadow AI is a problem for IT, security, and the organization because it often happens without visibility, approval, or authorization.  
  • AI adoption is accelerating because AI is easy to access and increasingly embedded in everyday tools.  
  • Organizations need approved AI tools, user education, segmented environments, and governance that can keep pace with adoption.  
  • Non human identities and AI agents create new risks around over-permissioning, lifecycle, scale, and oversight.  
  • AI defense requires guardrails, detection, orchestration, automation, and fast response.  
  • AI governance is becoming its own security discipline.  

Key Quotes 

  • “You basically have to ride the lightning, because if you look at the market drivers of AI, you can’t put it in a bottle and put a cork on it.” — Gerald Auger 
  • “I’m a huge fan of educating your users, right? Just assume they’re all going to use it.” — Gerald Auger 
  • “I feel like specializing in AI governance is going to be an area, like a very special skill.” — Gerald Auger 
  • “People are over permissioning them, which is a massive problem.” — Gerald Auger 
  • “We rolled out email security training for employees years ago. I’m not seeing that same kind of AI security training yet. How do we expect users to know what they don’t know?” 
    — Jo Peterson 

Listen • Watch • Subscribe

Additional Resources

  • Flashlight in a Dark Room: A Grounded Theory Study on Information Security Management at Small Healthcare Provider Organizations by Gerald Auger 
    Gerald’s Dakota State dissertation, relevant to his long-standing work around security management, organizational risk, and cyber education. 
    https://scholar.dsu.edu/theses/329/