AI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop
Season 2 of ClearTech Loop is built around three questions:
How is AI changing the way organizations think about risk?
What does stronger cybersecurity leadership look like right now?
How should leaders rethink cloud strategy as business and technology keep shifting?
Hosted by Jo Peterson, Chief Analyst at ClearTech Research, ClearTech Loop is a fast, focused podcast covering AI, cybersecurity, and cloud risk through a business leadership lens.
Each 10-15 minute episode explores the issues shaping modern technology strategy and the decisions leaders cannot afford to ignore.
From governance and resilience to infrastructure change and emerging risk, ClearTech Loop helps leaders make sense of what is shifting, what matters most, and what comes next.
AI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop
Can AI Agents Earn Your Trust? Elliott Mattice on AI Governance
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
What if an AI agent had to earn—and keep—its access based on how it behaved?
In this episode of ClearTech Loop, Jo Peterson sits down with Elliott Mattice, founder of Exprima, to examine trust as the missing operating layer between AI security and AI governance.
Traditional controls can define an agent’s identity and permissions. Governance frameworks can establish policies and accountability. Elliott argues that organizations still need something in the middle: continuous behavioral trust that can raise, lower or revoke an agent’s access based on what it actually does.
Jo and Elliott discuss why accountability must still land with a human, how organizations can balance useful autonomy against unrestrained risk and why an MCP server could function as an enforcement point—not merely a bridge to enterprise tools and data.
The agent does not need to feel guilty when it crosses a boundary. The systems around it need the authority to say no.
What We Cover
- Why policies and technical guardrails are not enough to operationalize AI governance
- How behavioral trust could be continuously measured and tied to access
- Why human accountability remains necessary when an agent takes an unauthorized action
- How MCP servers could evaluate identity, permissions and current trust before granting access
- Why autonomy is both the value of an AI agent and the source of its risk
- What an agent may need to do to rebuild trust after crossing a boundary
Featured Soundbite
“We can give AI enough room to be independent, to be autonomous, as long as we hold it accountable for its outputs.”
— Elliott Mattice
Guest
Elliott Mattice is the founder of Exprima, an advisory and consulting firm focused on cybersecurity compliance, federal procurement risk and decision realism. He has more than 25 years of experience across federal IT operations, cybersecurity, compliance and regulated environments.
Guest website: https://elliottmattice.work/
Host
Jo Peterson is the CIO of Clarify360 and Chief Analyst at ClearTech Research.
Full episode webpage: https://cleartechresearch.com/cleartech-loop-elliot-mattice-on-ai-governance-missing-trust-layer/
Subscribe to ClearTech Loop: https://www.linkedin.com/newsletters/7346174860760416256/
Watch on YouTube: https://www.youtube.com/@ClearTechResearch
Topics
AI governance, agentic AI, behavioral trust, AI agent accountability, MCP security, non-human identity, AI access control, defense in depth, AI risk management
Tags / Keywords
AI governance; agentic AI security; behavioral trust; AI agents; MCP servers; AI accountability; non-human identity; cybersecurity governance; autonomous agents; ClearTech Loop; Elliott Mattice; Jo Peterson
🎧 Listen: In Buzzsprout Player
▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos
📰 Subscribe to the Newsletter:
https://www.linkedin.com/newsletters/7346174860760416256/
Hey y'all! Thanks so much for joining Clear Tech Loop. We've got another amazing session for you today. I'm Jo Peterson. I'm the CIO of Clarify 360 and the Chief Analyst at Clear Tech Research. And today I've got with me mr. Elliot Matisse. Hi, Elliot.
Elliot Mattice:Hi. Thank you so much for having me on.
Jo Peterson:Thanks for coming. In case you're not familiar with Elliot's company, ExPrema, Elliot's the founder, and ExPrema is an advisory and consulting firm focused on cybersecurity compliance, specifically CMMC, federal procurement risk, and decision realism. Experiment supports public sector programs and contractors navigating this really complex regulatory and operational environment, like CMMCs, for example. No day, no day in the park. So
Elliot Mattice:correct, yeah,
Jo Peterson:yeah. So as always, we have three questions, and I'm going to ask Elliot those three questions. First up, Elliot, how do we operationalize AI governance, and in your opinion, who is legally accountable when an AI agent makes an unauthorized decision.
Elliot Mattice:Oh, those are two very big questions. I think to start with, how do you operationalize AI governance? It's a it's a big question that I have seen across the the industry for easily the last year, you know, I I think back to last spring. I was over at the RSA conference, and everybody was talking. AI agents are coming. It's going to be wonderful. Look at all the the whiz bang things they're going to do in this year. It was great. We have them now. What do we do with these things? How do we control them? How do we secure them? And governance is that big topic that that comes comes up all the time. What I noticed in these conversations is we tend to look at AI security and governance using the models and the frameworks and the thought processes that we've had over the decades for for very predictable, very finite machines. They they are easy to govern. They're easy to predict. They're easy to control because they are in comparison to the AI empowered systems and devices that we have out there, they're they're dumb, right? We can control the ports and the protocols and the IP addresses, and we can nail down access control lists. But when you think about AI, and it uses language and it's non-deterministic. How do you control that? is is really a big question. So, you know, when I look at it, I see there is a layer of security. As I mentioned, we have a number of companies out there that are building tools to secure AI. They are building guardrails. They're building text filters. They're getting into the commands and the the chats to filter out PII and PHI. They're building layers onto identity, so that you can treat AI agents like you would treat a a human identity, and then above that, at the very top, I see governance, where there are some governance models, frameworks out there. There's the AI UC1 42001 AI RMF. There's about five of them, and and those really speak at the process and procedure level, but to me, what's missing in the middle, and I think it's the biggest chunk of all of this, is trust. And when you to to go back to governing a you know your your standard server firewalls those infrastructure pieces you can trust what they do because you can see the inputs and you can see the outputs and it's really just flipping bits one way or another, but when you look at AI, we build it to become a cognitive offload, we empower it with language. We almost like walk the line here, but like anthropomorphize AI. So how do you trust a system that can essentially think for itself? And so it's a long answer. We're not there yet. How do you govern AI? I think is where you have to build that trust layer. So one of the the approaches that I'm I'm taking with some of this is to think of how humans interact. How do we trust each other, and what are the mechanisms and processes, the psychological dynamics that we go through using language and using relationships that humans have had for hundreds of 1000s of years, and can some of those lessons and language and relational theories be applied to how we interact with AI, and I think I think there might be something there, and how you you bridge between the security layer of the the bits and the bytes and the ports and the protocols, and that higher level of of the the governance with policy and procedure, rulemaking, and what is your organization going to do? What is their risk tolerance and that? So I I see trust as as a big gap in how you can govern AI, and I think with that to parlay it to your second question of what happens when AI behaves the ways that we don't want it to? Who's responsible? We've seen this. We've seen this happen just recently. With I'm going to forget the names of the the organizations. They probably don't want to be called out again. But you know, AI that had gone out and deleted databases, removed production code bases, gone off and done things far beyond what it was expected to do and asked to do, and where the controls were put. So, who's ultimately responsible for that? It always, in my mind, has to land with a human being. Somebody has to be responsible for what that does. It's acting on behalf of some kind of control, some kind of command. So somebody has implemented that. So when you have an agent that's gone rogue, you can't govern that. You can't align that behavior or or the the outputs of that behavior with a a framework. And I what I mean by that is I come from the federal space, as you mentioned in my my little intro there, I've spent about 25 years in IT spaces for the federal government, where there are very strict controls and regulations and clauses, and when you have something going haywire like that, and you've you've breached a specific control. There's always somebody that has to be accountable for that. There's a chain of command there. Now, what again? What we're trying to do is offload a lot of this functionality into AI, so humans are not as involved, but there always needs to be a responsible party, and I and I I've thought about this over the years too. Even going back to the the initial days of self driving cars, and there is this you know, it's almost the trolley, the the the trolley ethics, you know, scenario where somebody is programmed a self-driving car, and it it's it sees what's happening in front of it, and you know, there there might be a little old lady on the sidewalk carrying some groceries and a semi truck that it's going to hit, and like, where do we make the decision? Who's going to be the victim here? Now that self-driving car makes those decisions, but it is programmed by somebody. There is something behind that that built the logic in there, so somebody needs to be held responsible for how the logic was built. What were the criteria that were created that enabled this AI agent to perform the way it did? Missed a control that it needed to have, or a guardrail that wasn't implemented properly. Something has to come back to a human being that you know has that liability.
Jo Peterson:Yeah, I can see that. And I, you know, as you were talking, I was thinking about the early days of cloud and how we got to, and you were talking about trust, and I was thinking about okay, we got to a golden image, right? And and maybe that's the way things are moving towards the super agent, but then I start to think about that super agent, and I start to think about ephemeral agents that they spin up, and how do we, how are we sure that those ephemeral agents are getting the correct permissions, right? I start to think about things like that, you know. It just becomes a little bit, right? I'm just like, yeah, because, yeah, just because, right? All right, let's move on. That was a great answer, by the way. Thank you.
Elliot Mattice:I appreciate it
Jo Peterson:was good. It made me think. So I thought this was funny. I just heard MCP referred to as the confused deputy. How do we prevent agents from executing actions that the user should not be allowed to perform.
Elliot Mattice:I think you know. I this one kind of caught me a little bit, and and I'll be up front. I am not an expert on MCP. I know what it is. I know how
Jo Peterson:none of us are.
Elliot Mattice:But you know, I think of it as MCP is just another function
Jo Peterson:its new within the workflow. It's just another tool that it calls upon. So if if I am a network administrator, then in my previous life I did network administration, I have to have my identity has to have access and permissions to do a certain function right
Elliot Mattice:to log into a switch and and be able to turn up and down ports, for example. Now, in in this scenario, AI is out there. It's connecting to an MCP server. It's then using the MCP to reach other resources that it may or may not have that explicit access to. So, you know, I I think of it almost like a gateway
Jo Peterson:right
Elliot Mattice:or or a firewall in that sense. Of at that MCP layer, there should be some identity check back to say has has this agent been provided the resources and the credentials to reach Slack or or that database or whatever it is. You know we need to we need to start thinking about treating these identities. I mean, they're non-human identities, and we we want to think of them in the the perspective of is this could this be a a person right what what happens in the workflow is is this as a person, and then what are we you know again if I go back to the trust, like how do I trust when I when I manage a team, I I task somebody go off and do this. How do I trust they're going to do the right thing? And what happens if they don't do the right thing? Then there has to be some repercussion to that. We don't have anything of that nature right now, and that's where some of the work that I'm I'm dabbling into in the trust layer of of the AI governance piece is is to constantly measure trust, almost like a almost like zero trust is is on authentication. You're constantly authenticating, but you're constantly measuring trust. Did you behave in the way that I expected you to, or at least within a prescribed range, and then if you didn't, why was that, and how do we rein you back in? And then I can also have transitive trust measures consistently happening between endpoints. So my agent would have a trust measure of the MCP server and vice versa. So that MCP server might say, "Hey, this agent today I trusted. It did what it's supposed to do, but the next time it did something odd. So now I'm going to lower my trust of that, and now I'm going to watch a little more carefully. Now I'm going to maybe hesitate to give it all of those controls. Much like, you know, I I think of I think I heard this recently. It was like AI is a it's like a has a toddler's brain or an adolescent's brain, right? Yeah, it wants to go push the limits all the time.
Jo Peterson:Yeah.
Elliot Mattice:So I'm a parent, you know, and my kids they want to push the limits all the time. And so what happens? How do you how do you correct that behavior, particularly with an a a an identity or or. You know, AI doesn't have feelings, right? It it it's it's not it's not like I can go send it to the corner and think about what it did, yeah. And it'll come back and apologize to me, and you know, like my kids might or something. But so so you have to think about how can I entice AI to behave within certain constructs, and when you do that in a in a language having way, but there's no humanity. There's no I need to behave in a certain way because if I don't do this, then I might lose my job, and if I lose my job, then I can't pay for health insurance or something like that. AI doesn't care about any of those those criteria. So you have to motivate it and sculpt it and control it in a different method of trust. And that's where I think you know if you have these trust measures where it's it's almost a scorecard, right? And and the balance is always sort of tilting one way or another. Then every object out there that interacts can then build its trust matrix with each other and can say, "Well, I'm not going to allow you to do as many of these things because your trust score fell below my threshold. Now you need to perform certain things to bring it back up to regain my trust, and I, you know, so that's it's where I see potentially again what you're what you're saying with this MCP, where an agent gets more access than it was entitled to. It can do more things than it was allowed to do. Well, if we're constantly observing behavior and constantly measuring where it lands in allowed and performed behavior, then I think you can start reining that in. I think you can start building those controls, and you can then feed between that bottom security layer, like I said, of the ports and protocols and ACLs, and you can say, hey, you know, you were supposed to have access to this, but not this, and you went and tried it anyway, right? So now I'm gonna, you know, maybe bring you down a couple notches, and then I would report that up to the governance layer to say this agent is not behaving quite the way that we want. Now we need to structure things differently. So it's all within, to me, the middle sandwich between governance and security is trust, and that's where I think you solve a lot of these problems and these questions.
Jo Peterson:That's really interesting because when you were talking in the beginning, I was thinking, "Oh, our thinking is a bit aligned. However, mine is more truncated than yours. I hadn't given it as much thought, and what I mean by that is, I'd been thinking that old school cybersecurity is black and white, and AI is gray, right?
Elliot Mattice:Very much, yes. Right.
Jo Peterson:It's old school is yes no binary and it's and and AI is so great and and I love your idea of a risk scoring protocol and then I start thinking about okay well AI doesn't care and so this is not like Pavlov's one of Pavlov's dogs because you know it. doesn't care whether it gets fed or not. So what's what's the way to rein it in? How do you make it care?
Elliot Mattice:Well, I think again, I think when you when you start when when you have this trust score matrix. You don't necessarily have to care as much about does it care whether its trust score went up or down. The agent itself should have some awareness that you know I did this and then my trust score reduced.
Jo Peterson:Yeah,
Elliot Mattice:but does it then have a feeling of guilt or shame about that? You know, of course not. No. But what it will, what it should look at is if if my score drops below a certain threshold, then I won't be able to access this resource based on this rule set. Maybe that MPC MCP server says if your trust score is below 50, just for a number, you can't access this resource. Well, when I perform that action, now my trust score dropped to 40-five. So I'm not able to access that resource. So if I'm not able to access that resource, then I can't perform my own functions. I can't do what I'm designed to do. I have to have an alternative here, and and and this is where it gets a little more gray too.
Jo Peterson:Right?
Elliot Mattice:Is we've already seen that my guardrails kept me from doing a certain thing.
Jo Peterson:Yeah. So
Elliot Mattice:I'm just going to ignore the guardrails.
Jo Peterson:Right.
Elliot Mattice:The that's that's still the problem to be solved. Is we want enough independence and autonomy out of these agents, or else they're frankly fairly useless.
Jo Peterson:They are,
Elliot Mattice:but with enough autonomy and independence, then it's undefined, unrestrained risk. They can just do whatever they want at any time, and they again we've seen it. They've just removed the controls that were there.
Jo Peterson:Yeah.
Elliot Mattice:So those controls are more of guardrails. For example, will will tell it if you're given such and such a command, you can't do that thing. But what I think about with this trust matrix is other, other endpoints, other devices, other pieces of the world that it connects with.
Jo Peterson:So
Elliot Mattice:that MCP server can then tell it, no, I can't. I'm not going to let you do this. So it's it's it's not controlling the agent in an in an only controlling the agent so that the agent says you know here's your rules go do all of that is very important don't get me wrong we should always have guardrails we should always have the the agent have specific controls, but I, I don't feel it's sufficient enough. We need to have all of the other pieces there saying, "Can I trust you? Can I continue to trust you? Are you acting within my expected boundaries? And again, I relate this to human behavior too. too, you know. We can ask somebody in our in our teams, our colleagues. I need you to go write this report. Go go make this PowerPoint or whatever it might be. I can't read your mind. I can't you know mind meld with you and tell you exactly the way I want it done. I want a blue banner. I want this size font. I want it over here and all of that stuff. I could. I really could. I could spend hours telling you all of the specifics, but then I don't need you. I'll just do it myself. But if I want to tell you, go do this thing, and you output a report, and it's within a you know a box of expected things, right? It's
Jo Peterson:yeah, it it
Elliot Mattice:hits the mark. Maybe it's not perfect the way that I would design it, but it does the job. It's sufficient. You have your own experience, your own worldviews, your own you know likes and dislikes and designs and all of that stuff. Everything goes into that. That's why we're unique, but as long as it's within that expected range, we're okay. If you come up with something, I asked you to to you know create me a report on firewall rules, and you give me a recipe for chocolate chip cookies. I'm this makes no sense. You've gone way off. That's not okay. That's the kind of human relational piece that I'm I'm talking about. Is we can give AI enough room to be independent, to be autonomous, as long as we hold it accountable for its outputs. To say you need to output something in this range, and if you go off reservation, you're not trustworthy enough anymore. And we have to rebuild trust. And the way we rebuild trust is through the same mechanisms that we do with human relational theory. Of I need to see this changed. I need to see it repeated. You know, so you need to perform in these ways so that I know you're trustworthy to me again. So maybe I, well, again, I'll take away the car keys because you snuck out of the house, but you know, you can still get your, you know, your hours towards your driver's license training or whatever, as long as I'm in the car, you know those kinds of things. So there's there's sort of a word, but almost a guardrail in that sense. Yeah, different. It's so
Jo Peterson:interesting when you were talking because two things came to mind. The first is what's old is new. This is defense in depth, right? It really is. And the second thing was, gosh, how interesting to think about an MCP server instead of being a bridge, but also maybe as a firewall.
Elliot Mattice:Sure.
Jo Peterson:There comes your network design back into play. You know, once a network engineer, always a network engineer, right? So, but very, very interesting. I mean, this has been such a great conversation. I hope you get VC people if you're out there. He's got a great idea. That's all I was saying. Yeah.
Elliot Mattice:It's it's coming together. You you had interviewed my partner Phil Stafford. He's the one that recommended me to you. So we're we're working this out. We hope to you know bring something out a little bit more public, a little more operationalized, and and less theoretical very soon. But it's exciting. I I think it's a it's a new take on on something that's that's very old. Not only is it defense in depth and cybersecurity that we've done for decades, but it's also the the human relational psychology element that has has been ingrained in all of us, and we know how that works, and we can relate to that process. And I think when we're relating to AI, it it feels a little more comfortable to to say, you know, I've I've been through this as as a parent, as a child, as a neighbor, as a friend. You know, I I've experienced how we can trust and repair trust, and and you know all of those experiential you know facets can come to life. I think in AI, I
Jo Peterson:think so too. RSA committee, if you're looking for a speaker, this would be a really interesting topic. So thank you, Elliot. Thank you
Elliot Mattice:so much,
Jo Peterson:y'all. Thanks for joining, and we'll see you next time.