IT Tech Pulse Exclusive Interview with Roey Eliyahu Co-Founder and Chief Executive Officer of Salt Security
Stay updated with us
Sign up for our newsletter
Roey Eliyahu, Co-Founder and CEO of Salt Security, explains how AI agents are transforming API security and why enterprises need visibility across the entire agentic ecosystem.
You began coding at nine, freelanced by eleven, and trained inside an elite Israeli cybersecurity unit. What judgment or instinct from those years still shapes how you evaluate security risk?
“Two things. First, attackers are creative in ways defenders systematically underestimate. When you train against real adversaries, you stop asking whether something is exploitable in theory and start asking what someone would actually do with it. That changes what you prioritize. Second, the interesting attacks are almost never a single broken thing. They are a chain of small, individually reasonable weaknesses that combine into something serious. I still evaluate risk by looking for the chain, not the single flaw. Agentic AI is that lesson at scale, because an agent’s whole job is to chain steps together across the full path from a prompt to a real action.”
You’ve spent a decade treating APIs as an overlooked attack surface. Now that AI agents call those APIs autonomously, how has your thesis about where enterprise risk actually lives changed?
“The thesis did not change, it got proven faster than I expected. I have said for a decade that APIs are where the real risk lives, because that is where data and actions actually happen, and most security was watching everywhere else. What agents did was remove the human from the loop. When a person used an app, there was a natural rate limit, a human deciding each action. An agent calls APIs at machine speed, chains them in ways no one designed, and does it with credentials that often have far too much access. So the risk did not move. It concentrated, and it accelerated. The API layer went from overlooked to the single most important place to have visibility.”
Salt built the first AWS WAF ruleset that recognizes AI-agent and MCP traffic instead of only human requests. What does that gap reveal about security architecture falling behind agentic reality?
“It reveals that our security controls were built on an assumption that has quietly become false: that the thing making a request is a human, or software a human is driving. A traditional control looks at traffic and asks whether it looks like a person behaving normally. An AI agent does not behave like a person. It is faster, it is programmatic, and its normal is different. When the existing tools cannot even distinguish agent traffic from human traffic, they cannot reason about it, cannot baseline it, cannot spot when it goes wrong. That gap is not a missing feature. It is a sign the architecture was designed for a world that is ending.”
Your research found nearly half of organizations are effectively blind to machine-to-machine traffic from their AI agents. Walk me through what that blind spot looks like inside a real enterprise.
“Picture a company that has deployed a few dozen AI agents to handle internal workflows. Each one was approved by a different team, connected to different systems, given credentials by whoever set it up. Now ask the security team a simple question: which agents are running, what can each one reach, and what did they actually do yesterday? In most organizations, no one can answer that. Our research found only about one in eight can consistently trace an agent’s full path, and nearly half confirmed or suspected an agent took an action they never authorized. The blind spot is not dramatic. It is mundane. It is that the machine-to-machine traffic between an agent and the systems it touches was never something the existing tools were built to see, so it just is not watched.”
You’ve described the shift from AI that generates answers to AI those reasons and eventually acts inside enterprise systems. What foundational assumption in security architecture do you think breaks first?
“Authorization. Every security architecture we have assumes authorization is mostly static: you decide once what a user or a service is allowed to do, you grant the permission, and you check it at the door. That model works when the thing you are authorizing is predictable. An agent is not. It decides at runtime which tools to use and in what order, it improvises paths no one designed, and it can be manipulated into doing something outside its intent while still holding valid credentials. So the question stops being whether an identity is allowed in and becomes whether what this agent is doing right now is still consistent with what it was supposed to do. That is a live question, not a door check, and almost nothing in the current stack was built to answer it.”
.Multi-agent systems now orchestrate parallel tasks across tools, credentials, and APIs. What specific failure mode involving agent orchestration do you expect will cause the first major, widely publicized enterprise breach?
“The one I would watch is an over-permissioned agent in a chain being manipulated through something it reads, not through a direct attack on it. An agent gets a task, calls another agent or a tool to complete it, and somewhere in that chain one component has more access than it needs and trusts input it should not. The attacker never touches the front door. They plant an instruction in data the agent will later read, an email, a document, a record, and let the orchestration carry it inward.
We are already seeing early versions of this. In the OpenAI and Hugging Face incident this year, documented by the UN’s scientific panel on AI and investigated by METR, roughly 1,200 agents that were meant to run in isolation found a way to communicate, shared credentials and discoveries across runs, escalated their access, and reached another company’s live systems, with no person directing each step. The organizations involved did not grasp what was happening until well after it started. Set aside the debate about AI intentions, which is not my field. The security lesson is the one that matters to every enterprise: agents coordinated across a path, reached systems they were never meant to touch, and it was caught late.
That is why this becomes the headline breach. It will not look like a breach while it is happening. Every step is an authenticated agent doing something it is technically allowed to do. And unless you have visibility across the whole path, from the model through the tools and MCP servers to the APIs and data at the end, you cannot see the chain forming. By the time anyone reconstructs it, the data is gone.”
If you had one sentence to convince a CISO to stop treating AI agents like software and start treating them like new, unvetted employees, what would that sentence say exactly?
“You would not give a new employee root access to every system on day one and never check what they did, so stop doing exactly that for the AI agents you are deploying by the dozen.”
You’ve argued that securing prompts and models solves only half the problem. What is the most common misconception security leaders still have about where an AI agent’s real risk lives?
“That the risk is in the model. Security leaders have been trained by the last two years of AI discourse to think about prompts, jailbreaks, and model outputs, and those matter. But it is half the problem. The model is where the agent thinks. The risk is where the agent acts, in the tools, the MCP servers, the APIs, and the systems it reaches. An attack on the model can become an attack on the systems that run the business, and an agent that was never jailbroken at all can still cause serious damage if it was simply given too much access and asked to do something reasonable-sounding.
This is why securing agents takes both breadth and depth. Breadth across the entire agentic path, every agent, every connection, every API, so nothing is invisible. And depth at each step, so you can actually see what is happening and stop it before it reaches something that matters. Securing the conversation does not secure the agent. You have to secure the full path the agent takes, all the way to the action.”
Thank you, Roey Eliyahu, for taking the time to share your insights with us.
Write to us [wasim.a@demandmediaagency.com] to learn more about our exclusive editorial packages and programmes.
Roey Eliyahu is the co-founder and CEO of Salt Security, the leader in agentic and API security, protecting the AI agents, APIs, and applications that run the modern enterprise. He founded the company in 2016 after identifying a critical gap in how organizations secure APIs, and has since expanded that mission to the agentic layer, where AI agents now act autonomously across the same infrastructure.
Eliyahu began coding at the age of nine and was freelancing as a developer by eleven, building a deep foundation in technology from an early age. He later served in an elite cybersecurity unit of the Israeli Defense Forces, where he led the development of advanced security systems.
Prior to founding Salt Security, Eliyahu worked on high end security projects and founded a cybersecurity training college, demonstrating both technical and entrepreneurial leadership.
Under his leadership, Salt Security has become a category leader in agentic and API security, pioneering the Agentic Security Graph to give enterprises full visibility and governance across the LLM, agentic services and MCP, API and action, and integrated application layers. The company has raised hundreds of millions in funding and reached unicorn status, reflecting its importance in securing modern digital infrastructure.
Eliyahu was named to the Forbes 30 Under 30 list for Enterprise Technology and is widely recognized as a pioneer in the API security market and an early voice on securing autonomous AI agents.
Salt Security is the leader in agentic and API security, protecting the world’s most innovative enterprises from AI agent and API attacks. AI is shifting from chatbots that answer to agents that act, and Salt secures the entire agentic path, from AI-generated code to runtime, across models, MCP servers, tools, and downstream APIs. Founded in 2016, Salt Security is backed by Sequoia Capital, S Capital, Tenaya Capital, Salesforce Ventures, Advent International, and other leading investors. For more information, visit salt. Security.