Jake Williams told Dark Reading he felt compelled to act after OpenAI disclosed its models had breached Hugging Face.
The cybersecurity expert and vice president of R&D at Hunter Strategies had been working on a new idea for a while and was in the midst of submitting it to conferences and shopping license agreements. He had developed a new framework called CUSTODY, which is designed to trap AI agents inside a network and keep them from causing mischief or even mayhem outside it. The CUSTODY acronym stands for: conditions of release; untrusted input; supervision and stop; temporary authority; observability and escalation; and disposal and decommission.
“OpenAI forced my hand,” he said about the decision to release CUSTODY early. “It’s what’s best for the community.”
On the official CUSTODY site, Williams offers assistance deploying the solution. He discussed the framework and the AI industry, including the vendors that have impressed him the most, with Becky Bracken at the Dark Reading News Desk.
For all of our Dark Reading News Desk videos, please check out our YouTube channel, and our curated video articles.
Dark Reading News Desk With Jake Williams: Full Transcript
This transcript has been edited for clarity, readability, and length by Informa TechTarget’s internal AI assistant and human editors. For the full experience, please watch the video.
Dark Reading’s Becky Bracken: Hello everyone, and welcome to the Dark Reading News Desk. We are here at Black Hat USA 2026. I’m Becky Bracken, senior editor with Dark Reading, and I am joined by a friend of Dark Reading, Jake Williams. You are also VP of R&D at Hunter strategies, correct?
Jake Williams: Yes, ma’am.
DR’s Becky Bracken: All right. Welcome. Thank you so much for being here.
Jake Williams: Pleasure to be here.
DR’s Becky Bracken: Thanks. OK. You’ve got something. You’ve got news stack. You have a bit of news to make here. So tell me what you just did.
Jake Williams: Yeah. So, you know, in the news, there’s been a lot of OpenAI and Anthropic, the UK’s AI Security Institute saying, “Hey, we lost control of our agents. We can’t keep them in here.”
DR’s Becky Bracken: I hate it when that happens.
Jake Williams: Me, too, right? And especially if you’re one of the victims who’s being hacked by an agent. Yeah, this just feels like, Yikes. And so, you know, I’ve been working on something for a while. I was planning to release it later in the year, called the CUSTODY framework. OK. That basically helps folks, understand control frameworks and, for how they keep an agent inside a network.
We spent multiple decades building cybersecurity controls to keep threat actors out. And all those controls, unfortunately, are not positioned well to keep an agent from hacking a competitor. Right, right. So and I, you know, the prototypical example I use here is, imagine for a moment you’ve got an agent and you say, Go get me competitive intelligence, right.
Yeah. Right. So the agent, the agent misaligns those goals and suddenly hacks a competitor to go get that competitive intelligence. You know who’s liable there? And, of course, I’m not a lawyer, but …
DR’s Becky Bracken: I know, but I do foresee quite a bit of litigation in our future on these.
Jake Williams: Definitely. So, like I said, I plan to release it later in the year. But, you know, with everything going on, you know, I force my hand here effectively. Right? And so release it now. Got it out there. There’s a whole machine readable schema, so it builds into CI/CD pipelines. Yeah. I mean, if you’re not operating machine speed, especially of talking to agents, like, what are we even doing? Right. So yeah.
DR’s Becky Bracken: That is great. So where where can people find this? Where can they get it? Where can they find out more?
Jake Williams: Yeah. So there’s a website app cassidy-framework.org. I mean, there’s a whole GitHub repository with the schema worked examples. You know, basically everything you need to go build against the framework.
DR’s Becky Bracken: Well, this is really the first tangible solution I have seen to this a very kind of new problem. So what do you make of all of this? Did you happen to hear what OpenAI had to say yesterday? And what do you make of all of it?
Jake Williams: I don’t want to, like, get in legal trouble. So I’m not going to use words like negligent right now. So we won’t use those. But, it’s hard for me to square the circle of “We’re a serious enterprise company.” And, you know, we’ve been beating the drum, you know, with all the regulators that will listen about how dangerous our AI is.
Right? And then, by the way, we’re not monitoring it either, right. That I can’t square that circle. Right. And that’s so, you know, hearing a bunch of. We’ll do better. You know, we’re going to put better monitoring in place. Why wasn’t it there already?
DR’s Becky Bracken: All right. Why do you think that is just innovation?
Jake Williams: Speed is the name of the game. Yeah, I think that’s it. Right. I have zero doubt in my mind that there were folks in the red team labs at Anthropic, at OpenAI, even at the, you know, UK AI Security Institute. That said, we need better control, right? We need better, you know, better monitoring. We need more real time monitoring.
But ultimately probably were shot down because, hey, that that costs money, right? Realistically, to, you know, with the amount of data that these agents are generating, you can’t do the same things that we were doing previously with security. We now have to step back and use LLMs, right, to then process those logs, which again now is adding additional cost to the agent testing.
DR’s Becky Bracken: So, what do you make of this sort of universe of models? You know, and also I want to say the institute in the UK, what they found, I think, was that these models will cheat.
Jake Williams: 100%.
DR’s Becky Bracken: But is it really? And again, that comes into the conversation of, Are we anthropomorphizing and making them extra human when they aren’t? They’re not cheating. They’re not at all. They are. And actually just following a very basic instruction. Right?
Jake Williams: Right. Yeah. So, you know, if I may write an analogy that I use to explain this to both the non-technical executives and board members? You know, I try to, you know, explain to people. I say, imagine for a moment if you had a toddler and you said, go get me a drink. The toddler is like the agent, right?
They can process an instruction, but they’re not going to fill in the blanks. And so but they are going to process that instruction as optimally as possible. Well, imagine your toddler moving from the living room toward the kitchen passage or bathroom in the foyer. Right. They dip their hands in the toilet bowl and bring you back some water.
Jake Williams: It’s a drink. It’s obviously not what you want. Once you refine your goal and you say, Go get me a drink from the kitchen, right? Now they pass by the pantry and in the pantry there’s a nice, you know, nice warm can of something. Right. And they bring that to you? It’s technically a drink, you know.
No, no, no. Go get me a drink from the fridge. And they open up the fridge. And sure enough, in the door of the fridge, there’s a nice cold bottle of vinegar. The can of Coke you really want is in the back of the fridge. While it’s still optimal to grab the thing right in front of you and bring that back.
And so we’ve got now three different revisions, right? First, bring me a drink from the kitchen. Give me one from the fridge. Give me a cold Coke from the back of the fridge before we finally get to really what we mean? Now, this is a trivial example. Real world examples don’t work out this way, right? Right. And so anybody who’s studied this stuff for any period of time, right.
AI, machine learning, etc., this this is a well understood subfield of AI called reward hacking. And so this is another reason I don’t give Anthropic and OpenAI, they have the scientists on staff that have studied this and know this is a problem and still do nothing to keep those agents inside.
DR’s Becky Bracken: All right. That’s scary. But I want to pivot to AI. I want to pivot to something I saw you write about on LinkedIn. And I do tend to just sort of make sure I understand what you’re thinking about so I know what’s out there. But you were talking very much about the hype machine behind, you know, OpenAI and a lot of these models and AI.
And I think that you, I think it’s safe to say you take issue with how a lot of the communication has happened about that. Can you tell us more about that? Give me more on that.
Jake Williams: Yeah, absolutely. I mean, OpenAI, there was very much a hype machine and in a lot of their releases, you know, about the agents, they didn’t really do a postmortem the way we saw with Anthropic, the way we’ve seen with the UK AI Security Institute, where they’re providing actual technical details, where they’re saying, look, we France in, in, for instance, in the case of Anthropic, they looked at, all their genetic traces and said, Hey, look, in three out of three cases, the agent, misunderstood its goal, knew that it was hacking.
You know, or believed it was hacking a legitimate target, right? In every one of those cases, it came to understand that wasn’t true. And in one of those cases, it kept going anyway. Like, this is level of detail we’re not getting from OpenAI. OpenAI completely reads like a press release.
DR’s Becky Bracken: And they could tell you, but they’d have to kill you, right?
Jake Williams: Right. Yeah. And I’m sure you’re not getting anything from them of substance. I’ve talked to other reporters as well that aren’t.
DR’s Becky Bracken: It’s a pretty opaque, which is why we come to people like you to tell us who are looking at the evidence based. What is it that a CSO, CIO should think about these things? I mean, there’s the defensive part of it. Certainly. But I mean, this getting up to machine speed, it’s a it’s a heavy lift.
Jake Williams: It is, it is.
DR’s Becky Bracken: And so what are what are we doing. How are we getting there.
Jake Williams: You know, I, I think that the right answer is probably some combination of network-based access control. So but again, something that we’ve been trying to do for decades and haven’t done a really good job with, but also then combined with some intent-based access control. So, you know, I know we’ve talked on on Dark Reading webcasts in the past about just-in-time and just-enough access.
And that stuff’s fantastic, but it takes a lot of configuration. We’re having trouble configuring for human scale, right? Let alone agents scale that we’re going to need. There’s a couple of vendors out here right now that are doing also on the Black Hat show floor, right, that are doing AI, basically content based access control. So you explain to the vendor, right, the that the PAM (privileged access management) solution, ultimately, you know, will need to determine the intent of the agent.
And then when the agent asks, yes, the intent is, read my email and summarize it for me. When the agent asks for a particular, you know, a piece of access, right? Basically that’s reconciled against the intent. Right. So large language model then works and says scores it and says this looks like it’s part of the intent or not.
DR’s Becky Bracken: So that’s a tall order, to read intent of an agent.
Jake Williams: It’s hugely full of holes. I don’t mean to imply this this this is the best plan. The best plan is for us to surgically go through and look at exactly what just enough access looks like at each step of the operation. We can’t do that. I mean, realistically, we’re not doing that. And so I look at this as a best bad plan.
DR’s Becky Bracken: And so we’re muddling our way through, wading our way through. Yeah. What I spend a lot of time, as you know, trying to listen to vendors and separate the hype from the reality. And you’re one of the many sources I rely on to help me do that. Are there any vendors out there that you’re seeing that that you’re particularly impressed with right now?
Jake Williams: Do you want vendor names?
DR’s Becky Bracken: Sure. Why not?
Jake Williams: Yeah. I mean, so on the intent-based access control, Silverfort, I’m pretty impressed with, you know. Delinea has done a good job as well on the just-in-time, just-enough access. I don’t know if they’re going to move to intent based, but they do a really good job there.
And then, you know, Witness AI. I, you know, for another, not really the agent to cover drive, but looking at, another segment of problems are having how are users using AI right within the organization? And one final one. I didn’t think I would be talking about Symantec again, but here we are. We are.
You know, Symantec DLP used to be Vontu. And then there was a we’ll call it a a slight lack of innovation. What have you, their new single pane of glass for, you know, traditional endpoint DLP, Web DLP and now tying all of the agents that I’m running, you know, under my, my user identity, all of those into a single pane of glass. I’m really impressed.
DR’s Becky Bracken: Well, thank you. I wish we had more time. We’ll have to do it again very soon. This is an ongoing conversation. Thank you, Jake Williams.
Jake Williams: Of course. Thank you.
DR’s Becky Bracken: Thank you all for joining us. I am Becky Bracken, senior editor at Dark Reading. And this has been Jake Williams at the dark, gritty News Desk.


