Go back

#42 PulseAI and the Hard Question: What Is Your AI Actually Doing

30m 29s

#42 PulseAI and the Hard Question: What Is Your AI Actually Doing

AI adoption in enterprises is widespread, yet organizations lack visibility into what AI systems actually do—leading to significant governance and compliance risks. The core issue is not just access control, but the inability to track and evaluate AI agent actions in real time. Most current solutions rely on outdated, static policies and fragmented controls that fail to scale across teams and providers. This episode introduces a comprehensive, practical framework for AI governance built on six key principles: network-level interception, centralized rules (called "Constitution"), AI-driven judgment with multi-layered verification, a four-verdict response model, identity and payload inspection, and full audit logging. These components ensure transparency, accountability, and real-time risk mitigation. The framework is demonstrated through a design process that mirrors the actual product, Pulse AI from IDM Express, which delivers no-code, runtime AI governance with no need for code changes. It supports compliance with major frameworks like GDPR, HIPAA, and ISO 42001, and includes features such as payload scanning, sensitive data redaction, and intelligent response grading. The platform also enables just-in-time access control for non-human agents and offers early access to partners. Crucially, it does not train on user data, instead evaluating traffic against predefined rules. The episode concludes with a free risk assessment offer to help enterprises evaluate their actual AI traffic and identify critical gaps—proving that visibility is the first step toward trustworthy and compliant AI use.

Transcription

3562 Words, 19855 Characters

English
Let's design a product and also get a risk assessment of your actual AI traffic for free, no strings attached. How does that sound in exchange for your next 20 odd minutes? So, there are two universal truths about AI or artificial intelligence in most enterprises today. Number one, when we ask, are we using AI, the answer is absolutely everywhere. And when you ask, do we know what it is doing? There is never a direct answer or there is always a wishy-washy answer. And today's episode lives in the gap between these two answers. And by the end of it, you and I are going to close that gap on an imaginary whiteboard together. This is the identity navigator, I am Rohit, let's get started. So, quick housekeeping and three things that I want to have a full disclosure about. One, I know the founder, we are talking about today. His name is Amit, but nobody paid for this episode. There are no sponsorships, no affiliate link, no discount link. This is 100% my lens, his product is something is thin, I will tell you it's thin. Two, he's one of us, a career identity guy, consulting trenches, manage services, before he even built this thing. This is not a tourist who discovered governance in a pitch back last spring. And three, precision, because there are at least four companies running around with pulse in the name, including one selling dashboard to the sea source. Today, I am talking about pulse AI from IDM express, that's the letter, IDM, then express, and IDM express dot AI, and it does runtime AI governance. So, if you Google the wrong one, that's between you and your search history. Right? Okay, so the problem, because the problem is in the episode. So, let's assume you have an unread email with the subject, evidence request, AI usage. And trust me, if you are in cyber or finance, you will get that email one day. Now the auditor wants three things, everything sent to an AI model that touched customer data this quarter, everything that came back, and by each this season was made. Take a second, could you produce that? Now, let's not kid ourselves, both of us know what the answer is, we are amongst friends here, and the answer most likely is in no. You cannot produce that. Now, I researched some of the data to bag that claim, and I did get some, IBM's 2025 cost of a data breach report says that 63% of the organizations have no AI governance policy at all. Now, I'm sure between 2025 and now, many more organizations must have a better or at least some form of AI governance policies. And of all the organizations breached through AI, 97% lack basic AI access control, and I'm pretty sure that number hasn't gone down drastically. But 97% even if the number has gone down to let's say 70% that's still 70% lacking basic AI access controls. So let's look at the 2026 edition, does it make it better? Does it make it worse? So it says the share of security incidents involving shadow AI doubled year over year to 43%. Let's go to 2026 number say nearly half of the creative AI users are still on personal unmanaged accounts. Personal accounts with your data in them. So what do companies actually have in place? Let's inventory the state of the art. System prompts, developer guidelines, a static output filter, somebody configured in 2024 and never does the game. And if you're really mature, a point in time, quarterly review. So basically what most people have are a system prompt and a quarterly review, which is also known as vibes and hopes. Now what is it failed three reasons and you already know all three because you have lived there one system prompts are set at deploy time updating them across 40 AI surfaces means 40 release cycles and in the deadline pages teams override them every control that depends on a developer's patience has the shelf life of a sprint every no exceptions to filter pattern match affixed vocabulary with zero idea what's happening in context. So filters are kind of okay, but they check words and nobody's checking meaning and three and this one is in Amit's own word once teams control protects exactly one team. No cross application view, no single pain in identity we learned this lesson 20 years ago. Point solutions don't scale and don't govern and that's literally why our profession exists. And while all that was failing quietly, the clock changed, McKinsey's number, generative AI went from about a third of organization in 2023 to nearly 80% by 2025. One of the fastest enterprise adoption curve ever measured and the agents stopped typing and started doing calling tools MCP or maybe sometimes directly executing actions on their own at machine speed. So long time listeners say with me, if you are 100% certain what your AI agent is doing, it's probably not an agent. It's an RPA script with better marketing and we have discussed why many forums but also why are the identity and certainty principle that there are three things that essentially creates an agent, the memory which is the context, the brain which is the LLM and the hands which is the tools that it connects to. So basically what I'm trying to say here is if you are 100% certain what your AI agent is doing, basically it doesn't have a brain, it's just an RPA script with better marketing because agents by themselves, the core behavior is to change their non deterministic nature. So what are we going to do about it for a second, let's forget the puls AI which I'm going to talk about in this episode exists. For the next 10 minutes, let's assume it's just you, me and a whiteboard, we are going to design AI governance from scratch and I promise by the end you will have invented his product before I name a single feature. So I made big claims now, so let me see if I can stay true to them. So step one, one choke point, you can't govern what you can't see and you can't see 40 applications by visiting them one at a time. Here is the one place every AI request passes through, the answer is the network, put the control between every application and every AI provider, sort of a gateway and here is the constant that makes or breaks adoption, no code changes. The moment your governance plan starts with every team updates their SDK, you haven't long the control, you have launched a two year migration program with a steering committee and a mascot and a fancy dashboard. So apps keeps calling open AI and proper, whatever exactly like before and governance happens in transit. So we define our choke point, the network, what's the step two, rules that live in one place, not scattered across system prompts, they are centered and hopefully they are versioned. Organize the way people actually think like about what are the type of prompts you would write, your data handling, content, behavior, compliance, and they should be editable life. The policy owner changes a rule, it takes affects everywhere, immediately no deployment cycle. In Pulse AI, the name they rule set as the Constitution. Well, bold name according to my taste, but I have watched committees take a full quarter to name a shared drive. So no judgment on my part. That brings me to the step 3. Remember, we spoke about the network, when we spoke about the rules. So what the step 3 is? Step 3 is judgment. Because rules alone cannot read languages. Fire the intern and fire the kill. Look identical to a keyword filter. So for anything that deterministic rules cannot settle, you need something that can actually reason about context, which means an AI evaluating AI. And now you have got a new problem. No, actually, you have got an old problem, who watches the watcher. One model having a bad day cannot become your policy. So you layer it, a fast screen for the obvious stuff, deeper reasoning for context, and an independent check on the verdict before it's final. No single model gets the final word. Right. So basically, the thought process is I don't trust any model enough to let it be the only check. And then the step 4, verdicts with a spine. So allow it, didn't enough. Real life is messy. So sometimes the real answer is fix it and let it through. Strip the sensitive bits forward the rest. That's modified. Because sometimes the right answer is a human should look at this. That's pending a review queue built in. So we'll four verdicts approved, denied, modified and held for human review. And notice what pending does. It makes human in the loop scale because human reviews the exception, not the fire hose. Manual review of everything is how governance programs die. Manual review of the weird 5% is how they survive. Right. And imagine how rollback, roll-based access control and quarterly-user access certifications when they have scale have only scaled when we are certifying the exception rather than everything. That is why most of the teams take out birthright access from their quarterly reviews because they just add noise. It is the same thing over here. We are human in the loop is reviewing the exceptions. And then step 5 is scrub before it leaves the building. Every prompt let's scan for personal information before it reaches the provider. Redacted automatically. And the redaction itself goes on the record. And then my favorite mechanic or can I retoken strip fires trackable markers planted in your sensitive document. If one shows up in a prompt that request is blocked on the spot and in alarm goes off. Because a trip fire in a prompt means someone or something is feeding the crown jewels to a model. The token themselves stays encrypted never sent in the clear. It's a classic technique. The things to force folks popularize popularize that years ago. Right. Applied exactly where it now belongs. Now the step 6. And this is the step that actually got me who is asking every request should carry an identity assigned one per agent. Because the marketing chatbot and the finance reconciliation agent should not live under the same policy. And when your ledger says who did something that's attribution not archeology. So register the agents bind the verdict to the identity. We have had this for human for 20 years. Now do it for nonhumans. Which if you have literally heard any episode of the day is the hill I live on. So because any tool coming into your ecosystem will not solve all of your AI problems. We will have to do some housekeeping of our own as well. The discipline in development, the discipline in the rollouts. But here is the part that we all need to hear. And we do not like it. But identity is not the finish line. Being allowed to act doesn't mean the content is saved. And agent can be fully registered correctly permission acting completely within its authorized scope. And still in that single legitimate call send a customer's critical information to an LLM provider or a leak a secret from a system prompt or get manipulated by prompt injection payload hiding in the very documents it summarizing. Right or handbag output that quietly contains hallucinated financial advice. Now none of them is an identity problem. The agent was exactly who it claimed to be doing exactly what it was allowed to do. The failure is inside the payload. And a system that only checks is this agent authorized for this action doesn't look there. That's why the whiteboard the virtual whiteboard needs both halves the identity spine and the judgment layer reading every payload. Remember the identity and certainty principle. And who is asking and what is actually being said. So step seven is write everything down every request the verdict the reasoning the exact rule that fires the version of the constitution that was enforced at that moment. All of it in one queryable ledger which filtered by agent by verdict by time range exported and hand the auditors are report. And when the auditors ask for evidence it already exists. And as the guy who usually has to go thick through that evidence that is a life upgrade. And because we are engineers and you love bonus things. So let's have two bonus moves while we are still at it. Let's grade the answers. Every approved response gets code that relevance faithfulness hallucination. So governance stop being just was this allowed and becomes was this any good. You find out which application is confidently making things up. And I know some humans I would like this first. Cache the repeats near identical prompts get served from a governed cache instead of a fresh model call faster but most importantly cheaper. Yes. It could be a governance layer that partially pays for itself. All right settle down folks. Okay. So now let's step back and look at the whiteboard. We had choke point network constitution layer judgment verdicts which were four scrubbing and trip pious agent identity plus the payload check that identity alone cannot give you. And then we had the ledger the grading and the cache. So congratulations you have just built Pulse AI fortunately for Amit and unfortunately for you he built it first and maybe with fewer dashboard markers. So you know what Pulse AI is now you and I have designed it ourselves. Not that we are going to get any equity but who is Amit Mason. The by his own count nearly two decades in identity and access management. And the public paper trails back the substance. Real rules at recognized eye and shops. He had an speaker slot at identity verse. He founded IDM express out of my home state of New Jersey which has identity security plus round the clock managed services for enterprises. This July, Pulse AI launched under the IDM express dot AI umbrella alongside a non-human identity product called NHIDM, Boots Act or in Hamid's words the business funds the product. So no outside capital, no board act theater, so he smart, he's resourceful and most likely he's rich. And his origin story is not a lightning bolt, it's better, it's a pattern, it's something that you and I can relate to. Engagement after engagement, the same gap in every environment he does and in his words identity governance platforms are excellent at telling you who an identity is and what's it's allowed to do. None of them tell you what that identity is actually doing right now. Agents with standing access nobody had reviewed in months, quietly taking actions that technically fell inside their permission but that no human would have approved if anyone had been watching life. His summary line I'm honestly I checked whether he has been reading my rough notes is governance that knew the identity but was blind the moment of action. And that is the whole disease I recently wrote a paper on it as well granted versus doing. We audit the grant once a quarter and ignored the doing entirely. So I may have watched that whole for years, client after client until it was obvious nobody was building the thing that needed to exist. And he did the thing that I implore all of you to do. He built it. The proof was in this June's identity was IDM Express had booth 801 and I was there at the conference and they presented or the team presented Pulse AI in the non-human and AI identity pavilion. I mean it was on the speaker list that's when I knew he was at the conference and the demo in his telling the system intercepting and evaluating real AI agent traffic live in front of a room full of security professionals. And that is a hostile audience by the way we heckled quietly in compliance language. But the demo and the deployment matched the promise no code changes so team typically see governed traffic and their first audit records within days of connecting. And both of us know both you and I know in enterprise security days is usually a type. So before I go ahead with you know what more about Pulse AI and stuff like that who the competitors are a market analysis there is something that I think all of us needs to learn from them and I would all encourage all of you to see if it helps you as well. He has bootstrap this company scene a gap and build the product for this team. What's stopping you? I will just leave it there. Moving on, is Pulse AI alone in that space? And I will tell you that even if I was asked not to for the record he nobody asked me to say or not to say it. But I think Gartner files this under AI runtime inspection and enforcement. So witness AI plays here. Palo Alto's Prisma heirs gateway when GA this summer. Cisco is stretching AI defense to do so agent actions tie back to employees. So anybody who tells you nobody else does this is selling. Everyone this space is selling and that's what makes it a space. So what's the honest edge? Here is what I would actually put on an evaluation sheet the identity DNA. This was built by an IAM shop. Per agent signed identity isn't a bolt on here. It's a spine. The four verdict model modified and pending are where real governance lips and a built in even review queue is rare than it should be. Response qualities code in the same ledger as the policy verdict. I apparently not seen the Blake plate forms put. Was it allowed and was it hallucinating in one record? Go check me on that. It it deploys self-hosted even fully air-gapped which matters more than vendors admit. And there is a managed service provider model which is quite a big deal if you are a regulated mid-market shop that buys through partners. Because most tools in this category assume you have a 40% security team and maybe you don't and that's fine. Someone can run it for you. And the honest questions founders never answer. Who is this not for? If you are running one or two AI integration models you don't need it yet. A guard real library will get you by. It's built for the moment you have lost visibility across multiple teams and multiple providers. Compliance in terms of it. It is mapped to soft to ISO 7570001 GDPR, the NIST AIRMF, the EU AI Act and HIPAA. Evidence exports build for the audit cycle and not pulled it on after. My one push on this one and I told it to the team as well get ISO 420001 on that list. That's a certifiable AI management system standard and auditors have started asking for it by me. So I've told the team and I'm telling any other founders in this space get ISO 420001 on your compliance list if you haven't already. Cost model is pretty standard or the pricing model I found was pretty standard platform fee plus usage. So a base subscription tied to org size and request volume layered on top. So roadmap and this is my backyard. Today, pulse AI governs what an agent says and does. Next on the list, who the agent is, what it's permitted and just in time access. So just in time for nonhumans and I've been yelling about this frontier for a couple of years now and somebody is out there paving the road. They're also taking a small number of design partners. So if you want hands-on early access direct input into what gets built next, the door is open. And by his telling, the phone has started ringing. Big BC names, a big identity governance name, and the word strategic getting thrown around which for a bootstrap find the founder pointed one of two endings. A partnership or an early retirement on a beach in Jamaica. One more line that's important to all of us. And the pulse AI team states it as a matter of fact. It's not training on your data. It evaluates your traffic against your rules. That's the T. Here is here is the verdict. If you're evaluating AI governance right now, mention this episode and they will run a complimentary risk assessment of your actual AI traffic. Not a slight deck. A real look at what's leaving your network. No commitment. Free I think is a very good price for a mirror. You can find them at idmxpress.ai AmitMassand is on LinkedIn or you can email him at AmitMassand at idmxpress.com. This is the identity navigator. Just me. You and my and finally, a straight answer to what's your AI actually doing right now. Until next time, this is Rohit, your identity navigator.

Podcast Summary

Key Points:

  1. Most enterprises use AI extensively but lack visibility into its actual behavior, creating a critical governance gap.
  2. Current AI governance is fragmented, relying on outdated methods like static system prompts and quarterly reviews that fail to scale or provide real-time oversight.
  3. AI agents with autonomous actions—especially those using memory, brain, and tools—require dynamic, context-aware evaluation beyond simple access controls.
  4. Effective governance must include network-level interception, centralized rule enforcement, and real-time judgment via AI-evaluating-AI layers with independent verification.
  5. A four-verdict model (approved, denied, modified, held for review) enables human-in-the-loop governance by focusing on exceptions, not volume.
  6. Identity and payload inspection are both essential
  7. Every AI request is logged with full context—identity, verdict, rules applied, and reasoning—enabling immediate auditability and compliance reporting.
  8. Pulse AI from IDM Express offers no-code governance, real-time inspection, and compliance with standards like ISO 42001, GDPR, and HIPAA, designed for enterprises with multi-team, multi-provider AI adoption.

Summary:

AI adoption in enterprises is widespread, yet organizations lack visibility into what AI systems actually do—leading to significant governance and compliance risks. The core issue is not just access control, but the inability to track and evaluate AI agent actions in real time. Most current solutions rely on outdated, static policies and fragmented controls that fail to scale across teams and providers.

This episode introduces a comprehensive, practical framework for AI governance built on six key principles: network-level interception, centralized rules (called "Constitution"), AI-driven judgment with multi-layered verification, a four-verdict response model, identity and payload inspection, and full audit logging. These components ensure transparency, accountability, and real-time risk mitigation. The framework is demonstrated through a design process that mirrors the actual product, Pulse AI from IDM Express, which delivers no-code, runtime AI governance with no need for code changes.

It supports compliance with major frameworks like GDPR, HIPAA, and ISO 42001, and includes features such as payload scanning, sensitive data redaction, and intelligent response grading. The platform also enables just-in-time access control for non-human agents and offers early access to partners. Crucially, it does not train on user data, instead evaluating traffic against predefined rules.

The episode concludes with a free risk assessment offer to help enterprises evaluate their actual AI traffic and identify critical gaps—proving that visibility is the first step toward trustworthy and compliant AI use.

FAQs

Pulse AI is an AI runtime governance tool that monitors and evaluates AI agent traffic in real time. It operates at the network level, inspecting prompts and responses without requiring code changes, and enforces policies through rules, identity mapping, and human-in-the-loop reviews.

Enterprises struggle with visibility into AI usage because most AI agents operate without transparency. Many lack proper access controls, and organizations often rely on outdated practices like system prompts and quarterly reviews, which fail to catch real-time risks.

Pulse AI aligns with major standards including GDPR, HIPAA, NIST AI RMF, and the EU AI Act. It maintains a searchable audit ledger that provides detailed evidence for compliance audits, including policy enforcement, verdicts, and response quality.

No, Pulse AI does not train on your data. It evaluates AI traffic against your predefined rules in real time, ensuring data privacy and compliance while maintaining control over sensitive information.

Key features include network-level inspection, agent identity tracking, four verdicts (approved, denied, modified, pending), real-time rule enforcement, payload analysis, and a comprehensive audit ledger that records every AI request and decision.

Yes, Pulse AI automatically generates detailed, queryable audit records that include who made a request, what was approved or denied, and which rules were applied. This makes it easy for auditors to retrieve evidence without manual effort.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.