You Can't Secure an AI Agent with Software

Charles Guillemet, CTO of Ledger, runs the offensive security lab that breaks Ledger's own products before attackers can. He explains why software permissions can't secure AI agents that move money, and why hardware has to be in the loop.
Charles Guillemet is CTO of Ledger and the founder of the Donjon, Ledger's internal offensive security lab whose job is to break the company's own products before attackers do. He spent a decade in cryptography and hardware security before Ledger, including designing secure integrated circuits.

His argument is blunt: you cannot secure an AI agent with software alone. As agents start moving real money, API keys and trust scopes leave no physical verification layer, and Charles makes the case that hardware has to sit in the loop.
This one turned into a wide-ranging thought piece (and some debate) on what the agentic economy actually looks like, and how to stay safe inside it.

We cover:
  • Why Charles thinks "securing an AI agent" with software permissions and API keys is a false promise
  • The economic asymmetry between attackers and defenders, and how AI is collapsing it
  • How a policy engine plus a hardware-enforced signature can delegate rights to an agent safely
  • Why Charles thinks the agentic economy settles on blockchain rails over Visa and Mastercard
  • Secure elements, HSMs, and zero-knowledge proofs as execution-integrity guarantees
  • How Ledger uses hardware authorization internally for passkeys, signed releases, and multisig
  • A practical way to classify assets by threat model and match security to value
(0:00) Why securing an AI agent in software alone is impossible
(0:30) Delegating execution power inside your security perimeter
(2:28) The attack-defense asymmetry AI is erasing
(6:00) The alignment problem and delegating rights to agents
(9:24) Policy engines, intents, and hardware-enforced signatures
(13:19) From developer experience to agent experience
(15:12) Secure elements, HSMs, and execution integrity
(20:00) Zero-knowledge proofs, proving without revealing
(27:24) Convincing the skeptics on agent-driven payments
(34:49) Why Ledger bet on dedicated hardware
(36:15) Hardware as a determinism layer for agents
(38:52) How Ledger uses hardware authorization internally
(43:42) Classifying assets by threat model
(46:55) When attack and defense become symmetric
(48:44) Deepfakes, voice cloning, and the scam wave
(50:04) Closing thoughts on staying safe in the agentic economy

Connect with Charles Guillemet:
Connect with Chain of Thought host Conor Bronsdon:

Creators and Guests

Conor Bronsdon
Host
Conor Bronsdon
Creator and Host of the Chain of Thought Podcast | Technical Ecosystem Lead at Modular
You Can't Secure an AI Agent with Software
Broadcast by