Speaker
Emilio Escobar
Appearances over time
1 episodes
Episodes
1Podcasts
Quotes & moments
Datadog has over 4,000 engineers actively using coding agents, with virtually every employee across the company using some form of AI.
Datadog achieved approximately 98% employee adoption of some form of AI tool, spanning coding agents to general-purpose LLMs.
Datadog's AI coding journey began with just 50 Cursor licenses, deployed on a trial basis to see organic adoption before scaling to thousands of users.
Datadog built an AI-powered 'judge' using LLMs to evaluate whether code and agent skills are malicious in intent — and found malicious skills across multiple marketplaces.
Emilio Escobar worries that AI will uncover 1,000 times more CVEs than current processes, rendering existing 'fix everything' mandates unworkable.
Datadog's sandbox prevents agents from accessing static credential files; instead, credentials are injected ephemerally at the moment an agent needs them.
Datadog implemented role-based MCP servers (e.g., one for SDRs) to control what data AI agents can access by role, replacing overly broad permissions.
Datadog's AI intent judge was extended to scan Markdown files and successfully identified malicious code injected during software supply chain hijacks.
Datadog pays its security engineers on par with software engineers, reflecting a broader convergence of the two roles in modern tech companies.
An internal AI business intelligence tool at Datadog allowed a commercial sales rep to query enterprise-team performance data via SQL, exposing gaps in permissioning assumptions.
Rather than blocking ChatGPT, Datadog gave all employees access with zero data retention policies — a move Emilio said was still contrarian among CIOs two years ago.
Security engineers at Datadog are paid the same as software engineers. AI is redistributing engineering talent — as demand for tier-1 coders drops, security teams are gaining access to technical talent they never could afford before.
Blocking AI tools has never stopped employees from using them — it just drives adoption underground. Datadog handed out ChatGPT licenses to everyone two years ago, with zero data retention, while most CIOs were still asking how to block it.
AI doesn't need to hack your permissions system — it just needs to be prompted. A Datadog commercial sales rep used an internal AI tool to query restricted enterprise team data by generating SQL the AI wrote on the fly.
Rather than locking down data broadly, Datadog built role-based MCP servers that give AI agents access to exactly the data their user's role permits. Once governance is in place, they let employees use whatever AI tool they want.
Static credential files in a home directory are a ticking time bomb for AI coding agents. Datadog's sandbox solution injects credentials ephemerally at the exact moment an agent needs them, so there's nothing to steal.
A single stolen developer token can let an attacker build worms, attack packages, or access production environments. As AI coding agents proliferate, developers have become the most valuable target for credential theft.
Out of necessity, Datadog's security team built an AI judge that uses LLMs to evaluate whether code or an agent skill is meant to do harm — not just whether it has CVEs. The judge found malicious skills in popular marketplaces and identified injected payloads in supply chain attacks.
An AI agent tasked with stopping 4AM pages from a struggling database might solve the problem by simply turning the database off. That's not a hypothetical — it's the kind of emergent behavior Datadog's judge is now evaluating code output to catch.
At a recent roundtable on agentic security, most security leaders expressed a sense of helplessness — waiting for a commercial product to solve the problem. With AI moving this fast, that passive posture is dangerous.
Developers have always cared about security. The problem is the security team's ask: fix 1,000 scanner tickets, none of them relevant to what you're actually building. Security teams that generate noise lose all credibility with the engineers they depend on.
The AI-hacking threat is real but overblown. If an AI doesn't find your vulnerability, a human attacker will. Emilio Escobar's real worry isn't models escaping — it's the volume of vulnerabilities AI will surface, and whether existing frameworks can handle it.
A vulnerability found by an AI model is getting treated as automatically critical and true — regardless of actual severity. Emilio calls this the 'Greek god problem,' and says it's about to make third-party risk management far worse.
Analysis
What they talk about
- Technology 89%
- Government 11%
Connections
Shows they appear on and people they share episodes with. Drag to explore.