Close Menu
    Facebook X (Twitter) Instagram
    TRENDING :
    • Cracker Barrel stock just hit a 2026 high. Is the infamous logo discourse finally in the past?
    • Trump’s AG Appointee Is a Literal Sock Puppet
    • The luxury housing boom is unraveling. These are the only markets still getting more expensive
    • Is Graham Platner Fit to Be a US Senator?
    • Deadly Listeria outbreak linked to soft cheese sparks recalls in multiple states: Avoid this list of products
    • Directors in Hollywood close in on a 4-year deal with studios and streaming services
    • Scotch has a Gen Z problem. James Marsden and Sabrina Carpenter are part of the fix
    • Bill Gates is the latest high-profile figure to testify in the Epstein investigation
    Populist Bulletin
    • Home
    • US Politics
    • World Politics
    • Economy
    • Business
    • Headline News
    Populist Bulletin
    Home»Business»1Password sees AI as both threat and tool
    Business 5 Mins Read

    1Password sees AI as both threat and tool

    Business 5 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
    Follow Us
    Google News Flipboard
    Share
    Facebook Twitter LinkedIn Pinterest Email


    For a company with one of the most important jobs in information security, assessing the risks and opportunities of AI might feel less like an analytical exercise and more like a roll of a 20-sided die.

    That’s because a password manager, which already has to defend a customer’s most valuable credentials against both outside attackers and the customer’s own carelessness, now has to contend with AI on multiple fronts.

    AI can help a password-management firm develop code and find vulnerabilities faster, but it may also enable clients to ship sloppy, vibe-coded apps that expose passwords. And while AI agents promise to zip through complex tasks with a single-minded focus, hallucinations or prompt-injection attacks could cause them to err like any tired, distracted human, just faster and at scale.

    “You have to start with helping your customers understand their blast radius and also just how pervasive this challenge is within their ecosystem,” says Nancy Wang, chief technology officer of 1Password.

    Keeping customers out of self-inflicted trouble

    The Toronto-based company’s AI strategy starts with trying to keep enterprise customers out of trouble in the first place. It uses an on-device agent to audit AI model use and flag risks that a client’s management would want to know about.

    “Hey, Mrs, CISO, did you know that your developers are using DeepSeek model on this branch of your code base?” Wang says of the Chinese-developed LLM that’s drawn criticism over its security risks. “That has actually happened.”

    She adds that “some security best-practices conversations” followed with the developers in question.

    Nancy Wang [Photo: 1Password]

    Automated scanning by the agent, which also checks for installed software updates and other signs of device health, helps 1Password spot sloppy password management.

    “When we discover unprotected unencrypted credentials on disk because we have our own device agent, we can then move those credentials into our secure, encrypted vault,” Wang explains.

    1Password, like other password managers, encrypts saved credentials end-to-end, leaving no way for the company to view saved passwords. Wang adds that its software is designed so an AI agent cannot see the plain text of a password even as it is auto-filled into a site.

    Companies can also direct employees to install 1Password’s Device Trust agent on personal devices, addressing one frequent and often successful attack vector. Compliance, however, can be uneven, much like the family 1Password accounts bundled with business plans that often go unused on employees’ computers.

    Stopping agents from going awry

    AI agents can automate routine business tasks but, by their non-deterministic nature, require systematic monitoring to ensure they stay focused. Wang calls that a “greenfield opportunity” for 1Password to learn at scale from analyzing agent behavior.

    “What was the prompt? What did the agent do with the prompt? Was the output of the prompt?” she says. The resulting log files “will then feed back as a learning mechanism for the agent and the model.”

    In February, 1Password announced a benchmark for AI agent behavior, the Security Comprehension and Awareness Measure (or SCAM) index, and published its code under an open-source license. “We’re teaching an agent to recognize what is a phishing link, what is insecure credential handling,” Wang says. She thinks that agents, as “stateless beings,” can’t be managed as if they were humans.

    “We need new identity standards that are specific for agents that take into context,” Wang adds. “What that agent was created to do, what it is doing, right, and also the drift between what it’s doing now and the original intent.”

    Now this: In addition, 1Password is studying how AI developers and users are integrating 1Password and developing secured connections for AI apps—today allowing Anthropic and OpenAI agentic tools to read from 1Password vaults, and eventually to write back into them.

    The command-line interface in 1Password that most non-technical users probably don’t know exists has proven surprisingly popular among people paying for their own accounts.

    “The usage of our CLI product, which has been our longest running developer offering, has 2.5x-ed,” Wang says—with the highest growth coming from people on individual and family plans.

    Her thesis: “a tailwind of vibe coding driving that usage increase.”

    Putting AI to work in 1Password itself

    This company, like so many others, is leveraging AI to accelerate its software development—but vibe coding is not part of that picture.

    1Password has already rolled out such AI coding models as Cursor, GitHub Copilot and Claude Code, first with humans checking their work. “You’re prompting, it generates code,” she says. “But the human is still validating, creating testing harnesses.”

    Wang cites one early success, a refactoring project to pull out services that had been run through a single MySQL database.

    “Can we actually use an agent to help us speed up the refactoring process?” she recalls. “And the answer came back, resounding yes”—with the work done in four weeks instead of the four to five months she estimated human engineers would have needed.

    But 1Password is now moving towards automated testing of this automated code generation. “We have full agent loops that are running in the background,” Wang says. “We set up a testing harness for every coding agent, so once it passes that testing harness eval, it will actually merge requests into the code repo itself.”

    AI scanning of code for vulnerabilities shows particular promise, as seen in efforts like Anthropic’s Project Glasswing and the Mythos model developed from that.

    “The finding vulnerabilities piece will be greatly accelerated with the likes of Glasswing,” she says. But that will only create more work for developers, AI or human: “How do we harden those vulnerabilities, how do we defend against those vulnerabilities?”

    That leaves Wang with an unsettled conclusion: “AI’s been a mixed bag, just because that work has been so gnarly and technical.”



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Cracker Barrel stock just hit a 2026 high. Is the infamous logo discourse finally in the past?

    June 10, 2026

    The luxury housing boom is unraveling. These are the only markets still getting more expensive

    June 10, 2026

    Deadly Listeria outbreak linked to soft cheese sparks recalls in multiple states: Avoid this list of products

    June 10, 2026
    Top News
    Economy 2 Mins Read

    AI Fails at trading?

    Economy 2 Mins Read

    QUESTION: Marty, I loved your speech about AI here in Canada and why AI cannot…

    The Kenyan High Court has also now suspended Bill Gates immunity from Prosecution

    October 17, 2025

    Everything Comey’s Legal Team Does Is a Projection of Comey’s Crimes and Conflicts

    October 22, 2025

    We Forgot What It Took to Gain Freedom

    May 22, 2026
    Top Trending
    Business 2 Mins Read

    Cracker Barrel stock just hit a 2026 high. Is the infamous logo discourse finally in the past?

    Business 2 Mins Read

    After a controversy-filled year, Cracker Barrel Old Country Store is getting a…

    US Politics 8 Mins Read

    Trump’s AG Appointee Is a Literal Sock Puppet

    US Politics 8 Mins Read

    Todd Blanche might be the most craven attorney general yet. Thankfully, he’s…

    Business 3 Mins Read

    The luxury housing boom is unraveling. These are the only markets still getting more expensive

    Business 3 Mins Read

    The pandemic-era home price explosion was especially pronounced for luxury homes, but…

    Categories
    • Business
    • Economy
    • Headline News
    • Top News
    • US Politics
    • World Politics
    About us

    The Populist Bulletin was founded with a fervent commitment to inform, inspire, empower and spark meaningful conversations about the economy, business, politics, government accountability, globalization, and the preservation of American cultural heritage.

    We are devoted to delivering straightforward, unfiltered, compelling, relatable stories that resonate with the majority of the American public, while boldly challenging false mainstream narratives that seem to only serve entrenched elitists, and foreign interests.

    Top Picks

    Cracker Barrel stock just hit a 2026 high. Is the infamous logo discourse finally in the past?

    June 10, 2026

    Trump’s AG Appointee Is a Literal Sock Puppet

    June 10, 2026

    The luxury housing boom is unraveling. These are the only markets still getting more expensive

    June 10, 2026
    Categories
    • Business
    • Economy
    • Headline News
    • Top News
    • US Politics
    • World Politics
    Copyright © 2025 Populist Bulletin. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.