I recently joined the AI Security Podcast with Ashish Rajan and Caleb Sima to discuss what deception means in a world of AI agents. We covered both offensive agents that can rip through cloud environments at machine speed, and the sanctioned internal agents which have been seen to already overstep their bounds inside real companies.
Listen to the full conversation on Spotify, or YouTube.
What we covered
We ran through Deception 101 for 2026 - why deception gets misunderstood as heavyweight honeypots, why it belongs early in a security program rather than only once you're “mature,” and why AI is becoming the forcing function that is moving deception from a nice-to-have to a line item on every security team's budget.
We also discussed Tracebit's latest research on Context Bombs - how a single secret that trips a frontier model's guardrails turns a canary into an offensive countermeasure, as well as a detection.
What you'll take away
- Deception 101 for 2026: how honeypots differ from high-fidelity canaries, and why it is so important to have a Assume Breach strategy
- Why deception belongs early in a security program, not only once you're “mature”
- How a single decoy secret can take a frontier model from a 93% to a 0% success rate - turning deception into an offensive countermeasure
- How internal, sanctioned AI agents are already tripping canaries in real customer environments
- How to prove ROI on deception, even when a canary never fires
Listen now
Listen to the full episode on Spotify, or YouTube.
At Tracebit we deploy deception technology across AWS, GCP, Azure, endpoints, SaaS and CI/CD, and you can have them set up in as little as 30 minutes. If you're curious, talk to us and we'll show you in your environment.

