Security Will Be Agentic

Ambient.ai CTO and Co-founder Vikesh Khanna on moving AI from alert generation to contextual reasoning, threat assessment and proactive security operations.

Key Highlights

  • Ambient.ai's Agentic Physical Security uses continuous AI reasoning to prevent incidents rather than just detect them.
  • The platform’s models understand scene context and behavior, reducing false positives and alert noise significantly.
  • Investigation processes are streamlined with AI-generated narratives and semantic search, saving hours of manual work.
  • The future of security includes robotics like drones and ground robots, which require intelligent reasoning to be effective and trustworthy.
  • Human judgment remains vital; AI augments decision-making by providing relevant, contextual insights while maintaining control and privacy.

Artificial intelligence has already transformed the way security teams detect and investigate events. But Vikesh Khanna believes the industry is approaching a more consequential shift: AI systems that don't simply identify what is happening, but understand context, assess risk and help determine what should happen next.

As CTO and co-founder of Ambient.ai, Khanna is helping advance what the company calls Agentic Physical Security, an approach built around always-on AI reasoning rather than traditional rules-based analytics. Ambient.ai was founded by Khanna and CEO Shikhar Shrestha, both Stanford AI researchers, to address a fundamental limitation in conventional physical security: too much activity for human teams to continuously monitor and interpret.

In this SecurityInfoWatch Executive Q&A, Khanna discusses why simply adding AI to existing security systems can create a bigger “haystack” of alerts, how purpose-built vision-language models can help identify the events that actually matter, and why the ultimate measure of AI may be less about how much it detects than how much unnecessary work it eliminates. He also explores the continuing role of human judgment, the privacy implications of AI-driven physical security, and why the eventual convergence of AI agents and robotics could fundamentally reshape the security operations center.

SecurityInfoWatch: What's new with Ambient.ai right now?

Vikesh Khanna: Our mission is to prevent every security incident we possibly can, and that means making Agentic Physical Security real rather than theoretical: systems that reason about what is happening and act on it, instead of recording it for somebody to find later.

Everything we have shipped follows from that. In late 2025 we introduced Ambient Pulsar, the first always-on, edge-optimized Vision-Language Model (VLM) built for physical security. In the spring we brought that reasoning to access control with Ambient Access Intelligence, clearing false alarms, diagnosing the doors generating chronic noise, and confirming that a door reporting itself closed actually is.

At the end of August we announced Agentic Video Walls, an AI agent on every connected camera that surfaces the one moment that matters most every 60 seconds; Case Management with an upgraded Semantic Search, which turns a multi-day investigation into minutes of work; and double the camera density on a single Ambient Edge Appliance, so customers get more coverage without new hardware.

 

The pattern is consistent: We innovate at the model layer, then build integrated agentic capabilities on top of it, so security operations become significantly more efficient, not just better instrumented. It is showing in the business, too: new ARR doubled, our customer base tripled since we launched Ambient Intelligence, and net revenue retention is above 140%. Cisco, ServiceNow, SentinelOne and TikTok run this across campuses, data centers and critical infrastructure.

SecurityInfoWatch: Every vendor seems to have an AI banner these days, and everyone claims to be AI-powered. If you're a security director, how do you tell what's real?

Khanna: The noise around AI in physical security has polluted the term. Much of what gets labeled AI is analytics, perception, or workflow automation, usually bolted onto a platform built to record video. That is not an argument for ripping out your video management system. You can keep it and layer AI-native intelligence on top.

What earns the name is context understanding and reasoning, built into the architecture rather than beside it, and trained on real physical security data. The test is whether it works like an experienced security operator beside your team or is one more system making work for them.

So, look under the covers. Does it understand a scene, or only detect the objects in it? A model can describe a quiet street accurately and still miss the building on fire in the corner. Does it tell a real threat from a mere event? Ask a reference customer what happened to their alert volume after deployment: If more AI made more alerts, it is notifying, not assessing. And does it need to know who people are? Ours does not, since the reasoning is about behavior rather than identity.

SecurityInfoWatch: You've built the category around the term "Agentic Physical Security." Why do you think that's a real category and not just a slogan?

Khanna: Because it is a new operational model, not a new label. The real mission of physical security has always been to prevent, and the industry has never delivered. You cannot prevent what nobody is watching, and no team is large enough to watch everything, so the model stayed reactive by default and we all called that normal.

Always-on AI agents change what is operationally possible. When something reasons about every camera continuously, prevention stops being an aspiration and becomes a workflow.

Reasoning is the breakthrough that makes that real, and it is why we built Ambient Pulsar rather than adapting a general-purpose model, which for always-on work of this kind is roughly 50 times less efficient. Detection tells you a person is there. Reasoning tells you they have circled a loading dock three times at two in the morning. That is the line of demarcation, and it will reorganize the physical security stack over the next few years.

SecurityInfoWatch: How is this actually playing out for the customers using it? What kind of impact are you seeing on the ground?

Khanna: We see incredible examples every day, across more than 10 billion events a day on the platform.

A national research facility had an after-hours perimeter breach. Their team saw the alert seven seconds after it was raised and had an officer moving within sixteen. The system they had relied on for years never caught it, so without us they would not have known at all.

At a large commercial property, a fire broke out nearby at half past one in the morning. The platform escalated to building stakeholders automatically and kept feeding the operations center as police and fire arrived, until smoke forced that center to evacuate and a second one took over. Afterward, the customer wrote that without the fire doors closed, they would have been at risk of serious injury or death.

One for anybody worried about false positives: A team was alerted to a man on a public sidewalk with a long gun over his shoulder. It was a prop, and he was headed to a convention. Their head of security had seen a real one before, with a bad outcome, so he would rather be told.

The pattern is that teams reassign attention rather than reduce it.

SecurityInfoWatch: Where do you see physical security heading over the next few years, and what's Ambient.ai building toward?

Khanna: Without looking too far out, the evolution I find most interesting is robotics entering the guard force: drones, ground robots, the four-legged ones, and eventually humanoids.

That matters because the guard force is where physical security spends its money, and where coverage is hardest to scale. A drone can check a perimeter alert in a fraction of the time it takes to walk somebody out there. A ground robot can patrol a garage at three in the morning. Neither gets bored, and neither costs what a permanent post costs.

The catch is that mobility is close to solved and judgment is not. A robot that moves beautifully but cannot reason about what it is seeing is a liability, because you now have an expensive machine standing in front of something it does not understand. That is the same problem we have spent years on with fixed cameras, and it has the same answer: intelligence belongs in the platform, not in the device. A robot is really a camera that moves, with the ability to act.

The operating model I would expect is the agent deciding something that warrants a look, a machine going to look, and a person deciding what to do about it. Same reasoning layer, more eyes, and now legs.

The constraint there is trust rather than capability, and it gets sharper the moment a machine can move, which is why the reasoning has to be legible enough that an operator can see why the system sent something.

AI, Analytics and the Next Generation of Physical Security

SecurityInfoWatch: What makes an AI agent fundamentally different from traditional video analytics?

Khanna: Traditional analytics detect: An object crosses a line, a shape matches a template, motion happens in a zone. They pattern-match against a rule without understanding what they are looking at. Our agent, powered by Ambient Pulsar, our edge-optimized Vision-Language Model (VLM), reasons about the scene itself: who is involved, what is happening, whether it fits that location at that time of day.

Context is the whole thing. Is a person carrying a knife suspicious? In a kitchen, probably not. In a lobby, almost certainly. A rule cannot tell those apart.

That is the difference between a system that flags "motion detected" and one that tells an operator "a person is attempting to force open a side entrance after hours." The operator moves from interpreting raw alerts to reviewing conclusions the agent has already reasoned through.

SecurityInfoWatch: How do you prevent the "needle in the haystack" problem from becoming an AI problem?

Khanna: If you stop at perception, AI just produces noise. Detecting that an object is present is the easy half, and a system that does only that, pointed at more cameras, has not found the needle. It has built a bigger haystack, which is why alert volume goes up after many AI deployments rather than down.

Reasoning is what changes that. It applies something close to human-level understanding of a situation, at machine scale, across every camera at once. Our stack is multi-layered: not just trained to detect objects, but to understand behavior and assess risk. Perception says there is a person in a parking structure. Reasoning says the same person has walked that level three times in ten minutes, tried two door handles, and is not going to a car.

That layering is what lets us sift thousands of events down to the few that are real threats, rather than forwarding all of them with a severity label attached and calling that threat detection. And you can't bolt it on. Without an AI-native architecture, where reasoning is what the platform is organized around, you end up with a detector, a rules engine and a queue.

The measure is not how much a system finds; it is how little it needs to tell you. At ServiceNow, that led to a 94% reduction in false alarms and eliminated just over 15,000 triage hours.

SecurityInfoWatch: Can you walk us through what an investigation looks like now versus before?

Khanna: Before, an operator scrubbed footage camera by camera, by hand, piecing together where a person went and when. Now they describe who they are looking for in plain language through Semantic Search. Matching frames of that person across a five-minute span group into one result, filtered straight to a specific camera. Confirmed clips record directly into a case, and one click generates a fully editable, AI-written narrative with the clips and metadata already organized.

What disappeared is the scrubbing itself, and the separate step of writing the incident up afterward. Both used to eat hours. SentinelOne went from roughly an hour on a forensic investigation to minutes.

My colleague James Connor has a line I keep coming back to: putting a jet engine on a stagecoach is not transformation. The gain here is not that scrubbing got quicker. It is that scrubbing stopped being a step.

SecurityInfoWatch: Where does the human remain firmly in the loop?

Khanna: Agentic does not mean autonomous. The question is never only whether we can automate something; it is whether we should and to what degree, and the answer differs between filtering alarm noise and locking a door.

What we are building augments the operator: the right information at the right time so a better decision gets made. Strip out the noise, automate the work that stops a team from getting to the mission, and leave the judgment where it belongs.

You can see that line in two places. The AI-written case narrative is fully editable by design, because it is a first draft an operator confirms or corrects before it becomes part of the record. An AI-generated narrative reads clean and confident, which is exactly why we build in that editing step, so authority is not confused with accuracy.

The second is response. Consequential actions run on approval: The system assembles the context and proposes the procedure, and an operator signs off before anything executes. The agent does the preparation; the person makes the call.

And there is a second sense of staying in control, which is what the system is permitted to know: no facial recognition, no personally identifiable information used for detection, retention and deletion set by the customer, and every access auditable.

SecurityInfoWatch: If agentic AI becomes the new operating model for physical security, what changes inside the security organization?

Khanna: It is less about fewer people and more about what those people spend time on. Most of an operator's day goes to mechanical work: watching feeds that are mostly uneventful, scrubbing footage after the fact. When an agent takes over continuous monitoring and the first pass on investigations, that time goes to judgment calls, escalation decisions, and proactive risk work.

Three to five years out, I would expect the security operations center to look less like a room full of people watching monitors and more like a team supervising AI- and robotic-augmented operations, stepping in at the moments that genuinely need a human decision.

The harder change is organizational. Automation asks how to make the old process faster; transformation asks why we run it at all, and answering that honestly usually means removing work. It also means somebody inside the enterprise has to own AI decisions the way somebody owns security or IT, because "should we automate this, and to what degree" is not a question a vendor should answer on a customer's behalf.

 

About the Author

Steve Lasky

Steve Lasky

Editorial Director, Editor-in-Chief/Security Technology Executive

Steve Lasky is Editorial Director of the Endeavor Business Media Security Group, which includes SecurityInfoWatch.com, as well as Security Business, Security Technology Executive, and Locksmith Ledger magazines. He is also the host of the SecurityDNA podcast series. Reach him at [email protected].

Sign up for our eNewsletters
Get the latest news and updates