An AI that watches your every click may be the future of work | E2314
Monday, 20 July 2026 · 4 min read · Listen to the episode ↗
INT emerged from stealth with a 100 million dollar raise to tackle a problem the security industry has largely ignored: stopping human-caused policy violations before they happen rather than responding after a breach. The startup deploys an on-device agent on laptops and phones that intervenes in sub-second time frames without GPUs, targeting both the roughly one percent of malicious insiders and the ninety-nine percent who cause harm accidentally.
INT is a startup that emerged from stealth with a 100 million dollar raise, founded by Brandon Dixon, focused on preventing human-caused security violations inside enterprises in real time. Rather than building reactive breach-response tools, INT deploys an on-device agent on laptops and phones that assesses whether a user is about to violate corporate policy and stops the action before it occurs, operating in sub-second time frames without requiring GPUs.
Dixon argues that most breaches originate from well-intentioned employees making mistakes rather than malicious insiders, and that the security industry has largely abandoned prevention in favor of response. INT is designed to address both the roughly one percent of bad actors and the roughly ninety-nine percent who cause harm accidentally, covering vectors such as emailing financial data to the wrong recipient or sharing credentials in chat systems.
The rise of AI tools in the enterprise has created a new category of risk that INT is specifically built to address. Non-technical employees encouraged by leadership to use AI, which Dixon calls citizen developers, risk accidentally deleting artifacts, pulling in sensitive context, and leaking it outside the corporation. Developers running twenty or more agents simultaneously across an enterprise face similar data leakage risks. The host noted that he personally began using PowerShell and CLI tools only after gaining access to AI coding tools, illustrating concretely how AI expands non-expert capability and the associated attack surface.
The technical foundation that makes INT viable today is advances in embeddings, which translate semantic meaning into machine-readable representations. INT uses open embedding models it has modified and optimized internally, controls the embedding process rather than relying on third-party cloud providers, and runs those models on CPUs. Deployment begins with a baseline observation period of approximately two weeks to establish normal versus abnormal behavior for individual users, departments, and peer cohorts before any intervention occurs. The system also surfaces which policy violations a company genuinely intends to enforce, since corporate policies often contain rules such as prohibitions on social media that organizations do not actually act on.
INT is positioned to augment rather than replace existing endpoint detection and response tools, which Dixon described as a commodity with most enterprises already having a solution in place. The company targets Global 2000 and above enterprises and decided not to depend on any other security product for telemetry in order to remain preventative and make decisions quickly. Data sovereignty concerns drove INT to offer a self-hosting option, allowing the product to be deployed entirely within the customer's own environment so the vendor does not see the data. The platform supports one-click deployment inside major cloud environments operated by the customer, configurable toggles for every data type collected, and role-based access controls restricting which internal parties can view sensitive data such as screenshots.
Beyond cybersecurity, the behavioral data INT collects creates what Dixon described as a semantic substrate for organizational observability. The same data can accelerate closing true positive benign tickets in the security operations center, surface insider risk, identify employees who need training, and pinpoint work that AI agents could take over. Dixon used the analogy of world models in autonomous vehicles, which improved self-driving accuracy by enabling prediction rather than rule-based responses, to describe the concept of an organization work model. The host noted that once such a system captures how a company works it could identify inefficiencies and recommend process improvements well beyond cyber safety, and Dixon predicted that work ops will become a large category. Employee and enterprise norms around this level of granular observation are still being determined, and the host pointed to Meta's unpopular push to closely monitor engineer activity as an illustration of the resistance such products can face.
Sumay Labs, represented by founder David, built an API that routes across five or six video, image, and audio generation models and stitches together clips to produce videos up to 60 seconds long, addressing the fact that individual models cap at roughly 15 to 30 seconds. The user-facing workflow reduces complexity to selecting an avatar and writing a script, targeting the UGC video ad space with brands and direct-to-consumer marketers on Instagram and TikTok as the primary audience. The company currently has 20,000 users with approximately 90 percent of paying customers being brands, and the six-month goal is a fully autonomous video agent that generates marketing videos end to end without human input.
This summary was generated from the episode transcript and can contain mistakes.