Ledger Wallet™ just got another major upgrade

Take control today

EP - 117

Securing AI Agents: Hardware Trust in an Agentic World

with

Leonard Lin & Ian Rogers
Founder @ Shisa.ai & Chief Human Agency Officer @ ledger

Jun 25, 2026

On this episode of The Ledger Podcast, Ledger Chief Human Agency Officer Ian Rogers sits down with Leonard Lin, founder of Tokyo-based AI startup Shisa.ai, to explore one of the most pressing challenges at the intersection of AI and security: how do you make an AI agent safe to use? 

Leonard walks through the origins of Shisa.ai, his journey training state-of-the-art Japanese language models, and how his work building a secure agentic framework, Shisa D, led him to integrate Ledger hardware signers as a critical layer of human verification. The conversation serves to show why the default posture of today’s most powerful AI agents is deeply insecure, and what it takes to build something different.

“LLMs are insecure. They can always be injected into, or basically attacked. They don’t fundamentally see a difference between data and instructions. So that’s a real problem.” – Leonard Lin

Watch the full episode below:

Key Highlights:

From Open Source to the Cutting Edge: The Origins of Shisa.ai

Leonard Lin didn’t set out to build a company. When Meta’s Llama model leaked to the open-source community, Leonard, who was already immersed in stable diffusion experiments, was drawn in. He noticed something immediately: while English-language open models were advancing rapidly, Japanese and other non-English models were far behind, and the reason was surprisingly simple. 

“The open models are really bad because the data is bad,” he explains. “It’s garbage in, garbage out.” 

Rather than fine-tuning on existing poor-quality datasets, Leonard and his co-founders threw them out entirely and generated their own synthetic training data from scratch. The process took just four weeks but produced a 7-billion-parameter Japanese model that outperformed much larger 70B models on key benchmarks. 

That model became the backbone for Sakana AI’s first evolutionary model merging work, and Shisa.ai was formally born. Today, the company has expanded into real-time audio and translation, with sub-100ms latency capabilities and a consumer app, Chotto Chat, available on iOS and Android.

The Productivity Revolution: AI as an Orchestration Problem

Leonard’s approach to working with AI agents is something Ian Rogers calls his “productivity ideal.” Running roughly a billion tokens a day across a dozen simultaneous projects, Leonard has reorganized his entire workflow around agentic loops. The key insight he’s arrived at is architectural: humans should operate “end to end,” meaning they generate the idea and validate the output, while AI agents operate “middle to middle,” doing the execution in between. 

This framing shapes everything about how Shisa D is designed. Developers and knowledge workers, he believes, are rapidly becoming orchestrators of agents rather than direct executors of tasks. But this power comes with a critical caveat: 

“You can outsource your coding, you can outsource your thinking even to some degree, but you can’t outsource your understanding.”

The Lethal Trifecta: Why Today’s AI Agents Are Structurally Insecure

The central problem Shisa D was built to solve is fundamental to how large language models work. Unlike traditional software, which maintains a strict separation between data and executable instructions, LLMs treat everything as a single undifferentiated stream of context. “If data is treated as an instruction, anything you read could then tell it to do stuff,” Leonard explains. This makes every capable AI agent a potential target for prompt injection attacks

Ian Rogers distills the danger into a concrete example he calls the “lethal trifecta”: an agent that can read your email, send your email, and search the web simultaneously creates a chain reaction where a single malicious email can issue commands that exfiltrate sensitive information or take harmful actions, all without the user ever knowing. And unlike traditional software vulnerabilities, this isn’t a bug that can be patched. It’s a structural property of how LLMs reason. The more capable the agent, the more dangerous the exposure.

Shisa D: Secure by Design, Not Secure by Default-Off

Most attempts to secure AI agents default to the same approach: restrict what the agent can do. Leonard argues this is both ineffective and self-defeating. If you make secure software too cumbersome to use, people simply choose the insecure alternative. 

Shisa D’s philosophy inverts this: rather than piling on restrictions, it focuses on making the secure path the easy path. At its core, Shisa D adopts a posture of structural distrust toward the AI itself; The agent can propose actions, but it cannot unilaterally execute them. The framework currently includes around 300 security primitives, covering everything from memory lifecycle management (handling contradictions and updates to what the agent “knows”) to proxy systems that ensure the agent never directly handles passwords or secrets. It also actively defends against invisible attacks, such as prompt injection hidden inside Unicode control characters that render normally in a text editor but carry malicious instructions to an LLM.

Hardware Enforces What Software Cannot: Ledger Integration in Shisa D

The highest tier of Shisa D’s security architecture is where Ledger hardware enters the picture. Leonard describes a multi-level approval system: routine actions can be confirmed through chat, more sensitive actions require two-factor hardware authentication, and the top level—triggered for any action the user has designated as high-stakes—requires explicit approval on a Ledger signer’s secure screen. This matters because, as both Leonard and Ian emphasize, software confirmation mechanisms can be circumvented. 

An LLM that encounters a block will actively try to route around it. A hardware root of trust changes the equation entirely. Shisa D now supports Level 4 screen integration, meaning when an action requiring human approval is triggered, the exact command is displayed in plain text on the Ledger signer’s screen for the user to hold-to-sign or reject.

The Broader Vision: Ledger as an Authenticator Beyond Crypto

One of the most significant takeaways from this episode is what the Shisa D integration reveals about Ledger’s evolving role as a hardware authenticator for AI-generated actions. Ian describes Ledger’s Device Management Kit, recently overhauled to handle application loading and unloading automatically for a smoother developer experience, and notes that it’s now been wrapped as a skill so any coding agent can add Ledger signing to an application.

 The underlying principle is the same one that has driven Ledger’s security philosophy from the start: trusted display, hardware root of trust, and human consent at every critical decision point. In an agentic world where software can be manipulated and screens can be faked, physical hardware verification may be the only guarantee that holds

Key Predictions for 2026 and Beyond

Leonard Lin

  • Future knowledge workers will primarily function as orchestrators of AI agents, not direct executors of tasks.
  • Spec and test-driven development will become the dominant workflow for software engineers using LLMs, replacing line-by-line code review.
  • Real-time AI translation (under 100ms latency) will unlock a new category of consumer experiences, particularly for live events and cross-language communication.
  • The hardest unsolved problem in agentic AI is the risk/capability trade-off. No framework has yet found the right balance between what agents can do and what they should be allowed to do autonomously.   

Stay in touch

Announcements can be found in our blog. Press contact:
[email protected]

Subscribe to our
newsletter

New coins supported, blog updates and exclusive offers directly in your inbox


Your email address will only be used to send you our newsletter, as well as updates and offers. You can unsubscribe at any time using the link included in the newsletter. Learn more about how we manage your data and your rights.