Volume 2
π Secured Podcast
Episode 28 | Silicon Valley Is Coming For Your Lunch Money
The enterprise software crowd is at our door, and most of the industry isn't paying attention. This week on Secured, Lee breaks down who's coming, why the playbook always looks the same, and the one thing these outsiders keep getting wrong about our world. Listen here
π«£ Premium member-only content | Between the Lock and the Lobby
Lee Odess sits down with Phil Kirschner, Author and guide of The Workline, for one of our sharpest conversations yet on the collision between security and hospitality in modern office buildings β a tension the real estate and security industries have quietly avoided for years.
βπ» Articles
Brian Karas | From Entry Control to Risk Control: The Strategic Role of PACS Data
Your access control system may be telling you far more than who opened a door. PACS data can reveal patterns in movement, behavior, occupancy, and risk, but only if we stop treating it as a log and start treating it as intelligence.
Mike Gillespie | The Future of AI in Physical Access Control
AI is changing physical access control, but the biggest shift may not be what we think. From identity verification and predictive security to privacy and the future of the workplace, this article explores what happens when access control becomes more intelligent, connected, and proactive
Dominic Cornell | I Keep Changing My Mind About Flock Cameras
The debate around Flock isn't as simple as good versus bad. This perspective wrestles with privacy, surveillance, misuse, and the responsibility of the security industry itself, ultimately asking a more practical question: who controls the data, how long do they keep it, and what happens next?
Scroll down to go deeper β
![]()
Podcast | Secured: Episode 28
This week on Secured, Lee Odess takes on the outside players showing up at our industry's door. Okta is backing several companies, including Oloid. Then there's Y Combinator-backed OpenVector, plus CreativAI, are pushing in too. And they all follow the same pattern: big total addressable market, a North American problem, a slick solution, and a wild underestimate of how slow and deep-rooted this industry actually is.
Lee loves the outside capital and perspective. He also knows what these folks are about to learn the hard way. Case in point: tailgating. He dug into it with one of the founders this week and told him straight up that the problem has never been about technology. It's culture and habit. Always has been.
We're moving from a cottage industry to a mainstream one. And the old truths won't dictate the new ones.
The question: What are you gonna do about it?

A new feature we're rolling out just for the community. These are the conversations we keep off the public feed: unfiltered, behind-the-scenes, and exclusively for members like you. Find these podcasts ONLY in the 'Conversations with Lee' Channel.
A few things Lee and Phil get into:
- Why the person at the front desk can't realistically be a life-safety guard and an all-day host at the same time
-
What changes when access control stops being a product category and becomes infrastructure
-
The shift from "keep the bad people out" to "let the right people in" β and why that quietly breaks 30 years of how the industry has operated
-
Return-to-office friction, and why security and facilities teams barely talk until a very senior level
-
What a building that leads with curiosity instead of "no" could actually feel like
If you care about the future of work, workplace experience, or where security is headed, this one's worth your time.

Every badge swipe is an atomic data point. A typical mid-sized facility generates tens of thousands of access events a week, each a precise record of who went where, when, and whether the system said yes or no. Most of that data becomes log filler, analyzed only after a crucial event occurs. An extraordinary sensing network about the movement, or intended movements, of people, and we are using it as a dumb turnstile.
That is one of the most overlooked opportunities in physical security today. The Physical Access Control System is usually scoped as an enforcement tool. But the same system that enforces policy is continuously observing behavior. Pattern of life, occupancy, movement, exception rates: it is all already being captured. The only question is whether your security program treats that stream as exhaust or as intelligence.
The shift from entry control to risk control is mostly a shift in posture. Entry control asks a binary question at the door: grant or deny and does nothing with the metadata contained in the answer. Risk control asks what the accumulated answers reveal.
A credential used at two sites 400 miles apart within the same hour. A contractor whose after-hours entries have quietly tripled over a quarter. A cluster of denied reads on one door the week before a resignation. None of these trips is a traditional alarm, because no single event is a violation. The signal lies in the analysis of the aggregate data your PACS system happily generates continuously.
Practitioners already know the canonical anomalies: tailgating, after-hours access, repeated denials, impossible travel. What changes when you treat PACS as an intelligence source and analyze the data in real time is that it stops being incidents you investigate after the fact and becomes indicators you monitor continuously. Badge data becomes a leading signal for insider risk, a corroborating layer for investigations, and an occupancy feed for everything from emergency mustering to real-estate decisions. The data was always there; what is new is the ability to mine it effectively.
This is also where physical and cyber have a reason to talk. Converged, unified security operations are the clear direction of travel, and identity is the connective tissue. A badge-in with no corresponding network login, or a network session from a user the PACS says is nowhere in the building, is the kind of contradiction that neither team can see on its own. Feeding access events into the same correlation layer as endpoint, identity, and network telemetry turns a pile of door logs into a prioritized risk picture and cuts the alert fatigue that comes from watching dozens of disconnected systems.
Even better, realizing this does not require ripping anything out or changing what is already in place. It requires treating PACS data as a managed asset rather than a byproduct: retaining events long enough to establish a baseline, normalizing them so they can be correlated with other sources, and getting them out of the access-control console and into wherever your team actually does analysis. It means defining the questions worth asking: what does normal look like for this population, this door, this hour? Doing this before an incident forces the question, which already puts you miles ahead.
Vendors are moving this way, slowly. Analytics, behavioral baselining, and AI-assisted anomaly detection are mostly arriving outside of PACS platforms and in other tools. But tooling is not a strategy. The differentiator is whether a security leader has decided that accessing data is part of the organization's risk intelligence, or whether it remains a log that exists only to be subpoenaed after the fact.
The door is one of the most disciplined sensors most organizations own. It is deployed everywhere people are, it runs continuously, and it ties every observation to an identity. It is time to stop asking only one question. The teams that make that shift will not be buying a new capability so much as finally using one they have paid for all along.... continue reading here β

Artificial intelligence is transforming physical access control from a simple security function into an intelligent, proactive system. Traditionally, organisations have relied on keys, access cards, PINs, and security personnel to manage entry to buildings and restricted areas. While effective, these methods can be inefficient, vulnerable to misuse, and administratively burdensome. AI is changing that by making access control smarter, faster, and more responsive to risk.
The broader trend is clear. According to McKinsey's latest global AI research, 88% of organisations now use AI in at least one business function, up from 78% the previous year, demonstrating how quickly AI is becoming embedded in business operations. As organisations become more comfortable with AI, physical security and access control are emerging as key areas for innovation.
Intelligent Identity Verification
One of the most significant changes is the shift from credential-based authentication to identity-based authentication. Physical credentials such as cards and fobs can be lost, stolen, or shared. AI-powered biometrics offer a more secure alternative by verifying the person rather than the credential.
Technologies such as facial recognition, iris scanning, and behavioural analytics are becoming increasingly accurate, enabling users to gain access without presenting a physical badge. Future systems will combine multiple authentication factors, including biometrics, location, and behavioural patterns, to create more secure and reliable identity verification.
This evolution is already influencing product development, with manufacturers introducing AI-enabled access control devices that combine facial recognition, visual analytics, and multi-factor authentication into a single platform.
Predictive Security and Threat Detection
Traditional access control systems record events and generate alerts after an incident occurs. AI enables a more proactive approach by continuously analysing access activity, video feeds, and occupancy data to identify unusual behaviour.
For example, if an employee attempts to access an unfamiliar area or enters a building at an unusual time, AI can flag the activity for review or even present real-time alerting. By learning normal patterns of behaviour, machine learning models can identify anomalies, detect credential misuse, and help uncover insider threats before they become serious incidents.
Industry experts are increasingly highlighting how behavioural analytics and AI-driven monitoring are enabling security teams to focus on genuine threats rather than reviewing thousands of routine events.
Frictionless User Experiences
As workplaces become increasingly digital, users expect security systems to be seamless. AI-powered access control is reducing friction by enabling touchless, automated entry through mobile credentials and biometric authentication.
Employees may simply walk towards an entrance, with AI verifying their identity in real time and granting access automatically whilst also detecting and denying tailgating attempts. This not only improves convenience but also reduces queues, streamlines visitor management, and enhances the overall workplace experience.
In smart buildings, AI may also dynamically adjust permissions based on schedules, meetings, and operational requirements, ensuring users have access to the right areas at the right time.
Smarter Integration Across Security Systems
The future of access control lies in integration. AI is increasingly connecting access control systems with video surveillance, intrusion detection, building management, and cybersecurity platforms.
This convergence enables a more comprehensive view of security events. An unauthorised access attempt, for example, could automatically trigger video analysis, notify security teams, and initiate predefined response procedures. Access decisions may even be influenced by cyber-risk data, linking physical and digital security strategies for stronger protection.
The market itself reflects this shift. Analysts forecast the global physical access control market to grow from approximately $11.8 billion in 2026 to more than $21 billion by 2033, driven in part by the growing use of AI, automation, analytics, and cloud-based security solutions.
Privacy and Ethical Considerations
While AI offers significant benefits, its use also raises important privacy and regulatory considerations. Biometric data is highly sensitive, requiring organisations to implement strong governance, secure storage, and transparent policies regarding its use.
As adoption increases, organisations must ensure AI systems remain accurate, fair, and free from bias. Human oversight and compliance with evolving regulations will remain essential to maintaining trust in AI-driven security solutions.
To help mitigate this, it is likely that there will be a greater uptake of AI standards such as ISO42001, ISO23894 and the NIST AI Risk Management Framework.
Looking Ahead
Over the next decade, AI will transform access control from a system that simply opens doors into one that understands identities, anticipates risks, and supports smarter decision-making. Organisations that embrace these technologies will benefit from enhanced security, improved operational efficiency, and better user experiences.
The buildings of the future will do far more than manage entry. They will use AI to recognise individuals, detect threats, adapt to changing circumstances, and create safer, more intelligent environments for everyone who enters. As AI adoption continues to accelerate across industries, intelligent access control will move from being a competitive advantage to becoming a standard expectation within modern security programmes.
References
- The State of AI 2025: Agents, Innovation
- McKinsey's 2025 AI Adoption Survey: 88% of Organizations Use AI β But Only 39% See Real Profit Impact | European Purpose
- AI in Physical Security Market: Current Analysis and Forecast (2025β2033)
- AI in Physical Access Control Market Size, Share & Forecast Report, 2033
- AI in Physical Security: What Is Actually Changing | Security Industry Association
- How Artificial Intelligence Is Reshaping The Physical Security Industry | Security.World
- Physical Access Control Market Forecast, 2026β2033

I don't have a clean position on Flock. I've had about four of them in the last two years, and I'm not confident the current one survives the next news cycle. So instead of pretending I've got this figured out, I'm going to walk you through what my brain actually does with this topic.
My first real exposure wasn't a demo. It was the reporting that officers were running plates for personal reasons, checking on exes, tracking people with no warrant and no case. That's damning. I'm not going to soften it.
But then the part of my brain that's been in this industry too long speaks up: we do this to ourselves constantly.
In 2020, an ADT technician right here in the Dallas area was caught adding his own email address to customers' Pulse accounts during installs. He accessed roughly 200 households more than 9,600 times over four and a half years. He noted which homes had attractive women. He got 52 months in federal prison. And ADT didn't catch him. A customer did, by noticing an email address that shouldn't have been on the account.
That wasn't a policy failure at some police department. That was one of us. A trained, badged, background-checked technician from the biggest name in residential security. And nobody responded by declaring home cameras illegitimate. We said the access controls were garbage and the audit logging didn't exist, and we fixed it.
So when the misuse argument gets aimed at Flock, I have to ask whether we're applying a standard we've never once applied to ourselves.
Then came round two: people cutting the cameras down. Sawing poles in New York, throwing paint in Oakland, driving a truck into one in Idaho. And I understand the impulse. Nobody voted for a camera on their corner.
But look at the same people's actual behavior. About a third of Americans keep an always-listening microphone on the kitchen counter and gave it a friendly name. We all carry a device whose location history is valuable enough that an entire industry exists to buy and resell it. We walk into a grocery store under a dozen cameras and never think about it. We hand a retailer our phone number for four percent off.
We didn't lose our privacy to Flock. We sold it, cheap, for convenience, years ago, and nobody sawed anything down over it.
Which makes me wonder whether Flock is less a threat than a target. A physical, visible, hateable object standing in for something that already happened to us invisibly and with our consent.
And here's where I catch myself thinking something I don't fully trust: if you're that afraid of being tracked, what is it you're doing?
I don't like that thought. It's the lazy version, and I know it's lazy, because I've got a direct counterexample.
I lived through COVID. I watched what happened in California. Officers enforced orders that made no sense to anyone. They arrested a guy paddleboarding alone in the ocean, broke up gatherings, shut down businesses that were doing nothing dangerous. Not because those officers were bad people. Because they were handed a directive, and the job is to execute the directive.
That's the part that stays with me. The question was never whether the individual officer was decent. It's whether individual decency is the only thing standing between you and an order.
Now put a nationwide plate-reading network into that scenario. Not a hypothetical one. Flock's own count is north of 120,000 cameras, billions of reads a month, agencies sharing across a national network by default unless somebody deliberately turns it off. In 2020, enforcement was limited by manpower. What happens the next time, when it isn't?
I don't think Flock built this to be a lockdown enforcement tool. I don't think that's anyone's intent. It doesn't matter. Tools outlive the intentions of the people who install them, and they get inherited by whoever holds the office next.
So where does that leave me? Somewhere uncomfortable, and I think that's the honest place to be.
Here's the part that matters for us specifically: we install these things. Not the city council, not the ACLU, not the guy with the reciprocating saw. Us. Whatever gets deployed gets deployed by an integrator, under terms somebody wrote and somebody else signed without reading.
LAPD is the tell. They announced they were done with Flock, then resigned about a week later with department ownership of all data, no distribution to third parties, and no use of their data for AI training.
The technology wasn't the thing that changed. The contract was.
I still don't know if Flock is good or bad. I've stopped expecting to land there. But I've gotten a lot more interested in who holds the data, for how long, who they're allowed to hand it to, and who's reading the audit logs. Those are questions I can actually answer for a client. And they're the ones that decide which version of this we end up living in.
Sources for the claims above, if you want to link them: DOJ Northern District of Texas press release on U.S. v. Telesforo Aviles (Jan 2021) and CBS DFW on his sentencing (June 2021); NPR/Edison Research on smart speaker ownership; CNN (July 30, 2026) on camera vandalism; Fortune (July 15, 2026) on the LAPD renegotiation; Flock Safety's published camera count.
π As Seen In the Secured Community π
π€ AI & Tech
-
Salvatore DβAgostino shared
-How big AI players wants to set governance framework
-Cloudfare Gives AI Agents an Identity and a Wallet
π Research
-
Daniel Raines shared
What started out as a research project has now turned into an integration... Net2 USB Desktop reader, where a client wanted to use it as part of some custom software but where Net2 client was not installed on that machine. This offers a direct connection via USB to read various cards...
(Review and respond to Daniel's project in the 'Research' Channel!)
π€ Industry News & Insights
π Shameless Plugs
-
Jonathan Horvath shared
Z-bit Systems is officially releasing an embedded OSDP library for PDs. The goal is to reduce the costs and effort needed to produce security devices. The adoption of standards by the security industry provides an opportunity to reduce complexity.
πΌ Jobs & Opportunities
-
Lee Odess shared
ISC just opened a new Event Manager role focused on growing Digital Trust & Identity, Cyber/IOT, Emerging Tech, and Startups within the show. - Tom Wilburn shared
We have 2 open roles in our HID PACS Europe Presales Engineering team. One for a Mobile Access Sales Engineer based in the UK & another for PACS Sales Engineer covering the Benelux region. Please feel free to forward the below links if you have any suitable candidates or DM me if you have questions or want to apply.
π¬ Community & Random
- Hailey Canady shared
The trades are having a moment. Physical security should be next. - Roberto Licari shared
In few weeks ONVIF will have its annual meeting with all the registered members and one of the topic in our agenda this autumn is to discuss about Open Standards in the Access Control market. If anyone in this community would like to send me a specific question/provocation that I can use in the event/conversation/discussion we will have, I will be happy to share the comments/results after that.
(Respond to Roberto in the 'Community & Random' Channel!)
π‘ Consulting
- Dominic Cornell shared
What are your thoughts on Data Center canonical drawings?
(Reply to Dominic's Poll in the 'Consulting' Channel!)
ποΈ CPTED
- Chris Wilson shared

ACS26, The Access Control Summit, is heading to New Zealand in 2026 October 6 & 7th, hosted in collaboration with our city-host, Gallagher Security. Registration is OPEN NOW! Sign up here.
Speaking at the event? Go here.
On the fence? View some testimonials from previous years here.
![]()
Secured Presents: XPod from The Security Event
We asked everyone the same four questions. What came back was not a recap. It was a read on where the industry actually is, told through the people doing the work.
All stories:
Intro: What We heard at TSE
Episode 1: Identity Is The Center, Hardware Is The Floor.
Episode 2: Regulation Is Not the Tax. It Is the Moat.
Episode 3 β The Mainstream Moment Is Real, But It Is Not Singular.
You can stream directly from our Secured channel.

West to East series: We're looking back on 45 conversations with leaders from across the industry. Each episode offers a different perspective on the ideas, challenges, and opportunities shaping security today. You can stream all episodes right from our Secured channel.
π£οΈ Your Voice Matters.
Share your feedback, suggest topics, and tell us what questions we should be answering. Help us shape future issues and contribute to the conversations that move the industry forward.