As AI-driven systems become central to business operations, controlling access to their data, models, and actions has become mission-critical. With decisions increasingly automated, unauthorized or unchecked access can lead to compliance violations, data breaches, and ethical pitfalls.
Modern approaches to access control—such as policy-based authorization, zero-trust architectures, and dynamic access enforcement—are redefining how AI pipelines should be secured. Fine-grained controls tailored to AI workflows offer organizations a way to enforce accountability, transparency, and resilience.
Alexei Balaganski, Lead Analyst & CTO at KuppingerCole will explore the broader landscape of AI-based architectures, including current risks in AI model exposure, evolving regulatory expectations, and the intersection of IAM and AI ethics. He will discuss aligning identity, access, and policy layers to secure intelligent systems properly.
Gal Helemski, Co-founder & CPO at PlainID will demonstrate how policy-based access control enables organizations to manage AI agent permissions dynamically. Drawing from real-world implementations, she will share insights into securing datasets, APIs, and decision points while ensuring compliance and business agility.
Well, hello and welcome to another KuppingerCole webinar. My name is Alexei Balaganski, I'm the lead analyst at KuppingerCole, and my guest for today is Gal Helemski, who is the co-founder and chief product officer at PlainID.
Welcome, Gal. Thank you, and happy to be here. Looking forward to speaking about this very interesting topic. Absolutely, and the topic for today is, of course, Brains Need Boundaries, Stay in Control of Agentic AI with Access Control Policies. But before we jump into the webinar, we have to talk about some housekeeping rules.
So, first of all, all the attendees are muted, so you don't have to worry about microphones. We will run a couple of polls during the webinar, and we will discuss the results probably by the end of the webinar. There is a possibility for you to ask questions, you can do it at any time using the questions panel on the right of your screen. We will probably postpone answering those questions until the last part of the webinar, but who knows, maybe we can pick it up and discuss it immediately.
The whole webinar will be recorded, and the recording along with the slide deck will be available on our website probably tomorrow. You will all get a notification about it.
So, what are we talking about today? We are talking about trends, risks, and expectations for the future development of AI systems.
And, of course, we will specifically focus on security, compliance, and business agility of those. This is not our usual structured webinar, where we will kind of, first I would go and then another speaker would follow.
No, it should be an interactive discussion. So, we will just kind of go back and forth exchanging our opinions.
But still, we have some time reserved at the end for your questions. So, first of all, like, why the title? Why do brains need boundaries? When we came up with this idea, we thought it's kind of witty and thought-provoking, but in reality, it's actually a pretty solid topic, a very well-established topic in the human psychology as well, because human brains need boundaries as well for actually very similar reasons to the AI brains. We need boundaries.
We need some either self-imposed or externally imposed rules on the way we think and act to prevent cognitive overload, to basically focus and function properly and efficiently, to regulate our emotional state, and, of course, to make independent choices and resist external manipulation. In a sense, the same rules apply to those AI brains, the agentic systems, if you will. Those will have an increasing degree of autonomy, so they will be able to not just think and make decisions, but also act and implement those decisions without human intervention.
And it's extremely important that their goals are well human schools, that there are no conflicts, and their autonomy is controlled and restricted in a way to prevent misuse and catastrophes. So, before we jump into the actual discussion, a quick poll. What are your plans? Do you already know something about agentic AI? Do you have any strategies in or maybe you already started or maybe even finished your AI agent implementation?
So, we will just kind of give you a minute or two to think about the answer. So, Gal, what's actually your own experience with agentic AI? Have you actually seen them in action already? Do you have personal experiences?
Yes, absolutely. I see that they are already at play with many of organizations. I do see many of our current customers implementing or thinking to implement agentic AI or, you know, the basic AI systems to support their business. Some are thinking about that on a per-use case, like supply chain. That's a very common one. But others are taking that to on a larger scale. They are actually customers who are building an infrastructure, internal infrastructure, that would enable the build and usage of AI agents internally.
I think that's a very cool idea because it's like preparing everything you need in order to enable that type of usage. And I'm really looking forward to see how that evolves. Right.
Well, kind of from my perspective, which is, of course, by definition, more theoretical and more high level as an analyst, I absolutely see everybody who actually tried AI agents in action would love to have more of them. And this is exactly why we are focusing on this topic today, because even today, we have way too many, quote unquote, non-human identities working for us. And this number will only grow exponentially in the future.
And again, kind of we have to think that every non-human thing, that agentic system, which would act on our behalf, it actually isn't supposed to replace us in our job. It's supposed to work on our behalf. And this is extremely important to understand that we will still be responsible for their actions. And this is why having a strategy regarding agentic AI, even if you don't even have concrete plans or use cases, you have to at least start thinking about it today and know that the thing is coming. It's inevitable.
Even if it's just a fed in your specific industry or your specific company, you will face it with your partners, with your customers, with whatever companies you operate together. So AI revolution, if you will, AI agentic revolution is inevitable and it's up to you to be prepared for it.
So yeah, looking at the results of our poll, you can see that almost half of our attendees are actually already planning or at least considering something about it. But very few have already started and a whole third of our attendees do not have any plans yet. Let's hope that by the end of this webinar, you will change your mind and understand the urgency. Can you please close the poll?
Okay, so this is the slide which I could have liked to start almost every of my webinars. What a time to be alive. There is so much happening around us in the world and not just in IT. Unfortunately, all those developments, even the positive ones, to say nothing about the negatives, end up creating a profoundly insecure world for us to live in. Just because everything is so hyperconnected, always online, multi-cloud, increasingly mobile and outsourced to a managed service provider. There is so much happening, there is so much data flowing around the world at the speed of light.
We are losing this control more and more and of course adding generative AI was probably the last straw in this development. Because everybody wants to generate AI tools because they're so convenient and useful and easy to get into. But lack of control leads to massive risks and a lot of those risks are already turning out into real attacks and data breaches and of course sooner or later to compliance violations. And we hear a lot of experts saying that the traditional security tools cannot stop those attacks and cannot prevent those risks, but can they really?
And of course, agentic AI is the next frontier, is the latest fad, if you will. Now we don't have just brains, we have brains on steroids, we have brains with actuators, things, the artificial intelligences, which can now directly operate our existing IT systems or even physical world systems. And it's up to us basically to make sure that the Skynet scenario doesn't turn out to be true and that we stay in control of all those non-human identities working for us.
Right, so when we are talking about artificial intelligence we have to think about it in many stages. It all started decades ago probably in the mid-20th century, largely academic, but for the general public, the real AI revolution started with CGPT, Islamic Large Language Models, which finally were able to actually help us do our job, summarize our meetings, write emails, create reports, answer questions, and so on. It was just a few years ago, I mean, who remembers when CGPT was first announced?
I don't, it seems so long ago, but it was actually just a few years behind. But those AIs are things of the past, if you will. Nobody cares about smart brains living in an ivory tower, now it's all about working with business information and context. This is where REC architectures have appeared, Retrieval Augmented Generation, where you would feed an LLM with your own sensitive data and let it make summaries, decisions, answer questions, based specifically on your data.
This is where AI developments actually started to make sense for businesses, and this is what has recently evolved into real agentic systems. And the whole point of an agentic system is that they not just can answer your questions, but they can actually do your work directly through a set of actuators, connections, interfaces to existing IT systems. And by the way, we should not forget that an AI agent is by definition a system that can understand its environment, make decisions, and act autonomously to achieve a specific goal. For example, a self-driving car is an AI agent.
There is, however, a different definition which says an AI or an agentic AI system is not the same as an AI agent. It's a broader term that says any AI-based system designed with agent-like properties. It also includes autonomy, co-directed behavior, it has the capacity of planning, adaptation, and learning, and they often exhibit much more complex behaviors as standalone AI agents because they can actually initiate tasks independently, and they can keep the memory of the things they have achieved, their past goals, and adapt and change their future goals based on that history.
And they can freely interact with users, IT systems, and other agents. So what we have to keep in mind during this webinar and later is that when we are talking about agents, we're actually thinking about agentic systems, which is a much more sophisticated and complex ecosystem. And the term agentic basically reflects this intentionality and initiative. So it's no longer just a robot which helps you do your laundry or dishwashing. It's a robot which can decide suddenly without you asking it to do something.
To do that for you, and it's up to you to make sure that that robot not only understands your agency properly, but it also has very firm boundaries in place to prevent them to do something which you would think responsible, something catastrophic. Again, kind of thinking about Skynet scenarios, Terminator movies, and so on. It was like a running gag in the industry for decades, but we are actually quickly approaching the possibilities where this is almost possible.
Again, the more actuators an AI agent has to influence the physical world around them, the more boundaries they have, they need to have in place. Now let's talk about the AI system lifecycle.
I mean, we have heard a lot whenever somebody is about the risks of AI systems, they would inevitably talk about stuff like data poisoning, and bias, and lack of transparency, and so on. But is it really something which you see as a challenge for, quote-unquote, us mere mortals, and not the companies like OpenAI, who are actually developing their own models? Where do you see the primary, which phase of this AI lifecycle we should focus on as normal companies, normal organizations?
Yeah, so I think all part of the lifecycle are important to consider, but starting with design and planning. That's where you would consider security as part of that planning. I think we would review that fairly several times within this webinar, that the concept, the security concepts that are known up until now also apply to AI systems or agentic AI. There aren't any new concepts to apply. So we are just going to repeat them with the emphasis on this type of technology. So you would start always with design and planning, and that's where security needs to be considered.
Security needs to be part of the design process, part of the planning process, all security controls, because eventually you want your agentic AI system to be built right. And that means with security in mind to begin with. And then when we are looking at data collection and preparation, obviously data security is a big topic. Even before AI, it was a big topic.
With AI, it's even a bigger topic. So that's another part where you need to implement those best practices as part of this new implementation. And it goes all the way through the cycle to utilize the well-known practices in security. It never ends. As you know, security starts with planning, but goes all the way through the cycle to support eventually the secured product, to keep in mind the protection of your most valuable assets, which are basically the data, all the data which will be accessible through the agentic AI and the operations the system would be able to perform.
Do you agree that's the way to look at that? Well, that was very well said. I can absolutely get behind this statement.
However, I want to add one important consideration for our listeners. Whenever people would be talking about the AI system lifecycle and looking at a diagram similar to this one, they would inevitably kind of consider that it's their own responsibility for the entire lifecycle. In real life, it usually isn't. Just like with cloud, for example, we have sooner or later figured out the shared responsibility model where the cloud provider takes over some of those responsibilities and you as a customer care for the rest. The same should apply to AI systems too.
For example, unless you are a large company with your own team of data scientists and AI experts, you'll probably never design or train your own large language model. You would probably use one from a third other. While all these phases are equally important in theory, your own responsibility lies in some parts with much higher risks.
Obviously, you are primarily responsible for securing your data, as you just mentioned. You will be probably deploying the model in your infrastructure and integrating it. That's another huge attack surface to manage.
Of course, you will be operating the model. You will be asking questions. You will be using it for inference. This is where you should focus most of your developments.
Again, yes, somebody is going to design your agentic system, but it's not the same as designing the LLM itself. That LLM will probably come pre-packaged. You might spend some effort fine-tuning it, but this is not where you should focus your attention. You should focus your attention, again, on ensuring that the model interacts with the rest of your IT and the rest of your business, infrastructure, security, and in a very properly governed and compliant manner. This is why I have highlighted governance and compliance as kind of a meta step, which actually should permeate the entire life cycle.
It's not a standalone phase at all. Right, so whenever we are talking about AI, we talk about great stuff you can achieve, but we have to consider a lot of risks as well. On this slide, I try to summarize the risks which are not only related to security, but kind of a higher level of concepts like truth and trust, privacy and compliance, ethics and fairness.
So yes, misinformation, deepfakes, for example, this is a hugely important topic. Everybody is talking about them. Unfortunately, I don't think there is a lot of working solutions to actually tackle deepfakes.
So yeah, this is something we have to think about for the future. And hopefully, the industry and the states will come up with some regulations around that. But we have to focus less on those things and more on things we actually can solve today. And I would argue those are, of course, security, privacy, and compliance are the primary areas where we have to focus our efforts, because the worst thing you can actually do with your existing AI system or genetic AI system is loss of oversight.
Again, don't forget that loss of oversight for an agentic AI system doesn't just mean that your data will be leaking, but the agency of that system, the intentions and goals will be in stark conflict with your business's goals. And it's up to you to prevent that catastrophic results. It will be much worse than ransomware attack. If an AI with malicious intentions can have full uncontrolled access to the entirety of your IT, it will be a much more catastrophic scenario than any large-scale ransomware attack. And it will be something which you cannot quote-unquote prevent with traditional tools.
You cannot stop it with an antivirus or a firewall, because again, an agentic AI is acting on your behalf. It's probably with your credentials, or at least with an identity handled to it by legitimate owners. And it's up to you to ensure that identity only gets the privileges and options to act in a way that you expected to do it. We cannot talk about AI compliance and AI governance without mentioning the EU AI Act, which is basically the first attempt to regulate artificial intelligence. I don't know about you but I'm a little bit skeptical.
You know how they say, while Americans innovate, the Europeans regulate. It's like regulating things which you don't yet have in place. A little bit ridiculous. On the other hand, it's great to see that at least some people are already thinking about the future potential consequences of those uncontrolled AI applications. And it's good to know that at least there is some kind of challenge, some kind of penalty for people violating this and not doing a proper risk-based assessment of their AI systems. Do we want to go into some more details discussing this? Do you?
Yeah, no, I think we brought this as an example. And this is just one example, of course, this speaks of regulation, but we'll bring more examples moving forward of the importance to consider security controls throughout the AI development, and then later on the usage process. The highlight eventually we want to focus on, at least I want to focus on, is access controls and authorizations. And it repeats itself throughout regulation proposals and other papers which discuss security for AI, that this is one of the top priorities to consider. There are security risks with AI systems.
I think we all understand that. That's why we're part of this webinar. There are regulations that are trying to put some definitions and boundaries on top of that. But all of them, all of them consistently speak about the risks involved and where you should put your focus. And authorizations, access control, the challenge with data exposure, that's one of the top priorities that keeps kind of repeating itself over and over again. So this is one of the examples to look at.
One thing I actually wanted to mention is that, as you can see, it's clearly highlighted in the regulation that it's all about risk-based classification. There are some minimally risky systems like games or chatbots or whatnot. Those do not have the requirement to be strongly controlled and security regulated. But you have to understand that risks change all the time. Architectures change all the time and regulations change all the time. So you cannot start by different solutions for different kinds of risky systems.
You cannot say, hey, yeah, I will build one security stack to address the critical sectors and high-risk AI systems and a completely different set of tools for the rest of it. It will never work. The whole point is to communicate to every current and future subject to this regulation that you have to be agile. And I believe, in the end, the only way to achieve this agility is to make sure that your security and risk management is policy-based. And if the regulations change, you just make a change in your policies. You don't have to rebuild everything from scratch.
That's kind of my big takeaway from this slide. So yes, we are coming closer to the meat of our webinar. It's all about access control and authorization.
And yes, AI systems have some additional challenges. So can you maybe talk a little bit more about that?
Yeah, absolutely. I agree with you. And it kind of continues the line of discussion we started here. There are security risks involved in building agentic AI. Access controls and authorizations are one of the big challenges, just because agentic AI has access to much more data than before.
And also, it acts on behalf of the user. Identity-first security, zero trust, all those security concepts that are already known, very well-known, very well-established, are very, very much relevant also with agentic AI. Eventually, we want the enforcement to be done based on the end user who's doing the action or consuming the data. So is it different with agentic AI? I don't think it's different, only it's on a much, much, much larger scale. The identity is not always there. There are a lot of non-human identities that are acting on behalf of the actual user identity.
And additionally, the data exposure is at a much larger risk because of the amounts which are involved. Also, please remember that AI systems operate also on unstructured data. So not just structured data. Maybe if we thought we solved the structured data security, well, now we have other levels of data security to consider. So bottom line is, AI systems are the challenge we always had, but on a much bigger scale. And now the question is, what should we do about that?
So first of all, we need to understand there is a high risk of overprivileged access because of the context which an agent operates on behalf of. So it gets the ability to access many resources, many data resources, has access to a large number of actions and services.
Therefore, it's a non-human identity with a lot of privileges. Second, by acting on behalf, the actual context of operation is not limited to what the actual end user identity is authorized to do. So this is something that needs to be considered. The agent can do much more than what is the user who's asking for me is capable of doing just by itself. And the last part is insufficient controls.
In some, not in some, in many cases, we are talking about unstructured data, which is more challenging to control than structured data, I would say. There aren't sufficient enough tools today that can enforce the same level of granularity on this type of technology.
And again, we are here in this webinar because we are talking about the challenges, but also about the solutions. Eventually, what we are saying, you need to consider solutions that are addressing all those challenges, the overprivileged access, operating on behalf and the insufficient controls in regards to the technology. And let me emphasize one additional consideration here.
Again, an AI agent is not just a piece of hardware which is creating a meeting for you next week. An AI agent is, again, it's your Tesla car, which kind of drives you home without a human driver. It has a lot of potential things that can go wrong, like hitting a pedestrian. And even if it operates without you at the steering wheel, it's still your responsibility, because it's driving you on your behalf, if you will.
And it will become even more complex, not just from the technology perspective, but from the legal and analytical and compliance and whatnot, different even ethical perspectives, as soon as we will have more agents having more actuators for the physical world, not just the AT world. And this will be coming pretty soon. You'll probably see AI agents at the manufacturing plant pretty soon. You will see self-driving cars or even self-flying drones, for example. Who knows where it ends?
But yes, you're right. We are talking about challenges and again, kind of when we are talking about AI issues, we have to, we cannot just kind of not mention of us the top 10.
Of course, this is kind of the organization which is well known for identifying and creating lists for top risks for various aspects of cybersecurity and identity areas. And yes, they have quickly created one for large language models and AI applications. When we look at this list of top 10 risks of AI systems, one thing we cannot but notice is that at least like half of those are directly or indirectly related to access management.
Whether it's something pretty straightforward, like you disclose sensitive information because it wasn't encrypted or protected with authentication or whether you have like excessive agency. Again, it basically means there is an agent which has too many options to influence other IT systems without any access control. But if you think about like data poisoning, it's again kind of how would you poison, like how would a malicious access poison your data by having access to your data without you knowing.
In a way, it's an indirect issue, but it's still an access control issue. Same applies to system prompt leakage and other aspects.
Basically, most of these challenges are directly or indirectly relevant for authorization and access management. Yeah, which makes access control and authorization one of the top security concerns when building a new AI agent, AI system, and so on.
Yeah, and kind of again, when we are talking about the actual agentic AI, we have to understand that an AI agent is not just your helpful co-pilot, it's actually someone you have to watch all the time. Even if it's not malicious, it has a lot of possibilities to break something, to make something incorrectly or in a way you have never anticipated.
And yeah, there is a lot of potential for tool abuse and disruptive actions or just kind of the old plain leaking your data or unintended autonomy. And it's all directly related to setting those boundaries for AI agents. And those boundaries are no longer just kind of placed strictly in the digital area. It's not just about your data. It's not just about your specific application or even it's not just about the LLM itself or anything working with an LLM. It applies to any kind of interaction which is currently possible within your entire IT infrastructure.
Even if it's at the moment only served by humans, those humans might eventually be replaced by a helpful AI. And all those interactions, whether it's physical like unlocking the office door or walking in and turning the lights or something purely digital like, I don't know, sending some money over to your partner's account. All of those interactions, all of those data sources, all of those systems are now potentially vulnerable to agentic AI.
And this is why the scope of all those security challenges is actually much broader and much riskier, if you will, than a lot of people currently anticipate. And this is why, again, we cannot stress enough that AI security is basically now the entirety of your security. Not just digital, but physical as well. Even if it sounds a little bit ridiculous today, it will eventually become reality tomorrow, next week or in five years. This is not the question of if, but when.
And again, one other thing we cannot ignore is the MCP effect, as I've heard it named, MCP stands for Model Context Protocol. It's an emerging standard that allows AI agents to interact with systems which were previously not AI enabled. The great thing about it is that it's already a standard, even if it's a de facto one. It's very easy to adopt. It's based on the existing API protocols and very simple sets of rules regarding authentication and data exchange.
And the whole purpose of basically allowing you to easily connect your AI agents to anything, be it a database, an application, a file server, a cloud service, a physical device. If you can create an MCP server for that thing, basically any AI agent that speaks the same language can now operate that source. Which is great and awesome and definitely anticipates the same level of connectivity explosion that happened to REST APIs a decade ago. REST APIs were adopted because they were easy to implement, but now we have the whole bag of challenges because REST APIs were never to be properly secured.
And the same applies to MCP. If you are ready to risk the entirety of your IT security by making it easier for an existing, even worse, a third-party AI agent to operate within it, well you have to seriously reconsider your priorities, I guess. Because while it sounds great on paper, there are so many opportunities to misuse it. So basically all the risks you have we already discussed earlier. It's the same OWASP top 10 for LLMs and OWASP top 10 for APIs and probably a lot of other top 10s as well. I think I'll just add to that the bottom line here is MCP is happening.
Everyone is looking into that and the bottom line is it provides much, much more power to agents. They were powerful to begin with, but now they have more power. And then therefore that's the top thing you need to consider. How to make them act in a more secured, responsible way. And you're currently presenting the top risks there with MCP servers and we can see that unauthorized access and privilege escalation is ranked number one as the top security risk in regards to MCP.
Just because it's really so simple and for those of you who have looked into the matter, you have seen how easy it is to use an MCP tool. You can use an MCP tool to even create identities, to access data, to do all kinds of tasks and it's just a few clicks away, right? And that means that building all those systems, providing those systems with access to services and data becomes so simple. So we really shouldn't forget the security controls that needs to be on top of that. And just to clarify, these risk scores are actually a combination of both the likelihood and the impact of a risk.
So of course, unauthorized access and privilege escalation is the top one because it's both very probable and very catastrophic potentially in its impact. So when you multiply those two values you get an extremely high score.
Right, so the question is, of course, sooner or later we have to address the question, okay, though these are all the multitude of the challenges, where do we even start addressing those challenges? And I would like to start with the slide. I also kind of like to reuse saying stop trying to reinvent the wheel. There is no such thing as AI security in the large, in the big picture of the modern security environment because there is nothing special about AI that cannot be reduced to a combination of existing technologies, protocols, interfaces, data formats or infrastructure.
In the end, regardless of who and how and through which techniques is trying to basically maliciously exploit your AI system, they are all after your data in the end. But probably like one single exception of next-gen ransomware when they want to destroy your data. Make sure that you cannot even operate at all. But the rest of all, it's all about stealing your data, compromising your data. So you still have to focus on securing your data and all those things we described earlier are just new attack surfaces and attack vectors. So what are the key principles?
I guess we finally we can start answering those questions. What are the key principles of securing agentic AI? Where do we even start?
Yeah, and this is according to a science research. We have also the link attached there. There are multiple researchers on the subject, but basically they repeat the same key principles. Access controls being one of the top in priority to consider. You need to consider your access controls, your data protection solutions as part of any agentic AI system which you're building or considering to build. You might even want to think that to begin with as an infrastructure level solution. We can talk, we'll probably talk more about that later on.
But this needs to be there from day one, not after the fact. We don't want to repeat some of the mistakes of the past where technology evolved without security being part of that. Today is the time to consider just before you're starting or even as some of you mentioned, we are already in process. Consider those access controls and data protection as part of the solution which you're already building.
Yes, there are other security areas you need to consider as well, as you can see the mentioned here and also available in the report. But access controls and data protection are one of the top priorities. Right. Yeah. And if we consider those access controls and authorization challenges, again, we are repeating what we said. This is to leverage your known best practices. We spoke about this privilege in the years, we spoke about that some years already for now, and it is also very much relevant in regards to agentic AI.
Eventually, when an agent carries out an operation, we want to remember it's on behalf of the user. It needs to be doing that on behalf of the user with the user context, with the user approved access rights in regards to what data that user can see, what operations they can carry. There are several methods already known how to implement that. And that's one thing you need to consider. The second thing is identity first security.
Again, a very known practice in the security space. What does it mean identity first security? It means the operation which is being performed is on behalf of the user, again, with the end user context. We can't have all those non-human identities with overprivileged rights doing whatever they want. Right. If currently an agent is doing an operation on behalf of myself, then it needs to have access only to what I'm entitled to see and do. And all of that is eventually carried out by implementing dynamic and granular controls.
Again, not a new concept, a well-known concept, which is enforced by policies. The ability to make a decision on the time of access with the right context, that's crucial for AI agents. One thing I would say here is that static won't work. You need those dynamic, you need those fine-grained.
No, it's not enough to rely just on static and coarse-grained authorization as we used to do in the past. If we look at the core principles of access controls and authorization, we always like to look at the question of who can do what on what and when, and we need to answer that question. In the context of agentic AI, we do replace the who can do what, who can ask what, because it's always operating on behalf. I want to ask the agent, I want to ask the AI system to do something for me or to retrieve data for me or whatever.
So we're asking some system to do something, but still, within that context, the access controls should consider who is the end user identity, not only the non-human identity. What am I asking for? I'm trying to access the financial data of the company's US operations, or maybe I'm trying to access the HR data. And then can I do that now? I'm asking for an operation from the agent. Can I do that operation now? Can I access that data now in the context of which I'm operating in? I'm working from Europe, I'm working from the US or from China. This is now 8 a.m. or 8 p.m. and so on.
So any contextual access also needs to be considered. Eventually, those are the core principles of policy-based access control, considering the identity, considering what the identity is trying to do, when that action is actually being tried to perform, and all that leads to the access decision.
Granular, dynamic-based, at the time of access. And if I may add to that, this actually goes both ways. It's not just who can ask an agent to do something, but also the same policy, the same decision should apply to the agent's activities as well, because agents can ask another agent, or agents can do something directly in a target system. Or maybe in the future, an agent can even ask a human to do something for them. All should apply, I mean, all those rules and principles should apply consistently and in the same manner.
Otherwise, you immediately lose the oversight and the control of the entire situation. Right, moving on. How is it supposed to work?
Yeah, so how to take those core principles of authorizations and fine-grained and actually implement them in a full AI pipeline. So this is a high-level reference architecture of how a typical AI pipeline would operate. It starts always with the question, right, the prompt, where the user is asking something.
Then, in order to support the answer, there is a retrieval process which pulls data. Then data and question is fed into an LLM, and the LLM generates an answer. That's a very basic description, I would say, of the typical flow. So controls should be considered at three points. First of all, on the question, can I ask the question, I want to ask about financial data, but I'm an engineer. Why should I be asking about financial data? This question is not allowed for me. So controls on the question, that's one.
Second, to which data can support my question. I'm asking about financial data, but I am an account executive in Europe, so I should not have access to information from the US. So only parts of the data can support my question.
Now, as the answer is being generated, maybe I shouldn't be able to see all the addresses and phone numbers of the people that are mentioned in the report. So some of the data in the response should be masked.
Again, principles which you should be familiar with, but applied on the AI pipeline. Right. And of course, it's all based on policy management, right? Yes. That's the only sensible way to do it, because it's not something which you can do like on a perimeter level, or like as a set of rules for a firewall, or like setting up specific requirements for each part of the entire stack, database, cloud service, whatnot. It all has to be centrally managed, declarative, and dynamic. And that's exactly what policy-based access control is.
Exactly, exactly. Basically, we are arguing here that the way to achieve that security into your agentic AI is by implementing a policy-based access control, which provides the identity awareness, the granular access required in such applications. And one last thing I also want to emphasize here is the scalability of the solution. Agentic AI, as we mentioned to begin with, has access to vast amounts of data. Also data which might be distributed in multiple repositories. It has access to all kinds of operations. And eventually, that all needs to be governed in a central way.
PBAC has the ability to scale all across your technology stack. And that's another important aspect to be considered as part of the solution. All right.
However, if you actually want to consider an even bigger picture, we have to take another step or two back. Like this is a slide which I created years ago, even before ChairGPT, where I attempted to demonstrate that our modern world back then is a highly interconnected and extremely unprotected one. Because there is a lot of parts, internal and external, constantly communicating with each other. And the enormous complexity of these interactions is basically why it's so difficult to protect it.
But again, kind of just a few years later, the picture, and again, kind of same slide as five years ago, every part of that infrastructure is potentially vulnerable. But nowadays, the picture looks more like this. Because we have the big evil LLM out there.
And again, for most customers, it will be an external LLM consumed to the service, which has multiple interactions with the entirety of your existing quote-unquote dumb infrastructure to make it smart and intelligent. But you also still have people, tired, overworked people still working with most your existing tools and the LLM. But what's coming now, and it's going back to your comment earlier, it's all about scale. We have agents, tons of agents, thousands of agents.
Right now, there is an estimated for each human on the large internet, there is about 90 non-human identities. I believe it's just the beginning, there will be thousands, tens of thousands, maybe even millions of non-human identities per human. And at that scale, if we consider how many potential interactions are there, with existing systems, across agents, with LLMs, with humans, it's just the level of complexity becomes so enormous, that there is absolutely no way to attempt to secure a quote-unquote each individual one separately, with different tools.
Or to say, yeah, we will only focus on securing the interactions between a system and an LLM, or a human and an agent, or an agent with another agent. There is no way you can do it separately, in different ways. The only sensible approach is to say, stop bringing complexity. You have to replace your thousands, potentially millions of individual security controls with something which works the same way across the entire IT landscape.
And I believe that currently the only thing that actually allows that is, again, policy-based access management, where you have a single, hopefully a single entity, like a customs officer, who decides who gets in and who doesn't. And he has the ability to distribute his decisions across thousands, millions of policy enforcement points. And it doesn't matter whether that policy enforcement point applies to an LLM, or an agent, or a database, or a file server, or anything else. The beauty of policies is that they are declarative, and the decision is always made using the same rules.
And of course, the contextual information you have from a specific system or agent. This is the only way that scales. There is no other alternative.
And this, I believe, should be kind of the biggest takeaway of our entire webinar. So yes, if you're talking about takeaways, the first one is AI is here to stay and grow. There is absolutely no way you can hide and wait and kind of walk it off and hope that it will get returned back to normal in a few years.
No, it will only get worse. The complexity and scale will only increase. And zero trust is the only way to tackle it. You can no longer afford implicit trust anywhere. So you put identity at the foundation, and you apply similar policies and similar controls anywhere within your IT infrastructure.
And again, there is no need to reinvent the wheel. Yes, AI agent is something so new and amazing and different, but it's not really. It's still the same combination of code, and data, and interfaces, and LLMs, and standards, and protocols. You just need to make sure that your policy enforcement controls work with those protocols and standards. And I was thinking about kind of how to name my final message. I was first considering calling it the Stargent's Law of AI. If you are unfamiliar with Stargent's Law, it basically says 90% of everything is crap.
But I decided, let's call it the Pareto Principle of AI, which basically says that to reach 20% of your goals, you have to spend at least 80% of your efforts. And that's my message to you as a takeaway. AI security is at least 80% just API security and data protection. And we already know how to deal with that. And API security is at least 80% just dynamic access management.
And again, we already know how to deal with that. And this rule is relevant for at least 80% of all businesses out there, where my estimate would be like 99.9%. Because unless you are a giant like Microsoft or OpenAI, where you actually have to deal with specific risks of training and developing new LLMs, the rest is probably completely irrelevant for you. You just focus on what you can solve with existing tools. You will be almost there. Thank you. And I would just add that we spent a large amount of this webinar talking about challenges and security.
And basically saying, you know, those are the old challenges. And therefore, the old principles should apply. But there are also solutions. We haven't been talking about solutions, but we kind of very briefly mentioned them. If you're looking to learn more about solutions, then you're welcome to approach us and, you know, get a bit of feeling of how it looks like. Right. And by the way, before we close our webinar, we still have time for a quick second poll. So if anybody already has an idea how to tackle this and which approach they want to use, it would be interesting to hear your opinion.
Because what we've heard a lot in our discussions with customers and just people interested in all this, that they have different expectations. Some would believe that somebody will take care of the entire security stack. For example, the provider of the AI framework. Somebody would say, yeah, I will just focus on the API level, the network level security, which is fine, I guess. Or they would say, no, we will trust the existing security controls, which every database vendor or cloud service provider offers already. We will just combine them somehow.
I guess there is no single right answer in this poll, but it would be interesting to see what your opinion is. And if you have a different opinion, do not hesitate to talk to us after the webinar. So do we have any results?
Well, so far, the response, I have not figured it out yet, which is, I guess, still okay. If you are still considering your options, let's make sure that you do consider different opinions from different parties around the internet. The biggest mistake you could do is to trust a label, like buying something which has a label AI security on it, and hoping to just buy in the box and put it on the shelf to solve your challenges. Unfortunately, this is not how it all works.
So stop practicing the cargo cult of cybersecurity and start looking for solutions where you actually know what you're doing, and where you are using the tools you already have. And I guess that would be our message to our viewers. Thank you very much for being with us today. Thank you very much. And we'll hopefully see you in our upcoming webinars or conferences.
And again, if you have any questions, please consider talking to us directly, either me at Kubernetes.com or Merle at Plain ID. Have a nice day.
See All Locations
See All Locations