Not Just PAM
Combined Session
Thursday, November 26, 2026 10:30—11:30
Thursday, November 26, 2026 10:30—11:30
The EU AI Act obliges providers and deployers of high-risk AI systems to ensure "effective human oversight" (Art. 14) - including the ability to intervene or stop the system when needed. What reads like a straightforward process requirement turns out, on closer inspection, to be an identity and access governance problem that the regulation never actually solves:
The regulation never requires that the "natural person" assigned oversight duties be demonstrably qualified or certified - competence is assumed, never verified.
The technical access rights needed to actually intervene (stop button, override) are not tied to any privileged access framework - who gets these privileged rights, at what scope, with what logging, and with what revocation process, remains open.
Art. 12 requires logging the identity of the reviewing person for certain systems - but without any link to a broader identity lifecycle (role changes, offboarding, delegation), and without connection to a behavioral baseline against which "anomaly" could even be recognized.
The human overseer is expected to detect anomalies and intervene at the right moment - a requirement that's barely operational without identity threat detection-style mechanisms (continuous verification, context-aware access control) applied to the overseer's own access itself.
This talk bridges the legal analysis of the AI Act's oversight obligation with the concepts of modern identity-centric security — privileged access management, continuous authorization, identity governance - and shows how organizations can close this regulatory gap using existing IAM/PAM architectures, rather than waiting for the regulation to catch up.
Key Takeaways:
"Effective human oversight" under Art. 14 AI Act is not operationally meaningful without an underlying privileged access and identity governance framework - the regulation assumes it without actually mandating it.
Logging obligations under Art. 12 AI Act partially capture the identity of acting persons, but without any tie to identity lifecycle management or a reliable behavioral baseline.
Organizations can close this gap using existing ITDR/PAM/continuous authorization approaches - the talk offers concrete points of connection.
Just-in-time access and standing-privilege elimination have been best practice for years, yet most privileged accounts in production still carry permanent, unused entitlements. This panel goes beyond traditional PAM tooling to confront the governance, cloud, and shared-responsibility gaps that keep standing privilege alive long after everyone agrees it shouldn't be.