Let's assume an agent is acting like a very stupid person and you ask your agent, hey, I need some fresh air, can you help me with that? And the agent could just open a window for you, I mean, a real window, or as you stated, even though the intention is there, the agent could take a different path to the solution.
So, if the agent is not limited in options, he could also punch a hole into the wall and that would also lead to fresh air. Welcome to the KuppingerCole Analysts Chat. I'm your host, my name is Matthias Reinwarth, I'm analyst and advisor at KuppingerCole, and so is Phillip Messerschmidt. He's a colleague of mine in advisory, he's deputy chief of advisory.
Hi, Phillip, good to have you. Hi, Matthias, thanks for the invitation. Great to have you, and this time we really want to have a chat. This is not an interview, we want to look back at an event that happened at the time of this recording, exactly, more or less exactly four weeks ago.
So, it was the EIC, the European Identity and Cloud Conference in Berlin. We are working for KuppingerCole Analysts, but this is really the flagship event when it comes to identity management and everything around that for Europe. You've been there, Phillip, I've been there, we've worked a lot, we've talked a lot, we have not had the chance to watch everything because we had five tracks and a lot happened. You've been there, Phillip, from your first impression, when you look back at this EIC, was it different? Was it bigger?
Was it, yeah, was it different? Was it a change to others? What is your striking memory when you think back of EIC?
Well, I think it's not that easy to say it was different than the others. I mean, it was the same to that extent that we had a lot of topics less than a couple of years ago, but still enough. The quality of the presentations, that's at least what I heard from the audience, was, again, very good, a very high level of quality.
So, in that terms, it was not different. It was maybe better, but I would say it was the same like in the last years. What changed is the topics.
So, what we have seen in the past is that we usually had a couple different trends. This year, it was a little bit different. It focused a lot on AI and agentic AI, but there were topics right and left of that and not as prominent as AI and agentic AI, but we still have captured a couple trends besides that. And AI and agentic AI and non-human identities, we can discuss that term later, really overshadowed a lot, but that does not mean that there was not more around it, just as you said.
So, it was, of course, the elephant in the room to have this agentic AI topic there, and I did a lot around that as well, workshops and panels, and every second speaker at least had a mention of that topic in their presentation as well. So, it is a huge thing, and maybe we should also talk a bit about that, but we need to make sure that we also cover all the other topics that are as important, different important, differently important, but I think there are more to come. But start with the agentic AI topic.
So, is it, the last years in EDIC, if I think back, it was feeling a bit of more of the same and a steady evolution. This time, it felt like disruption, revolution, things changing, old paradigms break, and I think that changed the tone. Do you agree?
Again, to a certain degree. I would say AI and agentic AI are a new challenge for us, because when we think about the NHI in general so far, that were like technical identities that served a certain purpose, and we were aware of that purpose. We knew that purpose.
We were, I wouldn't say in control, but we would have the chance to be in control of all NHIs. With agentic AI, it's a little bit different because it acts autonomously, and that makes agentic AI more comparable to a human identity than to a classic NHI, like we know it. And the interesting part about agentic AI is, with acting autonomously and without, let's say, a framework of ethics, the agent can potentially act like an insider and can create an insider threat.
So, like a human, but without the idea of what is good and what is evil. And that's interesting because in IAM, we built our frameworks and our controls and everything around human identities and non-human identities that served a certain purpose. We have no frameworks that can handle an autonomous AI without a good ethical framework behind that.
So, I think the behavior or the agency of an agent is really something that we really need to wrap our heads around right now. This is something where also the industry agreed that we are not yet there, that not every solution is already on the table when it comes to formulating intent as something that is passed between different agents or from a person to an agent, to another agent, to an application server, to a database, to an MCP server.
So, that is really something where things change. But on the other hand, we are dealing with systems or with requirements to systems that we did not have before.
So, we are talking about machine speed, not people speed. I request access, I approve access, I assign access. This happens now within milliseconds.
So, this is something our systems were not built for. And the same is true for scale, for the sheer velocity, the amount of identities that are around. And then they are also agentic, they have agency. They solve their issues and their tasks for themselves, just as you said. And they don't care if it's legal or illegal.
So, it is ethics because they don't care about ethics, they just solve the challenge. And this is something that we are currently dealing with. And I think the industry is doing a great job in getting closer to that, but we're not yet there.
So, I think this is really something that really changed. So, we are breaking paradigms that worked for decades.
Yeah, absolutely. And we can see that with the trends that we have discovered at EAC.
So, as said, it's not all about agentic AI, but we can use some of the known technologies and some of the known methods that we already have in IAM for at least solving parts of the challenges with agentic AI. So, I'm talking about dynamic authorization, for example. We need to work with the agents that come at machine speed, making decisions at machine speed. And a challenge that we currently have is that the current authorization models are built to work with static entitlements, with static situations. And agents at agentic AI, they are no static challenge.
They act much faster, much more unpredictable than any human. As I mentioned earlier, they are autonomously acting identities without a sense of good or bad. And that makes them a threat if we are not able to give them the guardrails. And dynamic authorization can make that happen.
So, one very interesting presentation from one of the vendors and one of the statements that the person made was that we need to protect the data. It doesn't help us just to identify and discover the agents, but we need to protect the data.
So, instead of discovering thousands or ten thousands of agents, it's much more valuable to protect all the data points or the applications and put up the policy enforcement points in front of our data, ensuring that the agent needs to identify himself and the intention that the agent has. And that is, I think, an important point here when it comes to the trends that I mentioned.
So, we can see agentic AI requires the other IAM topics. I fully agree. Protecting data is, when it comes to security and also to governance, the first starting point. I would not say that it does not make sense to identify the agents, but in the end, when this thing, this agent, that process, that autonomously acting instance of software, when it makes a decision, when it transfers money, you want to know what agent was it and on whose behalf it acted or who is liable for that, who's responsible, who's the owner.
But that in a pyramid of controls comes second place, because you don't know which agent knocks on the door the next time. And maybe it's a known one, unknown one, first protecting the data and then later understanding what happened right now and who's responsible and why was it correct or not. Both dimensions are absolutely valuable and we need to find the proper way to deal with that. But protecting data in the first place, I would fully agree.
On the other hand, what we are still struck with, and you said they are like people, is that you can give them the same task and maybe next time they will choose a different approach to solve the same task, which is a good thing for a person and a regular thing for a person. This is what we're used to. Some ways are better than the other and some are more effective than the other and these things learn. But they are non-deterministic and that is a challenge that we as IT people who think in algorithms are not yet used to.
And this is something that we also need to translate into the proper controls. Jonathan, our colleague, mentioned the idea of having something like ATDR, which is of course a version of ITDR, Identity Threat Detection and Response, apply this for agents. It's not just the same set of capabilities, but it's machine speed, machine velocity, machine scale and being able to understand what the intent was. And I think this is where things get spicy. Do you agree as well?
I agree, but I think the way to get there is not as easy as it sounds. Let's take a simple example. If you tell your agent, let's take a real-life example where obviously no agent can help you, but let's assume an agent is acting like a very stupid person and you ask your agent, hey, I need some fresh air. Can you help me with that? And the agent could just open a window for you, a real window.
Or, as you stated, even though the intention is there, the agent could take a different path to the solution. So, if the agent is not limited in options, he could also punch a hole into the wall and that would also lead to fresh air. That was your intention. You not your intention in the end. And that is something that we see in technology as well, but it's a little bit more abstract and harder to understand for people.
So, with agents analyzing and covering agents' intent, that would mean that we need another agent ensuring that the first agent is not punching a hole in the wall. Both agents need to learn that.
So, the monitoring agent needs to have that understanding of what is good and what is bad. And that is something that the agents need to learn before they can start their monitoring work in the end. And interrupting the first agent basically before the mistake happens.
So, that is something that they need to learn and that we need to teach them before we can apply that. But in the end, I think the statement itself is right. When we want to use the advantages of the agents at machine speed and at machine scale, the human in the loop cannot be the solution, at least not at scale and not at the speed. It can be a solution for the learning and the learning algorithm for the, let's say, monitoring and governance agents, but it can't be the solution to ten thousands of agents running around at machine speed.
And that is basically something that Jonathan stated, that we can expect ten thousands of agents compared to one human as a ratio in around 12 months. So, let's see if that really happens. What do you think about that? One thing is clear. No matter how we achieve it, we need to have something that we did not have in traditional identity and access management.
Usually, we will need to have behavior analytics for agents at runtime. And as you said, the human in the loop is not really an option. It might help in some edge cases, but that's it because speed, velocity does not scale with people. Changing access management, access governance for agents by using behavior analytics, I think that is a starting point. How we do that, is it another agent that controls the agent, but who controls that agent? That will be the interesting part.
But when something happens with its own intent, with its own plan, its own agency, and its own strategy, we need to monitor the strategy and how it's executed. And that is something that we have not been yet used to do that. But we need to get there and we need to get there fast. This is really something that we need to do. And just one final sentence. When Martin suggested to do a pre-conference workshop on the changes of AI to IAM a week before we started EIC, the team that actually prepared for that sent in questions and areas where AI changes IAM.
And within two days, we had 15 changes and all were valid. And we thought we stick with them. And then we added up with 15 more. And I think we're still not yet complete. If somebody's interested in that, please look at the slide deck and it's available and the recording is available for those who've been there. So there is a lot that's changing. But actually, we wanted to look into the topics that are not AI and that are not agentic. And so the question is, and we've already had this overshadowing even from what we've been talking about. So stop it here. This won't go away, this topic.
We will have that for years. That will change a lot in identity and access management. But if you look back at EIC, what were the other aspects? You've mentioned dynamic authorization. What else happened?
Well, we have the always coming back topic of UID wallets and the success factors of this topic. We have a sovereignty, data sovereignty. That is also the thing that becomes more important, especially now when we think about the geopolitical world and how it is at the moment. We still need to think about cryptographic agility and what happens when the Q day arrives. So that is something that we need to prepare for. And then we have the identity fabric and the strategic view on all of the topics and how we can handle that based on structured frameworks. I think that's also important. Yeah.
And most of the other trends we have already mentioned with our AI talk earlier. So these are the four that we have left, I would say. So which one do you want to start with? I would add one because we will go back to yours. But the topics that you've just mentioned, they are real life topics, but they are challenging for many organizations when it comes to planning for the future. So they are somewhat future looking sovereignty. It's difficult because systems being available, crypto agility. Yeah. What do I do? Exchanging algorithms. So these are new topics.
We had a set of great presentations and panels that covered the topic of how do I make my own now existing identity and access management program slash project a success. So just back to basics, back to the real life key performance indicators, the best practices of how can I achieve the best for my organization when it comes to very traditional human-based identity and access management. There were a lot of talks about that, and this is still a topic.
And the EIC also needs to make the full balance between bread and butter topics and these shiny new AI topics that will influence our world for the next 15 years. And I think that is also an important part to have the practitioners exchanging with each other. How do you choose the right method to roll out the next authentication factor? And on the other hand, the really challenging new topics of AI. And if I go back to your question, I think the question of sovereignty is really something that is around right now.
So when I say we just recorded this four weeks after EIC and between EIC and today, there is the switching of AI capabilities within Anthropic based on a governmental decision by the US government. And that is something that influences a lot of organizations that are actually already trying to use these capabilities. So there are, without any political interpretation, we need to deal with changes that we did not have to do that much before. And I think that's a big challenge.
And we can look at that from various aspects when it comes to data residency, when it comes to who processes the data and who has access. I think that is a hugely important topic and it's really on the mind, especially of CISOs and of CEOs that want to protect their intellectual property and their employee data and their customer data. Don't you agree? I agree 100%. We see that currently a lot when it comes to data residency.
So especially highly regulated organizations, they don't want their data to go outside of their control, outside of their reach, outside of, in that case, of very often Europe. And they don't really trust, I mean, the hyperscalers in general, they still trust. But especially when we talk about software as a service, the trust in vendors that deliver from outside of Europe to a European organization, that trust feels lower than one or two years before. So data sovereignty, or in general sovereignty, is a topic that is really important.
Yeah, I absolutely agree. And sovereignty and also creating the right fabric for your services, not necessarily an identity fabric, parts thereof, but also to create a fabric of services that isolates this data and these services that are most important for you, while still integrating with other ecosystems. I think that is also something that we need to deal with, which I tried to be a good segue, but it did not work that well towards standards. Because of course, we need standards if you want interoperability.
And the more building blocks we have in our fabric, cybersecurity fabric, AI security fabric, identity fabric, the more components are in there, the more we rely on proper integration via standards, via APIs. And this is something that I, of course, want to mention as well, because a few weeks slash months ago, you and I welcomed David Brossard of CEN within this podcast, where we talked about their establishment of standards and profiles to allow for proper integration. And the CEN organization won an EIC award for their really impressive work regarding the standards.
If I remember correctly, Philipp, you did actually the Laudatio for the EIC award. So what was it that they were awarded with this award for? What was their actual achievement that you highlighted? I think the most important thing is the dynamic authorization part.
I mean, they started that work group a couple of years ago, when agentic AI and the challenges that now arise were not even a topic. So the original idea was just to standardize dynamic authorization beyond the actual solution. So making all the vendors being able to work with each other so that we don't see the same issues like with the IGA vendors, that every vendor has its own connectors to the target systems. And with dynamic authorization, and then especially, we now have a standard that supports that interoperability.
And the interesting piece now is with agentic AI coming up, this standard is also able to support agentic AI and the MCP communication in the background. So even though it started a couple of years ago, it is solving a problem that we were simply not aware of at that time when it started. But now it serves the purpose very well. Right. So they started the work right in time to solve issues they didn't know of. This is a good starting point. And maybe if you pick one more topic, and I think that is, I want to end with a quote that Martin said in his closing keynote.
And this is something that we both agreed before we started this recording. This is a striking sentence, and it's unfortunately very, very true. Martin said in the closing keynote, everything we failed to solve in the past decades bites back now. And so many challenges that we just did not properly solve from access assignment, access review, access governance, but also identification at scale. This is really something that we now have to solve quickly and the hard way. Right.
Yeah, absolutely. I mean, I've mentioned earlier that agentic AI behaves like a human, but is missing the right or wrong idea or ethics behind that. So an agentic AI behaves like a human identity inside a threat challenge earlier with a proper approach, we would be able to, at least to a certain degree, to handle agentic AI much better.
I mean, we would still have the issues with the delegation, but at least we would have a concept like zero trust in place. We would have the issues of DLP solved to a certain degree, and we would have dynamic authorization in real time. Stuff that we could use right now to solve the agentic AI problem. But what we can still see is that a lot of organizations are still struggling with I would call it the basics of IAM to a certain degree. We are still talking about roles and sometimes not even about roles.
Organizations are sometimes, not all, very immature when it comes at least to authorization. And that is an issue that will hit very hard when agents are going rogue. If the landscape, the IT environment is not properly prepared for an insider threat that behaves like a human, that can strike very hard.
Yeah, I would fully agree. And the question is really not, is this a separate challenge that we need to solve for these NHIs? I think the same challenge will come back to us also for the identities that we are used to. Privileged accounts, just regular employee accounts. When it comes to those who are using our systems from the outside, our partners, our service providers that do something within our systems that are no longer within our firewall delimited area. So we really need to be very fast. And if we would have done that earlier, we could have the time now to focus on what's really new.
Now we have to clean up the old and the new stuff, which really is a challenge in itself. The good thing is there will be a lot to talk about at EIC 2027 because these topics won't go away. We will look at these topics, of course, also, and this is the short commercial break at our Identity Fabric Impact Days and the Impact Days in general, three coming up later this year. We're just starting the plannings. If you want to contribute a talk, this is not to Philipp, also to Philipp, but not only to Philipp. If you want to contribute a talk, please reach out to us.
We're just currently planning the agendas. So if you have interesting things to say about these topics, go to our website and go to the call for speakers. We are just right now there. So there is a lot more to talk about. And end of the commercial break is, of course, the sentence. If you want to adjust your existing IAM solution towards a more mature, a more capable, a more NHI, a more agentic AI capable system, maybe you reach out to Philipp and Ormi to receive some guidance, some support, some advisory. Final question, what was the most interesting talk that you've seen?
I will answer that as well later. The question is, when you look back at 60, if I remember correctly, sessions that we did in five tracks over four days at EIC and Alexander Platz, what would be the one that you would recommend to everybody to have a look at it? To be honest, I'm not sure if I should answer that and pin it down to a single presentation.
But one moment that I remember back was Patrick Parker's presentation and how he stated the comparison to the data-centric defense model, I would even call it, to say when we want to protect against agents, we don't need to focus on the agents, we need to focus on the data and ensure that we secure our data. He made that very easily understandable with his example about the vaults and said when we have 27 vaults in Germany or in Europe, it is much easier to protect 27 vaults than discovering 100 identities and finding the 30 rogue identities in that bunch of identities.
That is something that I remember very clearly and that was a thing that made me think about how to approach agentic AI. If we are doing the correct thing with everyone saying discovery first or is it not discovery first, is it data-centric defense first?
Yeah, I think that's an important point and this is really, really forward-looking. There are lots of great efforts going on also in making the right decisions at the right time and then prioritizing applying risk-based principles. I think that is an important part. If I would have to answer that question, I would also not pinpoint one single presentation, but there were a set of presentations by practitioners who have just shown what improvements they've made. Things that we presented three years ago at EIC as the next big thing are now implemented, are now working.
Think of pass keys, think of identities for cargo rather than for people. Implementing identity management at scale at a national automotive company. There are lots of great talks that are not that super shiny but are so to the point when it comes to solving everyday issues for large corporations. If I mention a few, BASF had a great presentation about how to do access governance.
We had BMW who talked about their approach towards identity access management and DB Schenker was awarded with a prize when it comes to assigning identities to non-humans for a very different purpose, but still identities. Very interesting talks. I would really recommend that if you have the chance to watch them afterwards, please do. There's a lot in there to learn from and we learn from that as well. That's the our experience and our research.
Philipp, thank you very much for being my guest today. This was one very individual, very personal look back at EIC. Others would of course highlight very different aspects of that, but that's what this podcast is about. We shared what we think is important. Some topics just dictated them into our agenda themselves with their own agency, of course, and others I think we need to make sure that they are not forgotten when it comes to understanding the big picture of IAM.
Again, thank you Philipp and looking forward to having you soon again. Thank you Matthias and also thank you for your insights. I'm interested to see in 11 months at the next EIC what really realized and how people solved zero trust in one year and catching up with everything else that we mentioned. That will truly be an interesting year until the next EIC. If you do that, let us know. Maybe there's an award for you next year. Let us know. Thanks Philipp. I'm looking forward to having you soon. Bye-bye. Thanks. Bye.