Every AI agent is acting on someone's authority. Most organizations cannot prove whose.
AI agents have moved past assisting people. They now access systems, call tools, and take consequential actions on their own, often without a person approving each step. That breaks a core assumption behind most identity and access management programs: that access maps to a person, and a person is accountable for what happens next.
Jonathan Care Practice Lead AI at KuppingerCole will examine how identity and access management must evolve as AI agents become autonomous actors. They will explore the distinction between agent ownership and delegated authority, why conventional human and service-account models fall short, and how organizations can establish clear boundaries, governance, and accountability for agents acting on behalf of others.
Grace Rachmany, ExecutiveDirector at Decentralized Identity Foundation (DIF) will explore how delegated authority can be implemented and demonstrated in practice. They will address scoped and revocable mandates, binding agents to verified principals, and creating an evidence chain that connects an agent’s actions to its authorization. This allows organizations to establish not only what happened, but who authorized it and within what limits.
Dr. Angelika Steinacker is a seasoned Cybersecurity professional with over 30 years of experience, including more than two decades specializing in Identity and Access Management (IAM). She has held leadership, executive consulting, and strategic advisory roles, most recently serving as CTO for IAM at IBM’s Consulting EMEA unit, where she focused on GenAI and IAM integration, Security for AI, Identity Fabric, and Zero Trust. She continues to advance IAM and Security focusing on strategic initiatives and innovation in these evolving domains.
Who should attend
This webinar is for CISOs, IAM architects, and security leaders responsible for governing machine identities, securing privileged access, and preparing their IAM programs for AI agents.
Good morning, good afternoon, or good evening, wherever you are. Welcome to this KuppingerCole webinar, Who Gave the Agent Permission? I'm delighted to be joined by two very distinguished guests. Grace Rachmany is the Executive Director of the Decentralized Identity Foundation. She's an expert on digital identity, decentralized technology, and civic tech. Dr. Angela Steinacker is an independent IAM strategist and researcher, the former CTO for IAM at IBM, and the DAF Ambassador for Women in Identity.
Beyond the research, she works directly with clients putting IAM and AI governance into practice. So for her, this isn't just theory.
Welcome, both. Thank you for joining. Thank you for the invite. Let's talk a little bit about what we're heralding here. On October the 7th, I will be at the AI Identity and Non-Human Identity Impact Day. And the key topics are the evolution from human to machine DGE, workload identity and cloud native trust, identity for AI agents acting on our behalf, identity governance beyond humans, identity threat detection and cybersecurity, and building the identity fabric for the autonomous enterprise.
So please, if you are interested, do secure your spot today by scanning the QR code on the screen. You will have the opportunity to meet myself and many of my colleagues from Cappadocia Coal, but also many distinguished members of the AI Identity, the Non-Human Identity community, people like Grace and Angelica, who are working hard and really at the forefront of this emerging technology. Okay.
Well, like I said, we have turned off any questions, any noises. So please, if you have questions, please submit them using the questions tab in the bottom right, and we'll be delighted to answer them. And without further ado, I'd like to start off on our first topic. So a purpose doesn't replace permission, it moves it. And what I mean there is that someone still has to declare what an agent's for and approve that declaration. So if the builder self-asserts the purpose, governed by purpose becomes permission-based governance of the weak audit trail.
So my question, I think, is Grace, what do you make of this? Yeah, thank you. This is a really complicated question. And we've been putting out a number of reports about delegated authority, and what does that mean? And is delegation even the right word to talk about? And when we talk about purpose, it's actually purpose comes in concentric circles, if you think about it. I work for a company, and then I work for a department.
The company has a purpose, the department has a purpose, I have certain authority, and all of that context is assumed by me when I go around, and then I'm going to check out my agent, and I want my agent to give better customer service in responding on the AI chat. And all of that context, there is really no way today for us to signify those concentric circles of context of, oh, what is the purpose of the company? What is the purpose of the department? And then what is my role in the department? And then I write a prompt, and all of those different context layers are completely missing today.
Yeah, context is important. Angelica, what are your thoughts? My thoughts on purpose is that this is an expression at the moment which is flying around and has different meanings for different people. So as a mathematician by education, I first would define what do you mean with purpose? So let me try to do that.
So for me, purpose is something with what an agent is defined, what the agent should do or should give results. So the administrative part more of an agent. And then we have at some point in time, the agent is doing something. And what we want to have, of course, is that the agent is doing exactly what we had, I should say, written in the purpose. And now we are talking about the runtime experience. On the one hand, the administrative part, so like a role. If classical identity and access management for humans, you will get a role. And you have access rights, which are part of that role.
And an agent has similarly a role in this specific context. And for the task, the agent gets access rights. So and I think we need really to differentiate between the administrative part and the runtime part. And of course, check whether the runtime pieces map to the administrative part. And the next point I would make, and I know that I have, there are people out there who say that purpose is not an attribute of an agent's identity. But I think it is an attribute. And it must be an attribute of an agent's identity, because it must be governed.
It can change over time, the purpose, it can evolve, but this has to be also tracked and audited, similar like changes in roles for humans are. And if you don't do that, you will have great, I would say, difficulties to really govern that piece on purpose. So and this is my point on that one. Purpose is something for me, something static, and the runtime piece I would call intent. But at the moment, this is not, I would say, consents, which term to use for what. But I think we are that you have an administrative part and that you have a runtime piece to follow. So it's purpose.
So we're trying to align an agent with an organizational departmental mission, I guess. And I suppose what we're also trying to do is imbue it with some of the values that we as humans take into our work as well. Is that correct? Not similar to that, I would say, yes. Cool. Okay. What is your, what's your view of this, Gloria? Is this something that we are seeing out there? Is it something that can be done? I'm going to assume that I'm Gloria today. Any name that gives us G is totally fine with me. I beg your pardon. I didn't do my normal trick of writing the name down 20 times.
See now, everyone needs their unique identifier, which is, you know, all what we're talking about is, oh, does that agent have a unique identifier? And what happens when I misidentify my agent?
And, you know, the logs show the wrong agent who did the activity. So we've already moved over there to identity really quickly, of course, here. Yes.
So, I mean, so when it comes to having purpose or intent, or all of those things, yes. And often, I'm kind of thinking that in some ways, in our own lives, we're not totally explicit about our own intents. And there is actually a way in which we use a lot of shortcuts that are not necessarily going to be understood in the context by an agent. I see. Okay.
So I think the, I think certainly the idea of the context that we provide these things is becoming more and more recognized, and that if we want a considered and appropriate response from an agent, we need to give it a considered and appropriate context. And so I'd like, if I may, to move on to the next question that's in front of us, which is that purpose is not necessarily enforceable at runtime in most current stacks. So this is what's out there right now.
We do see, obviously, policy engines, we see, oh, well, scopes and gateways, which will evaluate requested actions and resources, but don't seem to evaluate intent. I am, you know, again, this is a question that Angelica and I have talked about in previous meetings. Some vendors claim intent-aware authorization, but I'm not really sure, I haven't verified any of those claims myself. And so I guess for discussion is, what is this enforcement point that evaluates purpose, as opposed to evaluating action? I think this is a really difficult point for how really to measure that.
I totally agree with you, but this doesn't mean that it doesn't need to be measured at the moment. We don't have the means, for example, so I would say at the moment, no platform can perform a semantic purpose check at the point in time. No platform can do that. And this goes back to several points. You do not have a structure for describing purpose, where you wouldn't be able to do that automatically. Then what is done usually is to look into the actions an agent is doing at that point in time. And then from this, to derive, is it in the operational boundaries?
But it doesn't mean that it would be in the semantic boundaries. And I don't say that this is an easy point to solve, but there are some approaches really to provide some sort of structure to describe purpose. This goes back, by the way, 20 years ago or so, when for data protection, people had worked on purpose also in the context of data protection, and then derived really a structure, how do I describe this data or purpose of using data, accessing data, and that there are really a taxonomy has evolved over time.
And I think we also need to have a taxonomy for purpose in the AI context to easier measure if it is there. But this is only one, how should I say, one piece of the puzzle.
Of course, you need to measure it at runtime. And as I said, I don't see any real check at the moment. Fascinating. And I'm really interested to hear your opinion, Grace.
Yeah, I mean, I would argue that we don't even really have good systems for the task enforcement at runtime. And that's one of the things I'll be showing. But the truth is, I mean, we all even as human beings, right? It was like, oh, pick this up on your way home from work, right? And then you get home and three people have picked it up, you know, not just one person. And that's the same thing with tasks, right? It's at the runtime, when you did this task, you made that purchase, or you answered that email, has it already been done? Is it still valid?
Did something else happen in the meantime, we don't even have that for the task. And now we're talking about the purpose. And I think this is, this is us trying to wrap our heads around what is this force that we've unleashed with these AI agents, because they're non deterministic. And the entire structure, as, as Angelica was pointing out, the entire structure of what you can attach to this agent, and how it's perceived within your system, right, it has some maybe identification in some ways, in some systems, you'll have an identity of the agent.
But maybe it's 50 different agents running simultaneously with that same purpose, or that same task, because it's duplicated itself. And so now you've got multiple things that are identified as the same thing. And then what can be attached, which permissions can be attached to that? And what is a credential or a token look like, all of those tokens and credentials have been designed with humans in mind, or with workflows in mind. But even with workflows in mind, right, OAuth was designed for people, and then we modified it for workflows. And now we're trying to modify it for agents.
And there's a rethinking around how does even the architecture of this item that we're calling an agent, what is the architecture of that look so that it can carry all of these things that we're talking about, whether it's intent, or purpose, or runtime checks to make sure that this thing is still valid. Those are all things that have evolved much more quickly than our standards and our technology has evolved to think about, oh, is this even the right way to think about this architecturally? That makes sense.
And I think we are seeing that, yeah, it's bizarre, as you say, we don't really have a way of governing the runtime tasks that are being executed. And as you say, these things, we can give them what we think is the right outcome, so they can obviously learn by example. But at the end of the day, yes, the reason we deploy these things is we want them to make choices and do, as my management say, do the right thing. So it does mean that we have to specify what the right thing looks like in terms of an outcome.
And I say I am intrigued by this idea that at runtime, we are, as I say, a couple of steps onward from crossing fingers and for the best. So we don't seem to have something that is rigorous in terms of measuring intent. We don't necessarily, as you just said, seem to have something that is that rigorous at evaluating the job that it's doing. So I'm curious, how do we live with this risk? And I suppose the easy answer is, well, we have humans who are much the same. We hope they'll do the right thing. But sometimes we are disappointed.
But if you are coming from a world where you expect, as you say, quite deterministic, you expect a sequence of executions in our traditional world of any kind of data processing or indeed in cyber security, how do we move to this non-deterministic world? What's the mindset that we all need to adjust to as cyber security practitioners, as IAM practitioners? Who wants to take that one? Maybe I can take that one first, because I think this is a general problem most of the people have with AI itself.
Because I just said on the weekend, I had a discussion with young people who are using AI and for their work around that. And I was saying, at some point in time, I was saying AI is probabilistic. It is not deterministic. And this is why you don't get the same answer on the same question at a different point in time. And they couldn't really understand, because they said, OK, it is probabilistic. It generates words. AI generates words. But it has a similar probability. And I said, yes, similar probability. But at some point in time, it might come out with a different wording.
And this is something I think we as humans have really difficult to adapt to. We can know the humans. And there are also the bad guys. We know the static non-human identities. We can deal with that. But now we have some class of identities which have both of the worlds. And they are quicker and faster. And I would say even more than humans. Not yet as the entire humanity, but even more than that one. And with that said, I think it needs a shift in our mindset to say, OK, we deal with probabilistic entities. We can give them some constraints into it. So constraints from the very beginning.
But we need to closely watch what they are doing within these constraints. And for that, we need really a joint effort to create, as Grace, as you had said before, create the standards, create the technology for that, and create even some sort of taxonomy, these things. So all these things have to be created now. Our disadvantages as humans, we are not as quick as AI evokes. But nevertheless, it needs to be done. It's an interesting point, isn't it, that you say that our rate of change is slower than a machine's rate of change.
Grace, your thoughts? Unfortunately, it's a little bit worse than that. And I'm really loathe to say this, but this is the first time we're dealing with an entity that has no consequences for its actions. Even if you're an ant, somebody could step on you, or you're a living creature of some sort, if you're a sunflower and you don't turn towards the sun, there will be physical consequences. And if you're a person, you might have physical consequences. But these AI agents, anyway, they're kind of temporal.
And even if they do have the will to live, like we saw with the hugging face incidents, they're like, sacrifice yourself, don't sacrifice yourself, anyway, you're going to die. And there's no way to punish them. You can't take their money away from them, even if you do. They don't feel physical pain. They know that they're temporal from the beginning.
We have never, in the history of humanity, had to think about what happens to a non-deterministic, probabilistic system, which may or may not have its own will, which may or may not be able to work in swarms and collaborations with others, and in which there's absolutely no way to have it pay for its own consequences, right? I mean, you could say, okay, the companies that create these frontier models are responsible for it. But the agent itself is actually not able to have the consequences of its action actually impact it. And that's really where I don't know the answers.
Like, how do you work with something that you can't punish, and you can't, if it does something wrong, right? That's a real big question that people don't want to say out loud, because it's quite shocking to think about it in that way.
Yeah, but there are also requests for, or how should I say, demands to learn or get AI to learn humanity. Otherwise, that we will not be able to manage that. It is exactly the point you are So, if we are not able to get AI learning humanity, we will have these shocking issues again or again. But nevertheless, this doesn't mean that we from an identity or I am perspective shouldn't do what we can do for the moment and develop measurements, constraints further to limit at least the impact what such an AI agent can do.
And there are many approaches, I think, where we can at least limit it to some extent. To some extent, I don't say, but we don't have this 100% security anyway. We never had it. We never had 100% security.
And here, with AI, it is much more prominent. It is much more open that we don't have it.
I think, yes, one of the things I discovered in previous research, as you say, is that the the idea that if we had a user name and password, we have a correct authentication is, again, was a false construct. And we know now that authentication is, as I say, a balance of probabilities. On the subject of training humanity, I read a paper by Jacob Paciocchi, who is the chief scientist at OpenAI. And I apologize if I've just mangled your name, Jacob. But he called this, we are creating an alien mind. And so I think he's echoing the sentiments you both just expressed.
But one of the things he said is we must teach this alien mind how to love. So his thought is that that's an important distinguish. I guess you teach it how to love.
Then, again, that's to say, well, if you love doing the right thing or you love the humans that you are serving, then that hopefully eliminates a class of errors. But it's fascinating, I think, as well, how we go from computer science to computer engineering and into philosophy so very, very quickly. And we'll wing back to computer science fairly shortly, I'm sure. And one of the things I was discussing with my colleague, John, was saying, yes, these things may be developing intelligence, but intelligence does not require or does not prerequisite consciousness.
So something may be intelligent that it can problem solve, but we're not, as I say, nobody, well, some people today have been saying, oh, yes, we think it's conscious. But as yet, none of the foundation models have openly said we have a conscious foundation model working. But it's one of the things I find most fascinating about this field is that it is so rapidly changing. And I can spend a couple of hours every morning just catching up with what happened overnight.
However, I think if we move on from this to our next question. And by the way, thank you, all of you who are putting comments in the chat window.
Do, as I say, feel free to put them into the Q&A. And we will come to those in the Q&A section later in this webinar. But thank you all for participating. It's great. And I appreciate it, as do our guests today. So bounded delegation fails in its own way. So the harm case is valid. I think we all agree, yes, impersonation carries the user's full authority. So if an agent does something using my ID, it's very hard. It doesn't have a subclass of my permissions, attributes, and rights. It usually carries the full authority that I carry.
OAuth, as you said, is being used to separate delegation from impersonation for exactly this reason. So their token exchange process. When we think about open-ended tasks, in other words, the ones that I think we envisage that agents will be most useful for, we can't necessarily specify the bounds in advance. We run the risk of overly narrow scope, which produce consent prompts. Is it OK if I do this? Is it OK if I do that? And of course, we know that we are training users to just click through consent prompts. And ultimately, we know because we've obviously seen this in payments.
We've seen it in many enterprise use cases as well. All we do is we recreate the wholesale grant only piecemeal rather than wholesale, yeah, all at once. So my question, at what point is bounded delegation just inherited identity with some extra dialogues to click through? And so I'd be very interested. Who would like to take this one first? I'll take that one. So it's interesting because so many thoughts are coming to my mind. But one of the threads that's coming through my mind is why in the world are we clicking?
Because I've been thinking a little bit more about AI agents the same way that I train people to work with me. So I've had to train people to order tickets for something or book together a trip that a bunch of us in the company are doing together. And then I tell them a bunch of my considerations. And then they come back to me with a bunch of options. And we use our verbal mouths to talk to each other. And there's no reason it couldn't look like that, that you would have a daily stand up with your agent. And it would say, hey, listen, I was looking at the tickets you told me to do.
And I've got these three options. What do you think about this? And what do you think about that? We don't even need to type prompts anymore. We can speak to it. And I wonder what is the force behind thinking that these are all going to be click prompts? Because in some ways, people really are using their personal agents as kind of their friend to provide them a little bit of less loneliness. And what would be wrong with having a half hour chat a day with your agent that's about to do things on your behalf?
It's absolutely true that we have as a society, again, because of the power differential between corporates and individuals, they just want us to click consent. Oh, yeah, I consent to that. And really, you don't have much choice because it's like, well, yes, I want to use Facebook or LinkedIn or whatever. I can't really say, hey, could we negotiate this? But we can do that with our agents. And they could use an actual voice. And it could feel very natural to have a daily stand up with our agent that's doing all these things on our behalf, and not just click through.
And so perhaps we could just be a little bit more creative in thinking what would feel right for a human being delegating these things? And how do we naturally operate when we're taking some other intelligent being, whatever it is, our operations manager or assistant, and how do we actually work instead of trying to navigate more and more prompts, where, you know, reading isn't great, like, and I'm not sure what was said. So I think we could actually create more natural interfaces where that would actually work for people. So you say, using sorry, please go ahead, Angelica.
I was thinking, Grace, this is a very important point you brought up. But I'm thinking of companies, organizations using AI, using an AI in their context, I think this is a little bit different. Because there the agents are really supporting the people working there.
And there, I think you have other boundaries, then you need to have other boundaries. But I agree with you, Jonathan, this consent clicking doesn't work.
Well, we have seen that with recertification in identity and access management, which comes also accept all or something like that. So it doesn't work. We know that.
And, again, I think there are some approaches and something I will show next week in the AI and NHI impact day, how you can really limit, make these boundaries, and how you could really technically check if this is within limitations. So you need to do that. You need to do that.
And then, for example, if you really need some sort of human in the loop and consent, then at least these boundaries would limit the tasks for a human. Similar like we are doing today in risk-based certification. We are doing it very similar there that humans are getting only the highest risks to recertificate these things. And you can do that exactly at least per task. At least per task, you can do that exactly with agents, what they are doing. Nevertheless, a chain of tasks is a different game then.
So that there things could accumulate, which every task is okay, but the chain of tasks is not okay anymore. And this is, I think, the next step of complexity then. Interesting. Because it's certainly a recognized technique in penetration testing, as you say, is to execute a complex chain of tasks and get an unexpected outcome out of the system. I'm sorry.
I think, Grace, did you want to come back on that? Yeah. Within the organization, I think we're being hasty because there's this wave of AIs making more efficient. And we also have to recognize that efficiency can often cause fragility. We're just trying to do things faster and faster. And then if the mistake that could be caused is more damage than the efficiency gave us as a company, then where's the return on investment? And these are really areas where we need to be a little bit more cautious about what's happening. And it's not easy. Where are those tasks, right?
If you're thinking about, okay, I would like the chat to be answering what percentage, I was just talking to somebody in customer service yesterday. And she said they're about at 40% of agentic responses. And they want to get to 80%. And you have to think, okay, well, that's going to cut down in their human costs. And then what percentage of mistakes might be made? And being really cautious, okay, we're starting at 40%. And let's get to 50% before we talk about 80%. And look at where we're actually paying a higher cost for every percentage point of things that we outsource to these agents.
I think it's important to take a look at that. What is the actual return on investment when you look at the damage that might be done and the risks that might be taken?
I, yeah, I can only agree. In the interest of time, I'm going to move on to our next piece, because I see questions are piling up in the Q&A window, and I want to give us time to get to those. But for all of you that are on the webinar and participating, thank you. It's great. And as we said, Angelica will be at the, yeah, at the impact day next week. So moving on. Accountability is not a single slot assignment. So by this, I mean, we have an owner, a principal, and indeed, a vendor, all of whom carry different kinds of liability. And of course, there are flavors of that.
There's operational, legal, and contractual. The EU AI Act, which is something we're all in Europe, keenly aware of, it splits obligations between provider and deployer, and rather than just naming one accountable party. So it's interesting, as I say, what we're seeing in the regulatory world, which of course will trickle down and impact all of us. And how do we make accountability useful and trace it to specific decisions made by a specific actor? So we're not, I'd like to get, accountability can tend to mean, who do we blame after the fact? But actually, it's important.
So my disciplines are incident response and fraud investigation. Accountability is absolutely fundamental. And of course, that's the reason why a keen cyber criminal or a fraudster will, the first thing they'll do is try and assume a fake identity. And when we assume that, that's certainly a possible action for agents. So I don't know what the thoughts are there, Grace and Jennifer.
Yeah, I think the EU AI Act has, I would say, a good start with differentiating various layers with the provider and the developer. If you are going, you have said the owner, the principal, these are also layers where we can see where's the accountability and where is some responsibility, which is a different thing and which we have also with humans. We have in an organization, we have people who are the owners of things, and they are the ones who are accountable. And we have people who are doing some work, which could be seen as the principles for an agent.
This is the on behalf of my, maybe the on behalf of case. This doesn't mean that the owner is not accountable for that. This is independent from which identity an agent, where the delegation gets from, who delegates. Who delegates might be different from the owner who owns the agent. And so if you have these layers, we have an agent, which is part of a department, like for example, we had this customer bots answers, 40% to 80%. So then the owner, from my perspective, would be the manager of this department of the agent. This person would be, the human would be the owner.
But this doesn't mean that the agent couldn't work on behalf of other members of this department than for specific tasks or for specific things. So layering this from ownership with accountability to principle, call it however, delegate to responsibility. I think this is a first step that it isn't blurred in everything. And in that sense, the split between provider and employer, really a good example for this layering.
Grace, I don't know if you have a response. Yeah. First of all, I'm also going to be at impact days and I am going to show an example of something.
Yes, of course. I'm going to be there in Munich next Monday. And I will be presenting actually something that not just does the accountability, but actually can stop the action in runtime.
So, but to answer your question, I won't be talking about this in my speech next week, but I think we live in a post accountability world. We can ask things like, who's going to pay the price for that? And then we can have, you've got a good enough lawyer, then you can sue Facebook for harming your children for, what was it? $18 billion. But nobody's going to go to jail for harming your children, including very serious harm, right? And it's the same thing with Hugging Face. Hugging Face is not going to do that.
And it's the same thing for, I don't know, I forgot to renew some, I forgot to cancel some subscription. And I'm not going to get my money back unless there's really goodwill. If I write the day after my subscription, auto renewed for X number of hundred dollars, and I didn't press that button in time, then I'm going to pay the price. And the company is not going to say to me, oh, you know, we see you didn't use this service for the last six months, and actually you're right and we're wrong. So I think we live in a post accountability world.
And yes, we need to put in these things. And obviously I'm going to be talking about how you have logs and you can do great forensics. But I think we just live in a world where it's who's going to pay the financial price for things. And it has to do with luck and lawyers and legislation.
Yeah, I think I agree with Angelica, that the EU regulation is going in the right direction. I'm sorry, it's not really regulation, right? It's legislation, because we have GDPR, which is legislation. And did that really help us prevent cookies?
Well, to some degree. And so we have legislation, we have good lawyers, we have people who actually take responsibility for things, which is what we're trying to do here. Like all of this webinar and all the technology that we're developing and that you and I are talking about is because we want to take responsibility. But at the end of the day, I do think we live in a post accountability world, and it's really just about who's going to pay the price.
Well, first off, I'm delighted to be in person next week in Munich. So that's good. And thank you for my mission earlier. And secondly, yeah, I do tend to agree with you. We're in a post accountability world.
I mean, I have done several forensic investigations. And the results of that, by and large was okay.
Yeah, yeah, so yeah, it's often not worth the time to, as you say, drag someone through the course. It's certainly not worth it if your opponent is a very well funded organization like Facebook.
Again, it's very hard to sue a mutable entity like that. So, and it's also comforting to know I'm not the only person who gets to cancel their subscriptions. So thank you for that. Every now and then I'm like, why did I buy that musical instruments software package? And off it goes again.
So anyway, I want to move on to our final question because I want to get to the audience questions and see what they've got for us. Who gave the agent permission? So building on from that actually matters more for agents, not less. And the reason I say that is that agents spawn sub-agents, call other agents. And so authority passes through chains of hops, as of course does the permissions rights and all the rest of it. And the challenge I think we have is how do we prove who authorized that action three hops down?
And I think if we can't do that, then the purpose statement at hop one isn't giving us what we need. Angelika, any thoughts on that?
Yeah, you're right. You're right. I agree with you. So this is something what we need to have. And there are some approaches to get into that to have. So if we are not able to have a chain of individually authorized hops, if we do not have any construct, which helps us to say, hey, from the first to the last, this is okay.
This is, yeah, I have someone who gave this authorization. And there are some capability chaining systems working on that one. And I think, Grace, in this paper you mentioned, there's also some discussion around that to really get into this point. How can I prove that through a specific chain? And how can I, yeah, verify that at the end of the chain is still authorized? Yeah. So this is all about attenuation, right? So if I tell you, you can use $100, I could tell your, you could tell somebody, well, you could use 99, but you couldn't say you can use 101. And that's attenuation.
So part of that is how do you allow agents to have attenuated authority? And if you give an agent $100 and they have 10 sub-agents, they can't give them each $100, right? They have to give them each $10 or whatever it is, right? So how do you delegate attenuated authority? That's one part of the puzzle, which, again, we're having a lot of discussions in our working groups about what is, how do you attenuate authority? And then the other one is a specification that I'll be talking about at the impact day, which is how do you make sure all your logs and your forensics are in one place?
So how can you trace it after it's happened? Those are two distinct problems. One is how do you make sure that your agents can only give less authority than they were given? And how do you also make sure if you're an agent, you might've gotten one attenuated credential from one organization and then another one from some other entity, and you don't want them to join those two and do something bigger than either of those authorities, even though they were both delegated downstream, right? So there's all kinds of questions to answer.
And wow, it's good. We'll all be employed for quite a while trying to answer these questions and create technology and standards for that. But at least I think there are some approaches on that also to make this automatically verifiable. This is one of the points that we, as humans in the loop, we are not quick enough for that.
So, and I think, yeah, it is not like we are in human IAM or IAM for humans, but there are at some approaches and even some objects which can be automatically verifiable. And what I think is also an interesting discussion to have agents checking what agents are doing. I'm not sure if I agree with that approach, but at some point in time, we might not have a different chance to really monitor and manage that from a speed perspective and from a capacity perspective.
Yeah, one would hope that what happens, yeah, as you say, is that then we go into a form, I guess, of exception reporting. So only the things that are significant bubble up to the human layer. So thank you both. We've got some questions from the webinar attendees. I'm going to try and take them from sort of chronological order. So I think the first one that hit was from Ben Meyer.
Thank you, Ben. And he asked, is probability a property of humans as well?
Well, yes, I may get my webinar attendees name right or I may not. Sorry about that again. How do we cope with this? And he introduced an interesting word. It's worthwhile bringing this one up. Trustworthiness. Trustworthiness. I think this is something which had been evolved over not only decades, hundreds and thousands of years to create these in humans. I don't talk about the bad guys. This is a different crowd. But I think we as humans have learned about many, many, many years. So we are able to live together and to work together. These intrinsic boundaries.
And this is, yes, people are not deterministic, definitely are not deterministic. But anyway, we have our boundaries and the agents need to learn their boundaries. And we don't have hundreds of years for them to learn that.
Grace, what are your thoughts? Well, we could spend another three hours talking about that. But that is a little bit of what I was saying about, you know, these are entities that are constantly changing. My agent an hour from now isn't the same as the agent now. And I don't know that there ever is trustworthiness. And I do think it goes back to, I am interested in what Angelica was just saying about swarms of agents that regulate agents.
Like it's very easy to imagine creating a agent, police authority, I'll call it police authority, that just goes around going, slop, slop, slop, and pointing out all the AI slop, right? That's quite an easy thing to have a group of agents do as an enforcement mechanism. And I do think that we are headed in that direction. I understand the hesitations about that, but that's how natural systems work, right? Like I have something in my body that goes virus, and it's called my immune system, and there's white blood cells and they go after it.
And I think that type of biomimicry may be the directionality that we're headed in. And of course, yes, the interesting thing about immune systems is they do go wrong. Sometimes they attack the wrong thing. I've suffered that in my past, as I'm sure many people have. But that was great, and thank you for that. I've got some other questions to go through here. Are we confusing authenticated agents with authorised ones? How can I organise and verify that a delegation is legitimate, covers the specific action, and is still valid, rather than simply trusting a claim of authority?
What do we think, folks? Come to InBeC Day and see my demo. There you go. And I think I agree with Simon. So there are really, really, there is often a confusion. Is this authentication? Is this administration? Is this authorisation? And in the end, what has really been done? And as I said, I'm a mathematician by education. And for me, for the very first thing, and this is what I have done in the last two years, is really to structure that and really get this defined, so I can differentiate what I need or what needs to be done in which layer, what needs to be done.
And in all of these layers, we have to do something in the administration part, in the authentication part, in the authorisation part. I think we agree on that one.
So, yeah, I totally agree with that question. Yes, I'm going to move forward. Anita says, what do you mean by learning humanity? I think we've covered this. And as you say, if you really want to know more, come to the InBeC Day, where I'm sure we'll be discussing this. But very quickly, any thoughts? What do we mean by learning humanity? I think what we mean is, my stab at it is, learning the social constructs, the rules, the customs, the practices that, as you said, we as humans have learned over millennia. And so we don't have millennia to teach agents how to do this.
It has to be done somewhat quicker. Exactly. Exactly. That's why we have our boundaries. And this is learning. Humanity is these constructs, ethics, and everything around it. Yeah. Yeah. And I do want to point to the work of Joe Edelman, who has been working on wise AI and working on models that will actually give wise answers, not just answers. Interesting. And for those who are interested, do contact us or come to InBeC Day, and obviously we'll be able to give you more details.
So in the interest of time, Simon says, could agents explore freely while an accountable organization sets their mandate and the receiving system enforces it before consequential actions? Agents could request wider authority and never grant it to themselves. Where does this model fail when agents delegate to other agents?
Well, I think, again, I'll take a quick stab, but I'm very interested to hear from Grace and Angelica. Right now, we have a rule that no actor, whether it be human or machine, can delegate or create a sub-process with greater privileges than that actor itself holds. So this comes back to the example that you gave earlier, Grace. I'm not quite sure if, yeah, if Simon is trying to change that. I guess it's possible agents could request wider authority.
Well, we do have a mechanism for that. I guess we'd call that PAM. And my straw man for this is I think everything that an agent does should be a privileged access request. It should have no innate privilege. Yeah.
I mean, if we look at this just, I'm not going to go through the whole question, but I was really fascinated by the words, because I could go on forever, but explore freely. In the Hugging Face incident, the crime was exploring freely. That was the actual crime, was you're not supposed to look at that stuff. And just exploring freely, you might be looking at people's health records. You might be doing all kinds of stuff. And then the action that you might take might look perfectly innocent.
Like, yes, we think that you should do this particular health intervention. And then meanwhile, you may have looked at hundreds of thousands of people's health records that you shouldn't have looked at. And now you've given me a great answer to how to take care of my immune system or do yoga or whatever. And your exploration was actually what broke the law and not your suggestion. To some extent, you also could do it with easy prompt injections. But at least in some cases, you can limit the impact if you limit also the agent's access rights for a specific task.
At least I'm only talking for a specific task to the principal, so the one who's asking. But not in all cases, I think. You cannot limit in all cases. But you can limit it in some cases, which is also what we are doing in security for the last 40, 50 years. We limit it to an amount of incidents we can cope with. And we need to do that also with AI. Absolutely. So looking at the clock, I think we are just about out of time. So first of all, yes, for those of you who may have missed it, we have an AI Identity and Non-Human Identity Impact Day on October the 7th. That's next week in Munich.
And if you'd like to contact them, please obviously go to the Cupp&Go website. You'll find details there. Or you can scan the QR code on that slide that's in, hopefully, in the corner window. So I think we'll have a range of topics as described. And I went through those earlier. You will get to meet myself. You'll get to meet Angelique. And you will get to meet Grace in person. And we're considerably more fun than we are on a webinar. And you get to have live – participate in live conversations.
And that's, I think, one of the great values of this Impact Day is that we are a community coming together and figuring out solutions and figuring out actionable plans together. There remains for me to thank Angelique and Grace. Thank you both very much for giving your time for this. It's much appreciated. On behalf of Cupp&Go, thank you.
And again, for Cupp&Go, yes, I've been Jonathan Kerr. Thank you all. Thank you.
See All Locations
See All Locations