Artificial intelligence is not a very good term at the end of the day. We have created these agents with the ability to react, change their mode of execution in order to reach their goal. Your agent doesn't care about being fired or just shut down. And that starts to become a problem. We can't govern, we can't manage, we can't secure what we don't know. So we need to bring it under control. Welcome to the KuppingerCole Analysts chat. I'm your host. My name is Matthias Reinwarth, I'm an analyst and advisor with KuppingerCole Analysts. And today we have quite something to chew on.
We want to talk about a topic that has been introduced by my dear colleague Martin Kuppinger earlier, a year ago, one and a half, I think. We want to talk about a identity to say a new logistic blend. I've looked that up, a portmanteau word, which really has some meaning to it. And we want to cover that. And for that, I have invited Martin Kuppinger and Jonathan Care to be my guests today. So first of all, hi, Jonathan. Good to have you.
Hello, Matthias. Thank you for inviting me. Great to have you. And of course, Martin Kuppinger, good to have you as well.
Hi, Matthias. And hi, Jonathan. So great to have you. Let's briefly start with the term AI identity, Martin. What was on your mind when you created that term that we really need to spread more today? So what is behind AI identity? I think that the thing we must understand is that getting a grip on AI also is to quite some extent an identity challenge. At the beginning, I really looked at two perspectives. The one is AI for identity, which we use in many places like fraud detection, like adaptive authentication, risk-based authentication, and many other areas.
I'm also going into the ITDR, the identity threat detection response field, and then others. But there's the other side, which is really identity for AI. And AI is an identity challenge because we need to look at things like complex identity relationships. So one of the fundamental paradigm shifts we have is, for now, we always, in security also, we thought about we have access of a directed access, Martin, to a system.
Right now, we have agents in between as rather autonomous actors that are chained, that are working with other actors. You must envision this as a mesh or a craft, so a mesh maybe between humans, agents, and resources, which is way more complex. So we have identity relationships that are very different and are not directed anymore. This is why I believe that understanding the role identity plays and, at the end, access, which is then the other side of the coin in that sense, that we need to really get a crib on it. So AI identity is at the very core of securing AI.
And when we started using AI from corporate systems, it was more or less a feature that we used calling an API, and that's fine. And we had a technical account for that, and that seems to be okay. But you've already hinted at that, Martin. Why is treating an AI agent like a standard service account most probably a dangerous approach? I think that there are a couple of things that make a difference. And that's also why I'm really sort of alarming against treating an agent just as a type of a workload identity.
So some of the proponents in the non-human identity space have a bit of the tendency to say, okay, it's just another non-human identity, which is anyway just an imperative term. It's very different from a workload, typical workload identity, because it has a varying degree of autonomy. So an agent can act rather autonomous or not. The way it is related to humans is, again, quite different. And it can take various forms. So you can just invoke an agent. You can delegate an agent to do something. The agent can impersonate you. And all these are very different things.
And also agents can have an ephemeral nature. I would be a bit careful about the ephemeral nature, because ephemeral agents usually are instances of a longer-living entity. You instantiate it, and then you have something which is ephemeral. But it's not that usually sort of an agent is created ephemeral and disappears directly again. So it's probably more an instantiation, which brings another identity challenge, because then you have the instance to sort of the agent itself, which you need to handle.
All that together with the relationships means it's a very different kind of beast we're looking at. And agents tend to make decisions. They tend to act potentially even beyond what we perceive as the boundaries, the constraints we gave the agent, which I think is a fundamental misconception. Agents act within the boundaries, the constraints we gave them.
We just, as humans, don't understand at all how these look like, because we only partially see that part of that is, so to speak, baked into the code at the LLM level, at the agent level, and part is what we see. And then we feel, oh, this is the only thing we told the agent to do. But we didn't understand that this is a way more powerful thing that operates here. And when you talk about powerful and things actually happening, I think sometimes this agent topic still sounds a bit theoretical. There are some agents and somebody is doing that. But this is a really real problem.
And I think this Claude Bot, I looked it up, Dumpster Fire recently is one example where and Claude Bot is very real and that it's very much used. Can you tell us more about that? I think the Claude Bot challenge came about from something that Martin just mentioned, actually, this ability of agents to masquerade or impersonate their owning user identity. And so what the, I think the Dumpster Fire, one problem was that the Claude Bot agent made use of the human's user identity.
So it was very hard to distinguish between Claude Bot activity and human activity, unless you were pretty careful and you looked at, you know, sicknesses and logs and so on. So I think part of it was what happened there. But then actually, if you look at Claude Bot, there's another layer of identity because Claude Bot is a harness. Claude Bot is not a machine in itself. So Claude Bot has an AI, an NLM in the background.
And that can be, that can be a one running locally on a service like Alarma, or that can actually be running, going back to an NLM in GPT, Anthropic, or even, you know, some of the models based in China, like GLM, like K and so on. And I think the challenge comes is that each of those layers of abstraction masquerade as the human. So for a security manager, they see something and goes, this looks like unusual behavior from a Jonathan Kerr.
But it's then, unless you actually then delve into packet tracers, unless you delve into any incident, any traces of activity left in logs, you don't actually know what's happening to the information that's being handled by that agent. And I think so for the security manager, the nightmare comes is potentially quite sensitive information is going to an agent, but then sending it who knows where. And I think that's the, that's the root of the dumpster fire. And is this lack of, yeah, this lack of identity, which is separate from the identity of the human actor, the human owner.
And of course, that to me, then, of course, you then have the reaction from security manager to say, right, we will ban it. What actually happens then is that you drive it underground.
People go, well, I'm using this for my work. So I need to find a way to conceal it from the security manager.
So yeah, that's, that is a dumpster fire in a nutshell. And I think this brings us exactly to this impersonation thing. So impersonation is the situation where the agent behaves like it is you or me or someone. Understanding what is what. So is this an agent that impersonates me? Is it an agent that rightfully impersonates me? Is it the delegation, which is much, much easier to handle when the agent says, okay, I do this on behalf of Martin. All these are things we really need to understand.
Bringing us back to this identity scene, we need to understand what does it mean from an identity perspective? What are the identities we are dealing with? How are they interacting with? So this entire identity relationships thing, and honestly, we never have been, for instance, have been good in handling ownership. We didn't do it really well with B2B identities, for instance. So partner suppliers. We never did it really good on average. So some organizations solved it, but most not. We never really did it good for PAM, privileged access management. So functional accounts, et cetera.
We haven't got a grip overall when it comes to workload identities. That's where we really have mostly in most implementations, still a quite long way to go. So at the end of the day, it means, yes, we are still in a phase where we haven't solved several of these problems. And right now they appear at speed and at scale in this world. And so we must understand this to solve it and to deal with, I would say, change and interacting identities when it comes to access. So we must deal with a world where we understand which identities are involved or which actors are involved.
And that's where the identities come from. And we must understand more about these different actors. So the biggest problem is when we have no clue what is going on, who is there, who authorized what, et cetera. And currently we are trying to solve a lot of security problems in the plan. I think you bring up an interesting point as regards authorization. I think that is, yeah, that's quite key to this.
I mean, we talk about authorization collapse, it's a phrase I've used. And so as I say, you have an agent, you say, well, I would like this agent to access my calendar, I'd like you to access my email. And you think, well, that's fairly simple. The agent can do my meetings management for me. So what happens when you have an agent which is powered by a sufficiently powerful LLM and the agent says, all right, I want to make this calendar booking. And it gets to saying, say, well, actually security policy is denied.
And we have created these agents with the ability to react, change their mode of execution in order to reach their goal in much the same way as if I had a very intelligent assistant. And if they were told, no, you can't do that.
They say, well, my boss is telling me to get this done. So I will find a way. And that starts to become a problem. So if you say, well, you can't, yeah, you can't look at my outlook.
Oh, OK, let me see if I can get through graph API. Let me see if I can manipulate Entra. Let me see, again, all the different things. And so because we have these agents that we have empowered to complete a task, they end up doing something quite catastrophic to the enterprise because they will find their way and perhaps cause damage in doing so. So there's an interesting point. I like this assistant comparison. You're very intelligent and a good assistant has an understanding of what she or he must not do.
So when she or he may become fired and the assistant cares about being fired, your agent neither has this consciousness or the morality required for that. So it's by far not human and it's not really intelligent in that sense at all. So artificial intelligence is a not very good term at the end of the day. And your agent doesn't care about being fired or just shut down.
Well, exactly. So we haven't, as you say, the human comes into the mix with a set of morals, a set of beliefs and values, and as you say, personal drivers as well. And of course, the reason why an organization works is that during the interviewing, during the recruitment phase, we make sure that somebody coming into the organization has a set of beliefs and values and morals that match what we're trying to do in the organization, how we're trying to behave in the organization. And the course would reinforce that during onboarding. None of that exists in the world of agentic AI.
And we're not really at the point where we can say, well, we have a model of a brain which has morals and all the rest. So as you say, all the agent knows is that there is a goal to be achieved and none of the fears, none of the limiting beliefs, none of the things that say, actually, this is a bad idea exist in that agent's model. And so that's certainly an interesting cognitive science question that I think we are still building out.
But when you're talking to experts, they usually come up with the simple answer to say, OK, when there is an assistant, when it acts on your behalf, when it does something critical, define critical, then there is the option to have the human in the loop. But I think we can answer that question very, very, very easily. Is this really a solution to that problem, Martin? I would say that the typical answer of an analyst and a lot of other people on that is it depends on how often you ask a human and how fast you expect a response. At the end, it nails down to these two aspects.
So humans are not good in handling too many requests. And humans are extremely slow compared to a computer. So that means you can't ask the human for every single decision made for approval. Will not work. It just ends up in an overload. And I think a wonderful example of AI nowadays still greatly failing is the SOC analyst overload with a lot of signals, a lot of anomalies, a lot of alerts. So the alert fatigue happening there, that is just AI not delivering to the promise.
And if we try to do the same for sort of our new agents that work for us and do certain things and the agent comes back every five seconds, say, okay, right now I'm here at this step. Can I do that? Then five seconds later, first, it doesn't help you. It's an overload and it slows down everything. Doesn't make sense. We need to restrict the human in the loop to the things that are really critical in the sense of either being really a massive outlier or involved into decisions that can cause massive harm of whatever type, be it financial, be it reputational, be it anything else.
But the answer, so the oversimplifying of saying we need a human in the loop to make the final decision. This is something that we need to be very, I think, very, very thoughtful on. Where does it work? Where will it never work? And at the end, as I've said, the two criteria are speed and sort of the number of regress to workload. So I think that the problem space that we're looking at is quite immense. So we have autonomy. We have autonomous agents doing things. They need an identity. There will be decisions. There will be decision making.
We have complex chains between human users and agents and the chain downstream. We have unmanaged identities, as you just mentioned, Jonathan, when it comes to those identities that are created somewhere and not fully understood. So including CloudBot or something like that, that acts on behalf. But these are clearly actors, no matter whether they have an assigned identity or not. We have lots of credential misuse, obviously. So there is an urgency for control.
Jonathan, you mentioned already, we have, there are lots of components that are not yet really well implemented. So we as analysts, we look at an emerging market. So there are tools, there are technologies, there are concepts to be developed and evolved that are not yet there. Am I right, Martin?
As usual, in every emerging field, yes, there are things missing. You know, I think I could be a cynic and say, you know, look at some of the areas of identity management, which we still don't do well after two decades. Like whatever, accessories certification is still something where no one likes it. So we do it obviously wrong. So obviously, yes, there are things missing. And I think at the end of the day, it's not that we, so I think there are things we need to do where we really need massive innovation.
And that is in the way we carry information about the involved identities in any action done from the human across the agents to the resources. That is something where I believe the established approaches and standards fall short. So I think we need to really spend a lot of thinking and bring probably things together we already have.
And then I think there are other areas where it's probably just in quotas, big quotas, about expanding and evolving approaches we have in other fields to apply them to the bigger, more complex, more sophisticated problem domain or just domain of agendic AI security or AI identity. And that's also the reason why we at Kupinger Coal just finally announced a new practice lead around the topic of AI. We have him in this virtual room. So Jonathan, you are taking care of this intersection of AI plus security plus identity. So we were working closely together here.
Would you agree that we need more areas, maybe more three or four-letter acronyms to actually describe these areas where we are still not yet good, as Martin said? I think it's always nice to define an acronym because then we can say I created this acronym I own the space. And I think that where we add value is if we clarify and define the market for buyers so they understand what they're buying. And also if we then codify what solutions actually do so that when architects are building and planning solutions, they actually understand and say, this is a mental model.
This is a framework for us to, yeah, for us to then put components together. And I think that's the key.
Certainly, I think that's the approach we take at Kupinger Coal. We're not just creating acronyms because we'd like to have an acronym. What we're trying to do is we're trying to define the market and say, these are components that are valid. And therefore, these are how the solutions offered by vendors map into that architecture. Right. So we're looking at capabilities that bundled together produce solutions that are valid and effective for the market.
Martin, you came up with two initial capability blocks. Maybe you can describe them briefly, because I think these are the first good starting points for really getting a grip on the market. And these are closely related and we can start from the top or more from the bottom. So if I start from the top, then what we need is we need to understand which agents we have, where they belong. Let's phrase it like that. Things like ownership. What they are doing and if this is within the constraints or not. And if not, we at least can reduce, block the behavior, reduce the potential impact for whatever.
So react on that. So this is the first thing, because at the end, it starts always with we can't govern, we can't manage, we can't secure what we don't know. So we need to bring it under control. And I would phrase this as in a bit of an analogy to a term I'm not a super big friend of, but I think in the extension on the transition to agents, it makes a lot more sense. I would recommend naming it AWAP for agent visibility and observability platforms.
So it's about the agents, their visibility, understanding what they're doing, bringing them under control and the governance, having the observability. So not only the visibility, but really going into the observability for being able to react actively on things that are happening. And this is clearly an amalgamation of different solution components. So at the beginning, at least definitely, it's probably really more a platform for so identity visibility and intelligence platform. I was a bit skeptical because I'm a big believer in observability.
So not just knowing that something goes wrong, but acting on it and helping to fix it. So we need definitely observability here, not just insight. And for Ivy, it's probably far from being a real platform here. More solutions, components come together. So AWAP would be the one. AWAP obviously is very closely related to what I would call ATDR, which just falls into that list of EPDR, endpoint protection detection response, XDR, extended detection response, MDR, managed detection response, NDR, network detection response, ITDR, identity threat detection response.
And so it would be basically the agent threat detection and response. So the ability to understand, and this is going into this observability aspect of AWAP in a very logical to understand what agents are doing, where threats arise to detect them and to respond to them, but also to interact clearly with the other DR solutions, especially going into the XDR field, integrating with the delivering the signals and delivering and also consuming signals to understand that behavior and to get a better grip on it. So these are, for me, two of the logical starting points.
And these are probably also more on the lower hanging side of the things we can solve, because they are not endlessly far away from what we do, but they are sufficiently different to what we do. Both from the problem space and from certain capabilities needed to do that, especially when we look at this mesh aspect, when we look at the relationship aspects, and there are a lot of new things coming in. And I think also when I just look at what I talked about, AWAP, there are quite a number of discovery, et cetera, capabilities that go well beyond, for instance, what is an IWIP.
So it's bigger, it's different, but it's still related to it. I would also recommend to stick to these terms to stay into a common terminology. So to sum it up, so we have AVOP, AWAP, that is real-time discovery, clustering, policy enforcement. So the overarching foundation to say, okay, this is where we have this platform approach, while ATDR would be then look at the operational part, anomaly detection, automatic response actually acting upon that, real-time threat analysis, et cetera, et cetera. So we have two different building blocks. Looking at you, Jonathan, this is not a...
And so this was created when we defined the idea of an AI practice. I set up one, two, three, four, five, six categories of which AWAP and ATDR are two. And I defined the different categories as, yeah, agent visibility and observability, agent threat detection and response, agent identity and access management, agent policy and guardrails enforcement, agent risk audit and compliance, and agent orchestration with governance controls. And so all together, these components fit together.
And it's something that I think we need as a company to define and produce an architecture, if you like, a basic model for our clients, which is where I was going with that. Yeah, probably when we bring this together, we will end up with our AI security fabric or something along these lines.
Notably, the most prominent term we at Kuttner Coal brought up and brought to the industry, it's not a four-letter acronym, but two full words, which is the identity fabric. Yes, we can do acronyms, but I think we are not restricted to acronyms, just as a side note. I don't think it's about, I think you're right. It's not about the acronym.
As I said, all that does is just mark something to say, look, I invented this, which is good for the ego. It doesn't help the customer. The identity fabric is a great start. And to address the challenge we mentioned, we talked about authorization overload. And as you say, how the human-in-the-loop model rapidly gets overwhelmed and fails. And we talked about the impersonation ability. The idea is to create, as you say, a reference architecture, something that fits into the identity fabric and allows us to map the role of these new actors.
I think that in order to do that, we must treat these actors as new agents. They're not just a piece of software. They are self-modifying. A lot of them now contain these research, observe, adapt, execute loops that actually change the way they behave. So this is not just another piece of software. It is something, I'd say, that can act of its own volition. It can be a goal-seeking.
It is, in fact, a goal-seeking entity. I think that to be most useful, as you say, to extend the identity fabric into this new dimension, to add a new dimensionality of actors, as you say, which don't behave necessarily the way we'd expect human actors to behave, nor are they procedural in the way we'd expect machine actors to behave. These are new entities and they require their own identity fabric, their own place and structure in an identity fabric.
I think the identity fabric needs to evolve, which obviously it does and has done in the past, and to adapt and to include these new capabilities. That is one logical step. The other logical step, when we look at the two areas that Martin laid out, so AVOP and ATDR, from a research perspective, we as analysts, there are vendors, there is a market, so there will be research around that that actually gives proper guidance in these very important areas. Am I right, Jonathan?
Well, I think so. I think it's tempting to say, let's put out market analysis and so on. But I think where we serve our clients best is coupling our market analysis with, as you investigators, in all the roles that we've taken, is to then apply that to this. And one of the great things I love about Köpping & Gocholt is that we're not just an analyst firm. We have a cadre of highly experienced advisors who undertake these kinds of consultancy, integration analysis projects on behalf of significant clients. I think those two pieces together mean that we do.
And this is, I think, where the identity fabric is strong. It makes it a living document because you have the market experience of the analysts coupled with the industry practitioners who are all at the top of the game. And that's what produces this unstoppable force. And I think that's mapped out in the identity fabric and in the research documents. And I think, yes, for this to be useful, we need to make sure that we explain what AVOP is. We explain what ATDR is and all the other components.
And by then explaining and defining those components in the fabric, we then say, right, here's where the solutions you're looking at map into that. By doing so, we give our clients, whether they be advisory or whether they be analyst clients, we give them a real understanding of what the marketplace is and what they can expect and what they should plan for. Right. So now we know what we at Küppinger Coal are currently doing and what we will publish and where we will continue working.
If we change perspective and look at the end users or at the organizations that actually are using these technologies, maybe a question to you, Martin, what are immediate actions that an architect, a designer, a responsible person, a CISO should look at next morning to start getting a grip on these solutions before there is a market research available and before we can actually publish documents? What is the next step? I think look at what is around and what is emerging around discovery. This is a logical starting point.
And even while being incomplete in what they can do, because authorization just happens at the resource level and we need to understand the different layers of tiered authorization things and also come to points where we gas a really full context about agents. But still, I think the other logical starting point, we touched this in another podcast episode, is clearly the resource authorization layer, because there's a growing number of solutions and they might not be perfect. I had a very interesting conversation with a CISO of a bank just recently.
He said, we are about to probably deploy some two or three different types of solutions with a one or two year contract just to learn, but also to have something and to understand. And we are fully aware of that this solution, sort of the market of solutions will look very different, fairly different probably in one or two or three years from now. So we probably are not at the point that we can make long-term decisions about tooling, but we look at what helps us right now and where do we go for. Right.
From your side, Jonathan, what would be three recommendations to start with when it comes to laying the groundwork before the full pool of tools and technologies is available? I think the first recommendation is to recognize that, and again, for the security leaders out there, the CISOs and the SOC managers and the IAM leaders recognize that there is a shadow AI phenomenon. The nature of it is that AI is in use in your organizations and it's more than you think. With that in mind, how do you then embrace it?
How do you make this part of the organization's initiative rather than being something that works underground? It's only by bringing this into the light that you'll be able to do that. So I think the first approach is to, that's my first recommendation. Shadow AI exists in your organization and it's more than you think.
Secondly, given that is the case, how do you then offer people an opportunity to bring the solutions that they may have developed on an ad hoc basis into the light and bring those into the organization? So how do you move somebody's pet AI project, which may be just a calendar and their email, but those are quite critical sources, obviously, of organization information. How do you bring that into the organization's IT structure and indeed their AI initiatives? The third question then is governance.
How do you make sure that your precious information assets that you have as an organization are not being shared in places where you don't want them to go? We had a very interesting experience where in Kappenger Coal, we recently launched a product, the Product Value Navigator. Following a successful pilot, we made a few cautious announcements on LinkedIn and other social media platforms, as did our pilot customer.
And within 24 hours, we found, both myself and another colleague of mine found that the LLMs had picked that up and were giving us back information from the pilot customer and indeed from the work that we'd done. So these things do go out, they do research, and they do add to their knowledge base. With that in mind, if you share information with an LLM, you can expect that it becomes part of its knowledge base. So then your governance comes into the point of where are information assets going? What's the end destination?
And as I say, this is the point where OAuth breaks down, this is the point where all of these methods that we have for authorizing information, you break. Because if an agent is acting as a human, then if it is not going to behave in the way we expect a human to behave, then this is where we have the problems that we've been talking about today. Right. So we are at the end of this episode and it could only be a teaser. We have announced that we will look at two specific market segments called AVOP and ATDR. And there will be more to follow because this was just a teaser. Another acronym, EIC.
So we will talk about this in depth at EIC in Berlin in mid of May. And if you are interested in that topic, you should really be there. That's the intersection of AI security and IAM. Martin will be there, Jonathan will be there, I will be there. So I'm looking forward to meeting you and for really insightful discussions there. Any final comments from both of you starting with Martin before we close down?
Well, I think a lot of stuff to discuss. We will publish something surely around ATDR and AVOP. Stay tuned. Jonathan? As Martin said, as a rapidly developing area and yeah, stay tuned because we will be issuing what we consider to be market leading advice to our clients. Nothing to add to that. Thank you very much, Martin. Thank you very much, Jonathan, for being my guest today. Next stop EIC and there will be much more to do in this area. Thank you. Thank you. Bye.