We need to be very careful when we look at existing approaches and whether they really work because it's different to say Martin has access to SAP, that's the past, or even Martin uses a functional account to access a database is still very directed and very deterministic to Martin does something which triggers a mesh of agents and some agents at some time end up at some resource servers, knock on their doors and say, I want something. There's nothing directed anymore, there's nothing deterministic anymore.
And also to be very clear, your resource server does not know who will be knocking on its door in the next minute and ask for something. Welcome to the KuppingerCole Analyst Chat. I'm your host. My name is Matthias Reinwarth, I'm an analyst and advisor with KuppingerCole Analysts. We have a special episode again this time. We want to talk about a topic that is called AI Security Fabric. So if you stay with us, by the end of this episode, you will have a first overview how a nice, proper approach towards an AI security fabric infrastructure architecture should look like.
And since I'm not capable of doing this alone, I have invited two really experienced people long in the business, both working with KuppingerCole in different roles. We have Martin Kuppinger and we have Darren Rose here. And I first introduce Martin because that's easy. You know him already from other episodes. Martin Kuppinger is our distinguished analyst. Hi Martin. Good to have you. Hi Matthias. Pleasure for inviting me again. So looking forward to this talk, given that we created many years ago, the original identity fabric.
This is where this entire identity fabric thing started and you and me, we both were involved in that. So I'm really looking forward to seeing about how the AI security fabric should look like. So I don't start now thinking, but I think it might be also very interesting to see what evolves from that talk. Right. Exactly. And a person who is for the first time with this podcast is my colleague, Darren Rose. I don't say too much about you. Maybe it's easier if you introduce yourself. Hi Darren. Good to have you. Hello there. Yes. Good. Good morning. Good afternoon, gentlemen.
Great to be with you. Obviously, I've had a long working history and identity in a very close association with you guys. As you know, I'm an analyst fellow, which means that, you know, I still work with you guys on, we're very much with an analyst hat on. I've obviously had a history in, in vendor space with, um, uh, sale point and wave set and others sort of helping in the identity governance space. And now I'm, I'm do a lot of board advisory and I'm general, general troublemaking, uh, in and around identity and particularly interested in this, this topic of an AI fabric. So great to be here.
Great to have you. And I think you both, Martin and Darren, have a, have a long common history and different roles coming together, um, over the years. I don't ask for the number of years, um, but we can imagine, I'll assume. Yeah. Let's just say we're OG. Right. As they refer to it in America. Right. Okay.
So then, then let's start. So, so, um, we want to talk about the AI security fabric. So there must be a reason why we do this just right now. So we hear a lot of alarm about AI security in the news right now. And before we go into solutions, AI security fabric, maybe. How bad is it really? Maybe to both of you, starting with you, Darren, is enterprise AI security in crisis or is this just noise and news and buzz?
Well, I think it would be, it would be all of the latter there. I mean, it's obvious there's a lot of noise, there's a lot of buzz. There's a lot of happening.
Um, and interestingly, a lot of the driver for the adoption of AI is coming from the top of the organization, from the board. I mean, we very frequently hear the board says we should, um, which is fascinating because does that board truly understand the security implications of what they're doing? And so I think every organization today is answering the question, what is our strategy? How do we move forward? And some are running at it. Some really are pushing the boundaries of, of their corporate policies really with, with their approach to the adoption of agentic systems.
Others are standing on the sideline and looking, um, to see how this unwinds. But, um, I think brings us to our topic, right?
What does, um, a fabric of controls, administration, governance, um, and security mean, uh, for agentic? Is it the same as it always was, uh, for non-agentic systems? And that's what we're here to discuss today. So fascinating topic. I think it's definitely happening. It's definitely happening in conversation, if not in mass deployment.
So, so, so when you asked the question, is it in, um, in trouble, so to speak, I would say, uh, you know, the point is in most cases can't be that much in trouble because it's not yet there. So the cynic in me would probably say in most cases, we really haven't started to, to solve the challenge of AI identity, of AI governance, of AI security. And you could say, okay, we're really in trouble, uh, or we are not, not, or not even at the point that we could be in trouble.
The other thing I think is that, um, while we see a lot of solutions emerging in that field, which is good, which is really great, a challenge still is that a lot of these, um, or that all of these solutions are solving certain parts of it and several of the solutions. And we had a podcast just recently, which looked a bit more about sort of fundamental or foundational changes we see. And clearly a lot of this will need to evolve over time.
So we are still in the early days, but I think that is especially the point where we need probably can ideally start with a proper conceptual and architectural thinking. And that brings us to the topic of a fabric approach, because I think also what is very clear, there is no single solution. There's not the silver bullet to this problem. There are a lot of elements we need to bring together. And when it's about a lot of elements like in identity, like in other areas, then taking up this notion of a fabric makes a lot of sense.
Yeah, it certainly does, because it has to extend, right? I mean, that's, um, I think the work that your team has done, you know, you say you did found that word fabric, identity fabric. I think we apportioned that back to you, Martin, right? But it was instrumental in helping us understand that there are classifications of capability which come together in an architecture. So the idea of fabric drives architecture, drives implementation. And it feels to me that that must be the same here. And it will leverage some of that previous technology, but maybe not all.
And there's new pieces, as you say, new vendors, new pieces. And I think this fabric thing, I frequently have been asked over all these years about this term fabric, and the term, the fabric has at least a dual meaning in the English language, which is more fabric as here on my shirt. And you could also say a mesh, something that brings things together.
So it, in that sense, it's about a mesh. It's about orchestration, about bringing different elements together to form a holistic solution. And the other thing clearly is fabric as in factory, as in production. So it needs to deliver the services that are needed. And a lot of these services probably are services that are consumed in the future by other types of components, like risk signals, behavioral analytics, authorization services that are consumed by all the various, let's call it resource servers. Maybe we have a better term in the future than that.
So this is basically a bit the same like in the identity fabric, which builds the integration, the master mesh, the orchestration of identity services, and which also delivers services to consume via APIs. And you're absolutely right. I think we need to start with the capabilities, move to services, to architecture, and then to the technology that delivers this. This technology, I'm absolutely confident, will be very fast moving over the next years because we're in a super agile field of evolution.
So the capabilities, to a certain extent, I think we can already start working on a relatively stable list of capabilities we potentially need. How we implement them, this is something which will be a lot of new versions of different changing the tools, et cetera. But this is where the fabric for itself will remain stable.
Yeah, that's a very good point. I think two things you said there that really resonate with me is one, that things move faster now.
You know, we're on AI time, we're on AI speed, and that's not just hype. It's the fact that you could sit down with a 10-agent Claude environment now, and you've an open Claude dev team basically happening in real time. One guy driving 12 agents writes software in a weekend now. The implementation barrier has got much smaller.
But also, I think the other thing you said that's really important is that it's like everything is new, but nothing is new. And maybe that's because we've been in this space for so long. It seems to me that there's a recurring set of patterns here, which is good. That means reusable technology, really. But there's also a recurring pattern of mistakes. The jello hasn't set yet on some of the underlying standards for things like token delegation on behalf of token flows. There isn't a model there yet, a single. It's like pre-SAML days.
And if you implemented SSO before SAML, you didn't get fair multi-party federation. It didn't work, right? And there's some of that happening in the underlying elements of the protocols, even. So we're not there yet. And I think we need to be very careful with it's all similar, because I think there are fundamental changes. So I think that is something where we really need to be very, very thoughtful. So on a very technical end, I strongly believe that it will not be sufficient to just sort of blow up OLS and OIDC and some of the other standards. I think we need to bring in other ideas.
We may have everything. I believe if you bring in verifiable credentials from decentralized identity into this equation, we can do a lot. But that's a side topic. Maybe we have time towards the end. Maybe it's a separate podcast. But I think that there's a fundamental shift, which means we're going away from a directed and deterministic access to a non-directed, non-deterministic access. And this has a lot of consequences. So we need to be very careful when we look at existing approaches and whether they really work, because it's different to say Martin has access to SAP. That's the past.
Or even Martin uses a functional account to access a database is still very directed and very deterministic. To Martin, that's something which triggers a mesh of agents. And some agents at some time end up at some resource servers, knock on their doors and say, I want something. There is nothing directed anymore. There's nothing deterministic anymore. And also to be very clear, your resource server does not know who will be knocking on its door in the next minute and ask for something. So we can't predict what will happen there, which is very different.
Before that, we said, OK, we need to give access to this and this and this. That's what's happening. Fundamentally different.
Yeah, I think the old world and I think the thing that remains the same is the idea that you have to be able to govern an audit at the highest level. It really doesn't matter whether it's happening deterministically or non-deterministically. Someone has to carry the pay the check, if you like. And I think that the underlying principles of controls and oversight and governance and audit don't change. But to your point, we've accelerated ourselves from an entitlement catalog, you know, well described things of access that can be apportioned to known principles and can execute.
You know, I'll often draw out a picture to kind of scare people a little bit of a non-deterministic matrix. Matrices, when you have intent flowing through multiple layers of token delegation through MCP servers to data.
I mean, that is now the access, that is now the, in double quotes, entitlement. And it's non-deterministic. It's Bayesian, it's risk oriented. And I think most organizations aren't ready to do structured access governance, let alone unstructured access governance in this way.
So again, that's an area of just sort of pause, you know, to make sure that the standards and the approaches develop at the same speed. And if we look at the term that you've coined, Martin, a identity, to have a new term for something means there is something different. So you've already looked into some of the aspects, but what is fundamentally different when you talk about a identity? What is actually changing with that term?
And maybe it's also changing for the identity fabric and maybe the results need to be overall AI security fabric that goes beyond identity and towards behavior, effect, risk management, et cetera. So where is it new? I think there, again, you could say all or nothing is new in a sense. I think there are a couple of things which definitely change. And there were, you know, there's this term of non-human identity, which is a bit difficult because it's too unclear, too fuzzy, too much of an umbrella term across multiple things.
There are workload identities, there are IOT identities and other stuff. And there are the identities of agents in agenda AI. And they are not similar to workload identities to this. Some brought this up, but it's a fundamental misconception to my perspective, because what comes in here is this level of autonomy. And it's the very different types of relationships we have. So even for workload identities, they are created during development. They are not in that sense autonomous. Agents act autonomously by their very nature.
And they act in a sort of, in a way more complex set of relationships than we had before. For workload identities, it's at the end of the day, a workload that uses certain whatever call it service accounts, could be also different things to access certain resources or other types of workload identities. But it's still a very traditional way of, we can still sort of transfer it to a very traditional way. It's a little bit more complex when you think about ownership. But agents can create agents. They try to find the right resource for what they are doing.
They are not looking, not built for going again, directed versus non-directed to a certain resource. This makes them really different and adds a certain level of complexity. So this identity relationships thing, we have never solved well so far. So clearly several have been working on identity relationships over the past years. This is something which I would feel is really new, the autonomous aspect is really new. And then also the way agents are related.
So if you think of this relationships as a graph, then you have the connections between the nodes and the graph, and they can be of very different nature. I just currently have the German terms in my mind, not the English, but probably the Go for it. What is it? The edges between the nodes. So I think the content. Vertices. Okay. Vertices. Okay. And you know, then we have a huge difference between a human or an agent or a non-robot identity, just sort of invokes an agent, but there's no sort of acting on behalf or so. Then we have the delegation. So agent do that for me, travel agent.
Or we have the impersonation where the agent says, I'm Martin. These are different relationships we have here. This makes the thing way more multifaceted than everything we have seen. And I think when we start with this, then we end up with quite a number of other fundamental changes or things that don't work the same way. So take behavioral analytics. We're doing a lot of behavioral analytics for humans or for other identities.
The point is if you do it for an agent, it becomes multidimensional because there's the behavior of the agent in the context of, and this context is not only the context maybe of Darren. It might be the context of another agent that is acting on behalf of Darren. And then we have really a way more complex perspective on behavior because it's not just the agent's behavior. It's a broader context we need to understand to understand whether this is a good or bad behavior. Right.
So on my desk, there's currently a blog post which has the statement, we didn't build IAM for a world where the actor, the path and the destination are all unknown until the moment of access. Of course, this is provocation. But Darren, you are very familiar with the identity fabric. Is this something that the identity fabric can deal with or does it break it or what do we have to change? I think it's a, like all things, it's part of history that teaches us the future. First of all, I would say traditional deterministic access isn't going away. Right.
I have quite often I'll speak to an identity program owner and they'll say, oh, blimey, everything I've done in the last, has it gone away? Well, no. The deterministic access, everything isn't going to be an agent for some considerable time, let's just say, if ever. So everything we're doing in one of the things we'll probably get to is, is that how do you connect what one might think of as historical legacy and or static fabrics to this new, because as Martin's quite clearly articulated, it is different.
I mean, just intent, verification and drift. You know, I think that that's a new area of the fabric now, right? We now have this thing called intent.
You know, I chatted away to an agent to have it do something. How has that intention drifted over time? That that isn't in the historical view of things because our entitlements were known, fixed and controlled and an assignment was the control. And we no longer have that. I think things like token governance is just a huge topic here. These on behalf of token flows.
I mean, okay, so we hope it will be OIDC based in the future, but it's not fixed yet. To me, it looks like the historic, the historical process of SAML, like we said, you know, it's how did you do SSO before SAML?
Well, it didn't work properly. It wasn't trackable, traceable and manageable. And there's conflict there at the moment in the underlying standards. And we can kind of get into that.
You know, Dick Hart's doing a great job with AORTH, but so everything is changing and there are new parameters here, new things that need to be included. I think a great example of that is human in the loop. The way I see a lot of enterprises today, working with this non-deterministic flow is to pop a human in the loop.
By that, I mean an approval process. You know, the authorization happens very dynamically and non-deterministically. But there's a rule that says if the value is over a thousand dollars in this trade, let's do an UMA-like flow back to the original intent provider to just make sure this is okay. And that sounds a little bit like an approval, which is really interesting, but it's not. It's happening in real time. So everything's the same. My problem is that exactly the human in the loop basically, in many cases, really ends up with a human being asked to do something.
The problem with humans is humans are, from a computer's perspective, from a machine's perspective, humans are incredibly slow and so little scalable that it's really annoying from a machine's perspective. You know, a machine gets mad when it needs to work with humans and wait all the time until the human comes back and says, okay, yes, I finally noticed that you're asking me something. Let me think about it. It doesn't work from that perspective. And it doesn't work from a human's perspective. And by the way, it's a wonderful example.
If you go to this permanently mentioned SOC analyst, alert fatigue, overload, et cetera, it's a wonderful example, not only of how we bring in humans in the wrong way, it's also a wonderful example of failure of AI, because AI doesn't focus on the really important things. And I think this is the first thing we need to learn. We need to learn when to bring in the human. We need to learn how can we, as much of the intent, the constraints, et cetera, of the human, the consent of the human, deliver with this entire sort of chain of things happening, humans to agents, to agents to resources.
From the very beginning, again, this is where I believe YDC, et cetera, way too limited. I think we need to factor in verifiable credentials, wallets, where all this stuff is stored, where we can consume it, and not only from the humans, but also of the agents, et cetera. Then I think we can do a lot of things better. But I think, so it is something where the human loop is not the best response, but maybe going back to the fabric, because this is, I would say, our core theme. And there was implicitly the question of, is the AI security, whatever, compatible with the identity fabric?
Can the identity fabric deal with the future things like that? I think, first, I believe these concepts are overlapping. So there's, I would say, quite a considerable intersection between the two, because the field of identity, of access control, et cetera, is something which overlaps. I also believe that a lot of what we learn from dealing with AI identity, but also nowadays from workload identity, will impact our workforce identity. Automation, we can do so much more automation, et cetera.
Continuous controls that are automated instead of manual access entitlements and recertification, all that stuff. We can learn a ton of things, and it will flow back. The identity fabric basically is about the access to governance. There will be new capabilities needed. Some of them will map to the AI security fabric. But in the AI security fabric, there are also elements that go beyond what we look at in an identity fabric, securing the LLM, the model, the data, and all that stuff. To a certain extent, it's access, but there are elements that definitely go beyond that.
Or explainability, which I would also count into an AI security fabric, really are capabilities that are going beyond that. There's clearly an intersection. There's an impact of the learning. So we start with what we know. We learn that we need to probably evolve several concepts, some of them quite fundamentally, and it will flow back. It will help us to get better on the other side of it.
Yeah, that's exactly right. Let's hopefully learn from everything that we've known and bring that forward. I think it's interesting what you've said about there being some sort of capability, I won't call them principles, because that obviously has a meaning in terms of authorization, but some fundamentals that have matured in the identity fabric, which will be super important here. I agree with you that claims and verifiable attributes have a much bigger role to play here.
I also think things like agent telemetry and the notions of observability, which is nothing new, are critical here, absolutely critical to be able to understand the behavioral flow of inference as it runs through these systems and just decide when to sort of throw in a break, a stop. They're obviously principally runtime authorization.
Again, critical. It's not contradictory to what happens on the other side. When you look at a lot of discussions I currently have around, for instance, the future for authentication, for instance, shifting to, if you think radically, then we should end up with a passive authentication as the standard means. So we don't actively authenticate anymore at all. Because already when we take our phone or anything like that, that phone already, the dearest answer knows already, okay, this is the way Martin picks up his phone. I swipe to open it up. It looks at my face ID.
It has so many signals already. Plus all the contact signals, behavioral signals, et cetera, et cetera. So we use a ton of signals basically to make a decision about authentication, about authorization. The same basically is happening at the authorization server that we need to consume a lot of signals. Signals that are sort of explicitly transported like claims, verifiable credentials, whatever it is. Like behavioral signals around agents and their context. Like stuff we know about the agent. So one of the first thing will be discovery of agents and understanding which nature are these agents.
This is a managed, unmanaged agent. Do we know whether it's potentially good or definitely not? And all these signals together formed the foundation for the authorization. And at the end, it's still authorization. And the authorization will be way more complex, way more signal-based than ever before. And the same is happening, so to speak, in the pure identity play for everything. Also when no agent is involved, we will go to more signals.
And that also, for instance, means that in both areas, we will quickly move beyond policy-based access control because nothing of that will be, can be policy-based anymore. Nothing. Because if you have, if you try to formulate a policy for only 10 signals, think about how can you formulate an access policy that is based on 10 different signals or call it attributes. Quite complex. Oh yeah. For a human, extremely complex.
Basically, it means we need machines, to avoid the term AI here, to do that job for us, to handle this properly, which we basically in some areas already do. And that means we are still working in a sense attribute or signal-based, maybe partially token-based. But it is something which is well beyond policies already. Yeah. Runtime authorization is having its day. As someone that worked on XACML way back when, I've always been a big fan of, in fact, I think I remember speaking about it at some EIC events in the past.
I was always fascinated by runtime access control from a governance perspective, from my time at SailPoint. How do you govern a real-time access where you can understand the policy, and you can understand the inputs into it, and you can take some view of control or review of that? But to your point, I think it's just happening at machine speed now, which is interesting.
I mean, I see a lot of people trying to retrofit, re-go loop-based policy languages, and I don't think they work. I think that Amazon's got the right idea with Cedar as a policy, something that's non-ensuring complete, so as they can run at embeddable speed. Because we're going to be making decisions here in microseconds that could potentially change the world. So how do you govern that? We're still trying to work out. How do you provide an auditor a path of assurance that the right things are happening?
And you've got to look at the behavior, and you've got to close that loop very, very quickly. And it's like everything we ever learned about access in generation one has now got to happen in real time. Right the way down to attribute source and providence, policy evaluation, and control over the agent intent process. So it's an exciting time to be in our space, I think.
Yes, maybe we go back to the fabric and how we get there. Yeah, the question is, as you said, how do we get there? The question is, what will stay stable? What can we have as of now? And what needs to be added? What capabilities do we just not have right now? And just from the discussion that you had right now, on the one hand, we have this idea of intent. You give an agent the idea what it should do, more or less, and it starts or a group of agents or spawns different agents.
They do something with their own agency that they do something trying to solve a problem rather than having an algorithm that says, go A, B, C, and then do this. So this is the intent part. On the other hand, we have the behavior part to understand what is this thing just doing right now at machine speed, as you said, right now. I have not yet come across a capability that maps actual behavior to proper intent and to understand this is expected behavior and this is unexpected behavior. So I think building this fabric. Let's start with intent schema.
I mean, I can't help it. You know, coming through SPML and SCIM and all of the, you know, I think in turn, there is no standardized intent schema today. There's three or four competing models for it.
I mean, it's a bit like if you don't have a way to represent something, how can you transfer it, audit it, control it, you know, encrypt it? It's sort of, so there's some fundamentals here still missing.
And again, it's like the past repeating itself. You know, we're going to, we're going to standardize provisioning, but we don't have a lingua firma for provisioning.
Oh, well, let's define one in standards. And a lot of that is happening here to my mind. It makes it fascinating.
Yes, the interesting question is the breadth of intent, but at the end of the day, too big to define it in a sort of deterministic manner. So maybe it is that we need to be very abstract in how we describe it, more going to some sort of N-tuples. I don't know if this translates correctly into English, where we say this is a very generic N-tuple, which describes a certain intent, and it can basically contain everything. And if it maps to the right stuff at the other side, it works.
And then maybe we can move to certain domain-specific schemas, like for whatever banking, travel, and other things, where we say, okay, this is maybe then based on such a very generic approach, the right way to forward to then sort of at the specific variants over time and evolve them. So let's see where this ends. But I think when I look at the fabric more generically, I think, and you brought it up at the beginning, an identity fabric has capabilities to services, architecture, to tools. And the same basically is true for AI security.
It's about which capabilities do we need, how do we bundle them into services, and how do they fit together, how do we orchestrate them, that stuff, to which technical technology we use below that. From that perspective, we can use an analogy, and that I think helps us to move towards a fabric. We could also, and that's something we discussed around the evolving cybersecurity fabric. For instance, we can also lean towards the NIST cybersecurity framework.
So just very well-known cycle and say, okay, let's start with identifying the challenges, then detect probably more in the sense what is around there, which agents are out there, then go to protect to understand what these agents are about, what is, so visibility, observability, it would be to behavioral analytics with all its complexities. So that would be really the detect parts, basically, to really then reacting, responding on and recovering maybe. So kill switches for agents, bring or getting information back, all that stuff to improvement.
So I think we can lean on different approaches at the end of today to describe such a fabric and how the elements work together.
And maybe the one is more the fabric higher level picture, and the other is probably more what helps us to build a proper reference architecture, like we have in the identity fabric, we have our identity fabric and we have our code identity reference architecture to take different perspectives, but all of them at the end of the day, we'll go into what our capabilities, what our building blocks we can bring together, and it will help us to understand what do we need first? What do we need at all?
What do we have either in our organizations or what we already have as a technology that's available in the market? And so we can measure our gaps and all this stuff based on that in a similar manner as our fantastic advisory team at Kubing & Kohl analysts does for the field of identity management and cybersecurity.
Yeah, I agree. I think with things moving as quickly as they are, I think the approach, the fabric really lays out the approaches for things that sit there. And I think that's something we can define now. This space is moving so quickly, you're unlikely to get to a holistic architecture as quickly, which is why I think you start with some of the fundamentals, right? Let's start, Reggie.
I mean, I often have a conversation with a client that will say, you know, where do I start today? Just start with an agent registry.
It's just, if you've got nothing else, have that, right? I mean, it's sort of the principles of control. And I think the beauty of the identity fabric and the beauty of the fabric paradigm as a whole is that you can extend it and you can combine it. And I think one, Martin, you asked, how do we build that AI security fabric? I think one key aspect will of course be the identity fabric because without identity, security won't work. Maybe it's not yet complete still to be confirmed, but there will be other layers as well. And we've talked about that implicitly.
It's identity or AI identity, it's AI security. And maybe one aspect that many are often ignoring is the part of AI governance, including ownership, liability, responsibility for identity. You won't be capable of doing this on a one-to-one basis, but in the end, when an agent is out there, there should be not a human in the loop, but a human responsible or a group of people or an app owner responsible for a service, which is responsible for the AI agents. And there is an owner for the app. So I think this governance organizations processes, you've mentioned visibility.
I think this needs to be added on top of, or parallel to security and identity to get to this overall fabric. And I think we are building on strong grounds and we can start with an MVP for this AI security fabric, and then extend from that. Not doing anything is wrong. Applying old principles only is wrong. The question is, how do we build it up and extend it? I think I fully agree with both of you. First was discovery is a perfect starting point. So we can't govern, we can't manage, we can't secure what we don't know.
So discovery is a key thing, and it's probably the lowest hanging fruit in this entire field. I think we also need to think about the authorization. It will not be perfect yet because we are lacking signals, we are lacking intent delivered, et cetera. But I think it's a logical starting point.
And yes, we need to think about identity as one element, about what you said, governance, which can include explainability. Explainability could also be something separate. I'm not exactly sure about it. And security as really technically security. And then some things, you brought up discovery.
Discovery, I would say, is a part of governance. For me, ownership is part of governance. Visibility is part of governance, while observability then shifts into the security. So taking the actions based on what we really see here.
So, and I think we shouldn't be shy of thinking, okay, how do we do it? I think, and I brought up sometimes, a lot of the things we did in the past will not work in the future. But that does not mean that we should think about what we did will work, what we did will at least help a bit, unless we have something better. That's always still the better solution than saying, okay, we look for the perfect solution because we can't wait for the next years. So I think we need to also be pragmatic and say, okay, this is the best what we currently have. Let's start with this and evolve here.
We then must not stop by saying, okay, we have something. Okay, we are good now. I think we must be very ambitious to rethink this. Always keeping in mind that the cool thing is a lot of the learnings will help us in the other fields of identities massively. Automation, dealing with relationships. So relationships, ownerships, et cetera, they are more complex in the workload identity world. They are even more complex, not well-solved. Then you look at a very simple, basic thing. So we have a technical, so a functional account in privileged access management.
And we rarely have good ownership management in the sense of the ownership, for instance, changes when in sale point to take Darren's old tool, not old in the sense of it's old, but Darren evolved from the very early days. And if you have a, whatever, a mover process there, it should trigger ownership changes.
A very, very small ratio of organizations have implemented something like that. So we can maybe learn how to automate it. So there's a huge potential. At the end of the day, I think the best is, and I'm also a believer in the fabric from another perspective, because it helps us in deconstructing the problem. If we say we need to solve security and identity and all this stuff for AI. Good luck.
Yeah, we are facing a problem that is just too big. If you paint it as a picture and with the various capabilities, still probably each of these capabilities is big to solve. Way smaller. I did an initial picture a while ago with 15 because it looked nice on the slides. Three columns, governance, security, identity, five key capabilities each. So good for a keynote. Probably there are some more, but at the end of the day, it means we are slicing the elephant into pieces and then it's much easier. Consumable pieces. Yes.
Yeah, it's interesting. I think it's our job as advisors and long-term practitioners here I like to keep bringing it back to the top, to a business level, right? So many times we're told now, go do agent, go do agentic. How fast are you moving to agentic? There's a lot of top level board fear. My message back to that same board is, we're moving fast and this is going to cost, right?
Again, there's a lot of people think they just go do agentic. No, this is every bit as big a task as we ever had in identity and look how long and how much money it cost us to get there with identity. Doing this with real-time token, it's just as big. Keep your wallet close to your heart as it were as a business owner because there's a lot of work to do here still. This clearly shows that you are currently sitting in the US. Marcin and I, we are sitting in the EU. I see lots of top-tier management people that are very hesitant to actually go that step to say, okay, I do not want to risk this.
Who makes the bigger mistake, Darren? Wow, you're right. It's almost geopolitical in that sense. The US likes to run first, right? The reason I'm in the US is because in funding in the UK when we were doing our first startup meant putting your house up as security.
The US, you could find venture money. Venture money didn't exist in the early 90s, right?
America, I believe, has always been on the forefront of risk-taking in that respect. I do see a lot more risk-taking in this space. Like you say, I was on a group call with folks from all over the world. Everyone was talking about agents here. There was actually a German guy that came up. I can't say which company he was from.
He said, but there are no agents in the environment that aren't registered, understood, and known. It was sort of a sense. It was just like sense and logic. Whereas the Americans were like, we've got agents everywhere we don't know. So I think there's a certain element of giving geos run faster and accept the risk.
Yes, I think the Europeans have a bit of a tendency maybe to over-engineer things. Maybe sometimes think them through a little bit too much. And I think at the end of the day, we need to find a balance. And honestly, all agents registered in a larger European organization, no, sorry. That is then probably ignoring the reality. Because at the end of the day, that happens. It's not that these agents are not there. We have this wipe coding. We have this, I don't like this term wipe. And I also don't like this term democratization in this context, et cetera.
But at the end of the day, these things are happening. There's a shadow AI. So I think we must not ignore it. And we must figure out pragmatic ways to do it. I think again, and I think this is not only European, it's probably global. Businesses can't say we don't do AI, we don't utilize AI. Because for remaining competitive or even becoming, strengthening leadership, you must utilize it. And then it's our job as the identity and the security and the governance people to make it work and to mitigate the risks as best as we can.
Business people sometimes will need to take risks and to say, okay, we accept the risk because it's important for the business. And we need to work on how can we mitigate this as much as we can. And I think there are a lot of things we can do. But just not doing something is not the right solution.
Yeah, we're at a transition point. We've seen them before. Mainframe to distributed, distributed to client server, client server to web, and now web to agent. And in every phase, I agree with you that ultimately, it's still a business ownership thing, right?
So yeah, governance doesn't go away with agentic. Right. And if you look back at the Fabric approach, so we have these three different angles, identity, security, and governance. We are not starting from nothing. We have living and mature frameworks in place that we can apply. You've mentioned NIST for security. We've talked about the identity Fabric, which proves valid for many use cases, maybe not for all as of now. But we are bringing things together to solve issues that are real, but solutions that are more or less already real as well, but need to be extended. Final question for today.
What needs to be extended? What do you think, if you have to name the single hardest unsolved problem, and I think Darren hinted at that already, it starts with off and ends with orization. So what are the single hardest challenges, problems in this space that really demand for a solution that is not yet there? Maybe starting with Darren, then with Martin, and maybe I have a shot as well.
Yeah, I think the alien on the face, really, for me at the moment is token delegation. Without a form of on behalf of token delegation, coming back to the point of intent. I mentioned UMA, all credits to Eve, and that it's almost like we need an UMA-like principle with non-deterministic systems. If you've got token authorization being passed across agents and being reused, you've got to track and monitor that stuff. So that would be my alien on the face, a model for controls and governance over that.
Martin, what is not yet solved? A lot. But I would also say that the point I would say we need to really spend or put our focus on is the standards. So I refrain from naming standards. I think it is about probably joining a lot of elements like UMA, Verified Intentions, OIDC, OOS, et cetera, to bring together the best of that and the relevant of that in a form that goes beyond what we could do when restricting ourselves to say, OK, we expand that or that or that. I think it's more on combining things, because that will help us to deliver a lot of the signals we need for authorization.
That will help us to deal with the complexity of a mesh when we have multi-party, multi-agent stuff, when we have multi-tier authorization, et cetera. We can transport a lot of information that helps us shifting from, assume that this is the intent of the agent to, we know that this is what the agent is supposed to do. And we probably can get rid of most of the loop when we do it right. And this will fix a lot of the other challenges. So that is, at the end of the day, probably really the big thing to solve. Maybe if I'm allowed to add something.
I think accountability is still an unsolved problem. The more we get to agentic AI solutions, which are really spread across different landscapes, but I have, of course, this identity relationship management between them. Do I really know what that agent does in this AWS environment that I spawned from my local desktop some five minutes ago? Am I accountable? Am I responsible? And how do I know? And why the hell am I responsible? I did not ask it. I think this is something where we're still not there.
Again, related to what I think what Darren and I said, at the end of the day, if we are better in delivering all that consent, constraint, intent, et cetera, from humans, from workloads, from agents. So agents, we define that is the purpose of the agent. And they should also have some sort of a wallet that can issue verifiable credentials. If we solve that, then a lot of these problems just disappear. Quite simple. Not simple, but logical. Before we close down, final question.
How long, just a simple question, but a bit funny also. But how long will it take to have a first working version of an AI security fabric, I think it will not take long, honestly. I think it's a couple of weeks until we can have something.
Yeah, I'd agree. I think let's start with something, even if it is almost underlying fundamental principles restated, much as we have done on this conversation. Let's just start there, because I think everyone's a little lost at the moment. Right. So now it's my time to close down. And where can we talk about an AI security fabric?
In Berlin, in May at EIC, there will be people who are willing, able, and actually eager to talk about that. We will be there. Please reach out to us if you have any questions, if you have suggestions, if you have solutions, partial solutions, and overall solutions, good governance concepts. There is still something to add. So let's meet and talk in Berlin at Alexanderplatz in the middle of May this year for the European Identity Cloud Conference. Thank you very much, Darren, for joining us today. I hope this was not the last episode where you joined us for.
Thank you, Martin, for pushing the term AI identity and everything that comes with it. And I'm really looking forward to meeting and talking to you all in Berlin in May. Thank you very much. Thank you. Thank you.