We are facing a situation where we need to enable AI. I think there's no way not to use AI for organizations, so that is an absolute must. We need to think about what is the foundation for delivering AI capabilities at the speed of the business. Welcome to the KuppingerCole Analyst Chat. I'm your host. My name is Matthias Reinwarth. I'm an analyst and advisor with KuppingerCole Analysts. My guest today is Martin Kuppinger, and he is a distinguished analyst with KuppingerCole.
Hi, Martin. Good to have you.
Hi, Matthias. Pleasure being here. Great to have you, and I think we are starting a series of episodes today because we want to dig deeper into the changes we see and expect for identity when it comes to providing identities to autonomous systems, to AI. I think it was more than a year ago when we sat together in just such an episode and you coined the term of AIdentity, so this conglomerate of AI and identity, and things have improved, have changed, and the challenge has increased when it comes to AIdentity. Why is it even more important today to have this term?
What problem are you trying to name with this new coined term that traditional IAM cannot handle anymore?
Yeah, so I think the term AIdentity has a bit of a logic because AI and identity, and what we are facing is a situation where we need to enable AI, so I think there's no way not to use AI for organizations, so that is an absolute must, and so we need to think about what is the foundation for sort of delivering AI capabilities at the speed of the business, and that requires a layer that provides us with AI governance, with AI security, with AI explainability, and with AIdentity, and AIdentity is one of these elements.
It's I think very clearly close to AI security, and I think there's also in the term identity security there's a blurring line between these areas, but the point is we have some really fascinating, I would dare to say, identity-related challenges. So first we have this non-human identity, and an agent being non-human is something that needs some sort of an identity.
We have agents that work as agents, we have agents that live long, we have agents that are more ephemeral, so we have obviously a lot of the challenges that we see in the workload identity piece, or machine identity management piece of non-human identity management as well, but with a much higher degree of autonomy.
The other thing is we are facing a very interesting identity relationship challenge, because we are shifting away from Matthias has access to system A or B, towards Matthias in some way, willingly or unwillingly, knowingly or unknowingly, invokes an agent that may invoke other agents, that may even create agents that access certain resources. So it's a much more complex sort of resource access than we ever had before in any other scenario.
And that is also a very fundamental distinction to the non-human identity workload identity aspects we are discussing since the past two, three, four, five years or so. Because we have really this identity relationship, which also is in itself very differentiated, it's not always sort of the same type of relationship. And that means we need to tackle this as well as the accesses changing. We need to think about multi-tier authorizations, because there are multiple layers of authorization. And we need to think about more often the orthogonal type of access control.
So in access management, we are relatively good in controlling functional access. So SAP transaction codes as the extreme, where we say someone is allowed to perform that or that or that function. We are not really good in controlling access to data. So having a data-centric perspective on access control.
For AI, we need data-centric access control on steroids. So I think we are both in identity management for decades now, and we always relied on some basic assumptions so that there is something like consent, there is something like a human that actually in the end does the decision-making process, sessions, role models. This is what we are used to with autonomy and autonomous agents, that we are losing that partially. So we need to find new solutions, right? I think we needed to do that before. So I think roles never have been a good concept, to be honest, and I talked about it before.
They are an artifact we used to cover that humans are not really good in handling things at scale. So if humans would be good in handling individual entitlement assignments, we wouldn't need roles. Roles help us to keep it structured and to bring in the efficiency. But I think this is exactly the point towards which we are moving. The point is, the world we are in now is one that is not only autonomous, it's very volatile, very agile, and it's something which is at very high scale. And humans are not really good in handling things at scale.
And all these sort of manual processes, the workflows we have in IGA, et cetera, the manual request approval stuff, recertification, the way we did it, will not work anymore in this very dynamic world. It doesn't work for NHI, where we have to scale. It doesn't work for agentic AI.
And we need to find solutions that are built for that speed, which might be, by the way, very interesting for our traditional identity management, because when we learn to handle stuff with a high degree of automation, at scale, at speed, we probably can derive a lot of learnings for improving our traditional identity management. And I think that's an interesting point. So we are not just thinking of adding another tiny capability to our big IAM building.
We are also thinking about not changing every capability, but actually changing the way that IAM works when it comes to the underlying structure, the volatility, the volume. So that is something that we are seeing IAM changing just right now.
Yeah, I think it will take a bit until this dribbles into the sort of workforce and other human identity management aspects. But it must happen. I think it's just logical that we do that. And in a sense, we've tried this for long. I think when you look at all the dynamic authorization aspects, it is not that we didn't think about it. We just didn't do overall a very good job on that. And I think right now we are mandated to do that.
It's also, you know, we hear a lot about human in the loop. I would say most of the things I read and hear about human in the loop are just fundamental misconceptions. The sheer idea that you have humans that approve all the actions of agents is just, it's an impossibility. You can't do that. Because the human is not fast enough. It would be the overload. And I think we really need to think about these things. I think we have proven anyway in other areas that we are facing challenges in this sort of intersection between AI stuff and humans.
So take the, we hear a lot about it, we read a lot about it, it's just a reality, the overload of SOC, so security operations center analysts, where at the end of the day, the solutions greatly fail, because if this is the result of all the automated analysis, that the humans then are not capable of properly handling it, then obviously it's a failure. And we must avoid these failures in the space of AI identity or AI security and all the other areas. And think about where can we really, and where must we bring in the human? But what is automation? And what is just working smoothly?
And at the end of the day, you know, we also have to set the same thing in identity management. We have, in that sense, we have a recertification overload, which is far too complex, done by this rubber stamping.
It's, again, something where we didn't properly think about what are the really, really essential things the humans must do. This is what we need to think about when we think about AI identity. If we go back to the example that you've had earlier, so Matthias just invokes an agent that acts on behalf of me, so does something that I just don't want to do anymore. The question is, how can I verify the decisions that are made? How can I even stand there and say, yeah, this is Matthias that has taken this decision, because this thing acted on behalf of me.
And I think everybody of us uses AI right now. And you type in the same prompt and through the same AI and it works for 10 times and the 11th time it looks different. It's silly. It's not following the rules. The question is really, how do you impose this additional layer of scrutiny when it comes to say, when I come to say, yeah, this agent acts on behalf of Matthias? This is a challenge because the human in the loop, you've just removed me. Yeah. I think the question is, what are the things you need to approve? And I think this is one of the first things to think about.
So what are the things that can be done? Another thing is, and when you said the agent acts on behalf of you, I think this is very imprecise because it might be that you just invoke an agent that does always the same things for whoever invokes the agent. It might be that you explicitly delegate a certain task to certain constraints to the agent, or it might be that the agent impersonates you. So basically makes others believe that the agent is Matthias, which all are very different from the level of control we need. So I think this is also something to keep in mind. It's not always the same.
I think at the end, we need to focus on where are the, so at the end of the day, probably we will need AI to govern AI in the sense of AI spotting outliers. So what is the normal? What is the non-normal?
What are, what is where obviously some certain rules, certain constraints are in kept. I personally believe, and I think this is something the industry should very, very thoroughly analyze the researchers. I believe that verifiable credentials as in decentralized identity may play a very important role in this entire concept because they are a means of delivering consent, explicit intensive, which is a bit dichotomy, but I think you know what I mean. And rules and other things in a secure and to an identity associated way so that it becomes clear this is something that comes from Matthias.
Maybe this is also something that describes. So you could also have agents having these, so to speak, their wallet with their credentials, which allows them to express certain things about the agents. And that way we can, across the entire chain, across all these complex relationships, transport information that is way more visible and way more clear than it is in the current state where a lot of this is assumption or sort of ex post analyzes in a sense. But I think there are things we need to do.
At the end of the day, it is very clear, the more critical, the more sort of the more outlier behavior it is, the more we come to the point where the human needs to be asked, but not always and not for everything. Right. And you've mentioned that relationship management, that underlying relationship management that is required to have this lineage, this understanding that, yes, this thing acts on behalf of Matthias. This is something that we can model, but we typically do not model.
So if you look at current infrastructures and if I look at IAM, IGA systems, access management systems that we're using per today, what is currently missing? What are these systems not yet representing that we would actually need? You talked about the vendors, the industry, they need to change what is missing, what needs to be changed, what needs to be added when it comes to capabilities right now. I think we need a fundamentally different set of capabilities at the end of the day. So one element really is relationship management, which we see in very few solutions done properly.
And we need it, by the way, for other areas as well. So we need it also for whatever the supply chain identity management we need, handling of relationships for other areas as well. I think that is clearly one of the parts. I think we need to look at the dynamic authorization field because all that must be around dynamic authorizations. We need to think about how can we manage and create, so to speak, the identities, which also includes the discovery element, which is how do we automatically assign identities, then properly handle them. With sometimes very short lifetimes, lifespans, et cetera.
So I think at the end we have really quite a set of challenges we are facing we need to solve. I think what will come to its limits rather quickly is trying to just reuse and alter a bit of established technologies to just apply it and then to apply it to the field of AI identity, AI security. I think we need to go into the conceptual level. It might be an interim solution. It may be a step in this direction to say, OK, we look at what we can with what we have, can do with what we have now.
But I think on the midterm, there must be a lot of really fundamental change in concepts and architectures. The right place to talk about these changes, of course, is, and I need to mention that here, is, of course, EIC, the conference that we're holding in mid of May at Berlin Alexanderplatz in the BCC. And I think this will be a topic, I've seen it, I've been in the agenda committee and I've seen lots of suggestions and proposals for talks and for panels to talk about this. You are just currently laying out your view on that topic.
So EIC will be the right place to talk to people, to learn from people and to get a full picture of the challenge we are facing. I think that is something, and you will talk about that as well. You will be doing the opening keynote again, right? I think so, yes. At least I know. You are in the agenda team, so you probably know better than me.
Right, and I think that will be a key topic. But those who do not want to wait until EIC, although they are joining, of course, we talked about how things are not yet well available to use, and maybe there are even mistakes to make if we don't adapt to that. What would be your key recommendation for security and identity leaders? Where to start right now? Understanding that there are challenges, that there are blind spots that we don't yet can cover properly. But what to do today to tackle that challenge and be prepared for the next steps?
I think we can look at this from an operational and from a strategic level. From a strategic level, I think it's pretty simple, and not simple as well. If a challenge is really complex, the best way to tackle it is deconstruct it, solve the different elements, reconstruct it. So that means not saying, I want to solve AI security, but looking at what are the elements of AI security? How can I solve one after the other, or at least somewhere in parallel, and then bring these things together? And that's basically also looking at sometimes the tactical solutions that are on the market.
From a technical perspective, I think the very clear starting point for everything is discovery. We can't govern, we can't manage what we don't know. So discovery is the very clear tactical starting point.
Right, and there are vendors around that support you in finding those unrecognized yet. In stocking, yes.
Yeah, all right. Okay, so at least we can not yet clean up the basement, but we can look what's in the basement that we need to clean up later. So that would be the analogy when we come to that. So thank you very much, Martin, for talking about this. We will follow up on that. We will talk about that at EIC, of course. But this will stay with us for the next years, I'm quite sure. And the market will change. So thanks for your time.
Okay, thank you.