The first thing I need to say is this is definitely AI generated and it was not generated by me the title. So I wasn't maybe not careful enough when it was proposed to me by the team. But I think we are in a situation where we... So the statistical uncertainty is a bit of a tricky thing. I think we see fundamental changes in what is happening nowadays. And we need to learn about how to do certain things quite different. So my talk will cover a couple of things, thoughts I have around AIdentity from different perspectives. But my starting point really is that we...
And I think this is the point where really the deterministic or non-deterministic thing comes in. So I struggle less with the deterministic security part of the title versus the statistical uncertainty. But this is also AI generated, but by me and it's not perfect because I think the typical LLM is currently at the stage of a kindergartner as a kindergarten child, not a kindergartner. So it means you say something, do this and then you say, oh no, this is not exactly right. Try it again, try it again, try it again.
Sometimes I give up, but I think this should illustrate a basic idea, which is we have certain types of identities, not just humans, there might be others. And we have certain resources. And by the way, this is not the resource. This is the resource, whatever the SAP system, the database, whatever is behind it. I think that we should be careful not to think we are done when we have an MCP server authorization. That is halfway done.
And I said in another talk, then when we have solved MCP server authorization, we are probably at the level of a sideminder in the year 2000, CA sideminder in the year 2000. So we have still some way to go from there. So really it is something which is changing. But the main thing is there's, so in an ideal scenario, clearly you say, oh, we have this managed agent that does exactly this. Then you don't have this complex thing in between. But in most cases, it's some sort of a mesh of agents. And that means things are changing.
So in our old deterministic world, we would say, okay, we have Martin, this is Martin, has access to SAP. That is very deterministic. It's directed, so Martin to SAP. It's deterministic. It's exactly this relationship and only to SAP. And maybe we give Martin some more access to other systems, but it's a very deterministic thing. And right now we say, okay, Martin does something.
We say, okay, Martin does something and that results in something happening here and ending up somewhere here or somewhere else, which is non-directed and non-deterministic. And it's a fundamental shift we are observing. So this situation of we have humans or non-humans, I struggle with this term, non-human identity, because I think it's not very precise. Acting on behalf of, so the agents that are acting on behalf of that, communicating with the other agents, maybe even creating agents on the fly and not even digging into, oh, by the way, the counter is not working.
And it would be ideal if I would see how much time is left. Otherwise I may speak for hours. So Guillaume, you interrupt me when I should stop. Yeah. It right now started, but I still have 90 minutes and 45 seconds left, which probably is not exactly true.
Anyway, then something goes back and this is the situation we are in. And that means we have a different scenario and we need to figure out ways, different ways to deal with that. So we can't think in traditional entitlement approaches because any of the day this MCP server or the backend system, they don't know what will happen next.
And unfortunately, another aspect of non-deterministic is if you change the LLM, or it's just a little updated, or it has learned a little, there might be a different result, a different path, a different route for the same prompt, for the same question you're asking. So also this is not deterministic. And this one doesn't know which agent will knock on the door the next minute and ask for what and why. So it is really a paradigm shift you're observing. And during the opening keynote, I brought up this AI security fabric and I put in trust for two reasons.
I didn't list everything I have in mind as building blocks or a couple of phrases. So we will add a reference architecture. My PowerPoint skills are limited. So I just used the space I have. And also people told me I shouldn't always bring up a four point font size chart. So I try to keep it a little bit readable at least. I think I've built a reputation over the years to have this every now and then have a slide, which no one can read in the entire room, even when you're sitting in the front row. So I tried to avoid this this year. And by the way, this is a fully handcrafted slide.
So there are more things we have on the radar, but basically the point is to say, okay, what do we need and capabilities to handle them? There are quite a number of things. We need security elements, which is like saying, okay, we have, for instance, data security, securing the data of a language model. I used the XLM for LLM and specialized small whatever language models, which other models may appear. Learning governance, which is a quite fascinating thing. So how do we ensure that we can control what the language model learns?
And so the racks of today definitely are another answer because they are black, white. So today we say either it can learn or not, which is not a very good solution. It's another way we should look at it. It should be made way more nuanced. And that will be a tricky thing to do. We need to secure the model and a lot of other things. We have this, I'll leave this for the end. We have safety.
Again, one of these things, a lot of people talk, oh, we need an agent kill switch as a last resort. We may, but it's the last resort. So kill switch is always when everything else failed. So for safety, we need more than that. We need containment, isolation, other approaches first before we shift to a kill switch, especially when we don't know exactly what the job of the agent is. So if the kill switch then, whatever, stops the belt in your factory, then you did probably something wrong. We need the governance aspects with discovery, with visibility, observability, very important.
So visibility, I always say, doesn't help much. It helps. It tells us where we have a problem. Observability helps us fixing the problem, which is much better than just knowing that something's wrong. So we need explainability, and explainability starts with immutable logging, and we need protocols, a standard, not protocols, a protocol for that, a single one. Traceability, all that stuff needs to come in. And that then is the mesh of agents.
There will be a lot of signals I talked about this in a couple of other talks to the resources, and then we can build our services like an agent discovery service, visibility, observability service, authorization services, et cetera. And then the AI identity management, and all the other things as the technology is below that, we have to surface it. Not everything is there what we need, technology-wise, and not everything is at a perfect level of maturity. It can't be because this is so fast moving that this will take a while, so that we can then protect everything.
And the authorization, I think this is where then the, so to speak, the statistical aspects come in. I think also in the behavioral analytics, there's a lot of things we need to understand from a mathematical perspective, probably. Behavioral analytics is much more complex now, because in the old world, we said, okay, this is the regular behavior of Martin.
Right now, it is the behavior of an agent, but that agent may operate for Martin or for Patrick, or for someone else. So it's a multi-dimensional behavioral analytics in a sense, which is a little bit more complex to do it right. So we need to understand these things to do it properly. And the other thing is the authorization piece. And when I maybe quickly go back to the previous slide, we have a lot of signals we potentially can consume and can travel. There's what Martin asked to do. There might be, by the way, Martin may ask something, or I may ask something, but my intent may be different.
So intent-based is not a good term, sorry, because the intent is somewhere here in my brain, and it's not necessarily exactly what I asked for. So intent is the wrong term, absolutely. Maybe we can change it now, because it's still early on the journey before it gets put into stone. But then we have what are corporate guardrails. We have context.
We have, starting from device, we have signals from the agents, or sorts of guardrails, authorizations from the agents, et cetera. And all this travels somewhere here where we do an authorization.
Ideally, it travels even further to the backend, so that the backend understands the details and not just gets an information, okay, this seems to be okay and authorized, but we need to think really down to the backend. And that's an interesting area then, because this is where we end up, not with one or two or three signals, but with 50, 100, hundreds of signals. And then the question is, how do we handle that many signals?
So this authorization piece here, here, wherever it is, this is definitely one of the interesting challenges, because our static entitlement thing is pretty simple and deterministic. Yes, you have an entitlement or no.
Right now, it says we have these signals, and then we need to figure out whether this is good enough to pass, sort of, or not. So it is really a very different way to handle authorization. We had a couple of conversations here, and basically, it seems that there are two mathematical approaches that come up in this conversation. The one is vector algebra, so understanding signals as vectors, and in a multi-dimensional space. And the other would be Bayesian, where you deal with uncertainty.
So I think we, probably, industry and people that are smarter in mathematics, or deeper in mathematics, than I am these days, will figure this out. But I think we will have a different way to handle authorization. It's not black-white anymore. So it's really a different thing which will happen, and that will be interesting. And then the other thing is, we will need different types of technology. So we listed some types of the technologies that will pop up, and I think I'm probably already at the end of time.
Oh, I did change the counter. That's the point. So this is correct, again. So I can keep talking a little. This is what my colleague, Jonathan, brought up, saying, okay, what is the tool text on the meta-categories we see? And you see these are three or four-letter abbreviations, as analysts tend to do. Jonathan talked about a couple of them, like the risk audit compliance aspects, like the identity access part. I want to focus on two of these today, for the remaining minutes, which is the AWAP and the ATDR, which are, I would say, very logical things to look at.
And as I've said, Jonathan, I think, covered in his keynote and other talks, so if you haven't missed it, I'll record it. So, oops, that wasn't me, I think, at least. So AWAP is visibility and observability. A little bit like IWIP, but with an O in, because as I've said, IWIP falls a little short in saying, okay, this is wrong, but doesn't fix it. And it's probably way more platform-focused nature, which is visibility of agents, so which agents exist. So it goes into discovery, into agents, so the characteristics, the context of agents.
So not only knowing, okay, there's an agent, but also better understanding the agent, the activity, and that leans down into the DR thing. And that's why I said it's not versus, because at the end, these are very, very closely aligned things. Structured insights, dashboards, NLP query interfaces, usual stuff. Ability to act upon visibility based on the signals from ATDR and other sources. And it can do everything from nothing, because everything is fine, to report about something, to contain, to maybe finally kill.
So yes, it kills, which is the last resort, but it may be in. So it is really platforms that are integrating visibility signals from a variety of sources. And then we have the ATDR thing in a sense, so the threat detection response, where it's about the behavioral analytics, multidimensional of agents and the entities that are invoking the agent. I think this is where the multidimensional thing comes in. The context, the real-time analytics and response element, signal-based integration, delivering information to AWAP and other tools, also XDR, as I've said, it's the integration to everything.
So it's really the detailed threat analytics monitoring takes place here, while AWAP is the model layer on top of this. And I think we need both categories. They may have different names when our friends from the other really big analyst firm come up with something, but I think that's probably some structure and some type of categories we should think in. And we see already that vendors are starting to build stuff that probably will fall well into this. And obviously there also will be sooner rather than later, the first market analyzer stuff and leadership combust things around that.
So we need technology that helps with understanding, monitoring agents, putting it in context. But it is, and that goes back to the initial point, it is definitely way more complex than in the good old deterministic world of black and white, yes and no. It's really different. So we may have a little time for questions. And as usual, the typical QR code. So I think, by the way, QR codes are a really bad idea from a usability perspective.
I hate going to a restaurant and being asked to scan a QR code to look at the menu at, I'm 60, so looking at a menu on my smartphone, it's not the right thing for me to do. But anyway, we have these QR codes here. You may use them, even while they're a bad idea. So thank you.