Pleasure having you here. As usual, I'm the one to do the first talk. The title is a bit boring compared to what I hopefully will present, but it's about identity security for everything which includes AI, but not only AI.
So, obviously, yes, I will touch AI identity, AI security, but I will also talk about some of the other things. But I want to start with something which my colleague Matthias Reinwald brought up recently. That's from EIC 2019. The summary of the key themes of EIC 2019, seven years ago.
AI, decentralized identity, identity fabrics. So, I think a little bit of a proof maybe that this is the place to learn about the future. I want to start with identity fabric. This is what I talked about last year.
So, this was 2025. The identity fabric for the 2040s. And what I basically did is I added some aspects.
So, we added AI and smart infrastructures. So, we extended the list of target systems. We focused on a more modular approach. We talked about the mesh.
So, really understanding the identity fabric as something which orchestrates adding orchestration platforms and central authorization platforms to the identity fabric. Starting to talk about signal exchange. We have right now at the SSF, the shared signals framework as an important thing. And I want to start with the identity fabric and add a little bit of update again here. And to explain it, I'll go back to what was what triggered the identity fabric when we started it several years ago. We stepped back and asked ourselves, what is the job of identity management?
The job of identity management is delivering seamless yet secure and well-governed access for everyone and everything. And this was in from the very beginning to everything like services, systems, applications, and not to forget in the age of AI data.
And so, this is a bit, maybe a bit more clear perspective, very close to our initial identity fabric picture. Looking at, again, the signal sharing. I moved it up because I think it's just where we interact from an identity perspective with everything else like cyber security services. We have the structure of capabilities to services to tools. And the capabilities are structured basically, again, around, I still tend to use the administration analytics or the authentication to 4A.
We have the integrations, both bespoke integrations to model legacy stuff to IAM, legacy IAM and the standards-based integrations. And we have the central layers. I talked last year about the orchestration layer, the authorization layer. We should think about a data and relationship layer, a sort of a graph we have here. And AI is a bit everywhere.
So, it's probably not a layer of itself, but probably something which plays more a role everywhere. But it's around identity relations, analytics, AI-powered UX, stuff like that, which we have. And we have the different types of identities. And I thought a lot about the terminology because I never was super, super happy with non-human because it's a little bit of a fussy term.
And we structured it right now around autonomous identities, so the ones that are acting, so to speak, autonomously on their behalf, like an AI agent, which falls into that category, and dependent identities like workload identities, like identities of things, et cetera, that don't have this level of autonomy because an AI agent, in a sense, is way more, or an AI identity is way closer to a human identity probably than to a workload identity. And so, it's just a proposal, but I think we need to rethink a bit the naming and the structure of it.
So, identity fabrics here to stay. Some updates here. And what I then like to introduce is a cybersecurity fabric.
So, in a sense, a counterpart to this. And again, looking at a purpose, what is the purpose of cybersecurity? It's secure and resilient data, so information, as in information technology, and operations, the technology in information technology. We're relatively good on the technology side. We're not so super good on the information side. But it's important in the context of AI.
And so, when I look at a cybersecurity fabric, the structure, again, is pretty much the same. So, we look at the structure of capabilities because we always must start with the capabilities, not the tool. This is what we need. We need to think about which capabilities do we need, how do we structure them into services, which tools deliver these capabilities. The capabilities, in this case, you'll see it in a minute, are structured around the cybersecurity framework.
Basically, we have, again, these different types of actors, in a sense. So, that do something with systems which can be the autonomous ones or the modern dependent, lesser autonomous ones. We have services we protect and data. It's a bit of a misbalance here.
So, basically, data is equally important to all the services. But my PowerPoint skills are a bit limited and I didn't want to use AI to create my slides. I did it purely by hand, in this case. We have integrations.
Again, what we should think about, like in the identity fabric, how can we deliver, on one hand, an API, a consistent API layer, so a cybersecurity API layer like the identity API layer, and how can we, on the other hand, share signals. Again, signal sharing is essential and I really appreciate that we came to standards like the shared signals framework that help us in better sharing signals, telemetry data, et cetera.
So, as I said, the structure of the capabilities follows the NIST cybersecurity framework with identify, protect, detect, respond, recover, govern. These capabilities then are mapped to services that could be the SOC service. It could be business application security. It could be third-party risk. It could be data security or OT security or AI security.
So, always a little flexible. So, this is not a definite list always. It depends on your environment, what you need in services. And this is then delivered by tools, which can be more on the platform side of things or on the modular side of things, depending on whether you lean more towards platformization or best of breed. It doesn't matter in a fabric because it's about orchestration. It's about bringing these things together.
And again, there are some common layers to be loaded, which is, again, orchestration. Orchestration then also is a functional integration of components, but it's also signal integration.
So, there are different ways of integration to look at. And it's also admin flows. I think from the admin flow perspective on the identity side, it's also the user flow. The admin flow here on the cybersecurity side is probably more the admin flow. Data integration layer, a seam without functionality is basically sort of an integration layer.
And again, AI is everywhere. And when creating fabrics, the logical next step would be AI security fabrics.
So, when we look at an AI security fabric, the question again is, what is the purpose of that? Why do we need this AI identity, AI security? We need to ensure that AI does what we want. Seamless and secure, safe, not going rogue, well governed, reliable. This is the job we need to do. And we need, again, something that is about who and what, left-hand, right-hand side, about capabilities and the other thing.
So, you will see, or you already probably have seen, the structure is quite similar. The who, that could be, again, autonomous and dependent identities, like the humans, the digital twins, the digital co-workers, or autonomous agents and bots. Or it could be machine workload identities, whatever else. Capabilities structure into AI security and safety.
So, safety would be the kill switch or containment. AI identity, so dealing with the identity, assigning identities, knowing the discovering. Governance goes already into discovery. And AI explainability, a very important point. We need to be able to understand and explain what has happened, et cetera. We have some services, and they are things like discovery services, visibility, observability services.
The XLM, so small or large language model security. Resource access authorization, a huge theme. As you all, I think, know, data security, et cetera. And then we have tools, again, to deliver, which could be more the platform or more on the best-of-breed side. I think it's really something which is not put in stone. This discussion is really old, best-of-breed versus suite, we call it.
Right now, we call it platformization. Always the same.
Like, we need AI identity management. We need MCP server and other resource server authorization. Security platforms for the language models, agent discovery, behavioral analytics, and a lot of other things. And that is to protect the what? It's actions taken by AI and by data produced, delivered, changed by AI. To all the resources, and very important, this entire thing does not stop at an MCP server level. We need to think until the back end.
So, the MCP system which is behind it, the database which is behind it. This is where we really need to think through, because if you just end up authorization at a level of an MCP server, et cetera, it's a very coarse-grained authorization. It's a bit like web access management in the 1990s. We need to go beyond that. The full way down end to end. And this is, to my perspective, built by a mesh of agents.
So, the technology will be probably, or AI security, be a mesh of agents and a mesh of signals that are used to transport information across all these interacting agents. I think this is one of these fundamental paradigm shifts.
So, until now, our thinking is Martin has access to SAP. Now we have situations where Martin does something and then an agent does something that triggers other agents that do something and end up at some resource service. We have no idea where it ends up. It's a mesh. It's sometimes a mess. It is something which is very different to everything we did before. It builds on LLMs and SLMs. And all this together, as you've seen, there's a pretty consistent structure. This is what we need to look at. And these fabrics are related to each other.
So, there's the cybersecurity fabric with the big picture. The identity fabric that helps us taming the complexity of IAM. And the AI security fabric, which helps us securing the new complexity.
So, we need the one because no security without AI and no AI without security. The identity is a central element of AI security. And identity security brings together these things. But we have different perspectives, different stakeholders.
So, I believe it makes sense to also have different fabrics that give us different views and help us to solve the different problems. But keep in mind, all of this is related. One of the big challenges, and this is not a finite list, we are facing is everything we didn't solve in the past years backfires with force now.
So, dynamic authorization management, we are still not yet there. Even while this year is the 50th on the mainframe.
So, we know how to do dynamic authorization for a while. There's no excuse. We always did technology security firewalls instead of information security. Distributed data centric security, who has a perfect access control for all this data, warehouse, business analytics, et cetera, where many systems come together and where you have complex decisions to make? Probably no one. Identity relationship management, crafts, et cetera, still not really good. Automation.
And so, we need to work on this to solve the challenges we are facing. The next thing I'd like to look at is where does decentralized identity come in? And I believe this is something we should think about, really, because AI is something that autonomously. And in that sense, decentralized. Centralized identity approaches won't fit for this world.
So, all the things that come from a traditional centralized world, like some of the federation standards, may be part of the solution, but they can't be the full solution. We need to think about the role of decentralized identities in that game, like, for instance, verifiable credentials delivering information about intent, consent, et cetera, across the chain, across the entire mesh of agents.
Again, a slide from last year where I talked about decentralized identities and signals coming together for, I called it back then, policy-based access control. I think it's more than policy-based access control. It's probably a signal-based access control because we will not be able to describe the policies. If we have 50 or 100 or more signals in a single interaction transaction, no human is able to create that long policy in a written form.
So, we will need AI to do that to deal with the signals, which is a bit of a challenge of a recursive distrust, but I think it's very important to do. And the AI identity plays in this role where these identities basically can act rather autonomously on these decisions, and authentication authorization will change. We will need to be able to identify an agent by the attributes, by the signals, and we can do that. We have everything we need. We need to work on that.
So, traditional IAM is something which tends to fail when we look at the new world of AI identity, AI security. Humans are far too slow for machines.
So, this is fast-moving at scale, doesn't make sense. Static entitlements, dynamic environments, obvious, doesn't make sense. Our traditional direct entitlement assignments, Martin can do that in SAP, doesn't work for the mesh of agents. And all this is non-deterministic. We also don't know which agent will knock on the door of a resource server the next minute and ask for what and why. We just don't know it.
So, we work in a different world. We need to rethink.
Also, something from last year, from one of my presentations there, where I said, okay, we need to deliver. Organizations need to work on AI. They need to deliver better products, innovation, business process improvements.
So, we have the technology. We use the foundation of data. We don't protect it well. And that is why we need an AI-controlled framework around AI identity, as I said, security, safety, all the stuff which make up the AI security fabric. We need it to enable the business to move forward. And that means we are facing a lot of tectonic shifts. Some of you have our workshop in the morning.
So, there are a lot of fundamental changes. I don't want to go into detail. The recording of the workshop will be available where we discuss all of these tectonic shifts. There will be a lot of research. But it's very clear the entire thing is fundamentally changing, as I said, non-directed, non-deterministic, a lot of new challenges, multi-tier authorization, et cetera. For the fabric, the next thing we will deliver, and this is just a bit of an idea where this is heading, we will, in the next step, deliver also our reference architecture for that.
This is something I did a bit ago, looking at the pillars of AI governance, AI security, AI identity, and there are quite a lot of elements we have that we need to bring together to build this AI security fabric in our organizations. Some of that is here, some not. There will be an interesting evolution, and it will lead to new market segments. There will be new technology areas. My colleague Jonathan defines some of them. I will talk later this week about AWAP and ATDR, so agent visibility and observability, not just visibility, but also solving things, platforms.
I will talk about agent threat detection response. Jonathan will talk about other areas. There will be new tools. There will be a lot of things, and there's a lot of stuff to do. That's what I want to end up with.
We need, as an industry, as a community, work together, and to quote a German comedian, I can't take care of everything, make the most of it. Thank you. Congratulations on being bang on time. What else? A tough act to follow, but we do have one question here. You packed a lot in there, tectonic shifts and the like, but the question here is, what is the most practical first step to move from this fragmented visibility that everyone's got to a coherence governance model across all the identities that you mentioned? I think that's important.
When you look at all the new types of technologies, when you look at the tectonic shifts, we don't have solutions for all of that. We can take tactical measures for a lot of them. We talked about this in points. The one is discovery, so understanding which agents do we have. We can't protect, we can't govern what we don't know, so discovery is a logical starting point. The other edge is the access to the resources, so in front of the resources to do as much and as good an authorization as we can do at that time.
It will evolve with more signals, with different types of authorization mechanisms, but it's still the logical starting point, because this is a sort of a control point. We can get a grip on all the agents.
Great, thanks very much. Moving swiftly ahead to our panel, please take a seat. You're on the panel.