Again, my name is Vlad Shapiro. I have my own company, Costidity Inc., even though I also have other things to do. By the way, for your information, Costidity stands for Cost of Curiosity and Stupidity. Because in my humble opinion, a lot of problems are caused by people's curiosity and stupidity of the policies of the companies. You probably agree with me, right?
Okay, so today we will talk about agentic AI. And the most important thing is we had the presentation before when they're saying that security people hate us, right? Hate identity people. I don't remember who said that, but I think they did. He's not in the room yet.
Well, this is an effort to change the tide. Because I was called by security people to make sense of governing agentic AI, agent AI, whatever we're going to call it. It's hard to believe, but that's happened. So the conversation today will be about how we, as practitioners, can help the security people to understand what's going on with the threats. And the second thing is, as what I usually do at every my presentation, how to sell it to our management. Is that important? Raise your hand if it is, right? Okay.
So what do you think is going to happen if you tell your management something like this? Like, you know, agentic AI, agent AI, AI agent, what is this? The answer is software acting as an agent achieving goals with no human interaction.
Please, it's a software, it's a service, you can call it identity, you can call it whatever you want. But at the end of the day, it is a software running. And by the way, as you know, it has two sides, right? Which one do you want to present to your business? By the way, that image was not created by AI. It was created by Ukrainian creator, lady who is helping me out with the slides. I don't use AI to create that slide, okay? We're going to say software as soon as the management see your software, they say, why do I even care, right?
Serve me, right? You have, you know, then you can say, well, you know, agentic AI is an interesting thing. It's very different from typical thing what we do. So it's autonomous, it can perform multi-steps, it can interact with us and non-human identities and workloads. Don't use those words for management, just say it can interact. And then always completes the mission. Do you see the danger here? Where is the danger in your opinion? In my opinion, it is right here. Only completes the mission. It doesn't matter what happened, it should give you something. By the way, that is used by bad people.
Unlike a human who say, I can't do it, this thing should do something, right? So some serious, interesting people from the security point, very important ones. I'm going to name some names, but you will see. Created this interesting survey among security people and security specialists working with agentic AI. Came up with this beautiful list. I have slides describing all of them, but I'm not going to go all over them because it's too much. But what you're going to say to management, we're going to discuss it later, is like, listen, it is great that we have it. It is great when we use it.
We can't live without it. It's going to be a future. The communication between agentic AIs at the end of the day will be the one. But we have serious risks. Do you think any of this risk is calculable at this moment? No. Do you think any of the companies who are giving you cyber insurance have any idea how to do that? No. You know what they usually do? They will deny your insurance and say, until you show me the risk here, I'm not going to give you anything. So that came back to me.
It's like, OK, what can we do about it? What practitioners like us can help?
Again, I'm not going to go through all of them, but in general, you can probably understand most of the list. The most important thing we have to tell to our business, remember, agentic AI has no idea what we're trying to do. It assumes it knows by us telling them what we need to do. But here is the problem. When agentic AI goes from one place to another, to whom the agentic AI will talk? A lot of people think it's going to talk to database or it's going to talk to some kind of a source of data. Do you know what's going to happen a couple of years from now?
It will talk only to another agentic AI and that another agentic AI we're going to talk to another agentic AI. So every time we're trying to push the policy from one agentic AI to the other one, we're going to have a loss in translation problem.
Also, since we don't know if that particular agentic AI is rogue or not, it's influenced by people who you don't want to get influenced by or not, we have to have some ideas how we're going to do it. So I'll give you a couple of examples. This is a very typical story called agent authorization control hijacking.
Basically, agent authorization control hijacking occurs when an attacker manipulates or exploits an agent permission system causing the agent to operate beyond intended authorization boundaries. What do you think with development of agentic AI, what do you think is going to happen? How often will it happen? Very often. Do you know why? Because we have no idea what the boundaries are. We can say the boundary about our agentic AI, but what's going to happen to the next one? We don't know. So the method is pretty thin and outcome is pretty bad. What can we do about this? What do you think?
What can we do about this? The recommendation in this particular case which I gave them is the following.
I said, every time somebody is doing something, there should be a task at site. What is our goal? Where are we going? What exactly should this task do? I need to produce a financial report for my customer. We should contain his own information about his financial in the last 12 months. If that is the thing was done, it would be a very good idea through MCP or something else. I don't know what's going to be in the future. It doesn't matter. But that thing should arrive all the way to the end and come back. So we know that something not happened in the middle.
Again, there is no mechanism today for doing this, but this is very critical. If we authorize what we know, what we try to do is much better than what we authorize we don't. That's why when you order tickets, probably buying a house in some other country, probably not a good authorization task. Next one is, I'm not going to spend a lot of time on this, but clearly untraceability is a big deal for most of the security people. They want to make sure we know where we're going. Unfortunately, again, there is no solutions here yet. For most of those threats, there is no solution.
So all of the people in the room can actually think about one. But from access control, say, I said, well, here is what I think. The traceability means someone touches something and produces and send more information in, correct? So we don't know who it is, but if we know what information was shared, what message was sent farther, we at least have a better idea how dangerous it is or not. Because the whole idea of agentic AI is not being traceable to the step. But what we can trace, we can trace an outcome. And an outcome, around the outcome, we can put some traces.
So I have some mathematical representation of that as like a matrix, but that's a different story. Okay, next, critical system interactions.
Okay, first of all, does everybody know how many critical systems do you have? How many? Do you know in your company?
Okay, whoever said they know can probably talk to half of the vendors around here and prove them they're not. Because the definition of critical is very different from person to person. But as soon as C-level people hear the word critical system, they immediately think, oh, that's interesting. You know what works in this case? The critical system for me is a system which makes you money. That's your critical system. Everything related to making you money as a company, providing your services, that's critical.
Okay, including people working with it, including agentic AI touching this. So how are we going to do this kind of thing? Put more restraints, port guardrails specifically in the critical systems. Next one is, that is my favorite hacking. Faking vulnerability. Have you seen that before? Not in our space, but this is one of the ways that agent pretend to follow the rule but exploit the root cause. Okay? So basically, you're pretending there's vulnerability, trying to weigh around, pretending they're going around vulnerability, but in reality, they're avoiding your policy. I call the deviations.
I put it in my book a long time ago. How to figure out this thing? We need to see at least the movements, right? And if we run the same thing many times and you see completely different traces, there is a problem. Would you agree with me? Unfortunately, in this particular case, simulations and multiple repeating of the same thing works much better than anything else. Okay? In my last year presentation, I presented here a strange method.
Sorry, it was before Trump became a president. It's called USA.
Update, simulate, analyze. When it comes to this, this has become a critical thing. So in my humble opinion, run it once, not enough. And we have to run it in pre-production mode to test, to simulate what's going to happen before we allow any kind of a system to actually operate like we're doing it in regular software. Next thing. This becomes a huge deal when we don't know the task. What's the difference between task and goal? Anybody? Anybody?
Come on, someone. Exactly. That's a big difference. It's what you do versus what you wanted to achieve. Unfortunately, the goal is what we're trying to achieve, right? And task is what we do. That's not the same thing. So if the goal and instruction can be manipulated with keeping the same task, that looks like we're within bounds, right?
So now, why it's important is because, again, we need to figure it out the way how can we straighten up the process of comparing the goals and the task we're using. Again, could be simulations. It could be put some, again, guardrails around what is within the bound of how we can achieve that goal, what is bad idea, what is good idea.
Again, you cannot define it from the beginning, but if you try to do it many times, it will happen. All right. Next thing is the agent impact chain and blast.
Oh, God. That is when we touch one thing and go to the second, it doesn't mean the third, fourth, and fifth will not be affected. Blast rate is a big deal.
Again, my recommendation from access control and identity control is if you want to know what happens, you have to monitor not one direction what you're doing, but all the adjacent. How do you know adjacent? What do you need to do for that? You have to try it. Then you will see what changes happen in your system while you're trying to go through the main door, right? Okay. Moving along. This is a memory context manipulation. I'm not going to discuss that. Memory security. Within the memory, a lot of calculation going. Orchestration, multi-exploitation.
This is what I was already talking about, right? When several agents are talking to each other parallel, you know, consecutive, this is one of the events we need to kind of discuss and take it seriously. My idea in this case is simplify. Find the simplest way and prompt it to the simplest way of the shortest steps on. The less steps you have, more at least risk you can control, right? More steps you have, you have more problems. Make sense? Moving along. Engine supply chain and dependency attack.
Well, this is about ecosystems, libraries, and everything else. I'll tell you, we are experienced in this, but we don't know yet because a lot of open libraries, a lot of open tools we're using, we have no idea what's on the back. We have no clue, right? So if we put ourselves in the position of thinking, every time we're dependent on something, we have to predict this idea that probably whatever we're dependent on has completely different rules of game than we. Completely different policies than we. Completely different legislative regulations than we. Right? We have to take this into account.
That's a good conversation to the legal people, by the way. Okay? And finally, this is a typical story of if you have a certain loop, which you're in, and suddenly there is ability to, you know, doing the critical decisions without the first sight, and then we can use unsafe operations or unintended consequences or exploitations because we're out of the familiar with us information, that's where we become vulnerable.
Now, when the security people put this all together, they all try to scare us, right? That's the idea. But I'm not here to scare you. What I'm saying is we need to develop together the strategy for identity life cycles, for task-based governance, meaning I have a task to perform, I have a goal to reach. Let's build it based on the business, right?
So, when we talk to our C-level people, we're not talking all of those stand-alone businesses. That's what we're talking about. We're saying we are using it. You already heard the terminology which showed up right now called shadow AI. How about shadow agentic AI? Huh? Doesn't sound really, you know, promising. But this particular case, if we are, as the industry and as the organizations, what we're doing, trying to work on that, that is achievable. Right? The principles are pretty class practices, you know, also pretty definable, right?
One of the things I want to specifically call ownership is definitely ownership and business need. In my opinion, whoever benefits from this should be the business owner. I don't know about you, but I think that's what it is. Coming back to the question, what is a critical system? Critical system, system which helps you to make money. Whoever runs that system, whoever owns that system should own also all of the tools and AI, agentic AI we're trying to use to help to achieve this goal. If they don't agree, they say, well, don't use it. Right? Unfortunately, that's the only way to convince.
But when you go talk to the C-level people, say like, do we know owners and business needs why in hell they're using this? And if the answer is no, we have to find out before we even release this thing. Would you agree? That would be not such a bad idea. Okay? So what I'm saying is we definitely have a lot to do. And one thing which I strongly recommend is including agentic AI into IGA program. Agentic AI is a cool new toy. No company expect to make money out of it. Do you know anyone who really want to make money out of it? I don't. They're using it because it's cool at this moment.
But we as an IGA practitioner should say, hey, we must include this into the program because they have a bunch of different agents, agent of change, agent of communications, agent of contact, agent of enforcement. Right? All of that should be part of our program because if it's not, then it becomes a gray zone and becomes shadow agentic AI. You can use that terminology if you want. I don't know. Maybe I'm the first one who's using it.
Anyway, finally, first security, agentic AI should be protected the same way as human identities. Agentic AI should be limited to assigned tasks only. And agentic AI dynamic logging, token actions result, it must have. Absolutely. Okay?
With that, there's a couple of papers. There's OWASP papers which will coming up right now. I'm not sure if it's still, this is beta version. They're going to be released at some, at certain point. And you're definitely welcome to read it. Thank you very much. And that's it. I have probably one question. One time for one question. Anybody? Any questions? Yeah. All right. I can give you the microphone. Yes.
So, you've used the term agentic, you know, AI, but I actually heard it for the first time, agentic shadow AI. So, really interested to know a bit more on that. I just came up with this term right now. Basically. It's not an official term. But in my opinion, it's a very powerful term to use in front of your management. Because if you say shadow AI is like, whatever. But if you say agent, the word agent immediately kind of clicks inside.
It's like, ooh, there's something serious about that. All right.
Anyway, the whole, the main message is, do not be afraid to talk about it. Think about agentic AI as a part of IGA program. And try to use one of those advices. And please, if you come up with some great ideas, let me know. There's a whole group about, you know, agentic AI. It's everybody's, you know, corporate world. I would say this way. Corporation works great. Thank you very much for your time. Thank you. Thank you. Thank you. Thank you.