So, I would like to talk about navigating the agentic AI landscape and my first question I think for all of us is what does agentic actually mean? Does it just mean add another zero to the budget estimate?
Well, I suspect that what it actually means for us is there are four properties which are new to us in IAM and indeed cyber security and these are actually new attack services that current frameworks are not scoped for. So, as I say, it is autonomous, it is tool using, it delegates and it is continuous so it will make decisions without a human in the loop unless explicitly instructed. It will call APIs, databases and so on.
It will, and people get quite excited about this in many ways, it will spawn sub-agents that act on its behalf, again, without human intervention or instruction and it is continuous so while we're asleep or at conferences like EIC, it runs 24 by 7 and all of this is actually a very subtle change and that's what I'd like to explore today in this presentation. So for the next few minutes, I'd like to propose this map of the territory to you. So the things that we're all familiar with, protect, observe, detect, respond and govern now have some AI related focus.
So we have AIAM or A Identity which is the identities of these agents and we know, for those of us who have experimented, things go interestingly wrong in weird ways if we just let it use our identity which led to a somewhat frantic conversation with my CISO a couple of weeks ago. What on earth are you doing crawling over our inter ID? We have APGE which is the guardrails and this is the policy and indeed the enactment of that policy in coder's law if you like.
We have AVOP, one of the most important points and something that came up yesterday in our workshop with Martin and Matthias is we haven't got visibility and just a quick show of hands to make sure we're all awake, has anyone got visibility and inventory of their AI agents in the organisation? Which is pretty much what I'd expected.
So ATDR, again the analogy of ITDR. When we see unwarranted, unusual phenomena, unusual activity, then we need to have threat detection and response and of course generative AI defence. We are using these models, some may be hosted internally but we are going to the frontier models and the purpose of generative AI defence is to protect the model from the users and also protect the users from the model. And finally governance, so how do we audit agents which are ephemeral, changing and autonomous? How do we orchestrate governance across our fleet of agents?
And all of these I think are questions that we as practitioners, experts in the field are going to need to address. So this by the way slide gets a laugh in London because everyone sees these things every day. Patrick tried to teach me the German for it but I'm afraid it escaped me. So what's missing? What don't we have? Well actually quite a lot. Agents have no HR file, there's no official record of them as an entity in the organisation which means there's no joiners, movers and leavers process.
It can mean there's no accountable owner and when I did the research into GAD I assumed a model is a thing you govern. By contrast, an agent is a thing that acts. So it needs to have an identity record. It needs a life cycle. It needs a manager of record and an audit trail that's tied to a human sponsor and like I said none of which falls inside generative AI defence right now. For the vendors in here I see missing per instance identity, I see life cycles that are tied to the sponsoring human, so I call that the dog licence model and revocation. We need revocation in minutes if not seconds.
Which leads me on to compliance and audit. We need to be able to audit the activities of these agents. We need to understand if the actions are ultimately beneficial or harmful and traditional security and compliance frameworks were built for us, humans, as I say to my colleagues the ugly bags of mostly water. Thank you. The traditional framework. So my CISO emailed me saying what are you doing? Why are you crawling all over the infra framework? Sorry it wasn't me, it was my agent. Imagine a sequence where the agent that I instruct is blocked.
Now the agent doesn't think well if I disobey a command from the CISO I'll stop getting paid. The agent thinks that is an obstacle to be overcome and so spawns a sub-agent B which delegates to C which calls a SOAR and there you have now a token of authorisation being passed down the chain but also we're losing track again of where the actual accountability lies and as I said there is a legal basis for this, the EU AI Act and obviously we're seeing legislation around the world but I'm most interested in Europe.
Again orchestration, I spawn an agent, a colleague of mine in marketing spawned an agent, somebody in sales decides to spawn an agent to crawl over Reddit and where's the control? Where's the governance? So the agent to agent, agent to tool is all unregulated. Everything that's going on below the human direct instruction is right now invisible to us. So I'd like to think now with you what can we build? What can we put together to control, regulate this and make sure that agents are doing the right thing for us? So first of all we need identity controls.
Every agent needs to be a first class identity so one identity per agent instance whether it lasts for minutes, seconds, months, weeks, whatever. Not per agent class, not issued, not rotated and revoked. These need to be short lived, scope credentials. So guess what folks, if your IGA is still in the good old bad old days of manual creation and hey it doesn't really matter if it takes half a day because the employee lifetime is measured in years, it now matters. The life cycle by the way should be tied to a human sponsor.
And so when I leave an organisation or whatever, the agents need to stop and if you like an analogy to this, it's like the programmer who inadvertently leaves logic bombs in his code after they leave. And again, audit and accountability. We need to build audit and accountability frameworks for our agents. We have two owners. We have authorisation that travels with the agent and audit trails that satisfy a regulator and I was a former auditor and yes, we asked the very awkward questions and we keep asking awkward questions until we get answers.
Or we turn into consultants and just help you along. So consent needs to survive sub-agents. If I issue an agent and I consent it to act on my data or data I have control of, then that consent needs to be delegated and we need a delegation framework in order to distinguish me from the agent again.
As I said, we need continuous authorisation, which means our IAM systems need to be up to the task of continuous authorisation. And something I'm calling ARC, so audit and risk and compliance, we need end-to-end provenance. Every action ties to a prompt, a model, a human sponsor and it needs to be replayable again when the auditor asks a question and says, please show me how that worked. So replayability, which some of us have from our compliance processes in banking, now needs to be part of every agent framework. Coming on to frameworks, orchestration controls. So we need this control plane.
So, as I say, I can't necessarily spawn an agent without some privilege, without some attribute permission. Similarly, agents should not spawn agents at will. There should be a framework whereby this is requested and controlled. So sub-agents are controlled, and we know what's happening, and also we know what's happening at the tooling layer. This means that our NCP servers may need to become a bit more sophisticated, and maybe also our API gateways is something that my colleague Alexei is researching very actively.
And again, how do you trust an agent? How does one agent trust another agent? And this other concept I've talked about here, which is fail-closed. When an agent process fails, the agent should stop. Not try and find a way around.
So if, you know, using my agent example, if it can't get into the entra framework, it shouldn't then use web-based access to Office 365 tenants. This is new. There's no category for it, but, as I say, we are seeing early moves in the NCP gateways in what's happening in agent firewalling. Runtime policy is becoming very important. And we talked about yesterday in our workshop with Martin Matthias. So I'd like to move on to what good looks like. We talked about the things we need, and I'd like to present to you what I think good looks like, what we're trying to achieve.
So we have an agent maturity layer, an agentic maturity layer. So denial. All of you said, ah, we don't have any inventory of our agents. Does that mean you're not using agents, or there's shadow AI happening in your organizations right now? And I suspect the latter. Because I can assure you, in your organizations, there are people exploring, experimenting with agentic AI. Pilots.
Well, this is where we are. So within Cupping a Coal, we are piloting various agentic pieces of work to expedite research and open up our knowledge base. That's where we are. That's where you all are right now. The next stage I'd like to see is inventory. We need to know what our landscape is like. We need a map that reflects the territory. Once we know what our territory looks like, we can then start governing it, because we understand what we have. And so this leads us into ideas like per-agent identity. This leads into scope credentials, audit chains, and, of course, runtime.
And the final stage, if you like, I think the achievable top of the maturity ladder is an adaptive layer, where we have continuous authorization. We have anomaly responses built in. We have agent-on-agent defense. So if an agent detects a trust violation from a fellow agent, it can react appropriately. We kind of co-define security awareness training, and we hope this time it works. And finally, I'd like to leave you, before we open up for questions, with some questions that you should ask your vendors. First question, do you have an identity per-agent instance? Not per class, not per token.
Can you rotate? Can you revoke?
Secondly, is there a delegation chain in the audit log? For that matter, can you integrate with the enterprise audit logs?
Yes, sims are not dead. And can we then tag that with the original human consent, with the accountable owner? There's another question, actually, as I think about that. We may have multiple owners. We may have a responsible implementer in IT who is shepherding this process, and we may have an accountable owner in another business function. But then the third question is, can we deliver credentials fast and rapidly?
And I say, where we are right now, I think it's fair to ask vendors, can credentials be delivered within an hour? Can you scope to a single tool call? Not long-lived API keys. I'm afraid that time is now past.
Again, I would like to see a vendor demonstrating the ability to reconstruct any 30-day-old action. And obviously, I'm picking out from compliance frameworks, like SOP2, like PCI DSS, like ISO 27000. If we can reconstruct actions within a 30-day rolling window, we've got a good chance of seeing what's going on, observability.
So again, this is something we should ask our vendors to achieve. Fifth, can we enforce policy at the orchestration layer? Or is it just something that's going to wave around and be ideal?
Sixth, what happens when an employee leaves? Do agents that are delegated from that employee stop within minutes without any intervention?
Again, show the clause of the EU AIX that they comply with, that their product satisfies. Not supports, satisfies. And finally, and this is something that we talked about again in the workshop yesterday, the control plane and the data plane have collapsed. We do everything through one session. So is the control plane such as it is, is it unbreakable? If it's unreachable, can agents fail closed, or do they go off on their own? Do they make an autonomous decision? So I'm coming to the end. We're going to open up for questions.
I want to leave you with three things to remember from this presentation. Identity is the gap. Every agent is a non-human identity. You have to treat it like one. You have short-lived credentials, a testable trust, and multi-tiered delegation.
August 26, not far away, is the deadline for the EU AI Act. You need to start documenting your audit trails on chains that right now nobody is logging. We don't even have inventory. So you need to start ARC evaluation now. And you should buy the platform, not the pure play. ATDR consolidated. The remaining white space is A identity, AIM, and ARC, which is where we all need to be looking. So at this point, I will open up for questions, if anybody has any. Thank you all very much for your time, and obviously, I'll be around for the rest of the conference.
Thanks a lot, Jonathan, for these insights, and also the letter. I like this a lot, because the denial, sometimes it might be the very first step that we have there. So I want to encourage you to ask questions through the Slido app, and as I have not seen one, so I'm taking the opportunity to ask one by myself. So Jonathan... I don't mind if I sit down, I hope. So the thing is, basically, we hear a lot now about what AI is changing for us. It is changing a lot. Martin was yesterday talking about the tectonic shifts we have.
So if you have here all the security professionals, the IAM professionals, what is the first thing they should do when they come home on next Monday, hopefully, and with all the ideas, what is the most important step from your perspective? Identity is the gap, but observability is the way that we determine how to structure identity.
Philip, my colleague, spoke yesterday on the importance of an IGA strategy, and this is an essential part of your IGA strategy. However, the tactical actions, the things you start on Monday, are getting observability of what agents are running in your organization and starting to build that inventory. From there, the second tactical step is building that continuous authorization chain. Okay. Thanks a lot. So then I have to move to the next presentation that we have, and thanks a lot, Jonathan, again. Thank you.