Well, welcome guys. Please sit down, take your seats, take your microphones.
And yeah, the topic is really interesting and quite philosophical. It says, I Know You Got Soul. And the question is, do we actually, should we actually treat AI agents as non-human identities or machine identities? Or are they indeed something else entirely? I guess we should probably start by giving everybody a quick chance of introducing themselves, who you are, what are you doing in this area and what's kind of your motto about AI agents?
Okay, let me start. Hey everyone, I'm Zsolt Varga. I'm a co-founder of Riptides. I have an engineering background and at the infrastructure and runtime security. I've worked at a previous startup and that was sold to Cisco. So I was at Cisco for four years and then we started a new venture and we are trying to tackle the runtime security aspect of the agentic error and workload security in general.
And yeah, as for the question about... Hey, I'm having issues with the microphones.
Maybe, thank you. So as for the question about how should we handle or our agentic workloads should be handled like humans or not, I think before getting really into the context, I think certainly it raises some questions about the security models that we have today. So I think we have to think kind of like out of the box and so it would be easy to say that, okay, it's just another workload and the necessary technologies exist to control those. But I think it's a much more complicated question and I think we will have time to discuss something. Thank you. Hello everyone. My name is Mark Rehmer.
I'm a partner with UI. So I've been working in the IAM field for around 13 years now from strategy development for IAM implementation.
Recently, majority of audits governance focus.
So from the risk perspective, also from regulatory perspective, seeing what's changing at the moment in the market, like how clients are at the moment implementing the IAM AI journey and also looking forward what's coming from regulatory perspective and looking at the EU AI Act coming live in August with the high risk elements of it and how it's implemented then from client perspective mainly and also what the clients are asking us, how should we treat this and maybe it can also give a glimpse on like how we from audit perspective look in this field in the next busy season following the winter this year.
Because we're also adapting our audit standards to this regard and my perspective actually is from, yeah, it's another type of non-human identity. It's being implemented, of course, a new complexity and yeah, technology behind it. Can you do something about my phones? Okay.
I see that from we had robotics at one point a few years back for automation that was treated to link to personal identities from government's perspective and yeah, so I would say let's go on to this pragmatic, see what's there already in frameworks, how we can maybe extend it to AI identities and I'm happy to join the discussion. Yeah, my name is Gerhard. I'm with a company called Curity. I love technology and I believe that technology should simplify people's lives and also make it secure and easy.
AI agent have it, they can make people's lives easy but they also introduce risks and at Curity we focus on access intelligence. What does that mean really? We tokenize the access and every access has to be justified with a token that is minted for that transaction and if you map that to what agents should do or should not do, we will have a discussion of is it a non-human identity, is it a human identity, is it a separate category and how long should that identity live and should you log every identity of every agent somewhere in a directory?
I don't think we should but we should treat them as a category and having zero stand privileges and allow them to do what they are supposed to be doing for that transaction and that's, yeah. Right, right.
Well, I guess I have to make a short confession as well because as opposed to many of my colleagues at Kubernetico, I'm actually not an identity expert at all. I come from a developer and cyber security background and to me this whole notion of non-human identity has always been weird. Like there are clearly human identities, there are clearly machine identities which both existed for a long time. Why are we suddenly inventing a new term to call the things that already existed and then trying to clump AI agents into the same category as well?
Do you really think that AI agents are just a new type of machines or are they kind of almost humans but they will definitely evolve, they will be smarter, more autonomous, more intelligent. They will certainly replace some kinds of humans so shouldn't they get a little bit more recognition for that?
Well, you know, when stuff becomes software, right, you need to think about it. Or software becomes stuff, so that way around, yeah. So I think they need an identity. Typically they're attached because they always act on someone's behalf but they clearly shouldn't have the same privileges the user has, yeah. You wouldn't want your agent go wild and buy things for you when you're asleep, yeah.
So, you know, giving them a human-like category, I think. They're clearly not humans, they're not machines either, yeah.
Yeah, I mean looking at especially these cases when what happens if an AI goes wild, who's responsible for that, yeah. I mean you can attribute it like what's the cause, it's the AI, but who introduced the AI agent in the end, right. When you look from current governance models, you have the organizational model, you have as a manager you're in charge of recertification of provisioning rights, yeah, you have the processes there.
So in the end the manager in one business area is responsible and this manager is also the one introducing the AI in the beginning as like looking from organizational perspective. So that accountability from my perspective is clear but then it comes to how do we like use it in the processes in the end, yeah. Is it the same as it is today or do we need to find new models around that?
Yeah, I think it's, excuse me, so first of all I think that this non-human identity term to me is a bit more loaded or I don't know, I don't really like it because we just started calling credentials non-human identity and simply those are just credentials and I think we are getting, you know, derailed if we are, you know, coming up with silly terms just for, you know, the sake of I don't know what. So the thing is that that's one thing that I think it would be very important to have proper identities for workloads.
I think it would have been good to have that even previously, so for traditional workloads let's say, but with the agentic emergence it's more apparent that the current, you know, security model for handling machine-to-machine or workload-to-workload communication security it's like we stuck in 1970, I don't know, it's just not going to cut it.
So that's one thing but I think so to me what's important or what's interesting with agents I think there are some aspects which seems to be like human kind of behavior but there are a lot of things which are totally different and for example, so if you have obviously an employee there are certain aspects where you don't have to, let's say, enforce the employee to don't do such simple things like behaving erotically in the workplace or whatever usually because there are social contracts that the employee understands, there are cultural references, so there are lots of these kind of pre-existing, you know, kind of self-enforcement so basically what you have to do in terms of access management is on top of that, right, so so whatever else there is on top of that within the organization but that's not true for the agent.
So for the agent you have to be not to take at face value that it will behave correctly and I think also how those agents and the agent systems are built up they are trying to mimic human behavior and this is also a risk to acknowledge that like a normal human behavior so they act like they have some kind of passion or those kind of emotions so it's, I think it's risky to, you know, base on that assumption so I think we have to come up with different kind of security models for that and just one other example is that I think also this kind of simple access management controls, I'm not going to cut it simple for the reason because there are aspects where a particular action is certainly justifiable and then in the next second the context changes and it's not so for example let's say you have an application and or an agent application and you have provided access to call out to the internet let's say and that's totally fine but if in the next second some PI comes from somewhere or the user provides some PI that taints the context and so after that that outreach to the internet is much more risky so you have to evaluate basically at one time all the context.
Right, well to be fair it does apply to humans as well right so you should not single out AI agents for that kind of risk. No, sure, yes. By the way let me just remind to our audience feel free to join the discussion if you have a question just raise your hand and in the meantime I guess I'll ask another one of my own questions. So the more I listen to presentations well yesterday and today the more I have this feeling that again kind of we are mistreating our agents already and it will only get worse in the future. Aren't we kind of creating the kind of digital slavery even?
Or should not we or maybe even consider like we came up with a funny acronym earlier today HAIR for human and AI resources, a centralized kind of management area in the company which would apply the same rules and policies and processes to both human employees and AI employees if you will because the border between them is going to be more and more blurry in the future. So what's your stance on that kind of idea?
Well you know I think traditional AI has focused on proving that the person that accesses something is the person that actually should get access right and I fully agree with my panel colleague here that with an agent you have to look at context almost in real time every time an access happens and that requires you know tokenization, short-lived tokens and a new approach to it to justify the access almost at runtime yeah and I think that gives us a better chance that agents don't go wild.
You know he said it perfectly right you ask an agent to find vacation for you and then you go asleep and you're happy because you found a great vacation deal yeah and then the agent doesn't sleep yeah he goes and buys more vacation and if you have this standing privilege a lot of bad things can happen and that you need to prevent in like lumpsumming agent and humans together I think there is a difference yeah.
Agents also don't live forever they have a different life cycle so you know you need to look at context and yes attach it to a human being if it acts on behalf of that human but still you need to have a log that logs all these things you may not have to have a directory entry for every agent that I don't think is feasible and cannot be managed even now.
But why not I mean if you already can have a company with now hundreds of thousands of human employers which prevents you from having a directory of hundreds and thousands of AI agents it's not the matter of scale well yeah I guess it will be become worse in the future automation is needed but scalability is it an issue? If you have a set of rules what an agent can do and what a human can do and you combine the two and and the sum of permissions you know the limitation of what a corporate policy says and what a human can do that will give you the same result. Should I start?
Okay to your point that you just mentioned from my point yeah to the point that you just mentioned in my opinion I think or in my point of view the accountability is the difference between agents and humans because if an agent goes wild you can okay I own the agent or I am the one who created it so I'm accountable for it whereas if a person goes wild you can hold that human identity accountable for it so would that make sense as a differentiation for you?
Well that's a great question and I think we can refer it to our panelists so accountability well obviously it exists for humans as well but agents we call it delegation I presume so what can you tell us about that?
Well today we have controls in place to help so today I don't I don't have like a beacon on me or what it's an influence okay so today we have controls in place yeah already so we have segregation of duties as a concept as a concept so we have an organizational model we limit the access to certain to certain systems yeah for one human identity we don't give one employee access for the whole value chain yeah for the whole business process if you think about it in agentic terms yeah the more access we give it and we maybe ignore concepts like segregation of duties the more risk we attribute to the to the AI and I think today even organizations struggle to it starts with repositories usually yeah to have a complete when you look at current CMDBs applications are not fully listed IDVs and internal data processing is not listed so with legacy IT that's not already managed in a proper way now we're introducing a new type of IT and where are agents used in which at the moment we see it's a bit like wild west the organizational state they try out what can we achieve with AI do we have savings to process efficiencies yeah I mean this is all fair like we in this trial phase but now moving it to a more governed body and I think like starting with the repository where I'll be using AI and then trying to apply current models I mean it may not work for all aspects of AI but I think it's important that the concepts are already there now we have control processes we have like before process when we give access rights when you give access rights for the provisioning we have recertification we have SOD this is all in place already yeah we should try to apply that at the beginning before we like think okay we need something completely from the blank sheet and it should always be aligned with the current AI strategy in the organization so it's not a parallel thing that's in another silo.
I think I'm obviously I'm not experienced on the legal part of things but I think it seems like to me what you said is like okay we have some kind of controls but let's acknowledge that there are different kind of behaviors with the AI agent so traditional applications that I mean stick applications there is always there was some human touch somewhere either the engineer or the coder or whoever who wrote it or somebody who instructed it and then it did something so eventually if there was an issue there was a human at the end of the end of the loop or out of the way who can get hold accountable now obviously if there are there are agentic use cases but actually there is a human right so human ask for something and so in that case the human can get hold accountable right but we are getting into the into the area or into into use cases where actually there are autonomous agentic applications now there is no human to hold accountable so I think to me it's somewhat similar like to autonomous driving and I think there are a lot of legality nightmare around around that topic as well if there is an accident so to me it's very similar between agentic applications in an in the autonomous way but one another you know aspect that I wanted to to just raise maybe it's a bit strict but I think the whole notion about you know giving so to me AI and AI driven applications those are tools right so I don't really like the sentiment that hey AI will solve this or that no we are going to solve it by using AI as a tool so I think it's a different kind of sentiment when we say AI will solve it or we are solving it you get what I'm trying to say so I think just to me it's important not to be you know be mistaken about what this is this is a statistical you know machine that basically based on you know mathematical formulas to try to figure you know what would be the best next step but it's and maybe it's could be similar to how the human brain works but still it doesn't have the same contracts as we have within the society so I think that's an important distinction but doesn't it imply that basically legal and ethical issues are more complex and complicated than technical ones yeah I would say so yeah and and also I think the technical technical problems are I think very hard and seems very slow but compared to societal change or legal system change or this kind of stuff those can be much much more you know slower and so yeah I would say those are harder issues to solve you know I mean it's a question of what comes first right you have a technological capability and then you need to address it in a corporate environment and so that's the challenge we are having there is not really a way around it because prohibiting it gives you a competitive disadvantage not addressing it gives you a risk you may find yourself on the front news front page news because of a cyber incident so you have to address it and it's natural that technology advances and you know some regulation has to follow yeah but there are technical tools to you know in a way govern access based on policies that are in place we just need to implement them yeah right you know this reminds me of a somewhat kind of parallel and similar issue in the field of cryptography everybody is talking about post-quantum cryptography but nobody actually wants to implement it until the actual quantum computers suddenly arrive tomorrow but of course the deep inside we do understand that it will be too late when they arrive so we have to start early can we start early with some technical measures on this whole AI quote-unquote ethics and responsibility and delegation issue and maybe we should just kind of make this your final takeaway to our participants as a final question for this panel so what would be your most critical recommendation to our viewers so I think there are tools out there that govern access at the time of request but my recommendation really is start now don't wait for perfection you know talk internally there's a lot in organizational talk to partners talk to vendors and start acting now and if you have one use case or two use cases that you can address address those but don't wait because as I said if you prevent the use you have a competitive disadvantage if you let it happen you have shadow id that also introduces risk so you know accept the challenge and start yeah also from my perspective there's from legal perspective no room for waiting yeah so as I said a UAI act is going live on August 2nd with the high risk areas then this two framework is an RFP also 4201 is in RFP so there will be yeah especially there will be governance around it there will be compliance needs and also from audit perspective this will be in the next busy season and next audit season we will look into AI as part of from this perspective so there will be there's no chance to wait yeah but so but the thing is start pragmatically think about governance models that you already have in place how you can extend it to AI and this will develop over time there will be yeah tryouts yeah it's a new technology so maybe resolutions around this one over time but waiting until like the perfect solution exists this is going to be too late because you want to apply AI now you want to have the benefits now and as you grow from value perspective you also need to grow from compliance and governance perspective in parallel yeah I think I'm completely agree with Gerhard on this I think generally I cannot add that much to it just maybe more direct is that I think yeah on the problem I think if you if you don't not going full throttle on AI you're going to lose on the business side of things but acknowledge the risk acknowledge the problem and don't wait until you you got breached because that's that's that's my final advice right well thank you very much guys it was a really insightful conversation so please a round of applause for our panelists and of course of course the recommendation applies everywhere in the security and identity and AI anywhere in IT just don't wait you cannot afford waiting because we are already collectively too late for almost everything so we have to run even faster just to stay in place great thank you very much this was actually the end of our track today