So I would like to start with a quick introduction round. So if everybody quickly can say your name again and give one key statement about the topic.
Yeah, we need just 30 seconds each and then I will raise the first question to start the conversation. Yeah, I guess it's on Eleanor.
Yeah, I'm Eleanor Merritt. I run product development and product strategy at ARCON. We're a PAM company, best known for that, but right now also exploring agentic AI security like I think many of our co-panelists.
Okay, next please. Thank you. So Jamie Wilkie is from SSH. We're a European provider of modern solutions for IT and OT. And looking at the world of agentic, I would say a few years ago, if you came to a conference like this, everyone was talking about big data and where are we going to get all the data scientists from to handle this huge volume of data?
Well, now we have it. We have the agentic AI. I'm Sanjay Nadimpalli. I'm founder of Tuebora and Stimulate. At Tuebora, we build IGA solutions for organizations of all sizes at Stimulate. It's a new entry that we've created. It provides a cursor for IAM kind of experience to orchestrate any vendor system. Thank you. Thomas Miller-Martin. I'm working as a field strategist for OMADA. We're a European identity governance vendor.
And I think that everybody's talking about solution, but rarely people understand the problem and teams don't have the headspace to take care of the new challenges that are evidently there and need to be addressed quickly. Good afternoon, Dominic Forrest. I'm the chief technology officer of iProve. iProve is a UK-based biometrics company focused on providing very strong authentication and securing many of the world's leading national identity schemes and most attack cyber properties in the world.
I also sit on the agentic AI forum, part of the Linux Foundation that's specifically working on identity on agentic AI agents. So really looking forward to the session this afternoon. Okay. So then thank you very much. Maybe Eliane, if I can ask you to, I don't know, explain the current situation maybe. So are organizations actually ready to govern artificial intelligence identities or are we trying to build the next layer of complexity on top of an already very fragile IAM foundation? We discussed a little bit up front, but I think you have an opinion about that.
Yeah, I think we're all probably in agreement that organizations are not ready for the challenge of identity and access management for AI agents. All of us who are vendors are also, I think, still very actively exploring solutions and we're really hungry for definitions of standards, whether or not they come from within the IAM community itself or via regulations or what. But I think it is really time right now that we all came to come together and align on standards that we can put into practice to enable better safety around AI agents, better security.
It's very easy to get wrapped up in the excitement of agentic AI, but there's real problems around there that we can all either imagine or know of and so those need to be addressed. Yeah, I would completely agree.
I mean, agents are scaling massively and also they're sprawling themselves and maybe that is something for Thomas. So how can we keep humans in the loop then if all those agents appear and they create their own, so they have little sub-agents running all around and probably thousands or ten thousands of them?
Yeah, so I think in the space of identity governance, we were very used to solve problems in the human time, right? So you have a request access, one of the many things that you can do. You have a request access, then there's an approver, maybe he or she's on the Ike, will come back next week and then approve. But when we look at agents and the speed that agents need to be controlled and approved and observed, the human speed won't do it.
So we need to have something in parallel that includes the human speed because we need ownership, transparency, we need to see the drift and people that deciding whether this access drift is still okay in parallel to decision making in fractions of seconds. And that's the new challenge that we need to find out where we need to have this better integration with many vendors, because lots of you are taking decisions in very quick fractions of seconds, while there are other solutions that are rather around the human entity, a business process, etc.
And now where we always talk about identity fabrics and everything comes together, now we really see this demand of more vendors with their individual capabilities are coming together and bringing something. Governance more for ownership and others more for real-time decision making, but everybody has their stake and nobody can solve this alone. That's true and I see a real challenge.
I mean, humans are simply not fast enough to be still in the loop, right? We're practicing. Practicing, okay.
Yeah, if you want to enhance on this. Can I build on that though, because I think actually you've hit the nail on the head with that comment. What is it about? It's an agent, it's doing something. We've been talking about the fact, you know, the scope, to limit the scope, to give a passport to an agent, to understand what it is, to keep it short-lived, to give it the credentials. But at the end of the day, who is giving it the credentials? What is giving it the credentials? That's the human.
So the humans have to be in the loop at the beginning of the cycle and getting the scope right now to do it. And how do you know it's a human and not another agent? Or how do you know it's an agent but it's been given permission to do so? That all comes back to tying it back to the real, live human being who's there right now. So giving that permission at the beginning and getting that scope right. If you get it wrong, you can get very badly burned.
I mean, a personal example this weekend, I had some agents doing some things for me at home and to my surprise on Sunday morning, I discovered one of them was solving captions and doing all sorts of things I wasn't expecting overnight, you know. And that's what bad looks like in the corporate workplace.
For me, it was very tightly scoped. It couldn't do any harm. But how do you know it was Dom that authorized it and I authorized it to do this? That's got to come from the human. We can't do it in milliseconds. We can't do it in thousands of times a second. We can do it on a regular basis. Identity has never been and will never be about a one-off process. It's ongoing. You've got to give that authorization to an agent and be able to trace it. Passport idea, I love. Being able to trace it back to the passport, great. The agent has a passport.
So does a human being probably and maybe that's how you identify them. Okay, so I was also asking myself how can we still keep things kind of at least visible? How can we try to keep under control what's going on here? Maybe that's a question for Jamie. So if AIJs are one kind of a non-human identity and how can we identify them and at least have some logging and visibility of what's going on there? Before I answer that, just to follow on your comment, the people who are missing at the table up here would for instance be HR and a lawyer. So what does that mean?
The liability as for agents which are going off and doing something which you don't necessarily understand. Who's going to come and get you for it and what protects you? To come back as to your question though to the visibility, I think the first thing is to try and as it was slow down our thinking. We're talking about masses of agents working very quickly. But just remember each agent can be given an identity, must be given an identity.
There are schemes out there at the moment as a spiffy spire, as an open source, as a project which is designed for machine identities even before as an AI actually. But it is in a position very quickly to create an identity which can be so authenticated and which is traceable. And that's the start. The trick is to implement that in a system which is then going to be as a fast enough to be applicable to AI. We're not slowing things down, we're enabling things.
First we need the identity and then we also need to give as a guardrails as to what the AI agent is doing, precisely the point that you were making because they go off and they do creative things which is sometimes good, sometimes bad. And we need to be able to trace back what the AI agent has done. So some kind of as a recording mechanism is also necessary. We can go back. The other thing I think which is necessary is to be realistic about what AI agents are good for and what they're not good for.
So if I think in the OT space, I don't think you're going to have AI agents controlling safety systems which have to react within a fraction of a second, SIS systems, and stop a bad accident from happening. That's not going to be the space of AI agents. But if you're looking at a factory which is perhaps as a controlled by AI or which involves AI, that could be really useful for scheduling. So we need to find also the right domain to use these tools.
Okay, so maybe Sanjay, you want to talk a little bit more about how actual solutions could look like then in this area. So I think we described now quite well what is the challenge. We understood we need to identify those AI agents. We need to understand what was original user intent. But then how should all these things come to life? Do we have some ideas, some solutions in mind how that could look like? Sure. I think good coverage on the pain points and the fact that we're all trying to figure out.
I think one of the things to look at is foundationally we have to treat humans, non-human identities, and AI agents as kind of similar. There are some semantic differences, but if you try to treat them as different pieces in your architecture, that might potentially become an issue because it becomes very fragmented approach. Because the whole operational intelligence of your environment from identity standpoint will be completely disconnected and inadequate.
The other thing is to the point that he was making, there is traceability and it's also important to understand because of the chaining that happens, it's very important to understand the whole things surrounding from who delegated it, what workflow happened, and what EPA was executed, what PAM credential was used for that, which system got modified, the entire audit trace becomes important. So make sure your audit traceability architecturally is in place as well, especially here.
And then what happens in the past when we're dealing with risk, here the risk is something that has to be modeled on a continuous basis during that flow. It's not that you can compute risk at the end of it. Every chain reaction and action that is happening, the risk model has to be done. And more importantly, policy comes into place throughout this series of activities, right? So the policy evaluation optimally should be done in a way that you're able to execute this. So when we're really talking about access governance, we had a certain framework, certain methodology to do things.
Today we are talking about execution governance. So the kind of a different beast in itself, right? Because why, who did it and all that in supposed to who can do it has kind of changed to who did it and the authorizations and risks and policy surrounding that. So holistically, you have to model it in a way that this can be achieved. And lastly, it becomes very hard to discover these agents, right? That are happening. So what do you do?
I mean, some of the pilots we are running, we are not able to solve the problem or even know how it is done because they're so short lived. And many times there are no logs, you won't even know. So you have to find some heuristics to say, okay, this was treated by a human or something. So the natural nature of the agent itself presents a huge problem. If I could just build on that briefly, I think you're absolutely correct. And you know, it comes back to is getting that scope, right, getting the time of the authorization, but also getting the purpose of the intent, right?
The challenge you have, though, is you know, that reauthorization is a process. If you do that, the reauthorization process with agents, then suddenly you've got agents enabling agents to do whatever it is they're doing. You've got to have the situation so you don't end up with the spool that was talked about, the credentials, all the stale credentials. Forget the long lived keys. You issue it. And when it needs reissuing, it's got to be a human in the loop giving the permission to do that. You can't just automate that as a process.
You want to automate it, but that final yes, I want this to happen has to be the human. Not their key, not their handset, not some identity they've had, the human being themselves. And unsurprising, I would say the only way to do that is for the human themselves, the person to be given that permission. And to your point about the legalities around it, if an agent's acting on my behalf, then I should be held accountable for it.
Therefore, it's on me or on the company to ensure that the permissions it's given, that the scope it is given, that the task it is given is appropriate and limited. And if it goes rogue, that has to be on the person whose identity it's using. So maybe back to Eliane or sorry, why I'm struggling with this. So we discussed something about, I think you were talking about kind of an agent registry or something, right? And I think that fits into this discussion.
Okay, what could be the solution? Because we discussed now, how do we identify them? We discussed that we need kind of a dynamic control about what agents are allowed to do. We need to somehow get a connection between the user intent and what then the actual user agent is doing. But maybe we need to have kind of an registry for those kind of identities where we store what they are allowed to do in terms of actions they are doing. And I found that or think that's an interesting approach. Maybe you want to talk about that?
Yeah, and it's very analogous to what Jonathan was just talking about, what an agent passport. But I do think there needs to be metadata that's associated with every agent, which helps a user or a consumer of that agent establish trust, right? So what's its provenance? Who created it? What LLMs were used to build it? What versions? What standards it was based on? If there's a human associated with it or not? And I think we can go on. We can probably flesh this out in much more detail. What should go into a trust registry?
But before an agent can be authenticated to do anything, we need to be able to establish its trust. And I believe in the idea of a trust registry or a passport that's associated with an agent. Because an agent, let's face it, it's not responsible for anything in the legal sense, right? So agents just come and go. So in the legal sense, only humans or organizations can be held responsible for anything going wrong.
So then there needs to be something that an agent is associated with, either an organization or a human, so that again, if something goes wrong, it's these entities can be held responsible. So yeah, I would love to kind of sort of riff on this whole idea of trust registries with anybody who's willing to discuss that with me. And establishing standards around metadata to build trust in agents. Because I think that's really foundational to being able to safely use agents in the world around us, especially in the business world.
Like, you know, outside the business world, you know, I think it gets a little harder. But in a business world where things are regulated and you have to take accountability for what goes on, we need something like a registry or passport.
Okay, so maybe final round, 30 seconds each. But of course, Jamie, go ahead.
Okay, I'll then use it also as a final statement. I think it's what has been really interesting in this conversation has been the speed and the power of these AI agents versus the responsibility of human beings. In a real business process, how do you bring those two together? At what point does a human intervene? It can't be in every single step in the journey, that would be absurd. So where are the right points? And how do you do that in a manner which is efficient for the organization? And does it protect the user against the risk? Thank you.
Sanjay, can we just do a roundtable finishing off? Sure. I think we've seen the internet, the cloud, the mobile and automation, all of them started off with very little governance or security. And the agents are coming in, I think we'll see the challenges there. But I think we shouldn't slow down the adoption of the same, but start with some governance controls, I think we'll get to where we need to. So I think that we have overloaded teams with identity management projects, unable to tell their management what we're doing, why it's super important.
And now we say, factor 100, because you have so many agents coming in, you don't have the headspace to cover that. The next short term thing you need to do is make sure you make your identity management project lean enough, use AI to create those policies that you were talking about, allow things to happen that combine this human speed with the machine speed, and try to reduce the friction between the different solutions that you're using. That's the journey that we're on at the moment, how to integrate each other more and more.
And then in the second space, of course, you mentioned the standards, etc. Those will be established at some time. The entire industry that said identity is the new parameter should not go out and say, we're in front of the game, we know everything that is coming in the next five years, we're playing catch up, everybody's doing that. And it's such an important piece of cyber security at the moment, that we should not take it lightweight and go out and say, we solved everything. I'll keep this brief because I'm very conscious of time. Take one minute, that's fine.
We all have enough problems as it is with identity, even without agentic AI coming into this. Take a step back, look at, you know, MGM a couple of years ago, look at GitHub spoke Microsoft yesterday. That's all about the compromise of a single identity and how much harm it can do. We now have this on steroids, get the basics right, build on those identities of humans, because if you haven't got your basic human identities right, the people in your IAM system, you don't know who they are.
We may have a great system to authenticate an AI agent, to authorize an AI agent, to allow that AI agent to just do that on a very short time scale and follow the best practices. If that person who's using those credentials to do that is not the user you think it is, is not the real, correct, live human being, then all you've got is the attacker starting to drive your agents and give those scopes out. So we have to work together. We know how hard it is getting it right across an entire large organization, but those human identities have to be right first.
And then you can build the agentic AI on top of it. I'm not saying wait. Jonathan on a previous presentation put up a 90 day plan. I think that's great. My personal view is you don't have 90 days. It's moving faster than that.
Okay, with that, thank you very much. Unfortunately, there's no time for questions, but I think all of the panelists are in the room here.
I mean, catch up with them. That's all about. Let's talk to each other and try to find the correct solutions for that. And I think we already heard some good ideas and opinions about that. And with that, thank you very much and take care.