Okay. Welcome everyone. Happy to see you after lunch. So today we're going to have a panel. We have a lot of people joining this panel. So the conversation is going to be about machine with identities and securing AI agents. While we were trying to prepare for this panel, there were a lot of exchanges. So it was a little bit difficult to come up with just some questions because we only have 20 minutes and it's a really, really cool topic. So I have some questions to sort of set the stage, but maybe in the last five minutes we can try to open the floor for the audience.
So you guys can also jump in and ask anything that you like. So maybe we can begin with some brief introductions. Maybe we can start with Andre first. Hello everybody. I'm Andre Priebel. I'm the CTO of iConsult, a system integrator focused on identity and access management. I'm in the industry now for more than 20 years. And what should I say? The last two years are likely the most dynamic and changing ones.
Therefore, it's great being here together with you guys and having an exciting discussion about the topic of agents. Hi everyone. My name is Haris Mohamed. I'm a product manager at Microsoft. Been in the technology game for over 20 years and very excited to be here. So my name is Andreas Muller. I'm running the central and eastern sales team for a company called Delinia. I came to Simsung more than 20 years in the market. And as Andre mentioned, we've seen a lot of change over the last one and a half, two years with the one big thing that has changed a lot and developed a lot over the time.
So the AI. Hello, my name is Mikhail Zengalushka. I come from Latvia and work for IFPNC insurance. That's the largest insurance company in Scandinavia and Baltic countries. My role is global. I am product manager, so I'm bridging business and IT in what relates customer and partner identities. And I'm Mike Koser. I do strategy and standards at SailPoint. Awesome.
Well, thank you so much. I'm going to, again, set the stage with some questions, but each of you, you don't have to answer.
I mean, if you want, you can jump in, comment, but it's not mandatory because I have plenty of questions and I'm sure that the audience is also going to be happy to to ask around. So, I mean, the first question would be, why do agents need identities at all and how are they different from traditional applications and workloads, service accounts? Who volunteers? Harry?
Yes, I'll start with the latter part. How are agents different from human identities, from applications?
I guess, number one, you can think about they're not deterministic, right? So when an agent does, can change, it can evolve over time.
You know, an example that I recently heard that really stuck with me was like, hey, if you were to come over to my house and I asked an agent to go give you a glass of water, that agent might go through all of the cabinets in the house, it might go look at the bowl of water that the dog gets, it might go to the backyard and get some water from the swimming pool. It will exhaust every possible path to make sure it can come back to you with like the best glass of water, right?
If I was to go ask a human to do that, my son, for example, he would just simply go to the cabinet and get a glass of water. Agents are non-deterministic in that way. If I went to another neighbor's house and asked a different agent, that agent might go through a whole bunch of other steps to get a glass of water. So that's one way that they're different. And we know that there's different types of agents. They work on behalf of us as humans, where they sometimes inherit our permissions and what we have access to, and other times they're autonomous. They're out there completely on their own.
So yeah. But I think the why part hasn't changed. It's because we want to authorize that or that person or agent to access the asset and prevent unauthorized access. The why part hasn't changed. It's just we're not prepared well for that type of actors, maybe. And what's the alternative, right? If you don't give them their own identities, what are you going to fall into? You're going to fall into an agent acting on your behalf and no one knowing that the agent is doing that, right?
How many presentations have you seen this week that look better, more stylized, more aligned textually than you have before? I guarantee that people are using AI to create slides. Right. Shocker. I'm not against that per se, but how they talk about it.
They say, oh, I made these slides. No, no, you kind of didn't. You prompted an agent to do that for you. And while it doesn't matter in creating slides, it really matters if they're doing important things in my business. I want accountability. I want hard decisions being made. I want a chance to be heard. I want a chain of authority that's been delegated, not just access.
So that's, you know, there's the stakes get really high, really fast. Yeah. And I would like to add two points when it comes to the differences to scripts to human beings. The first one, very obvious. It's about the velocity, the speed to human beings. I don't have to explain it to anybody.
Well, how long do you need time to make your presentations? The agent is doing that faster. But also when it comes to scripts, of course, a script is running much faster than whatever an agent can do. But if you look at the different capabilities the agent can do in that short period of time, it's still on a different league. But the second difference is more important from my point of view. An agent is naive.
So comparing it to human being, when it comes to the kind of confused deputy scenario, no attacker was ever able to convince my assistant, human being, to follow these stupid things like, hey, please buy some vouchers for a customer, these kind of things that never worked out. Agents are very, very supportive. Agenia is very, very supportive. And that's something what we have in mind when it comes to the topic of leveraging that part of technology. It's not thinking the way we would like it to be. We have to build more constraints around it than around the human beings.
And that's something which is an important difference. And other than building these constraints, Mike, you talked about accountability. How can we establish trust and accountability? And these things were already a problem with human users. So what's different? If I may share the story like this from a practical perspective, like I represent insurance business in this on the stage and it's the real thing. It's not imaginary thing anymore. Right. So when like I call them wild agents. So those who you don't own, you don't control.
So these are third party agents who come and try to represent the user and sign and buy like motor policy for the car. And they on the way to the policy, they have to accept terms and conditions. So they accept. So is this kind of policy in force? Let's take it further. The agent terminates the policy for the car and then the user gets his car smashed. And so should we pay the insurance reimbursement then? That's a real dispute. That's a legal dimension. We can argue in this state where we are. We can argue forever maybe. So we had disclaimer.
Yeah, but I didn't see that disclaimer. It was not me. Right. So and now where the root of the problem in this case is when the information is protected by identity now, the user gives control and authenticates for the agent and okay, go and do. What we as a service provider, insurance service provider online receive from identity provider is just social security number and the name. We don't know if it's the agent. And we cannot root this type of conversation towards like path which is adjusted for agentic client so we can like serve it properly and confidently.
What we would like instead to see the ideal world, we are not there, would be like that's the agent A is coming and the user B has delegated or asked him to go and do some stuff on behalf of the user and the scope of authorization, actually the actions which the user authorize the agent to do is like C, like by policy for example. And we know we can control. And the last thing in this equation is and all these three items to identity and authorization have been certified at level C. So substantial enough for us to serve.
That's the ideal answer so we can like make, take some automated decisions and respond accordingly. And if you think about this now from the perspective of digital identity wallets, it's actually the verifiable credential but it should not to the human being but to the agent. We flip the like roles a little and it's the same thing. So before we have introduced, really introduced digital wallets for people, we already are in need of digital identity wallets for agents now, right? So I'm not sure if it happens soon but that's the way at least I think we could try addressing this problem.
Any other perspectives in the panel? Well on that one, so again the same story is something that we had years ago when we had the first automatic brakes go in the cars and so it's always the ownership model. So it's the shared model that we have in cloud so the shared responsibility model. I think it's more about thinking and if we're going back we're now discussing AI so it's a complete new thing.
If we look on it like we would do separate from the speed and all of the other things like we would handle an assistant that is really working on my behalf and if we would handle them like we would or we should handle human beings in the mental build. So it's not really technically possible because of the velocity but if we think back like what we did in the before it would be a good step forward because I would not trust my car. So I still have problems with going to San Francisco and sitting in a car that is driving on its own.
I know every other people are like that but in the end this is the first step into that. Can I really trust that car to brake without me having control? Well I'm an old-fashioned guy I don't know but this is something that is a little bit of tricky thing and the same goes for AI. A lot of companies a lot of entities are now experimenting with what AI is able to do but no one ever thinks about what are they allowed to do and the best AI the best thing they can do is they learn from the whole house and a lot of waters that they bring.
So are we really in the position to allow them and if you think a little bit back going to the old world of OT where you have NT where you have XP and all of the other stuff the way is some one way of it it's not the most productive way by the way but one of the ways is to really limit their outreach which of course causes a little bit of reduction in in the output or control what they're allowed to do like you would do with any human. What's really fascinating is that we are we are feeling our way to what we need.
I think we all know they well I think we all know that agents need identities and we also know that they need strongly attested strongly verified identities. Those are different levels of kind of the same thing but then there are open questions as to when does it deserve a new identity. Is it an agent basis? Is it a session basis? Is it when I change intent? These are all you can make arguments for various levels. I'm making not making argument for one or the other. Nat's talk was brilliant the other day because he tried to lay out a framework for thinking about that.
The standards that are under development thinking about delegated authority and all of this they are they are predicated on having strong attested identities for all of this stuff. Now the discussion still is unresolved I think to some degree about when you get a new identity and when you don't which is pretty interesting. I think that's spot on.
I would just like to add like in addition to an agent being having an identity being bounded to the user that granted it access to work on its behalf it needs to be bounded to context right context that's evolving that's changing because as we discuss the behavior of an agent is evolving and it's changing and who the agents may be discovering out there in the world of other agents they do that on their own so understanding that context and being able to apply runtime authorization based on that context is very critical and for us to you know be thinking about.
I'd like now to maybe open the floor. Do we have any questions online? No? Anyone from the audience? Don't be shy no? Okay then I have plenty of questions. I think Andre you were saying in the email exchange about the new risks with this rapid adoption of AI architectures and MCP ecosystems. What are some of those risks that you think are worth taking into consideration? A couple of them but maybe first to start that point. MCP I guess somehow known to most of you. It's the most important AI protocol. It's a kind of USB C interface for AI agents.
We talked a lot about agents so far and it's such a powerful tool and it's a risky tool and by adding MCP to it you are multiplying the potential by 100 and the risk as well. So it's really a catalyst for what you can achieve and the risk that we see is that right now MCP interfaces or MCP server capabilities are growing extremely fast. Every software vendor out there is building it, already built it or there are a couple of third-party MCP implementations out there to allow these applications, these resources to be part of the agentic world and guess what?
The first thing they are thinking about is hey, how to authorize that? Of course not, right? Nobody's taking care of that and there are already so many incidents out there where really large industry-leading software companies were publishing MCP servers without having authorization in place and it's quite a complex topic to solve, right? So we had a couple of different scenarios already discussed, agents as an assistant, agents working very autonomously, so it's not easy to bring in things like human in the loop and the things are really getting critical, right?
You have one agent calling another agent, calling another agent, calling MCP interface of the very critical resources. How would you want to enforce that now there's a human in the loop? There's no UI, there's no direct communication channels, there are a lot of things to solve. The point here is the application layer won't solve that, there's no application layer. The network layer can't do that, the device layer can't do that. The identity layer has the best capabilities in place to solve that because we are doing out-of-band already in a couple of scenarios, right?
And you connect Siba to mention one of the examples. So we have the capabilities and we are as an identity community in charge of allowing the use of MCP in a secure way because that's the most massive leverage we have when it comes to AI productivity.
Hi, were you going to say something? I was just going to, I think Andre touched on something very important there, which is you really need to be thinking about having a multi-layered scope with respect to discovering agent behavior, right? We know most, the other thing that's unique about agents is they're so informally and easily created, right? Like any one of us can go on cloud, chat GPT, create an agent, give it a lot of permissions, give it access to my Slack, Google Workspace, Jira, whatnot, and all of a sudden that agent's running around. So how can you discover that agent's actions?
You need something inspecting, browsing your monitor traffic, you touched on the network layer, are there being API calls coming from my corporate network, right? You need something inspecting endpoints, are there local CLI agents tools being accessed off of an endpoint? It's a multi-layered approach to discovering all of the agent activity happening in your environment. And once you are able to identify that activity, right, apply an identity to it, then you can start to get to the point where you can apply runtime authorization to it.
And the key point that Andre is talking about, these MCP servers that are out there, they expose multiple tools, multiple API endpoints. So granting access at the MCP server level is not fine grained enough, right? You need to be going down at the tool level that the MCP servers expose. I'm afraid we're running out of time, so if you could, each of you, in less than 30 seconds, do a main takeaway, or if you were speaking to a CISO, what would be the thing that you would like to emphasize today? Maybe we can start first with Mike, and we can go. Thank you before I talk.
First off, it's different than came before, and it's not different than what came before. It's the same kind of thing. Getting visibility, establishing controls, putting in policies to govern it, whatever it is, it's kind of the same thing. I think what's fascinating about AI and agentic AI is the ideas around incentives. What makes this harder is that there are incentives from vendors producing AI agents or helping people produce AI agents, and the people using the technology themselves to not disclose their use.
That's a little bit different than doing work the way we used to do it, clicking into a database or whatever else. So I find that we're trying to secure it, and yet there are incentives to hide it, which is kind of a fascinating thing to me. Being here for the third day, the good thing is I don't feel alone with this problem I claim here about wild agents, because I really saw a good keynote presentation around this problem. So I'm confident we together can do some magic soon with this.
So AI holds a lot of potential, especially for productivity, but as in every other, I would say, regulatory or any other security matter, I would recommend that everyone is not thinking we will manage when it happens, but always go into the state it already happened. The speed is so much that we all are running behind what has already happened. So the first thing is, again, as Mike said, first is discovery, knowledge, knowing what's happening there, and don't take the snapshot of now as the given, because within seconds it has changed.
And I think this is quite like what we do or what we did in all of the tech prevention things in the past. Always consider you already hacked, and I think it's not comfortable just because it's productive. Right on. I guess the thing I would leave the audience with would be that securing AI begins with securing your users. If your users are currently exposed, your AI agents that are working on their behalf will only amplify that risk that exists. So make sure you're using phishing-resistant authentication. Make sure you have least privilege.
Make sure you have a human in the loop of your users' access. Okay, to close it, first of all, understanding importance. It's not like the invention of the internet. It's also not like the invention of the steam machine. It's more like the anthropogenic use or human use of control use of fire. That's something that will completely accelerate innovations that we have never seen before that we can experience today. So I would recommend, first of all, leveraging the tools that are already there. The identity layer is strong. There are a lot of things to improve. We all know that.
But we have tools in place that we can build on. And then it's about really collaboration. There are typically things like API management out there that help you to get things under control, like the MCP server topic, right? So build on what you already have, and then have a kind of vision in place to enable the security in your organization. There's no way to stop that train at a fast pace, right? Great.
Thank you, guys.