Hey everyone, so nice to see you again here. I'm Gal from PlainID, co-founder, and I'm going to speak with you today about identity security and AI.
Now, probably you've heard in previous sessions that AI and identity security, there are multiple ways to look at that. First of all, what can AI contribute to identity security? And secondly, how can identity security contribute to AI, which is what I'm going to focus about. We are going to speak about how to secure your AI systems, your AI agents, and why should you even care about that?
So, let's start with that. Why should you care? Up until now, you know, most of you have been in the space for quite some time or entering the space, but the purpose, the main purpose of identity security is to support the overall security of your organizations, right? We have challenges with the applications. Identity security is there for the rescue. Security challenges with data.
Again, identity security is there for the rescue. We are suggesting, we are offering, we are enabling our organizations to be more secure, to have better systems.
So, what's the issue with AI? The thing with AI is, sorry, the challenge has got bigger. Same challenges, same thing as we have been dealing with up until now. We have to protect our data. We have to protect our services. We have to protect what we have in the organization.
But now, with AI, it's much more accessible. I am focusing in this session on AI systems, which we are developing internally, and many organizations have already started doing that, which means we are creating a technology space that provides access to more data, to more services, through AI systems, through AI agents, and that means that all challenges we've been facing up until now are there, but bigger, and we need to deal with them. We need to understand that this is not just another area someone else can take care of.
No, day one, we need to be, identity security needs to be there to support that initiative. Just as a reminder, if you look at how data security evolved, it was very much separated. Data security between identity security, they were not, they have not evolved together. In many cases, there were even different organizations within each of each company. That should not happen with AI. It shouldn't be separated. Identity security should be there from day one, because it's not a whole new space that has nothing to do with identity.
It has to do with identity, very much has to do with identity, and we'll see why. Now, in this session, I'm going to focus on authorization, because that's what we do, access control and authorization.
So, let's see what are the main challenges that AI systems present when in regards to authorization. So, first of all, it means more access to more data, right? If you consider today your current applications, there are applications, systems, they have, they provide access to data, right? And we had to protect that.
Again, in many cases, it was very much separated. IAM was considering or securing the authentication of the identities, the definition of the identities, and data security was someone else's problem. That can no longer be the case, especially with AI. AI systems today, in order for them to be efficient, they have, they provide access to data, and it means just much more data, which is now accessible. Additionally, in AI systems, there is more acting on behalf.
Now, those of you who have been here in the first session today, the focus was a lot around non-human identities, but you also need to consider the human identity, who is beyond that system. Eventually, non-human identities are there to act on behalf of a human identity.
So, whatever they are doing, there is a human identity in many cases beyond that system, and that's what we need to remember. There is much more acting on behalf of someone in AI system, and there is much more access to data with AI systems.
Actually, we can see that already the market is pointing out that the majority of cyber security attacks was going to be around access control issues. Okay, this is just one statement. I'm going to add some more statement to support that, but the majority, again, the majority of cyber security attacks is going to exploit access control issues, and that means that access controls, authorizations, are so much important when dealing with AI systems and AI agents. It can't be, again, it cannot be separated. It needs to be there day one.
To support that statement, we can also look at the OSAP-10 report that was released earlier this year. Now, this report lists all the vulnerabilities for LLMs, large language modules, applications, and generative AI, and you can already see that four out of ten of those vulnerabilities are related to access control. Access control becomes much more important when protecting, when thinking about the protection of those types of systems, and it repeats itself over and over again.
Many of the security organizations are listing today the vulnerabilities that are a result of the development of AI systems and AI agents, and access controls, authorization, is one of the top concerns many are pointing out. Another evidence to that you can see from the European Data Protection Board.
Again, also there, they are pointing out the gaps in access controls and API protection. This is an extensive report that lists all the security vulnerabilities that are a result of the development of AI agents and AI systems. I'm just sharing with you two samples. You can find many, many more, where the security vulnerabilities are pointed out in regards to AI systems, AI agents, and such, and access control is always there. Always there as one of the top priorities to consider, one of the main concerns as part of protecting those types of systems.
So, first of all, what has changed, and what should we consider in order to address this challenge? So, let's first of all look at what has changed. AI has evolved very, very fast.
Obviously, you know that in the last past years. Just want to point out some of the main changes, right? First of all, we started with AI-based assistants. They just provided recommendations. They had access to a lot of data, but they didn't really know how to act. They just provided recommendations. They told us things we wanted to know about. But then came AI agents.
Again, from an access control perspective, the focus was now not only they tell us something, they also act. So, not only access to data and sharing data, now they can also act on behalf of the user.
So, they got much, much more power. And then came MCP.
Now, I know MCP is something, you know, just three letters everyone is talking about, another technical aspect. Why is it so important? Why should we even care about something that is called MCP?
So, I want to share my point of view, and I like this analogy. I know entropy. By the way, MCP is a standard for accessing services and data by entropy, right? This is the standard. They call it the USBC for AI agents, which basically means they can connect to everything according to a standard. But why should you care? Why should you even consider the importance of that standard?
So, you know, my daughter asked me, okay, what's, can you explain to me why is it so important? So, think about yourself or those of you that went to school around the 80s, let's say, the 80s.
Okay, so, if we wanted to write a report, we had to go to the library. We had to actually get out of our houses. We had to take a bus or ask our parents to drive us to a library, and then we had a set of books we could read. We had to work very hard in order to get access to data. That's what we had to do, and then we got our assignment done.
Today, my daughter, when she needs to do an assignment, what does she have to do? She doesn't need to get out of the house. All she needs to do is access to her phone or tablet, and she has everything there, all the information she wants to access. Just think how much power that gives every student today, access to power, and that, to me, is MCP. That's what MCP, the change MCP has done to AI agents. In the past, which was not that long ago, like six months ago, AI agents had to work very hard in order to get access to data and to services. They had to develop each and every new interface.
With MCP, they don't. It's so simple. Access is there, ready to use, and that means much, much more power. That's what it means. It just means the attack surface is bigger. What you need to do as identity security professionals is to consider that and to mitigate that in advance to provide solutions, because this is happening. This is not stopping. It's happening, and already developers, engineers within your organizations are developing AI systems, and they're using MCP and all the other buzzwords around AI, but what you need to do, you need to control that.
Someone else said, not me, I just saw that, I think it's very relevant to the subject. With great power comes great responsibility. AI has a lot of power. It's good.
I mean, your organizations are developing AI systems, AI agents. They need that. You need to add the responsibility layer to that. Don't let them do just whatever they want, but provide them with the right tooling.
So, what are the tooling we want to provide? So, core principles of access control and authorization are who are the identities, what should be accessed, when access is valid, right? Those are the core principles. In the context of AI, it's not just who can do what and when, but who can ask to do what.
Remember, I'm asking something from the agent, from the system. I am asking for data, or I'm asking them to act on my behalf to do something, right? But the same principles are still there.
Always, who is the identity? Not just the non-human identity, the real human identity that is behind the system.
So, who is the human identity there? What that human identity is trying to do, what data they are trying to access, and what's the context of access, right? And if we consider those principles and apply them on an AI system, there are three questions to be asked.
One, what can a user ask? The flow of an AI system or an AI agent is, first of all, asking a question, the prompt, right?
So, can the user ask that question? We need to control that question. If I'm from engineering, should I be able to ask a financial-related question?
Well, maybe not. So, question needs to be controlled.
Second, when I'm asking a question, what feeds, what data feeds the response to my question, right? The way AI system works, there is a question, and then the AI model gathers information, documents to support the answer, to generate the answer. Should everything, all the data support my answer? Maybe if I'm an account executive operating in Europe, I shouldn't have access to all the sales information in the US? Maybe. Okay?
So, what feeds my answer? And the last one, once answer is generated, should I see everything in the answer? What if the answer contains PII? Maybe I want to mask that. And if we take that and place that on top of the AI flow, this is a very high level, very general flow of any AI system. It starts with a question. It always starts with a question. I'm asking something for information, something to be done. It goes through some kind of smart retriever, right?
The rug, right? Smart retriever that fetches the documents. That data is pushed to the LLM, large language model.
Again, this is very simplified, right? LLM, which generates the answer, and then the answer is sent back to the user. We need to control each and every step of the way. We can't leave that open.
So, controlling the question, controlling what feeds the answer, and masking the answer which is sent back to the user. By the way, all of those have solutions, right? That's why I'm here speaking with you. But those are things you should be considering. Two use cases I want to share with you.
One, a supply chain use case. This is a very common use case as many organizations today are considering how to leverage AI in a supply chain type of scenario.
Now, in this case, you can see how confidential data is very much accessible throughout this whole process. It's very common to use AI or to consider using AI in that type of scenario to optimize the overall process. Where should we provide our supply? How should we adjust whatever we are manufacturing to fit, to best fit what we need to provide? That is all based on amounts of data which in many cases are confidential. That's why day one authorization should be part of that, should be in the design of the system. This specific company has taken that into account.
They have created an infrastructure where both authentication and authorization was there from day one to support their overall processes. Another example I wanted to share with you. Some organizations have even taken AI another step forward, and I think this is really, really great. They already acknowledge that internally their engineering, their developers, the business would require development of AI agents and systems. So what they said is we are going to create an infrastructure that would support that.
We are going already to prepare a set of tooling, including security tools, authentication, authorization, so you can build your AI agents, whatever you want to support, whatever business use case you have, but you have the infrastructure with the relevant toolings to support that. This is actually a use case of one of our customers which we are working very closely to embed authorizations as part of the framework they are building internally to support the development of AI agents and AI systems. And just running out of time, so just two takeaways from this session.
First of all, remember that AI development is part of your responsibility. It's not someone else's.
Still, identity security is very, very much important for that. Second, consider that as kind of a green field, right? It starts now. So start it with security in mind.
Start, enable your organization not to move fast and later mitigate whatever risk was there. From day one, provide the relevant tooling for both authentication and authorization. Create secure AI systems from day one. Thank you.
As always, a very full, thorough, and well-thought-out presentation. Thanks so much, Gail.
Wow, so you've been warned from day one, everybody, and it is your responsibility. I hope you got that message. Just one question. Which identity governance controls are most critical for demonstrating compliance in AI-heavy workflows, particularly with emerging regulations like the EU AI Act?
Wow, okay. Big question. I'll try to answer very, very quick. I think the current governance tools in place are relevant. It's not new governance because it's the same problems we had up until now.
Bigger, right? So we need the same governance controls. Who can access our data? Where are our identities? What our identities can do? Okay. Thanks very much, Gail Halemsky.