AI has already slipped inside of enterprises. Employees are experimenting with generative tools, vendors are embedding AI features into platforms, and business units are spinning up AI agents without security sign-off. The result? A growing shadow workforce of non-human identities that few organizations even acknowledge, let alone govern.
Legacy identity programs were built for people and service accounts, not autonomous systems. Pretending AI is “just another user” is a dangerous simplification. To survive the AI gold rush, enterprises must classify AI as a distinct identity type, subject it to strict governance, and enforce controls as strong or stronger than those applied to human employees
Nitish Deshpande, Research Analyst at KuppingerCole will challenge conventional thinking around AI governance. They will highlight why legacy IAM frameworks fail when faced with autonomous decision-makers, discuss the ethical and regulatory blind spots most organizations ignore, and argue that AI identities require a radically different trust model.
Simon Gooch, Field CIO at Saviynt, will share insights from his extensive experience leading global IT and security transformations. He will discuss how Saviynt Identity Cloud enables organizations to secure all identities, human, machine, and AI, and will highlight real-world use cases where enterprises have achieved measurable outcomes by consolidating and modernizing their identity platforms.
Hello everyone. Welcome to today's webinar, Rethinking Identity Security for Enterprises in the Age of AI. My name is Nitish Deshpande and I'm joined by Simon from Saviynt. In today's webinar we will be talking a bit around what is the current state of traditional IAM when it comes to dealing with AI identities and what are the key points we should take away from when moving to securing these AI identities. But before we begin I would like to mention some of these housekeeping rules. You all are centrally muted. We are controlling this from here so you don't need to mute yourself.
As always we try to keep these webinars interactive so we will be running a couple of polls during this webinar. So I would like to encourage everyone to participate in these polls, provide your opinions and we will definitely discuss the results of these polls towards the end of the session which is the Q&A session. If you have any questions during the webinar you can enter those questions at any time using the control panel and we will address as many questions as possible towards the end of the webinar.
And we're also recording these slides so you will have the presentation and this recording available for download in the coming days. Quick agenda. This is a bit different so Simon and I will be focusing more on having a conversation around this topic rather than presenting tons of slides. So before we begin I would like to invite everyone who is attending here to participate in this first poll. So the question is like how aware is your organization of the AI identities currently operating in your environment? Is it first very aware so you're tracking them quite formally and regularly?
Is it somewhat aware you have some sort of partial visibility on your AI identities? Not really aware is the third option where you're not really sure how many identities you have. The fourth is you're not at all tracking this AI identity. So please use the control panel to provide your answers and we will discuss them towards the end of the session. And I would like to now invite Simon to the stage. Simon if you would like to maybe quickly introduce yourself. Hey Nitish, thank you very much. So Simon Gooch here.
I am the field CIO at Sabient and that means I'm responsible for all post-sales delivery but also I am part of the team that makes sure that we are understanding what's happening in the identity space, in the security space and how do we make sure that Sabient is providing an appropriate platform and solutions to really support how businesses are evolving the way that they operate. Leveraging some of the technology that's kind of pivoting around AI and agentic AI.
So I'm part of that team that helps us think about the kind of strategy and where we want to move to, to make sure that we can support honestly some of the critical business activities and functions but also some of the risk that we're starting to see evolve as we start to make this big kind of AI enabled pivot. Perfect, thanks Simon.
I think that brings us to a very interesting topic to begin with is that even with the first poll as I mentioned earlier is if you talk about this kind of this shadow workforce of AI identities, you know we are seeing these AI agents, co-pilots, automation bots that are quickly multiplying inside organizations. From your perspective Simon, so how real is this problem and what are you seeing is that what does it actually look like in the enterprise when it is?
Yeah I mean in terms of what we're saying in terms of the you know broad coverage then you know we're seeing a lot of organizations whether we know about it as security professionals or not you know really starting to look at you know how do they leverage things like you know conversational agents, how are they looking at building digital twins, looking at the whole AI agent as an assistant and there is a little bit of work going although and I'll come back to this in a minute, a little bit of work going on in some organizations to look at you know how they're starting to build truly I guess autonomous AI agents but I don't think there's an organization that I've spoken to in the last six months probably that isn't trying something within those kind of broad categories that I just mentioned but fundamentally I think what we're not seeing at the moment across a vast majority of the organizations that we talk to or that we poll is really any honestly any real structure around you know how are those agents going to be leveraged across the broad kind of technology ecosystem within an organization and then you know part of the point of this conversation is then honestly how is that stuff going to be controlled and managed and what are the key aspects of that control or management framework so I mean the simple answer is I mean a massive amount of use I think you know the last formal data I saw you know talked about 48 to 1 in terms of non-human to human identities honestly I think last time I checked that was up at 80 plus to 1 and we can expect that to say you know that's just going to go through the roof you know I think over the course of the next 12 months as we see many more organizations just start to test out what they can do with some of these new kind of constructs.
Yeah absolutely I agree with you I think as working at Cooperator Coal right now we are working on a leadership composite on specifically this topic of let's say NHIs as well and when we talk with all the vendors in this space there's quite a big industry around this one several new vendors are coming up and they keep on saying that when they are working with the customers they are seeing the same number is that 40 to 50 times more than a normal human identity and that's that's a I think this is because these are being created well I can say without oversight you can say they perform these tasks make API calls but tracking them has been quite challenging especially the AI agent part where they are kind of like a hybrid identity so they are an NHI can say to an extent but they are also making decisions not high priority ones but some kind of decisions for human identities as well so I think maybe the key phrase would be here is that these AI identities they behave like a workforce you don't hire but you're not also managing as well so it's quite quite interesting to see where this place is going and we need some sort of framework here and talking about framework I think this is I would like to take us back and discuss around why maybe a traditional IAM framework does not work in this case is that from your perspective Simon so do you have any specific points you would like to mention here around why yeah framework is not suitable and I think I'm actually gonna I'm gonna come back to one point you raised and then we can come back to it because I think it's a super interesting point about about about the you kind of mentioned the kind of HR you mentioned the word HR and before I answer your last question I do just want to I do just want to throw that one out there I think for consideration and I think it'll be part of the roadmap and some of the things we can do about the future in terms of having more I guess control but like at the moment I don't know I don't know of a single organization that I've spoken to that has got their heads around the concept of who is who is the HR for non-human identities and some people laugh at that statement you know but generally speaking I think it's a really really important point to consider because like we don't we don't think about humans in our organization without a whole range of I think kind of good practices that we know we have to deploy so when we bring someone on board we you know to an organization we onboard them right we don't just go hey you joined yesterday have at it you work out how to access all these systems you know what sort of data you should be able to work with how you do your training how we make sure we understand who you are as an as an individual in your identity where do you live how do you get paid you know you think about any aspect of a human human and the human identity it's managed right I mean it's fundamentally managed at its core at least the starting point of it is HR.
HR might not do the payment piece but they make sure that finance has your records and your data to get paid.
Organizations aren't thinking about that when it comes to non-human identities particularly you know agentic AI type identity constructs and I think that's one of the fundamental opportunities we've got is to really address that challenge and start asking ourselves and I'm not necessarily saying I'm not saying it has to be the identity or the security team but I actually think that's the right place for it to live ultimately but what are the translations of those human constructs in terms of managing the person the identity translate those into the non-human construct I think they're all so valid right like how do you train the thing how do you manage the thing how do you give it guardrails anyway I mentioned that because you mentioned HR I think we'll come back to it maybe in a little bit but if you don't have the answer to that question I actually think you don't have one of the fundamental things you need to have in place to be successful in the future but I'll park that for a second let me come back to the you know I think a good starting point which is you know how how do legacy or what do we need to add to legacy identity governance identity access management governance frameworks to be more successful as we look about moving forward and I think for me it's super simple right there's there's two things we need to consider that we didn't have so how do we build those into our into our frameworks and our choices about you know what tools we use to enable or support those frameworks and our approaches one is you have to make sure that you can get the coverage of the different types of non-human non-human identity constructs that enables that you've got at least an understanding of what all those different things are like without having that then you have no kind of foundational basis for understanding ultimately you know where is your risk coming from what actions do you need to take so for me actually it starts with having everything under some sort of centralized and I'm not going to use the word management because you need to be careful about what you're trying to do when you're managing but some sort of central visible platform that gives you an insight into everything that you've got and is going on for me becomes absolutely foundational and that's where if you think about legacy identity and access management frameworks and the tooling that supports them was like it started from a really really narrow focus thank you classically it started from kind of audit and compliance right like so we only thought about certain things that we really cared about we thought about making sure that we could manage that stuff in a fairly honestly static or non-dynamic way so you know your six monthly you know audits and making sure that you understand you know what permissions and privileges were you know associated with the access to some small number of critical systems if you're looking at it from a SOX audit and compliance perspective so you know that's how we used to think about that stuff I think it's evolved a little bit but you know one of the main changes that I see coming is we've got this massive you know we just talked about it at the start right we've got this massive explosion of identity types human non-human does it really matter I don't think so but but we don't necessarily have the right approach to or the right thought process around how do we start to view those as things that we need to manage in totality or in the entirety so for me it's super simple then I think I've just taken 10 minutes to say it but make sure that you've got insight to everything right I mean consider all identities in scope work out how do you start to that's that's number one and I think the other fundamental construct if you assume that that's something you're going to work on is how do you make sure once you've got some sort of visibility to and government structure around all your different identity types how do you understand what they're doing right so context becomes king when you talk about identity and context requires you to in effect know I think a lot more about your identity estate than or your technology estate stitched together by identity than I think historically we've thought about when we thought about kind of let's just call them legacy frameworks right again you know we only thought about connecting to certain systems or certain types of data in our ecosystem and we did that for very good reason but now if we look at you know look at that paradigm of non-human identity constructs you know and we'll talk perhaps in a minute about what they can be used for but they can basically be touching anything in your ecosystem now if they are doing that and you understand some of the risks that are not new risks but I think amplified by this volume thing right like a hundred to one a thousand to one then suddenly making sure in your kind of modern forward-facing frameworks that you actually have some sort of insight into or connectivity to all of your applications actually all of your data that for me becomes the other part of the kind of thing you need to focus on that we didn't focus on when we looked at legacy identity and access management frameworks I think it's absolutely part of the future it is being able to have that insight to what's going on across everything so you've got to have this and to connect everything right and that's and that's potentially problematic and we can talk about that and again in a minute in terms of how to do those things you know the cost the friction so for me it's super simple like absolutely you have to be accountable for all identity types and you're going to have to try and connect to all the different systems and data platforms that you've got absolutely I agree with you Simon I think you mentioned really good points around the limitations of traditional frameworks as you have they're built around kind of you can separate type of human behavior so you have you had freaks roles you had starting access patterns and but these are different these are adaptive you can say for example AI agents they're adaptive they're kind of not deterministic and time and time again they can get overprivileged they can collect lots of privilege which which is again a big challenge as well but that's then we come back to your point is what we need is a centralized platform which shows visibility across all kinds identities and I think that makes complete complete difference and but it's yeah it's not straightforward you mentioned it's from different point of view but that's one starting point as well but maybe if you go a bit deeper into that sorry because the other thing I think that's important in that is you know if we want to move from the past to the future I think the other thing that is incumbent on all of us is honestly as identity professionals and security professionals is is making sure I think that the organization truly understands the value of that identity construct we frame it in a modern way you know to deal with that dynamic nature of the you know the new technology ecosystem but I actually think at the heart of kind of one of the fundamental accountabilities that we've got you know you me and others is making sure that we have the organization understand understands the role that is critical for identity and I'm not you know people talk about identity security they talk about the identity fabric they talk about the identity um perimeter I mean and those are all I guess valid and good terms potentially but I also think they're a bit of a misdirection um potentially because I think you know we need to be able to describe to the you know the organization that we support that there is no transaction that happens in a modern particularly in a kind of modern dynamic AI enabled driven world where identity you know isn't the fundamental currency of every transaction I love the kind of thought process I'm not trying to invent a new term but you know identity is currency or the currency of any technology transaction I think helps us when I go back to my kind of things that we need to consider about the future not the past because if it's the currency of every transaction then yeah every type of transaction driven by every identity to any data in any system has to make we're at the heart of it right so I just think part for me of that kind of forward looking perspective is repositioning not not the importance of us but obviously actually I think I've just spoken about the importance of identity within you know an IT ecosystem but but also just I think if if everyone really gets the role that identity truly plays then we kind of achieve this and you know you've heard it perhaps called the kind of oil class of value where everyone wants to understand what should they do with this thing that's at the heart of everything this identity and so people will come to us right they will ask us questions they will want to know what should I do with this non-human identity with this human identity we become sought out in terms of a critical enabler and control mechanism and I think that's important and again that took me a long time to say that but for me it's about it's about how do we reposition as well absolutely I agree with you I think that that's that that addresses several things that you mentioned and I was just trying to go a bit deeper into that but thanks for bringing that up what I would like to maybe quickly touch base on is you know what kind of different types of identities you can say are in this one in this AI space and that so I think maybe it could be defined on a few parameters it's like the lifespan so they are either ephemeral or long-lived but you need to also understand the origin of origin of these identities and from what data they are being trained but do you have any particular you can say point of view on what how you would define these types of identities and will you have a different kind of approach for these different kinds of identities in between these AI enabled entities?
Yeah I think you know we've got a certain type of non-human identities that have been around for quite a long time you know if we look at you know some of the kind of you know service principles for example I mean service principle I think it's a great example of I think of it I think of it as a non-human identity but to some degree like you don't necessarily have to get too I think bent out of shape by you know necessarily exactly what's in scope what isn't scope potentially if you say that hey I need to make sure I've got some sort of coverage for all of that stuff but you know I like I like service principles as an example because I mean they're something that can be spun up in minutes potentially exist for minutes perform or support some sort of activity that fundamentally you know might give you access to process some sort of critical data you know perform some sort of output deliver some sort of you know product and then be closed down and literally within the space of five or ten minutes you may have potentially you know some really important transaction that's occurred and some critical business process where how well how well do we understand what just happened like do we care about what just happened I mean that's probably the first question I mean I would argue any time that we touch some data in our ecosystem we probably should care right like we should always be seeking to understand you know what happened did it follow a set of common principles or guidelines do we understand you know the appropriateness of the activity so the context was there any risk are we accountable for anything from a compliance perspective etc etc so I mean I think you know there's a whole range of those sorts of non-human identity constructs that already exist the one that's obviously you know we talked about a little bit and is really really growing I think in volume and I think has potentially probably a lot more risk to us just because of the way that I think organizations are thinking about leveraging some of these identity constructs and that very much is you know that kind of agentic AI construct and I think you know the whole kind of assistant thing becomes super when you're looking at you know how you know are we giving are we giving our AI assistants and say I've got 10 or 20 of them you know how are we thinking about the privilege that's assigned to them how are we thinking about are they are they leveraging my identity and my permissions to perform tasks on my behalf and we're seeing a lot of that right I mean that's a that's a kind of obvious evolution of how you leverage some of that tech because it offloads some of the workload for me it enables me to be much more effective and efficient but to some degree I'm still at the heart of that function I still have an element of control over what's happening in terms of they are performing actions on my behalf I mean they could be deterministic or non-deterministic but I'm still at the center of that and I think that kind of human at the center or human guided activity is where we're starting to see quite a lot of development because I think it's easy to yeah so I think you know our job as security experts and identity experts is to ask the hard questions about do they do those do those constructs in that example do they inherit my permissions is that an appropriate model are they given their own permissions that are mirrored by my permissions understanding the context of the task so do we need to build task frameworks to enable us to have context so I think you know that type of agent development is fairly easy to understand and I think fairly easy to build the sorts of controls we want to have and you know some of the ability to manage some of those activities I think more effectively what what I think becomes super interesting and I'm not seeing much of this at the moment but definitely seeing it is when you see some of the more kind of autonomous agent constructs and interestingly you know where you might see agent to agent interaction yes like how do we make sure that we understand what's the implication of that because if you had an agent that maybe if you were a maybe you're an insurance organization and your agent is responding to insurance claims and you know his job is basically you know it might be fairly deterministic so it takes a set of inputs it analyzes them against a set of rules and it says hey yes I can process this claim I'm all good what we're starting to see is actual agent to agent communication where you might be a customer of I don't know you know some sort of services provider you might be I don't know you know it might be vehicles and you're you know you could be Hertz and you could be leasing a vehicle you know for your rentals from Ford and actually you're because hey you've had some sort of damage to the vehicle to put forward your claim which is now being interfaced by an agent on the other side then we start to have and we're starting to see those things evolve they're not massive at the moment we're starting to see organizations build those sorts of more autonomous agent agent capable to agent interactions and the complexity of that in terms of well you know where's the human in that loop is there a human in that loop how do we make sure that you know as as we've got those types of interactions and maybe you know you're getting requests for data that's flowing between two agents like where are the rule sets for that where are the interaction rules that's what I'm starting to see that's becoming interesting I think as we look at some of the different types of identities that are starting to be evolved.
Absolutely I agree with you I think you mentioned about the really important point about human in the loop you need some at least for right now maybe in the future I'm not sure but right now with this highly developing space you need some sort of human accountability in there is to some oversight and that again brings me back to your first point which you mentioned about having a sort of a platform where you get full visibility and everything and that would be the direction to go to from from let's say from a savings point of view how are you seeing this you mentioned a really nice example around this let's say car rental but from your point of view in your experience with the customers where do you think is the current challenge right now?
In terms of? From just the governance and the management of these AI identities and let's say for example some type of a real world use case you can share with us today.
Yeah and I think again I'm going to keep it super simple right and I think and I think the we have to keep it simple when everything is exploding and changing incredibly rapidly and for me it starts it starts with visibility so you know you'll you'll hear quite a lot in well in the identity space and a little bit in the data space you know data security posture management or identity security posture management so ISPM and for me ISPM isn't well I mean it is a tool but it's not just a tool it's actually a really really useful principle to apply to I actually think to everything you do but I think it lends itself particularly well as we start to think about solving this non-human identity control challenge because it it starts with insight like you have to start to understand if you apply an ISPM mindset like step one is always understanding what have I got so you need to be able to you know for us it's one of the reasons why we doubled down in the last six months on making sure that you know our ISPM for non-human identities was going to be critical for us because you know we understand that organizations need to get a handle on what have they got you start with the inside right you need to be able to plug in you know some of your some of your systems of record or some of the platforms where you build and manage some of these constructs you need to be able to plug those in to that central processing platform where you can start to bring all of your identity constructs together so so for me you know I always just think about I think about it in terms of ISPM and I think about it in terms of initially making sure that I do and I I'm going to use the word inventory but it's not a classic inventory because I think I just mentioned with service principles right those things can only exist them potentially can exist for minutes and I don't think that's necessarily true of you know agent-based identities but we need to have insight we need to know what have we got and it's not a you know and I know you and I have chatted about this before but it's not a one-and-done right like IS the the initial discovery piece of ISPM isn't a I've done it and I'm good it's a principle that you start and apply and it has to be continuous right and so I actually think if you do nothing else like working out what do I need to connect to to be able to start to get visibility to all of the different identity constructs that existing in my organization and have that processing you know we can talk about whether it's every hour every day every week but starting that process you know is critical to success if you don't do that and you think of it that way you will not be successful so so actually like if the good news is that's pretty straightforward like that's all you have to do and I think the other good news is that's not just true as a principle and an approach for non-human identities it's what we should be doing now moving forward but all identities is we need to make sure that we have visibility so for me it's you know that's it that's step one like got visibility you can move on to the next step which is starting to understand the context so you need to you need to then be able to start to and this is where you know I know you know we're working heavily with this in terms of our platform you need to start to be able to well what are those identity types being used for now some of that context you know classically will come from you know how you have defined the types of systems you're using and you know what sort of roles you've got and how those things interact and you know that is been fairly static and it's not you know it's not relevant and valid in the future world and I think it still becomes you know broadly speaking a good set of data when you're talking about the more static human identity types but it's not dynamic enough I don't think it works fast enough for you and gives you enough insight in a non-human world so you need to start actually this is the good news right because this we're just talking about managing AI but you need to use some of the different AI capabilities to help you get that context now the good news is you can do that right I mean you can understand the use patterns you can start to understand you know what's happening in a range of systems and really you know use a range of different AI capabilities to give you that context or that insight which enables you I think to have a much better picture of now what have I got and what is it being used for and the context for that use so again it's pretty straightforward and that then leads you to the third stage which you know I'm sure everyone understands when you think about an ISPM principle or process but then you need to bring those things together and you can actually start to think about well and normally classically the conversation pivots to risk and I'm not saying risk isn't important when you're talking about you know what have you got and what's it doing but I actually think we need to hold our thinking a little bit so we absolutely need to think about but risk for me talks to you know honestly a control mentality rather than an enablement mentality and I think one of the big opportunities for us is when we think about that third stage in our kind of ISPM applied set of principles is to start to think about yes like what does that mean what are the risks so are we seeing activities or behaviors that we just fundamentally wouldn't want to allow because I am it breaks a whole load of legal and regulatory stuff that we already understand or why would why would that um why would that you know AI agent be trying to access this HR data source because all it's doing is performing you know some sort of financial system um financial data processing so you can start to attribute risk in terms of the behaviors you're which I think is important but we can also start to I think understand like the business functions as well it actually gives us a really interesting insight into what's happening well you know where is data moving from one place to another what are the identity types or constructs that are supporting those activities does that make sense we can actually have a conversation with the about what we're seeing and check that that's kind of supporting the process that they were thinking about so for me it helps us qualify and quantify what do we want to have happen that's the risk bit are we seeing stuff that fundamentally you know breaches any of our like I said legal regulatory risk-based controls but I actually think we can start to see and talk to the business about an understanding of some ways the business is working I don't think we had insight into before yeah I absolutely agree with you I think I agree with the points you mentioned is first we need to have a good sort of process from finding how many these kind of ideas you have in your system start with the discovery and the inventory and the classification of these kind of identities and then defining who owns which kind of identities and then that way once you have this established you have a good visibility into these identities and then we move towards something like setting policy guardrails before doing the scaling part so you know you can adopt more AI tools definitely but first you have to define what AI is allowed to do in your environment and I think the thing that struck me in the last definitely the last three months has been I mean we're talking about an area where everyone is needing to invest to keep up like investment talks to money budgets you know security budgets are capped like you know no one's getting any more money and it's obvious but no one is getting any more money to deal with what is an increasing level of things that we have to manage right so part of our challenge is and this is why I do think you know applying that ISPM principle and then leveraging some of the tooling that supports that is is critical for success because it helps you prioritize in that third stage you're you're basically doing a prioritization right like yeah and if you can talk to the business about a prioritized set of things that you can do that supports risk reduction or you know enabling certain things to happen in a in a in a way that's leveraged leveraging some of this new technology then I think you have a much better chance of getting the funding that you need to support you know your organization and its growth and it's securing its growth because you've been able to tell them that you know what's there and and to some degree based on risk and value you can you can explain to them how they might think about prioritizing what they might ask you to do right so so for me actually the prioritization piece becomes really really useful right absolutely makes sense yeah and I think what I would like to maybe quickly check in with our audience is that I would like to present them with one more poll so it was an interesting one what I would like to understand is what is the let me share my screen again yes so I mean we around some of the key takeaways what we believe it would be the next steps but what also I would like to understand from the audience point of view is that when do they expect AI identity governance to become a top priority in the organization so your options are first is if it's already deployed is it second is it in the next 12 months third is it in one to two years or is it more than two years Simon from your point of view where do you think we are in this current AI identity governance are we still there yet or is there still some time to go I mean I'll be interested to see the results of the poll and it's kind of going it's going the way I would anticipate I can't see that AI governance isn't a priority for a large number of organizations in the next 12 months and for me that means we've got work to do because the first poll told us that we're not where we want to be right we don't have the visibility we don't understand in effect you know the context and therefore the risk of what's happening in our organization and we have to go solve that problem now solving that problem is broadly speaking going to be for me you know a it's going to always start with well I was going to say it's always going to start with securing the budgets that enable you to go deploy some of the technical capabilities that will enable you to get some of that insight that enables you to move forward but actually I'll come back to my previous point it's enabling you I think ultimately you know the thing that we need to focus on in the really really short term is does our organization understand the importance of the identity at the heart of all of this change such that when you start to present them with you know some of the some of the ask to be able to move forward and you know have a strategy that gives you the governance you want for the next 12 months like you have to be able to tie that stuff together so actually like you know for me the critical the critical thing in the next three months is honestly like actually having a strategy like the strategy isn't isn't have you know achieving all of the outcomes it's just saying hey this is how we want this thing to work these are the key moving parts this is what we're going to do to start to peel back you know peel back the onion to see what have we got and make make I think rapid and significant steps forward but continue to move forward because every one of our organizations is changing and they're changing pretty rapidly um and if you know we think it's going to become a top priority which is what we're saying in the survey right I mean in the next 12 months or at least the next one to two years we have to break that down into those simple steps so we have to be able to start to say that we understand how to get insight into what's going on how to prioritize it how to then think about what we do next and it sounds pretty simple but I think we have to actually do those things perfect thank you so much Simon I think that is a really good note on the next steps for this uh governance and a perfect time for us to go towards our Q&A session as well and maybe we can start first with understanding the result of the first poll so um we asked the question how aware is your organization of the AI identities currently operating in your environment and 50 percent have said they are somewhat aware so there's some sort of partial visibility in there um 33 percent have said like they're not really aware so there could be more than they know 11 percent are saying they're not aware at all about their AI identities while six percent are saying they're very aware so that's Simon this is is a positive we can say uh takeaway from this poll I can say is that 50 percent are aware there's some sort of partial visibility uh but what is your take on this result of this first poll it speaks to the fact that I mean we've got a job to because we need to move from being aware to starting to take action for me it's that simple right like we have to do something like even if we only do one or two things we'll start to make one or two small steps like I think and I've seen this over the last 12 months a lot of organizations are waking up to the reality of it like that conversation like time for conversation is done and I know I'm talking about the topic a lot but we need to actually start to propose and do something yeah absolutely and that's and that takes us to the second question is when should we be doing this and we ask the second poll question and the results are in as well so there is a time so 38 percent have said within the next 12 months which is something which you agree with and I agree with you as well 38 percent another has said in next one to two years after after 12 months while there's zero percent for already deployed so right now we are not seeing any AI IT governance currently deployed I think that that's that's the right that's a big up for everyone is to go towards now securing these ideas which are growing at a really strong pace so Simon do you have anything to add yeah and I think um Nitesh that the key thing is we have to remember that anything we want to do and I you know we I you know I talk about trying to move at pace but it will still you know realistically it's going to take time so you know I think again building the awareness starting to talk about how we get the insight qualify you know the risk and then start to look at the programs or the activities you know even if we're only thinking that's going to be a reality in 12 to 24 months all of that work needs to start now right I mean like again we're not just waiting and I don't think anyone's talking about necessarily doing this but you know we need to do all of the priority work we need to think about you know what will our approach be um how are we going to work through that and you know what do the time scales look like to really execute a program where it gives us some sort of better ultimately control over the next 12 to 24 months again that has to start now perfect yeah exactly that has to start now and I agree with Simon's point as well that takes us to now the Q&A session as well so we have some questions in already um I will take the first one is what's the most common privileged access issue you're seeing with AI agents so are these specific controls which they should implement to prevent AI overreach Simon do you have anything to answer to this one yeah I mean I think the most common issue that we're seeing is just a lack of actually well there's a whole load of risk around um just kind of classic kind of privileged attribution so or or honestly you know any sort of kind of privilege accumulation against the silently yeah yeah like we you know we just see I mean fundamentally unmanaged identities right and therefore you know I think one of the you know that kind of I don't think we're really seeing um kind of credential theft at the moment I just think we're broadly saying you know for non-human identities um we're just seeing misuse of credentials we're seeing a classic thing we saw 10 20 years ago you know using shared credentials for a whole range of different agents without understanding the implication too deeply of what happens you know in terms of if those credentials honestly if those credentials change all those agents fail to function that's pretty bad depending on the of a problem state where we just you know stuff that we tidied up five six seven eight years ago for human credentials we're now starting to see just repeated a lot of those mistakes for non-humans partly because the systems to ensure the guidance and the control and the visibility don't exist as per our conversations probably you know for the last 20 minutes so I actually think that's probably the biggest problem like just a fundamental lack of understanding about some basic kind of credential hygiene in a lot of cases yeah completely agree with you I think what we are seeing is that these agents AI agents um that have admin rights that they don't need sometimes they are they also have non-expiring tokens they have access to sensitive API so what we need is more uh understanding of the visibility and also maybe some best practices could be like if you go into much details we can talk about time on access well I mean I think it and I think it reinforces some some really and we talk about this a lot right but I actually don't think it leads you to reinforce some basic principles of control and good practice because I think it forces you to think about how do I do stuff like just in time or least privilege because you know because that actually helps you solve a bit of those problems right um so it reinforces some of the you know credential appropriate credential um usage patterns but apply some stuff that we've talked about for a while and we've talked about just in time I mean because for me I mean just in time really should apply to all identities right and all credentials like what why not like it shouldn't just be you know a classic privilege thing if we apply it to everything then we start to reinforce some of those things that we're seeing or removes the impact of some of those things that we're seeing as bad behavior I think actually yeah absolutely I agree with you I think that would be ideal to have let's say zero standing privileges but that's I think we're a bit far away from that but that's a different topic as well yes we have a few more questions as well I think the next one is let's say what we talked a lot about visibility and so we have questions around that is what's the best way to gain visibility into AI identities which we didn't create or don't manage directly so I think that's an interesting question so the AI is which you have not created or you have not managed so well I mean I think to start with most I mean I think actually most AI identities exist at the moment weren't created or managed by the identity of security team so I actually think that's the I mean that's absolutely the starting position so for us for us one of the first questions in an organization is forget our role in it asking the organization and quite often this is perhaps the broader well actually it's interestingly the broader IT and also the broader business because we're enabling the business to perform a lot of the kind of creation of these identities themselves I mean you know one of the great benefits of kind of citizen development and platforms that enable you to do that stuff is that flexibility so a like we need to know what what are the systems in use but we have to understand that and then that's not again that's not a security question it's a broad IT question.
You're doing inventory your machines and your yeah like that that's a bigger thing that I think IT is struggling with like what is our inventory of technology and again you know it can't be the kind of no disrespect the kind of static CMDB approach of the past you know we need to think about making that more dynamic but you know but a lot of these things you know are are built and developed in platforms that intrinsically are connected we just need to make sure that we understand what those platforms are there needs to be honestly again you know it's not a stifling I think of the innovation or growth or development but you know we need to bring in and leverage you know some of the principles we've applied for things like you know our CICD pipeline control frameworks like we need to start having those sorts of conversations with the organization about bringing some of that control and the benefits of doing it so understanding what we've got and then once we've got that sort of strategy in place and you could call it your kind of overall AI enablement framework but you're basically saying hey look like you know as with everything technology enabled in the organization prior to 12 months ago we had guidance it wasn't necessarily to get in the way it was to give us enough and understand enough of an understanding of who's using what for where or at least what's the guidance that we can we can then plug into those systems they can become at least our initial data sources and you know reasonably authoritative sources of information but that's compensating that's not a security conversation that's a tech enablement IT conversation so we need to start there honestly like that's the conversation we need to be part of it and then we need to plug into those systems and if you're leveraging you know this conversation a modern you know a modern identity platform like that's when your jumping on point comes in terms of leveraging your kind of ISPM capability to start to ingest the data from those different sources.
Perfect thanks yeah I agree with you we have a few more minutes and a couple of more questions as well so maybe I'll take the next one is how should we think about risk scoring for AI identities versus human identities or should AI have a different risk model and I think this goes back to I guess having a more idea about first of all what AI is you have and what they're accessing what kind of privileges they have and then maybe yeah my thoughts on it are a little bit I think you shouldn't I don't think you should be overly fixated about the identity construct type so is it human or non-human I think that I think what you need to think about is what are you doing right again context becomes king like what are you trying to access what date like data is data is at the heart of everything right I mean applications are just pathways to get to data data is the thing that puts your organization at risk if it's used by the wrong people or used in the wrong way whether that's malicious or you know unintentional so actually I answer that question by saying well make sure that you understand your data what have you got what are you trying to do your identity construct what is it trying to do that's how you answer that question I don't think whether it's humans or non-humans is that important I think those are the things that give you the signal that you can leverage in your identity platforms that help you do risk scoring but yeah it's complex.
Also maybe having some sort of let's say understanding the impact of the decision that it is doing so maybe that and also data sensitive you mentioned as well so these these points will definitely.
Yeah and I think the only thing to think about when you think about risk scoring particularly I mean a obviously your risk scoring capabilities I mean in a in a non-human construct then you're not going to have the same rate of kind of assessing the risk looking at someone's request to do something or someone's kind of action because we just talked about it right a load of this stuff is much more dynamic like we create something to go off and do something we're not going to be looking at that and kind of approving it on mass on bulk that would let me that's going to break one of the principles for which we would have built some of these AI agents right and using some of these AI identities so what we need to be able to do when we think about risk scoring is start to build some risk control frameworks that you can define volume because hey like one off it might not be particularly risky but if you start to see a volume of it because someone's miss you know miss design some AI agent and you've now got 10 000 of them about to perform a certain activity that could cause you a real issue like you have to start to think about some controls that you can apply based on some of the more dynamic nature of the activity in terms of non-human identities so I think that actually becomes important as part of not your risk scoring but your kind of overall risk control framework and that's one of the big changes I think when you move from human to non-human yeah perfect I think that very well ties in with one more question that we have is that should AI systems ever be allowed to request or escalate their own access and if so how do we control this and again that's kind of what exactly what you mentioned is we need to have sort of some sort of frameworks and sort of approach to maybe classify AI identities some identities should only be able to read data should take some predefined actions and so the danger comes I guess is from not having this kind of guardrails you can say policy guardrails yeah and I think we are going you know I mean it's a big thing kind of in the network world where we've got network segmentation and I think we think about data segmentation a little bit already because you know we have some fairly static models for data classification I mean they're okay but the problem is and then a they don't really change well they were never designed to be leveraged based on context so you what is trying to access for what purpose like those things can change now and they can change very quickly with some of these you know agent based constructs so I think actually I mean to answer the question yes I think they can be allowed to request and escalate their own access but it's within I think it's within and you said it right but it's within a framework that gives you I think the right level of control and segregation because there'll be some things that there's that rule that never applies to right so it's not a universal yes it's a context space yeah so hey we've got a data set or a set of applications over here where we can apply some rules and yeah maybe we can allow that to happen because we've qualified the risk right we know what happens if maybe some of the controls aren't as effective or you know there's always there's no such thing as an absolute kind of outcome that you can determine but we understand we understand the risk then you're going to have some data that maybe that's riskier maybe actually the answer is yes but there's always going to be a fire break in this thing just to check or we will constantly check what's happening so we're gonna you know we're gonna have a lot more processing of the validity of that sort of you know escalation or ownership control because we've been able to systems in this data and we can define it and we can we can actually give guidance and manage the access and then you're going to have you know some data segregation and some systems into data the answer is flat out no it's too risky to allow that thing to happen we'll have a completely different set of guardrails they'll be leveraging the same platforms but the principles we apply will be different and that sounds incredibly complicated I think one of the other things that I know we're working on in our platform but I think it's a real benefit you know for everyone is actually starting to leverage AI to really think about the policy because what I was just talking about was policy right like segregation and definition with a policy that you can describe that deals with all of that different context and those different intents that's incredibly complicated like we've never really been able to do that successfully in the past like I really like policy definitions but AI is changing that like that is changing how I think we can effectively enable all of these different things yeah even ideally for you can say for human identities we would like to have a more policy-based access control but um if we are not there yet I think we are quite far away well I and I would say we're not as far away as you might think you know again I know we for one you know watch this space in the six to twelve months it's part of how we're looking to leverage AI to change the dynamic of policy to make it I think much more consumable and effective and I think you will see that coming in the next three to six to nine months definitely hopefully that would be ideal scenario as well yeah definitely um I think we have a last couple of minutes left so Simon maybe do you have some closing statements regarding so that it has been a pleasure to have you today with us yeah I mean for me again honestly I come back to like some really simple things and everything we talked about is great and there's so much that we need to focus on but like you just need to make sure that you've got all of your identity types with all of the different implications of what you're trying to do with them under some common governance I think that's key like you need you need to be leveraging platforms that give you that common governance you also need I think to be making you know making a decision about how much do I need to get connected to and I actually think the answer is everything like I think if you're not connected to stuff you know the risks that you've got now with that proliferation of non-human identity constructs have grown exponentially so actually just going hey I'm only going to connect 20 percent of my systems I think it's a big risk now actually so getting more of that coverage and then honestly think about the future like I like you have to make sure and it's easy for me to say but like you know you need to work with tech providers and platforms that can grow and develop at the pace at which you're encountering these changes like no one realistically thought about truly what they were going to have to do in the space to the level of detail we're now concerned with 12 months ago that change is just going to keep coming so you need to make sure that you're working with tech partners that can keep up with that level of change.
I think I would like to say thank you Simon for your time and for everyone who joined us today for this webinar we look forward to seeing advancement in this area and so stay tuned at Computer Goal we will soon release the latest leadership compose on NHI in the next week so it's a very interesting report salient is in there as well but there are several other vendors in that space so you can find our website on our website at computing.com so thank you Simon and thank you everyone so see you next time. Thank you.
See All Locations
See All Locations