We must understand this, that there's a thin line between doing something really useful to the organization by creating agents versus causing really bad harm to the organization. Releasing a protocol like MCP without security, without proper security, that is just fully unacceptable, and this is an extremely unprofessional behavior of an organization. Welcome to the KuppingerCole Analysts chat, I'm your host, my name is Matthias Reinwarth, I'm analyst and advisor with KuppingerCole Analysts. My guest today is, again, Martin Kuppinger, he is Distinguished Analyst at KuppingerCole.
And we want to continue a conversation that we started earlier, that we actually started years ago. We want to talk more about agents, about a identity.
Hi, Martin, good to have you. Hi, Matthias, pleasure being here. Great to have you, and we want to continue also a conversation that I had with our new colleague, Matthew Gardiner, a few weeks ago, when we talked about SSPM and about the challenges that these technologies are facing, but I think the problem is even larger. Matthew talked about shadow AI, which is a bit of an escalation of shadow IT. We want to talk about shadow agents and the identity crisis that is connected to that.
So, when you use the term shadow agent, what makes this different from shadow IT, from shadow AI in general? You know, I think shadow agents in that sense are a specific element within the broader shadow AI.
So, if you say shadow AI, it might be the point that someone trust, quotas trust, uses some sort of LLM or other language model, not necessarily only LLMs, and whatever runs the prompt or it just says, okay, I use without account or with an account that or that AI to do something. The shadow agent then would be when someone starts building own agents, deploying these agents, and using them in this case, in the business context. It resembles me a bit of the good old or not so good old Lotus Notes times, where we have all the notes databases popping up and also a lot of shadow stuff.
At the end of the day, we also have it in Excel in a sense, where we have a ton of macro enabled Excel solutions. The problem with AI is that it's way more powerful and probably even harder to get a grip on and that it tries to gather the data.
So, I think the fundamental difference is that it's not operating on a, so to speak, a control set of information and a contained set of information, but that it's trying to get a grip on every information the agent needs to do the agents job. And I think also the issue of those things being autonomous, having their own agency, really trying to solve problems on their own. And I think the next escalation is the ability to create new agents from there.
So, spawning new types of agents that contribute to solving the actual challenge that has been initially given. I think that is really where also the identity part comes into play. Bringing your own AI, so using these shadow agents, shadow AIs, that is also coming directly with an identity problem, with a governance problem, with a security problem, right?
Obviously, and it's a much bigger problem than we had in the past, as I've said, because the containment we had in other areas is widely lacking. So, the agent goes out and, so to speak, looks for the information in a hard to control and hard to monitor way. And I think this is really what makes the fundamental difference to the past.
And so, yes, we need to understand this and to get a grip on it, which at the end of the day, from my perspective, starts with discovery. So, we need approaches that help us to learn on the fly about agents that appear in our environments and to understand where do they come from to apply proper ownership, which is also a very interesting theme, because ownership handling in that world, as well as in the entire sort of non-human identity world, is definitely a very complex theme.
So, who is really the owner of that agent? And depending on managed versus unmanaged agents, et cetera, that is something where we need to probably also develop a concept first. We are not yet there. And only then, only then we can start with governance. I think the counterpart to that is that we look at it from the resource side. And I think we need to do both in parallel. And we can't do everything perfectly now just saying, okay, we go for one AI security solution itself, everything far away from that, far away. We have some bits and pieces. We have some missing parts of the puzzle.
We have some, let's say, very handcrafted parts of the puzzle that still need to evolve. Probably not colored yet, just I guess the jigsaw created quickly.
So, we are quite a bit away. I think the resource side is equally important because that is about saying, how can we at least try to minimize the impact of unknown to rogue, but also to managed agents?
So, how do we restrict what they can do, setting some sort of borders? I think that's the other side of it, which then directly leads to the problem again of, what is this for an agent? Is it an agent at all?
So, also a question here. And then we are back to the discovery side of things.
So, I think these are the two sides from which we must tackle the challenge. Right. And I think, as you said, when we have this discovery process in place and we identify unknown agents that are acting within our systems, not within our network, because that has gone before, the question is really, what are they accessing and how do I control them? And I never imagined actually that I would think of the problem also being based on our colleagues, on everybody in every company that are now in a situation to create agents very quickly, very efficiently and very rapidly on their own.
People which we did not expect to do any coding at all five years ago. In the sense, they don't know coding. And a lot of that, I think this is also leading to another, I think, you know, it was a disaster. I think we can talk about a disaster here. It was a disaster that was very predictable. I've been talking about low-code, no-code, as sometimes I'd select next Lotus Nodes disaster. But at scale. And I talked about this for quite a while.
A couple of years ago, I started hinting on that because it's extremely, and we even have in our leadership compass, we have questions about how do you sort of control, if you support low-code, no-code, how do you set sort of a proper governance for that? Do you have capabilities for proper governance? And right now it's, so to speak, exploding because everyone easily, without coding knowledge, can do these things. And so we tend to like all the proper things.
So, you know what, my development days are long ago, but I had a look, never being a super, super expert, as I wrote a book about C++ at least, so not totally blind in development at least, but I would also say C++ probably was the last programming language I really digged into. And things before were things like basic COBOL and some other old stuff. But in that day, I think it was very clear that you document, that you do certain things properly in development and you need quite a bit of skills.
Right now you don't need the skills, but there's also a lack of whatever documentation versioning, all the other things, or you put it into a Git and it may become so you may face new and other security issues. So it means there's, I think there's a bigger problem, which right now, so to speak, explodes almost in that context of AI security, which is really just nowadays, I think it's called white coding, a really strange term to me. And I think this is where we really need to look at.
And again, we will not stop it. So we must first try to learn what is going on so that we can take proper measures. And I think the next, one of the next logical steps is clustering in the sense of putting it into boxes, which we can treat in a rather similar way. So is this a managed versus unmanaged agent? What do we know about it? Is it totally suspicious? Because we're not even know what it is and where it stems from. And then we can take appropriate actions to control what these agents can do or not. So you don't need any more of these evil attacker from the outside.
It's enough to have white coding employees that exfiltrate data already, that, you know, our biggest problem, our biggest problem always were insider attacks. And not all insider attacks were attacks, but a lot of them were or just mistakes made. And at the end of the day, a lot of what is done and most of what is done inside with agents is not meant as being negative, as being sort of problematic.
But in terms, we say there's a huge difference between or the opposite of gut gemeint is gut gemacht, which means the opposite of sort of wanting to do something positively is having good intention, is doing it well. So a lot of good intentions just go wrong. And here are a lot of things that have a good intention, just go wrong. But I think what is behind what you said is we are, that way we are massively increasing the attack surface.
I think this is the point because what comes in, what is used from external, we have all the prompt injection type of attacks and all the risk of data leaking, of ending up as an element in learning of models and all the other stuff, which just makes it a much bigger problem. But yes, we must understand this, that there's a thin line between doing something really useful to the organization by creating agents versus causing really bad harm to the organization. And that is what we need to learn. I think there's not a simple answer on that, what to do.
But clearly the network is this, we just don't allow anything. It will be bypassed. It already is bypassed. So at the end, it's our job to gain control about that. And I think it's also a bit of a job of the providers of the entire AI and the tooling behind that to act way, way, way more responsible than they did until now that they are doing now. So releasing a protocol like MCP without security, without proper security, that is just fully unacceptable. And this is an extremely unprofessional behavior of an organization.
And I think we'll leave it with that because of course we could talk about tools that support us there and there will be tools that support us there. But first of all, it's also about responsibility. It's about liability, about understanding what people are actually doing. We see things spreading and we will need to tackle that with tools, but to apply the proper level of scrutiny also starts with teaching and educating your colleagues, your security people. And I think the right place for learning, for teaching, for educating is of course EIC, final sentence by me.
We are very, very close to EIC in Berlin right now. So if you have the time, if you have not yet a ticket to join us in Berlin, join us and talk to Martin, talk to the vendors, talk to those who should be held responsible to make AI and to make agents more secure, more governed to use while leveraging the benefit and the potential that comes with that. I'm looking forward to seeing you in Berlin, Martin, and giving your speeches and talks and panels there. I hope our audience joins us there.
And any final sentence that you would like to say when it comes to AI and the usage of AI in corporate environments right now? I think there's a tremendous potential and I think we can figure out ways to deliver at the speed of business without sacrificing security. Right. So the terminator scenario can be avoided if we do it properly. Thank you very much, Martin, and thank you for your time. And we will continue this discussion. It's not yet solved, but there's more to do. Thank you. Thank you. Thank you.