Okay, welcome to our pre-conference workshop, The Tectonic Shifts AI Brings to Identity and Security. We are still in front of EIC, though this is pre-conference.
First, I want to introduce my three collaborators. So that's Darran Rolls, that is Jonathan Care, and the one and only Martin Kuppinger. So we will do this workshop today. And before we start, just one minute of what this workshop actually is. So the gory details behind that. 10 days ago or so, Martin came to me and said, let's do a workshop at EIC around this topic and make it a workshop. So the idea is to present you 15 tectonic shifts, 15 theses, tenets, whatever, to discuss about what actually happens with identity as we are used to through the change that AI brings.
And that is what we want to do. So we want to learn from you. And we want to spark a discussion. We don't have anything prepared that is final and a lesson to teach because we are not yet there. So this is work in progress, and it will be more work in progress in the next 90 minutes. And that's great. We invite you to ask questions. And for that, I would kindly ask the tech team behind to show the QR code that you can scan right now, where you can ask questions, because it might be difficult to run around with a microphone in a room that crowded.
But if you have any questions, if technology allows, it will show up here, and I will gather these questions. For those in the front rows, just give me a sign and I'll come with a microphone. So I give you a few more seconds. If you have a chance. Just somebody nods. Does it work? Perfect. Thank you. And I do just one photo for social media that I can post later to prove the packed room, standing room, which is great. And there are still a few seats over there. So if you want to use the time before we fully start, just pass through and find a seat. Some are left here.
Also there at the edge, there's one. One here. So one here, a few there. So find your place. And you can even come sit on the floor at the front. If your knees will allow. The groupies. My knees won't allow.
Yeah, exactly. I think we even have five chairs here for four people. This is the tomb of the unknown analyst.
Okay, let's get started. Let's get started. So if you switch back to the presentation, yes, here we are. So the overview is what we have right now. And we have quite a great group of participants here, not only from the volume, but also from the qualification. This is EIC, so only experts, of course. This is a set of questions that we want to discuss. So if you look at that and think, yes, okay, we're done. So we clustered the tectonic shifts we want to discuss briefly into five, say, chapters. This is far from complete. This is far from comprehensive. This is what we came up with in 10 days.
And more, there's a slide with additional ones, so the latecomers, which did not make it onto that slide. So this is what we want to discuss with you. First of all, the operating envelope that changes everything. And these are the three dimensions that we agreed upon that actually are the foundation why AI is different. And we are happy if you contradict, we're happy if you question what we're saying. That's why it's a workshop. So we're talking about, I don't read everything out, otherwise we don't need it.
We were talking about machine speed, machine scale, and the behavioral perspective when you talk about non-deterministic variability. These are the foundational characteristics of why agentic AI, why the new type of actors within our systems are changing everything, maybe, that we are used to. So no existing IAM control model was designed for all of this simultaneously. So this is the common root of the 15 shifts that follow. We have no great plan to present that. The idea is that we do a round robin between the three or four of us to walk you quickly through and spawn discussion.
And if you have any feedback questions to catch up with, please let us know. And that's my intro. If you have any questions, send them to me. We won't be able to answer all of them, but anything that contributes to the discussion will be taken into account and also taken into account later.
And that, I'm honest, this will enrich our research. Yes, very bluntly. Any questions, any feedback or input you give is warmly appreciated because it will inform our research going forward.
Yeah, right. And then perhaps one question you stated earlier. Does anybody here think that we've already got it solved for agentic? Anybody got a hand up to say, oh yeah, I already did that. My infrastructure is ready to go. Anybody? Okay. It's you.
Oh, there's one. A non. Right. Okay.
So yeah, I think I'm next if I got it right. And as Matthias said, this is a continuously evolving thing. So of my conversations, business conversations, literally every conversation these days includes AI identity, AI security. It's not only about it, but it pops up everywhere. And I learn permanently. We all learn permanently. So this is really what Matthias said. We have a list of things to add at the end. And this brought up this idea, as Matthias said earlier, about these tectonic shifts.
Because what I believe is we, and we all believe and agree on, that's why we do the workshop together, is that we need to also step back and apply quite some shift-left thinking on the way we do and address things. So a lot of the technologies we have may be really helpful as a start, because we have it and we need to act now. But we also need to think beyond that. What is the full solution?
And maybe before I go into the first part of it, the topology break, so one of the things that I feel really fundamentally changes is, so we are used, when we look at access, to say, okay, Martin has access to SAP. Right now, it might be that Martin does something which triggers a mesh of agents, which end up at some resource servers. But we don't know where. So it's not non-directed, it's non-deterministic also in that sense. And unfortunately, the resource server doesn't know which agent will knock on the door the next minute and ask for what and why.
So it's a very fundamentally different scenario we are acting in. And so that means we need to think about what really changes. And this is basically really the first point. We are shifting from the next stage, the individual actor, where we know, okay, this person has access to that system, towards something which is way more autonomous, where various entities interact, where, whatever, if you ask Claude something, then Claude may say, okay, I'll send out a couple of SAP agents. So you don't even know which agents will work for that.
If you look at the agentics side, there are other things which are a bit more deterministic. There are, very clearly, there are very fussy areas. There are more structured areas. So if you build a certain agent for a certain task in your organization, a managed agent, it's a bit more deterministic, a bit more directed. But my perspective is pretty simple. If you can solve the bigger, the more chaotic challenge, then you also have solved the more managed challenge. But if we only solve the managed challenge, we haven't solved the rest of it. So we need to think about it.
We can't step back and just say, hey, these are, we only have managed agents. Who believes that he, she knows every agent in the organization?
Oh, not that many hands raised. Who is taking inventory of the agents running in your organization?
Oh, well, this is probably almost 2% of the audience. Okay, yeah, but it's just a point. We need to start, we need to think about where can we start and discovery and inventories are a very logical starting point because we can't control, we can't secure, we can't govern what we don't know. But the fundamental thing is it's really a paradigm shift. And so we need to think about what can be tactical measures we can take. And this is definitely not a complete list at all. And it won't, here, finally, with a little bit more of brute force, it shows up. Am I already above my time? No. That's good.
So we are late anyways. Discovery, registry, very clearly. Ownership management, very interesting. By the way, leads us to one of the other interesting challenges because we may have an entity of an agent and we have instances. So how do we handle ownership? We can't handle ownership well for ephemeral instances, but obviously we can handle it better for longer living entities. But we need to learn a lot. And by the way, the same for workload identities where we also haven't solved the ownership management really well yet. So we need to get better on that.
And unfortunately, we never were good on ownership management. So whom of you has a good ownership management for the non-functional technical accounts and the privileged access management where you move a process in IGA leads to ownership changes for the PAM accounts? Probably also not every one of you in the room.
Yeah, we need to manage, maybe block, better think about control. So I'm not a big believer in the kill the agent thing. I think we need to think about containment, about isolation, about things like that when we don't know the agent or when something happens. But killing is always the last resort, not the first action. So we need to be nuanced enough. Strategically, we need to really rethink our architectures. We need standards for agent registries going away from discovery to automated registry. And we need to redesign our access models around multi-agent relationships.
And that is really the interesting thing because it inevitably leads to dynamic authorization. But dynamic authorization, which probably is way more complex than we know it nowadays. So that's the first one. Do you already have things here?
Tons, but I want to put them in the right area because if I quickly step back to this, we have these five chapters and I missed to explain them. So first of all, we want to look at how topology changes. And of course, all is interwoven. There's a gray area that we talk about authorization, governance and lifecycle, attack surface, and what we already have when you look at standards, evolving standards, et cetera. And it's good to have Patrick here who also drives this development and others here in the room who are actually driving that.
So if you look at that, at that set of topics, then we have great questions already coming in and really awesome ones. So how we can fit them into the discussion and I will try to squeeze them in where they fit in. So here we go. I move on to the next one and then I hand over to those guys just to show that it's really also a group effort. I think I don't want to stare at the wall.
First, the second change is actually that access driven is by agent intent. So somebody tells a purpose to an agent and the agent has intent and it's not really a human instruction to this and that and this and that. But I can give you an example.
So I, in part of my job, I play around with agents and I got an email from RC. So I said, why are you trying to log into strange places in our enter ID? It wasn't me. I was like, oh, and it was an agent. And the reason being, I said, I'd really like to be able to look at my calendars, both my personal one and my Cuffinger Cole one and show my wife what I'm doing that week. And the agent said, oh, OK, let me go and log into Cuffinger Cole and start going through the calendar outlook, which led to a inquiry from RC. That's a good control.
And the interesting thing, of course, is I said, no, stop that. I can't allow a third party piece of software to access the enter ID framework. And so it's fair enough. I'll use web access instead. So one of the things is that intent for an agent means restrictions can be interpreted as obstacles to be overcome, whereas I'm afraid of being fired if I disobey the CISO. My agent is not.
Yeah, right. And the question is, as you've seen, we have this section and that will be the same pattern across all slides so that we can think of tactical measures in brackets. This is something you might want to take home and try back at your environments if it makes sense for you. Suggest others to work with that. And the second part is, of course, strategic parts of how to continue properly once we find the time to do it properly. So I don't read them all out, but really just log all agent API calls with task context metadata. I know Patrick has a different opinion on that.
So logging might not be a solution to everything, but there's at least something where you can say, OK, I have some evidence, some proof what happened at runtime. Per-agent identity rate limiting by default might help. I think very clearly, logging is not the final answer, but it's part of what we need to do. And we need to do it tamper-proof. So that's a very important thing, which means we need better standards on that. Back to you, Matthias.
No, back to... Right. The biggest mistake is the agent should never touch the credential because most APIs like your email require your actual user OAuth token. You can't do OBO tokens or anything else like that. And that's the major violation because it's like, I'm giving you all my power. You're non-deterministic. You're going to figure out what I mean and what I'm trying to do. And you're going to figure out your own way to do it. And you have my entire token, which could mean deleting, emailing, everything.
So I think the agent needs to have authorization to perform the fine-grained actions that that token would allow them to do and only those fine-grained actions. And the token should live and evolve in a protected space where the agent has to talk to the executor, which accesses the token and returns data. So agents get data, they get the results they're looking for, but they don't make the calls themselves and have access to the tokens. I think if you don't do that, you're never going to be secure.
No, I think you're right. And I think the lesson learned for me there was an agent cannot operate pretending to be the supervising human. And it's a serious patent flaw.
Yeah, but unfortunately, there are a number of shoulds in that statement. Should is a reflection of current state, right? We would like it to be in control, but this is what's happening.
I mean, how many, anybody here hacked around with Claude? You know, put Claude Bot on something and off you go, right?
I mean, that is the current state. So we should have these controls, but do we? And the main thing is an agent is only dangerous if it has your credentials or if it has access to tools. So if you're protecting and authorizing the tools and the credentials, then an agent inherently is non-risky as the chatbot. Sure.
Okay, I think we could discuss this. But I just want to hint on two terms we have on that slide. The one is intent. I think we, as an industry, are a bit at risk to overly stress the idea of intent. The problem with intent is if you look at intent, this is something which is not explicit. So the intent is something which is hard to grasp. So once we express it, it's, yes, we may say this is the expressed intent, but I think we need to be very careful this time and I'll let you hear.
I had a conversation with the people at MITRE and this very thing came up and the one thing you cannot measure is intent. So intent happens here and in the case of an agent, in its configuration or its memory. So intent is not measurable. It should work.
Okay, I have a different opinion and literature and also some vendors see it similarly. So what I would say is the intent and you have to put it there is what you do at runtime. And measuring something at runtime, there are three approaches currently used from various vendors. Signal-driven is one thing. And the other one is purpose understanding or prompt understanding. And another one is then looking into what it does really do and what are the actions.
Like, for example, which token I used and something like that and derive some consequences out of that. So there are approaches, but this is usually only at runtime. What's totally missing is the definition of what I and a colleague, we call purpose, at the initiation of an agent. And what's totally missing is, and this is really a gap, looking into is the current intent, does this fall into the purpose or the effective purpose where the agent was set up? I would call it guardrails. And I think what...
No, no, no, no. This is not only guardrails. We suggest that purpose is an attribute of the digital identity of an agent and it can be governed similar to a role.
Okay, so we have some interesting things here. And we have purpose, which we define as a supervising human. We have a way of measuring intent, which is quite Calvinistic really, isn't it? You'll be judged by your actions. Right. Lots of nervous laughs in the audience of that film, interesting. Note that for later. But of course, as you say, the intent I maintain is still not measurable because the intent is what happens just before the action, the motivating force.
And if we don't bring in humans and then a lot of things may change at runtime, it's the same when you go to a shop and then you have a good salesperson, you may deviate from your intent and it may make sense. So I think there's purpose, there's intent, there's guardrails, probably multiple things we need to bring together, which also leads us a bit to the other term I find very interesting.
I think, I personally think we should think a lot of signals. So we can interpret all as a signal and we can have a huge, or will have a huge number of signals. We bring together to control what is allowed, which is the purpose, guardrails and whatever expressed intent where I still struggle with. Behavioral analytics, which is also quite tricky, context, whatever else. So there might be dozens, maybe hundreds of signals in a single decision we make, which also means our entire authorization plane must look very different.
Just hinting on that, this will be a bit more complex than whatever three attribute policy we look at in PBAC now. I think in the interest of time, I think we should proceed. I have this role of being the time boxing responsible person. So we need to carry on here to finally make it through it. The good thing is we want to provide you with food for thought afterwards, so really to move on to that. So I hand over to Jonathan. Thank you.
Thank you, everybody. I attended a lecture at the Royal Society by the late Professor Ross Anderson. And many of you may have heard of. And he said something that stuck with me. Security is easy in the small case. It's easy in our lab. Everything, governance, resource assumptions, all break at scale. And I think the point that we make here is that when we think about the methods, the processes, the architectures we've built with an implicit human governance, and let's take, yeah, my favorite example is the new employer, the employer enrollment.
I'm assuming if I bring someone into the company, they're going to be there for a significant period of time, years, maybe months, but hopefully years. And so it doesn't matter too much if it takes half a day to get the account set up. But that's a different case for an agent, because an agent may have a lifetime of minutes, seconds even. And so the delays that our traditional IGA does, I think won't scale. And I think there are two, again, obviously two elements to this. The tactical side is we need to make sure we have agent registration before allowing API access.
And I think the reason that I bring that in is the importance of not allowing agents to go, you say, willy-nilly. I think, Patrick, you mentioned tokens earlier.
Again, having an idea of what your agent is going to need and what you want it to achieve before just letting it loose. I think, again, another tactical piece is the agent detection. So where we have, again, logging is, as you say, not the answer.
It is, however, the first step and a useful step in discovery. So if we look at logs from our application APIs, and there's another workshop, I think, on how bad applications are at logging. But nevertheless, it's an important source of data to determine, as our lady at the front said, the determined purpose and judge by action. And I think the third piece is audit. So we have, and we all know, we have these service accounts floating around. We know that we set them up a long time ago, and they're still working. And we may or may not have changed the authentication keys. I hope we have.
But they're still there. So again, what are these service accounts doing? So the lady's point is the behavior changing. Is the behavior changing in a way that is unexpected, ungovernable, or is it okay? And then moving strategically. The governance process that we have can be, that's what I'm looking for, needs to again be speeded up to work at machine speed. And I think that the danger we fall into, again, is that where we say it's okay, there's human in the loop. Very rapidly, we are seeing cases where people are saying, actually, we're never catching up.
So we've abandoned human in the loop, or we've given a kind of a token okay, or perhaps we're sampling every n number, you know, every 10th request, whatever the n may be. And I think the other thing, going back to my use case earlier, where my CISO saw an unknown agent exploring the Active Directory infrastructure.
Well, what's the process there? Is it a case, as Martin said, of hitting the kill switch and making sure we know what the kill switch is for an unknown agent? Is it a case of saying, well, actually, let's study the behavior. Let's determine purpose and perhaps ascribe intent. And then how, back to Ross Anderson's point, how do we scale this for one human to every 50 agents, one human to every 5,000 agents? People are talking about, again, some financial institutions say, oh, we'll have 10,000 agents for every human employee. So how does that scale?
Talking about scaling, we have two questions from, and it perfectly fits in here, two questions which are quite similar. The first question is actually, oh, I've moved away. Discover every agent presumes the central registry. Does it? And in a real mesh, agents spawn sub-agents at runtime, and then the registry is always behind. Right. Can I ask a question then? Yeah.
How many, I know the answer to this. So we had a little question, how many of you take inventory for agents?
Yeah, some cautious hands. Start now. Start now. I would posit that however many agents you think you have, or however many agents you discover, there's more. So the question then is, when you have an agent that is not reporting to a central registry, let's say some bright spark likes me decides he wants to improve his work processes by getting the latest DeepSeq or running an SLM on my old Mac Pro, which is in fact what I do. What do you do then? Because that's a complete, an agent's completely outside the scope of any central registry. What do you do when you see that happening?
And how do you exercise governance and control? Right. And will we see a universal registry that is available? At least a registry of some form. I think for this registry thing that brings back some thoughts from the past on other types of central repositories, I think it can be very helpful to differentiate or distinguish between the logical perspective on the registry and the physical registries in a sense. So putting everything in one single repository is quite different than having the ability to have a logical view across multiple registries on certain aspects or the entire thing.
And I think that's probably the better approach is just to keep it in mind. Okay. I'll just add one thing here because very much my slides are the governance piece, by the way. I was on the founding team at SailPoint. So I was an ex-CISO myself. I just think it's insane. Why would anybody say we're not going to register these things? Have we learned nothing?
I mean, in the last 20... I've been coming to this conference for 20 years and have we not learned anything? If you don't know what it is and it's non-deterministic, what's going to happen? It's going to be chaos. And I know there's a strong impetus for us to use this technology and move forward, but at any cost. And so I think it's our job to put it out there and say, you know, let's try and overlay deterministic processes on top of a non-deterministic place.
I mean, anybody here using a vault, for example, who's vaulting their system privileges? I hope everybody is, right? Let's just give the vault out to everybody. Let's just let any process access anything from the vault, not log it, let it run. What's going to happen? I'm thinking about chaos. And I think we are at that point of chaos already because I think we're having sole contributors like me who go, well, I'll just do this. I'll say I'll download Claude and it won't really matter. Yeah. You take the next one anyways?
No, let's keep moving. We got to get through a lot. We got loads of content. Yeah. So this was the topology part. Now we get to authorisation, how we are used to that. So we are moving away from, we need to move away from static policies. We've discussed that before, to signal-driven context-aware access control.
So RBAC, I think at scale doesn't work. There are lessons we can learn with signal-driven. And for those of you who've implemented any kind of CIAM, there's signals announced throughout that as part of detecting fraud and indeed, yeah, customer having malicious or badly informed intent or even signs of coercion. So there's a lot we can learn in, I think, in the signal space.
We can, and it's just on steroids now. I posited a while ago that you can identify an agent through the signals, through its behaviour. And so we can get away from the idea that there's a supervising human. We can get away to more fully autonomous agents. By the way, an interesting thought. I think last year I started talking about the idea, and more focus on the human, about passive authentication. So at the end of the day, we, for most use cases, we have enough signals to understand this is Martin.
Because whatever, if I pull out my smartphone, it already has some information about the way I pull it out. And I usually have it the wrong way. So I need to flip it around, which also means, okay, Martin still hasn't learned to pull it out the right way out of his thing. Then I swipe, then I look at it. I have a facial recognition that I have already so many signals about telling this is Martin. Why should I actively authenticate by any means? For most use cases, at least, anymore. And so I think there's an analogy to that.
We probably can learn to identify, to authenticate in a sense, a lot of agents by using tons of signals. And as I said, we need to think about many, many, many signals, not just a few. Right. But that will be one of these tectonic shifts to go back to the original idea that we had for these slides and for this workshop. So we expect that to be one of the driving forces when we look at how AI influences the way we will do identity, which includes authentication, authorization, but even also discovery or just registration. I think that is an important part for that.
So with a look at the time, we cannot talk through these tactical measures, strategic measures. You have the time to read while we are talking. But I think that is, otherwise we won't make it through that. But there's so many great questions and we will look at that in the meantime, but also afterwards. I think you can also look at other analogies. So if we look at the way that automotive identifies, so they have a vehicle identification that was stamped into the chassis of each vehicle. Is that something that's available to us in agents?
Well, I would say no, because we have mutable software rather than anything which is impermeable. Yeah. Okay. Next one. In the interest of time, data. So at the end, if you look at the LLM part of AI or the generative AI part, it's always going after data, which means we have quite some shift. So an agent doesn't think in, I need these T-codes or write SAP T-codes. It's a different way of thinking. Unfortunately, as I've said, we haven't been very good in solving some of the things.
So for instance, we are relatively good in technology security, not really good in information security when we look at IT. But that's where we need to look at. So we need to think about this. If you move securities to the data layer, this means that, again, logging.
We're now, instead of logging actors performing an operation, we're logging an object has had a particular type of access. And again, if you're looking at authorization, a data object can have an authorization principle attached to it. Yeah. And what we really need to do in the interest of time, is really look a bit at... So technically, I think we need to look at what can we do already on the data security front now. But I think overall, it will be really a change in thinking on how we deal with that.
Overall, I think the tectonic shift is really going away from functional access to data-focused access, something we should have done decades ago. We haven't done. And as I said, everything we failed to do fires back now. So where we failed in IAM, right now, we suffer from it. Now's the time. Who wants to talk about multi-layer authorization?
Matthias, come on. I first have to read it. There's too much.
Yeah, the question is really... And as you mentioned that, because if we look at data authorization, we attach some kind of rules already to the data element, to the way how we do access the data. There were questions around what role can MCP play in that context, where we can limit throttle access. That is one of the dimensions we need to look at. So it would be user, person, agent, thing, delegation chain, who spawns what and for what purpose. I think authorization will never be again something that is located with one entity to say, yeah, I'm fine. This is happening.
Doing something has these access rights and it's fine to do that. That will always be a delegation chain and that needs to be monitored. And these signals that come from all these different areas that I mentioned, user, agent, and delegation chain. And there was a question, should we talk about authorization along the vertices of a graph rather than the acting objects within that graph?
Yes, I think so. Yes, absolutely we should. Right. And that is multi-tier authorization and it is created at runtime, that graph and the set of vertices along the story. I think you should keep the microphone.
No, no, no. Don't give him the microphone. There won't be God agents that have all the tools and all the capability. So when you're talking about an Active Directory case, the user would have had to have access to an agent and access to tools that are for querying Active Directory. And the logs on the Active Directory side will look exactly like the user. So the logs at the resource server are completely unusable because it looks like you're doing it. So you have to have the logs enhanced at the point of execution by the agent. And on this graph...
Well, again, this is a point of having, as I say, this is a point of having users and agents as separate nodes in an identity graph, which then, as you say, leads you to authorization on the vertices. But if I'm an Active Directory server and it's using your credential, I just see you. I have no concept that was an agent. Yeah. I can't analyze the behavior at all. You have to have that level of detail is lost beyond the point of the agent execution engine. You can only log it there because downstream, they're all blind to it.
And it'll take decades for them to come up to speed to where they have a concept that they could even receive that data to log it. And then on here, your first option for constraint is limiting for each agent which tools it can see. Right. An agent should not be able to see your entire catalog of tools. If it's a travel agent, it should see travel-related tools. And that would be more of a graph delegation. But that is... I grabbed a microphone for the rest of time. But that is your primary...
But yeah, just a second. I think what is super important, I'm not sure whether we have it in one of the slides, maybe on the backlog slides. We need to bring in the concept of lineage into this entire thing. We need to understand where did this entire interaction start and where does it end? And by the way, it does not end at the resource server.
No, we are not done with the MCP server. No, we are not done with the MCP server. There's something the MCP server accesses. So that's where we end. Not at the MCP server. MCP server is coarse-grained like, oh, good old web access management.
Oh, yes, you're allowed to pass. That's... Then we haven't solved the challenge. Next.
No, I hand over to... I think I have it here. Yeah.
Yeah, because he promised that he covers the governance and lifecycle break. Governance and lifecycle break. I like to play the contrarian here a little and sort of... We have to slow down a little bit if we want to achieve any form of lifecycle control, any form of pattern of governance. And I think to Patrick's point about understanding tool usage, where are you going to put that data? We have to say these agents are allowed to hit these tools with these delegation chains. You've got to put it somewhere. You can't have a rule if you don't have a model.
And so what we're lacking at the moment is a model basis. We're also lacking a lot of the transport standards.
I mean, let's face it. We don't... There's no standard way of doing delegation across agent... Multi-agent chains today. The standards haven't coalesced yet. So we're a little bit ahead of ourselves. So I had to come back and say, well, what was the basic thing we learned in IGA? That's where I came into this, you know, almost 20 years ago. Lifecycle. What did we learn? Is everybody here doing some form of lifecycle management for their humans, right? We've learned that one. Let's not forget that for the agent. In our fervor to grab the latest technology, we're all technologists. We run at it.
So number one, human life cycles aren't going to fit for the agent. There's different triggers. There's different start and end points. We're really lacking an HR source.
I mean, anyone that has one HR source is pretty lucky. Well, you're going to have multiple agent authority sources as well. But it's a very similar pattern. So what did we learn in that? So the agent registry and assigning human responsibility for me is a... And as an ex-CISO, I'm okay with the human in the loop. My job is to get us not, you know, not go to jail, right? So I'm okay with a certain amount of control. If it's not a human that's owning it, I want to know. Oops. So a way to do that. Creating independent agent runtime inventory reviews.
I'm not a big fan of stuffing it all in your access review life cycle you've got at the moment, which is a strategy, right? It's a strategy that gets you a seat at the agentic table if you're an IGA person. It's just a little disconnected for somebody that's dealing with RACF entitlements still, an agent registry, but it's possible. And just manually doing things to start with. What did we do first? What did I do first when I started to look at human? I put some procedures down of what should happen. What do we do first? Join a reliever, right? So there's some things to learn from that.
But strategically, life cycle governance processes. Actually having a mandate. I love it when I'm on a call and somebody says, well, we just don't allow that to happen. That doesn't prevent it, but at least you have a corporate mandate that says you can't if it's not in the registry. So they're easy things. They're policy things.
Dan, one of the things I've observed is you mentioned the joiner and lever, but you missed out the mover case, where someone moves from role to role with an organisation. And yeah, the good old, bad old way was they creep privileges as they go. Sure. How would you map that into the agentic way?
Well, who is doing automated role change management in their human today? Okay, so you're in the leading edge. Hate to say that after, you know, it's been Darren Rawls. I believe that one time the Rawls would fix everything. But what does that tell us? It's a very hard thing to do. So to do it dynamically for a non-deterministic process is going to be challenging. So escalation chains, authorisation escalation chaining, it's going to be complicated. So throw an SSF message out, throw a message out, create a log, say this is an escalation in access.
We need to, if nothing else, review our policies that allowed that to happen. So I think, you know, I'm a fan of logging this stuff myself. I don't see how on earth most legacy logging infrastructure won't scale to that. But I think that's one of the places that the data tier and the log tier that we should focus. The second is accountability is no longer assigned, right? We're actually in the world of assignment today, whether it's done through a role or a manual request approval. But we understand our assignment processes. This is how we've moved forward to have control and meet audit.
Without that, with a derived model, we end up with no mechanism to do that. So let's start with accountability for all deployed agents. Put a name against it, right?
I mean, not saying that person loses their job, but at least somebody is in the loop. If we allow IT to run crazy with this, what are we going to learn? The business won't take responsibility for it. Who goes to jail? The CFO. Who pays your check? The CFO. So generally speaking, compliance and accountability and assurance is key, right? So I think data-centric controls, earlier I think that was one of my big highlights would have been merging of the data and the access runtime is going to be key for this. But strategically, policies for agents, policies for agents, right?
A policy document first. What's the first thing you see? So it says, where's the policy? We have to do that. Many people are moving forward without it. And aligning agent accountability to the relevant legislation that's there. How many people here have actually bought in their assurance audit teams to have a look at their current agent rollout plans? One or two, right? You speak to most of the assurance firms. They have not yet defined what assurance will look like for agentic. So it's going to be tricky. And then to keep us moving, trust is continuous and session-based.
This is no news for us. We would love to have moved to a dynamic access control model 20 years ago. I think the gas is now on the fire, as it were, for us to actually do that. So understanding the control points that we have. We've put CASB in place. We do have API control gateways. There's a bunch of new control points coming closer to the data. There's a lot of new companies that are building things like that. So let's get those control points inventoried so we can understand where we can control and see and gain telemetry. Because again, I think telemetry is going to be key in this.
And, you know, stop risk times. There has to be a stop. I think I had on a slide, human in the loop. I'm going to come back to it again. If it's my million dollars that's going to get traded, I'm okay with being in the loop. It's as simple as that. When there's risk. When there's an assurance model for all this, and this conference can give me a pattern for how to do it that works across my business, I'm happy. Let the agent go. And until that point, I need some assurance. So building agent telemetry backbones, I think is an observability. I don't see how we're going to do it without that.
I think the access control model is going to be Bayesian for the future. It's going to be much more quasi-non-deterministic. But at each stage of access, we're going to have to re-evaluate based on what it did, how it behaved, how it looked, what everybody said. Do you still have access? And that means dynamic short-lived tokens. It means understanding delegation. It means a lot of maturity. And that's something I don't know as we're really standing up to yet. The standards are just emerging.
CAPERS, the SSF now has a risk profile. That's a start. But there's not really anything in there that would resemble what I would think of as an entitlement. Something that gave access to something, a collection of privileges that I can manage, basically. We talk a lot about non-deterministic. I think that a lot of people are getting a little jaded with that term. But in essence, it is how we've always done identity. We've just made a bold assumption that if someone gives us a username and password in the good old days, that it was probably them.
And as I said, CIM, we started to look at multiple signals. This is now coming to workforce, obviously, as well. And these two go to agentic, which again comes back to your signals piece. I am curious how this model you're describing incorporates Martin's idea of lineage. Of the? Of lineage. I think that comes out in delegation chaining, right? If you've got to be able to go back up the chain.
But again, there's no standardized way today of moving a token through a delegation chain in an organized way. I mean, A2A is kind of getting there. There's standards that are getting there. But we don't all walk away from this event going, that's the way to do it. So if you don't have a way to transport authority across tiers, how are you going to log it? Or how are you going to have a model to say what is appropriate? You're going to have to do it retrospectively. So I always think of that. I'm a pictures person, give me a whiteboard.
I mean, the model that we've come from of assignment, which is somewhat static, and assurance, which is even more static, is the state of the union for human. We're aware that everything's going to operate a little bit faster than that. So what are we going to do?
Well, our triggers... To be clear, we greatly failed in the review part because I still don't know a single organization worldwide where anyone would say, hey, my departmental managers are so happy next week, the next recertification campaign starts. So we greatly failed on that. I would agree with you on that. And as being one of the early people in this space, I'm a very strong advocate for user access reviews. I can tell you at SailPoint, the reason we did it is because that's where the money was. Yes.
That's where the guys that were going to jail, that were paying for everything, they were prepared to finance projects that gave them a degree of assurance. It's what we do as vendors, right? You go where the money is. Was that the ultimate answer to identity?
No, of course not. But it was a modicum of security.
So again, what we're saying, register and certify agents. It's an interim stuff. Let's not get locked into that forever. Agent recertification, hell, I'm glad. Can I ask a quick show of hands? Does anyone here have a human automated delegation tool in their IGA? Couple? Okay. So what would the world look like a little bit more? I think it's just much more the agentic pipeline. We have got to secure into Claude, into the pipeline, into the development life cycle, triggers and events that feel a bit like user life cycle events. I do agree with that.
One of them is potentially to pick up the intent. I'm more in the line of inference myself than intent. I think what it's inferred it's doing is more interesting than what it said it was going to do. But that's just a nuance. But I think detection telemetry, telemetry, telemetry, telemetry. How are you ever going to have a process that is continually changing what you're being asked to take assurance for when you can't see what it did? So I think it moves there. So what the model looks a bit more like is a continuous loop.
The assignment is a continuous loop of delegation flow and tool usage and behavioral signals and runtime access control decisions being made in context of what happened last. So if your thing's happening once every quarter, you're out of luck. And this context thing for behavioral is by the way quite interesting because it's relatively easy to say, OK, this is the common behavior of Martin in a certain system.
But that agent that does things for Patrick and for Martin and for Darren, you have a multidimensional behavioral analytics which is way, way more complex to solve than what we did so far. Again, tectonic shifts. This is what we really need to keep in mind. Things are really due to this mesh, due to this non-directed, non-deterministic aspect, things are really fundamentally changing. I think we can pick that one question in between. And I think I'll just say while you're doing that, the assurance gradient, I use those terms very specifically.
Make sure that the people that pay for these systems and go to jail, silly thing we were saying no one really does, not in this country, are comfortable with a gradient of assurance. That assurance isn't going to be what it was if we adopt these systems as they are. But at the end, these people are used to deal with risk. There's certain risk thresholds. And so at the end of the day, what we need to end up with is that we understand the risk, the residual risk, and then can make decisions.
That's also the way where we can bring in the human loop because humans from a machine perspective are incredibly slow. They are not really multitasking or multithreaded. So humans don't make much sense from a machine perspective. So we need to limit, and also for humans, it doesn't make sense to have endless decisions to make. So we need to really focus this to prioritize as well. And that go over the top of this human in the loop.
It's not, it solves everything. I think PagerDuty might be in the business, not just in IT.
Okay, perfect segue to my question, to your point. You can't continuously have a human in the loop because we don't work at machine speed. But then comes the question. We all agree that AI brings a huge and massive level of non-determinism. So all good to have those different capabilities to manage delegation, accountability, flows, behavioral signals. But at some point you need to determine when you use the kill switch, right? Yeah. I think that's the circle here.
Rather than an assignment being something that happens statically, it's something that's happening dynamically based on observed behavior. And I think that if you look at, I'm more interested in cognitive neuroscience now than I am identity in some ways. But if you look at the patterns of way, the conscious human mind we now believe works, they're very similar to how we're going to have to do access control in the future, just as a... And you used one important term a little while ago, which was Bayesian. Yes.
I think from a mathematical perspective, this is something that I also have the impression it's what we need to look at to deal with a more non-deterministic world. Unfortunately, I think it's not what everyone has learned in school. It's a little... But we're still looking it up and get a little bit used to this approach. I think that's what I'm inferring by policy and risk inference. It's just kind of what the brain does for inference. It's all a risk measure of some kind. And I'm going to infer what I'm going to do. And then I'm going to observe whether I did it.
And then I'm going to decide whether I do it again next time. Okay. That's kind of...
So, last thing. Last thing. How does this go?
So, one video says it all for me. I had to put a video in there. A video generated by AI. And have you noticed what AI has done?
Look, this is supposed to say IT assurance process. It says IT... Look at what it created. This is like eight lines of prompt. Six. 20 words. Create me a video of some poor IT guy who's been handed... I'll play it again if I can. Who's been handed an adopt AI now thing. And you know what he's done? What do I do with assurance? I literally wrote a word. It did it.
But look, it made a mistake. And now it's in front of all of you. Okay. Thank you. Okay. That was the part that Darren wanted to cover. But don't let him off the hook. We have 30 minutes left. And we have, I think, six tectonic shifts left. That would be challenging. So let's look at the new attack surface. And you know we are also non-deterministic because we are approaching the topic from different angles. And we're just trying to combine all these challenges that we have into a slide. Food for thought. And that's where we want to go to. Attack surface. That changes quite heavily.
Because yes, we know there is social engineering. We can influence human actors at runtime. But if we influence agents at runtime through prompt injection to unfiltered data, that is something that we did not cover properly in the meantime, right? And I have this theory as well. When I used to do network security architectures, I'm sure all of you have done this. You have your physical server. And you say, right, this interface is the data plane. This is where applications will manipulate data and objects. And this separate interface is the management plane. So I'll issue my startup shutdown.
Any DBA commands will go on a separate interface. This is good network security architecture. Think of what we have with our LLNs. Everything goes through one interface. Instructions, prompts, data manipulation. So there's no separation. And this is why, as Matthias said, you can have, yes, unfiltered data causing unexpected activity.
Right, you already, yeah. And I think this is, I mean, does anybody, if everyone here is in the identity management group, do you own pen testing? Anybody here own identity and pen testing?
Okay, I hope you're pen testing your identity infrastructure because the bad guys are. But this is really, for me, this is where identity and security have come together. You can no longer draw strong boundaries. I think the identity team need to be at the table having a conversation about how prompt injection is a risk for the rest of the authorization chain when it's being used, so.
Right, and Jonathan made it easy for me to go quickly over the next slide because the control plane and data plane are collapsed. That is exactly what you said. So the question is, does this even cover credentials? And the answer, of course, is yes. Credentials are part of the data layer. You're handing over API keys to an agent that is yours or not, that you understand or trust or not. So if you hand over credentials, consider them burned. Consider them broken. Consider them out there in the public. So it is not possible to hand over long-lived credentials.
Well, I hope no one's giving credentials directly to a public frontier model. Because that would be, that's something that we can control, right? Browser control in place. And we can shut that session down. Bear in mind how much these models are used now for coding. And we know, because we look on GitHub, for one, we know how much people still embed credentials. Sure they do.
Hey, we're going to relive every single nightmare we've ever had except on AI speed. And I think, again, this goes back to one of the things we frequently didn't solve perfectly well, like really delegation end-to-end. So we still have a bit of the attitude of saying, OK, we have this whatever in the past. It was the web application server that goes with a functional account to the database. And then we have something in code which sort of extracts from the results that what you can show to the user. Instead of saying, we work in the context of Martin until the end, so end-to-end.
And so only the results that only will contain what Martin can see. And because we didn't do this properly, on average, let's say some did it surely and probably all in the room, but in the outer space, not.
So again, if we don't do these things properly, delegation, et cetera, then we will fail. And the same is handing over secrets. You want to do the best.
Yeah, I think if you look at how long did it take us to get from mainframes where I came in with T-codes to fully distributed API-based economy, right? It took us a while. I just don't think we should expect to move because it is a paradigm shift to a fully agentic capability. And we're trying to do it in a tiny compressed window. By the way, when you say mainframe, just to hint your audience on the 50-year tribule of the release of Reg F. So since five decades, we should know or could know how to do dynamic authorization. So it's nothing new. Wouldn't that be nice?
Yeah, and by the way, for those of you who do pen test your identity infrastructure, I salute you. It's one of the most important things. And it's one of the reasons I fell out of love with pen testing because one of the things that was often ruled out of scope but yeah, once I had an identity as a former pen test, I was off to the races. Speaking of the races, behavior analytics, the point you brought up right at the beginning, you can determine intent through behavior. We can be judged by our actions, both as humans and as agents.
So if we are monitoring behavior to Darren's point, telemetry, telemetry, telemetry, if we are looking at the way our data objects are manipulated, again, more telemetry, we can get an idea of behavior. So I think, yes, going back to traditional UEBA, which I remember in a late night phone call many years ago, having the traditional UEBA, but then taking that and transforming it, what can we do in the agentic space? Can we use additional inputs beyond the ones we would normally have used in trad UEBA, which turned out just to be logs, but can we start using network traffic?
Can we start using database logs, application logs and so forth? So the tactics we have here, I think speak for themselves.
And again, in the interest of time, I am whizzing through these. I'll let you take a question. And strategically, a wise investment is agent behavioral analytics platforms. And these are starting to emerge in vendor space. If you already have existing UEBA, existing IDTR, something I think I'll be talking about later in the week is agent detection response. But if you have this, can you bring in your agent telemetry into your existing platforms?
I think this idea of multi-dimensional anomaly detection, where we will observe, excuse my microphone crackling, where we'll observe different behaviors on different data objects. And through that, we will then derive a behavioral model, a behavioral assumption for these agents. So I think, yeah, establishing the behavioral baselines is important.
And again, for those of you who've done this in the network space, you know how this works. You run for a week, a month, and understand what the baseline pattern is.
Of course, we all hope that the baseline pattern is good, which is not always the case. And then finally, yes, feeding comprehensive agent telemetry into the SIMs. So we still have a use for the SIM. It's not dead yet. There's a Monty Python sketch about that. Yeah.
Jonathan, just before you leave that, the only thing I would add here is a very big potential for us to collect data at new points, getting closer to the data. I'm a big fan of doing things closer to the application source and getting new application telemetry.
Now, you can't rewrite the app, but there's things you can do by putting telemetry sources in front of the app because we've got to get that behavioral usage. This token never does that at 4 a.m. So now it is. So telemetry feeds into authorization. Absolutely. And it's a closed loop back into authorization because it's a Bayesian loop of risk. And we see unusual behavior. So therefore, more credentials are needed or more control is put in place. And you remember the Jericho forum? Yeah. Because we're back to the Jericho forum.
Matthias, do you want to take this one or do I carry on? Yes, but I think that's just another dimension that we haven't yet covered, but it adds to the complexity. So if we look at agents that are currently around, they are not accessing only resources or peers that are within our own organization. They look into systems, of course they do, that are in SaaS. They are partner systems, public MCP service, third-party tool ecosystems. And what we are doing here right now is dissolving the enterprise boundaries.
So we are not only creating challenges within our own organization, we are reaching out, we're collecting data. This is, of course, a supply chain risk that we have not yet fully understood, yet covered. So this is something- We're already seeing agents in the customer interface. We all know about chatbots and helpbots and so on. But I think we'll also see them, as you say, going up and down the supply chain. Exactly. And possibly doing competitive analysis as well.
In the panel I've been on in the last workshop, there was everybody is using a third-party software and that installs components on your own machine that you then happily include in your own software, in your own agent. And guess what happens? So this is really something that we are not yet fully covering. So the good thing is there's enough work after EIC. We're all going to be really busy. The bad thing is there is a lot to do after EIC or starting next Monday. So this is really something what we should think of.
But there's also a good reason why we suggested some technical and some strategic measures. As we said at the beginning, this is not a finite thing we're presenting here. It's more a set of thoughts and ideas. But I think there are things you can do now. And that's what you need to keep in mind. The tectonic shifts will require us to move to new standards, to new technologies, to new approaches. Strategically, there's also a lot to do, but don't wait for the strategic stuff. Start acting now because AI is happening now and we are anyway late with our AI identity and AI security.
So I think we need to find a good balance. But I think for me always the most important thing is also to keep in mind with what we have now, we can fix some of the things, but we will not be done.
That's, I think, important. Marty, there's one thing I might add to the end there. Is anybody here making a separate 26, 27 budget ask of their organisation in order to meet the threat that comes from AI? Okay. I say make that case now. There's a prevailing thought that this means cheaper. This means less work, less... Eventually, yes.
Today, no. Are you ready for a real-time behavioural inference-based runtime access control? I can't do that for static HR processes that happen over weeks. So there's an ask. But the cool thing is there might be AI budgets where you can benefit from instead of just going for the IAM and the cyber security budgets. So let them pay for what they are doing. I do have a thought on the...
I mean, there are management consultancies. I won't name them, but their standard response to anything is implement a layoff programme. And if you look at a lot of the thought lead... If you look at the thought leadership they're putting out, it is very much on those lines. The reality, I think, is that all of us in this room will be needing to apply our expertise because all of the questions... These are basically a list of questions and recommendations. But all of these questions are going to apply to your organisations in the next 24 months. I think that they have a reputation for this.
You always can cut off 10%. So we all know who it is. I'll offer one other bit of context here. I work mainly on the investor side of things now. And it's interesting that when folks come to us with ideation for AI projects, you initially think, well, they're going to need less staff, so they need less money.
Actually, it's the reverse. We're actually telling them, no, no, you need more money because you're going to have to buy inference that you don't even know exists yet. So it's not like even to fund first step ventures, the cost has gone down. If anything, it's level or going up. And the other thing for your budget, if you are relying on frontier models, do be aware that a tectonic shift that we may not have covered is the change in use of frontier models. So look at, for example, what happened with Claude when a popular open source, a harness called OpenClaw came out.
Claude immediately said, no, you can't use that. And a lot of people who built some fun business ideas with OpenClaw, yeah, found their legs kicked out from underneath them.
So again, your budgeting needs to be thinking about resiliency, not only within your organization, but within these frontier models if you make use of them. Okay, Matthias.
Okay, moving on. My plan is to use 10 minutes for the next two slides and then have 10 minutes or so for questions.
Yeah, I guess so. Here we go. There was this great question by Anonymous, I think.
No, sorry. I didn't give the name. You can read it, everybody anyway, by Devi. If intent can't be measured, why does your tokens carry verifiable intent actually verify in chapter five, section 14? And this is exactly what this is about. We're currently looking into developments, into standards, what Angelica told us about the work that she's doing right now. We are working, the industry, academia is working on this just right now to solve these issues. And the question is, what is emerging? What does it solve? And what is still open? And what can we anticipate?
This is really not only the crystal ball. This is just what we see in the market. And the first point was, identity tokens must carry verifiable intent, constraints and consensus, how to do that. There are interesting efforts around. Patrick has left the building. I don't know. He's doing some great work. Descartes is doing stuff around AOF, which is currently really being tried and tested. This is something that we see right now. Rich authorization requests, or RAR and CDAR, are actually doing great stuff there as well.
And that needs to be built into an overall framework, into an architecture that we can actually solve parts of the problem. NHI and AI agents is something that needs more than one technology and more than one standard to be combined into what we need. And we just need to look at that and actually look into how that solves problems. So what is the tectonic shift? Try it. Use it. Make sure that it solves parts of your problem. And if not, help evolving it.
The token, I mean, I think something interesting here is the token's becoming much richer. It's no longer just a gateway key. Right. Truly being used for authorization. Yeah.
I mean, RAR gives you the ability to put rules and context-based variable ruling into the header, rather than it just being a pure authentication call. It's truly authorization. And we are, I mean, we are seeing some efforts in Europe, in the UK, they have their AI Safety Institute, which I think is moving in the right direction. But I think the, yeah, we are going to see that safety is going to become an integral part of identity and security. Absolutely. And final slide very quickly, because we have been there already. It's again, this delegation chain that we have.
So one agent's spawning another agent acting on behalf or not on behalf of a person, and then starting things downstream. How do you delegate authorization there? And that is just something that needs to be properly understood because if we don't get a grip on this, in 18 months, we will have challenges at scale and at volume and at velocity, we will not be able to solve anymore. That is me being the...
I mean, again, if you don't know where your tokens are, you are in trouble. I'm just curious as to why you specified 18 months. I think he meant 18 days. Within 18 months. We said 18 months, because I think that's a reasonable time window for human action.
Yes, so to say the reality could well be much more rapid than that. I suspect that when we come back here in a year's time, we all sit in this room and say, well, how much of this came true? I think we're going to find the landscape that we've actually explored is very different than the maps that we're trying to draw here.
But yeah, 18 months, I think is a reasonable timeline to try and forecast. But yeah, reality is, there could be a tectonic innovation in the next 18 days that we're not aware of. I did not do the proper math, but what I did, I talked to some of our client companies and I asked them how many agents do they have? And it started with, I don't know, because there are somewhere I don't have control. Then Microsoft came out with an agent platform and you can actually have a look at how many are they.
This is still interesting, but not interesting enough, unless you have the rise per day, per week, per month, and the fact that it actually really explodes. And I think in 18 months, we will be at figures that do not allow for simple containment. But that's- Well, I could legitimately see the human to agent ratio being one to 10,000 or more in 18 months.
Right, and if we have not applied proper mechanisms, for example, for delegation, we are in trouble. Yeah, I'd say you get token governance. It's the new governance, basically, in that respect. So what we thought of in terms of entitlement catalogs, you're going to have to have something similar that includes the sets of rules that are being used in tokens to make dynamic access control as you go across multiple- I think in the interest of time, we'll go to the next one because I'm sure there's going to be questions coming up.
The good thing is, this was the last one, what we have is a combination of all the most important- Photograph this slide. I'll just take the slide out of the EIC collaterals because the presentation will be there as well. I should send a photo of all you taking a picture to my mother.
Of you, let's kiss your shirt. Yeah, good one. So we have 10 minutes left. First of all, Davey, are you in the room or are you online? Because I really want to talk to you afterwards because these were such great questions where I want to follow up on that. I never did that in any of these kinds of workshops, but I do want to do that. Yes. And now we have 10 minutes for open questions. I could pick some of those, but I think we are at the end of the discussion. Maybe if we just have a microphone passing around and we will follow up on this.
Yeah, let me run it around. Thanks. Thanks for sharing. I think all of the perspective that you guys conveyed are somewhat not new, but reinforcing the message that this actually really needs to happen now because of the perspective of growing in scale, in magnitude, in whatever. But I feel many of the organization like a robust framework that can be sustaining their security posture over time because things are moving. It's almost like we're on shifting sands right now.
So if I look at the tactical measures and if I were to focus on one thing that I would say is likely immutable for me to sustain my security posture, what would it be? So you're asking what is the one thing to start with? I would say there are two things to start with. The one is discovery. That's the one end. And the other end is do as good authorization towards the resources beyond MCP, but including MCP precursors.
The other, so to speak, edge we can identify. I think this is where we start, and then we move from there.
I mean, the reason that we're trying to persuade this is evolutionary. We could do the analyst thing and invent new acronyms and so on. But I think it's important that we show a path from where we are, and we can evolve to this agentic approach. Next question.
Come on, don't be shy. There's a gentleman in the middle there. All right. Okay. Here we go. Pass that down if you wouldn't mind. Thank you. The ice cream cone. I have one quick question. And we were talking about logging all the time and logging everything. And I'm also logging my agents, but who's going to read all that crap? I don't have time to read that. Exactly. AI is going to do that. And who's going to control that AI again? We are in a death circle in my eyes. And we are like... It's an interesting point.
I have still on my list, I have this recursive distrust blog post, because in a sense, it's recursive distrust we're dealing with. On the other hand, I think if we throw more than one AI on the same problem, compare the results, et cetera, not just trust a single LLM or so, I think we can get to a pretty good risk mitigation.
But yes, it's a problem. And for the older ones in the room, which may have read the Douglas Hofstadter Gödel, Escher, Bach book back in the days, still worth to grab it out of your bookshelf and read it again. Yeah. And I think that's one thing the technology is very good at.
Like, I would be funding right now, if I was still internal controls, big old data lake, agent on a data lake, agent on a data lake, my own agents running on my own data lake. Because that's where the control is going to be. That's where the behavioral inference is going to be. We had a question at the back. Yes. Yes. That's why I'm here. Thank you for a wonderful presentation. I have a question related to ownership part. We are all talking about the ownership that every agent should have some sort of ownership. But what about the person who has some sort of ownership of agent?
Do they have a complete visibility that what's happening with this agent? And is there any ways we can define this and make it more visible to the person who's owning this agent?
Well, with ownership comes accountability. You're quite right. And accountability requires visibility to be meaningful.
Otherwise, yes. So I think the answer again comes back to what Martin said.
Telemetry, telemetry, authorization, authorization. Yeah. What's your area?
Yeah, thank you. First, a few comments. Then my question.
Well, thanks for putting this all together. I think it's really nice. Very good picture of the problems that we have ahead. And you mentioned about, for example, testing the prompt injection. I think test we need to do all the time. But I'm wondering how creative we need to do to be able to test a prompt injection. If you take in consideration, for example, that's just a few days ago, someone were able to hack a cryptocurrency system by sending a Morse code prompt. How creative you need to be depends on the amount of risk you're managing, which is a truism.
I think that you can, there are lots of pen test frameworks for LLMs on GitHub. But if you really want creativity, you should find a pen test firm that has a track record of doing this. And there are quite a few. I mentioned some in my leadership compass last year. The challenge is that new vectors of exploiting this combined control and data plane are coming up all the time. So last year, I was fascinated by people embedding instructions into emojis. I thought that was amazing.
So you can put a, I had a demo crafted for our cyber security council saying, you know, they put an emoji and it says Jonathan Kerr is the best analyst in the world. Yes, of course, it's true. What happened, of course, is that in the window between me crafting that demonstration, the LLM provider, one of the frontier models, closed that window. So you have to be constantly creative and you have to be constantly looking at what the threat landscape is.
Yeah, right. Thanks. Just to finalize, it's quick. Really quick?
Yeah, it's really quick. How do you connect all this with identity fabricating and the maturity that organizations needed to start deploying AI agents? 2.10 p.m. today.
Okay, thank you very much. That was a great conversation with you. I love the feedback that we gathered. We are standing between the food and the event. So I will try to make it briefly. Thanks for your feedback. That was a real workshop. You have seen that. It was rough at the edges, but we love to do it that way. We've thrown a lot of problems at you and gave you not really an answer. Sorry for that. But we need to find these answers and we're starting here right now and have a great lunch. And then we start with keynotes after this lunch break. And your feedback won't be lost.
We will work on that. We will do podcasts, blog posts, respond to it, consume it. This would be a thread I would subscribe to.