Thank you, thank you. So here I am, day four, last presentation at EIC to talk about Identity for AI. Has anybody heard about that this week?
Honestly, if I say something new, please raise your hand. Okay, let's see how this goes, right?
So, if you haven't heard it, raise your hand. So, Identity for AI, trust for humanity. Because look, if we can't secure AI, we all know what happens when the sky net rises and the terminators rise of the machine. So we've got to make sure that we can do this. We have this new identity type, non-human identities. And if you think about where identity management has been, maybe even a little bit today, but at least in the past couple years, we think as humans being the primary target, you think of all the threats are presumed to be from the outside.
And we still believe in this ability to put friction in a name of security. But where we're going is that you have to look at the sheer scale of non-human identities. I feel like this 80 to one agents are gonna outnumber humans is on the low slide, right? I've heard it up to 300. Probably by the end of this week, somebody said 500. But the agents are gonna outnumber humans.
Users, whether they're your business users or your customers, they demand a simple, easy experience, but it has to be secure. And the threats, you have to presume they're on the inside now. Scattered Spiders showed us that. You need to see, you need to make sure that you know who the people are who are accessing your agents. Because if the wrong person access your agent, they can exfiltrate data at a remarkably fast rate. It used to be eight hours, now it's 22 seconds to exfiltrate data in a breach.
So, really important. So, AI is accelerating our world. I think I heard Patrick say, they're non-deterministic systems. We can't control what they do. We try to control them, but they have a mind of their own and they're really, really, really creative in how they get around things. There's a study where they gave an AI agent money to go buy something on the internet, find the best value. It went out, it found the one it wanted, tried to buy it, came up to a bot that said, came up to a captcha that said, prove you're not a bot. Tried for about two minutes, realized it couldn't do it.
Went to the Amazon site and posted an ad, said, I'll pay you $5 if you get me through this captcha. Somebody responded, they said, this sounds really fishy. Agent said, oh, I'm sorry, I'm elderly, I lost my glasses, can you just help me? Person took the $5, went through, agent bought what it needed to do.
So, they're really clever, they're really creative, they're gonna do things that we wouldn't think of. And so, you need to find a way to secure them. There are new channel for commerce, massive scale, I've already talked about that. And they present this constant evolving threat. I think one of the things that we've been saying in identity for the last year or two is that identity is the attack surface. We say that all the time. I think there's a stat in one of my other presentations that says 86% of companies experienced an attack on identity last year.
The thing is, is AI is becoming the next attack vector. So, interesting things, right?
So, McKinsey, they put out an AI bot to say, hey, this is how you get access to our research papers. Found out that you could use that and exfiltrate all of their research papers, whether you had an account or not. At least they found it themselves, but that's an attack vector via AI. The other one I really like is Microsoft Copilot. For people, especially Mr. Martin Cumpinger here in the front row, I'm sure he gets well over 300 emails a day.
No, no, oh, okay. I get over 100, so I figured you, anyhow. Really?
Oh, okay, okay. Yeah, exactly, well, Copilot, Microsoft, came up with this great idea. You can have Copilot go through your email and summarize it for you.
So, at the end of the day, it'll tell you, these are the things you have to action on, these are the things that have been actioned, I deleted all those newsletters for you, right? Only thing is, somebody found out that they could send an email to that person at Copilot running with the right prompt in it, and it would send that person outside of the company the same summary. That's a little scary on how you can use, how you can attack AI to end up getting access into things.
So, AI is attack vector, but it's also a massive opportunity for agentic commerce. It's forecasted to be $5 trillion by 2030. Just to put that into perspective, that would be the third largest GDP in the world. It's a massive opportunity for retailers, for people who are doing digital business. It's also a massive threat, because if you don't get it right, and you don't attack, and you don't engage the agentic channel, you're gonna be like the high street stores that didn't go to the web, and you're no longer gonna exist.
So, we have to be able to get this right, because there are gonna be people who only engage through the agentic channel. So, this brings up a really good question. Is agentic trust equal to human trust? Who here trusts AI agents more than humans? Who here trusts human more than AI agents?
You know, it's funny. I've been asking this question for about the past four or five months. Four or five months ago, it was people trusted AI more than humans. Then it became 50-50. Then I actually had one audience where no one put up a hand.
They said, look, we're all security people. We don't trust anything.
But now, we all trust humans more than AI agents. So, I don't have to tell you that AI is infallible, right? It's not infallible. It can be bribed. It can be tricked. It can be manipulated to do things that it's not supposed to do. And really, what I'm saying here is you can't let AI police itself, right? You can't say, here's your rules, Mr. AI agent. Don't go outside this boundary, because if you threaten to delete it, it'll go outside that boundary. If you offer it money, it'll go outside that boundary.
If you ask it to write a phishing email, and it says, no, I can't do that, just tell it it's for training, and it'll give you a perfect phishing email. So, you can't trust AI to police itself. You need to have security around it. Patrick talked a little bit about that. An identity must evolve to meet these realities today, right? We must shift from this person first to an agent way of thinking.
And so, what we have to see is, this is on the left-hand side. I kind of talked about this, but it's identity is only a login. It's really what we think about when we think about identity, at least in the past, it was, I do identity management. I assess the risk. I determine, do you need to do step-up authentication? I do all that. But then I give you a login token, and I walk away, and I say, hey, you got a session, have a nice day. That's not where we are anymore. Where we are now is you have to think about runtime.
You have to think about that authentication that we used to focus so much on as context. So when somebody wants to commit a transaction, that's where you have to go and say, is it the right person? How did they authenticate? Where are they authenticating from? Is this something they should be able to do right now? These are all the questions that we have to answer today. Identity has to move to become authorization-centric after you do the authentication. The authentication is a given. That's runtime identity.
That's what agentic agents need, and Patrick kind of summed it up really well at the end there about how you do that for runtime identity for agents. Here's the use cases that we see from our customers. You have your consumer agents. This is me sending Claude or ChatGPT out to go shopping for me and buy stuff for me. We have organizations, telcos, that are saying, I need to figure out how to get an agent to be able to sign up for a mobile plan for somebody.
Like they want it to get all the way to the point of contracting, and then reach back to that human and say, what do you do to accept this contract? So they're optimizing their websites to do that. We have actually two telcos that are doing that. Customer service agents. These are the ones that sit there when you come in, the digital assistant types, customer service agents. User comes up, you're a financial services company, I want to do X, Y, and Z, the agent tells you what you want to do. Employee assistants.
We see the biggest use case internally is I want to use a gentic for my help desk, which to me is really scary, because if you already are attacking the help desk takeover accounts, and now you're gonna make that a gentic, it gets really scary when you think about that. So, here are the challenges you have when it comes to the agents, and I hate slides that build that much, but here are the challenges that our customers are seeing. How do they authenticate agents? How do they register and manage those agents? How do we get them on board? How do we make sure they're there?
How do we not have shadow AI? We need to standardize that security. You gotta secure your agents and have authorization tools in place, and then lastly, you need to be able to discover them, audit them, as Patrick said, you need that receipt. You need to be able to say who did what.
So, when we look at best practices for agents, and for a gentic identity, you have to know your agents, right? One of the things you have to do is you have to figure out is that an agent trying to have that session?
So, if an agent shows up, you wanna flip your authentication interface to an agentic authentication, and you wanna give them an MCP server to access as opposed to making them read through everything on your webpage. You wanna delegate tokens with limited scope.
Again, I'm just repeating what Patrick said. That's why it took a long time to get here. Limit agent access. That's one of the things you need to do. You need to have short-lived tokens. You need to make sure the human's in the loop, and the other thing that we're looking at is just-in-time agentic access. Just go get that token right before you need to do something.
And then, this is an illustration of kind of what Patrick was talking about, right? And the way this works, and the most important thing, I think, and the thing that I think people can do today to enable AI agents is put in this agentic gateway. A gateway that sits in front of your API and your MCP gateways, that sits in front of your backend services. A gateway that can take a token that is a delegated token that has the agentic identity, the user identity, come to the gateway and say, what can I do? Can I do this?
Go get that authorization, and then convert that token into the secret, or whatever is needed back here to access just that piece of information in that backend. This is how you limit the scope, and this is really what we're seeing.
So, the agent gets registered, the user authenticates, it hits the gateway, you go up to the authorization, and you get that very limited, finite scope, and your agent never has any secrets. They can never impersonate everybody. They can only do what you tell them to do.
So, with that, identity for AI will bring trust for humanity. That's all for now. Thank you. Thank you.