Thank you. Yeah, shall I start?
Yeah, okay. So, I think this is the most interesting topic, not just in this conference, right?
The AI, the AI agent and the AI in general, it's just mind-blowing, right? I was just in a, just an example, right? I was two weeks ago, was it, in a trip, vacation in Japan, and I needed a sunscreen, right? I just took a screen, like a picture of a shelf full of type of sunscreen, and the response was, oh, based on your skin, your preference, please take the one on the left-hand side, the second row, the blue one, the light blue. If you have a budget issue, you can take that.
It, like, every day, right, when I interact with the AI, it is mind-blowing. You don't need me to, you know, to share it. I bet it's experienced across the world. And this is what we're going to talk about today, right? We're going to talk about the enormous potential that it, that would bring. We'll try to frame it a bit, right?
Like, how do you handle that? And we'll share, like, some guidelines and the strategy, and then how we approach that amazing revolution, I would say, that we are going through. My name is Leana Dabney. I'm a VP product at Ping, leading the identity trust services alongside the verified trust strategy. And Adam? Perfect. And my name is Adam Rusbridge, so I'm a group product manager at Ping as well. I am responsible for our authorization product line, okay?
So, that was a good intro, right? So, really, what we're trying to do here is make some sense of the chaos, right?
You know, the world is moving very fast. We're trying to make sense of the chaos.
So, you know, Ayelet, maybe you could start. What is trust these days?
Yeah, you know, it's a tricky question, you know, because, as you said, things are moving so, so fast, right? So, when I think about trust and digital trust, I think about consistency, right? Transparency. Every time I get into the workplace, the application, I get the same experience, I know what to expect, right?
So, this is trust. And it used to be, you know, potential, something can be broken, right?
Either, I don't know, something new happened these days, right? Or actually, in the past, if you want to keep the trust going, right, and maintain it, although some changes occur, like, I don't know, platform change, feature, a new feature, some new interface, right? And you kept up with the pace.
Today, the changes is not yet discrete. It's all over. It is all happening at once. The platform, the interface, the technology, the feature, the new business line.
So, it is all changing at once. And that is a huge challenge, right?
So, yeah, it's a good question, what is trust? I think we know what is trust. We're a human being. But the question is, how do we maintain the trust within these, you know, enormous changes that we're going through? And the potential, by the way, it's not just for us, right? Those that want to do good, but also, it's an opportunity to abuse, right? Absolutely. Yeah. Absolutely. Okay.
So, Adam, I know you guys at your team did some research, right? Tried to understand what our customers think, how industries are actually feel about trust, mind sharing?
No, of course. So, last year, you know, Ping surveyed about 700 IT professionals, right, from across the industry about these topics of AI around fraud, decentralized identities, right?
So, we just wanted to run through some of the highlights from that survey there, okay? So, 54% of organizations are extremely concerned that AI technology will increase identity fraud, right? 41% of organizations expect cybercriminals to significantly increase their use of AI over the next year. 48% of organizations are not confident they have the right technology in place to defend against this. 48% not confident they could recognize the deepfake of their CEO. And when we asked about investment, right, 95% of organizations were expanding their budgets to fight these threats, okay?
So, overall, you know, we can see the concern that our customers have around the implications of AI on fraud, on trust, on the evolution of this landscape, right? We can see the investment being made to address this.
So, Ayelet, you know, how do we get here? Yeah, speaking of trying to structure it, right, making some order in what is happening around us.
So, if I look back, right, a few years ago, the technology that was out there was rule-based. If, else, then, right, things were structured. Speaking about trust, right, it was easy here to establish and maintain the trust. And then there was some evolution, right, machine learning, some statistical module. Next step was deep learning, right? There was some kind of reasonable pace of the evolution. And then AI, you know, arrived, right?
And the pace of the innovation and things that we get from customers, things that we see out there in the news, new tools and new threat that we'll share in a second, is, like, the evolution is mind-blowing, right? And I think when we made this, it was, I don't know, a while back, a few weeks ago, right?
So, we were kind of looking for some cool stories that either we hear from customers or we saw in the news about things that are available today, like think about, you know, the food chains in the US, right? I think 500 chains, stores, already implemented an AI agent that take the drive-in order.
So, it's not a human being. It's an AI agent that take the order automatically.
But I bet, since then, there may be a few more. So, the change is, like, we can talk about AI agents and assistant AI agent, but it is so, so soon would be an agent that would take decision, right? And would behave behalf on us, either permit or non-permit. But the pace is amazing. Yeah. Okay.
So, you know, we see these changes happening faster, right? This is a good news story. Yeah. It's a good news story. Yeah. Yeah.
Well, I think, you know, if we look at this video, we can start to see that it's not just being used for good. Welcome to this live demonstration of detecting deep fakes in a Zoom call.
Today, we'll show you how easy it is to change a face in real time using modern face swap applications. With just a few clicks, the face swap application alters the presenter's face. Notice how realistic it looks, mimicking every movement and expression. Our advanced algorithm detects the deep fake in real time. The badge on the bottom of the screen updates automatically to keep users on the other end of the Zoom call informed. This ensures that all participants are aware of the potential manipulation. Thanks for watching. Yeah.
And I'm sure if any of you, not me, I'm not scrolling in Instagram or anything. I'm spending my time reading books. But if you do, right, there are so many fake videos that everyone can believe into, right? There is a very famous economic, you know, a journalist that all of a sudden starts selling and recommends stocks. That was fraud. It wasn't him. It was all over Instagram. And there are all sorts of, you know, manipulation. And it's very, very easy, both to create that, but also to believe that because you believe what you see. Yeah. So.
So the important thing then becomes like, what's the foundational infrastructure that we have in place, right? You know, what are the building blocks that we've got to kind of counter some of this and detect against it, right? And the good news is that our IAM platforms can already deal with a variety of threats like what we see on the screen here, right? Even when those threats have been enhanced with AI and they can be effective, you know, effective when it's both humans and AI that are at the end of the line, right? When AI is being used to make the attack better or more believable. Okay.
So, you know, AI in this regard becomes this force for good because it can recognize the unknown, unknown threats, unknown behaviors, right? And we can expect these threat protection tools to get better over time, you know, to continue to evolve, to make them better at detecting deepfakes like what we've just seen before, right? Okay.
But, you know, we've seen this change then with the arrival of AI agents now, okay? So, the world continues to evolve.
So, AI isn't just about making or stopping threats, right? So, we need to rethink our approach to identity and there's this, our approach to non-human users, apologies, and there's an inherent, excuse me, identity problem in that.
So, you know, formerly we would basically think that all non-human users were bad actors, right? And then that we would prevent these from interacting with our states, okay? There may be some exceptions, you know, we had web crawlers and so on, like good neutral agents, right? But apart from that, if we had an automated bot who was trying to log into our systems, we expected that that was some kind of attack, right?
So, the world's kind of changed and now non-human users can come in many different forms, right? So, now we can see adversarial AI, but we can also see AI agents that will be helpful, right?
And so, these agents are going to have this transformative impact across our enterprise estates, across our businesses, across the way that we interact, like Ayelet was describing that scenario earlier on, okay? So, you know, unlike adversarial AI, we're going to have to allow and support these as opposed to blocking them, right? But we need to be appropriately in control of what they can do.
So, again, this is coming back to our identity landscape. So, the key for us is going to be identifying these non-human users when they arrive. Are they familiar? Have we seen them before? Are they bad actors or are they digital workers? And how can we tell the difference between these adversarial and helpful AI agents when they hit our systems, right?
So, what we're starting to talk about here is IAM for AI agents, okay? And obviously, that's like a theme that we're seeing come through in this session today, but really through the conference as a whole.
I think, you know, the challenge is that most of our IAM frameworks today are designed to authenticate and authorize human users, not autonomous AI-driven entities, right? So, our traditional access management methods will fall short when applied to agents, right? We support a variety of access patterns today. We onboard, we off-board employees. We have to deal with delegation and approval flows and handle a variety of different entitlement management scenarios.
However, you know, what we're going to see is that agents are going to augment the workforce and assist consumers and the scale is going to go exponential, right? In part, this will be because of the relationships involved, but it's also just the number of identities.
So, we're no longer just consumers, employees, third-party business partners. We're AI agents, agent teams, operators, right?
So, effective IAM is going to be who can scale and remain cost-effective, okay? All right.
So, very briefly, what will that IAM infrastructure need to support? Here's another quick video that we've got, right, that's just showing a simple, a very simple agent, the simplest agent that we can imagine, right? This is an agent offered by a retail organization helping someone purchase a TV, okay?
So, we're just asking, the agent is asking, do you know anything about me? Don't have access to personal information around you, right? I'm looking for a TV, right? We're going to ask some questions about that, okay? And ultimately, then we're going to log in. We'll show that, excuse me, the system prompts the user to log in. We get some consent on behalf of the user and we get some information about the user, who they are, their address, and we can streamline the overall process, right?
You know, we're again guiding the user towards the destination, right? But there's some interesting aspects that go along with that, right? When we think about the world, the sort of agentic world that we're going to start living in, okay, we can think about whether we are delegating control to an agent, so whether an agent is acting on behalf of us. In this scenario here, this agent is acting on behalf of us, but then we're also going to have autonomous agents. So maybe in a workforce scenario, we're going to have agents that are acting under their own identity, right?
So we've got some attributes of these agents that are starting to come through here, okay? There we go. Great. Bought a nice TV, shipped it to me.
So, you know... Can I just jump? This is not theory. This demo is something that we build because we're working with a customer that want to build an AI agent, right? So it's not theory. It is happening right now. We're working with customers that are reaching out to us as an IAM vendor. I have a new identity, and I need to handle that. So it's not theory. It is happening. Sorry.
No, no. Please. Thank you. All right. So in that scenario, right, that agent was acting on behalf of the user.
But, you know, as we see down in the lower side, it can also... We will have other scenarios where the agent is acting under its own identity. Our infrastructure needs to support that, right? We're going to have, you know, differences in supervision.
So, again, in that top scenario, what we just saw, that agent was attended, and we had a human user interacting with that agent. We'll also have unattended agents, right? And then different forms of agents interacting with our estate, okay? We may have managed agents that we are, again, in a workforce scenario. We're provisioning across our own estate and into our own infrastructure. Or we'll have unmanaged bring-your-own-agent-type scenarios.
You know, think about the chat GPTs, the operators, these kinds of scenarios, okay? So we need to make sense of the different types of agents that are going to interact with our estate, and then we can start to think about what we do about that, right? So what that starts pointing towards is this identity landscape for AI agents, okay? We need to know our agents so that we can track and classify them, assign owners, manage their life cycle, provision them, deprovision them when needed.
We need mechanisms to detect our agents, so to recognize when they're active, how we can distinguish them and apply controls like privileges or step-off authentication at appropriate times. We need controls so that we can use delegation rather than impersonation, right? So by that, I mean that we can delegate some controls as opposed to handing over our usernames and passwords or using long-lived service accounts into that kind of scenario, right? We need to authorize our agents carefully so that we adopt principles of least privilege, short-lived tokens, and so on.
And then ultimately, in many of these scenarios, we're going to need to have mechanisms to verify humans for sensitive actions, right? So we can bring the human into the loop as we saw in that previous video there where we had the user provide consent, okay? So I think the final piece, and then I'll hand back to Ailet, right, is just that, you know, that previous slide was really talking around the infrastructure changes, okay? So these are the things that our IAM infrastructure is going to need to handle going forward at scale.
We're also going to have this policy framework that wraps around it, right? So how we adapt to threats that are going to emerge and surface faster than our IC teams today can handle, right? Zero trust will come into sharper focus as we need to continuously verify every request, like as we saw in that previous presentation today. We're going to have these notions of ephemeral access, so just in time, just enough access, and wrapped around all of this will be the lifecycle management of these agents kind of at a scale that we've not seen before.
Yeah, so how do we approach this change? What is our strategy? How do we look at the, you know, what is happening out there, and how do we approach it? So we think about it as you need to trust every moment. So it's not an isolated trust check. It's not just a login, but it is looking at that in a way more holistic way, and it is how do you trust every digital moment? So if in the past, right, trust was implicit, right? So it was assuming you had your credentials, you know your username, you know your password, maybe some more advancement. We assume it is you, and we let you go.
We build the trust, and everything was okay. As the world is shifting to this complex, right?
Well, it was complex in the past, but way more complex. We look at that as explicit trust. You need to make sure, you cannot just imply, you need to make sure that you are interacting with IELTS, and it's not just on the login. It is not just in one point in the journey. It needs to be consistent. It needs to be every moment. It's not just to ensure that this is the credentials, but it's really the identity. That's how we look at that, and by the way, let me go back. We talked about all the changes that are happening at once.
It is not just me against the organization or the brand, but it's also peer-to-peer trust. So maybe I'm purchasing something from someone else. Maybe I see someone posting something, right?
So, the trust is not just between me and the organization, but between two people. So, the concept is verified trust. Trusting every moment. Not just rely on implicit trust, but literally verify that you're talking to the right person, ensuring the security, the assurance level is right, and no identity fraud. And when we look at that in a holistic way, we get to the verified trust.
So, it is verify the onboarding every moment, the access, verify self-service, reset the account, and make sure that the user is authorized to what they do. And the idea is if you don't rely on authentication per se, like implicit trust, but you need to verify the trust, this is where we kind of take all the pieces of technologies that we have. Identity verification, face biometrics, authentication, security layer, protection against fraud, authorization. We take all that, we mix that together, and kind of closing the gap between authentication and verification.
Closing the gap between user experience that you anticipate when you authenticate. So, we take the verification and merge it into the authentication journey to make it as frictionless as authentication. We layered it with security. We work on making it as frictionless and user experience-wise and secure-wise. We build a holistic approach so you can literally verify every moment and trust every moment. Yeah? We're actually over time a little. Over time. That's what we do. We take all the pieces of technology that we have, mix it together to help our customers address all those challenges.
If you want to talk more, because we're running out of time, we're at the booth and we'll be happy to chat. Thanks, guys. Really appreciate that.