AI Agent Security: Why Identity and Access Control Matter More Than Guardrails

AI Agent Security: Why Identity and Access Control Matter More Than Guardrails

What happens when an AI agent is compromised, manipulated, or simply does something nobody expected, but already has permission to access your most sensitive systems?

In this episode of Tech Talks Daily, I speak with Geoffrey Mattson, CEO of SecureAuth, about why securing enterprise AI requires businesses to think beyond protecting models and start paying much closer attention to identity, authorization, access control, and what AI agents are actually allowed to do.

Geoffrey argues that AI agents present a different security challenge from traditional software. Conventional applications can be tested against relatively predictable behavior. AI models are far less deterministic, particularly when prompt injection, excessive permissions, unexpected behavior, and autonomous actions enter the equation.

His advice is to assume an agent could behave unpredictably and control what happens when it attempts to access a database, execute a financial transaction, call an API, or interact with another business system.

We discuss what this means as companies race to introduce agentic AI. Geoffrey shares examples of employees granting AI tools permissions without fully understanding what they have approved, along with agents gathering information that creates unexpected privacy and compliance problems.

This creates a difficult challenge for CIOs and CISOs. Boards want AI adoption because of its potential competitive value, while employees increasingly depend on AI tools to do their jobs. Simply blocking agents is unlikely to work. Security teams instead need mechanisms that allow innovation while controlling what those agents can access.

Geoffrey explains why Zero Trust becomes particularly relevant here. Rather than authenticating a user or agent once and assuming it remains trustworthy, enterprises need to continually evaluate whether an action should be permitted at that specific moment.

This leads to the concept of continuous authorization. Geoffrey explains how identity security is moving from asking "Who are you?" toward understanding intent, behavior, context, and authority for individual actions. This becomes increasingly important when one AI agent can create sub-agents, which can then create additional agents and pass permissions down the chain.

We also discuss why agentic AI is exposing years of accumulated security debt. Many of the underlying problems are familiar: excessive privileges, inconsistent access controls, incomplete Zero Trust implementations, and systems that trust identities for too long. AI agents amplify those weaknesses because they can operate at machine speed.

Geoffrey describes this as combining the unpredictability of humans with the power of machines.

For CIOs, CISOs, security architects, identity teams, and business leaders deploying agentic AI, this conversation offers practical questions to ask before connecting agents to enterprise resources. What can the agent access? What authority does it have? Can that authority be reduced as tasks are delegated? Is every important action evaluated independently? And can access be revoked immediately when behavior changes?

The goal is not to prevent organizations from using AI agents. It is to create a security layer that gives developers and employees room to experiment while ensuring agents only have the authority they need at the moment they need it.

As autonomous AI becomes part of the enterprise workforce, identity alone may no longer be enough. Businesses increasingly need to understand intent, control authority, and continuously decide whether the next action should be allowed.

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(2000)

Is Your Network Holding Back Your AI? Kentik CEO Avi Freedman on AI Infrastructure

Is Your Network Holding Back Your AI? Kentik CEO Avi Freedman on AI Infrastructure

Companies are spending billions on GPUs, data centers, foundation models, and AI infrastructure. But what happens when the network connecting all of it cannot keep up? In this episode of Tech Talks Da...

10 Aug 22min

What Clarecast Data Reveals About AI and Quiet Restructuring

What Clarecast Data Reveals About AI and Quiet Restructuring

Is AI really causing widespread job losses, or are a small number of announcements creating a much larger narrative? In this episode of Tech Talks Daily, I speak with Marvin Pohl, chief data scientist...

9 Aug 33min

Creating a Coordination Layer for AI Agents With Blue Language Labs

Creating a Coordination Layer for AI Agents With Blue Language Labs

What happens when an AI agent is authorized to make a payment, but nobody can verify the wider agreement behind it? In this episode of Tech Talks Daily, I speak with Zor Gorelov of Blue Language Labs ...

8 Aug 27min

Scaling Embedded Finance Around Customer Value With Zip Co

Scaling Embedded Finance Around Customer Value With Zip Co

What separates an embedded finance partnership that changes customer behavior from an integration nobody would miss? In this episode of Tech Talks Daily, I speak with Rory Herriman, Chief Technology O...

7 Aug 24min

Building Creator Trust Through Better Payments With Tipalti

Building Creator Trust Through Better Payments With Tipalti

What happens to creator loyalty when somebody delivers the work, attracts an audience, and then waits weeks to be paid? In this episode of Tech Talks Daily, I speak with Rob Israch, President at Tipal...

6 Aug 26min

Building Reliable AI Agents With Knowledge Gardens and MongoDB

Building Reliable AI Agents With Knowledge Gardens and MongoDB

What happens when an enterprise AI agent can retrieve thousands of data points but cannot understand the customer, decision, or business moment in front of it? In this episode of Tech Talks Daily, I w...

5 Aug 33min

Turning Warehouse Blind Spots Into Real Time Intelligence With Dexory

Turning Warehouse Blind Spots Into Real Time Intelligence With Dexory

What happens when a warehouse management system believes stock is present, but nobody can find it on the warehouse floor? In this episode of Tech Talks Daily, I speak with Oana Jinga, co-founder of De...

4 Aug 28min

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
forklart
popradet
stopp-verden
fotballpodden-2
rss-gukild-johaug
nokon-ma-ga
hanna-de-heldige
det-store-bildet
dine-penger-pengeradet
rss-ness
e24-podden
lydartikler-fra-aftenposten
aftenbla-bla
frokostshowet-pa-p5
aftenpodden-usa
oppdatert
grasoner-den-nye-kalde-krigen
rss-borsmorgen-okonominyhetene