Podcast Episode
Who Owns an AI Agent? Rethinking Identity, Security, & Accountability

About this episode
Especially as rogue AI agents are increasingly escaping safe testing environments, such as OpenAI’s rogue AI agent attacking Hugging Face, it’s now more important than ever for enterprises to implement AI agent identity governance strategies that prevent unauthorised access to their systems.As AI agents seem to be turning into employees in enterprises, the majority of identity security strategies were never created with software that can act on its own.As a result, a new security issue has emerged concerning AI agent identity governance and the security of non-human identities (NHI). Since enterprises are now using agents who can access data and choose tools while carrying out actions on the employee's behalf, the conventional approach of granting access once and then reviewing it later is starting to appear increasingly unsuitable.Levent Besik, Chief Product Officer at SailPoint, believes that the solution is continuous authorisation. It means evaluating, as soon as an AI agent tries to carry out a particular action, whether it should be allowed to do so.In the recent episode of The Security Strategist podcast, Besik joined host Nitish Deshpande, a Senior Analyst at KuppingerCole, to talk about why AI agent governance needs restrategising, starting with continuous authorisation for non-human identities. Besik said that identity had to be something that you assessed at every action rather than something that you could check simply at the door.“The question most security leaders are asking is: Is this AI agent authorised with one-time permission?” Besik added, “It should be: Is this specific action by this agent on behalf of this human that has access to this data still authorised right now, in that very moment?”However, it goes to show a pivot from the static provisioning time process to a continuous, real-time plane of authorisation. “Identity has to be evaluated at every action, not something you can check once at the door,” Besik said. The change is necessary in a rapidly changing technology environment in the cybersecurity industry. In the past, human identities have been the main focus in the area of identity and access management (IAM), but the growing influence of agentic AI is quickly increasing the number of non-human identities working within enterprise environments.Why does AI Agent Governance Need an Audit Trail?According to Besik, businesses need three basic principles: human ownership coupled with deep context, an unchangeable record of agent activity, and constant risk assessment.A real-time ledger of all the agentic activities is what’s needed, the Saipaint Chief Product Officer notes. “An immutable record that agents cannot alter, because we've seen these agents erasing their tracks.”It’s like "something which you would have read about in a science fiction book ten years ago is now actually taking place."Without such an unchangeable record, enterprises run the risk of establishing what Besik refers to as "autonomy without accountability".The other option is what SailPoint refers to as “governed autonomy.” This comes in because an agent should never have the capability to exceed the permissions of a human.While AI agents can function on their own, they cannot go beyond the permissions granted to the human user they represent; all of their activities can be monitored, and their level of risk is constantly assessed.For Besik, this eventually leads to a convergence of the governance of human and non-human identities.He says that the identity, human governance and agentic NHI governance should all be brought together since each side needs the context from the other side. As enterprises go from experimenting with AI agents to putting them into use across their business-critical processes, AI agent identity governance may well serve as the link between AI autonomy and enterprise security.TakeawaysAI agent governance must go beyond discovery.Agents need clear human ownership and context.Authorisation should be validated continuously.AI security must cover prompts, planning/MCP actions and runtime.Human oversight should match the level of risk.Immutable logs are key to agent accountability.Human and non-human identity governance will converge.
Chapters00:00 Introduction to the episode and guest01:01 Levent's background and expertise in identity and security02:05 Emerging challenges in AI trust and security03:22 The impact of AI waves on enterprise security04:21 From static to continuous trust in AI environments07:19 Discovery as a foundation for AI governance09:15 Lifecycle management of AI agents12:39 Real-time protection and continuous authorisation16:29 Layered security model for AI agents21:35 Balancing autonomy and human oversight in AI23:46 Converging human and AI governance strategies25:37 Final thoughts and industry outlookVisit sailpoint.com for further information on AI agent governance when dealing with non-human identities (NHI). AI Agent Identity Governance, AI Agent Security, AI Agent Governance, Non-Human Identity, NHI Governance, NHI Security, Continuous Authorisation, AI Identity Security, Enterprise AI Security, Agentic AI, Autonomous AI, Identity Governance, Identity Security, IAM, AI Access Governance, Shadow AI, AI Agent Lifecycle, AI Agent Discovery, AI Agent Accountability, Runtime Authorisation, MCP Security, AI Governance, Governed Autonomy, SailPoint, KuppingerCole, Security Strategist