The Non-Human & AI Identity Podcast

Ep #11 - Securing AI Agents In Runtime

47 min · 28 de may de 2026
Portada del episodio Ep #11 - Securing AI Agents In Runtime

Descripción

AI Agents Don't Have Identity — They Have Access. That's the Problem. Most security teams are still applying human and machine identity frameworks to AI agents. It won't hold. Agents with memory, tool access, and the ability to spawn sub-agents operate in a fundamentally different threat space — and the credentials sitting in that memory are a live vulnerability right now. In this episode, Oded Hareven, CEO and Co-Founder of Akeyless, breaks down why static entitlements and session tokens can't govern non-deterministic behaviour — and what a runtime authority model actually looks like in practice. What's covered: - Why credentials in agent memory aren't just a bad practice — they're game over (the Pocket OS breach shows exactly how) - The architectural shift from identity to per-action, intent-aware authorisation - How an AI gateway proxy gives you traceability, choke-point control, and ephemeral credential issuance — and why nothing else does - Agent-to-agent delegation: how OAuth-style context passing should work, how it's being done dangerously wrong, and what accountability collapse looks like - Why current IAM frameworks aren't mature enough for complex agentic architectures Essential listening for CISOs, IAM architects, platform engineers, and anyone building or governing agentic AI in production. Key Moments: Mr NHI's Human Identity In The Hot Seat 1:40 – 12:38: What makes AI agents fundamentally different from machines and humans? 13:00 – 17:00 Why credentials in agent memory are a critical security failure 17:00 – 20:00 The shift from identity to "runtime authority" — a new security paradigm 21:20 – 24:40. The AI gateway proxy — how it works as a policy engine and kill switch 24:40 – 31:30 Agent-to-agent delegation: the governance time bomb 31:40 – 37:20 Are current frameworks mature enough for complex agentic architectures? 37:20 – 39:40 Akeyless's agentic runtime authority vision and what's coming 39:40 – 42:00 Key takeaways and where to start securing AI agents today 42:00 – 45:00 Closing thoughts and Identiverse 2025 preview 45:00 – 47:00 📚 NHI Knowledge Centre: nhimg.org 🔗 Learn more about Akeyless: akeyless.io 🎟️ Non-Human & AI Identity Summit at Identiverse — June 15 Subscribe below and Follow Us On: LinkedIn - https://www.linkedin.com/company/non-human-identity-management-group Tiktok -https://www.tiktok.com/@mr_non_human_identity #cybersecurity #ai #artificialintelligence #nonhumanidentity #iam #aiagents #zerotrust #airisks #runtime #akeyless

Comentarios

0

Sé la primera persona en comentar

¡Regístrate ahora y únete a la comunidad de The Non-Human & AI Identity Podcast!

Prueba gratis

Empieza 7 días de prueba

$99 / mes después de la prueba. · Cancela cuando quieras.

  • Podcasts solo en Podimo
  • 20 horas de audiolibros al mes
  • Podcast gratuitos

Todos los episodios

78 episodios

episode Neil McGlennon is Mr NHI's Human Identity In The Hot Seat artwork

Neil McGlennon is Mr NHI's Human Identity In The Hot Seat

AI agents are evolving into powerful enterprise identities — yet most organisations still lack the governance frameworks needed to control them securely.Neil McGlennon, Global Field CTO at SailPoint, responds to 10 rapid-fire questions focused on AI identity governance, non-human identities, and the growing security risks tied to autonomous systems.As AI agents gain access to sensitive environments, the questions become harder to ignore: should they be governed like human employees or managed like software? Are businesses prioritising innovation speed over identity controls? And when an AI identity is breached, who is accountable for the consequences?🔑 Key Takeaways:• AI agents are creating a new class of identities that challenge traditional governance models• The way organisations classify AI agents impacts access control, auditing, and lifecycle governance• Many enterprises are accelerating AI adoption without fully addressing identity security risksIn this clip, Neil McGlennon explores the intersection of AI, identity governance, and enterprise security — and why organisations need to rethink how trust is established in the era of autonomous systems.#CyberSecurity #SailPoint #IdentityGovernance #AIAgents #ZeroTrust #IAM #NonHumanIdentity #IdentitySecurity

4 de jun de 202611 min
episode Michael Trites is Mr NHI's Human Identity In The Hot Seat artwork

Michael Trites is Mr NHI's Human Identity In The Hot Seat

Enterprises are deploying AI agents at machine speed — but governance and identity security aren’t keeping pace.Michael Trites, Senior VP of Global Sales at Aembit, tackles 10 fast-paced questions on the rise of AI-driven identities, the expanding NHI threat landscape, and why organisations are repeating familiar security mistakes as autonomous systems scale.Should AI agents be governed like employees with assigned accountability, or treated purely as software identities? Are security teams giving AI systems privileged access too quickly? And when an AI agent is compromised, does anyone truly own the incident response?🔑 Key Takeaways:• AI agents are becoming highly privileged non-human identities with limited oversight• Existing IAM and PAM frameworks were not designed for autonomous AI access patterns• The rush to operationalise AI is creating governance gaps that attackers are beginning to exploitIn this short-form discussion, Michael Trites shares perspectives on identity-first security, machine access governance, and why AI agents are rapidly becoming one of the biggest emerging challenges in cybersecurity.#CyberSecurity #Aembit #IdentitySecurity #NHI #AIAgents #MachineIdentity #ZeroTrust #IAM

3 de jun de 20263 min
episode Stanislas Crépin is Mr NHI's Human Identity In The Hot Seat artwork

Stanislas Crépin is Mr NHI's Human Identity In The Hot Seat

AI agents are quickly becoming one of the largest unmanaged attack surfaces in enterprise environments — and most organisations still lack the controls to secure them effectively.Stanislas Crepin, Senior Global Director Sales Engineering at GitGuardian, answers 10 rapid-fire questions on the growing identity and secrets management risks surrounding AI agents and NHIs. From access governance to accountability, this discussion highlights where organisations are falling behind as agentic AI adoption accelerates.Do AI agents require the same trust validation as employees? Are companies unknowingly exposing sensitive systems in the rush to innovate? And as machine identities multiply, are security teams losing visibility over who — or what — has privileged access?🔑 Key Takeaways:• AI agents are introducing a new wave of non-human identities that traditional security models struggle to manage• Treating AI identities like software alone creates dangerous governance blind spots• Speed-to-deployment pressures are weakening security processes across agentic AI initiativesIn this clip, Stanislas Crepin breaks down the growing overlap between AI governance, identity security, and secrets exposure — and why organisations must rethink how they secure autonomous systems.#CyberSecurity #GitGuardian #NonHumanIdentity #SecretsManagement #AIAgents #IdentitySecurity #ZeroTrust #IAM

2 de jun de 20265 min
episode David Lee is Mr NHI's Human Identity In The Hot Seat artwork

David Lee is Mr NHI's Human Identity In The Hot Seat

AI agents are scaling inside organisations faster than security teams can properly govern them — and attackers are already taking advantage of the gap.David Lee, Field CTO at Saviynt, takes on 10 rapid-fire questions around the identity risks enterprises can no longer ignore. From the growing exposure created by unmanaged NHIs to the debate over whether AI agents should be treated more like employees or software, this conversation goes straight to the governance failures security leaders are now facing.Should AI agents undergo the same scrutiny as human users before receiving access? Are organisations sacrificing security controls in the race to deploy agentic AI? And when an AI-driven identity is compromised, who actually owns the fallout?🔑 Key Takeaways:• AI agents are rapidly becoming unmanaged identities that existing IAM and PAM strategies weren’t built to secure• How organisations classify AI agents directly impacts governance, lifecycle management, auditing, and access revocation• Pressure to accelerate AI deployment is causing security oversight to slip — increasing enterprise risk exposureIn this short clip, David Lee shares sharp insights on non-human identities, AI governance, and why enterprises are repeating many of the same mistakes previously seen with machine identity sprawl.#CyberSecurity #IAM #AIAgents #ZeroTrust #IdentitySecurity #NonHumanIdentity #PrivilegedAccess #AI

1 de jun de 20264 min
episode Oded Hareven is Mr NHI's Human Identity In The Hot Seat artwork

Oded Hareven is Mr NHI's Human Identity In The Hot Seat

Treating AI agent identities the same as standard non-human identities isn't just lazy thinking — it may be the most dangerous assumption in security right now.Oded Hareven, Co-Founder and CEO of Akeyless, faces 10 rapid-fire questions on whether the industry is sleepwalking into the same governance failures it made with NHIs, only this time with autonomous agents operating at scale. Are CISOs truly ready to manage fleets of autonomous digital employees? Can zero trust even work for agents that make decisions independently? And if agentic AI identities need to be governed separately, is anyone actually building for that yet?From background checks for AI agents, to whether PAM needs a fundamental rebuild, to the question no one wants to answer — can you truly govern and control agentic AI at all — this clip covers the ground most security conversations are still avoiding.🔑 Key Takeaways:Agentic AI identities operate with a different threat profile to standard NHIs — conflating them is a governance blind spot most organisations haven't caught yetZero trust principles face a genuine stress test with autonomous agents that act, authenticate, and escalate privileges without human approval loopsThe industry is repeating the same under-governance mistakes made with machine identities — but the blast radius this time is significantly largerIn this clip, Oded Hareven, Co-Founder and CEO at Akeyless, delivers machine-speed answers on agentic identity governance, secrets management, and why the window to get this right is closing faster than most CISOs realise.From The Non-Human & AI Identity Podcast 🎙️#CyberSecurity #NonHumanIdentity #IAM #ZeroTrust #AIAgents #SecretsManagement #IdentitySecurity #shorts

29 de may de 202610 min