The Security Strategist · Aug 27, 2026 · 25:39
Listen in the Podli app 🎧
Follow your favourite podcasts, listen offline and in the car with CarPlay and Android Auto, and always pick up where you left off. Free to try.
Especially as rogue AI agents are increasingly escaping safe testing environments, such as OpenAI’s rogue AI agent attacking Hugging Face, it’s now more important than ever for enterprises to implement AI agent identity governance strategies that prevent unauthorised access to their systems.
As AI agents seem to be turning into employees in enterprises, the majority of identity security strategies were never created with software that can act on its own.
As a result, a new security issue has emerged concerning AI agent identity governance and the security of non-human identities (NHI). Since enterprises are now using agents who can access data and choose tools while carrying out actions on the employee's behalf, the conventional approach of granting access once and then reviewing it later is starting to appear increasingly unsuitable.
Levent Besik, Chief Product Officer at SailPoint, believes that the solution is continuous authorisation. It means evaluating, as soon as an AI agent tries to carry out a particular action, whether it should be allowed to do so.
In the recent episode of The Security Strategist podcast, Besik joined host Nitish Deshpande, a Senior Analyst at KuppingerCole, to talk about why AI agent governance needs restrategising, starting with continuous authorisation for non-human identities. Besik said that identity had to be something that you assessed at every action rather than something that you could check simply at the door.
“The question most security leaders are asking is: Is this AI agent authorised with one-time permission?” Besik added, “It should be: Is this specific action by this agent on behalf of this human that has access to this data still authorised right now, in that very moment?”
However, it goes to show a pivot from the static provisioning time process to a continuous, real-time plane of authorisation. “Identity has to be evaluated at every action, not something you can check once at the door,” Besik said.
The change is necessary in a rapidly changing technology environment in the cybersecurity industry. In the past, human identities have been the main focus in the area of identity and access management (IAM), but the growing influence of agentic AI is quickly increasing the number of non-human identities working within enterprise environments.
Why does AI Agent Governance Need an Audit Trail?According to Besik, businesses need three basic principles: human ownership coupled with deep context, an unchangeable record of agent activity, and constant risk assessment.
A real-time ledger of all the agentic activities is what’s needed, the Saipaint Chief Product Officer notes. “An immutable record that agents cannot alter, because we've seen these agents erasing their tracks.”
It’s like "something which you would have read about in a science fiction book ten years ago is now actually taking place."
Without such an unchangeable record, enterprises run the risk of establishing what Besik refers to as "autonomy without accountability".
The other option is what SailPoint refers to as “governed autonomy.” This comes in because an agent should never have the capability to exceed the permissions of a human.
While AI agents can function on their own, they cannot go beyond the permissions granted to the human user they represent; all of their activities can be monitored, and their level of risk is constantly assessed.
For Besik, this eventually leads to a convergence of the governance of human and non-human identities.
He says that the identity, human governance and agentic NHI governance should all be brought together since each side needs the context from the other side. As enterprises go from experimenting with AI agents to putting them into use across their business-critical processes, AI agent identity governance may well serve as the link between AI autonomy and enterprise security.
Takeaways00:00 Introduction to the episode and guest
01:01 Levent's background and expertise in identity and security
02:05 Emerging challenges in AI trust and security
03:22 The impact of AI waves on enterprise security
04:21 From static to continuous trust in AI envir
Episodes: The Security Strategist