AI & Technology

AI and legacy identity management are on a collision course

By Jim Routh, Chief Trust Officer, Saviynt, and Fellow, Institute for Critical Infrastructure Technology

Aspirations for AI represent a poor fit for traditional IAM 

CIOs at enterprises of all kinds are under pressure to capitalise on AI because technology waves and opportunities don’t come by every day. Giants like NVIDIA and Oracle are already seeking major transformations with the former planning for 50,000 employees working in tandem with 100 million AI digital assistants. Others see time-hog activities like strategic planning shrinking by 70-85%. The scope to lower the cost of doing business and drive growth is vast indeed, but there is a technological trade-off involved here. That is, the critical path for agent deployment at scale necessitates a fundamental redesign of identity security capabilities. 

The identity governance platforms and processes that most organisations depend on were designed to manage human identity access. They were predicated on human beings making decisions and those people were suitably provisioned, certified, and deprovisioned as demands changed.  

Today, that aging approach and architecture is acting as a boat anchor for the contemporary, AI-infused world. The hard consequences of this are to slow down innovation and change. Enterprises have a growing backlog of application integration projects because existing processes can’t handle non-human identities. 

That is a big blocker as AI agent identities outnumber human identities by perhaps 80 to 1 today, according to various sources, and this disproportionate ratio will only become yet more unbalanced. Some projections suggest that we could be talking about a 400:1 human:agent identity overload within just a few years, some say a much higher figure. Cloudflare CEO Matthew Prince has predicted that online AI bot traffic will surpass human traffic by 2027, while a study by Human Security suggests that has already occurred.  

Clearly, we can’t allow for AI agents and bots acting in an uncontrolled manner. So, given this parlous situation, what does the right-fit identity management architecture for organisations stuffed full of AI agents and processes look like? 

A new world order 

The old governance platforms are essentially glorified record-keeping systems that track 

transactions, grant access to specific systems, perform periodic certification checks and revoke access when it is no longer desirable. They are overseen by systems administrators and are sometimes delegated to power users for governing divisional access. 

For years now, Privileged Access Management (PAM) services have been deployed to  

provide more granular control. But time marches on and 90% of the time PAM does not control the swelling numbers of non-human identities. A confluence of trends has contributed to today’s situation with the switch to cloud and SaaS applications plus the widespread use of APIs for machine-to-machine connectivity helping the proliferation of service accounts.  

And so today we see AI agent deployment taking place, sometimes without IT sanction as ‘Shadow AI’, and continuing to grow in an ungoverned fashion, without their being discovered, recorded or managed.  

The new identity security architecture must be a data lake of entitlement attributes that let every identity (both human and non-human) be logged and risk-scored with policy applied to block specific actions while enabling others. 

This redesign of identity security will support an increase in the volume of transactions at lower cost, delighting stakeholders and bolstering the underlying concept of “least privilege” to improve resilience. Speed is maintained and costs managed by dynamic provisioning and  a layer of continuous validation applied to privileged access in real time. Effectively, this means AI agents managing AI agents and acting to enforce policy and governance guardrails. 

 The maturing of standards like the Model Context Protocol (MCP) are positive for enterprises deploying but MCP alone can’t enable agent identity registration and policy management. Identity registration-free agents increase the volume of unknown assets deployed, thereby extending the attack surface for malicious actors.  

The history of IAM governance has its roots in the 1960s when Fernando Corbató at MIT created the first password for a file-sharing system used by research scientists. He was perhaps the first identity administrator and thousands or millions have followed but we have passed the stage where human beings can handle the sheer volume of access rights needs.  

Security II: The new architectural paradigm 

The new model described in outline above takes an attribute activity pattern baseline 

for normal behaviour of an individual user, an API transaction, an AI agent and an MCP server. Measuring pattern deviation is relatively straightforward and results in a number that can be used as a risk score. Simply put, the more significant the pattern deviation, the higher the risk and the greater the likelihood that a threat actor is using compromised credentials or that an AI agent is potentially acting in a damaging way.  

Of course, there is a cost to moving to a new paradigm and way of addressing identity but CISOs can justify the implementation of the new architecture and repurposing of identity management staff through operational cost savings and, of course, increased security and governance.  

Ultimately, the desired state is one where a digital immune system responds to threats in milliseconds, delighting stakeholders and lowering overall costs – a clear ROI. A new architecture and way of thinking is needed… and it is here today. 

Related Articles

Back to top button