Cyber SecurityAI & Technology

AI agent chaos means ‘least privilege’ security isn’t enough anymore

By Daniel Wicks, Regional Vice President, UK and Ireland, Saviynt

Privileged access management issues are changing, now that AI agents are everywhere. It’s time to rethink PAM. 

For many years now, privileged access management (PAM) has been the go-to model for CISOs desperate to protect against the risks associated with careless users, imperfect security defences, untouched root accounts and service accounts, and admins who scream for permanent access. By placing severe restrictions on who gets to access what, where and when, PAM has been a lifebuoy in the frothy waters of IT management. But I bring bad news: our halcyon days of delivering fewer standing privileges and stronger controls are being threatened by the inexorable rise and rise of AI agents. 

AI-delegated power is the problem 

Houston, we have a problem. AI agents are replicating like rabbits and SecOps teams are struggling to cope with their ascent to power. 

Saviynt recently surveyed 200 CISOs and the results, to say the least, were not pretty. We found that the large majority (86%) don’t enforce policies for the tide of AI identities. We discovered that fewer than a fifth (17%) govern even half their AI identities. And hardly anybody (5%) feels confident they could restrict a compromised AI agent.   

We know that identity is the new currency of trust and what is happening with AI agents is a seriously dangerous new front in how we control identity. These agents are great: they do the jobs we hate, faster and without errors. They don’t take holidays or get out of bed on the wrong side. They don’t quit over not getting a promotion or a pay rise. So we give them more and more power (and privileges)… and now we have a security challenge.  

Here comes PAM (again) 

PAM has prospered because it helps govern identities and there’s no reason why it can’t successfully manage nonhuman identities in the way it has successfully managed human identities. 

We need control because AI agents today have amazing access. They can go directly to core systems, they run autonomously, operate at speeds and over time periods that humans can never match, and they often pack embedded credentials. In reality, these agents are power users who behave like senior admins. They don’t need approvals and they come out at night as well as the day, like zombies with an extra trick. 

Worse, they are often deployed outside the purview of corporate IT. Yes, Shadow IT, we see you have returned…and this time in the guise of Shadow AI. 

Visibility alone doesn’t cut it 

Many organisations use visibility metrics as evidence of their progress and ROI. But PAM depends on enforcing standing privilege, throttling post-compromise access and reducing the blast radius scope to mitigate egregious actions. But,as our survey told us, few CISOs believe they can control an AI agent that has been compromised. 

So, what we observe here is a systemic challenge. A breached identity will be able to move laterally far faster than a malicious actor could. If an AI identity is breached today, most organisations are left naked and without a shot at managing the mess.  

Going back to that poll again tells us that few have evolved to govern AI entities in the same way they govern human identities. That lack can no longer be tolerated in the AI age. PAM is great but it requires rigour and that means no free pass for admins or service accounts. If we want the power of AI agents, then we need to govern them and erect guardrails on what they access. The guardrails include all the details we put on human roles, when services can be accessed, how, and with what limitations.  

Farewell, Least Privilege 

If this article has been distressing or a worrisome read, sorry. Let’s end on a happier note. Addressing the looming AI agents crisis isn’t a case of starting over. But we know that agents today can bypass policy enforcement, sprint past approval processes and be tough to rein in once they are compromised.  

In its current form, PAM hasn’t got a grip on AI identity management. We need a return to order where PAM enforces principles for non-humans that act with autonomy. We can’t just enforce least privilege. The new best practice must be based on Zero Standing Privilege and enabling just-in-time privilege to control AI identities that run at machine speed. 

Ultimately, we need to treat privilege as an identity problem, not just an access problem. That means writing a new formula we might call ‘PAM + IGA’, for identity governance administration, to meld new, consistent policies and build accountability across identities that come from flesh and blood or binary code. The CISO role is all about bringing order: it’s time to address the scope for chaos of AI agents.  

Related Articles

Back to top button