Indonesian Political, Business & Finance News

SailPoint: Identity Security Must Protect AI Agents and Non-Human Identities

| Source: ANTARA_ID Translated from Indonesian | Technology
SailPoint: Identity Security Must Protect AI Agents and Non-Human Identities
Image: ANTARA_ID

The development of artificial intelligence (AI) is pushing companies towards increasingly autonomous organisations. This shift means identity security management can no longer focus solely on humans, but must also encompass AI agents, machines, applications, APIs, tokens and other non-human identities.

SailPoint Senior Vice President and General Manager for Asia Pacific, Chern-Yue Boey, said non-human identities can work on behalf of humans, make decisions and execute actions at machine speed. “Companies are no longer just talking about digital transformation; they are talking about transforming their companies from automated enterprises into autonomous enterprises,” Boey said in Jakarta.

According to Boey, companies moving towards autonomous organisations need to ensure visibility across the entire digital workforce, be able to control the requests and actions of those identities, and have the capability to perform auto-remediation when inappropriate actions occur. “The fundamental control point here is identity,” he said.

He said the previously static approach to identity security needs to shift towards Adaptive Identity Security. Access, particularly for AI agents, should not be granted permanently. The concepts of Zero Standing Privilege and Just-in-Time Privilege allow AI agents to obtain access only when needed to perform a task.

SailPoint divides identity ecosystem management into three pillars: discovery, governance, and protect and remediate. At the discovery stage, companies need to identify all human and non-human identities within their digital ecosystem. Those identities must then be recorded in a registry and have clear, immutable human ownership.

On the governance aspect, companies need to ensure identities can be managed and audited, including when an AI agent passes work on to another agent, application or data. Meanwhile, protect and remediate encompasses the ability to detect anomalous actions and either halt the activity or escalate it to a human to determine the next step.

Boey also highlighted the risk of shadow AI, namely the use of AI technology that is unknown to or not authorised by the company. One risk is employees entering confidential company information into AI services without oversight. In addition, tokens and API keys used by AI agents to access applications and data can also become an attack surface.

“Identity security is no longer enough if it only looks at access to applications; it needs to extend to the data level, including the chain of relationships from humans, digital workers, agents and applications to data,” he said.

To anticipate these risks without hampering innovation, SailPoint encourages the adoption of shift-left security by integrating security aspects from the application and AI agent development stage. “Managing and controlling human identities alone is no longer enough. Securing non-human identities such as AI agents and machines is now equally important,” he said.

Boey stressed that AI agents have no morals or ethical intuition and merely execute commands to complete tasks. Therefore, companies need to ensure every digital identity can be identified, has a clear owner, and is controlled throughout its activity lifecycle.

“The core principle is simple: you can only control what you know,” he concluded.

View JSON | Print