AI Infrastructure

AI Agents Are Breaking Enterprise Identity — Keycard’s Ian Livingstone on the Fix | TFiR

0

Enterprise security infrastructure was engineered for a world where humans made every decision. Today, AI agents are making those decisions autonomously — reasoning through tasks, calling APIs, accessing sensitive data, and taking actions across organizational boundaries, all without a human in the loop. The identity systems built to govern human behavior are not equipped to handle this shift, and the gap is creating a structural vulnerability at the heart of every enterprise AI strategy.

The problem isn’t that AI agents are untrustworthy by nature. The problem is that they inherit the full privileges of the user who launched them, operate non-deterministically, and leave security teams with no visibility into what actions were taken, on whose behalf, and with what authority. Without a new identity model purpose-built for autonomous agents, enterprises face an impossible choice: restrict agents so heavily they deliver no value, or let them run free and accept the security risk.

The Guest: Ian Livingstone, Co-Founder and CEO at Keycard

Key Takeaways

  • AI agents inherit full user privileges by default — there is no native mechanism in current IAM systems to scope agent access below the level of the delegating human
  • Consent fatigue is a real production risk: when agents prompt humans to approve every tool call, users say yes to everything, creating the conditions for accidental privilege escalation
  • Execution-time access control shifts enforcement from token issuance to the moment of action — factoring in prompt intent, agent identity, task context, and organizational policy
  • Agent identity is a new category: not human identity, not traditional workload identity — but a hybrid that is stable, delegatory, and dynamically scoped per task
  • Security and platform leaders need to look for shadow IT signals now: unusual access patterns, high-velocity user actions, and IT ticket floods are early indicators that agents are already operating without governance

***

Read Full Transcript & Technical Deep Dive

The Real AI Decision Driver Isn’t the Model — Rob Hirschfeld of RackN | TFiR

Previous article