Cisco / Matt Caulfield
Agentic AI promises to transform business strategy from the ground up. But it also poses a serious challenge to IT leaders. You don’t want to slow your teams down in experimenting with autonomous agents and miss a competitive window for productivity and revenue gains. At the same time, you’re navigating a technology that evolves from week to week and, at a scale many can’t even fathom, could be putting your systems at risk.
“Somewhere in your environment right now, an AI agent is almost certainly operating without a proper identity, a defined owner, or any meaningful access controls,” Cisco VP of Product for Identity Matt Caulfield, who leads the team behind Duo Agentic Identity, told ZDNET in an email. “Developers are already connecting these agents to production systems without looping in IT, and that is a massive security blind spot.”
Harnessing what agentic AI can do, without absorbing risk most organizations can’t yet quantify, is crucial for long-term strategy. This means rethinking identity management for your enterprise and reimagining what’s possible.
Traditional identity management stretched to the breaking point
AI agents are autonomous actors, capable of querying databases, triggering workflows, sending communications, and making decisions on their own, at machine speed, sometimes with the option to forgo human permission or intervention. That autonomy is precisely what breaks the assumptions built into nearly every identity and access management system currently in use.
A traditional human identity is defined once, at onboarding, and updated every so often after that. An autonomous agent, by contrast, often inherits whatever credentials happen to be sitting in the context it’s running in, which can provide it extremely course-grained access to whatever action it decides to take.
The tools built to manage non-human identity before agentic AI existed weren’t built for this, either. “Those tools were designed around service accounts and API keys. In other words, predictable, static entities,” Caulfield says. “They were never built for the kind of per-action, per-session enforcement that an autonomous agent demands. The result is a gap that’s widening every quarter: Businesses are adopting agents faster than IT can figure out how to govern them.”
Adapting Zero Trust for the agentic era
This architectural mismatch seemingly leaves organizations with an uncomfortable choice: deploy agents at the speed the business wants and accept risk that’s difficult to even measure, or hold agents back and watch competitors capture market advantages that won’t wait around. But Caulfield said he doesn’t think that’s actually the choice.
... continue reading