Loading Events

Executive event recap

AI Agent Identity Security: Governing Autonomous Access Across the Enterprise

A private conversation on securing AI agents, machine identities, short-lived credentials, certificate lifecycle risk, and the cryptographic changes security leaders need to prepare for.

Executive summary

Enterprises are moving from AI experimentation toward controlled deployment.

Enterprises are advancing from early AI experimentation into controlled deployment, but progress remains uneven across industries. Most organizations are still in exploratory or early production phases, prioritizing internal efficiency gains, low-risk use cases, and selective automation. Heavily regulated sectors are progressing more cautiously, balancing innovation with governance, compliance, and risk management requirements. Across industries, the immediate focus is less on transformation and more on understanding how AI fits within existing operational and security frameworks.

As adoption accelerates, the nature of risk is shifting. Initial concerns centered on securing human interaction with AI systems, but attention is now moving toward securing autonomous actions taken by agents. These systems operate at machine speed, often in non-deterministic ways, introducing challenges that traditional governance, identity, and logging frameworks were not designed to address. Runtime decision-making, dynamic authorization, and continuous validation are becoming essential as enterprises move toward agent-driven workflows.

At the same time, organizations are struggling to quantify value. While efficiency gains are widely reported, few have established reliable baselines or frameworks to measure ROI. This is compounded by the emergence of token-based cost models and the rapid proliferation of AI agents, which can scale faster than governance structures. The result is a growing need for disciplined frameworks that balance experimentation with control, enabling organizations to scale AI responsibly without introducing systemic risk.

Moderator and panel

Security, IAM, cloud, and AI leaders in the room.

A cross-functional panel spanning identity security, cybersecurity engineering, generative AI, and enterprise data science.

Moderator

Oded Hareven

Akeyless

Oded Hareven

Co-Founder & CEO

in

Speaker

Quiessence Phillips

Kroll

Quiessence Phillips

Head of Security Architecture and Engineering

in

Speaker

Nader Nassar

Capital One

Nader Nassar

Director of Engineering: Cybersecurity & IAM

in

Speaker

Jimmy Kaw

AWS

Jimmy Kaw

Partner Strategist, Generative AI Innovation Center

in

Speaker

Pradeep Jeyachandran

Bill

Pradeep Jeyachandran

Senior Data Science Manager

in

Key themes

How enterprise AI risk and operating models are changing.

The discussion focused on uneven AI maturity, the shift toward autonomous-agent risk, runtime governance, ROI measurement, and the rapid growth of agent ecosystems.

01

Early-stage adoption with uneven maturity

Most enterprises remain in experimental phases, prioritizing internal productivity and low-risk use cases rather than full-scale transformation.

02

Shift from human-to-AI security to agent-to-system security

Risk focus is moving toward securing autonomous agent actions and their interactions with enterprise systems.

03

Runtime governance as a new requirement

Traditional design-time controls are insufficient, requiring real-time enforcement of security, authorization, and validation.

04

Lack of clear ROI measurement frameworks

Many organizations struggle to quantify value due to missing baselines, inconsistent metrics, and difficulty translating efficiency gains into financial outcomes.

05

Rapid proliferation of agents and operational complexity

The number of AI agents is scaling quickly, creating challenges in visibility, governance, and user adoption.

Operating principle

Governance has to move from design time to runtime.

As AI systems become more autonomous and non-deterministic, static policies alone are not enough. Enterprises need dynamic authorization, continuous validation, and controls that can evaluate agent actions as they happen.

Actionable takeaways

What enterprise leaders can do now.

The discussion translated into a practical set of controls for scaling AI while maintaining governance, measurability, and operational discipline.

Prioritize governance before scaling high-risk use cases

Deploy AI in low-risk, internal workflows first while building governance models for broader adoption.

Implement runtime authorization and validation controls

Shift from static, design-time policies to dynamic, session-based authorization and continuous validation of actions.

Adopt a layered security model for AI systems

Structure governance across data, identity, and control layers to simplify risk management and enforcement.

Establish baselines for process performance

Measure current task duration, cost, and output quality before introducing AI to enable meaningful ROI evaluation.

Frame AI value in terms of business outcomes

Move beyond time savings and define how AI contributes to revenue growth, risk reduction, or competitive advantage.

Use sandbox and staged deployment models for agents

Enable experimentation in isolated environments before promoting validated solutions to production.

Control agent sprawl through centralized visibility

Track and categorize agents to prevent duplication, unmanaged growth, and user confusion.

Enforce just-in-time access and ephemeral credentials

Reduce risk by limiting access duration and scope for both users and AI agents.

Prepare for emerging agent-based threat models

Anticipate misuse, unintended actions, and AI-driven security risks, and design controls accordingly.

Align security as an enabler, not a blocker

Embed controls into workflows so security supports innovation rather than slowing adoption.

The room

A focused peer environment for enterprise security leaders.

The dinner was designed for senior security and IAM leaders from major enterprises in the New York metro area.

5featured executive voices
NYCprivate executive dinner
Identity + AIruntime access, machine identities, cryptography
AkeylessAWSKrollCapital OneBill

From the room

The conversation behind the security strategy.