Managing AI Agents as Privileged Identities in Enterprise Systems
As AI agents increasingly access enterprise systems, data, and privileged networks, identity management teams face a critical challenge: how to govern autonomous, machine-speed identities. In a recent discussion, Melissa Carvalho of Royal Bank of Canada and Gaurav Sharma of Ping Identity explored how AI agents are transforming identity governance, privileged access, and accountability.
Carvalho emphasized the need to redefine privilege and manage access for AI agents differently. Organizations must identify existing agents, determine ownership, and assess their access rights. The National Institute of Standards and Technology (NIST) is now focusing on AI agent identity and authorization, highlighting the urgency of this issue.
The conversation covered key topics, including new approaches to privileged access and least-privilege controls for AI agents. Experts also discussed how to discover 'shadow agents', unauthorized or unmanaged AI entities, and prioritize controls based on potential security risks. Continuous monitoring, runtime authorization, and rapid containment were identified as essential strategies as AI agents gain more autonomy.
This discussion is part of the ongoing 'Proof of Concept' series, which previously covered crisis response and breach aftermath management.