CISOOnline

Zero trust has a big AI agent problem ahead

That means agents will get a mix of “rate limits, transaction boundaries, spend and data budgets, sandboxing, approval gates for high-consequence actions, and immutable activity trails,” Wilkes says. “Most importantly, autonomous systems need quick and confident undo buttons. Type 2 decisions, where the consequences are reversible, are much safer to delegate than Type 1 decisions such as deleting production data, changing IAM policy, transferring funds, or making irreversible infrastructure changes.”

Brian Vecci, field CTO at Varonis, argues that the agent situation is worse than most believe. 

Enterprise CISOs “are woefully underprepared for NHI with their non-deterministic actions. You need to assume that identity is a woefully inadequate level of control,” Vecci says. 



Source link