Session

Agents with Authority: Governing AI-Driven Non-Human Identities Across Hybrid Enterprise Attack Path

Autonomous AI agents are no longer experimental. They negotiate API calls, execute multi-step workflows, request delegated permissions, and persist OAuth tokens across enterprise environments all without human oversight at the transaction level. In identity governance terms, they are non-human identities (NHIs) with dynamic, context-driven authority. The problem is structural: our identity frameworks were built for human principals and static service accounts. They were not designed to govern systems that reason, adapt, and propagate privilege.

This session maps AI agents as identity nodes within hybrid attack graphs spanning Active Directory, Entra ID, and SaaS platforms. Drawing from investigative workflows converted into defensive playbooks, the presentation demonstrates how autonomous agents expand attack surfaces through three realistic vectors: prompt injection attacks that redirect agent behaviour while preserving token legitimacy; API abuse chains that exploit over-permissioned service principals; and lateral movement patterns invisible to conventional SIEM correlation rules because no human credential was misused.

Three enterprise case studies, a Frankfurt bank treasury exfiltration, a German manufacturer HR agent breach, and a law firm SaaS OAuth takeover ground the threat model in operational reality. The session introduces the ARIA Framework (Autonomous Risk and Identity Architecture), a governance model addressing privilege lifecycle management, behavioural baselining, decision-chain logging, and audit trail requirements aligned with GDPR and EU AI Act obligations.

Attendees leave with a structured governance posture, a threat model template, and three specific CISO-level actions implementable within existing IAM and PAM programmes with no new tooling required for the first two.

Atharv Tiwari

COO Nevis Info Systems, Security Trainer, Cyber Crime Researcher,

New Delhi, India

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top