Session

Non-Human Identity Crisis: AI Agents as Unaccountable Actors in Enterprise Security

Abstract:
As AI agents become embedded in enterprise systems, they are increasingly performing actions traditionally associated with human users and service accounts—accessing data, invoking APIs, and executing workflows. However, these agents do not fit cleanly into existing identity and access management (IAM) models, creating a fundamental gap in how organizations enforce accountability, authorization, and auditability.

This talk introduces the concept of the “non-human identity crisis” in AI agents, where autonomous systems operate with delegated authority but without clear identity boundaries. We explore how AI agents blur the line between user intent and system execution, leading to ambiguous ownership of actions and breakdowns in traditional security controls.

Through practical scenarios, we demonstrate how AI agents leverage shared credentials, inherited permissions, and implicit trust to perform actions that cannot be easily attributed or governed. These challenges impact core security functions, including access control enforcement, audit logging, incident response, and compliance reporting.

The session analyzes how existing IAM frameworks—designed for humans and deterministic services—fail to address the dynamic and context-driven behavior of AI agents. We highlight gaps in identity propagation, session context, and authorization enforcement when decision-making is delegated to LLM-driven systems.

To address these challenges, we propose a set of design principles for managing AI agents as first-class identities. This includes binding user context to agent actions, enforcing explicit authorization at execution points, and enhancing audit trails to capture intent, decision flow, and action outcomes.

This talk provides a new lens for understanding AI agent security—not just as an application risk, but as a fundamental identity and trust problem that requires rethinking how enterprises model and secure non-human actors.

Key Takeaways:

1. Why AI agents do not fit into existing IAM and identity models
2. How lack of identity boundaries creates security and audit gaps
3. Challenges in attributing actions and enforcing accountability
4. Impact on compliance, logging, and incident response
5. Design principles for managing AI agents as secure, auditable identities

Session Format:
Technical and architectural deep dive with real-world scenarios.

Niladri Sekhar Hore

F50 - Lead Engineer - Threat Detection & Applied Intelligence (AI / ML)

Bengaluru, India

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top