More The Secure Disclosure episodes

AI Agents Must Have Identity & Access Control w/ Johannes Keienburg thumbnail

AI Agents Must Have Identity & Access Control w/ Johannes Keienburg

Published 17 Mar 2026

Duration: 00:37:08

Autonomous AI agents, with transformative productivity potential, pose significant security, accountability, and governance challenges requiring dynamic access controls, human oversight, and industry-wide standards to ensure safe and regulated integration.

Episode Description

AI agents are here, and theyre already transforming how we work. But beneath the hype lies a massive, unsolved security problem.In this episode, Macke...

Overview

The podcast explores the rapid emergence of autonomous AI agents, likening their current development to a "Wild West" scenario due to a lack of established norms or regulations. It highlights parallels to past technological revolutions, emphasizing the transformative potential of AI agents while addressing significant challenges, including security risks, accountability gaps, and insufficient governance frameworks. Autonomous agents pose threats due to their ability to access systems with broad permissions, operate without personal accountability, and execute actions at machine speed, often beyond human oversight. The discussion underscores the complexity of securing these agents, particularly in managing access rights, which are already a critical issue in cybersecurity (e.g., OWASPs top concern: broken access control). Current systems struggle to enforce "least privilege" principles for AI agents, which interact with multiple systems autonomously, exacerbating authorization challenges.

While the podcast acknowledges the excitement around AIs potential to revolutionize productivitysuch as streamlining workflows and enhancing efficiencyit cautions against uncontrolled adoption. Risks include agents performing unintended or harmful actions, like data deletion or unauthorized access, due to static, overly broad permissions. The conversation critiques existing solutions like LLM-based guardrails as inadequate, stressing the need for dynamic, job-specific access controls and human oversight to manage agent activities responsibly. Proposals include implementing time-bound, task-specific permissions via a "separated access gateway" and prioritizing cross-industry standards to mitigate risks. The text concludes that while AI agents could unlock significant productivity gains, their safe integration hinges on developing robust authorization systems, fostering collaboration, and balancing innovation with security safeguards to prevent misuse.

Recent Episodes of The Secure Disclosure

14 Jul 2026 How to Stop Supply Chain Attacks Without Destroying Developer Productivity

"Cybersecurity threats, especially supply chain attacks on developers and open-source packages, demand balanced mitigation strategies, AI-driven security challenges, and early integration of security in development, with collaboration and adaptability key to addressing evolving risks."

1 Jul 2026 Solving the Supply Chain Security & Malware Crisis w/John Amaral

Escalating software supply chain threats target open-source ecosystems through credential exploitation, AI-fueled malware, and upstream compromises, with challenges in dependency management and outdated libraries driving AI-driven remediation strategies like automated patching and version pinning, though human oversight remains critical for validating fixes.

16 Jun 2026 Your Microphone Became a Keylogger w/ David vonThenen

Machine learning analyzes keystroke acoustic signatures to infer typed characters over remote platforms, highlighting high accuracy with known keyboards, privacy risks from surveillance, and challenges in noise and variability, while proposing defenses and noting AI's dual-use implications.

More The Secure Disclosure episodes