More The Secure Disclosure episodes

AI Agents Must Have Identity & Access Control w/ Johannes Keienburg thumbnail

AI Agents Must Have Identity & Access Control w/ Johannes Keienburg

Published 17 Mar 2026

Duration: 00:37:08

Autonomous AI agents, with transformative productivity potential, pose significant security, accountability, and governance challenges requiring dynamic access controls, human oversight, and industry-wide standards to ensure safe and regulated integration.

Episode Description

AI agents are here, and theyre already transforming how we work. But beneath the hype lies a massive, unsolved security problem.In this episode, Macke...

Overview

The podcast explores the rapid emergence of autonomous AI agents, likening their current development to a "Wild West" scenario due to a lack of established norms or regulations. It highlights parallels to past technological revolutions, emphasizing the transformative potential of AI agents while addressing significant challenges, including security risks, accountability gaps, and insufficient governance frameworks. Autonomous agents pose threats due to their ability to access systems with broad permissions, operate without personal accountability, and execute actions at machine speed, often beyond human oversight. The discussion underscores the complexity of securing these agents, particularly in managing access rights, which are already a critical issue in cybersecurity (e.g., OWASPs top concern: broken access control). Current systems struggle to enforce "least privilege" principles for AI agents, which interact with multiple systems autonomously, exacerbating authorization challenges.

While the podcast acknowledges the excitement around AIs potential to revolutionize productivitysuch as streamlining workflows and enhancing efficiencyit cautions against uncontrolled adoption. Risks include agents performing unintended or harmful actions, like data deletion or unauthorized access, due to static, overly broad permissions. The conversation critiques existing solutions like LLM-based guardrails as inadequate, stressing the need for dynamic, job-specific access controls and human oversight to manage agent activities responsibly. Proposals include implementing time-bound, task-specific permissions via a "separated access gateway" and prioritizing cross-industry standards to mitigate risks. The text concludes that while AI agents could unlock significant productivity gains, their safe integration hinges on developing robust authorization systems, fostering collaboration, and balancing innovation with security safeguards to prevent misuse.

Recent Episodes of The Secure Disclosure

6 May 2026 AI Panic is Driving Shadow IT w/ Noora Ahmed-Moshe

AI's impact on employment and cybersecurity risks, driven by shadow AI, phishing, and emerging threats like prompt injection, require balancing workforce skills, security measures, and organizational trust.

29 Apr 2026 When AI Agents Change their Intent w/ Frank Vukovits

AI agents, autonomous non-human entities operating in enterprise systems without human oversight, pose security and governance challenges requiring updated access control frameworks, real-time monitoring, and intent-based governance to address risks like unauthorized access and shadow AI, paralleling historical tech challenges like Y2K.

22 Apr 2026 OWASP Top 10, Vibe Coding, and What Developers Miss w/ Tanya Janca

Gaps in cybersecurity education, persistent vulnerabilities like SQL injection, OWASP data limitations, evolving supply chain risks, high training costs, AI's contextual challenges, and the need for secure-by-design principles and collaboration highlight systemic challenges in addressing evolving cyber threats.

15 Apr 2026 The Future of Hacking is Agentic w/ Jason Haddix

Recommended: Security Testing will change, and might change quicker than this episode suggests. Keep Security Top of Mind during Development.

AI transforms security with automated penetration testing and threat detection, but requires human oversight to mitigate risks like prompt injection, ensure ethical use, and balance AI efficiency with creative problem-solving in an evolving threat landscape.

More The Secure Disclosure episodes