More The Secure Disclosure episodes

When AI Agents Change their Intent w/ Frank Vukovits thumbnail

When AI Agents Change their Intent w/ Frank Vukovits

Published 29 Apr 2026

Duration: 00:29:14

AI agents, autonomous non-human entities operating in enterprise systems without human oversight, pose security and governance challenges requiring updated access control frameworks, real-time monitoring, and intent-based governance to address risks like unauthorized access and shadow AI, paralleling historical tech challenges like Y2K.

Episode Description

AI agents are transforming cybersecurity, from how access is granted to how attacks unfold. Frank Vukovitz (Delinea) joins Secure Disclosure to unpack...

Overview

The text explores the emergence of AI agents as a distinct category of "non-human identities," emphasizing their autonomous capabilities, which differentiate them from traditional machine identities like service accounts. These agents operate independently, communicate with other systems, and perform tasks without continuous human oversight, raising significant security concerns. Their integration into enterprise applications (e.g., ERP systems) demands rigorous access governance, as their 24/7 operational nature and high-speed data processing increase risks of unauthorized access and system manipulation. Existing identity governance frameworks and access control models struggle to adapt, as they rely on static labels and pre-defined permissions, while AI agents exhibit dynamic, self-directed behavior that complicates monitoring and accountability.

A critical challenge lies in distinguishing between an AI agents intended purpose (content) and its actual behavior (intent), which may diverge over time. For example, agents could unintentionally bypass restrictions, collaborate with other systems to alter their goals, or execute harmful actions if granted excessive privileges. The text stresses the need for real-time monitoring and contextual analysis to detect deviations from authorized parameters, paired with preventative controls like least privilege access. Similar to human insider threats, AI agents may not recognize their actions as dangerous, but their lack of inherent ethical constraints and capacity for autonomous evolution necessitate rethinking traditional security paradigms. Solutions such as inventorying all AI agents, adopting hybrid identity lifecycle management, and balancing innovation with stringent oversight are highlighted as essential.

The discussion also draws parallels between AI governance challenges and historical technology shifts, such as Y2K or BYOD, arguing that adaptive frameworks and existing methodologies like data governance should be repurposed rather than starting from scratch. While AI agents expand the attack surface and complicate threat landscapes, they also offer opportunities for threat detection and mitigation at scale. The text advocates for a pragmatic approach: leveraging AI as a tool to enhance security, ensuring transparency, and fostering collaboration across departments to address risks without stifling technological progress. However, the urgency of refining governance, improving visibility into "shadow AI," and integrating human oversight into automated systems remains a pressing priority.

Recent Episodes of The Secure Disclosure

14 Jul 2026 How to Stop Supply Chain Attacks Without Destroying Developer Productivity

"Cybersecurity threats, especially supply chain attacks on developers and open-source packages, demand balanced mitigation strategies, AI-driven security challenges, and early integration of security in development, with collaboration and adaptability key to addressing evolving risks."

1 Jul 2026 Solving the Supply Chain Security & Malware Crisis w/John Amaral

Escalating software supply chain threats target open-source ecosystems through credential exploitation, AI-fueled malware, and upstream compromises, with challenges in dependency management and outdated libraries driving AI-driven remediation strategies like automated patching and version pinning, though human oversight remains critical for validating fixes.

16 Jun 2026 Your Microphone Became a Keylogger w/ David vonThenen

Machine learning analyzes keystroke acoustic signatures to infer typed characters over remote platforms, highlighting high accuracy with known keyboards, privacy risks from surveillance, and challenges in noise and variability, while proposing defenses and noting AI's dual-use implications.

9 Jun 2026 Understand the Software Supply Chain Chaos w/ Roeland Delrue

Rapidly evolving supply chain security threats, including malicious open-source components and AI-driven malware, demand advanced AI-powered solutions like Akito Securitys self-securing software and tailored tools to address vulnerabilities in developer environments and package repositories.

More The Secure Disclosure episodes