Episode Details

Back to Episodes
Who Controls AI Agents When Software Starts Acting Alone With Oasis Security

Who Controls AI Agents When Software Starts Acting Alone With Oasis Security

Episode 53 Published 2 days, 22 hours ago
Description

What happens when software can reason like a person, move at machine speed, and use every permission it receives?

In this episode of AI at Work, I speak with Adam Ochayon, VP of Product Strategy at Oasis Security, about why autonomous AI agents create a different identity and access problem from the software businesses have secured for decades.

Adam explains that traditional software is fast but generally deterministic, while people can reason but usually act slowly enough for organizations to intervene. AI agents combine reasoning with machine speed. They are goal-seeking, capable of choosing different routes to complete a task, and likely to use any access available to them. Permissions that might remain unused by an employee can become active risk almost immediately when assigned to an agent.

We discuss why static roles are poorly suited to this behavior. An agent may need different permissions from one session or task to the next, depending on the person directing it, the data involved, its recent behavior and the action it is attempting. Adam argues for contextual authorization that can grant narrowly defined access at the right moment, monitor behavior continuously and provide a kill switch when an agent begins operating outside its approved purpose.

Ownership presents another problem. Employees can create, modify and reuse agents across several business systems. Some agents act on behalf of a person, while others receive their own autonomous access. In both cases, companies need to know who remains accountable, which credentials the agent holds, what happens when its owner leaves and how its permissions are retired.

Adam connects these questions with the wider problem of nonhuman identities, including service accounts, API keys and secrets. Companies that have not brought those identities under control may find AI adoption magnifying weaknesses that already exist. Security teams also face a delicate balance. Excessive friction encourages employees to bypass approved systems, while unrestricted access creates unacceptable exposure. Adam believes identity teams can become advisers to the business by creating controls that permit faster adoption with clearer boundaries.

We also discuss Cyera’s announced $1 billion deal to acquire Oasis Security and what the combination of data security and access governance may signal about the direction of enterprise AI security. Adam closes with a practical sequence for leaders: discover which agents exist, understand their access, assign ownership, define policies, monitor activity and enforce controls across cloud and on-premises systems.

Who owns your AI agents, and would your organization know when one moves beyond its approved purpose? Share your thoughts with me.

Listen Now

Love PodBriefly?

If you like Podbriefly.com, please consider donating to support the ongoing development.

Support Us