Amir is CEO of aizome, which he co-founded earlier this year. Prior to that Amir was the CEO of AxoniusX, an innovation business unit of Axonius, where he led the launch of the Axonius SaaS Management product in the SSPM domain, and the Axonius Identities product in the IVIP domain. Amir was also CEO of Alcide, Kubernetes security company acquired by Rapid7, and before that the CEO of CyberInt, Threat Intelligece company, which was acquired by Checkpoint. Amir is an angel investor and former board member in a few cybersecurity startups, including Seraphic (acquired by Crowdstrike) and Zecops (acquired by Jamf). Amir also held various roles as VP at Amdocs, including Chief of Staff to the CEO, and VP CBE for the Singtel Group account.
He received his MBA from INSEAD (J06), and has BSc (Cum Laude, Dean’s List) in Industrial Engineering and Management from the Technion – Israel Institute of Technology.
Making Enterprise AI Agents Accountable – Amir Ofek – IDV26 #1
Organizations looking to unlock the power of Enterprise AI Agents, and in a controled and safe way at the speed of AI. Identity is at the heart of it. However, NHI Governance Is Not Enough for Enterprise AI Agents. The identity industry has responded to the rise of AI agents the same way it responds to every new identity challenge: extend existing frameworks. Map agents to human owners. Enforce least privilege. Govern them like non-human identities. It is a reasonable instinct. It is also insufficient in ways that matter enormously. Non-human identity security was built for a deterministic world – service accounts, API keys, bots. These identities do what they are configured to do. Their beh...
This episode is sponsored by
Full Segment Notes
Organizations looking to unlock the power of Enterprise AI Agents, and in a controled and safe way at the speed of AI. Identity is at the heart of it.
However, NHI Governance Is Not Enough for Enterprise AI Agents.The identity industry has responded to the rise of AI agents the same way it responds to every new identity challenge: extend existing frameworks. Map agents to human owners. Enforce least privilege. Govern them like non-human identities.It is a reasonable instinct. It is also insufficient in ways that matter enormously. Non-human identity security was built for a deterministic world - service accounts, API keys, bots. These identities do what they are configured to do. Their behavior is predictable enough that static governance models work.Enterprise AI agents are categorically different. Not in degree - in kind. They don't execute fixed instructions. They reason, plan, and adapt in response to context. Their scope shifts with every task. Their behavior at runtime can diverge significantly from anything true at provisioning time. Unlike any identity that came before them, they frequently change their intent, at a pace no governance model built for human movers or machine credentials was designed to handle.Wrapping them in the same framework you use for a service account isn't wrong. It's just insufficient in precisely the places where risk accumulates.Segment Resources:https://go.sans.org/I9L8dM,
https://www.linkedin.com/pulse/all-ai-agents-born-equal-your-identity-stack-doesnt-know-difference-1vxtc/?trackingId=TOq%2BMfCbrZUSemfMR0igfQ%3D%3D,
https://www.linkedin.com/pulse/nemoclaw-got-us-here-heres-whats-still-missing-aizome-ai-ay7ne/?trackingId=gmE3crsfSFmkql3nApPWXw%3D%3D,
https://www.linkedin.com/pulse/beyond-token-why-oauth-solves-wrong-problem-enterprise-ai-agents-aenue/?trackingId=ca95KzWARoJdfWlpmHOFDg%3D%3D,
https://www.linkedin.com/feed/update/urn:li:activity:7467945864142172160/This segment is sponsored by aizome. Visit https://securityweekly.com/aizomeidv to learn more about them!
Guest
Stay in the Know, No Smoke and Mirrors – Join Our Newsletter
Get expert insights and technical breakdowns straight to your inbox.
You can skip this ad in 5 seconds







