Identity, AI/ML, Application security, Governance, Risk and Compliance

From autonomous agent to trusted worker: Building identity and accountability for AI agents

Robots And Humans as AI or Artificial Intelligence facing off as a symbol of future technology and employment or unemployment as automation in society changing the global economy.

AI agents derive much of their value from their autonomy. They can reason through problems, chain API calls, interact with multiple systems and adapt their own actions without requiring human approval at every step.

Yet those capabilities also make AI agents difficult to trust. Traditional identity and access management (IAM) assumes that users or applications, especially regular non-human identities (NHIs), will behave within relatively predictable boundaries.

AI agents cannot be governed by such processes because they make probabilistic decisions and pursue dynamic, multi-step tasks. The agents' unpredictability is both a bonus and a danger.

Likewise, restricting agents until they can barely do anything defeats their productivity benefits. A better approach is for organizations to transform autonomous agents into trusted digital workers by implementing zero-trust principles.

In that way, the organizations can establish "who" each agent is, continuously evaluate what each agent is attempting to do, and preserve human accountability without requiring humans to supervise every routine action.

Why each AI agent needs a pre-defined identity, owner, and purpose

Zero trust begins with identity. Accordingly, every AI agent should receive a unique, stable identifier tied to an accountable person or team, as well as an authorized purpose, an operational scope, a list of systems it is permitted to access, and an expected lifetime.

Without such a foundation, an AI agent runs the risk of becoming a shadow resource outside normal governance.

Credentials assigned to AI agents should likewise be short-lived and dynamically issued for individual sessions or tasks instead of being persistent secrets that can be stolen or abused. Implementing automated rotation and revocation of credentials can provide agents with necessary access while limiting the blast radius if an agent is compromised.

Identity policies based on zero-trust principles lay the foundation for productive autonomy, which lets an organization know which agent is acting, for whom it's acting, and within what boundaries.

Why trust must be enforced dynamically at runtime using context and policies

By itself, just having an assigned, defined identity does not make an agent trustworthy. Because agent behavior can vary with each task, authorization needs to conform to the zero-trust principle of continuously evaluating access rather than assuming previous authentication is sufficient.

In other words, it's better to closely and continuously monitor what an AI agent is doing than to give it static credentials and send it on its way.

In a recent white paper sponsored by Ping Identity, Martin Kuppinger of KuppingerCole argues that policy-based access control (PBAC), as opposed to role-based access control (RBAC), is the best solution for evaluating risk factors, including data sensitivity, current threat levels, task scope and degree of agent autonomy, whenever an agent attempts an action.

Using PBAC, a routine read request against a low-risk system might be allowed to proceed automatically. An attempt to modify financial records would require additional checks or human approval.

"Authorization decisions for AI agents should reflect the nature of the operation being performed," writes Kuppinger. "Defining these tiers explicitly, rather than assigning a single set of permissions to all agents, limits the potential damage from a misbehaving or compromised agent."

This best-of-both-worlds approach avoids the two extremes of either blindly trusting agents or requiring constant human intervention. High-risk actions will require human-in-the-loop approval; routine, well-understood operations can run autonomously under human supervision.

How to provide accountability and containment to manage trusted digital workers

Trusted digital workers also need accountability. Every API call, data access and decisive action should be recorded in immutable logs that capture not only what happened, but what the agent was told to do and why. These decision logs will make investigations and compliance reviews more meaningful.

"Regulators and auditors increasingly expect organizations to explain decisions made by automated systems," notes Kuppinger. "Explainability is not just a technical feature; it is a legal and reputational risk-management requirement."

Controls should also exist beyond the AI agent. APIs and resources must independently enforce access policies rather than trusting an AI agent's stated permissions. For agents with production access, organizations should build in a kill switch that can instantly suspend or terminate activity.

"The ability to stop an agent quickly is a basic operational requirement, not an advanced feature," writes Kuppinger.

Deploying zero trust does not prevent AI agents from acting autonomously. Properly implemented, zero trust in fact makes greater autonomy possible.

By giving every agent an identity and an owner, enforcing contextual authorization at runtime, maintaining least privilege, and recording decision trails, organizations can let agents have substantial operational freedom within enforceable boundaries.

The result is neither an anarchic autonomous agent running wild nor an overcontrolled subservient assistant that asks for approval at every turn.

Instead, an AI agent will be a governed digital worker whose identity, authority and actions can be continuously evaluated, letting organizations pursue the benefits of AI productivity without surrendering their security or accountability.

Paul Wagenseil

Paul Wagenseil is a custom content strategist for CyberRisk Alliance, leading creation of content developed from CRA research and aligned to the most critical topics of interest for the cybersecurity community. He previously held editor roles focused on the security market at Tom’s Guide, Laptop Magazine, TechNewsDaily.com and SecurityNewsDaily.com.

You can skip this ad in 5 seconds