Thursday, October 1, 2026
HomeArticleSecuring the AI Era: Building Trust Through Identity, Access Management and...

Securing the AI Era: Building Trust Through Identity, Access Management and Zero Trust

  1. Generative AI is moving rapidly into enterprise environments. From a security perspective, what makes AI fundamentally different from the technologies organisations have secured in the past? 

    CA: Generative AI is not just another application layer on top of existing IT. From a security standpoint, it changes several assumptions that security teams have relied on for decades. Traditional technologies process data according to deterministic rules written by humans.AI systems learn patterns from data, generate novel outputs, and continuously interact with users in ways that are often probabilistic rather than predictable.The fundamental shift is: Traditional security focused on protecting systems that follow predefined rules. AI security focuses on governing systems that exhibit emergent behaviour.Information security teams are no longer protecting only applications, networks, and data. They are securing a dynamic ecosystem of models, prompts, agents, training data, retrieval data, and autonomous actions.

    For CISOs, this means AI security is not merely an extension of application security or cloud security. It is the convergence of cybersecurity, data governance, model risk management, privacy, and operational resilience into a new discipline: AI security and AI governance.

    2.As AI applications increasingly interact with enterprise systems, how should organisations rethink the concept of “identity” in an AI-driven environment?

    CA: The ISO/IEC 27002:2022 Information security, cybersecurity and privacy protection — Information security controls standard introduced a control called ‘Identity management’ and the control says: ‘The full life cycle of identities should be managed.’

    The guidance to implement this control includes the ‘identities assigned to non-human entities are subject to appropriately segregated approval and independent ongoing oversight’. What this means is: Organizations need to expand the concept of identity from human users to human, machine, and AI identities.
    In an AI-driven environment, AI assistants and agents can:

     Access enterprise data
    Make decisions
    Execute actions across multiple systems
    Act on behalf of users

    As a result, every AI agent should have its own verifiable identity, clearly defined permissions, and full auditability, just like a human employee or service account.
    Key principles such as least privilege, delegated authority, strong authentication and authorization and continuous monitoring and auditing applies.
    In short, identity management must evolve from managing people to governing an ecosystem of people, applications, services, and autonomous AI agents, all under the same zero-trust principles.

    3. AI models often require access to large volumes of organisational data. What governance mechanisms are essential to prevent inappropriate or excessive data access?

    CA: To prevent inappropriate or excessive data access, organizations should implement strong AI data governance built on Role-Based and Attribute-Based Access Controls (RBAC / ABAC), Least Privilege Principle, Data Classification and Segmentation, Human-in-the-Loop (HITL) Controls, Audit Logging and Monitoring, Data Loss Prevention (DLP) and Privacy Controls, Regular Access Reviews.

    HITL is relatively a new control that requires approval for high-risk actions or access to sensitive information.

    Organizations should consider implementing ISO/IEC 42001:2023 Information technology — Artificial intelligence — Management system standard and ISACA’s Digital Trust Ecosystem Framework (DTEF).

    Organizations should treat AI systems as privileged users and apply the same rigorous governance, access management, monitoring, and accountability controls used for human identities.

    4. With the rise of autonomous AI agents, what new security challenges emerge when software can make decisions and perform actions without direct human intervention?

    CA: The rise of autonomous AI agents introduces several new security challenges because software is no longer just processing requests but also making decisions and taking actions independently.

    Key challenges include:

     Privilege Misuse: AI agents may have access to multiple systems, increasing the risk of unauthorized or excessive actions if permissions are not tightly controlled.
     Prompt Injection and Manipulation: Attackers can influence an agent’s decisions through malicious prompts, documents, emails, or web content.
     Expanded Blast Radius: An incorrect or compromised decision can be executed at machine speed across many systems before humans can intervene.
     Lack of Visibility and Accountability: It can be difficult to trace why an agent made a particular decision or action.
     Agent-to-Agent Risks: Multiple autonomous agents interacting with each other can create unexpected behaviours and cascading failures.
     Data Leakage: Agents with broad access may inadvertently expose or share sensitive information. To address these risks, organizations need robust AI security and AI governance.

    5. How can organisations apply Zero Trust principles to AI workloads without creating excessive friction for developers and business users?

    CA: Organizations can apply Zero Trust to AI workloads by treating AI models and agents as untrusted identities that must continuously verify access, rather than granting broad, persistent permissions.

    Relevant practices include: Giving AI agents access only to the specific data and systems required for a task; Assigning AI agents unique identities and enforce authentication for every interaction; Making access decisions based on user identity, data sensitivity, device, location, and task context; Limiting AI access to specific applications, datasets, and services rather than entire environments; Logging and reviewing all AI actions, data access, and decision-making activities; Providing temporary permissions when needed instead of always-on privileges.

    To minimize friction, organizations should automate policy enforcement, integrate controls into existing developer workflows, and use centralized identity and access management platforms. This enables secure AI adoption without slowing innovation or productivity.

    6. AI systems increasingly depend on APIs to communicate with models, applications and enterprise platforms. What should organisations prioritise when securing these AI-to-system interactions?

    CA: Organizations should prioritize API security as a core component of AI security, since APIs are the primary pathway through which AI models, agents, data sources, and enterprise systems interact.

    Key priorities include ensuring every API call is authenticated and governed by least-privilege access controls; Assigning unique identities to AI agents, models, and services rather than relying on shared credentials; Encrypting data in transit and validating that only authorized data is exchanged between systems; Continuously monitoring API activity and maintaining detailed logs of AI-driven actions and data access; Preventing misuse, automated attacks, and excessive API consumption; Defending against prompt injection, malicious payloads, and data leakage through API interactions; Assessing AI-API related risks and governing external AI models, plugins, and APIs that connect to enterprise environments.

    In summary, organizations should treat AI-to-system APIs as high-value trust boundaries, applying robust identity, access, monitoring, and data protection controls to every interaction.

    7. Employees are adopting public GenAI tools at a rapid pace. How can organisations encourage responsible AI usage without restricting innovation and productivity?

    CA: Organizations should focus on enablement rather than restriction by providing secure, approved AI tools and clear usage guidelines.
    Organizations need to establish AI Acceptable Use Policy; provide enterprise-grade AI platforms: prevent the accidental sharing of sensitive, regulated, or proprietary information by implementing DLP, training users on AI risks, data handling, prompt security, and responsible usage, monitor usage of public GenAI tools and assess risks: creating governance guardrails such as establishing policies for data access, model usage, content generation, and human oversight.

    The most effective approach is to provide secure alternatives, clear governance, and user education, allowing employees to innovate with AI while protecting organizational data and managing risk.

    8. Traditional IAM frameworks were largely designed around human users. What changes are necessary to effectively manage machine and AI identities?

    CA: Traditional IAM must evolve from managing human identities to managing human, machine, application, and AI identities at scale. It entails the following changes:

     Every AI model, agent, and service should have a distinct, verifiable identity rather than shared credentials.
     Apply provisioning, credential rotation, monitoring, and deprovisioning to AI identities just as with human users.
     Grant AI systems only the permissions required for specific tasks and data.
     Provide temporary, context-aware access instead of standing privileges.
     Continuously validate identity, behaviour, and risk levels rather than relying on one-time authentication.
     Track which AI agent acted, what data it accessed, and what actions it performed.
     Secure API keys, tokens, certificates, and machine credentials used by AI workloads.
     Competence plays a crucial role in securely adopting AI Technology. Students or professionals can pursue National Security Database (NSD) Certified Artificial Intelligence (AI) Security Professional (NCAISP) training and certification from Information Sharing and Analysis Center (ISAC).

    Organizations need to treat AI agents and machines as first-class identities, governed with the same rigor as human users under a Zero Trust framework.

    Disclaimer: The views expressed by the interviewee are solely the author’s and do not reflect the views and beliefs of Profinch Solutions; their affiliates, or employees.

RELATED ARTICLES
- Advertisment -
Google search engine

Most Popular

Recent Comments