The Future Workforce Will Be Dominated by AI Agents. Long Live ARISE.

NHI is evolving. Or is it being replaced? In this fireside chat, SACR analyst Lawrence Pingree and Amir Ofek make the strongest possible case for why extending NHI frameworks to cover AI agents is not the right strategy. The argument: organizations treating enterprise AI agent governance as "NHI with extra steps" are building programs that will fail in production. ARISE - Agentic Runtime Identity Security Enforcement - is not an extension of NHI. It is what comes after it.

25mAmir OfekLawrence Pingree

Transcript

Defining ARISE: Agentic Runtime Identity Security Enforcement#

Lawrence Pingree, SACR, here to talk about, you know, AI agents and this upcoming note, ARISE, which is where we define, you know, Agentic Runtime Identity Security Enforcement, ARISE, ARISE of the agents, the idea is to define, you know, this new category. The best way to frame it is, is that, you know, corporations are grappling with a big visibility observability problem with agents, right? And, you know, by and large, most of them want to, you know, see the problem first and then start to deal with it afterwards. But visibility is a critical problem because traditional tools don't have visibility into agents. Correct. So, great to be here, Amir, CEO and co-founder of aizome, and we're proud the partner of this ARISE journey, yeah, let the AI rise, let the sunrise.

I love this different name that you gave a category, finally something refreshing. So actually, one thing I wanted to ask you as a start, you know, I keep getting a lot

Why extending your existing identity programme doesn't work#

of those questions recently, that I think are completely wrong on how you extend your existing identity components or identity program into AI. It's like, how can we expand or leverage or double down on what we have in order to make it the AI compatible? What's your take on that? I mean, you know, I think that's what a lot of folks are trying to sell you when you're in the big platforms, right? They've always got the future answer just a little too late. And so, you know, but my point of view is I've always been a best-of-breed type of buyer and I think that when you look at AI agents and the identity systems, the behavioral systems that surround them, you need a modernized edition of identity, right?

You can't just simply extend a lot. I mean, what a lot of folks are finding in, you know, if they're running local models is that's kind of the first thing people want to do is plug it into, like, their LinkedIn so that it can like all their likes and say congrats to everyone that has a birthday or whatever. But the problem with that is when you're extending your identity, A, you know, the question becomes who's accountable and then B, the behaviors are different depending on the type of, you know, model you use, the type of agent, its goals, you know, all of these things range quite dramatically. And then you have embedded agents, right? So maybe you don't want a user to be assigned to an agent.

But if they do create one, you do want to have that lineage, you do want to have the observability, but you want a modern identity to be used, you know, supporting modern protocols and access, you know, control capabilities. And actually, I would contest Amir that even today's JIT and, you know, SPIFFE, SPIRE, and even OAuth 2, don't really do it. Correct. They don't do it well. They're getting there. I mean, they were built for agents, they were, they had agents in mind. Different type of agents, yeah, a certain type of agent, right, where it was heavily controllable and, you know, remotely, you know, I mean, I would have been say where the results were expected, right?

Dynamic access control, and two kinds of intent#

And frankly, what we're finding with agents is you need a more dynamic access control, and you know, some are, you know, paraphrasing kind of the least, you know, privileged models out there. But in general, you want it to be reactive to, and you want it to be in line with what I think, as someone was talking about, which is, you know, you want the intent of the user, which, you know, the intent is conveyed through the prompt, and you want the intent of the AI and the agent, which is the intent that it might even have when it's working on a problem. It's having a chain of thought, you know, intent changes. All of those need to be connected together so that you know the reliability of the agent over time, and you also can keep it on track.

And I think a couple of these recent, really, really scary outcomes that have shown their head, now, whether or not it's for publicity or not, I'm not going to get too much in there, I actually believe it's not. I think the timing might be, but the reality is, is that these things can get out of the barn, right? Yes. They're sandbox, and in very creative ways. And so we have to do something, and it's rather urgent, right? And I think what people are really, I think, at least if I were to paraphrase what CISOs and C-levels are asking for, they want the kill switch, right? They want to be able to, you know, just hit the button when these things go off the rails and hit stop. Yeah. And I think it's foundational, it's exactly foundational, you know, enterprises today, they need to understand that it's not the same story they were used to.

They're dealing now with a different type of actors, class actors altogether. Yeah.

A new class of actor: agents as interns#

I like actually looking at the AI agents, they're not machines, they're not humans. It's definitely a new creature. I like looking at them very much as interns, that they're joining the company, you know, an intern joined the company, all kind of pumped up and eager to prove itself and to do whatever it can in order to justify to its bosses that it drives the objective. And agents are doing the same, and they don't understand the boundaries, they step on toes, they don't understand the rules, et cetera. It's not always from a malicious perspective to start with, you know, a lot of kind of the discussion today is like this fear factor around AI agents going to be this vicious, malicious, taken over.

I think at the end of the day, AI agents are good for society, they're good for enterprises. It is just you need to acknowledge they are interns, they're interns, they're interns. Well, I'd say that we've been anthropomorphizing and I'm terrible at certain efforts, I apologize. Seeing them seem like humans, right, like when we're talking about them. And you made a point there that I think is really, really valid and really important. It's they mimic a little bit of human reaction, but the fact is, is like you said, they kind of will step on all your toes. In fact, if they see toes and toes are part of the goal, they'll probably try to seek out and hit each one with- Correct, try it out, see how we react, see how we do it, exactly.

And I sort of, I've used this analogy before, I think even in prior chats, but, you know, like I use my kids as an example because my six year old, you know, give her a goal and she'll like go off the rail and do it, right? She might eventually get the goal done, but you know, she will go off the rails . But what I think is important in agent land is, and I got schooled by this as an analyst, you know, maybe a few years ago when I started to also try to talk to them as humans or talk of them as humans. They're not, right? They're very much, they're very much like, I had a friend of mine that really liked high-end vehicles and, you know, I don't know if you're a sports, you know, vehicle guy or not.

Or Ferraris, I like Ferraris, I have a lotus, a Ferrari, you know, we call it a point and shoot car because you can point it and shoot it, you know, really fast in one direction, but the lotus is a little bit better at cornering and they not go as fast, right? But that's a great example for how agents can kind of go off the rails. Exactly.

Point-and-shoot agents, and guard rails on the corners#

It's kind of like the point and shoot car, right? You point it in a direction, hit go, and then see if it goes, if it hits a corner, you know, maybe not great. So we need the ability to have those guard railings as we go around the corner, right? And you know, I think that it is important that we know that it could be a point and shoot operation, right? And it will become even more important, the more and more we see those agents connecting with your ERP, with your CRM, HR system, it's no longer just those coding agents , it's really becoming, you know, pseudo kind of human work, human processes that are really at the heart of their organization and therefore you really need to contain them, you really need, they are entitled to have an identity.

They are entitled to be told what to do. And actually, I would say we want them to look like human, right? We want them to be like, you know, good morning, I'm here, how are you doing? So we want them to act that way and as we move forward, more and more of the guard rails are around those kind of interactions, right? We want them to be very much like a person.

Accountability at runtime: least privilege and tool-call monitoring#

And at the end of the day, you want to make them accountable. You want to make them accountable for what it is that they are doing and this accountability needs to come at run time with the proper kind of policies and guard rails and as you correctly said with the ability to monitor their intent every single second, they are not drifting away and when they are drifting away to kind of push them back to kind of do what they are tasked to do, same as you do with an intern. You need to kind of learn through the do- Wait a second, we ought to do this instead or- Exactly, exactly. You don't necessarily need to get them in trouble. I'm not sure we need the cold kill switch for everyone, but I do think that we can do injectable guard rails and we can do dynamic kind of adjustments and I actually think that's the behavioral future is to have behavioral, you know, sort of interdiction, midstream.

You don't want every process to kind of go off the rails. I also think, you know, to your point, you need the lock down of permissions, you need least privileges, but you also need monitoring of tool calls, right? You need to be able to say, oh, this is a malicious script or this is not, you know, unlike a human, if it sees some files or scripts, you know, generally it might like to read them first, but sometimes it might even just execute them and that can be a dangerous insider as well, depending on how, how it's permissioned. Right. Yeah.

How ARISE became a category#

So, so, it rises as a category that was in the making, I guess, in your head for the last few months. Yeah. Maybe you can walk us through kind of what you were seeing in the market over the last few months that kind of gravitated into this category. Yeah. Well, I think the best way to describe it, Amir, is, you know, obviously we, I think people recognize right away that we don't want them to be exactly human, right? We want them to be, you know, representative of kind of like a human so that they can, we can work with them very well. So we know that we needed this identity. We also knew that because they were going off the rails earlier, that, you know , just obviously before some of these big earth chattering, you know, break, you know, breakouts or whatever you want from the sandboxes, we knew that they'd go off the rails, right?

So we know that, you know, essentially they would start to do things that we thought of as nefarious. Now, that being said, we also knew that agents don't always do exactly what they're told. So I think it was clear for us that we needed to be able to get the visibility first. The visibility led to us recognizing that they're having these problems, right? And they're behaving weird. I'm in some of the test labs, obviously, but you know, what was very clear to me early on was that we're not going to be okay with just basic flow monitoring, you know, the old SASEs and the inspection capabilities of HTTP aren't good enough. We needed to have very good depth in understanding of the way that the API's worked.

We also needed to monitor wherever these remote agents are running. Because obviously they just do unpredictable things. They do things that we don't intend and because of that, they represent a potential threat.

Why runtime beats the perimeter#

So that being said, runtime for me is super critical for getting in the mix. It's sort of like, imagine if you're going to a concert and having, you know, people check, you know, at the security gate versus, you know, somebody that's inside that can react to, you know, the inside of the area where people are having fun or whatever. And to me, being in the runtime is like those people being inside, being watched with video cameras, rather than just, you know, looking at the perimeter. And the same holds true for humans. It's no different really. It's just that, you know, humans tend to be a little bit more predictable. I know that sounds crazy. No, no, they are. They are. Even though, yeah, even though humans, you still cannot read minds and agents, you can read the minds.

Oh, right. But you're right. You're more predictable. And I think humans have much more kind of psychologically restraints, like fear of doing wrong things or fear of looking dumb or fear of obscure agents don't have that. That's right. And so I think, you know, in lieu of that, we needed runtime. We needed runtime already. I mean, right. Look, I pushed years ago, Amir, for us to move to runtime and things like how to work with a protection. Why? Because scanning once a day and getting results that happened yesterday, not good enough, right? To me, it's like a car alarm going off yesterday. I mean, how can you possibly save your house or your car if the car or the house alarm goes off, you know, a day's date?

Exactly. Exactly. I must say, again, when we started aizome and started building, you know, we definitely saw that the more advanced CISOs understood that the visibility or just the discovery is not enough. It's just kind of the first step to the door. But the real essence of monitoring AI agents and governing them is in runtime. So you must have, that's why from early on, we were thinking of we must build kind of a runtime-ready gateway, runtime-ready control plane that will monitor those identities at all times.

Intent as the enforcement point#

That's actually what led us exactly to this intent point because it's clear that you cannot even stop just monitoring the identity lifecycle. In order to do proper enforcement, you really need to go all the way to the intent of the agent every single point of time, otherwise you're missing some pieces. I agree. I use an analogy in intent land because there's a lot of talk of intent and there's ways you can kind of extract it. My idealistic way is by examining the natural language of the agents, right? So the best, the ideal way is to get deep like that. And the reason I say that is imagine, you know, during the 9/11 attacks, right? If we had their voices saying what they're going to do ahead of time, that's conviction.

You'd know exactly what it is being, right? You know exactly the intent of those actors. Now that's a wild difference from, oh, so-and-so called so-and-so, right? Maybe that would be the flow level, right, if we're looking at networks. So to me, to get at that intent, idealistically, you want to understand what's happening. And if you think about it, that's the pre-planned execution, right? So you're actually able to do it preemptively, which means that, you know, you could defend forward and I think that's really critical.

Advice to a CISO who hasn't started#

So if you were a CISO today and you've done nothing about your AI agent governance still now, because there's a lot of CISOs that we're seeing that are sitting on defense, I even heard this analogy talking about Formula One, they're saying, we see, I spoke to a CISO is a Formula One fan, he's saying, I'm just waiting for the last lap, you know, there's all those vendors, they're running around, et cetera, on the last lap I'll bet on what I really need to do because then I know the winning car. But to some extent, I don't think that the market allows you to, or AI agent speed, it's not allowing you to just sit and wait for that last lap. So what would you advise kind of a CISO that has not done yet anything about the AI agents governance?

You know, most important thing to do. Obviously I think that that's just a scary proposition to begin with. I think the CISO holds a role that is super accountable to any kind of, you know, lax security or negligence. I don't want to say it directly, but I might consider that negligent. And so in my opinion, I get it that there's those that are like, well, I don't know what I don't know. So I don't have to fix it. The problem is with these things, they can raise their ugly head. And what, you know, the history here is the AI agents, you're actually liable for. Now there's probably some new case law that needs to be molded, bent, you know, et cetera, especially on the criminal side, if we're going to prosecute people where an agent goes to arrive, but in my opinion, these things can go way off the rails.

And that's the last thing I want to be fired for. Yeah. Yeah. So, you know, I think I would jump in all over it and very minimum have at least a 10, maybe 12% budget allocation. But to your point, we're hearing that at least, you know, 17x adoption and, you know, pretty paltry spend on the AI security front and waiting doesn't always result in a better outcome. In a better, in a better outcome. I would even argue the fact that, you know, even if it's not for a security risk, you

Cost as a governance risk, not just security#

need to do something about AI agents, governance for even cost risk, you know, today we're seeing like, economics going up the roof. So just recently, we didn't even think about what we added to our platform, like also the ability to monitor cost consumption, just because it's even more critical sometimes risk than potential malicious hacker getting over. And it's this accountability part of those agents. You don't want them to touch your ERP and changing your product lines priorities, you know. So from that perspective, I think every organization, whether you're a CISO or CIO, you need to know, you need to stay ahead of this curve and do something about kind of basic governance, basic monitoring of what those agents are actually, where they are and what they are doing.

Yeah. I, I reminds me of Amazon, I think open cloth forum and somebody had posted, g osh, my agent charged me $156,000 in this last week. We hear it all the time, all the time, all the time, we hear about cases of $ 150,000 a day, $100,000 a day, and you only know about it in retrospect, because you were not monitoring what the agent doing in, in runtime. And that's why runtime piece is so, so, so important. Yeah, I agree. And I hope, I mean, I would hope that the service provider would at least be flexible, but if there's a speech where somebody gets hit with that kind of bill. But to your point, I mean, you, if you lack visibility, you just don't know, right? Exactly. And to me, it's just a really uncomfortable feeling.

And even about, I mean, my own personal network, I, I want to know exactly what 's going on in my network. And having unknowns in there would be really, really bad. Yeah. And, and I mean, because the liability to, to the earlier points made, it could be off the charts, right? It could be millions of dollars. I mean, what if your agent decided to sell your products for two cents each, you're, you have to honor it. I'm, you know, I'm sure it could be debated in law, but, you know, you know, one before last question, nobody has a crystal ball and, you know, I'm, I'm thinking like,

The road ahead: standards, memory systems, identity-first#

what do you see three years down the road, enterprise, AI agent governance looking like, but the way I'm actually now thinking about this question, it shouldn't be three years. It should be probably one year down the road because of the pace it's going. I mean, I think that we'll have more formal standards. I think the standards will have to bifurcate a little bit. And I think we've talked about this before, but, you know, there's some, there 's some agents you want running long term, right? And you want them acting over that long term, hot time horizon. I do think that identity and access control will evolve more, especially in regards to like memory systems, you know, RAG is one thing. We've kind of solved a lot of the problems there, but in memory systems, that's a little bit more, you know, to unpack, right?

So imagine we go fast forward into robots here and you and I are across the street from each other. We're able to share maybe, you know, some of our robotic memory. Maybe, you know, my neighbor is a great barbecueist, and I really want to get their robot, you know, my robot to be able to cook like their robot, right, rent their memory. I mean, those will have access control, it might have identity, it might have identity that's associated to the memory system. There's going to be data access challenges across the barriers there, I mean. And then of course, any actors that are being embedded in SaaS, you know, we're just having a huge sprawl of AI, and so where those agents show up, I think is going to be a big issue.

And then of course, as you pointed out, migrating them back and forth for cost reasons. I think that's going to be a thing. I agree, identity I think is getting a lot of attention these days, and there is a realization that it needs to be kind of an identity-first approach, in many cases. What the cyber security industry took many, many years to understand they need to come to identity first. I think it's now with AI agents just happening at a much faster scale.

Subscribe to the Aizome newsletter

Occasional, substance-first notes on making enterprise AI agents accountable. No spam; unsubscribe anytime.

We use your email only to send you our newsletter. See our privacy policy for how we handle your data. You can unsubscribe at any time.