『AI Agents Change the Security Model』のカバーアート

AI Agents Change the Security Model

AI Agents Change the Security Model

無料で聴く

ポッドキャストの詳細を見る

【Amazonプライム会員限定】今ならプレミアムプランが4か月 月額99円。

10月19日まで。※適用条件あり

Send us Fan Mail

AI is moving from answering questions to taking actions. And that changes the security model.

In this episode of AI Security Multipliers, Steve explores what happens when AI evolves from an assistant that recommends what to do into an agent that can actually do it.

An AI agent may read email, access enterprise data, update records, call APIs, initiate workflows, modify permissions or interact with other systems. At that point, the security question is no longer simply, "What can the AI see?"

It's "What is the AI allowed to do?"

We look at why agent identity and authorization are becoming critical security boundaries, how delegated authority changes risk, and why familiar concepts such as least privilege, separation of duties, human approval and auditability become even more important when the actor isn't human.

Because every time you give an agent another tool, you're not just adding a feature. You're adding authority.

In this episode:
• The difference between AI that advises, assists and acts
• Why autonomy is really about delegated authority
• Why every AI agent needs an identity
• Whose permissions an agent should use
• The difference between capability and authority
• Why agents could recreate the service-account problem at enormous scale
• How tools and APIs increase an agent's authority
• What happens when an autonomous agent gets something wrong
• Why prompt injection becomes more serious when AI can take actions
• When "human in the loop" actually provides meaningful oversight
• Why logging and auditability matter for autonomous systems
• How separation of duties applies when the actor isn't human
• Why least privilege and just-in-time access matter for AI agents
• Practical steps for discovering and governing agents already inside the enterprise

The Multiplier:
Choose one AI agent your organization is using, building or seriously considering and ask five questions:

What identity does it use?

What data can it access?

What actions can it take?

Who can authorize those actions?

And how do we stop it?

If you can answer all five clearly, you've got the beginnings of a security model.

If you can't, the agent may already have more autonomy than your governance does.

Govern the risk, not the buzzword.


adbl_web_anon_alc_button_suppression_t1
まだレビューはありません