Worried About Rogue AI? Start with Identity Governance - #AuditTuesday w/ Justin Roy and Jeff Kushner
Worried About Rogue AI? Start with Identity Governance Enterprises are increasingly worried about rogue AI agents operating inside their environments. But one of the biggest risks may not be an unauthorized AI agent breaking in. It may be an authorized AI agent using the legitimate identity and access of an employee who is already inside. AI coding assistants and autonomous agents such as Claude Code and similar tools can operate directly from an employee's workstation. Depending on how they're configured, these agents may be able to interact with files, applications, APIs, databases, cloud resources, and other systems using credentials and permissions already available to that user. And here's the problem: many employees don't know how much access they actually have. An AI agent can rapidly discover what resources are available, what systems it can reach, and what actions its user's identity is permitted to perform. In effect, the agent can perform reconnaissance from inside the enterprise —starting with a legitimate, authenticated identity. If that employee is overprivileged, has accumulated unnecessary access, or hasn't had their permissions reviewed recently, the risk becomes significantly greater. AI doesn't create the entitlement problem. It magnifies it. That's why securing enterprise AI starts with strong Identity Governance. Organizations need to understand what their users can access, whether that access is still appropriate, when it was last reviewed, and which identities represent the greatest risk before AI agents begin operating with those same privileges. Join us for this #AuditTuesday discussion as we explore how organizations can prepare their identity environments for the rapidly growing use of internal AI agents. You'll learn: Understand the risk — How AI agents can inherit and leverage legitimate user identities and entitlements. Understand the impact — Why excessive, stale, and unreviewed access becomes significantly more dangerous when AI can act on a user's behalf. Reduce the risk — How Identity Governance and YouAttest can help organizations identify excessive access, continuously review entitlements, and establish stronger governance before deploying AI agents at scale. Featuring: Jeff Kushner —Compliance Expert/CMO, Allgress Justin Roy — Security Engineer, Microsoft Garret Grajek — CEO, YouAttest





