• Overcoming the biggest blocker to AI production

    From TechnologyDaily@1337:1/100 to All on Tuesday, September 01, 2026 10:15:25
    Overcoming the biggest blocker to AI production

    Date:
    Tue, 01 Sep 2026 09:09:32 +0000

    Description:
    Outdated security models stall AI agents, requiring unified, zero-trust identity architectures to prevent catastrophic risks.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Autonomous AI agents are
    already running inside core infrastructure executing code, applying
    policies, and managing DevOps functions. And the projects keep stalling, because the security models theyre being wired into were built for a world that no longer exists.

    Retrofitting non-deterministic actors into those models is costing engineers time they dont have, and it introduces risk no enterprise can manage. Ev Kontsevoy Social Links Navigation

    CEO of Teleport. Many projects have stalled amid concerns about deploying without a robust security foundation and with good reason. Weve already seen an agent delete a companys entire production database, and its backups, in nine seconds. Security teams are being asked to stop scenarios like that with tools built for a world of two actors. The cracks are starting to show. Something has to change, or innovation stalls under the weight of its own controls. Latest Videos From TechRadar Watch full video here: AI agents require a new identity model The pressure on production and engineering teams to speed up delivery is very real and pervasive. So they often fall back on old habits like granting agents broad privileges and treating them as any other microservice.

    But agents are very different from machines; they are error-prone and non-deterministic, just like humans. Yet, operating at machine speed, 24/7. Agents can delete entire production databases in nine seconds. How many
    humans do you know who could do that? You may like AI agents are inside the enterprise are your security foundations ready for them? Artificial intelligence agents need access, not secrets Why AI coding agents keep stalling before production and the governance controls that fix it

    And this brings me to the crux of the problem. Identity systems were built
    for a world with two kinds of actors humans and machines but there are now three. Trying to fit agentic AI into outdated systems makes each agent a potential source of compromise, and one that can execute thousands of actions across infrastructure in seconds.

    Yet this is what engineers are asked to do; stop catastrophic scenarios with legacy IAM tools that are breaking down. The cracks are starting to show. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro
    newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over. Why the old model breaks Historically, identity fragmentation has plagued engineers working with Kubernetes
    clusters, cloud platforms, container orchestration, CI/CD pipelines, databases, etc.

    For a human workforce, this was manageable. Humans are trackable; they log in and log out. They are slow enough that visibility gaps rarely turn into immediate incidents.

    Enter agentic AI, and the speed gets turned up to the max. Suddenly, teams
    are inundated with thousands of activity logs, and they lack the ability to effectively contain the agent before it executes unauthorized changes. What
    to read next Agentic security doesn't need a whole new definition you just need to reframe what you already know Why cybersecurity must evolve for the age of AI agents Phishing the agent: Why AI guardrails arent enough

    Trying to enforce strong authentication and short-lived privileges would mean building individual integrations for every tool in the stack. It makes AI
    hard to scale when each tool uses a different integration protocol.

    Rather than focusing on innovating with agentic AI, engineers are forced to stitch together IAM, infrastructure, and secrets by hand with no consistent identity, no visibility into agent actions, and every team building its own container or VM workflows from scratch.

    But creating a new tool to handle a third identity type is the worst reaction the industry could have. It would double the work for engineers, as they
    would need to rebuild the identity policy from the ground up and introduce greater anonymity. A new identity silo is anonymous to other siloed systems, making it even harder to catch attackers.

    This leaves us with the question of how enterprises can control an agent's behavior. The solution isnt about adding to the tech stack or implementing more tools; it's about changing our identity models to eliminate anonymity entirely. AI control means zero anonymity To remove anonymity from infrastructure , enterprises must give every actor spanning humans, machines, workloads, and AI agents first-class identities, cryptographically secured
    by a hardware root of trust.

    Ditch static credentials entirely. Eradicating API keys and passwords eliminates the credential sprawl that causes breaches, as well as the threat of secrets being stolen or handed over to the wrong actors. With identity rooted in real-world factors, attackers cannot impersonate a trusted machine and trick an agent into exfiltrating a database.

    But strong authentication in itself is not enough. AI agents, like all other actors, need to adhere to zero-trust principles. This can only happen when siloed systems are replaced by an infrastructure layer in which agents have the exact same identity type as the machines they run on and the humans who authorize them.

    Agents should operate with short-lived privileges tied directly to specific actions authorized by a human user. Privilege attached to the action, not the actor. For example, an agent generating code must inherit its mandate from a human owner with matching authority, restricting privileges to only the specific data tables required for that task.

    Non-deterministic actors also require a contained, trusted execution environment before touching production infrastructure.

    With no default privileges, the blast radius is heavily bounded. But this can only be achieved when a single policy is set by a single system for all identities.

    Identity policy can also be introduced as an enforcement layer between the agent and its inference endpoint, so behavior is controlled before instructions are ever executed. With a unified architecture, identity becomes the control plane for AI AI agents are unlocking immense opportunities in enterprise environments, especially when deployed in live infrastructure, where they deliver the most value. From managing routine changes to fixing deployments in real-time, the possibilities are endless. Succeeding with AI
    in such critical business operations requires tight control of behavior.
    We've featured the best AI tool. This article was produced as part of TechRadar Pro Perspectives , our channel to feature the best and brightest minds in the technology industry today.

    The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit



    ======================================================================
    Link to news story: https://www.techradar.com/pro/overcoming-the-biggest-blocker-to-ai-production


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)