AI Agent Security: Why Identity and Access Control Matter More Than Guardrails
Release Date: 08/11/2026
Tech Talks Daily
What happens when an AI agent is compromised, manipulated, or simply does something nobody expected, but already has permission to access your most sensitive systems? In this episode of Tech Talks Daily, I speak with Geoffrey Mattson, CEO of SecureAuth, about why securing enterprise AI requires businesses to think beyond protecting models and start paying much closer attention to identity, authorization, access control, and what AI agents are actually allowed to do. Geoffrey argues that AI agents present a different security challenge from traditional software. Conventional applications can be...
info_outlineTech Talks Daily
Companies are spending billions on GPUs, data centers, foundation models, and AI infrastructure. But what happens when the network connecting all of it cannot keep up? In this episode of Tech Talks Daily, I welcome back Avi Freedman, co-founder and CEO of Kentik, five years after our previous conversation. Avi has been operating large-scale networks since the 1990s, including more than a decade at Akamai, and brings a rare combination of founder experience and hands-on knowledge of how the internet actually works. We discuss why network performance is becoming an important factor in...
info_outlineTech Talks Daily
Is AI really causing widespread job losses, or are a small number of announcements creating a much larger narrative? In this episode of Tech Talks Daily, I speak with Marvin Pohl, chief data scientist and cofounder of Clarecast, about AI layoffs, quiet restructuring, predictive workforce intelligence, and the responsibility that comes with forecasting company growth. Marvin’s career began in physics and physical chemistry. After completing his PhD in Germany, he worked at Berkeley Lab and UC Berkeley before moving into data science at BASF. He describes how his role changed as generative AI...
info_outlineTech Talks Daily
What happens when an AI agent is authorized to make a payment, but nobody can verify the wider agreement behind it? In this episode of Tech Talks Daily, I speak with Zor Gorelov of Blue Language Labs about the infrastructure businesses may need as AI agents move from answering questions to negotiating, approving, purchasing, coordinating, and settling commercial activity. Many current business processes depend on human coordination. People reconcile spreadsheets, chase signatures, confirm deliveries, review exceptions, and resolve disagreements between systems. This work often remains...
info_outlineTech Talks Daily
What separates an embedded finance partnership that changes customer behavior from an integration nobody would miss? In this episode of Tech Talks Daily, I speak with Rory Herriman, Chief Technology Officer and Chief Operations Officer for Zip’s US business. Rory works across product, technology, operations, and business strategy, giving him a broad view of what happens after the API connection is complete and real customers begin using the service. Rory challenges a common understanding of embedded finance as placing one financial product inside another company’s experience. Customers...
info_outlineTech Talks Daily
What happens to creator loyalty when somebody delivers the work, attracts an audience, and then waits weeks to be paid? In this episode of Tech Talks Daily, I speak with Rob Israch, President at Tipalti, about the payment infrastructure supporting the creator economy. Platforms may be able to add thousands of creators quickly, but the systems behind onboarding, tax collection, approvals, global payouts, communication, and reconciliation often struggle to keep pace. Rob cites research suggesting 87 percent of creators have experienced late payments. For a creator, payment is a direct test of...
info_outlineTech Talks Daily
What happens when an enterprise AI agent can retrieve thousands of data points but cannot understand the customer, decision, or business moment in front of it? In this episode of Tech Talks Daily, I welcome back Boris Bialek, Vice President of Industries and Global Field CTO at MongoDB. We examine why the enterprise AI conversation has become more professional as organizations move beyond demonstrations and begin putting agentic systems into production. Boris argues that many companies do not have a shortage of data. Their problem is turning scattered data into information and then into usable...
info_outlineTech Talks Daily
What happens when a warehouse management system believes stock is present, but nobody can find it on the warehouse floor? In this episode of Tech Talks Daily, I speak with Oana Jinga, co-founder of Dexory, who oversees the company’s commercial strategy and product roadmap. Dexory has developed autonomous mobile robots capable of scanning inventory at heights of up to 18 meters while creating a continuously updated digital view of warehouse operations. The company says its robots have scanned one billion locations across 12 countries. Its customers include Maersk, DHL, Samsung, GE Appliances,...
info_outlineTech Talks Daily
What can Formula One and football teach businesses about building customer relationships that continue long after a single event? In this episode of Tech Talks Daily, I speak with Ben Lewis, Vice President of Marketing at Infobip, about the company’s work with AI-powered sports companions and what those experiences can teach customer experience leaders in every industry. Ben explains how Infobip worked with TGR Haas F1 Team to create RaceMate, an AI companion available through WhatsApp and Apple Messages for Business. Fans can access team information, driver histories, race schedules,...
info_outlineTech Talks Daily
Late payments have become so common that many businesses simply accept them as part of commercial life. But should they? In this episode of Tech Talks Daily, I speak with Pat Bermingham, founder and CEO of Adflex, about why late payments continue to cost the UK economy an estimated £11 billion every year, why thousands of businesses fail because of cash flow pressures, and how technology could help change payment behavior rather than simply respond to it. Pat argues that late payments are rarely an administrative accident. In many industries they have become an informal financing mechanism,...
info_outlineWhat happens when an AI agent is compromised, manipulated, or simply does something nobody expected, but already has permission to access your most sensitive systems?
In this episode of Tech Talks Daily, I speak with Geoffrey Mattson, CEO of SecureAuth, about why securing enterprise AI requires businesses to think beyond protecting models and start paying much closer attention to identity, authorization, access control, and what AI agents are actually allowed to do.
Geoffrey argues that AI agents present a different security challenge from traditional software. Conventional applications can be tested against relatively predictable behavior. AI models are far less deterministic, particularly when prompt injection, excessive permissions, unexpected behavior, and autonomous actions enter the equation.
His advice is to assume an agent could behave unpredictably and control what happens when it attempts to access a database, execute a financial transaction, call an API, or interact with another business system.
We discuss what this means as companies race to introduce agentic AI. Geoffrey shares examples of employees granting AI tools permissions without fully understanding what they have approved, along with agents gathering information that creates unexpected privacy and compliance problems.
This creates a difficult challenge for CIOs and CISOs. Boards want AI adoption because of its potential competitive value, while employees increasingly depend on AI tools to do their jobs. Simply blocking agents is unlikely to work. Security teams instead need mechanisms that allow innovation while controlling what those agents can access.
Geoffrey explains why Zero Trust becomes particularly relevant here. Rather than authenticating a user or agent once and assuming it remains trustworthy, enterprises need to continually evaluate whether an action should be permitted at that specific moment.
This leads to the concept of continuous authorization. Geoffrey explains how identity security is moving from asking "Who are you?" toward understanding intent, behavior, context, and authority for individual actions. This becomes increasingly important when one AI agent can create sub-agents, which can then create additional agents and pass permissions down the chain.
We also discuss why agentic AI is exposing years of accumulated security debt. Many of the underlying problems are familiar: excessive privileges, inconsistent access controls, incomplete Zero Trust implementations, and systems that trust identities for too long. AI agents amplify those weaknesses because they can operate at machine speed.
Geoffrey describes this as combining the unpredictability of humans with the power of machines.
For CIOs, CISOs, security architects, identity teams, and business leaders deploying agentic AI, this conversation offers practical questions to ask before connecting agents to enterprise resources. What can the agent access? What authority does it have? Can that authority be reduced as tasks are delegated? Is every important action evaluated independently? And can access be revoked immediately when behavior changes?
The goal is not to prevent organizations from using AI agents. It is to create a security layer that gives developers and employees room to experiment while ensuring agents only have the authority they need at the moment they need it.
As autonomous AI becomes part of the enterprise workforce, identity alone may no longer be enough. Businesses increasingly need to understand intent, control authority, and continuously decide whether the next action should be allowed.