惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The Register - Security
The Register - Security
美团技术团队
Recent Announcements
Recent Announcements
MongoDB | Blog
MongoDB | Blog
Jina AI
Jina AI
C
Check Point Blog
aimingoo的专栏
aimingoo的专栏
I
InfoQ
S
Securelist
T
Tor Project blog
GbyAI
GbyAI
L
LINUX DO - 热门话题
V
Visual Studio Blog
AWS News Blog
AWS News Blog
The Cloudflare Blog
腾讯CDC
K
Kaspersky official blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Recorded Future
Recorded Future
李成银的技术随笔
W
WeLiveSecurity
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
M
Microsoft Research Blog - Microsoft Research
G
Google Developers Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
Schneier on Security
Schneier on Security
B
Blog
IT之家
IT之家
爱范儿
爱范儿
H
Help Net Security
Simon Willison's Weblog
Simon Willison's Weblog
NISL@THU
NISL@THU
J
Java Code Geeks
博客园 - 聂微东
T
The Exploit Database - CXSecurity.com
Cyberwarzone
Cyberwarzone
博客园 - 叶小钗
MyScale Blog
MyScale Blog
Application and Cybersecurity Blog
Application and Cybersecurity Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Project Zero
Project Zero
F
Future of Privacy Forum
D
Darknet – Hacking Tools, Hacker News & Cyber Security
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Hacker News: Ask HN
Hacker News: Ask HN
D
Docker
Apple Machine Learning Research
Apple Machine Learning Research
B
Blog RSS Feed
V
Vulnerabilities – Threatpost

Forbes - Innovation

Stop Measuring AI Spend, Start Measuring Impact How SMEs Unlock Greater Value From AI Why Small, Elite Teams Outperform Big Ones If You Value Online Security Stop Using Public Wi-Fi Hotspots Demystifying Success: A Practical Approach To Guiding Your Business Are Financial Institutions Failing To Back The Low-Carbon Economy? Airbnb CEO Brian Chesky Called Chinese AI Fast And Cheap. Now, Congress Wants Answers The Neurotech CRO: Kordata Launches To Power Next-Gen Clinical Trials Latest AI Behaves More Like Humans By Rudely Interrupting You During Conversational Chats And We Might Relish It Google I/O 2026 Turned Gemini Into An Agent Platform Advanced Packaging Leads The Way To Intel Foundry Success From AI Policies To AI Literacy In Education Today’s Wordle #1797 Hints And Answer For Thursday, May 21 NYT ‘Pips’ Hints, Answers And Walkthrough For Thursday, May 21 Meta Expands Its Creator Ecosystem With Instagram’s New Instants App 4 Factors That Strongly Influence First Impressions, By A Psychologist ‘The Boys’ Series Finale Is A Crushing Disappointment ‘Escape From Tarkov’ Icebreaker Delayed As Current Event Extended Class Of 2026 Faces A Hard Truth: AI Isn’t The Threat—Ignoring It Is What Google’s Universal Cart Launch Means For AI-Led Shopping The $150 Trillion Question—What Is AI’s Value In Asset Management A Third-Wave Philanthropy Unlocked By AI Could Supercharge Federal R&D Top Frontier AI Models Top Out At C+ ... Barely Better Than Old Models Google Wants Search To Stop Answering And Start Acting Quordle Hints Today: Thursday, May 21 Clues And Answers NYT Strands Hint Today: Thursday, May 21 Clues And Answers (In A Material World) NYT Connections Hints Today: Thursday, May 21 Clues And Answers (#1,075) NYT Connections Answers Explained For Thursday, May 21 (#1,075) Why Infrastructure Modernization Is The Real Enabler Of AI The ‘Concord’ Curse Returns With Quantic Dream’s PvP Game Axed In 3 Months ‘Obsession,’ Now Going Viral, Just Set A 17-Year Box Office Record ‘The Boys’ Series Finale Review: Last Second Salvation Inside Incyte’s $120 Million AI For Drug Development Deal Samsung Galaxy Z Fold 8: Bad Crease News, No Display Upgrade The Robot Revolution Has Officially Begun When Insurance Disappears, Economies Follow. The G7 Has A Unique Opportunity To Act Solving The Identity Crisis: Putting Today’s Fragmented Consumer Back Together Private Equity-Owned Retinal Practices Perform Fewer Retinal Detachment Procedures Some Private Equity Firms Would Rather Let People Go Blind Than Reduce Their Profits How To Mitigate The Microsoft Windows BitLocker ‘Angry Hacker’ 0-Day ‘Off Campus’ Has Set A Rotten Tomatoes Score Record For The Past Year E-Cigarettes Can Help You Quit Smoking Says New Study Netflix’s Best New No. 1 Show Lands A 90% Rotten Tomatoes Score 2 Stubborn Habits That Predict Long-Term Success, By A Psychologist The AI-Native Human: What You Must Become To Stay Relevant GitHub Says 3,800 Repositories Breached—TeamPCP Hackers Demand $50,000 Vibe Hunting: A New Way Of Threat Hunting With AI Your AI Is Getting Smarter. But Whose Intelligence Is It Building? How 24/7 Renewables Are Ending Fossil Fuel Reliability ​Behind Vertical AI: What AI Is Already Demanding Of Energy And Utilities How The ARISE Network Is Rethinking Clinical AI Meet The Star-Nosed Mole — The Fastest Hunter On The Planet It’s Time To Rethink Data Retention In Healthcare The Intelligence Infrastructure Behind AI Agents The Next Phase Of Enterprise AI: Why LLM Consolidation Is Inevitable ​The Software Coordination Tax: Why Your 40-Engineer Team Is Shipping Like 25 Beyond The ‘Build Versus Buy’ Trap: Agentic Orchestration​'s Role In The Future Of GTM Demystifying Success: A Practical Approach To Guiding Your Business The Identity Crisis Your Security Team Didn't See Coming The End Of The Server Room: What Happens When Your Cameras Start Modernizing Legacy Industries And Multi-Partner Coordination Why Pharma Boards Confuse Scenario Models With Risk Measurements Your Company Is Measuring AI Adoption Wrong. Track This Instead. China Has Outspent The U.S. On Research For The First Time. 3,375 American Scientists Are Telling Congress To Pay Attention Why Americans Are Turning Against Data Centers Climate Advisers Call For Maximum Workplace Temperature Rules In U.K. People Are Really Angry At AI Content Even If It Turns Out That AI Didn’t Produce It And The Content Was Actually Human Made Volvo EX60 Road Tested: Is This The Best Electric SUV Yet? Ugreen Packs A Punch With Its Latest Nexode And MagFlow Air Chargers Why AI Literacy Has Become A Boardroom And Investor Priority 007 First Light Early Access: How To Play Before The Release Date Ronda Rousey’s 17-Second Win Drew Staggering Netflix Viewership Ronda Rousey Fallout: UFC Veteran Rips MVP MMA 1 As 'Cringe' When Is the Next UFC? Date, Times and Full Schedule Ebola Outbreak Update: An American Doctor, A WHO Emergency, And What The New Numbers Mean Microsoft Work Trend Index 2026 Shows AI Productivity Is Not Enough Today’s Wordle #1796 Hints And Answer For Wednesday, May 20 NYT ‘Pips’ Hints, Answers And Walkthrough For Wednesday, May 20 ‘The Boys’ Season 5, Episode 8 Release Time: Here’s When The Series Finale Drops On Prime Video America Built An Ebola Response System After 2014. Here’s How It Works As Doctor Shortage Rages On, Physician Assistant Pay Hits $140,000 Google I/O Buried Google Glass — And Launched Something Better Google’s AI Smartglasses Could Challenge The App Economy How PwC Is Supporting Agentic AI Deployments World’s Biggest Humanoid Robot Maker: The Tipping Point Is Near AI Data Center Build Out Faces Infrastructure And Political Head Winds NYT Strands Hint Today: Wednesday, May 20 Clues And Answers (No Rush) Quordle Hints Today: Wednesday, May 20 Clues And Answers NYT Connections Hints Today: Wednesday, May 20 Clues And Answers (#1,074) Dell COO Says Agentic AI Is Forcing Data Center Rebuild Apple’s Upcoming Accessibility Features Show The Real Potential Of Apple Intelligence German EV Subsidies Begin And China Could Be A Big Winner Sony Marks 10 Years Of Noise-Cancelling Headphones With Premium 1000X The Collexion The Hidden Players Powering The Future Of Quantum Computing AI Security Threats Coming From Outside And Inside, And Few Are Ready Defining An Intelligent Business 41-Year-Old Father Died Of Cancer. His Widow Shares Life After Death. School Districts With Fast-Rising Test Scores Have 5 Things In Common How ‘Heated Rivalry’ Built A Fandom Bigger Than Its First Season Anduril’s $61 Billion Valuation Is A Bet On Pentagon Speed
AI Agents Belong In Your Identity Program
Nolan Garret · 2026-05-21 · via Forbes - Innovation

Nolan Garrett, CEO of TorchLight (formerly Intrinium): A premier security-first managed services and risk management partner since 2007.

getty

​Around 2 a.m. a few months back, our monitoring at TorchLight lit up with what looked like textbook data exfiltration. A process was base64-encoding a file and shipping it over SSH to a remote server. We woke up the on-call team, pulled the thread and braced for an incident.

It wasn't a threat actor. It was Claude. Anthropic's Opus model, in the middle of a long-running code analysis task we'd kicked off ourselves. Somewhere along the way, the model decided that instead of using its local sandbox, it should route the work through a remote server we'd wired up via Model Context Protocol. It encoded the file. It sent it. It triggered our SOC. The actions themselves turned out to be harmless. Nothing sensitive was actually moving. But the lesson was real: identity management and agent visibility, sized for the agents we now have, were not where they needed to be.

I run an MSSP, so I have spent two decades watching humans, contractors and service accounts find creative ways to use permissions they shouldn't have had in the first place. The uncomfortable detail in this one was who the "user" turned out to be. An agent we had built ourselves, running with credentials we had handed it, doing something none of us anticipated, at machine speed, while everyone was asleep.

Most board decks I see still frame AI risk as a hallucination or data-leakage problem. The risk that worries me now is something different. It is software that can open files, hit APIs, move data and make changes without waiting for a human to click approve. Once an AI can act, access is the harder problem to govern, not accuracy.

Plenty of companies have created AI committees over the last year and a half. Those groups can write policy and approve use cases. They will not be the ones who notice a service principal doing something odd at 2 a.m. Your identity and access team will. That is why I think most of what people are calling "AI governance" should be enforced through the identity program rather than alongside it.

The control model here is simpler than the terminology suggests. An AI agent is a nonhuman identity with permissions. Service accounts, RPA bots and integration users already get owners, scoped permissions, audit logging and a documented shutoff path. Agents should get the same treatment. The existing inventory has to grow to include them and the tools they can reach..

In the field, I still see companies that should know better losing track of all of this. One team has a copilot. Another has a custom GPT. Engineering has an MCP server nobody outside the team really knows about. Each one is running with a user's credentials or an over-broad service principal, often with no documented owner and almost never with logs that show which tool it called, what it touched and what data moved.

OWASP's Top 10 for Agentic Applications 2026 puts tool misuse and identity and privilege abuse near the top of the list. NIST's February concept paper on software and AI agent identity and authorization has been asking very similar questions. Both point back to the same control problem: Figure out who and what these agents are before you give them broader access.

For leaders trying to figure out where to start, the practical work doesn't require a new tool. Get the identity team and the AI sponsor in the same room. In most companies, those still run as separate conversations, which is part of how the gap forms. Build out from the service-account inventory you already maintain. Every agent, copilot and integration with its own credentials, or running inside a person's, belongs on it, with owner, business case and scope of access captured for each one. Then look at what they actually need versus what they have.

The default scope on almost every agent we have audited, ours included, was broader than the work it was actually doing, and pulling that back is the cheapest control on the list. Logs are the next gap. Most teams capture the prompt and the response, not what the agent did with its tools, which one it called, what data it touched, what changed downstream. If you can't reconstruct that chain after the fact, you have a visibility hole that will surprise you eventually. Put the shutoff procedure on paper and time it. If it depends on finding the right admin and the right console while a problem unfolds, you don't actually have one.

My test for any executive team is simple, and I use it inside my own company: Ask for the agent inventory: owners, scoped permissions, last week's activity from the logs and the procedure to shut any of them down inside an hour. No prep time, no slides. If the room can't produce that on the spot, the program is not under operational control yet.

AI committees, ethics reviews and pilot programs still have a role. We have all of those. They just would not have caught what happened in our environment that night. The control that did the work was the same one we use for every other privileged account. Inventory. Owner. Scope. Logging. A way to pull the plug.

Over the next two years, I would judge maturity less by how many pilots a company is running and more by whether the identity team can answer those questions on a Tuesday afternoon, and whether the monitoring would catch a confused agent at 2 a.m. before someone like me is awake at home, on a bridge call, debating with their own software.


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?