























Co-authored with Naveen Kaul, IBM Consulting, partner and global IAM leader, IBM
Across industries, organizations are entering a new era of productivity powered by AI agents – systems capable of analyzing data, executing workflows and making decisions at unprecedented speed. From financial operations to software development and enterprise knowledge management, AI is becoming a digital workforce that can operate alongside humans. But as automation accelerates, these threats expose a dangerous possibility that an AI agent operating with valid credentials could execute high-risk actions at machine speed, without meaningful human oversight.
This brings an important question for leaders across technology, finance and risk: How do we ensure automation moves at machine speed without compromising trust, governance or accountability?
The answer lies in a new model of Human-in-the-Loop authorization – one that allows AI to act autonomously in most cases, but requires cryptographically verified human approval when the stakes are high. We’re excited to partner with IBM and Auth0, forming a powerful partnership to secure agentic applications and harness the power of AI while ensuring trust and governance for high-risk actions. Together, we ensure that products are secure by design so teams can move AI agents from pilot to production with confidence – solving the ‘autonomy vs. accountability’ gap through Asynchronous Authorization, using Human-in-the-Loop approvals to bridge that final mile of trust.
AI agents are no longer limited to answering questions – they can take action across enterprise systems. Imagine the possibilities this brings organizations:
These capabilities promise dramatic improvements in speed, productivity and decision-making – but they also introduce a new challenge. AI agents are becoming what security leaders call “digital workers.” They operate with legitimate credentials, interact with sensitive systems and increasingly have the authority to execute real actions.
This raises a fundamental governance question: How do organizations prove that the right human intervened or authorized critical decisions made by AI?
The cyber threat landscape showcases the growing security pressure facing organizations adopting AI-driven workflows:
The risks that automation brings to specific groups is widespread, impacting individuals across an organization. As we consider these risks, there are a few important implications:
Traditional identity systems were never designed for this model because they assume a simple flow:
Human authenticates and authorized → system grants access → action occurs
But when AI agents act autonomously, the identity layer must answer a more complex question: Who authorized the action, and can we prove it?
— Ritika Gunnar, general manager, data and AI, IBM (June 2025)
The solution is not to slow down AI or require humans to approve every action. Instead, organizations must identify specific categories of actions where human authorization is required. For example:
In these cases, human authorization becomes a structural control – not a workflow preference. And it must be enforced cryptographically, not simply recorded in logs after the fact.
This is where the collaboration between IBM, Auth0 and Yubico establishes a powerful model for governing agentic AI systems. Together, these technologies create a workflow that combines AI speed with human accountability. This capability unlocks countless new enterprise use cases and frees up a wide range of personas who can achieve superhuman levels of productivity and efficiency without undermining the integrity of a process and outcome.
In effect, the YubiKey becomes the final human controlled point protecting critical enterprise actions.
This creates strong guarantees for regulatory compliance, risk management, financial accountability and business continuity. Most importantly, it provides non-repudiation – the clear proof that a specific, verified human authorized the action.
The next wave of enterprise productivity will be driven by AI agents capable of acting and not just advising. They will write code, execute transactions, approve workflows and orchestrate decisions across complex systems.
And the real question facing leaders will no longer be: “Can we automate this?”
It is now: “How do we govern automation responsibly?”
By combining IBM’s AI orchestration, Auth0’s identity flows and Yubico’s hardware-backed security keys, organizations can enable AI-powered automation while ensuring that the right human remains in control and authorizes critical decisions. The result is a new foundation for the autonomous enterprise – AI operating at machine speed, secured by human trust.
If you’re attending RSAC, don’t miss our session in person or on-demand on Tuesday, March 24 at 5:00pm in the North Expo Briefing Center. Yubico and IBM will explore how to build trusted identity, achieve cyber resilience, and ensure business continuity with an efficient, secure passwordless strategy in the modern cyber age of AI-powered threats.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。