A Practical Framework for Closing the AI Enforcement Gap

Thursday, October 22, 2026  |   11:00am EDT
What will I learn?
  • Real incidents where autonomous agents escalated privilege with no human in the loop
  • Why agents that inherit a user's full access resurrect the standing-privilege problem you already fixed
  • A framework for auditing what agents can reach and what they've actually done
  • What a defensible AI access record requires beyond a named-approver policy


AI governance moved fast this year. Most organizations now have a written policy for what AI tools and agents are allowed to touch, but enforcing that policy at the moment an agent acts is a different story. That gap is where the real risk lives.

AI agents don't behave like the systems identity programs were built to control. They choose their own path to a goal and can drift outside their intended scope for days before anyone notices. And it's already showing up in production environments.

This webinar breaks down new survey data from IT and security leaders and the employees actually using AI day-to-day, paired with independent analyst perspective on why policy keeps outrunning enforcement, and what closing that gap really takes.

Get answers to these important questions:

  • How do we prove our AI access policy is enforced, not just written?
  • What would it take to authorize an agent at the moment it acts, not just at login?
  • How do we stop an agent from inheriting more access than its task needs?
  • What does a defensible answer look like when someone asks who approved an agent’s access?

Who should attend this webinar?

  • CISOs, CTOs, CIOs, CAIOs and Executive Leadership
  • Compliance and Audit Teams
  • Developers
  • Directors of Information Security, Security & Risk, and Security Operations
  • Identity and Access Management Teams
  • IT Security Professionals
  • Legal Advisors
  • Risk Management Professionals

Featured Speakers

John Martinez
John Martinez
John Martinez, Technical Evangelist, has had a long 30+ year career in systems engineering and architecture, but has spent the last 13+ years working on the Cloud, and specifically, Cloud Security. He's currently the Technical Evangelist at StrongDM, taking the message of Zero Trust Privileged Access Management (PAM) to the world. As a practitioner, he architected and created cloud automation, DevOps, and security and compliance solutions at Netflix and Adobe. He worked closely with customers at Evident.io, where he was telling the world about how cloud security should be done: at conferences, meetups and customer sessions. Before coming to StrongDM, he led an innovations and solutions team at Palo Alto Networks, working across many of the company's security products.
delinea-headshot-frank-vukovits
Frank Vukovits

Frank is Chief Security Scientist at Delinea. He has over three decades of experience as an auditor and security professional, along with corporate IT executive management. Frank holds Certified Internal Auditor (CIA) and Certified Information System Auditor (CISA) designations. He is a frequent speaker at audit (IIA), IT audit (ISACA), software publishers, security, and user group events. Frank's recent work focuses on AI governance and securing AI agents as a new class of privileged identity, including runtime authorization of agent actions and the audit-ready accountability enterprises need as AI adoption accelerates. He writes and speaks frequently on these topics, including at Identiverse, Black Hat industry briefings, and for GRC organizations such as OCEG.

delinea-headshot-carlos-rivera
Carlos Rivera

Carlos Rivera, Principal Advisory Director, Security & Privacy, Info-Tech Research Group Carlos has 30 years of experience in IT and cybersecurity, primarily within the fintech industry. His expertise covers all aspects of security architecture, cryptography, application security, cyber risk management as well as communication and transmission cybersecurity: SFTP, SSH, SMTP, DNS, DHCP and IPAM (DDI).  In addition, Carlos has conducted presentations delivered in various conferences, such as the Nevada IT Symposium focused on fintech cybersecurity and the MITRE facility to present on Threat Intelligence & Management for the Department of Defense (DoD).