Move fast and don’t break things: A new model for AI governance
AI agents are already running in your environment, but most governance models have no idea what they're doing once they're inside. This session shows how the fastest-moving organizations are deploying AI at scale without losing control of what their agents access, what they do, and who's accountable when something goes wrong.
Governance, big hand, please.
Good afternoon.
Thank you for thank you for coming.
Thank you for staying for the presentation.
So my name is Art Gilliland.
I'm the CEO of Delinea.
Delinea is a identity security company.
We're based in San Francisco.
We've about 600 million in revenue and about 9,000 customers.
And so today I'm going to share some details about.
There's about 300 customers of ours today that are actively using technology to secure AI.
And so we are learning together with our customer base.
And so I wanted to share some of what I think are the top learnings that we've taken away from that interaction with the customers that are actively trying to govern AI in production right now.
And so I'm going to start off just to giving a sort of a brief view of the kinds of conversations we have, dig into some data, share a little bit of it about the data, highlight the one or two top-level learnings that we've received from the customers.
And then if you we're going to try something, we're going to see if we can take live questions.
If you have live questions, I'm happy to answer that and we're going to give it a shot.
And maybe that won't work at all, but we'll find out.
So here we go.
So what I would say I spend about 40% of my time on the road talking directly to customers.
And I will tell you that most of our customers today are asking two very specific questions.
The first one is how do I adopt AI and do it really fast, but make sure that it's safe.
And so as a CEO, I'm telling my company to do that.
I'm pushing my, my own internal folks to use AI as much as possible, try to drive productivity.
I also have to run a company and try to go faster.
And so the big challenge we have is can I go fast without breaking stuff?
And a lot of the conversations that I have today are, I am piloting AI. I got it in a test area, but I'm not quite confident enough yet to go big with it.
So that's part one of the conversation that we have.
And I'm going to spend some more time talking about what we do there and how we are learning with our customers there.
The second question, also super critical, I won't spend a lot of time on this one, but how do I protect myself from the AI attacks that are coming, right?
And it's not that AI is going to go crazy, although you did see some of that with Hugging Face.
But it is the adversary using the same tools we're using to be more productive so they can be more productive.
And so that is the other big question that boardrooms and CEOs and CIOs are asking us around what is it that you can do to help us be more secure when somebody outside the company is using AI to attack us.
And so interestingly, the answer is very similar.
And so I'll talk a little bit about that as we go.
So let's let's dig in first to some data.
One of the things that we have done is we surveyed about 2,000 CIOs and CISOs, Chief Information Security Officers, and asked them a bunch of questions, and I'm going to share a little bit of the data.
One of the big takeaways that we that we took from the research that we published and is available on our website is there is this interesting paradox that's going on within companies around the confidence that they have to be able to go forward with AI and the actual ability to secure it.
And so that is one of the big things.
And so I think one of the things that came out was 87% of all companies say, I am ready, let's go do this, let's go do it.
AI, they're telling their senior folks, CEOs and boards, yep, we can do this, let's go.
And then you ask the next question.
How are you going about actually knowing what's going on?
Can you find and understand what the agents are doing and how are you keeping the level of security high when you do that?
And so the paradox is pretty significant.
I'm ready, but I don't really have any tools.
I don't really know what's happening.
And I'm being asked to reduce the level of control and security within the environment so I can go faster.
And so these are the things that we're learning from our customers today, hearing from our customers today.
And so learning number one from the companies that are using this today: we are asking ourselves to make a false choice.
What is that false choice?
One is, do I have to loosen controls?
Do I have to allow and ask for more, more leeway to be able to make progress with AI?
And our customers are basically telling us that is what's actually that's what they're being asked to do in my world, which is identity security.
Like the cardinal sin is to have standing privileges, basically always-on access to systems available through passwords and those things.
That's what AI uses to find to find access.
So if you looked at the Hugging Face attack, it was basically use a vulnerability to break in, then scan the environment looking for things to steal, credentials to steal, and then logging into a new system.
So standing credentials are like the big red line you wish you could have removed.
It's hard, but you want to do that.
And so they're being asked to allow that to happen so AI can get its job done fast.
The other side is, OK, well, if I'm going to enforce that, if I'm going to make those controls happen, what is it that I'm going to do?
I'm going to slow down all this great innovation.
Don't make it hard for my IT teams, don't make it hard for my business leaders to to move forward.
And we think that, and we've seen that that is a false choice.
It's still a conversation that's going to happen.
You're going to have to have that conversation.
But it is a false choice if you can build the right tooling and controls in place.
So that's learning number one that we've taken away from our customers.
The second big learning from our customers is this thing that we're calling the inventory trap.
It is how do I go out and discover all the agents in my environment.
Good luck with that.
If you think about the security world in general, we've always wanted to start with an inventory, and even Delinea will tell its customers, go and find all your users and their passwords, do a scoring about them to figure out the risk, and then implement controls.
That has been sort of the golden rule for security: inventory first, controls second.
With AI we are learning that that is going on its head.
And why, why is that?
If you think about the way we're using it. So we inside of Delinea use Claude Code.
And so all of my employees have this harness, as the new word is, I guess — Claude Code — on their on their laptop.
That laptop then can can you can ask it questions.
So I asked it to do some things for me.
I use it also.
That spun up an agent.
That agent spun up three more agents.
One went and talked to Snowflake, one went and talked to my customer database.
One went and talked to an internal system for revenue, brought all that, created a spreadsheet for me that spun up like three or four agents that were there for 15 minutes and then disappeared.
If you're not scanning right at that moment, you're not going to see any of that.
And so what is the answer?
Like what is it we want to do for this?
I think what we're learning is a model, like a governance model, that was designed and built for humans.
So things that don't really change that much in your environment: a human, a physical server, even a machine identity that is permanent, like an API.
Those kinds of models are not working for AI because it's ephemeral and non-deterministic.
It decides what it's going to do.
It's only there for a couple minutes.
And so what we are learning is that you still need to build inventory.
I don't want to, I'm not going to stand up here and tell you that inventory is not important.
But what's important is not an inventory of agents, which you will chase the rabbit and never be able to solve.
It is an inventory of the actions that those agents take in your environment.
And so be able to to be able to build an inventory from control out is, I think, the new model that is going to be necessary here.
The next thing that we are learning is that the traditional approach of providing access at the front door.
So think about this: club or bar.
For me, that was a long time ago.
But for some of you, I can tell you're young enough that you probably still do this.
You're going to the bar, you're going to the the club, and there's a bouncer at the door saying, hey, can you get in?
Can you not get in?
OK, you're drunk, you don't get to get in.
But it's not that person that is the problem with AI.
It's what happens after you're in the bar.
It's all the decisions that get made after the connection has happened, after the session has been opened, because AI makes decisions as it goes, as it learns.
And so the model needs to look a little different in this new world.
It's not just about what happens at the front door.
You have an identity.
You may now go in the bar.
It's OK, now you've had like 17 drinks in the bar and you probably should leave.
So you need that bouncer inside after the connections have been made.
And so what does this look like?
What this looks like is something that the industry is starting to talk about that says runtime, runtime access or runtime authorization.
It's how we're thinking about building the the future of the technology.
And so what is this?
This is, yes, you need to have that front door connection.
I am now connected to a database, but now every decision that gets made after that needs an incremental authorization decision based on the context that you have built in and around the agent's intent.
Whether that's through the intent of the prompts that are created or its intent that's in the protocol itself, the MCP protocol, understanding what it's trying to do and then making a decision.
Do I want it to do that?
Do I not want it to do that?
And so to be able to make runtime decisions, you must be in the path, you must be in the session itself.
And so this is a lot of what we're learning as our customers are using this in production.
And I would love to say we have it all figured out.
We don't.
We're also learning. As, as you can imagine with this, one of the things that's going to happen is, OK, I'm going to set policy then now on these agents and what they're allowed to do.
How do I create that policy?
If it's really 100 agents for every one human in my company, we've got about 1,300 employees.
That's 130,000 policy statements that my team would have to manage and write.
Impossible.
And so we're going to have to start thinking differently about how policy gets created, how it gets managed as part of this, which is something we're working on currently with the customers that are running this.
So let me talk about a real customer example.
There's a a customer called Telnyx. They're a an IVR, so they do AI-driven sort of phone responses.
They're also a telco, and so they were using AI to manage their environment.
And so what they had, and they had a challenge with it.
They had a database administrator who was working, of course he has access to production, but he was also working in a QA environment.
And so he's switching from production to QA and he asked his agent to go clean up a database.
So it went and cleaned up the the test ones, but it also had access to production and accidentally cleaned, cleaned up the production database.
Not an awesome day for that guy.
What Telnyx struggled with is, OK, what happened?
Did you do it?
Did the agent do it?
Like what?
What actually happened?
And did I see it at all happening at all?
And so we worked with them, and this is part of how we built the system.
We realized that both AI and humans were going through the same interface, the same pathway, because it was Art, let's say, with credentials to those databases.
And I am giving my credentials to Synthetic Art.
So what should I do about that?
So we worked with them to create a, a way to see the difference.
So fingerprinting Art, fingerprinting Synthetic Art, and then building in policy control to separate policy: Art can do these things.
So I will say in Telnyx and also within Delinea today, you can say Art can do destruction on a database.
Synthetic Art cannot do destruction.
And so you can set rough-cut policies today.
And so what we've done with Telnyx is now there is a different policy for their agents doing work for them versus the human doing work for them.
And you see that difference actually hitting into the infrastructure.
And they can also now archive and log and have a provable chain of what actually happened, which will be very important for a lot of the regulatory issues that are coming down now in Canada for regulated industries.
How do you create an audit trail?
How do you prove what was done?
And so this is the kind of work that we're actively learning from.
So all right, getting ready for questions, if you have any.
I'm going to just pose a couple of questions of myself.
And if there are no questions, we will end.
But here we go.
So first, as you're thinking about your own environments and what's happening there, do you know which critical assets in your environments, which things you care about the most, are being talked to by AI?
Do you know?
I think that is one of the primary areas of real inventory.
Understand your assets, protect those assets, and who can talk to them and what they can say.
That's question number one. The second is, if an agent actually took an action in your environment, would you know, and would you know whether it was Art or Synthetic Art?
Could you tell the difference?
That's going to be a critical point of understanding, especially for the regulatory rules that are coming.
How long would it take you to figure it out if that was happening? How long?
And then specifically for the regulated organizations and companies out there, do you have an, are you building the infrastructure to be able to adhere to the OSFI regulations that are coming down in 2027?
Because being able to do that audit trail, being able to prove definitively what happened in your environment, is going to be super critical.
So thank you very much.
If you have questions, I think we have a, here we go, over here.
Kathy's going to help.
If there are questions, I'd love to answer them.
I've got about four minutes.
Otherwise, we will give it back.
If you raise your hand, that's good.
Otherwise we can be good.
There's a question over here.
Hold on here.
Hi.
Hi.
You spoke about the false choice of slowing adoption, but you also spoke about needing the right tools to allow that thing to happen.
So how do you do both at once?
You need the new tools to make that the false choice.
Yeah.
Or can organizations with their current tools already make that the false choice?
Yeah, I think it'll depend on your tools.
So I think everybody heard the question.
I, I think the reality is you do need to bring tooling in to be able to control and manage AI.
And so you're going to want to be able to do that.
Now the reality is identity security is one tool that you can use.
So Delinea has an ability to help you do that.
And so we can definitely talk about that.
But you definitely need tools, and AI is different and it's behaving different, like what we shared
And so there is some level of get ready, go slow to go fast, right?
And I think that's probably what I would, I would say.
OK, well, thank you very much.
I really appreciate the time.
Merci beaucoup.