Securing AI Decisions, Systems, and Autonomous Agents
In Part 1, I argued that AI governance cannot stop at models, data, and outputs.
Organizations must also govern the identities that build, train, deploy, modify, invoke, and oversee AI systems.
That requirement becomes even clearer when we move beyond GenAI.
AI now influences fraud detection, physical operations, cybersecurity, medical decisions, recommendations, identity verification, industrial automation, and autonomous actions. In each of those cases, identity intelligence provides the attribution, context, and accountability required to establish trust.
Identity Intelligence Beyond GenAI
Identity intelligence supports many AI use cases that have nothing to do with chatbots or generated content.
Predictive Fraud and Risk Models
Banks, insurers, retailers, and payment providers use Machine Learning (ML) to identify suspicious transactions and account activity.
The model may analyze transaction velocity, devices, locations, payment instruments, merchants, and behavioral patterns.
Identity intelligence adds attribution.
It can reveal that several apparently unrelated accounts connect to the same person, device, phone number, credential set, or infrastructure.
The important question becomes more than:
Is this transaction unusual?
It becomes:
Who is actually behind this activity, and what other identities connect to them?
That deeper identity context can help distinguish a legitimate customer from a synthetic identity, compromised account, or coordinated fraud operation.
Industrial and Operational AI
Industrial organizations increasingly use AI for predictive maintenance, process optimization, anomaly detection, quality control, and automated equipment management.
These systems depend heavily on machine identities. Sensors, gateways, controllers, robots, maintenance platforms, and analytics engines all communicate and act.
A compromised sensor identity could send false telemetry.
A stolen maintenance credential could modify an optimization model.
A malicious workload could issue dangerous recommendations using apparently trusted data.
Identity intelligence can establish whether each machine:
- Has an approved owner.
- Runs expected software.
- Uses valid credentials.
- Communicates with approved systems.
- Behaves consistently with its purpose.
- Remains trustworthy after maintenance or modification.
In these environments, an identity failure can become an operational or physical safety failure.
Recommendation and Ranking Systems
Recommendation engines shape what people buy, watch, read, and discover.
Ranking systems also influence pricing, advertising, search results, marketplace visibility, and platform/digital trust.
Attackers can manipulate these systems through fake accounts, bot networks, coordinated reviews, fraudulent clicks, compromised partner feeds, or insider access.
Identity intelligence helps identify which employee, partner, process, or machine changed a ranking rule.
That attribution becomes essential when an organization must investigate manipulation, favoritism, fraud, or harmful outcomes.
Cybersecurity Analytics and Automated Response
Security teams use machine learning for behavioral analytics, malware detection, account compromise detection, threat prioritization, and automated containment.
These models improve when they understand identity context.
A privileged administrator accessing several servers may represent legitimate incident response.
The same activity from an exposed contractor account may indicate active intrusion.
A service account transferring large datasets may perform an approved backup.
The same account operating from new infrastructure could signal credential theft.
Identity intelligence supplies context that raw telemetry cannot.
It connects human, device, workload, credential, behavioral, and external-risk information. The model can then evaluate not only what happened, but who performed it and whether the organization should trust them.
AI Supply Chain
Every AI system has a supply chain.
Developers contribute code. Data engineers assemble datasets. Pipelines train models. Registries store artifacts. Automated workloads test and promote releases. Applications invoke the resulting system.
Each stage contains human and non-human identities.
An effective identity intelligence layer should establish:
- Who contributed which dataset.
- Which pipeline transformed it.
- Which identity initiated training.
- Which model registry stored the output.
- Who approved promotion.
- Which workload deployed it.
- Which applications may invoke it.
- Who can change, roll back, or retire it.
This provides an identity-based chain of custody for the AI system.
Agentic AI Raises the Stakes
Agentic AI can take action, which makes it an important element.
An agent may retrieve data, invoke APIs, create accounts, change configurations, approve transactions, communicate with customers, or interact with systems.
That makes delegated authority one of the challenges that define AI security.
An enterprise should never grant an AI agent authority merely because an authenticated user started it.
The organization must understand:
- Who created the agent.
- Who owns its actions.
- Which identity it represents.
- What authority was delegated.
- How long that delegation remains valid.
- Which elements the agent can invoke.
- Whether it can delegate authority.
- How the organization can revoke it immediately.
An agent needs its own governed identity. It should not inherit a user’s complete access profile or rely on shared credentials. Its privileges should be limited by task, resource, duration, context, and risk.
Every action should preserve the identity chain:
- Human initiator
- Agent identity
- Delegated authority
- Tool invocation
- Affected resource
Building an Identity Intelligence Layer for AI
Organizations should integrate identity intelligence directly into AI governance rather than operating it as a separate security effort. A practical model requires six capabilities.
- Discovery – inventory human, machine, workload, model, pipeline, API, device, and agent identities. Simply put, an organization cannot govern identities it does not know about.
- Binding – every service account, model, agent, robot, and pipeline needs an accountable human owner and documented business purpose. Someone must be responsible for the identity’s privileges, behavior, lifecycle, and risk.
- Mapping – document what each identity can access, change, approve, invoke, and delegate. A service account with permission to deploy a model may also possess indirect access to sensitive data, production infrastructure, downstream applications, and automated decision systems.
- Contextualize – connect enterprise identities with devices, workloads, behavioral patterns, external exposure, compromise indicators, and related (non-enterprise) identities. A corporate directory record provides only one piece of the identity. Organizations need to understand the relationships between corporate accounts, personal exposure, machine identities, credentials, devices, and infrastructure.
- Enforce – use identity risk to adjust authentication, privileges, session duration, transaction limits, and required approvals. This equates to continuous enforcement of risk-based access. Access decisions should reflect current trust, not yesterday’s entitlement review. An identity that was safe when a session began may become high risk after credential exposure.
- Preserve – attributable evidence must be preserved. Log who or what took action, under whose authority, through which system, against which resource, and with what result. Organizations should be able to reconstruct a complete decision tree and action chain.
A Question Boards Should Be Asking
Boards often ask whether their organizations have an AI policy.
That question no longer goes far enough.
They should ask:
Can we identify every human and machine with the authority to influence an AI decision or action?
A mature organization should be able to answer that question quickly. It should identify who trained the system, who changed it, who approved it, what data it used, what authority it holds, who invoked it, and who can stop it.
When those answers remain unclear, the organization does not have AI governance. It has AI documentation.
Trust Begins With Identity
The next major AI incident may not begin with a hallucination or sophisticated adversarial algorithm. It may begin with a valid credential.
A compromised developer may poison training data.
An abandoned service account may deploy an unauthorized model.
A synthetic identity may manipulate a fraud system.
A malicious insider may change a ranking algorithm.
An overprivileged agent may execute a legitimate command for an illegitimate purpose.
In each case, the model may operate exactly as designed.
The failure will occur because the organization trusted the wrong identity, granted too much authority, or could not attribute the action.
AI governance must therefore answer three foundational questions:
- Who or what is taking some action?
- On whose authority is it doing so?
- Should we still trust that identity?
Identity intelligence provides context to make those answers possible.
Without it, organizations may govern AI models while leaving the people, machines, agents, and authority surrounding them dangerously ungoverned.