Library Header Image Library Header Image

The Death of Authentication: Why Identity Isn’t Enough for AI Systems


Posted on by Harsh Verma

Key Takeaways
  • Authentication ≠ safety — AI agents can be fully verified and still misuse access, escalate tasks, or cause harm.
  • Trusted-agent misuse is the new risk — incidents can happen entirely within legitimate, authorized workflows.
  • Zero-trust must go beyond identity — security now needs continuous behavior monitoring, not just one-time verification.

The foundation of cybersecurity has always been trust. This has lasted for decades because if organizations could verify who was assessing a system, they can determine whether the activity was legitimate. Knowing who is acting matters less than what they’re trying to do. Focus on identity vs intent, trusted agent misuse and Zero Trust for behavior. That model is breaking down.

Microsoft Security’s post on cybersecurity strategies to prioritize shows that AI agents are changing enterprise environments because trusted systems can now operate autonomously, decide, and communicate across workflows with no need for continuous human oversight. This has made it such that verifying identity alone is no longer enough because these trusted agents can become operational risks.

As Sadie-Anne Jones stated, in an RSAC blog: “Machine identities are proliferating faster than most teams can govern them, creating blind spots in access management.”. This feature extends as the future challenge in cybersecurity is not unauthorized access. It is navigating trusted systems that behave in dangerous or unintended ways.

Identity vs. Intent

Traditionally, trusted security models and identities only produce trusted behavior. This assumption worked well in human environments where users worked in predictable workflows, permissions were stable, and systems were predictable. AI systems changed this because an authenticated AI agent can still:

  • Misuse its permissions
  • Escalate workflows unexpectedly
  • Manipulate processes
  • Generate harmful outputs

The problem is not an authentication failure. It is the fact that an autonomous system’s behavior cannot be predicted after authentication.

This has forced organizations to rethink cybersecurity around intent and runtime behavior instead of access control. Security must evolve from verifying identity to understanding intent and monitoring behavior at runtime.

Sept 16 blog graphic 1 2026

Trusted Agent Misuse: The New Enterprise Risk

One of the most important changes in AI security is the rise of trusted-agent misuse.

Future AI incidents may involve valid credentials, approved workflows, trusted integrations, and authorized access paths. Everything looks proper and legitimate, but the compromise happens within legitimate operational boundaries.

An enterprise AI assistant connected to an organization’s internal systems could unintentionally expose sensitive information, escalate tasks incorrectly, manipulate workflows without contextual reasoning, and trigger widespread downstream operational failures.

The problem is that the system may be fully authenticated the entire time.

This creates a tough challenge for traditional security fixtures because existing controls focus on blocking unauthorized access instead of evaluating dangerous behavior from trusted systems.

Uber case Breach study: A Warning Signal

Uber’s breach in 2022 when attackers gained access to Uber systems through a social-engineering campaign that exploited MFA fatigue--is a strong case that shows why modern security can no longer focus only on verifying identity.

This is because in this case, repeated authentication requests were sent until an employee eventually approved one. Once access was granted, the attackers used authenticated credentials and legitimate permissions to move unseen through the system.

From a traditional security perspective, authentication succeeded because it had to be given before they could access the system. But the resulting activity was clearly unauthorized and harmful.

Sept 16 blog graphic 2 2026

Why Zero Trust must evolve for AI systems

According to NIST's Risk Management Framework, zero-trust facilities were designed around the principle: never trust, always verify. But AI systems require an expanded version of this philosophy because these future AI systems need:

  • Continuous verification of behavior
  • Regular trust evaluation
  • Context authorization
  • Operational intent analysis

These have caused organizations to start implementing Behavioral scoring systems, Runtime monitoring layers, AI observability infrastructure, Contextual policy enforcement and adaptive permission controls.

Authentication has always been treated as the foundation of cybersecurity. If a user or system could verify its identity, organizations believed that its behavior was legitimate. AI systems change that with a transition from identity-centric security toward behavior-centric security.

Enterprises now know that trusted systems can still create operational risk through misalignment, poor reasoning, workflow misuse, or adaptive behavior. My perspective on this is that the future of cybersecurity will not be defined by who has access, but whether systems that are trusted can and are behaving safely long after access is granted.

Contributors
Harsh Verma

Principal Software Engineer - AI, Palo Alto Networks Inc

Blogs posted to the RSAConference.com website are intended for educational purposes only and do not replace independent professional judgment. Statements of fact and opinions expressed are those of the blog author individually and, unless expressly stated to the contrary, are not the opinion or position of RSAC™ Conference, or any other co-sponsors. RSAC Conference does not endorse or approve, and assumes no responsibility for, the content, accuracy or completeness of the information presented in this blog.


Share With Your Community

Related Blogs