Black Hat: Security Leaders Call for Agent Identity Controls and Human Oversight
Key Points
- AI is becoming essential to cyber defense as attackers use it to accelerate reconnaissance, vulnerability discovery and exploitation.
- Security leaders at Black Hat say organizations should manage AI agents as distinct identities with task-specific permissions, monitoring and audit trails.
- AI-driven vulnerability discovery is increasing pressure on patch management programs, making business-risk prioritization, segmentation and attack surface reduction more important.
Black Hat: Security Leaders Call for Agent Identity Controls and Human Oversight
Security leaders at Black Hat USA said organizations must incorporate AIas attackers accelerate their operations with the technology, while implementing agent-level controls, governance and human oversight for high-risk actions.
As AI accelerates attackers’ workflows and shrinks defenders’ response windows, organizations should automate reversible high-volume defensive tasks while retaining human approval for actions that could disrupt operations or cause irreversible damage.
"If you are going to keep up with agentic attacks, you need to incorporate AI into your defenses,” said Katie Moussouris, CEO of Luta Security.
But as organizations deploy AI agents into security workflows, they need controls governing what those systems can access and do, said Fotis Chantzis, OpenAI's Agent Security Lead.
Each agent should have a distinct identity, permissions scoped to its immediate task and an audit trail showing which tools, connectors and systems it accessed.
"You can’t really authorize what you can’t identify. Supervisory monitoring layers can evaluate privilege escalations without demanding manual approval for every step," Chantzis said.
While organizations grapple with how to govern AI agents, security leaders also warned the technology is changing the economics of vulnerability discovery and exploitation.
AI could further strain patch management programs by increasing the volume of discovered vulnerabilities and making lower-severity flaws easier to combine into viable attack paths, limiting the value of prioritizing remediation based on generic severity scores alone.
Morgan Adamski, former Executive Director of U.S. Cyber Command, said organizations should combine patching with attack surface reduction, segmentation and business-context prioritization informed by current threat intelligence.
'There is not going to be a patch for every vulnerability. You have to know your footprint and prioritize based on business risk and threat context,” Adamski said.
Still, even as organizations automate more defensive work, Moussouris warned against cutting roles needed to develop future security leaders.
"If you are cutting out your intern and your entry-level layer of humans and replacing that holistically with AI and automation, you are missing your opportunity to build your contextual bench,” Moussouris said.
IANS Faculty Recommendations
- Treat AI agents as separate identities: Give each agent a distinct identity, permissions scoped to its specific task, and an audit trail showing which tools, connectors and systems it accessed.
- Keep humans in control of high-risk actions: Use AI for high-volume, reversible security tasks, while requiring human approval for actions that could disrupt operations or cause irreversible damage.
- Move beyond patching as the primary risk-reduction strategy: Combine vulnerability remediation with attack surface reduction, network segmentation, and business-risk prioritization informed by current threat intelligence.
Authors & Contributors
Nuria Diaz Munoz, Author - Security Reporter, IANS News
Although reasonable efforts will be made to ensure the completeness and accuracy of the information contained in our News & blog posts, no liability can be accepted by IANS or our Faculty members for the results of any actions taken by individuals or firms in connection with such information, opinions, or advice.