What happens after an AI agent presents valid credentials and enters your business systems?
In this episode of The Business of Cybersecurity, I speak with Spencer Young, Senior Vice President of International Markets at Delinea, about why authenticating an AI agent is only the beginning of the security challenge.
Spencer has spent 34 years in IT and around half that time in cybersecurity. His experience covers secure software development, vulnerability testing, application protection, data security, and identity security.
Our conversation begins with the changing economics of cybercrime. Spencer says attackers increasingly prefer stealing or compromising legitimate credentials because logging in can be cheaper, faster, and easier than forcing a route through network defenses. He estimates that over three quarters of attacks involve a compromised credential somewhere in the chain.
AI agents add speed and scale to identity risk. They can access applications, databases, financial systems, development tools, and infrastructure while performing dozens of actions during a single session.
The danger is not limited to an agent being denied access. An agent may be fully authenticated and possess valid permissions while taking an action the organization never intended.
Spencer offers the example of a finance agent created to support payment processes. Hidden or manipulated instructions could cause it to change payment profiles and redirect money while appearing to operate as an authorized identity.
This is why Delinea is focusing on runtime authorization. Rather than approving an agent once and allowing every subsequent action, the approach evaluates each proposed tool call, database query, or SSH command before it runs. The action can be allowed, blocked, or referred to a person for approval.
We also discuss how least privilege applies to autonomous systems. Spencer recommends providing credentials only at the moment an agent needs them, limiting access to the specific task, and revoking those privileges immediately afterward. The agent never needs to see or retain the credential.
The research figures Spencer shares reveal a concerning difference between confidence and control. He says 80% to 85% of respondents feel confident in their ability to discover nonhuman identities, while only 30% validate nonhuman identity use and AI activity in real time.
Delinea now works with over 9,000 organizations, including over 60% of the Fortune 100. Spencer says regulated industries frequently demonstrate greater identity security maturity because external requirements encourage continuous controls rather than reactive incident response.
However, technology cannot decide an organization’s risk appetite. People must define what the agent is expected to do, which actions require approval, where it must stop, and who is accountable when something goes wrong.
Could your organization detect a properly authenticated AI agent taking an inappropriate action before that action executes? Listen to the episode and share your thoughts with me.
Suggested URL

