AI Agent Identity Becomes the Next Security Challenge
AI Agent Identity Moves Into the Spotlight
AI agent identity is becoming a critical issue as enterprises start to imagine agents handling sensitive tasks on behalf of people. In this Techstrong TV interview, Mike Vizard talks with Philipp Pointner, chief of digital identity at Jumio, about how organizations should think about trust, delegation and accountability in an agentic world.
Pointner compares an AI agent to an assistant running an errand for a CEO. The assistant must prove who they are, show what they were asked to do and sometimes prove the CEO’s identity as well. That same model applies to digital agents. Teams need to know which human an agent belongs to, what the agent is allowed to do and whether the transaction requires human proof.
Delegation and Traceability Matter
The conversation explores the emerging standards around verifiable credentials, delegation protocols and agent permissions. Pointner notes that many building blocks already exist, but practical implementations are still limited. Most websites and services are not yet designed for agents that need clear signposts, scoped access and auditable interactions.
AI agent identity also raises hard questions about traceability. If an identity proof is shared, organizations must know whether it came directly from the person or from the person’s agent. That distinction will matter for banks, payments, onboarding and any workflow where identity fraud creates risk.
Fraudsters Are Already Using AI
Pointner warns that attackers are adopting generative AI and agentic tools quickly. Fraud operations that once required teams of people can now use bots, scripts and adaptive models to test defenses repeatedly. That makes identity verification more important, not less.
Reusable digital identities can help reduce risk because cryptographic proof stays with the user. Instead of copying and reusing passport scans or face images, businesses can receive verified identity data while the proof mechanism remains under the user’s control.
Start Small, But Do Not Stand Still
The interview also addresses regulation, payments and the need for more agentic security systems. Pointner expects new attack vectors and believes AI will be needed to defend against AI-driven threats in real time.
For security and technology leaders, the practical advice is to experiment carefully. Start with low-risk use cases. Learn how protocols such as MCP might change digital interactions. Give developers room to understand the technology. The worst option is to do nothing, because AI agent identity will become a foundational part of securing the next generation of digital services.
Transcript
Hey guys, thanks for the throw. We're here with Philipp Pointner, who's chief of digital identity for Jumio, and we're having a chat about, well, AI agents. We all realize that they got to be assigned an identity, but that's a lot easier said than done.
Philipp, welcome to the show. Thanks for having me. So we're all wrapped still in the...
Try this again. Yeah. So we're all still wrapping our heads around how all these AI agents will be governed and deployed, but one of the things that keeps coming up is they have identities.
Sometimes that identity might be inherited from a human, and other times, that's a unique identity for the AI agent. But how do we assign all these identities, manage them? Because, well, heck, we can barely manage our own identities today, let alone model AI agents.
So the way I think about identity for agents is I use the analogy of, let's say, the assistant to the CEO. Right? So the assistant to the CEO is going to the bank and running an errand on behalf of the CEO of a company, right?
What do they have to do? So first of all, that assistant has to prove their own identity. So who are they?
They have to prove that they have this task, that they have been ordered to do something at the bank. And then last but not least, in order to do the transaction, they probably also need to prove the identity of the CEO. And so these are really the three things, and it translates to the digital world exactly like this.
So identifying the agent, does this agent belong to Philipp? Is this Philipp's agent? What has Philipp told the agent to do?
What is it allowed to do? And then as part of the transaction, it might require that also Philipp's identity is proven, and there are tools for that as well. So that's the framing of the three things that we need to accomplish in order to have AI agents do very sensitive tasks for us.
Do we have the systems in place to manage identity to that level of depth, or will AI agents require us to revisit the current platforms that we're using to manage identity? There's definitely already a lot in motion. There are standards being developed by the big model developers.
There are standards that come more from open source and the community. So there is bits and pieces of, for example, there is delegation protocols already, where you can define the scope of what you can do. You can take an identity credential, like a verifiable credential.
You can also delegate that so that agent gets their own copy, which is important because at the end, you need to prove, was it the agent's copy of the identity proof that was shared, or was it Philipp directly? And so the traceability and the logging of what exactly happened is extremely important. Where there are still very big gaps is in actual applications.
So that right now this is all theory. And then also for banks or other websites or other digital services to even have these signposts for agents to tell them where to go and which services to talk to. And so if you're looking for a website today that you can send your agent to and do a fully automated onboarding procedure that might involve identity verification, I don't think there's one out there.
So far a lot of theory, a lot of the standards, a lot of the tools, a lot of the thinking of how might this work, but there is no practical implementation at the moment. Will we have scenarios where these AI agents are essentially very rich targets, and I would expect that cybercriminals will, at some point, try to take one over and do something. As that happens, do we need the level of depth you were talking about to prevent that, and how does that happen?
Do I create a bunch of policies and go execute that, or how do I make sure that the thing that has identity is what it actually is? Yeah, there's good news and bad news. I'll start with the bad news.
The bad news is that, for obvious reasons, the fraudsters and criminals are extremely good at using agents and using gen AI tools and the whole agentic world and ecosystem to form their attacks. In the past, what we often saw in the background of the ID photos that we take at Jumio, we saw that these are regular offices where there are people sitting, one desk after the other. And everybody has a stack of fake IDs there, and they get a target for the day, and today we're taking this bank or this financial services company.
And then they try to open as many accounts as they can. What we see now is that this is no longer a office, this is no longer done by humans. This is all done by bots that use scripts and do these attacks repeatedly, and also try to use the very forefront, and sophisticated models that are able to learn and change tactics and try different things by themselves, which is very interesting.
And so that's the bad news is that this technology that we're talking about here is extremely powerful also in the hands of the fraudsters and the criminals. But on the other hand Once we move to digital identity and reusable, portable digital identities that have cryptographic proof mechanisms built in, there's a lot more security and a lot more traceability and a lot more just barriers for attackers to really try to steal someone's identity. Because while you are sharing your information with that business, the ability to prove that is your identity stays with you as the user.
So what do I mean? Today, if you go through an onboarding process somewhere, and you submit a scan of your passport or your driver's license, that photo, alongside probably with your face photo or anything that you had to deliver as part of the onboarding process, now is stored somewhere and sits somewhere. And if somebody gets it, they can use this exact same photo material to act as if they are you and prove the identity on a different platform.
With digital identities, that doesn't work any longer because yeah, you're handing over the information that you are Philipp Pointner, you're born on this date, and this is your address and whatnot, but it's only data. The proof stays with the user because it's a cryptographic proof. And so that's the big advantage that the digital world of identity is going to bring.
Right. In the meantime, is it possible that cybercriminals will attempt to replace an AI agent and have it sit there and behave normally for, I don't know, weeks, months at a time, and then suddenly engage in a lot of malicious behavior and then at a time when it's least expected? We'll see fascinating new attack vectors.
I'm sure there is going to be a lot of creativity in the process. I think this binding of the agent to the human is really going to be the central effect then. So you mentioned that already.
The idea that some agent can prove that it is my agent and I gave the instructions and nobody else, that's really going to be critical. I think a lot of it is going to get back to not attacking these systems because they're going to be fairly secure and with cryptographic proof, but attacking the human element and trying to scam people into using their identities or giving authority for tasks that then get twisted into something else that wasn't the intention. As we put all this together, do you think that the business leaders understand there's a level of risk here?
Or are we so hell-bent on deploying AI agents as quickly as possible that we're overlooking some of the obvious security issues? I think especially when it comes to identity and payments, actually what you see is that it's going quite careful and slow at the moment. So we haven't seen any of the big model providers come out with an identity or payment solution yet that is fully baked into the agentic story.
And so I also think from a consumer adoption, this is going to take a while before the consumers really go, "Oh yeah," go off and buy a pair of blue shoes and I think there's still going to be a human element to controlling the payment. And then in many countries internationally especially, you have regulation about payment authorization that do require a human element. And so a fully autonomous payment or a fully autonomous verification of the identity probably wouldn't be accepted by the regulators anyways.
That might change, of course. Regulation changes. But at the moment, I think there's a lot of countries where a fully automated payment executed by an agent would not be possible because you have to have some kind of a real-time authentication of the user.
Mm-hmm. Where do you think we are with those regulations? It seems like the auditors are playing catch up, but eventually won't they have a set of AI agents that'll just track all the misbehavior of the other AI agents and maybe just email them a fine later?
Yeah, I think it's going to be as always. We now have a lack of regulation. The regulators don't even know where to start and what to do, and there's no clear definitions of what the goals are.
And so then it's going to get overly regulated, right? There's going to be a big swing to just a heavy-handed approach that puts the thumb on everything. And then it's going to inch its way back to more of a middle ground.
That's usually how it goes. So what's your best advice to folks about how to start putting all this in place today? Because it's clear that the business is way ahead of the security folks, so what should they be thinking about and what should they be doing?
I think it's really about experimentation, doing little things, right? Like getting familiar with the concept of MCP servers, trying something out with these new protocols that can basically tell an agent how to interact with a website. There are many good use cases that are not that sensitive where businesses can start to gather some experience and get to know the topic a little bit.
But the worst thing you can do right now is do nothing, because this wave is coming whether you like it or not, and a lot of businesses are going to take advantage. We integrate a lot of different products from different third parties as well into our platform. A lot of these now open fully AI-supported integrations and protocols and MCP servers.
So, that whole new layer to the internet that is now no longer Tailored towards a human looking at a screen, but more an agent trying to interact with a service or product. That is where I would start, is really trying to get to know how this works and what it does and where to start and try something small. Go small, get some experience, and especially get your developers, give them the chance to also gather experience with this.
Right now, it seems like AI agents are designed to aggressively accomplish whatever task assigned to them by any means necessary. So what is your sense that we are ultimately going to be able to secure these things, or is it always going to be some level of risk, and we're trying to figure out what the right balance there is? So I'm not sure anymore, especially with the developments over the last two weeks and the things that we saw with the different security breakdowns and hacking attacks that bots are doing and whatnot.
I have no idea where this is going to end. I think that at the end of the day, you'll need AI to fight AI, and so probably on the security side and on the threat mitigation side, there's going to have to be much more AI that works real-time and looks at intrusions and tries to fight them actively. Almost like we have it in the '80s sci-fi movies where you have one bot who's trying to break in, and you have another system that's trying to keep it out in real time.
And so that's I think where the security side is going. But the bots themselves, whether these guardrails that companies try to put in are going to hold ultimately, I have no idea. I'm not going to make a guess on that.
When you put all this together, do you think that we're going to need a different approach to security? And I ask this question because today we have a mess of tools and platforms and all these different silos. And so is the advent of AI agents going to finally force us to address something that we've kind of been ignoring and living with for the last couple of decades but is far from ideal?
I think there's going to be radical shifts in the way that people look at cybersecurity. The bleeding edge models, they can find exploits. They have now proven that they can work across multiple different machines, right?
So, it's a chain of attacks, basically, that propagates deeper and deeper into systems. Those are capabilities that are going to be very hard to counter with the conventional current best practices. And so I'm certain that our cybersecurity approaches will have to be stepped up and become more agentic as well.
All right. " My view is always from the identity perspective, and what we see a lot is that we now see another big wave of successful scams, where people are tricked into using their identities on websites that are not real, and then the identity is used somewhere completely different to open accounts. And so it's really just the awareness and just the street smartness on the...
If you're on the internet, you have to be a little clever, and you have to be careful with who you give your data to. All right, folks. You heard it here.
Hey, we've been talking about identity as the new perimeter for years now, but think about it. There soon will be, I don't know, billions of AI agents that each have an identity that needs to be secured, governed, and managed. It's a tall order.
Hey, buddy, thanks for being on the show. Thank you so much. And with that, back to you guys in the studio.