A very good morning to everyone who's joining us today. Today, we are going to go through a research that was conducted recently sponsored by Akeyless on what the data reveals about AI agent identity risks. To have a fair assessment of the results, I have with me Calambar. I'll have him introduce himself in a bit. The way we will approach this info this, data and information is we'll go through the premise of the research as well as look into what the data says. And following which, hopefully, I can share some insights based on the conversations that I have with, customers and prospects on Akeyless as well. With that, let me hand it off to Callum to introduce himself, to see what we are going to cover today and also to introduce the firm that conducted this research. Callum, over to you. Right. Thanks, Huresh. Lovely to be here and really looking forward to sharing, some amazing research findings. We've got loads of great data to run through with you today. So using our findings from the research, we'll be able to give you a really clear view of how quickly AI agents are moving into enterprise environments and why that creates new identity risk discussion for security teams. Let's jump into the data then. Great. Thank you very much. So hi again. So I'm Callum. I'm the research director at MRA Research, and I personally have been working in the IT and tech research space for about fifteen years, working alongside leading cybersecurity businesses like Akeyless. And for anyone not familiar with MRA, we're a specialist B to B research agency who work with lots of technology and B to B organizations producing high quality, impactful research and develop data driven insights. So just to summarize this study, the aim was really clear at the outset. We wanted to understand how AI agents are reshaping identity risk. And in particular, we wanted to look at where agents are being used, what kind of access they have, how they're being authenticated, and whether existing governance and identity controls are keeping pace. And to very, very quickly summarize the scope and the methodology, we ran a survey of four hundred IT and security leaders across the US and the UK, and those respondents came from a mix of industries and organization sizes, and they were recruited through a multistage qualification process. So the results I shared with you guys today are not a theoretical view of AI agent security. They're really grounded in what IT and security leaders are actually seeing in their working environments. So with that in mind, we'll start quickly with adoption because that is ultimately the first thing that we need to discuss. So one of the clearest findings from the research is that AI agents are no longer experimental technology sitting off to the side. They're already operating inside enterprise environments. This number on the left-hand side tells you that ninety four percent of organizations report some level of AI agent use today, and more than half say that agents are already deployed broadly across multiple parts of the business. And in IT and tech firms, adoption is even more aggressive with nearly two-thirds who report widespread deployment. And that's really, really important because it changes the way we need to think about this topic. We're not just talking about pilots or isolated innovation projects. And the other point just to note here quickly is this is accelerating. Organizations expect AI agents to grow their usage by another forty four percent over the next twelve months. So whatever the access picture looks like today, it's likely to become even more complex very quickly. And there's a key identity risk that these agents have got, and they're already accessing meaningful data or sensitive data. So more than eight in ten say that AI agents can access that sensitive level of data. And it means that this is the starting point. AI agents are already being deployed inside enterprises. They have got access to sensitive systems and workflows, and that scale is likely to rapidly increase. So, Suresh, I know this is something you're seeing in the market as well. AI agents moving from experimentation into production very quickly. Yeah. I I I want to tell you guys a little bit of a story about our own product journey. When the advent of ChatGPT happened, we started, of course, being a fast moving start up seeing what's happening in the market. We started thinking about how agents would evolve and what sort of solution or product was needed to help our customers, secure agentic interactions. At that time, I would say this was about twelve, eighteen months back. Think, the origins of ChargeGPT. Right? Our our thinking was that agentic adoption broad based within organizations would probably take a year or two. Twenty thirty seven was more likely when it would happen, it has it has surpassed all our expectations in terms of speed of development, the time to market, and how fast agentic adoption is happening. And this data and this is the reason companies like us do this research to get intelligence from what is happening in the market that informs our go-to-market and product development. So this is actually even the large analyst firms like Gartner, they predicted that this was something that would happen in twenty twenty eight and twenty twenty nine, but ninety-four percent of organizations use agents. Eighty-four of them access sensitive data. That is a rapid adoption, and the fact that it is accelerating is also pretty impressive. I do see this, you know, continuing to accelerate, and I do see this as the biggest enabler for enterprises, but also the biggest threat. Callum. Great. Thanks, Harish. Great to have that additional context as well. Okay. So this next question looks at the types of credentials that are used by AI agents or other machine workload identities. And you can see from this chart that the most common answer is API keys. Nearly seven in ten organization are using API keys in this way. But for me, perhaps most worrying me in this chart is that more than half still relying on static usernames and passwords, so you can see the fifty two percent there. And on the right hand side, another headline finding from this research is that every organization surveyed reported using some form of persistent credentials somewhere in their AI agent environment. So this isn't just a marginal issue. It's very common and a very common part of how AI agents are being deployed today. And at the same time, more modern approaches are not yet as widely adopted, so less than half said that they use short lived credentials. So the issue is not simply that organizations are using credentials because, of course, agents need to authenticate. But the issue is that so many are still authenticating with credentials that can live for a long time and become really difficult to track or to control. So, Suresh, we're seeing that this is where the security implications become a little bit more tangible. How do you see the findings? Yeah. This is, of course, one of the most concerning findings, but there's something I would add here as well. Let us take an example of an agent. Right? And let us assume that it has access to some of your systems. In a typical environment, when an agent is tasked with an outcome, it has access to multiple systems. Say, for example, it may have access to employee database. It may have access to a finance system. It may have access to a CRM. It may have access to an on-premise server or application which has to perform the task based on the information that the agent has retrieved. And all of this will require different forms of access. Some will require a database password. Some will require an auth token. Some will require certificates. And so what happens if there are persistent credentials out there is they expose the organization to risk. And this is, of course, most concerning of the agentic interactions because this is happening right now. And for those of you who may not know, I would suggest that you look up the vertical breach wherein a third-party AI, application was being used by an employee internally, and the OAuth token that was used to access the, data sources was compromised leading to, significant risk to the company as well. So this persistent credentials, they accumulate risk over time. They get copied. They get embedded into workflows. They get shared between systems and often remain active long after anyone remembers that they exist. Now that's manageable when you were dealing in a world with a handful of automation scripts, but it's much harder in an AI driven environment where multiple systems are being accessed simultaneously and the action and, can happen in milliseconds. So this is, of course, one of the most concerning aspects that came out of this research. Got it. Thanks. Thanks, Suresh. And as you say, the acceleration clearly, exacerbates this challenge, isn't it? So a second pattern that we've seen in the data is that AI agent development is happening really quickly and often outside of traditional governance processes that organizations are used to. So you can see here that seventy two percent of organizations say that AI agents are commonly being created using prompt driven or AI generated development approaches, often referred to as vibe coding, and that increases the security risk even further. And you can also see that fifty percent of organizations say developers are regularly bypassing IAM controls in order to keep AI agents operational. And what the data really reflecting here from my perspective is pressure. So organizations are under pressure to show progress with AI, to build new use cases, and to get value quickly. And in that environment, these types of teams are making pragmatic decisions to keep things moving. So the risk is not just the AI agents have been adopted. It's that that adoption is happening faster than the security model around it and the security models developing alongside it. So, Suresh, this connects, I think, directly to the operational reality that organizations are facing. Does this finding surprise you at all? Not at all. I mean, let us just go back and think about your respective organizations. When the origins of ChatGPT and Claude and Gemini, you know, most of the teams and functions within your organization start using it. When they started using it, they were using their own budgets assigned by their businesses to go do it. It wasn't going through any form of IAM controls at all. And you know this. I I know this is the way it started with agentic usage started happening within organizations. But then these tools started adding more capabilities, you know, Claude, Covert, ChatGPT, Codex, and then Claude code. And you have from a small experimental agentic project that was funded out of a business unit without IEM controls, without IT oversight has now become a significant issue where you need those controls now. Otherwise, your applications are being accessed by agents and your systems being accessed by agents, and you have no control of what agents are accessing which system. And I I I wouldn't say this is because the IAM teams and IT is callous. It's because AI projects often started as these small experiments and now have grown into these, business critical workflows much faster than the governance processes could adapt. The challenge is that these shortcuts taken early, now have become permanent parts of an environment. This is a this is a, in my opinion, a wake up call for IAM organizations. Yeah. Absolutely. Couldn't agree more. So the next bit, if we just build on that, we can think about visibility. AI agents are becoming more widespread, and organizations are struggling to maintain a complete view of the credentials and secrets that those agents rely on. Now on the left hand side, we can see that as few as forty four percent say that they know where all of their AI agent credentials or secrets are stored. And what that means, if you flip that, that means more than half cannot say with confidence that they do know where all of that is, which to me is absolutely staggering. And at the same time, we can see on the right hand side that credentials are being stored across a wide range of locations such as dedicated secrets managers, cloud provider native services, configuration files, application codes, CI/CD tools, and even in some cases, hard coded or embedded directly into workflows. So to build on Suresh's point, the more dispersed those credentials become, the harder it is to answer the basic those basic and critical questions. So what credentials exist? Where are they stored? Who owns them? Which systems can they access? And what would need to happen if one of those was exposed? So this is really where it becomes both a security challenge and an operating challenge. And, Suresh, I've described this as staggering, but how do you see this one? Oh, this is the most alarming statistic, but here is the interesting piece to this. This is a problem that existed before the agentic era and has been exacerbated by the agentic era. What I mean by that is before Akeyless was this unified identity and identity security platform for machines, AI agents, and humans, we had our origins in the world of secrets management. So we have seen the issues associated with secrets sprawl, secrets being embedded in code and configuration files, and not being stored or managed centrally, not being rotated automatically. And all of this has now been amplified as a function of an agent. Think about an agent doing a task as a hybrid of a human and a machine, tasked with the same level of responsibilities. It has just exacerbated the problem. If it is true for Gartner that seventy percent of all enterprise applications eventually will be some form of agents, we have just exposed this problem significantly. It's going to increase the risk manifold. It becomes more important than ever that agents don't have direct access to the systems, and, they only have just in time ephemeral identities and access only when they need it, only for the task that they need to complete. It's critical, I would say, a foundational element of planning that needs to happen going forward as agentic adoption and enterprise, become more mainstream. Absolutely. Thanks, Resh. So we also asked our organizations about what concerns them the most when it comes to AI agent security, and nearly all respondents believe that AI agents do introduce new security risks. And what stood out is the nature of those risks. So you can see from this chart that the top concerns are not only about AI behavior in a more abstract sense. These are very practical identity and access concerns. So organizations are worried about secrets or credentials embedded in AI agent workflows. They're worried about detecting compromised agents. They're also worried about accessible unmanaged access to systems and data. And as we just discussed on the previous slide, they're worried about poor visibility into what agents can access once they are deployed. And that tells us something really important. For many security leaders, the AI agent risk conversation is actually starting to move into an identity conversation too. And, Suresh, I know you've got a perspective here of why organizations are quite rightly becoming concerned. So what are your thoughts on this one? I was just looking at these graphs, and I was looking at the access that has what are all the reasons for the risk. And what I find interesting here is that the concerns are overwhelmingly identity related. Organizations aren't primarily worried about these terms that they used to hear at the early stage of, the evolution of AI agents was either the model performance. I've heard about prompt injection as an inch issue. I've heard about agentic hallucinations as an issue. That's not what you see here. I mean, what the research suggests, it's, hey, it's about access. It's about permissions. It's about credentials. It's about visibility. That's consistent with what we are seeing in our customer and prospect conversations as well. And, OWASP, the nonprofit agency for application security, released their top ten for agentic applications. Please go review that as well. That I found it very insightful. And they identify that identity and privilege abuse as one of the core risks facing agentic systems. Now, of course, the reason is simple. Agents are increasingly operating with legitimate access. They inherit permissions, use delegated credentials, and interact directly with business systems. The challenge becomes understanding what an agent should be allowed to do and maintaining control once that access has been granted. Because even with a legitimate access, an agent can take destructive actions. Right. And we so we've talked a little bit so far about the outline, how the the land lies, and then we've talked a little bit about some of those concerns. But we also wanted to understand whether those concerns are still theoretical or whether organizations are already seeing some signs of those AI agent related security issues. And from the data, what we are seeing is absolutely that those risks are already materializing. So on the left hand side, you can see that two thirds suspect AI agents have already accessed data beyond their intended scope and emphasis on the word already there. More than six in ten have already had to revoke or rotate AI agent credentials because of that suspected exposure. And furthermore, the thing that hit me straight between the eyes was organizations report spending more than a million dollars on average over the past year responding to AI agent identity and credential issues. So, ultimately, the data is telling us that many organizations are already experiencing the operational and, perhaps more importantly, financial consequences of managing AI agents with limited visibility and control. And, Suresh, this is where we start to see that risk becoming to feel very, very real, and then not just what agents might do in the future, but actually what organizations are having to respond to right now. Correct. I mentioned earlier in this presentation that AI is the biggest enabler and risk to an autonomous enterprise. And what I mean by that is you can't not adopt AI. You have to be live in a world where the productivity benefits of AI as well as what it can do vastly the benefits of it vastly outweigh the risks, but it has to be done in a way where the risks are managed. And if not, it could be, lead to destructive consequences for the enterprise. This is this is very tangible data. And, as we do, we usually conduct these surveys, years out so we can look at how the data is changing. Continue to work with folks like Callum to doing that. I suspect I forecast that next year when we do this research, that one million is going to be much higher. I think we are just scratching the surface of, enterprises determining what it costs to fix those issues. I believe most of the issues are yet to be identified. And I believe as the scale of adoption as we saw in the previous slides of AI continues to grow, the risks associated with it will grow. And now is the time to actually invest in the systems to secure them so this cost doesn't go up as well. I want to, you know, just talk about one more incident. This is the pocket of us incident that was also on the news. Please search for cloud and pocket of us, and you will find what this incident is about. But in a nutshell, what this is is clock powered coding agent. What it was not supposed to do this. It was supposed to work on some other aspect and task, but it deleted the company's entire database in nine seconds. Now it had legitimate access. It had it had complete authority. There were principles dictated, to it that it is not supposed to do it. But in the process of attempting to complete the tasks, it that deleting the database was the easier way to go about completing the task. It violated the own principles given to it. What this means is the world of deterministic policies, what an agent can do and cannot do as predetermined aspects, and what it can access and cannot access predetermined. Is the the is is would that work for the world of machines and humans? What work for the world of agents? And that is what we are seeing in these bridges. Great. Thanks, Rasha. Like you said, it'd be really interesting to see how these findings change as the pace is continuing to accelerate. Another really clear finding from this research is that existing identity and security controls are struggling to operate at the speed of AI systems. So only seven percent of organizations believe that their current controls would prevent a compromised AI agent from operating or behaving maliciously, and another thirteen percent say that they could immediately detect a compromised agent. So that means the vast majority would not identify a rogue or compromised agent until it had already started executing. And you can see from the middle of the right hand side here as well, the timing gap is really significant. On average, organizations estimate it would take about fourteen hours to detect a compromised AI agent and then nearly an additional six days to contain and remediate the incident. So that's a very, very different time frame from the way that agents actually operate in real life. And AI agents can take actions very quickly. They can chain tasks together, move across systems using legitimate credentials or approved access pass. So that really does put put us behind where we need to be. So, Suresh, can you share a couple of your thoughts and experiences on existing approaches? So as I look at this data, this is where I feel that the IAM approaches that we have today are starting to show their limitations. To rewrite back, the traditional IAM was built around humans. What I mean by that is users logging in, requesting access, performing relatively predictable actions, what they are supposed to do, what they are not supposed to do. And as I mentioned, a few minutes back, agents don't behave that way. They can chain together dozens of actions across multiple systems in a matter of milliseconds, often using legitimate credentials, approved access paths. The problem is no longer about authentication. The problem is what happens after authentication at run time. Once an agent has access, organizations need a way to continuously evaluate what it's doing, whether its actions remain within policy or whether something needs to be stopped before a district of action or damage occurs. That's why we are seeing this, growing interest in this term run time control and continuous authorization rather than relying solely on the access decisions made at the beginning of the session. Right? And it's, it's it's what matters at run time more than what was dictated to the agent upfront in terms of what it can access and what actions it can take. Great. Thanks, Suresh. So I've just got one more, finding for you today, and this just is one that really stood out is that organizations are not ignoring these challenges. So with this slightly more futuristic look, we see that ninety seven percent say that they do plan to strengthen AI agent security over the next twelve months. So this is really not an awareness gap at this point. It's the organization can see the AI agents introduce that different kind of security and access challenge. But the bigger question is then how do they respond in a way that allows them to scale AI safely? So, Suresh, that feels like a good point just to pass over to you for a summary on your side of the findings and what you believe those priorities should be to organizations. So so when I look at this so this is exactly the findings that that that came from our early customer inquiries when agent pick adoption started almost eight to twelve months back that led to us developing our agentic security products. So it's clear it's pretty clear. Right? You can't go on any agents if you don't know they exist, what they access, or who wants them. So the visibility becomes a factor. Then they need to reduce reliance on persistent credentials. We talked about why that is an issue. That has been an issue even before the rise of the agents' secret sprawl and and credentials in code and configuration files. And now agents carry those credentials and can access multiple systems, in milliseconds and can also, you know, they can also be revealed through prompt injection. They can be, coaxed into sort of sharing what the credentials are. The controls need to extend beyond authentication and into runtime. We talked about why that runtime factor is important in the world of AJA agents as well. And finally, they need clear ownership and accountability just like any other identity operating inside the organization. Now we we need to take these together. They aren't four separate projects. They are a foundation of an identity model built for autonomous systems. But now that you are at the at the last of the findings of your data, hopefully, I can take a couple of minutes to to tell our audience about how we can help with this. So if they have these challenges, we are happy to help. Akeyless recently announced what we call agentic runtime authority. And what it basically does is you can see some of it in the screenshot where you see fourteen active sessions. You can see all the active sessions that your agents are having. You can see the actions that they are taking, a risk score associated with the actions based on the resources they're that they are accessing. You can block requests automatically using both deterministic and nondeterministic policies. And what I what I mean by that is your deterministic policies are your r back and a back and predefined policies. And nondeterministic is an intent based engine. And if you go back to the example of the pocket OS where it delete where where a database were deleted, assume that word. But in this case, when the agent decides to delete the database, there is an intervention that would happen if they were using agent equivalent time authority that would have asked or tried to determine the intent behind the need for deleting the database. If it finds out that, hey, it is because the agent is trying to bypass the requirement to complete the task and it determines that the database is too critical for that for that intent to be bypassed, it will block that action. It will alert the administrators, and it happens at run time, which is what, is a critical aspect of the nondeterministic policies because they are going to behave, they're gonna hallucinate. They're going to take actions with legitimate access, and we need the ability to block suspicious activity based on dynamic AI based policies. And, of course, there's an aspect of, the full forensic audit and traceability. What was prompted? What was asked? What was the response? Why was it blocked? And you need to see be able to see this in run time, in real time, not after the fact, not a postmortem. And this is what the Akeyless agent to grant time authority will enable you to do as well. And, why don't I, ask Callum to help summarize the key takeaways, and then we will open it up for, Q and A. Yeah. Great. Thanks, Suresh. So if I just pull together some of the main threads that we've spoken about today. So for me, the first takeaway is that AI agents already have access to sensitive systems, data, and workflows, and that's not a future state issue. That's already happening in meaningful parts of the organization. And the second takeaway is that the identity model has not fully caught up. So organizations are still relying on persistent credentials, fragmented controls, and approaches that were largely designed for human users or more predictable machine workloads. The third point is that risk is already showing up in practical ways. So respondents reported that they suspected unauthorized access. They, experiencing credential exposure, and they've already faced significant cost and effort tied to remediation. And the final takeaway for me is the positive side of the story. Organizations that modernize identity controls will be better positioned to scale AI securely. So the message from the research is not the organization should slow down or avoid AI agents. It's the the identity and access model needs to evolve alongside them. And that really was a snapshot of the research. So if you if you found those interesting, those findings interesting, there's a full report on the Akeyless website to to rub it through as well in your own time. But with that, I'll move on to the q and a. Just before we jump into the q and a, there is a q and a panel. Please ask your questions there. I see three of them already popped up. I'll go through those, but I wanna take a moment to thank Callum and the MRA research team for this, research, conducted in big markets like US and UK where agentic adoption is actually at its peak right now. And this is, this is not just for, companies like us to inform our go to market and understand what is happening in the market. I I hope sharing this research with you also helps, opens, some insight into what your colleagues are doing in the IT and security space and what you can learn from this as well. Now let's jump, into questions. Let's see what the first one is. My organization already uses Okta. Why isn't that enough for AI agents? Now, generally speaking, I respect all competition. Okta is a great company, so I just I don't want to specifically get into, any criticism of Okta. But, what I would say is I'd go back to this conversation that we had on, systems built for humans versus systems built for machine slash agent taken AI agents. Right? The challenge is that AI agents don't behave like human users. They are ephemeral, autonomous, and they often exist for seconds, maybe even milliseconds rather than years. And they can also spin off sub agents, the agents that are created in run time to take a specific action for that agent to complete its, task. Traditional IAM has always assumed that, you know, you have the inventory identities, assign permissions, govern them through a directory. Now that model worked well for employees and users. It has become much more harder when agents can be created dynamically. As I said, they spawn sub agents and disappear even before anyone knows that that they existed. Right? That is a completely different world from a more structured registry based approach to identity and access management. More importantly, authentication is in the hard part. An agent can have a perfectly valid identity, a perfectly valid token, and defined set of rules and can still take an action that you never intend. The question isn't just who is the agent, what is the agent trying to do. It it is more broader than that. It's what the agent can do at run time and how do we evaluate based on intent and block it. And that is the that is the systemic difference between the the products built for the traditional human IAM world and the products being built for the the ones like agent to grant time authority that we are building for the the the emerging challenges with AI agents. K. Next question. I believe, Karen, this is this could be for you. Which finding surprised you the most? Why? Good question. So thing that probably surprised me the most was we had the stat earlier. Sixty percent of organizations suspect that AI agents have already accessed data beyond their intended scope. And for me, that was a really, really remarkably high number, especially considering how early we are relatively in that AI agent adoption cycle. It suggested that organizations aren't just worried about future risk. Many believe they've already seen signs of agents operating outside of those intended boundaries. So what's interesting is that it doesn't necessarily mean intentionally malicious activity. It may simply be how difficult it is to define, monitor, and constrain agent behavior once agents are interacting across those multiple systems and data sources. But it also highlights that broader challenge. Many organizations lack confidence that they can fully observe what their AI agents are doing after access has been granted. So that is definitely something to keep an eye on as we continue to see the AI agent rise continue. You know, there there are there are two things that surprised me about that statement. One is, of course, the sixty seven person number, but the other was that sixty seven percent of organizations suspect agents have already accessed the data, which means that they don't yet know, yeah, how how much of the data they access. They still don't have visibility into that. There is a suspicion that this may have happened, which is even more concerning because the systems don't exist to actually know what happened at, run time and what behaviors happen. K. Let's move on to the next one. What's the biggest mistake organizations are making when they start deploying agents? This is a very common question when when when someone in the prospects that they talk to, they want to know what others are doing. So they are asking these questions to us as well. Maybe going by, hey. What did we are talking to a pharma company. They wanna know what did another pharma company that because it's also our customer do for it. I'd say that there is a lot lot to say here, and there are more qualified people to answer this question. But I would say that, you know, the biggest thing to avoid doing is treating AI agents like software instead of identities. We have already done that world of software that has there has been software related code security. There is SaaS security. The the systems for the software world were built. Don't make the mistake of assuming an agent is another SaaS application. I know this is you know, many of you will already agree with it, but this is something that is still out there where people believe that the technologies that were built for applications and even machines could be used in an agentic world. Machines certainly has some of the behavioral characteristics that can support it, but it doesn't we even machines and access are predefined on what they can access, what they can control, and then as an agent can take access with can access and make decisions with legitimate access controls and approved authority. So it's important that we don't treat them the same way. Agents have credentials, permissions. They have delegated authority. They access sensitive information. So if you don't establish ownership visibility, access controls, all these issues become harder to solve later. The biggest lesson from this research in general is that identity should be a part of the design process and not something that you add after the deployment. And that's why even this data research centered around the agentic risk with identity. Looks like those are the questions that we have for now. Calum, I wanna take this moment to thank you and your firm again for this research, very professionally done with a lot of big companies and what's happening in the industry. Lot of surprising findings for us as much as we have conversations with customers and prospects. The volume of data and amount of information that researchers like this provide is always insightful. And I hope all of you here, these are actually research and results, that, that are from, your peers and organization like yours that are connected. So, hopefully, you took away some insight into this as well. And, of course, I agree on this if I don't say if there is any way Akeyless could help you solve these problems and challenges with our agentic authority product and our underlying machine identity foundation. Please, please, explore our solutions at the Akeyless website. Request a demo. We are happy to help. Thank you, Calum. Thank you, team, for joining. Thanks, Suresh. Thanks, everyone.