Akeyless at AWS Live 2026
Hello, everybody, and welcome back to AWS Security Live super special edition where we are coming to you live from Black Hat USA in Las Vegas, Nevada, where we are protected by air conditioning in this beautiful exhibition hall. Outside these walls, it’s about seven hundred and sixteen degrees Fahrenheit. Rounding down. Rounding down. Yeah. I’m one of your co hosts for the day, Ryan Orsi. And I’m at AWS, and I’m one of the security specialists go to market leaders here. It’s a mouthful of words, but it means we get to have a lot of fun talking security with partners and customers all day, every day. I’m joined by my other cohost here. Christopher Wray. I’m also part of the same team, and I look after AI security go to market and helping customers be able to secure their AI workloads and also leverage AI for improving security postures and operations. And you’re crazy enough to live here as well. Indeed. We are joined today by, Akeyless Security, specifically with Yale. And we wanna talk to you about your background. How did you get into this? And give us a little bit more about Akeyla Security as well. Hi. And thank you for having me. So I’m Aiel. I’m chief strategy officer at Akeyla Security. I actually started my way in security about twenty five years ago with hardware security for video, protecting guys like Direct TV and Comcast from video piracy. That was my background as well. Oh, so we must have met at the other parts of the I think I might have been on the other side. Exactly. I’m sure many people here have been there. It was you trying to stop. That’s why the the lines started to come in and Exactly. And black screens. Yeah. Were you watching? All the fun away. Sorry. Somebody needs to protect the revenues of these guys. So I that’s where I kind of started my way into security. And then after many years there, I joined CyberArk and kind of came familiar with the the whole identity security for the enterprises where privileged account security became more important and more strategic where the big attack started and kind of fell in love with identity security and with the agentic challenges that we are having now. I think, I strongly believe that identity is one of the big pillars to security enterprise. Well, we were channeling, Christopher, we were channeling our AWS, like the internal security people that handle our own security operations, and we were channeling them, they would say thank you, because they would I think they would agree. Like, identity attack factor is usually where most of it begins. Yes. Either begins or they take advantage of of it at some point of the attack. Right. Right. Makes bigger. So I think that kind of leans into a question here, which is that a lot of the things that people are concerned about with agentic security are really just bad human behaviors that are now being done at speed and at scale. Is there anything else that people should be thinking about as they start to think about building out agentic workloads that is in addition to these previous behaviors that they were already dealing with for decades at a time? Sure. So I would say that while we, as a security industry, kind of learned over the years that hard coded credentials and giving the machines or the humans access to credentials and to sensitive systems is dangerous because that’s what attackers do. For some reason, we’ve forgotten all about it when we’re using agents. So many people apparently are use are copy pasting credentials into the prompt, into the memory, into the environment configuration. And it’s like, that’s heaven for for attackers. So my first message would be, just don’t give them credentials. Make that you keep your hygiene and your basic rules of security when you build agents. And it’s actually quite easier to do with agents because there are a lot of plug ins and security measures that make it much easier. Please don’t be pasting in hard coded credentials into your Your API key is Yes. Don’t do that. But then there’d be What’s the answer to that, Yael? Is it secrets management? And how has secrets management evolved from humans interacting with, let’s say, a web application versus agents interacting with tool sets that might call other agents? Yeah. So I would say that the basic problem of a thing, an entity, whether it’s a human, be it a machine, be it a agent, needs to access the enterprise system, whatever that may be. It’s it’s a basic problem, and that’s what secret management and more advanced like identity security is built to to solve. Whether it’s rotating the credentials for systems that you can’t do dynamic secrets or doing just in time access with least privilege permissions. That’s the basics. Right? What everybody should be thinking about. Our what we’re seeing that with AI agents, given the speed that they operate and given their ability to look for stuff and be very creative, we would say that that calls for an additional layer of security. So not just giving them just completely removing access and visibility to credentials from agents. So really brokering or kind of being the isolating them from credentials. So they don’t really have access to it at any point of time for how long ago. Of course, fifteen minutes for just in time is a world for an agent. That seems like persistent credentials in my opinion. But okay. So the the never heard agents should never have access to credentials ever. But they need access to things at certain times. And what’s a good length of time? Fifteen minutes is too long? I’m sure there’s like a depends answer here, but what’s the majority of your perspective? So the just in time aspect definitely needs to change based on the access, the pattern, and what they need to do with factoring into it. Agents operate very quickly. So what you really need, you need a way, a platform that can issue those just in time identities. It’s not even just credentials. It’s really factoring the permissions. And doing that on a scale to all the target systems. Because as you know, most of the just in time capabilities today are really limited to OAuth systems or modern systems. But really for agents, you have to do that for everything. So your databases, your SaaS applications, everything needs to be kind of just in time identity with the permissions and the ability to not even give the agents the token. So that’s kind of level of protection we’re talking about. And when you have a platform that is able to do that at scale, then it’s doable. And it’s it’s actually much simpler than people think to solve it. And the impact is huge. There’s always a way to write to log somewhere, right? Because I imagine as this happens, we need to be thinking about data lineage and also some governance concepts here. Governance and compliance, much as anyone would like to avoid talking about it, it’s a real thing now. Especially if you’re a larger company and you’re beholden to certain regulations, you need to keep that paper trail or digital trail here of what your agents are up to. Exactly. So while the builders out there would say, well, it’s just one secret that needs to connect to one database. So what’s the problem? Like, you know, it’s got to be fine. Chill out, man. Yeah. But when you look at an enterprise and kind of not too big of an enterprise customer for us, would have like twenty thousand secondrets connecting to fourteen thousand systems and that’s without AgenTix. So when you account for double the number of of agents and the speed that they operate, it’s a massive, massive problem. And therefore, you really need one platform where you have central policy that you can enforce and also a record of what identity interactions and what secrets were used. Making sure that they don’t sprawl, so they’re they’re not spreading. But also that you have interact like, audit trail of what the agent was doing. Not what it was intended to do, but what it actually did. And that is something that once you’re kind of in line between the identity kind of gateway all the way to the target system, you can do. And that’s the place where security the security folks in the audience should be worried about. Hundred percent agree. I think that’s what very well said. Now tell us, Yael, there’s you you said security folks. There’s also non security folks that make decisions in these companies. Right? And there’s the constant can be a divide or just like a confusion of translation between security lingo and business risk and business investment lingo here. But what would an executive need to put on, say, like a presentation slide if they’re talking about this this story about agents and keys and going going going like full full into the agentic universe here, but doing it securely? What should a CISO or like a CTO tell their board? Well, you start with the normal security strategy by scaring everybody. And that’s easily done because all the recent attacks with AI agents and without AI agents, they they use that. I mean, they use credentials. They use over privileged agents. And it’s very well documented and very easy to show how keeping the hygiene and keeping the secrets away from the agent can, in many cases, prevent, but also mitigate and contain an attack once it’s happened. So the business case for securing credentials and actually going secretless with with AI really not giving them no visibility, no access to credentials, kind of presents itself. But then you need to manage the, of course, the kind of objections or the builders are saying, well, you know, I need something that can move fast. I need something that is usable. And on that front, I think the industry has moved quite significantly and with a lot of integrations with Bedrock and with the other agentic platforms, it is way easier today and much simpler and actually less friction because you don’t have to define what you have access to. You don’t have to copy paste credentials. You just say, I’m going via this secret or this identity security platform and they take care of everything. So you have the audit, you have the secret list, and you don’t have to worry about that. And nobody will come to you and complain that you are the reason why the company got hacked. So I think a lot of developers would probably say, well, I can just build that kind of check-in the MCP server itself. I don’t have to have this whole harness around that. How would you respond to that? And how would you show them that it’s actually easier to go through this with Akeyless? So I would say the MCP is a great platform. It’s a great protocol, but it doesn’t deal with credentials. And actually, if you look at the recent data, it shows that a lot of credentials are leaking from the MCP servers themselves. Because people think they solve the problem by by kind of pushing it down the the line to the MCP servers, but that doesn’t solve the problem. It just actually makes it more central for the hackers, so can they can go there and and and take the the credentials. So I would say and also MCP is just one path that agents operate. They many of the agents don’t use MCP. So you need to make sure that you’re protected no matter how the agent, where it was built, however it operates, and whatever it communicates with. It needs to have this basic layer of protection and that is don’t give them credentials. Keep the humans away from the keys. Keep the agents away from We’d probably be eighty percent better off. Yes, absolutely. Hey, Yale, I’ve I’ve I’ve heard of a demonstration that you might want Yeah. To bring it to life here. The viewers online typically love demos. If you’re all watching still and are in front of the chat and the YouTube channel there, please get ready to fire some questions. But let us know if you want walk you Sure. So before I show you the demo, I just want to kind of lay out the scene. So it’s an agent that was built with Claude that needs to connect to AWS resource. And it uses the AWS IAM role to do that. And we’re showing the console because this is where we can see the interaction between the kind of the agent and the identity security platform. But normally builders would use CLI, would use other tools to do what I’m showing that we’re doing. You can play the demo. And what you’ll see here and what we’re trying to show is that it’s really simple. So what you see here is the Akeyless console where you would go and define the target system that you need to connect to and what IAM role it will have, what restrictions you want to apply. In this case, we wanted not to deliver IP addresses. So Okay. To kind of mask information, sensitive information. We’re giving the agent access based on roles. Not always do you have to predefine. We can use the role in order to give the the the permissions on the fly with a comment of what was said earlier. This is how the kind of developer again, we’re going browser just because it’s easier. All you have to do is say, go through Akeyless. So you don’t have to do anything. It’s really anything to do with credentials and permissions, go to Akeyless. And then you ask the agent what how can you connect to the systems? And it will tell you, I only have I only can access Akeyless and Akeyless take care of everything. Connects me to the systems. And you know that the agents look for it, right? They look in the memory, they look everywhere. So if he couldn’t find it, he couldn’t find it. It’s not there. And when you ask him what credentials you have access to, he tells you that he has this dynamic secret to this AWS resource, but he doesn’t have the value. He just knows that it has the And when he tries to do the task of really performing the action on the e on the e c two target, it performs the action but without the IP addresses. Right? Because we because we sit in line and we see what he asked for and we give it the identity to perform it, we can mask the information and give, by the way, the auditors and the security folks, hey, he asked to do this. But you mask it in the We masked it and we didn’t allow it to do this. So you have a full audit trail of what it was, what actions were performed. And if the agent will try and escalate, like move to another Yeah. That we it can’t be, you know, it wouldn’t be allowed. If it’s if you try to to do anything else, we just say, sorry, you you can’t do that. Because we see it in the enforcement layer, we’re able to to do that and give the builders what they need in order to move fast and but move in a risk free way. And the security folks to give them the visibility, the central audit and control, and the ability to control what the action is what the agent is actually doing. And I know you just showed this in the example of clogged code, but this is totally model agnostic because this is having a completely different layer. So as customers are getting there with like, let’s say Bedrock and changing out models every five seconds, this is a consistent control across however they’re building it. It’s a consistent control. What we build is a platform, that is able to By the way, of course not only AI agents, right? I mean, you have humans, you have tons of machines. I just looking at that demo, Yale, thinking, well, that’s great for a human developer as That’s not. Not just an agent. So that’s what the platform does. And this is why we already had the infrastructure to enable agents for it. What we needed to do is to add all these connectors to, of course, Bedrock and and the different agentic platforms, kind of leveraging the trust that already comes when you develop based on this. So in this case, AIAM AWS AIAM role gives us the trust and the role. So we understand where it’s coming from. We can attribute that to the user. So what auditors are looking for is the attribution. So knowing Down to the user even. Down to the user. Wow. So you have the full trail from prompt to action Yeah. In one place. And it can be trusted because it’s not It cannot be manipulated by the agent. It can’t be It’s a it’s a trusted, super protected kind of a place for you to have the full audit trail for everything that’s been I’m actually really curious, Eyal, about what you said that, like, the auditors wanna trace down to the human. And then, of course, the agent needs to be audited down to sort of where its intended actions and data access were intended to be. Because I imagine, for instance, someone in finance looking at financial data is acceptable. But someone in maybe product marketing or just tech support maybe shouldn’t be looking at financial data. Correct. How are you seeing Are you seeing it like the lines blurry here with the agents kind of like sprawling out a bit of what they’re supposed to be doing? Yes. So I would say that we talk on builder We’re about builders. We’re talking about the people here. But actually, everybody becomes a builder now. So the marketing, the finance, and they’re not as well educated, I would say, about security risks. And they’re not they’re used to accessing applications, SaaS applications, like like humans, and have read permissions and all of that. But when you talk about building automation with AI agents to just using the data on these applications, customers are worried about two things. One, you need an API key. And what these guys are doing are copy pasting APIs because they are not aware that you shouldn’t do that. So that’s one thing. And the second one is they don’t want to give them the full permissions on behalf of. So if a human has set one set of permissions when it accesses a marketing or a finance database, they don’t want to give the agent the same permissions. They want a subset of it. So what we’ve done in our platform, because we are creating those identities that factor both the secret and the permissions, we’re able to take the permissions that the user already have, role based, attribute based, and build another layer on it which is restrictive. So Yeah. Give them the subset of it and allow them to perform their action. And this is how you also make sure that somebody from marketing doesn’t have access to financial information or maybe they have access to financial information in one region and not another. Yeah. So all of these granular kind of controls on the activity level is something that you can do once you’re in line. I think I think you get it, Yael. And I think actually you’d be might be shocked, but we’ve asked many people that question of whether the agent should assume all the permissions of the human. You just clearly said no, a subset. I love how simple and quick the answer was. It’s what we’re hearing from customers. We didn’t invent it, right? I mean, it’s what our customers are saying and they’re big enterprise that are worried and are educated about security, but adopting AI very, very fast, which is amazing to It’s fun to see how they do that. So definitely there’s a way to do it, but it’s it’s it’s important to get it right. Well, fantastic. Yael from Akilas, thank you for joining us on security Thank you for having me. We’ll we’ll check back with you later in the year, see how Akilas is doing. And folks, be right back with more security live from Blackhat. Take care.
This video, broadcast live from BlackHat USA with AWS Security LIVE! featuring Akeyless CSO Yael Fainaro, explores the challenges and best practices for securing agentic AI workloads in enterprise environments.
The Rise of Agentic Security Risks
- Many AI agent risks stem from familiar human security mistakes, but agents amplify them by operating at machine speed and scale.
- Developers may expose credentials by placing them directly in prompts, environment configurations, or agent memory.
- Once exposed, those credentials can give attackers access to sensitive systems and data.
How to Secure Agentic Workloads
- Keep Credentials Away from Agents: Avoid giving agents direct access to long-lived or permanent credentials.
- Use Just-in-Time Access: Provide short-lived, least-privileged credentials only when they are needed.
- Broker Agent Access: Place a security layer between the agent and the target system so credentials remain isolated and permissions can be tightly controlled.
- Keep Controls Model-Agnostic: Apply security independently of the underlying AI model so controls remain consistent as organizations adopt or switch models.
Governance, Auditing, and Compliance
- Centralized governance is critical as the number of agents grows and manual oversight becomes impractical.
- Organizations need complete audit trails that connect agent actions back to the user or identity that initiated them.
- As more employees build AI automations, agents should receive only the permissions required for a task rather than automatically inheriting the user’s full access.