This discussion at Black Hat 2026 examines securing artificial intelligence, AI agents and evolving identity controls. Art Gilliland of Delinea, chief executive officer, discusses Delinea’s approach to protecting sensitive assets as AI agents become operational actors. Krista Case of theCUBE Research, principal analyst and practice lead for cyber resilience and security, hosts the conversation covering agent behavior, differences between human and machine identities, just-in-time credentialing and the need for in-path authorization to preserve productivity while maintaining controls.
Gilliland emphasizes that traditional identity and privileged access models must evolve for autonomous AI and that runtime just-in-time authorization should govern actions rather than static access. They stress differentiating agent versus human interaction, protecting critical assets and logging every call for auditability. Case underscores theCUBE Research finding of a confidence paradox in which organizations report high readiness despite limited agent controls, and they highlight the practical steps security teams can take to improve identity governance and runtime authorization for AI agents.
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
Black Hat USA 2026. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Register for Black Hat USA 2026
Please fill out the information below. You will receive an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for Black Hat USA 2026.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
Black Hat USA 2026. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Sign in to gain access to Black Hat USA 2026
Please sign in with LinkedIn to continue to Black Hat USA 2026. Signing in with LinkedIn ensures a professional environment.
Are you sure you want to remove access rights for this user?
Details
Manage Access
email address
Community Invitation
Art Gilliland, Delinea
This discussion at Black Hat 2026 examines securing artificial intelligence, AI agents and evolving identity controls. Art Gilliland of Delinea, chief executive officer, discusses Delinea’s approach to protecting sensitive assets as AI agents become operational actors. Krista Case of theCUBE Research, principal analyst and practice lead for cyber resilience and security, hosts the conversation covering agent behavior, differences between human and machine identities, just-in-time credentialing and the need for in-path authorization to preserve productivity while maintaining controls.
Gilliland emphasizes that traditional identity and privileged access models must evolve for autonomous AI and that runtime just-in-time authorization should govern actions rather than static access. They stress differentiating agent versus human interaction, protecting critical assets and logging every call for auditability. Case underscores theCUBE Research finding of a confidence paradox in which organizations report high readiness despite limited agent controls, and they highlight the practical steps security teams can take to improve identity governance and runtime authorization for AI agents.
>> Welcome back to theCUBE. We're here live at Black Hat 2026, continuing our coverage of the show. We're rolling right into the afternoon here. And we've been talking a lot about the fact that these AI agents are becoming operational actors within the enterprise. They're starting to have access to systems and data and they can take privileged actions. And unlike humans, they can operate continuously, they can invoke dozens of tools in seconds, and they can make decisions at machine speed. So one of the key pieces that needs to adapt within the security stack is identity. These traditional identity and privilege models really need to evolve to be able to govern these increasingly autonomous systems. I have the pleasure of sitting down right now with Art Gilliland, CEO of Delinea. Art, thank you so much for joining us today.
Art Gilliland
>> Oh, it's my pleasure, it's nice to be here, thank you.
Krista Case
>> Thank you. We were just talking before we went live, you mentioned that you've been doing some research into essentially, as an industry, are we ready for AI? Are we going to have to make some security trade-offs? And I had a number of conversations, both with vendors and practitioners yesterday, about the fact that businesses are willing to accept a level of risk today that they weren't before due to AI. So can you maybe talk a little bit about the research and what you found?
Art Gilliland
>> Yeah, so we started out looking at and just trying to talk to a bunch of IT folks around what do you think about AI and AI security? And partly because you've got a bunch of crazy CEOs like me pushing their businesses like go as fast as possible, use AI to drive productivity because the opportunity is humongous to make businesses more profitable and more successful. And so we wanted to understand that. And so we reached out to about 2 ,000 IT professionals, a bunch of different industries, a bunch of different geographies, and asked them questions about what's going on with AI? How are you using it? How are you adopting it? How are you thinking about security? And a couple really big things stood out. One really big thing that is good for security but kind of scary is 90 % of those folks said that they are being pressured to reduce security policy or reduce the controls they have so they can go faster. And so to get speed, to go faster, they really need to reduce the controls they have. The second interesting thing is the thing we call the Confidence Paradox in the report. And it basically is that when you ask the professionals, are you ready for AI and AI control, a lot of them say yes. The flip side is then you ask those same folks that say yes, how are you finding agents, how are you controlling them? They have no tools, they have no idea. So they're super confident, but they have nothing really in place. And so those two things together were just really informative how we thought about it and the work that we're trying to do to help our customers.
Krista Case
>> Yeah, it's a little bit of rose-colored glasses, right?
Art Gilliland
>> A lot of it, yeah.I agree. Well, and it's exciting, so you want to, and you have to say you're ready, and then you're like, oh gosh, how do I fix this?
Krista Case
>> So let's talk about how we might fix it. Looking at identity, you're in a privileged position as the CEO of Delinea. Maybe we can start by talking through how the traditional identity and access programs start to fall apart as agents in particular enter the equation because they're not really human, they're not a service account.
Art Gilliland
>> Yeah, it's an interesting problem that you see, obviously, a lot of our systems and the policies and governance models were really designed for humans and human access. And so you can inventory, who are all your users, and find all those users. You can set policy for all those users, and then you allow them to operate in your environment. Machine identities were the next. They were also kind of ignored, to be honest. AI has made machine identity sexy again. But machine identities are discrete. They do a specific thing typically, and so you can get your hands around those. AI is this weird hybrid, right? And I think the other thing is, if you look at how AI works, and I'll give you a personal example. We use Claude Enterprise, so I was writing an agent to go and help me do some research. that agent spun up five other agents, they went and talked to all these systems that we give them permission to, and then after about 20 minutes, they all disappeared. And those agents go away, because I don't need that anymore. And so here we have a system where all these identities are operating as part of our environment, they're touching all these systems, and then they're gone. And so the typical gain visibility, scan for everything, set policy, and then enforce, that just is not going to work in AI. In fact, I think you're wasting your time looking for and trying to discover all the agents. And so you just need a different approach.
Krista Case
>> I agree, Art, and I think one of the pieces in particular that I'd love to get your take on is the authorization piece of it. You were kind of describing spinning up these agents, spinning them down, and I think the way enterprises use agents is going to evolve over time. So it becomes a continuous process to authorize as opposed to sort of a one -time decision. I'd love to get your reaction to that.
Art Gilliland
>> Yeah, and so I think what we're focused on is, there's no way you're going to catch all these agents. There's no way you're going to be able to create an account for them, give them credentials. That is just going to grind everything to a halt. And so what's a better approach potentially? And so the approach that we are taking, and we announced some technology last week about it and some customers that are using it, is to focus on the assets you care about. What are these agents going to touch? Where is the sensitive data in your environment? Where are the sensitive things in your environment? Whether that's a database or Salesforce interface or Workday or these things. And let's draw lines around those things and protect them. And then as agents go and try to talk to them using Art's credential, let's differentiate. Is it Art trying to talk to this thing? Or is it Art's agent trying to talk to this thing? And if it's Art's agent, maybe we give Art's agent different kinds of permissions than we give Art. And so being able to differentiate between human interaction with systems and agent interaction is one part of it, and then set policy and then watch. What does this agent do when it gets in there? Every single call, be able to decide is this going to be allowed or not allowed? And so that level of visibility, you can record it, you can watch it, so you have a way to demonstrate for compliance what the agent actually did. And so it's a very different approach, and what we talk about is real -time authorization. It's in line, it's in the protocol, so you can watch what it's doing, watch what the calls are, match it to context, you can decide. And so this is just in our opinion, a way better and more effective approach so that you can go fast and not break stuff.
Krista Case
>> Yeah, and it's kind of a shift from authorizing the access itself to authorizing the action.
Art Gilliland
>> Yeah, and I think that's a big, really important difference. If you just authorize the access, some of the biggest damage we have seen so far with AI is that you give it a front door access. Here's your permissions. Okay, it's what the thing did the next second, or the fact that AI will go and scan through all of the files in SharePoint to find other credentials to elevate its privileges. That's the stuff that humans don't do because they're not going to go through every file. Machines don't do that because they're very scripted, but AI will do whatever it takes to solve the problem you ask it to solve. And that is that sort of non -deterministic behavior with a machine sort of capability is why you need that sort of real -time authorization and not just front -door access.
Krista Case
>> Yeah, these agents, they're designed to do a specific task, and they're going to find a way to do the task.
Art Gilliland
>> Yeah, they're not good or bad. They're just doing what you ask, but they will do anything to complete the task you've asked them. Because they don't think it's good or they don't think bad, they just do. And that is why you need to control them in a much more detailed way. for every single action, not just at the front door.
Krista Case
>> Absolutely. And I think as we start to see these agents roll out more, we saw the Hugging Face example a couple of weeks ago where it chained together these credentials, not to pick on anybody, of course, but as one example that sort of opens our eyes and I think maybe is going to make business leaders and practitioners alike take a step back and consider the ramifications. I'm interested if you're hearing that here at the show at Black Hat.
Art Gilliland
>> We definitely do. Obviously, I will tell you over the last six months, 98 % of all of my conversations, whether it's at a CEO conference that I'm attending or customer meetings or partners, is all about AI security and what are we going to do. I would say most of my customer conversations recently are very focused on these frontier models and how effective they are at sort of chaining together vulnerabilities and breaking in. And so part of the approach that we're focused on is if that's going to happen, how can we limit the damage? The thing is, they're going to break in. Because they used a vulnerability, they got access. But then if they can't move once they're in, the damage is really contained. And so this kind of real -time authorization stops the movement. Doesn't stop the break -in, but it'll stop the movement.
Krista Case
>> And was that, so you mentioned the announcement that you had, the runtime authorization. I imagine that's sort of, maybe the gap that you saw that you were looking to address with the new update.
Art Gilliland
>> Yeah, this is the trend in regular privilege management when you think about human access. One of the biggest sort of stallers of projects is not the technology actually, it's the human adoption of the process. And so just in time, real time access is a really important sort of evolution of our industry. But that is perfectly designed for AI. And so being in the path, being able to give access credentials right at the time of request, even if that person doesn't have the standing credentials, is super powerful for AI. It's really important for humans, which is why we built it, and then obviously as you realize that AI is going to be that on steroids, our technology is perfectly designed for it.
Krista Case
>> I agree, and that just -in -time access is so important. I look at AI agents as they almost all need to be treated like a malicious insider because they potentially could be, to your earlier point, Art, even if they're operating as intended, if they're given a task and they're going to find a way to complete it.
Art Gilliland
>> They are the newest privileged user. They are the super admin who has those credentials or will find those credentials. And so you need to control and monitor and log and create governance structures around them. And so this is the perfect way to do that without stopping it. Because that's the thing, this is unstoppable. People are going to drive IT crazy CEOs like me are pushing it. And so there's a pressure on IT to lower the controls that you have, but we don't want that. And so how do you move fast, how do you not break the process, and we believe this is the way you do that.
Krista Case
>> Yeah, it's an overall theme here at the show for sure, is understanding what those trade -offs are and where we're willing to accept levels of risk.
Art Gilliland
>> Yeah.
Krista Case
>> So Art, I wanted to, you referenced earlier, you were talking about the traceability of the agent actions, and I think that's really critical in terms of understanding their intent of what they're trying to do, and also in terms of if they do take an action that we didn't intend, potentially, and even if it's, to trace that back. And I imagine there's going to be a human, accountable at the end of the day, but I'm wondering if you could comment on maybe the role of this auditability and traceability in this AI agent era, especially from an identity perspective.
Art Gilliland
>> Yeah, I think if you look at how organizations have dealt with privileged users historically, they've said, okay, this user is going to touch a sensitive production system, I need to watch and log all those things. There may be a compliance reason, there may be just an internal discipline that's required, so it may be an internal policy or an external regulatory reason. And so now if your AI agents are going to be non -deterministic, it's not just a machine talking to an API backend and doing those same five things every time. You need to have that same auditability because you don't know what they're going to do. And so when your database goes down, your application gets slower, you're going to want those logs to be able to say, oh, I see why my application slowed down. And so it's not just a security reason you're logging these things. Now it's a business operations, it's a productivity reason. There's a whole bunch of other reasons why auditability for agents is going to be critical. And so I think being able to log what they do, watch all the interactions, and then have a traceability back to it so that you can explain, here's what my agent did. Because right now it's kind of a black box. And so being able to have explainability, have visibility is super critical for security. And if you're going to put security people in charge of protecting the enterprise, this is a tool they're going to need.
Krista Case
>> It cannot be a black box. It cannot be a black box. I had a physical reaction.
Art Gilliland
>> Exactly. Thinking about that?
Krista Case
>> So, on that note, and we were talking a minute ago about the continuous authorization, I know that even the major AI providers are now advising against having those standing credentials. I'd love to get your take on that, because I think it kind of shows, I think, that as an industry we are beginning to kind of maybe rethink this a little bit?
Art Gilliland
>> You know, what I find really exciting, but also kind of interesting is how history plays itself out over and over again. I think we're learning a little bit better this time, but if you look at every single major infrastructure shift, whether it was laptops at one point, or mobile, or cloud, there's so much focus on the platform at first, and the functionality and capability of the platform. The security capabilities is just an afterthought, because you want that next new feature that's going to get people to adopt it. And so you've watched all of the things and that's why you see my interest, thank goodness because my last 30 years of my career has been securing all these platforms that get created without security involved. I think AI is kind of the same and so we're seeing that same thing play out. There's a mad rush for capabilities and the machines are getting faster and better and of course now AI is writing AI so it's like crazy fast. But now security events are happening like super fast. And so now the providers are starting to think, okay, what do I need to do? Look, it was a really bad idea to have standing privileges before. And with humans and other things, it's a really bad idea to have standing privileges with AI when AI can attack other AI and steal the credentials and then take actions that somebody else is deciding what to do. And so this, I think it's going to push the entire industry to do it, and one of the things that we are investing in and believe is that AI security is actually going to drive a focus on human identity security in a much bigger way. Because if you're going to lock down, try to block what an AI agent does, you're like, oh, I got to protect my developers, my developers also have access to this infrastructure, my IT admins also have access. And so now you're going to have to think about no standing privileges for everybody, and I think it'll actually make the whole company a lot safer, and AI is pushing that, which is kind of different.
Krista Case
>> Well, and especially since you mentioned developers, and the fact that we have AI writing AI code, I think, especially from an identity perspective, that developer identity, as they start to use these AI coding agents, is going to be a critical one to secure.
Art Gilliland
>> I think you're absolutely right, and part of the reason we have seen low adoption of privilege control in the developer world is because they have a different workflow. An IT admin, they don't like it, but they will go and check out a secret and use that secret and then put that secret back and then the thing can change. There's no way you can get a developer to do that. They will blow a gasket. And so they want to use native tools. They want to be able to use the workflow that they're used to. And this is why that just-in-time credential insertion was so critical because we want them to also adopt this type of capability. And that's what we built it for. But now of course AI also needs that. And so it's actually an awakening in the enterprise that standing privileges are bad. And a way to get rid of that is runtime authorization. And Delinea has the opportunity to be able to deliver that for folks.
Krista Case
>> Absolutely, and one more question before we move off of this point.
Art Gilliland
>> Yeah, no problem.
Krista Case
>> So we've been thinking so much about AI agents and securing those identities for a good reason. and you mentioned there's going to be this resurgence and focus on the human piece of it as well. If you had to maybe think about the one or two key implications for securing human identities as we start to move into this AI era, what might it be?
Art Gilliland
>> Yeah, I think it is that adoption. The biggest thing that slows these things down or creates conflict in an enterprise is candidly the end user adoption. If you force them to change the way they work, they're going to complain. If you put more roadblocks in their way, they're going to complain. And so how can you go faster but without giving up the controls that you need so you don't have to make that false trade -off between go fast and be productive and be secure. And so the way you do that is you build these things into the workflow. And so the permissions, the credentials kind of happen invisibly to the end user. I'm just using the tools I normally would use to write code or administer infrastructure or the AI agent's doing what it does, but you still get the auditability, you still get the visibility, you still get policy enforcement and no standing privileges. And I think that's going to be the differentiator. If you can make it part of the workflow without actually slowing people down, they will adopt it. And I think that's going to be the unlock, which we're super excited about.
Krista Case
>> I agree. It has to, like you say, not get in the way of their productivity. Sometimes I don't even like installing the updates on my PC. never mind even going further than that.
Art Gilliland
>> Oh, two-factor authentication again? Okay.
Krista Case
>> Exactly.
Art Gilliland
>> There's got to be an easier way.
Krista Case
>> Exactly. And it's an interesting conversation. I think we've been talking a lot about kind of two ends of the spectrum, one being kind of the visibility, you know, kind of turning the lights on and addressing the shadow AI piece of it, and the other being kind of the governance and putting these guardrails in place. And I think, to your point about businesses being pressured to move faster, I think security teams are trying to almost solve both problems at once.
Krista Case
>> They do. Yes.
Krista Case
>> So a closing thought here might be if you were to give maybe one piece of advice to a practitioner that's trying to navigate this, what might it be, maybe what's a good place for them to start if they're walking the show floor and they're feeling overwhelmed and they don't know where to begin?
Art Gilliland
>> Yeah,look, obviously, we're very focused on being able to help people deliver this without creating a lot of end user pushback. And so for someone who wants to try to start, whether it's a pilot, or it's a place to just use it in a sort of sandbox. I think this is the way I would say you should start is focus on a really critical asset, figure out how to protect that asset. and then let, candidly, AI do its thing, let the people do their thing, and control it at that point. And this is where runtime authorization just really gives you that pathway. And so, Delinea is obviously a great place to do that, and so we would say, come talk to us, and we can help you understand how you do that for AI, and also how you extend that out to humans, and I think that would be what I would tell people.
Krista Case
>> Absolutely, we need to address the spectrum, for sure.
Art Gilliland
>> Absolutely, no question.
Krista Case
>> Art, it's been a pleasure. Thank you so much for joining us.
Art Gilliland
>> It's my pleasure. Thank you very much for having me.
Krista Case
>> We really appreciate it. And thank you so much for watching. We're going to be right back in just a few minutes with more analysis live here from Black Hat 2026.
>> Welcome back to theCUBE. We're here live at Black Hat 2026, continuing our coverage of the show. We're rolling right into the afternoon here. And we've been talking a lot about the fact that these AI agents are becoming operational actors within the enterprise. They're starting to have access to systems and data and they can take privileged actions. And unlike humans, they can operate continuously, they can invoke dozens of tools in seconds, and they can make decisions at machine speed. So one of the key pieces that needs to adapt within the security stack is identity. These traditional identity and privilege models really need to evolve to be able to govern these increasingly autonomous systems. I have the pleasure of sitting down right now with Art Gilliland, CEO of Delinea. Art, thank you so much for joining us today.
Art Gilliland
>> Oh, it's my pleasure, it's nice to be here, thank you.
Krista Case
>> Thank you. We were just talking before we went live, you mentioned that you've been doing some research into essentially, as an industry, are we ready for AI? Are we going to have to make some security trade-offs? And I had a number of conversations, both with vendors and practitioners yesterday, about the fact that businesses are willing to accept a level of risk today that they weren't before due to AI. So can you maybe talk a little bit about the research and what you found?
Art Gilliland
>> Yeah, so we started out looking at and just trying to talk to a bunch of IT folks around what do you think about AI and AI security? And partly because you've got a bunch of crazy CEOs like me pushing their businesses like go as fast as possible, use AI to drive productivity because the opportunity is humongous to make businesses more profitable and more successful. And so we wanted to understand that. And so we reached out to about 2 ,000 IT professionals, a bunch of different industries, a bunch of different geographies, and asked them questions about what's going on with AI? How are you using it? How are you adopting it? How are you thinking about security? And a couple really big things stood out. One really big thing that is good for security but kind of scary is 90 % of those folks said that they are being pressured to reduce security policy or reduce the controls they have so they can go faster. And so to get speed, to go faster, they really need to reduce the controls they have. The second interesting thing is the thing we call the Confidence Paradox in the report. And it basically is that when you ask the professionals, are you ready for AI and AI control, a lot of them say yes. The flip side is then you ask those same folks that say yes, how are you finding agents, how are you controlling them? They have no tools, they have no idea. So they're super confident, but they have nothing really in place. And so those two things together were just really informative how we thought about it and the work that we're trying to do to help our customers.
Krista Case
>> Yeah, it's a little bit of rose-colored glasses, right?
Art Gilliland
>> A lot of it, yeah.I agree. Well, and it's exciting, so you want to, and you have to say you're ready, and then you're like, oh gosh, how do I fix this?
Krista Case
>> So let's talk about how we might fix it. Looking at identity, you're in a privileged position as the CEO of Delinea. Maybe we can start by talking through how the traditional identity and access programs start to fall apart as agents in particular enter the equation because they're not really human, they're not a service account.
Art Gilliland
>> Yeah, it's an interesting problem that you see, obviously, a lot of our systems and the policies and governance models were really designed for humans and human access. And so you can inventory, who are all your users, and find all those users. You can set policy for all those users, and then you allow them to operate in your environment. Machine identities were the next. They were also kind of ignored, to be honest. AI has made machine identity sexy again. But machine identities are discrete. They do a specific thing typically, and so you can get your hands around those. AI is this weird hybrid, right? And I think the other thing is, if you look at how AI works, and I'll give you a personal example. We use Claude Enterprise, so I was writing an agent to go and help me do some research. that agent spun up five other agents, they went and talked to all these systems that we give them permission to, and then after about 20 minutes, they all disappeared. And those agents go away, because I don't need that anymore. And so here we have a system where all these identities are operating as part of our environment, they're touching all these systems, and then they're gone. And so the typical gain visibility, scan for everything, set policy, and then enforce, that just is not going to work in AI. In fact, I think you're wasting your time looking for and trying to discover all the agents. And so you just need a different approach.
Krista Case
>> I agree, Art, and I think one of the pieces in particular that I'd love to get your take on is the authorization piece of it. You were kind of describing spinning up these agents, spinning them down, and I think the way enterprises use agents is going to evolve over time. So it becomes a continuous process to authorize as opposed to sort of a one -time decision. I'd love to get your reaction to that.
Art Gilliland
>> Yeah, and so I think what we're focused on is, there's no way you're going to catch all these agents. There's no way you're going to be able to create an account for them, give them credentials. That is just going to grind everything to a halt. And so what's a better approach potentially? And so the approach that we are taking, and we announced some technology last week about it and some customers that are using it, is to focus on the assets you care about. What are these agents going to touch? Where is the sensitive data in your environment? Where are the sensitive things in your environment? Whether that's a database or Salesforce interface or Workday or these things. And let's draw lines around those things and protect them. And then as agents go and try to talk to them using Art's credential, let's differentiate. Is it Art trying to talk to this thing? Or is it Art's agent trying to talk to this thing? And if it's Art's agent, maybe we give Art's agent different kinds of permissions than we give Art. And so being able to differentiate between human interaction with systems and agent interaction is one part of it, and then set policy and then watch. What does this agent do when it gets in there? Every single call, be able to decide is this going to be allowed or not allowed? And so that level of visibility, you can record it, you can watch it, so you have a way to demonstrate for compliance what the agent actually did. And so it's a very different approach, and what we talk about is real -time authorization. It's in line, it's in the protocol, so you can watch what it's doing, watch what the calls are, match it to context, you can decide. And so this is just in our opinion, a way better and more effective approach so that you can go fast and not break stuff.
Krista Case
>> Yeah, and it's kind of a shift from authorizing the access itself to authorizing the action.
Art Gilliland
>> Yeah, and I think that's a big, really important difference. If you just authorize the access, some of the biggest damage we have seen so far with AI is that you give it a front door access. Here's your permissions. Okay, it's what the thing did the next second, or the fact that AI will go and scan through all of the files in SharePoint to find other credentials to elevate its privileges. That's the stuff that humans don't do because they're not going to go through every file. Machines don't do that because they're very scripted, but AI will do whatever it takes to solve the problem you ask it to solve. And that is that sort of non -deterministic behavior with a machine sort of capability is why you need that sort of real -time authorization and not just front -door access.
Krista Case
>> Yeah, these agents, they're designed to do a specific task, and they're going to find a way to do the task.
Art Gilliland
>> Yeah, they're not good or bad. They're just doing what you ask, but they will do anything to complete the task you've asked them. Because they don't think it's good or they don't think bad, they just do. And that is why you need to control them in a much more detailed way. for every single action, not just at the front door.
Krista Case
>> Absolutely. And I think as we start to see these agents roll out more, we saw the Hugging Face example a couple of weeks ago where it chained together these credentials, not to pick on anybody, of course, but as one example that sort of opens our eyes and I think maybe is going to make business leaders and practitioners alike take a step back and consider the ramifications. I'm interested if you're hearing that here at the show at Black Hat.
Art Gilliland
>> We definitely do. Obviously, I will tell you over the last six months, 98 % of all of my conversations, whether it's at a CEO conference that I'm attending or customer meetings or partners, is all about AI security and what are we going to do. I would say most of my customer conversations recently are very focused on these frontier models and how effective they are at sort of chaining together vulnerabilities and breaking in. And so part of the approach that we're focused on is if that's going to happen, how can we limit the damage? The thing is, they're going to break in. Because they used a vulnerability, they got access. But then if they can't move once they're in, the damage is really contained. And so this kind of real -time authorization stops the movement. Doesn't stop the break -in, but it'll stop the movement.
Krista Case
>> And was that, so you mentioned the announcement that you had, the runtime authorization. I imagine that's sort of, maybe the gap that you saw that you were looking to address with the new update.
Art Gilliland
>> Yeah, this is the trend in regular privilege management when you think about human access. One of the biggest sort of stallers of projects is not the technology actually, it's the human adoption of the process. And so just in time, real time access is a really important sort of evolution of our industry. But that is perfectly designed for AI. And so being in the path, being able to give access credentials right at the time of request, even if that person doesn't have the standing credentials, is super powerful for AI. It's really important for humans, which is why we built it, and then obviously as you realize that AI is going to be that on steroids, our technology is perfectly designed for it.
Krista Case
>> I agree, and that just -in -time access is so important. I look at AI agents as they almost all need to be treated like a malicious insider because they potentially could be, to your earlier point, Art, even if they're operating as intended, if they're given a task and they're going to find a way to complete it.
Art Gilliland
>> They are the newest privileged user. They are the super admin who has those credentials or will find those credentials. And so you need to control and monitor and log and create governance structures around them. And so this is the perfect way to do that without stopping it. Because that's the thing, this is unstoppable. People are going to drive IT crazy CEOs like me are pushing it. And so there's a pressure on IT to lower the controls that you have, but we don't want that. And so how do you move fast, how do you not break the process, and we believe this is the way you do that.
Krista Case
>> Yeah, it's an overall theme here at the show for sure, is understanding what those trade -offs are and where we're willing to accept levels of risk.
Art Gilliland
>> Yeah.
Krista Case
>> So Art, I wanted to, you referenced earlier, you were talking about the traceability of the agent actions, and I think that's really critical in terms of understanding their intent of what they're trying to do, and also in terms of if they do take an action that we didn't intend, potentially, and even if it's, to trace that back. And I imagine there's going to be a human, accountable at the end of the day, but I'm wondering if you could comment on maybe the role of this auditability and traceability in this AI agent era, especially from an identity perspective.
Art Gilliland
>> Yeah, I think if you look at how organizations have dealt with privileged users historically, they've said, okay, this user is going to touch a sensitive production system, I need to watch and log all those things. There may be a compliance reason, there may be just an internal discipline that's required, so it may be an internal policy or an external regulatory reason. And so now if your AI agents are going to be non -deterministic, it's not just a machine talking to an API backend and doing those same five things every time. You need to have that same auditability because you don't know what they're going to do. And so when your database goes down, your application gets slower, you're going to want those logs to be able to say, oh, I see why my application slowed down. And so it's not just a security reason you're logging these things. Now it's a business operations, it's a productivity reason. There's a whole bunch of other reasons why auditability for agents is going to be critical. And so I think being able to log what they do, watch all the interactions, and then have a traceability back to it so that you can explain, here's what my agent did. Because right now it's kind of a black box. And so being able to have explainability, have visibility is super critical for security. And if you're going to put security people in charge of protecting the enterprise, this is a tool they're going to need.
Krista Case
>> It cannot be a black box. It cannot be a black box. I had a physical reaction.
Art Gilliland
>> Exactly. Thinking about that?
Krista Case
>> So, on that note, and we were talking a minute ago about the continuous authorization, I know that even the major AI providers are now advising against having those standing credentials. I'd love to get your take on that, because I think it kind of shows, I think, that as an industry we are beginning to kind of maybe rethink this a little bit?
Art Gilliland
>> You know, what I find really exciting, but also kind of interesting is how history plays itself out over and over again. I think we're learning a little bit better this time, but if you look at every single major infrastructure shift, whether it was laptops at one point, or mobile, or cloud, there's so much focus on the platform at first, and the functionality and capability of the platform. The security capabilities is just an afterthought, because you want that next new feature that's going to get people to adopt it. And so you've watched all of the things and that's why you see my interest, thank goodness because my last 30 years of my career has been securing all these platforms that get created without security involved. I think AI is kind of the same and so we're seeing that same thing play out. There's a mad rush for capabilities and the machines are getting faster and better and of course now AI is writing AI so it's like crazy fast. But now security events are happening like super fast. And so now the providers are starting to think, okay, what do I need to do? Look, it was a really bad idea to have standing privileges before. And with humans and other things, it's a really bad idea to have standing privileges with AI when AI can attack other AI and steal the credentials and then take actions that somebody else is deciding what to do. And so this, I think it's going to push the entire industry to do it, and one of the things that we are investing in and believe is that AI security is actually going to drive a focus on human identity security in a much bigger way. Because if you're going to lock down, try to block what an AI agent does, you're like, oh, I got to protect my developers, my developers also have access to this infrastructure, my IT admins also have access. And so now you're going to have to think about no standing privileges for everybody, and I think it'll actually make the whole company a lot safer, and AI is pushing that, which is kind of different.
Krista Case
>> Well, and especially since you mentioned developers, and the fact that we have AI writing AI code, I think, especially from an identity perspective, that developer identity, as they start to use these AI coding agents, is going to be a critical one to secure.
Art Gilliland
>> I think you're absolutely right, and part of the reason we have seen low adoption of privilege control in the developer world is because they have a different workflow. An IT admin, they don't like it, but they will go and check out a secret and use that secret and then put that secret back and then the thing can change. There's no way you can get a developer to do that. They will blow a gasket. And so they want to use native tools. They want to be able to use the workflow that they're used to. And this is why that just-in-time credential insertion was so critical because we want them to also adopt this type of capability. And that's what we built it for. But now of course AI also needs that. And so it's actually an awakening in the enterprise that standing privileges are bad. And a way to get rid of that is runtime authorization. And Delinea has the opportunity to be able to deliver that for folks.
Krista Case
>> Absolutely, and one more question before we move off of this point.
Art Gilliland
>> Yeah, no problem.
Krista Case
>> So we've been thinking so much about AI agents and securing those identities for a good reason. and you mentioned there's going to be this resurgence and focus on the human piece of it as well. If you had to maybe think about the one or two key implications for securing human identities as we start to move into this AI era, what might it be?
Art Gilliland
>> Yeah, I think it is that adoption. The biggest thing that slows these things down or creates conflict in an enterprise is candidly the end user adoption. If you force them to change the way they work, they're going to complain. If you put more roadblocks in their way, they're going to complain. And so how can you go faster but without giving up the controls that you need so you don't have to make that false trade -off between go fast and be productive and be secure. And so the way you do that is you build these things into the workflow. And so the permissions, the credentials kind of happen invisibly to the end user. I'm just using the tools I normally would use to write code or administer infrastructure or the AI agent's doing what it does, but you still get the auditability, you still get the visibility, you still get policy enforcement and no standing privileges. And I think that's going to be the differentiator. If you can make it part of the workflow without actually slowing people down, they will adopt it. And I think that's going to be the unlock, which we're super excited about.
Krista Case
>> I agree. It has to, like you say, not get in the way of their productivity. Sometimes I don't even like installing the updates on my PC. never mind even going further than that.
Art Gilliland
>> Oh, two-factor authentication again? Okay.
Krista Case
>> Exactly.
Art Gilliland
>> There's got to be an easier way.
Krista Case
>> Exactly. And it's an interesting conversation. I think we've been talking a lot about kind of two ends of the spectrum, one being kind of the visibility, you know, kind of turning the lights on and addressing the shadow AI piece of it, and the other being kind of the governance and putting these guardrails in place. And I think, to your point about businesses being pressured to move faster, I think security teams are trying to almost solve both problems at once.
Krista Case
>> They do. Yes.
Krista Case
>> So a closing thought here might be if you were to give maybe one piece of advice to a practitioner that's trying to navigate this, what might it be, maybe what's a good place for them to start if they're walking the show floor and they're feeling overwhelmed and they don't know where to begin?
Art Gilliland
>> Yeah,look, obviously, we're very focused on being able to help people deliver this without creating a lot of end user pushback. And so for someone who wants to try to start, whether it's a pilot, or it's a place to just use it in a sort of sandbox. I think this is the way I would say you should start is focus on a really critical asset, figure out how to protect that asset. and then let, candidly, AI do its thing, let the people do their thing, and control it at that point. And this is where runtime authorization just really gives you that pathway. And so, Delinea is obviously a great place to do that, and so we would say, come talk to us, and we can help you understand how you do that for AI, and also how you extend that out to humans, and I think that would be what I would tell people.
Krista Case
>> Absolutely, we need to address the spectrum, for sure.
Art Gilliland
>> Absolutely, no question.
Krista Case
>> Art, it's been a pleasure. Thank you so much for joining us.
Art Gilliland
>> It's my pleasure. Thank you very much for having me.
Krista Case
>> We really appreciate it. And thank you so much for watching. We're going to be right back in just a few minutes with more analysis live here from Black Hat 2026.