This discussion at Black Hat 2026 examines securing artificial intelligence, AI agents and evolving identity controls. Art Gilliland of Delinea, chief executive officer, discusses Delinea’s approach to protecting sensitive assets as AI agents become operational actors. Krista Case of theCUBE Research, principal analyst and practice lead for cyber resilience and security, hosts the conversation covering agent behavior, differences between human and machine identities, just-in-time credentialing and the need for in-path authorization to preserve productivity while maintaining controls.
Gilliland emphasizes that traditional identity and privileged access models must evolve for autonomous AI and that runtime just-in-time authorization should govern actions rather than static access. They stress differentiating agent versus human interaction, protecting critical assets and logging every call for auditability. Case underscores theCUBE Research finding of a confidence paradox in which organizations report high readiness despite limited agent controls, and they highlight the practical steps security teams can take to improve identity governance and runtime authorization for AI agents.
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
Black Hat USA 2026. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Register for Black Hat USA 2026
Please fill out the information below. You will receive an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for Black Hat USA 2026.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
Black Hat USA 2026. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Sign in to gain access to Black Hat USA 2026
Please sign in with LinkedIn to continue to Black Hat USA 2026. Signing in with LinkedIn ensures a professional environment.
Are you sure you want to remove access rights for this user?
Details
Manage Access
email address
Community Invitation
Art Gilliland, Delinea
This discussion at Black Hat 2026 examines securing artificial intelligence, AI agents and evolving identity controls. Art Gilliland of Delinea, chief executive officer, discusses Delinea’s approach to protecting sensitive assets as AI agents become operational actors. Krista Case of theCUBE Research, principal analyst and practice lead for cyber resilience and security, hosts the conversation covering agent behavior, differences between human and machine identities, just-in-time credentialing and the need for in-path authorization to preserve productivity while maintaining controls.
Gilliland emphasizes that traditional identity and privileged access models must evolve for autonomous AI and that runtime just-in-time authorization should govern actions rather than static access. They stress differentiating agent versus human interaction, protecting critical assets and logging every call for auditability. Case underscores theCUBE Research finding of a confidence paradox in which organizations report high readiness despite limited agent controls, and they highlight the practical steps security teams can take to improve identity governance and runtime authorization for AI agents.
In this interview from Black Hat 2026, Art Gilliland, chief executive officer of Delinea, joins theCUBE's Krista Case to discuss how AI agents are forcing enterprises to rethink identity and privilege management as autonomous systems become operational actors within the business. Gilliland shares findings from Delinea's research of 2,000 IT professionals, revealing a "confidence paradox" where organizations claim readiness for AI while lacking the tools to actually govern agents. He explains why traditional identity models built for humans and machines break ...Read more
exploreKeep Exploring
How do AI agents—ephemeral, non‑human identities—challenge traditional identity and access management, and how should identity programs adapt?add
Was the runtime authorization announcement intended to address the gap that the new update aimed to fill?add
What is the role of auditability and traceability in the era of AI agents, particularly from an identity perspective?add
How will AI change the way organizations manage standing privileges and human identity security?add
How does the rise of AI coding agents affect developer identity and privilege management, and what solutions (e.g., just-in-time credential insertion and runtime authorization) fit developers' workflows?add
>> Welcome back to theCUBE. We're here live at Black Hat 2026, continuing our coverage of the show. We're rolling right into the afternoon here, and we've been talking a lot about the fact that these AI agents are becoming operational actors within the enterprise. They're starting to have access to systems and data, and they can take privileged actions. And unlike humans, they can operate continuously. They can invoke dozens of tools in seconds, and they can make decisions at machine speed. So one of the key points that needs to adapt within the security stack is identity. These traditional identity and privilege models really need to evolve to be able to govern these increasingly autonomous systems. I have the pleasure of sitting down right now with Art Gilliland, CEO of Delinea. Art, thank you so much for joining us today.
Art Gilliland
>> Oh, it's my pleasure. It's nice to be here. Thank you.
Krista Case
>> Thank you. We were just talking before we went live. You mentioned that you've been doing some research into essentially, as an industry, are we ready for AI? Are we going to have to make some security trade-offs? And I had a number of conversations both with vendors and practitioners yesterday about the fact that, businesses are willing to accept a level of risk today that they
Krista Case
>> weren't— Sure
Krista Case
>> . Before due to AI. So can you maybe talk a little bit about the research and what you found?
Art Gilliland
>> Yeah, so we started out looking at and just trying to talk to a bunch of IT folks around what do you think about AI and AI security? And partly because you've got a bunch of crazy CEOs like me pushing their businesses like, go as fast as possible, use AI to drive productivity because the opportunity is humongous to make businesses more profitable and more successful. And so we wanted to understand that. And so we reached out to about 2,000 IT professionals, a bunch of different industries, a bunch of different geographies, and asked them questions about what's going on with AI? How are you using it? How are you adopting it? How are you thinking about security? And a couple really big things sort of stood out. One really big thing that is good for security but kind of scary is 90% of those folks said that they are being pressured to reduce security policy or reduce the controls they have so they can go faster. And so to get speed, to go faster, they really need to reduce the controls they have. The second interesting thing is the thing we call the Confidence Paradox in the report. And it basically is that when you ask the professionals, are you ready for AI and AI controls? A lot of them say yes. The flip side is then you ask those same folks that say yes, how are you finding agents? How are you controlling them? They have no tools, they have no idea. So they're super confident, but they have nothing really in place. And so those two things together were what just really informed how we thought about it and the work that we're trying to do to help our customers.
Krista Case
>> Yeah, it's a little bit of rose-colored glasses, right?
Art Gilliland
>> A lot of it, yeah.
Krista Case
>> I agree.
Art Gilliland
>> Well, and it's exciting, so you wanna, and you have to say you're ready, and then you're like, oh gosh, how do I fix this, right?
Krista Case
>> So let's talk about how we might fix it. looking at identity, you're in a privileged position as the CEO of Delinea. Maybe we can start by talking to how the traditional identity and access programs start to fall apart as agents in particular enter the equation, because they're not really human, they're not a service account.
Art Gilliland
>> Yeah, it's really, it's an interesting problem that you see. Obviously a lot of our systems and the policies and governance models were really designed for humans and human access. And so you can inventory who are all your users and find all those users. You can set policy for all those users and then you allow them to operate in your environment. Machine identities were the next. They were also kind of ignored, to be honest. AI has made machine identity sexy again, but machine identities are discrete. They do a specific thing typically, and so you can get your hands around those. AI is this weird hybrid. Right? And I think the other thing is if you look at how AI works, and I'll give you a personal example, we use Claude Enterprise. So I was writing an agent to go and help me do some research. That agent spun up 5 other agents. They went and talked to all these systems that we make, give them permission to do. And then after about 20 minutes, they all disappeared and those agents go away 'cause I don't need them anymore. And so here we have a system where, All these identities are operating as agents inside of our environment. They're touching all these systems and then they're gone. And so the typical find visibility, scan for everything, set policy, and then enforce, that just is not gonna work in AI. In fact, I think you're wasting your time looking for and trying to discover all the agents. And so you just need a different approach.
Krista Case
>> I agree, Art, and I think one of the pieces in particular that I'd love to get your take on is the authorization piece of it. You were kind of describing spinning up these agents, spinning them down. I think the way enterprises use agents is going to evolve over time.
Art Gilliland
>> Yeah.
Krista Case
>> So it becomes a continuous process to authorize as opposed to sort of a one-time decision. I'd love to get your reaction to that.
Art Gilliland
>> Yeah. And so I think what we're focused on is, you know what, there's no way you're going to catch all these agents. There's no way you're going to be able to create an account for them, give them credentials like that is just going to, that's going to grind everything to a halt. And so what's a better approach potentially? And so the approach that we are taking, and we announced some technology last week about it and some customers that are using it, is to focus on the assets you care about. What are these agents gonna touch? Where is the sensitive data in your environment? Where are the sensitive things in your environment? Whether that's a database or Salesforce or ServiceNow or Workday or these things. And let's, draw lines around those things and protect them. And then as agents go and try to talk to them using Art's credential, let's differentiate. Is it Art trying to talk to this thing or is it Art's agent trying to talk to this thing? And if it's Art's agent, maybe we give Art's agent different kinds of permissions than we give Art. And so being able to sort of differentiate between human interaction with systems and agent interaction is one part of it. And then set policy and then watch. What does this agent do when it gets in there? Every single call, be able to decide, is this gonna be allowed or not allowed? And so that level of visibility, you can record it, you can watch it, so you have a way to demonstrate for compliance what the agent actually did. And so there's just a lot of, it's a very different approach, and it's what we talk about as real-time authorization. It's inline, it's in the protocol, so you can watch what it's doing, watch what the calls are, match it to context, you can decide. And so this is just a way better, in our opinion, a way better and more effective approach so that you can go fast and not break stuff.
Krista Case
>> Yeah, and it's kind of a shift from authorizing the access itself to authorizing the action.
Art Gilliland
>> Yeah.
Krista Case
>> You know,
Art Gilliland
>> and—And I think that's a big, really important difference. If you just authorize the access, some of the biggest damage we have seen so far with AI is that you give it a front door access, here's your permissions. Okay, it's what the thing did the next second or the next second, or the fact that AI will go and scan through all of the files in SharePoint to find other credentials to elevate its privileges. That's the stuff that humans don't do 'cause they're not gonna go through every file. Machines don't do it 'cause they're very scripted, but AI will do whatever it takes to solve the problem you ask it to solve. And that is that sort of non-deterministic behavior with a machine capability is why you need that sort of real-time authorization and not just Front Door access.
Krista Case
>> Yeah, these agents, they are— they get— they're designed to do a specific task and they're going to find a way to do the task.
Art Gilliland
>> Yeah, they're not good or bad. They're just doing what you ask, but they will do anything to complete the task you've asked them because they don't think it's good or they don't think it's bad. They just do. And that is why you need to control them in a much more detailed way for every single action, not just at the front door.
Krista Case
>> Absolutely. And I think as we start to see these agents roll out more, we saw the Hugging Face example a couple of weeks ago where it chained together these credentials, not to pick on anybody, of course, but as one example that sort of opens our eyes and I think maybe is going to make, business leaders and practitioners alike take a step back and consider the ramifications. I'm interested if you're kind of hearing that here at the show at Black Hat.
Art Gilliland
>> We definitely do, obviously. I will tell you over the last 6 months, 98% of all of my conversations, whether it's at a CEO conference that I'm attending or customer meetings or partners, is all about AI security and what are we gonna do. I would say most of my customer conversations recently are very focused on these frontier models and how effective they are at sort of chaining together vulnerabilities and breaking in. And so part of the approach that we're focused on is if that's going to happen, how can we limit the damage? an agent is going to— they're going to break in because they used a vulnerability, they got access. But then if they can't move once they're in, the damage is really contained. And so this kind of real-time authorization stops the movement, doesn't stop the break-in, but it will stop the movement.
Krista Case
>> And was that— so you mentioned kind of the announcement that you had, the runtime authorization. I imagine that's sort of, maybe the gap that you saw that you were looking to address with the new update?
Art Gilliland
>> Yeah, I mean, this is, I mean, it's, it is the trend in privileged access management when you think about human access. One of the biggest sort of stallers of projects is not the technology actually, it's the human adoption of the process. And so just-in-time, real-time access is a really important sort of evolution of our industry, but that is perfectly designed for AI. And so being in the in-path, being able to give access credentials right at the time of request, even if that person doesn't have the standing credentials, is super powerful for AI. It's really important for humans, which is why we built it. And then obviously, as you realize that AI is going to be that on steroids, like our technology is perfectly designed for it.
Krista Case
>> I agree. And that just-in-time access is so important. I look at AI agents as they almost all need to be treated like a malicious insider because they potentially could be. But to your earlier point, Art, even if they're operating as intended, if they're given a task, they're gonna find a way to complete it. So, even
Art Gilliland
>> if—They are the newest privileged user, right? Yes. They are the super admin who has those credentials or will find those credentials. And so you need to control and monitor and log and create governance structures around them. And so this is the perfect way to do that without stopping it. 'Cause that's the thing, this is unstoppable. People are gonna drive it. Crazy CEOs like me are pushing it. And so there's a pressure on IT to lower the controls that you have, but we don't want that. And so how do you move fast? How do you not break the process? And we believe this is the way you do that.
Krista Case
>> Yeah, it's an overall theme here at the show for sure, is understanding what those trade-offs are and where we're willing to accept levels of risk.
Art Gilliland
>> Yeah.
Krista Case
>> So Art, I wanted to— you referenced earlier, you were talking about the traceability of the agent actions. And I think that's really critical in terms of understanding their intent of what they're trying to do. And also, in terms of if they do take an action that we didn't intend, potentially, even if it's inadvertently or maliciously, to trace that back. And I imagine there's going to be a human, accountable at the end of the day. But I'm wondering if you could comment on maybe the role of this auditability and traceability in this AI agent era, especially from an identity perspective.
Art Gilliland
>> PerspectiveYeah, I think if you look at sort of how organizations have dealt with privileged users historically, they've said, okay, this user is gonna touch a sensitive production system. I need to watch and log all those things. There may be a compliance reason, there may be just an internal discipline that's required. So it may be an internal policy or an external regulatory reason. And so now if your AI agents are going to be non-deterministic, it's not just a machine talking to an API backend and doing those same 5 things every time. You need to have that same auditability 'cause you don't know what they're gonna do. And so when your database goes down, your application gets slower, you're gonna want those logs to be able to say, "Oh, I see why my application slowed down." And so it's not just a security reason you're logging these things. Now it's a business operations, it's a productivity reason. There's a whole bunch of other reasons why auditability for agents is gonna be critical. And so I think being able to log what they do, watch all the interactions, and then have traceability back to it so that you can explain, here's what my agent did. 'Cause right now it's kind of a black box. And so being able to have explainability, have visibility is super critical for security. And if you're gonna put security people in charge of protecting the enterprise, this is a tool they're gonna need.
Krista Case
>> It cannot be a black box. I had a physical reaction.
Art Gilliland
>> Exactly.
Krista Case
>> Thinking about that? So on that note, and we were talking a minute ago about the continuous authorization.
Krista Case
>> Yeah
Krista Case
>> . I know that even the major AI providers are now advising against having those standing credentials. I'd love to get your take on that, because I think it shows, I think, that in industry we are beginning to kind of maybe rethink this a little bit.
Art Gilliland
>> You know what I find really exciting but also kind of interesting is how history plays itself out over and over again. I think we're learning a little bit better this time, but if you look at every single major infrastructure shift, whether it was laptops at one point, or mobile, or cloud, there's so much focus on the platform at first and the functionality and capability of the platform that security capabilities is just an afterthought because you want that next new feature that's going to get people to adopt it. And so you've watched all of the things, and that's why you see, my interest— thank goodness, because my last 30 years of my career has been securing all these platforms that get created without security involved. I think AI is kind of the same. And so we're seeing that same thing play out. There's a mad rush for capabilities and the machines are getting faster and better. And of course now AI's writing AI, so it's like crazy fast. But now security events are happening super fast. And so now the providers are starting to think, okay, what do I need to do? it was a really bad idea to have standing privileges before, with humans and other things, it's a really bad idea to have standing privileges with AI when AI can attack other AI and steal the credentials and then take actions as somebody else, deciding what to do. And so this, I think it's gonna push the entire industry to do it. And one of the things that we are investing in and believe is that AI security is actually gonna drive a focus on human identity security in a much bigger way. Because if you're gonna lock down, try to block what an AI agent does, you're like, oh, I gotta protect my developers. My developers also have access to this infrastructure. My IT admins also have. And so now you're gonna have to think about no standing privileges for everybody. And I think it'll actually make the whole company a lot safer. And AI is pushing that, which is kind of different.
Krista Case
>> Well, and especially, so you mentioned developers and the fact that we have AI writing code. I think especially from an identity perspective, that developer identity as they start to use these AI coding agents is going to be a critical one.
Art Gilliland
>> I think you're absolutely right. And part of the reason we have seen low adoption of privilege control in developer world is because they are, they have a different workflow. An IT admin, they don't like it, but they will go and check out a secret and use that secret and then put that secret back and then the thing can change. There's no way you can get a developer to do that. They will blow a gasket. And so they wanna use native tools, they wanna be able to use the workflow that they're used to. And this is why that just-in-time credential insertion was so critical because we want them to also adopt these types of capability. And that's what we built it for. But now of course AI also needs that. And so it's actually an awakening in the enterprise that standing privileges are bad. And the way to get rid of that is runtime authorization. And Delinea has the opportunity to be able to deliver that for folks.
Krista Case
>> Absolutely. And one more question before we move off of this point. So we've been thinking so much about AI agents and securing those identities for good reason. You mentioned there's going to be this resurgence and focus on the human piece of it as well. If you had to maybe think about the one or two key implications for securing human identities as we start to move into this AI era, what might it be?
Art Gilliland
>> Yeah, I think it is that adoption. The biggest thing that slows these things down or creates conflict in an enterprise is candidly the end user adoption. If you force them to change the way they work, they're going to complain, right? If you put more roadblocks in their way, they're going to complain. And so how can you go faster but without giving up control? The controls that you need so you don't have to make that false trade-off between go fast and be productive and be secure. And so the way you do that is you build these things into the workflow. And so the permissions, the credentials kind of happen invisibly to the end user. I'm just using the tools I normally would use to write code or administer infrastructure or the AI agents doing what it does. But you still get the auditability, you still get the visibility, you still get policy enforcement. And no standing privileges. And I think that's going to be the differentiator. If you can make it part of the workflow without actually slowing people down, they will adopt it. And I think that's going to be the unlock, which we're super excited about.
Krista Case
>> I agree. It has to, like you say, not get in the way of their productivity. sometimes I don't even like installing the updates on my PC, never mind even going further than that.
Art Gilliland
>> Oh, two-factor authentication again.
Krista Case
>> Okay.
Art Gilliland
>> Exactly. There's got to be an easier way.
Krista Case
>> Exactly. And it's an interesting conversation, I think. So we've been talking a lot about two ends of the spectrum, one being the visibility, turning the lights on and addressing the shadow AI piece of it. And the other kind of governance and putting these guardrails in place. And I think to your point about businesses being pressured to move faster, I think security teams are trying to almost solve both problems. At once. So, over to you.
Krista Case
>> Yes
Krista Case
>> . So, a closing thought here might be if you were to give maybe one piece of advice to a practitioner that's trying to sort of navigate this, what might it be? maybe what's a good place for them to start if they're walking the show floor and they're feeling overwhelmed and they don't know where to begin?
Art Gilliland
>> Yeah, look, obviously, we're very focused on being able to help people deliver this without creating a lot of end-user pushback. And so for someone who wants to try to start, right, it's whether it's a pilot or it's a place to just use it in a sort of sandbox. I think this is the way I would say you should start is focus on a really critical asset. Figure out how to protect that asset, and then let candidly AI do its thing, let the people do their thing and control it at that point. And this is where runtime authorization just really gives you that pathway. And so Delinea is obviously a great place to do that. And so we would say, come talk to us and we can help you understand sort of how you do that for AI and also how you extend that out to humans. And I think that would be what I would tell people.
Krista Case
>> Absolutely. We need to address the spectrum for sure.
Art Gilliland
>> Absolutely. No question.
Krista Case
>> Art, it's been a pleasure. Thank you so much for joining us.
Art Gilliland
>> It's my pleasure. Thank you very much for having me.
Krista Case
>> We really appreciate it.
Art Gilliland
>> Cheers.
Krista Case
>> And thank you so much for watching. We're going to be right back in just a few minutes with more analysis live here from Black Hat 2026.