Burning Tree joins RSA Identity Unmasked to discuss AI, identity and the changing security landscape

Burning Tree CEO David Lello recently joined RSA’s Identity Unmasked video series for a special two-part discussion exploring one of the most significant challenges facing security leaders today: the intersection of Artificial Intelligence and Identity Security.
AI is changing the security landscape rapidly. But while the technology may be new, many of the underlying challenges are not.

At Burning Tree, our view is that AI does not suddenly make established security principles obsolete. Instead, it dramatically changes the speed, scale and accessibility with which vulnerabilities can be discovered and exploited. Organisations with strong identity controls, defence in depth, effective vulnerability management and mature security governance are therefore starting from a very different position from those without them.

The two RSA discussions explore both sides of this challenge.

Part 1 — How AI is Changing the Rules of Attack

The first episode examines how attackers are already using AI to scale identity-based attacks, automate social engineering and make impersonation increasingly convincing.

AI-powered phishing, deepfakes and increasingly sophisticated social engineering challenge some of the assumptions organisations have traditionally made about identity and trust.

The issue is not simply that AI creates new attacks. It can make existing techniques faster, cheaper, more scalable and more convincing.

That places greater importance on strong identity architecture, layered security controls and the ability to detect, respond to and recover when preventative controls inevitably fail.

Part 2 — Who Governs AI? Trust, Control and Accountability

The second discussion moves from attack to governance.

As organisations embed AI into business processes, applications and decision-making, important questions emerge:

Who — or what — is accessing our AI systems? What information can they access? What actions can they take? And who remains accountable for the outcome?

These are fundamentally questions of identity, access, governance and trust.

AI systems should not sit outside established security and governance disciplines. Organisations need to understand the identities interacting with AI — human and machine — control access to models and data, establish appropriate accountability, and ensure AI-driven actions remain visible and governable.

This is why we believe identity will become increasingly important as a control plane for secure AI adoption.

The organisations best positioned to take advantage of AI will not necessarily be those that adopt it fastest. They will be those that can innovate while maintaining control, resilience and trust.

Our thanks to RSA for inviting David to contribute to the conversation and for bringing together an important discussion about what AI means for the future of identity security.

Watch both episodes of RSA Identity Unmasked:
https://www.rsa.com/identity-unmasked/