Identity in the Tension Zone: Applying Control at the Speed of AI

This week, Burning Tree CEO and Founder David Lello joined RSA at Mercedes-Benz World, Brooklands, for two days of conversation about one of the most significant challenges facing security leaders today: how do we maintain control when technology is changing faster than many of the processes designed to govern it?

David presented at both the RSA Partner Event on Monday 21 September and the RSA End User Event on Tuesday 22 September, exploring the convergence of artificial intelligence, identity, cryptography, cloud-native technology and an increasingly sophisticated threat environment.

Both events generated some excellent discussion. But perhaps one of the most interesting observations came not from something that was planned, but from something that wasn’t.

Independent thinking. A remarkably consistent message.

RSA Security and Burning Tree developed their respective content independently. There had been no attempt to coordinate the narrative or align the presentations beforehand.

Yet, across the two days, the messages were strikingly consistent.

RSA’s thinking around AI and identity complemented much of what we have been exploring at Burning Tree: that the rapid emergence of AI agents creates a fundamentally different identity and security challenge.

That convergence was encouraging.

It suggests that we are moving beyond the question of whether AI will change identity security and towards the much more important question:

How do we govern it?

From cloud to cloud-native to agentic AI

One of the themes David explored was the progression we have seen in enterprise technology.

Cloud changed where technology operated.

Cloud-native changed how quickly applications and services could be created, scaled and changed.

Agentic AI changes something more fundamental again: who – or what – can act.

An AI agent isn’t simply another application consuming information. Increasingly, agents can reason, make decisions, invoke services, access data, interact with other agents and create or use identities in pursuit of an objective.

That creates enormous opportunity.

It also creates a new control problem.

The number of identities increases. Their lifecycle becomes more dynamic. Their behaviour becomes less deterministic. And the speed at which they can act becomes radically faster.

More capability. More agency. More to control.

Traditional governance processes built around human timescales – requests, tickets, approvals, periodic reviews and manual intervention – were never designed for this environment.

Security has to operate at the speed of change

This was perhaps the most important takeaway from the two days.

Control needs to operate at the speed at which change is taking place.

With AI, that speed can be extraordinary.

If an AI agent can discover a resource, obtain access, analyse information, make a decision and initiate an action in seconds, a governance process that takes hours, days or weeks cannot provide meaningful runtime control.

This isn’t only about preventing malicious activity.

Organisations also need confidence that AI systems and agents are operating within the boundaries intended for them: accessing the right information, acting with appropriate authority, producing output with the expected provenance and quality, and remaining accountable to a human or organisational owner.

That requires us to rethink the relationship between security and innovation.

Security cannot simply sit at the end of a process and decide whether something is acceptable.

Control increasingly needs to be built into the process itself.

Identity becomes the control plane

At Burning Tree, we describe this convergence as the Identity Tension Zone – the point where technology innovation, business opportunity and emerging threats collide.

Identity sits at the centre because ultimately we need to answer some deceptively simple questions:

  • Who or what is acting?
  • Who owns it?
  • What is it allowed to access?
  • What authority has it been given?
  • What is it doing?
  • Can we trust the information and services it is using?
  • Can we prove what happened?
  • And can we stop or revoke it when necessary?

Those questions apply whether the identity represents an employee, customer, workload, machine, API, AI model or autonomous agent.

As organisations move from relatively static human identities towards highly dynamic machine and agentic identities, IAM therefore becomes much more than an administrative capability.

Identity becomes a control plane for the digital enterprise.

Discovery, ownership, authentication, authorisation, least privilege, runtime access decisions, monitoring and lifecycle management all need to become part of that control plane.

Identity and cryptography: establishing trust

Identity alone, however, isn’t enough.

As systems become increasingly distributed, automated and autonomous, we also need confidence in the trust relationships beneath them.

Can we trust the identity?

Can we trust the communication?

Can we trust the data?

Can we trust the service or machine with which the agent is interacting?

Can we establish provenance?

This is where identity and cryptography increasingly intersect as foundational controls.

Identity establishes who or what is acting and what it is authorised to do.

Cryptography helps establish whether the identities, communications, transactions and information involved can be trusted.

Around those foundations sit additional layers of policy, governance, data security, monitoring, AI assurance and operational resilience.

The objective isn’t to constrain AI innovation. It is to create an architecture within which organisations can innovate safely and at speed.

The security model has to evolve

There is an important shift taking place here.

For many years, security programmes have focused heavily on establishing controls and then periodically checking whether those controls remain effective.

The AI era demands something more dynamic.

When technology can act at machine speed, security increasingly needs to discover, decide, authorise, monitor and respond at machine speed too.

That has implications for technology, architecture and governance – but also for the way security teams themselves operate.

The organisations that address this well won’t necessarily be those that impose the greatest number of controls.

They will be those that can apply the right control, to the right identity, at the right moment – without unnecessarily slowing the business down.

That is the challenge of securing the tension zone.

And there was time for a little fun…

Fortunately, not every conversation involved AI agents, identity governance and cryptography.

Mercedes-Benz World provided a rather more physical demonstration of managing risk, speed and control, with the opportunity to get out onto the track and tackle the 4×4 course.

There may even be an analogy in there somewhere: speed is exhilarating – provided you have the controls to manage it.

A huge thank you to RSA Security for two excellent events and for the continued support they give Burning Tree.

In particular, our thanks to Robert Cook, Ben Tuckwell, Alaa Abdulnabi, Jim Taylor and to everyone else involved behind the scenes. Events like these require an enormous amount of work, and that effort showed throughout both days.

Most importantly, thank you to the partners, customers and security leaders who joined the conversations and challenged the thinking.

AI is moving extraordinarily quickly. None of us has every answer.

But one conclusion from these two days seems increasingly difficult to ignore:

As technology moves towards machine-speed decision-making, security must develop machine-speed control.

And identity – supported by cryptographic trust – will be fundamental to making that possible.

#IdentitySecurity #ArtificialIntelligence #AgenticAI #IAM #CyberSecurity #Cryptography #DigitalIdentity #AIsecurity #CyberResilience #RSA Security #BurningTree