Identity has long been a primary route for attackers into enterprise environments, but the rapid adoption of AI, cloud and SaaS is changing both the scale of the problem and the way organisations need to defend against it.
Delving into these new security challenges in a conversation with iTNews Asia, Jeffrey Kok, Senior Director at Palo Alto Networks, said the rise of machine identities and AI agents is forcing enterprises to rethink identity security, governance and defensive strategies.
Kok explained that identity is not a new security perimeter, buta primary attack path for more than a decade. Compromising a valid identity allow attackers a direct avenue to bypass traditional defences.
He added that the shift to SaaS and cloud also means organisations can no longer rely as much on traditional network security. As AI becomes more embedded in the enterprise, controlling who or what can access systems is becoming increasingly important.
Machine identities are creating a more complex security problem
Human identities can be managed through established processes such as password changes, onboarding and access reviews. Machine identities do not fit neatly into those models.
“You can't really do that for machines,” Kok said, pointing to the difficulty of applying traditional password-management practices to machine identities.
AI is adding another layer of complexity. Kok said AI adoption is growing rapidly, while the number of AI and non-human identities can expand much faster than traditional human user populations.
That creates a problem with persistent access. Machines have traditionally been given credentials or API keys that remain available, often without the same level of continuous oversight applied to human users.
In an AI-driven environment, Kok argued, organisations should instead move towards access that is granted only when required for a specific task and revoked afterwards.
This approach, he said, can help organisations move towards zero standing privilege, where access is provided on a just-in-time and just-enough basis rather than remaining permanently available.
Governance has not kept pace with AI
The challenge is not simply technological. Kok said it also reflects a gap between existing governance practices and the way enterprise technology is now being deployed.
As organisations deploy AI agents with access to enterprise applications, APIs and third-party services, attackers are also beginning to see machine identities as a growing attack surface.
Hence the focus should shift from whether organisations will use AI to how they can secure it. Many governance frameworks were designed around human users rather than machines and autonomous AI agents. “The principles are universal. You apply to humans, machines, and AI,” he said, pointing to concepts such as zero trust and least privilege.
This also requires a move away from static security gates towards continuous verification and authorisation. “Maintain trust that's going to be continuously verified,” Kok said, stressing the need to detect and respond when an AI system behaves in an undesirable way.
Organisations must also consider how legitimate AI connections could be abused. As AI is increasingly used to connect systems and capabilities, those same connections could potentially be exploited by threat actors.
Defending against AI at machine speed
The speed of AI-powered attacks presents another challenge for conventional security operations. Kok argued that human defenders cannot be expected to respond at machine speed when attackers are using AI to accelerate their operations.
Organisations need autonomous detection and response capable of identifying and acting on threats quickly. But that requires security technologies to operate on a common platform rather than remain isolated in multiple silos.

If I don't have a platform, I have 100 different technology silos. How is AI going to help? Even if AI can detect, there's no way that they can respond.
- Jeffrey Kok, Senior Director at Palo Alto Networks,
Platformisation can help address security fragmentation
Kok said organisations are increasingly discovering that their problem is not a shortage of security technologies, but an excess of disconnected tools. A common platform can make it easier to apply governance across SaaS, cloud, on-premises systems and other enterprise environments.
This becomes increasingly important as AI agents operate across those environments and create a new access layer that traditional governance may struggle to control.
Rather than continually stitching together siloed technologies, organisations can consolidate capabilities and apply governance more consistently through a platform-based approach.
Kok acknowledged that organisations cannot transform large, complex environments overnight and hence recommends gradually extending existing identity and governance practices to machine identities and AI agents.
Continuous “friction” could become the new security discipline
Looking ahead, Kok said successful AI adoption will not depend on a single factor such as the AI model, identity controls or governance. Instead, organisations will need to continuously test how their AI environments respond to threats and failures.
He suggests introducing “constant friction” into AI operations. He compared this to a continuous fire drill, disruptive enough to expose weaknesses, but valuable because it shows organisations how their systems respond and where improvements are needed.
That means repeatedly testing AI environments against potential risks, including third-party vendor risk, governance weaknesses and other security scenarios.
“The objective is not to create friction for its own sake, but to turn those tests into a cycle of continuous improvement,” he explained.
For Kok, the fundamental principles of security remain relevant. What must change is how those principles are applied to autonomous machines and AI agents.




