Governing Machine and AI-Agent Identities: Professor Kai London on the Worst-Controlled Class

 

By the Resolute Islands News Technology Desk

Professor Kai London, board advisor and interim/fractional CISO, CIO and CTO
Professor Kai London — board advisor & interim CISO/CIO/CTO. Credit: professorkailondon.com

Amid all the attention on human passwords and phishing, Professor Kai London, a senior CISO, points to a quieter and faster-growing danger. “The fastest-growing and worst-controlled class of identity in almost every organisation is not human,” he says. “It is machines — service accounts, API keys, automation — and now AI agents that can act on their own.”

“Every AI agent you deploy is a login with real reach. It needs an identity, a boundary, monitoring and a kill-switch — exactly like a privileged human user, only faster and at greater scale.”

The invisible workforce

London notes that machine identities typically outnumber human ones many times over, and are often granted broad, standing privileges that nobody reviews. “They were set up to make systems work, not to be governed,” he says. “That is precisely the problem.”

AI agents change the stakes

As organisations deploy AI agents that can take actions autonomously, the risk sharpens. “An agent is a new kind of employee and a new kind of attack surface at once,” London says. “If it is compromised or misbehaves, it can act quickly and at scale.”

Applying the doctrine

His prescription extends the same discipline used for humans: authenticate machine and agent identities, apply least privilege, monitor their behaviour, rotate and manage their credentials, and always have a way to shut them down. “A kill-switch is not optional for an autonomous agent,” he stresses.

A governance gap to close

London urges organisations to inventory their non-human identities — a step many have never taken. “You cannot govern what you have not counted,” he says. “And most organisations would be startled by how many powerful non-human identities they run.”

For any operator increasingly reliant on automation and AI, London's message is urgent: the identities that never sleep and never get watched are becoming the most dangerous of all — and governing them is now core to security.


About Professor Kai London. Professor Kai London is a senior technology, security and transformation executive with 25+ years of board- and C-suite leadership across banking, aviation, defence, government and critical national infrastructure. He is Founder & CEO of Quantum AI Systems Security, an Honorary Professor in Cybersecurity, AI & Quantum Computing and a UCL researcher, holding CISSP, CISM, CCISO, ISO 27001 Lead Auditor, ISO 42001, DORA and NIS2 credentials. He is available for board advisory, NED and interim/fractional CISO/CIO/CTO mandates across the UK and internationally. Learn more at professorkailondon.com.

Popular posts from this blog

Why Recruiters Are Racing to Place Interim and Fractional CISOs: Professor Kai London Explains

Securing the Signal: Professor Kai London on Satellite and Wireless Security for High-Arctic Operations

Defending the Digital Arctic: Professor Kai London on Cyber Resilience for Sovereign and Remote Operations