Governing Machine and AI-Agent Identities: Professor Kai London on the Worst-Controlled Class
By the Resolute Islands News Technology Desk
Amid all the attention on human passwords and phishing, Professor Kai London, a senior CISO, points to a quieter and faster-growing danger. “The fastest-growing and worst-controlled class of identity in almost every organisation is not human,” he says. “It is machines — service accounts, API keys, automation — and now AI agents that can act on their own.”
“Every AI agent you deploy is a login with real reach. It needs an identity, a boundary, monitoring and a kill-switch — exactly like a privileged human user, only faster and at greater scale.”
The invisible workforce
London notes that machine identities typically outnumber human ones many times over, and are often granted broad, standing privileges that nobody reviews. “They were set up to make systems work, not to be governed,” he says. “That is precisely the problem.”
AI agents change the stakes
As organisations deploy AI agents that can take actions autonomously, the risk sharpens. “An agent is a new kind of employee and a new kind of attack surface at once,” London says. “If it is compromised or misbehaves, it can act quickly and at scale.”
Applying the doctrine
His prescription extends the same discipline used for humans: authenticate machine and agent identities, apply least privilege, monitor their behaviour, rotate and manage their credentials, and always have a way to shut them down. “A kill-switch is not optional for an autonomous agent,” he stresses.
A governance gap to close
London urges organisations to inventory their non-human identities — a step many have never taken. “You cannot govern what you have not counted,” he says. “And most organisations would be startled by how many powerful non-human identities they run.”
For any operator increasingly reliant on automation and AI, London's message is urgent: the identities that never sleep and never get watched are becoming the most dangerous of all — and governing them is now core to security.
About Professor Kai London. Professor Kai London is a senior technology, security and transformation executive with 25+ years of board- and C-suite leadership across banking, aviation, defence, government and critical national infrastructure. He is Founder & CEO of Quantum AI Systems Security, an Honorary Professor in Cybersecurity, AI & Quantum Computing and a UCL researcher, holding CISSP, CISM, CCISO, ISO 27001 Lead Auditor, ISO 42001, DORA and NIS2 credentials. He is available for board advisory, NED and interim/fractional CISO/CIO/CTO mandates across the UK and internationally. Learn more at professorkailondon.com.
