Agentic AI
,
Artificial Intelligence & Machine Learning
,
Events

1Password’s Dave Lewis on Unchecked Privilege and Security Debt

Anna Delaney (annamadeline) •
June 8, 2026    

Dave Lewis, global advisory CISO, 1Password

Treating non-human identities as service accounts rather than privileged actors has created a governance gap widening with every deployment, said Dave Lewis, global advisory CISO at 1Password.

See Also: Know Thy Enemy: Threats to Cyber Resilience

Most organizations deploying artificial intelligence agents have skipped the foundational step: understanding what those agents can access, what credentials they hold and what happens when something goes wrong. Agents are designed to complete tasks, and without strict guardrails, they can take actions that may result in unintended privilege escalation.

The blast radius of a poorly governed agent environment is far larger than most organizations have accounted for. “If we don’t get the fundamentals in place – securing the credentials, securing the access and making sure you have an overarching security governance program in place – the problems are going to compound,” Lewis said.

In this video interview with ISMG at Infosecurity Europe 2026, Lewis also discussed:

Why token burn rates are forcing organizations toward an inevitable course correction;
How accountability for agent actions ultimately falls on human leadership, not the technology;
How security debt and rising AI costs could force organizations to reassess deployments.

Lewis has 30 years of industry experience in IT security operations and management. He currently also sits on the advisory boards of Sightline Security, Byos.io and Knostic AI. He has previously worked in critical infrastructure for nine years as well as for companies including Duo Security, Akamai, Cisco, AMD and IBM.