{"id":405,"date":"2026-04-08T09:11:13","date_gmt":"2026-04-08T09:11:13","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/405\/"},"modified":"2026-04-08T09:11:13","modified_gmt":"2026-04-08T09:11:13","slug":"rsac-identity-security-key-to-safe-ai-adoption","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/405\/","title":{"rendered":"RSAC: Identity security key to safe AI adoption"},"content":{"rendered":"<p>At RSAC 2026, AI\u2019s rapid integration into organizations highlighted the critical role of identity security in mitigating risks posed by agentic AI. Chris Kelly, Delinea\u2019s president for go-to-market, emphasizes that as AI shifts from a tool to an autonomous agent, every AI action must be tied to a verified identity and governed by real-time policies. In this Q&amp;A, Kelly also stresses that just-in-time access is essential for managing AI agents and privileged users.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-86796 \" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/04\/delinea-headshot-chris-kelly-lr.jpg\" alt=\"\" width=\"157\" height=\"203\"\/>Kelly (Delinea)<\/p>\n<p>What was the big trend coming out of RSAC 2026, and how do you see that trend shaping the industry in the next 12 to 18 months?<\/p>\n<p>Kelly: AI is already everywhere, but it became clear at RSAC that identity is at the core of enabling secure AI innovation \u2013 especially as we step further into the agentic AI era. Over the next year and a half, we\u2019ll see a growing push to govern AI agents more comprehensively. Companies are beginning to understand that the security risks of agentic AI are beginning to catch up with their potential to drive innovation. Their volume is already outpacing the security controls organizations have in place, so I think we\u2019ll see a shift from a \u201cspeed over security\u201d mentality to a \u201csecurity to enable growth\u201d approach.\u00a0\u00a0<\/p>\n<p>\u00a0<\/p>\n<p>Delinea\u2019s recent messaging is around AI agents. As we move to more AI-as-an-actor (not just a tool), how can CISOs maintain an audit trail for an agent making real-time decisions?<\/p>\n<p>Kelly: To maintain an audit trail for AI agents acting in real time, CISOs need to move beyond basic logging. Every action should be tied to a verified identity, evaluated against policy at the moment of execution and recorded with enough context to explain what happened, why it happened and what systems or data were involved.\u00a0<\/p>\n<p>That\u2019s especially important as organizations treat AI as an actor rather than a tool. Standing privileges create too much risk; the better approach is dynamic, just-in-time access so AI agents only get the permissions they need for a specific task, with access revoked once the task is complete, to ensure every action is fully attributable and auditable. AI agents are a new class of privileged user, and should be governed as such.<\/p>\n<p>\u00a0<\/p>\n<p>Continuous automation: Is the goal to make the password vault obsolete in favor of Just in Time access, or do they co-exist (and why)?<\/p>\n<p>Kelly: Password vaults aren\u2019t going away, but they\u2019re no longer enough on their own. Vaults are still essential for securing credentials, but organizations also need just-in-time access to reduce standing privilege and grant elevated access only when it\u2019s needed.\u00a0 For most organizations, vault and JIT work together to reduce risk in automated environments.\u00a0<\/p>\n<p><a href=\"https:\/\/delinea.com\/resources\/ai-and-identity-security-report-pdf\" rel=\"nofollow noopener\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-86800 size-medium\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/04\/Deliniea-637x358.png\" alt=\"\" width=\"637\" height=\"358\"  \/><\/a>Source: Delinea\u2019s \u201c2026 Identity Security Report\u201d<\/p>\n<p>Delinea is emphasizing identity resilience. For a CISO on a budget, is resiliency more about buying additional backup tools or about a fundamental change in how they architect their identity stack?<\/p>\n<p>Kelly: Identity resilience is more about strengthening the way identity is managed than adding backup tools. The biggest gains come from getting the basics right: enforcing least privilege and just-in-time access across environments. That doesn\u2019t mean ripping and replacing your entire identity stack. Resilience improves when organizations build stronger controls around the identities and access paths that matter most.\u00a0<\/p>\n<p>\u00a0<\/p>\n<p>If IT leaders only change one thing about identity governance in 2026, what should that be?<\/p>\n<p>Kelly: The main identity goal for IT leaders in 2026 should be to treat non-human identities with the same governance as human users. You can\u2019t secure what you can\u2019t see, so the first step is discovering every identity, understanding what access it has and identifying where privileges are excessive, persistent or unmanaged.<\/p>\n<p>\u00a0<\/p>\n<p>Meet Chris:<\/p>\n<p>Chris Kelly is the President of Go-To-Market (GTM) at <a href=\"https:\/\/delinea.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Delinea<\/a>, overseeing Global Sales, Channel and Customer Success. With more than 25 years of experience in the cybersecurity industry, Chris has a proven track record of scaling businesses and leading high-performing teams at every stage of growth, from startups to global enterprises.<\/p>\n<p>\u00a0<\/p>\n<p>If you like these insights on cybersecurity, sign up for the<a href=\"https:\/\/newsletter.smartbrief.com\/ISACA_Cyber?campaign=541e9ee3\" rel=\"nofollow noopener\" target=\"_blank\"> ISACA SmartBrief on Cybersecurity<\/a>, a daily look at the top news and workforce education topics.<\/p>\n","protected":false},"excerpt":{"rendered":"At RSAC 2026, AI\u2019s rapid integration into organizations highlighted the critical role of identity security in mitigating risks&hellip;\n","protected":false},"author":2,"featured_media":406,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[179,24,405,25,569,570,571],"class_list":["post-405","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ai","tag-agentic-ai","tag-ai","tag-ai-agents","tag-artificial-intelligence","tag-delinea","tag-identity","tag-rsac"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/405","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=405"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/405\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/406"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=405"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=405"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=405"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}