A separate governance layer is needed for AI agents that move autonomously, a forecast said. [Photo: Shutterstock]

As enterprise AI agents are put into live work systems, concerns have been raised that they are difficult to control with existing security and access-management frameworks alone. On Aug. 5, SiliconANGLE reported that security firm Rubrik unveiled "Rubrik Agent Identity" to control agent access at the level of tool calls. It said autonomous AI agents need a separate control layer.

Rubrik's AI head Deb Rishi (데브 리시) said AI agents create security issues different from those of humans or service accounts. Agents combine non-deterministic models with federated identities, making it hard to apply existing software security assumptions as they are.

The problem is that each individual action can take place within authorized permissions. An agent can pull data from Salesforce and then paste sensitive items into an external outbound email. Each step may be allowed, but the combination of the two actions can become risky.

Rubrik said it applied a small language model called "Sage," trained to judge behavior like a cybersecurity expert, to address the issue. Rishi said agents can do 10 times more work than a person at the same time, making it difficult to respond by having people repeatedly press an approval button.

Observability was presented as the starting point for agent governance. In large-scale environments, however, raw telemetry becomes another burden. Rubrik said its internal operations generate trillions of tokens, and a separate intelligence layer is needed to identify risk signals and periods of surging costs.

This case shows that AI agent security does not end with authorization alone. An analysis said companies have entered a stage where they must manage not only individual actions by agents, but also combinations of actions, cost concentration and operational visibility.

Cases of using AI agents are also increasing in South Korea. Kakao is moving to build a marketplace where AI agents can be searched and used in one place. It plans an ecosystem, like an app store, where various AI agents and tools can be registered and verified, and users can find needed functions and combine them for use.

With this integration, users are expected to be able to get food recommendations through AI and handle orders and payments all at once within KakaoTalk chat rooms without switching to a separate app, but there are still areas of caution over control of security and access-management frameworks.

Keyword

#Rubrik #Rubrik Agent Identity #Sage #Salesforce #Kakao
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.