Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Druva: Governing AI Agents: Guardrails & Authentication

Druva
07/07/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


and as large enterprises, the risk that something goes wrong is huge. So, far, far less, I think it's probably changed mostly from the perimeter being the place you needed to be concerned about and making sure nothing got in. Internal. Now it's internal, and it is very much 50-50 between internal and external, that balance that you have to be worried about a well-intentioned employee who wants to do a good job, and they get an agent, and they start doing some work, and maybe there's a supply chain attack or something that allows an agent to do significantly more. So, I know we're, in the next couple of months, we're going to be talking about things like AA auth and new standards for authentication that have been worked through the various bodies to get to a consistent approach to how authentication should work for agents, delegated approval, and making sure that it's as limited as possible.

TL;DR

  • Enterprise customers are increasingly worried about the broad access AI agents can acquire, with the risk of something going wrong considered significant at scale.
  • The security threat model has shifted to roughly 50-50 internal versus external risk, meaning insider misuse — even unintentional — is now as concerning as external attacks.
  • Supply chain attacks targeting AI agents represent an emerging vector where a well-meaning employee's tool can be weaponized to do far more than intended.

Summary

In this short clip, David Gildea of Druva and Joseph Holland of Aon discuss the real-world security risks that AI agents introduce inside large enterprises. The conversation highlights a fundamental shift in how organizations must think about their threat surface: the traditional perimeter-focused model has given way to an environment where internal and external threats are now roughly equal in concern. A well-intentioned employee deploying an AI agent can inadvertently open the door to supply chain attacks that allow that agent to operate far beyond its intended scope. Looking ahead, the speakers point to emerging authentication standards — including agent-to-agent (AA) auth and delegated approval frameworks — being developed across standards bodies to establish consistent, least-privilege access controls for AI agents. The key takeaway is that governing AI agents requires purpose-built authentication and strict permission scoping, not just perimeter defenses.

Chapters

0:00 - Enterprise AI Agent Risk
0:08 - Shift to Internal Threats
0:33 - Emerging Auth Standards

Key Quotes

0:00 "Our customers are definitely concerned about the access that these tools have, and as large enterprises, the risk that something goes wrong is huge."
0:17 "Now it's internal, and it is very much 50-50 between internal and external."
0:21 "You have to be worried about a well-intentioned employee who wants to do a good job, and they get an agent, and they start doing some work, and maybe there's a supply chain attack or something that allows an agent to do significantly more."

FAQ

What makes AI agents a unique security risk compared to traditional software?

AI agents can be granted broad access by well-intentioned employees and, if compromised through a supply chain attack, can perform actions far beyond their original scope — making least-privilege controls and agent-specific authentication critical.

What authentication standards are being developed for AI agents?

The speakers reference AA auth (agent-to-agent authentication) and delegated approval frameworks currently being worked through standards bodies to create a consistent, limited-access approach to agent authentication.


Categories:
  • » Webinar Library » Druva
  • » Cybersecurity » Zero Trust
  • » Data Protection
Channels:
News:
Events:
Tags:
  • AI & Machine Learning
  • Zero Trust
  • Identity & Access
  • Security Operations
  • Thought Leadership
  • short_form
  • AI agent security
  • Authentication standards
  • Supply chain attacks
  • Least-privilege access
  • Enterprise risk management
  • AI governance
  • Internal threat vectors
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Druva: Governing AI Agents: Guardrails & Authentication

              Industry Events (Sponsor Hosted)

              • Oct
                13

                Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance

                10/13/202601:00 PM ET
                • Oct
                  15

                  Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                  10/15/202611:00 AM ET
                  • Oct
                    20

                    Harnessing Data Governance for AI with Cyera and Snowflake

                    10/20/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 10/13/2026
                      01:00 PM
                      10/13/2026
                      Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance
                      https://www.truthinit.com/index.php/channel/2159/transitioning-from-cjis-to-ferpa-essential-audit-evidence-for-compliance/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Leveraging CISA’s Zero Trust Maturity Model for an AI-Driven Landscape
                      https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-for-an-ai-driven-landscape/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Aligning Agentic Intent: Understanding Your Agents' Purpose vs. Their Actions
                      https://www.truthinit.com/index.php/channel/2158/aligning-agentic-intent-understanding-your-agents-purpose-vs-their-actions/
                    • 11/05/2026
                      01:00 PM
                      11/05/2026
                      HUMAN Dialogue: Redefining Authentic Trust in the Agentic Internet
                      https://www.truthinit.com/index.php/channel/2160/human-dialogue-redefining-authentic-trust-in-the-agentic-internet/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version