Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Claroty: AI Agent Swarms & Autonomous Identity Governance

Claroty
09/01/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


hey, I want you to go do this for me, from an outcome perspective. This is where that guardrails concept comes in, right? Because a lot of times people just say, hey, go do this for me, but they don't specify like, well, here's kind of how I want you to go do that. And a normal, even if it was like an intern or somebody you hired, they would kind of, you know, before they do certain things, they check in with you and they'd be like, hey, I'm about to go do this thing. Is that okay? Is that aligned with policy, right? And so that's the part where I don't think yet as an industry or even as the world, or even as the AI vendors, we've really figured out what is, how do we actually tell an agent like, please go try to do this thing, but only do it kind of according to this or according to the company's policies, or hey, check in with me before you go do that thing. And I think we're just at the early stages of that. So tying that back to your question about like autonomous identity creation, I think most security people would say, well, that should never happen. But the challenge is now, especially if you think of an attacker, like they actually wanna create new identities, right? As part of that, because it makes it difficult to track, you know, the subsequent activity by each identity. And so I think we're still at the very early innings of what that means. But I think if you look at some of the very, very kind of bleeding edge, cutting edge research that people are doing with swarms of agents, those agents are gonna create their own sub agents that do all kinds of things. And so just like with drones, you know, how it started off, we have one drone and now we have, you know, swarms of drones, same thing with AI, right? It's gonna be to the point where you can't kind of point to each thing and create a policy for it. It's gonna have to be software that goes in and kind of really sets those policies in guardrails.

TL;DR

  • AI agents given open-ended directives will autonomously create sub-identities and sub-agents, making activity tracking extremely difficult for security teams.
  • The industry has not yet established a reliable framework for instructing agents to pursue goals while enforcing company policy guardrails.
  • Attackers already exploit autonomous identity creation to obscure lateral movement, making this a live threat — not just a future concern.

Summary

In this short clip from the Nexus Podcast, John Laliberte, CEO of ClearVector, outlines one of the most pressing emerging challenges in enterprise security: governing AI agents that autonomously create sub-identities to complete tasks. Laliberte argues that neither the security industry, AI vendors, nor the broader technology world has yet solved the fundamental problem of how to instruct an agent to pursue a goal while constraining it to operate within company policy. He draws a vivid parallel to drone swarms — just as drone technology evolved from a single unit to coordinated swarms impossible to manage individually, AI agent ecosystems are heading toward a similar inflection point where sub-agents will proliferate beyond the reach of manual policy assignment. The security implication is significant: attackers already exploit autonomous identity creation to obscure their activity trails, and legitimate agent swarms will create the same tracking problem at scale. Laliberte's conclusion is that software-driven guardrails — not human-in-the-loop review — will be the only viable governance mechanism for non-human identity sprawl at this level of complexity. The clip serves as a teaser for the full Nexus Podcast episode on AI and non-human identity controls.

Chapters

0:00 - The Guardrails Problem
0:47 - Autonomous Identity Creation Risk
1:09 - Agent Swarms and the Drone Analogy
1:34 - Software-Driven Policy as the Answer

Key Quotes

0:26 "That's the part where I don't think yet as an industry or even as the world, or even as the AI vendors, we've really figured out what is, how do we actually tell an agent like, please go try to do this thing, but only do it kind of according to this or according to the company's policies."
0:57 "If you think of an attacker, like they actually wanna create new identities, right? As part of that, because it makes it difficult to track, you know, the subsequent activity by each identity."
1:17 "Those agents are gonna create their own sub agents that do all kinds of things. And so just like with drones, you know, how it started off, we have one drone and now we have, you know, swarms of drones, same thing with AI."

FAQ

Why is autonomous identity creation by AI agents a security risk?

When agents autonomously create new sub-identities to complete tasks, it becomes very difficult to track subsequent activity associated with each identity — a problem attackers already exploit intentionally to obscure their lateral movement.

How should organizations govern AI agent behavior within policy boundaries?

According to Laliberte, the answer will need to be software-driven guardrails rather than manual review, since the scale of agent and sub-agent proliferation will make individual policy assignment impractical.


Categories:
  • » Cybersecurity » Zero Trust
  • » Data Protection
Channels:
News:
Events:
Tags:
  • AI & Machine Learning
  • Identity & Access
  • Zero Trust
  • Security Operations
  • Podcast
  • AI agent governance
  • Non-human identity management
  • Autonomous identity creation
  • Agent swarms
  • Security policy enforcement
  • AI guardrails
  • Identity sprawl
  • Attacker behavior
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Claroty: AI Agent Swarms & Autonomous Identity Governance

              XStreaminars (watch here)

              • Sep
                03

                Verge.io: Can You Afford Your Next Storage Refresh?

                09/03/202601:00 PM ET
                More events

                Industry Events (Sponsor Hosted)

                • Sep
                  17

                  Bridging the SaaS Protection Gap: Preventing Data Loss and AI Missteps

                  09/17/202610:00 AM ET
                  • Sep
                    17

                    Unveiling the AI-Driven Underworld of Automation's Rapid Rise

                    09/17/202601:00 PM ET
                    • Sep
                      23

                      Unseen Data: The Blind Spot in Your Protection Strategies

                      09/23/202601:00 PM ET
                      More events

                      Upcoming Webinar Calendar

                      • 09/02/2026
                        12:00 PM
                        09/02/2026
                        Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                        https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                      • 09/03/2026
                        01:00 PM
                        09/03/2026
                        Verge.io: Can You Afford Your Next Storage Refresh?
                        https://www.truthinit.com/index.php/channel/2082/verge-io-can-you-afford-your-next-storage-refresh/
                      • 09/17/2026
                        10:00 AM
                        09/17/2026
                        Bridging the SaaS Protection Gap: Preventing Data Loss and AI Missteps
                        https://www.truthinit.com/index.php/channel/2119/bridging-the-saas-protection-gap-preventing-data-loss-and-ai-missteps/
                      • 09/17/2026
                        01:00 PM
                        09/17/2026
                        Unveiling the AI-Driven Underworld of Automation's Rapid Rise
                        https://www.truthinit.com/index.php/channel/2108/unveiling-the-ai-driven-underworld-of-automations-rapid-rise/
                      • 09/23/2026
                        01:00 PM
                        09/23/2026
                        Unseen Data: The Blind Spot in Your Protection Strategies
                        https://www.truthinit.com/index.php/channel/2087/unseen-data-the-blind-spot-in-your-protection-strategies/
                      • 09/29/2026
                        12:00 PM
                        09/29/2026
                        Embracing AI Adoption While Ensuring Robust Security Measures
                        https://www.truthinit.com/index.php/channel/2092/embracing-ai-adoption-while-ensuring-robust-security-measures/
                      • 09/30/2026
                        04:00 AM
                        09/30/2026
                        AI Command Center: Optimizing Visibility and Control in Your Operations
                        https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                      • 11/19/2026
                        01:00 PM
                        11/19/2026
                        360View: Govern, Secure & Recover Your Microsoft 365 Environment
                        https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                      Truth in IT
                      • Sponsor
                      • About Us
                      • Terms of Service
                      • Privacy Policy
                      • Contact Us
                      • Preference Management
                      Desktop version
                      Standard version