Companies are adding AI agents, cloud tools and SaaS platforms faster than ever. This growth is creating a new kind of security problem tied to identity.
Jeffrey Kok, a Senior Director at Palo Alto Networks, spoke with iTNews Asia about the issue. He said identity has been a main way attackers get into company systems for more than ten years.
Once an attacker gets hold of a valid identity, they can often skip past normal security defenses. Kok said this is not a new problem, but AI is making it worse.
Machine Identities Are Harder to Manage
Human accounts can be managed with regular password changes and access reviews. Machine identities do not work the same way.
"You can't really do that for machines," Kok said. He explained that AI and non-human accounts are growing much faster than human user numbers.
Machines are often given credentials or API keys that stay active for a long time. These keys are not always watched closely, which creates an opening for attackers.
Kok said companies should move toward access that is only given when needed for a specific task. Once the task is done, the access should be removed.
This idea is sometimes called zero standing privilege. It means access is granted just in time and just enough for the job at hand.
Governance Rules Have Not Caught Up
The problem is not only about technology. Kok said many governance rules were built for human users, not for AI agents that act on their own.
As companies give AI agents access to apps, APIs and outside services, attackers are starting to target these machine identities too.
Kok said the basic rules of security, like zero trust and least privilege, still apply. The difference is that these rules now need to cover machines and AI systems as well as people.
He also said companies need ongoing checks instead of one-time approval. Trust should be verified continuously, not just granted once and left alone.
There is another risk to watch. Since AI systems are built to connect different tools and data sources, those same connections could be misused by attackers if not properly secured.
Kok said human security teams cannot always keep up with AI-powered attacks, which can move very fast. He said companies need automated detection and response tools that can act quickly.
But automated tools only work well if they are connected. Kok said having 100 separate security tools makes it hard for AI to detect and respond to threats in a useful way.
He suggested that companies use a single platform to manage identity and security across cloud, SaaS and on-site systems. This makes it easier to apply the same rules everywhere.
Kok said big companies cannot fix everything overnight. He recommends slowly extending existing identity practices to cover machine identities and AI agents.
Looking ahead, Kok said success will not come from one single fix. Companies need to keep testing their systems against new risks.
He compared this to a fire drill that repeats over and over. It is meant to find weak spots before real attackers do.
"The objective is not to create friction for its own sake, but to turn those tests into a cycle of continuous improvement," he said.