AI Agents Push Identity Security Beyond Human-User Controls
An iTNews Asia interview with Palo Alto Networks executive Jeffrey Kok shows how AI agents, machine identities and persistent access are forcing enterprises toward continuous verification, least privilege and platform-based governance.

In an iTNews Asia interview, Palo Alto Networks executive Jeffrey Kok framed AI-driven identity security as a control problem that is outgrowing the human-user playbooks most enterprises still rely on, as cloud services, SaaS applications and AI systems reduce the value of older network-centred defences.
The pressure comes from a wider shift in enterprise technology.
Valid identities remain a primary path for attackers trying to move inside corporate environments.
Once an attacker compromises a trusted identity, traditional perimeter controls can be bypassed more easily.
Machine identities make that exposure harder to govern.
Human accounts usually move through familiar routines such as password resets, onboarding, offboarding and access reviews.
Machine accounts, API keys and service credentials often sit outside those routines, and they can remain available for long periods without the same continuous oversight.
AI agents add another layer because they can operate across applications, APIs and third-party services.
As those agents take on more enterprise tasks, the question shifts from whether organisations will use AI to how they limit what each system can reach, when it can reach it and what happens when behaviour changes.
The control model Kok described starts with reducing standing access.
Instead of leaving machine credentials permanently available, organisations would move toward permissions granted for a defined task and then revoked.
That just-in-time and just-enough approach extends zero trust and least privilege from human users to machines and autonomous AI systems.
Governance also has to become more continuous.
Static approvals or one-time security gates are a poor match for AI systems that may connect services, trigger workflows or expose new pathways as business teams expand usage.
Continuous verification gives security teams a way to maintain trust only while behaviour stays within expected bounds.
The speed of AI-enabled attacks raises the operational stakes.
Human analysts cannot be expected to respond at machine speed if attackers use AI to accelerate reconnaissance, credential abuse or lateral movement.
Detection and response therefore need more autonomous capability, but that is difficult when identity, cloud, endpoint and application controls are split across isolated tools.
That is where platformisation becomes part of the security argument.
A common platform can help apply identity governance across SaaS, cloud, on-premises systems and other environments instead of forcing teams to stitch together separate products for each layer.
For large organisations, the practical path is gradual: extend existing identity and governance practices to machine identities first, then tighten controls around AI agents as their role expands.
Kok’s longer-term test is whether AI environments can absorb “constant friction.” The idea is not to slow adoption for its own sake, but to run repeated exercises that reveal vendor risk, governance gaps and failure points before attackers exploit them.
The operating condition for enterprise AI is therefore a discipline of continuous testing, limited access and fast response, rather than trust in any single model or security control.




















