The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/The Authority On...
The Authority On... artwork

AI and Non-human Identities

The Authority On... · 2025-12-09 · 12 min

0:00--:--

Key moments - from our scoring

Substance score

60 / 100

Five dimensions, 20 points each

Insight Density14 / 20
Originality11 / 20
Guest Caliber13 / 20
Specificity & Evidence10 / 20
Conversational Craft12 / 20

As AI systems transition from tools to autonomous decision-makers in enterprise networks, identity and access management must evolve beyond human-centric frameworks. Jim Walker, General Manager of Service Delivery at Olympus Solutions, argues that non-human identities - including AI models, service accounts, containers, IoT devices, and API clients - now vastly outnumber human users, yet most organizations lack visibility or governance over them. The episode maps a practical three-step approach: achieving visibility across cloud, on-premises, and edge environments; implementing automated lifecycle management for credentials and certificates; and applying zero-trust policies at scale. Walker emphasizes that without treating AI agents as first-class identities with proper authentication, authorization, and cryptographic lineage tracking, organizations risk creating "trust by hope" - autonomous systems operating with fuzzy accountability. Device Authority's identity and access management platform, combined with Olympus's managed security services, enables organizations to reduce operational friction while maintaining strong crypto hygiene. The conversation connects identity governance directly to AI governance itself, arguing that cryptographic proof of data lineage and policy adherence transforms AI from an unexplainable black box into a traceable, auditable system component.

Key takeaways

  • →Treat AI systems as first-class identities with the same authentication, authorization, and audit rigor applied to privileged administrator accounts.
  • →Non-human identities now comprise the majority of network transactions and authentications in modern environments, requiring automated lifecycle management rather than manual credential handling.
  • →Establish cryptographic assurance and auditable data sources for AI systems to prove the lineage of training data, model versions, and policy compliance throughout the AI lifecycle.
  • →Zero trust cannot function without strong identity governance and telemetry that can answer who or what is taking action, whether it should, and why - applied equally to AI as to human users.
  • →Shadow keys, certificates, and unauthorized services emerge when organizations lack visibility and governance over non-human identities, creating attack surface that appears in incident reports.

In this episode

  1. 1AI as Network Actors: From Tools to Autonomous Decision Makers
  2. 2Governing AI and Non-Human Identities: Three Core Principles
  3. 3The Silent Explosion of Non-Human Identities Across Enterprise Networks
  4. 4Visibility, Lifecycle Management, and Policy Automation at Scale
  5. 5Identity as the Foundation of Zero Trust and AI Governance
  6. 6Cryptographic Identity and Auditability for Intelligent Systems

Mentioned

Device AuthorityOlympus SolutionsMolly MarksJim Walker

Guests

Jim Walker

Topics in this episode

API securityAI governanceZero TrustService accountsNon-human identitiesidentity and access management (IAM)Cryptographic assuranceCertificate lifecycle managementPrivileged access managementDevice Authority

Questions this episode answers

Why are non-human identities becoming a critical security issue?

Non-human identities - service accounts, containers, APIs, IoT devices, and AI systems - now vastly outnumber humans in enterprise networks and handle the majority of authentications and transactions. Most are created quickly, often with unrotated credentials and untracked certificates, and cannot be managed manually at scale.

What are the three steps organizations should take to govern AI and non-human identities?

First, achieve visibility by discovering non-human identities across cloud, on-premises, operational technology, and edge environments. Second, implement automated lifecycle management for creation, approval, rotation, and revocation. Third, apply zero-trust policies and automation at scale using identity and access management platforms.

How does cryptographic identity help with AI governance?

Cryptographic certificates and digital signatures prove the lineage of AI models - which data trained them, which version was deployed, and which policies governed their decisions - creating auditable proof instead of relying on labels in user interfaces.

What does 'trust by hope' mean in the context of AI security?

It describes autonomous systems allowed to authenticate and act without strong identity governance and telemetry, meaning organizations cannot actually prove who took action, whether they should have, or why - a weak security posture disguised as automation.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

14 / 20

The episode delivers several substantive ideas about non-human identity governance that a security operator could apply: treating AI as first-class identity, the distinction between capability vs. guardrails, the lifecycle management framework (visibility → automation → policy), and the critique of 'trust by hope.' However, these insights are somewhat familiar to practitioners already working in IAM and zero trust; the episode lacks deeper technical specifics, case studies, or surprising counterintuitive angles that would elevate it further.

In a typical modern environment, the majority of authentication and authorization is non human. Humans are now the minority on our own networks.
treat AI as a first class identity. Give AI agents, models and pipelines proper identities just like you would a privileged administrator account or a critical service.

Originality

11 / 20

The core framing - that AI/non-human identity is becoming critical and requires governance anchored in IAM - is sound but not novel in 2024. The three-step framework (visibility → lifecycle → policy) and the invocation of zero trust principles are standard industry playbooks. The 'trust by hope' quip is memorable but relatively surface-level. The episode lacks contrarian takes, first-principles rethinking, or any argument that meaningfully challenges how most practitioners currently think about the problem.

you can't secure what you don't know exists
AI and automation should raise the bar for trust, not quietly punch holes in it

Guest Caliber

13 / 20

Jim Walker holds the role of General Manager of Service Delivery at a managed security services provider, placing him in middle-senior operations but not C-suite. He demonstrates solid practitioner experience (references to real RFPs, incident reports, and operational patterns) and credible field insight. However, he is not a CTO, CISO of a major enterprise, or someone who has scaled identity systems at massive Fortune 500 organizations. He is a capable operator but not top-tier caliber for a podcast that aims to reach B2B decision-makers seeking cutting-edge guidance.

At Olympus, we're starting to see AI and non human identities move from interesting edge cases to the core of how organizations operate day to day.
we're seeing it show up in real RFPs architectures and incident reports

Specificity & Evidence

10 / 20

The episode is almost entirely abstract and principle-based. There are no named customer examples, no quantified metrics (e.g., 'we discovered 2.3M untracked service accounts'), no timelines, no dollar figures, and no specific tools or configurations. Statements like 'hundreds of thousands or maybe millions of non human identities' and 'service account that's been active since 2012' are illustrative but not concrete evidence. The lack of real data, incident examples, or measurable outcomes significantly weakens the substance.

they've got hundreds of thousands or maybe millions of non human identities
expired search, taking down critical systems or static tokens, sitting in code repositories

Conversational Craft

12 / 20

The host Molly Marks asks reasonable follow-up questions ('how can organizations begin to wrap governance around that?', 'Why has this become such a critical issue?') but rarely pushes back or probe deeper. She accepts Jim's framing at face value and does not challenge vagueness or press for specifics. The conversation feels collaborative and cordial but lacks intellectual friction; there are no moments where the host questions an assumption, asks 'but what about X edge case?' or demands concrete examples. The tone is agreeable partner-to-partner rather than incisive inquiry.

It's really fascinating. It feels like we're moving from securing users to securing behaviors and algorithms.
That's so true.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker C75%
  • Speaker B22%
  • Speaker A3%

Most-used words

identity21authority14human12trust12device9identities9systems9governance7data7security6service6allowed6policy6molly5olympus5services5

Episode notes

In this episode, Device Authority's Molly Marks speaks to Jim Walker, General Manager of Service Delivery at Olympus Solutions about the intersection of AI and non-human identities.

Full transcript

12 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Welcome to the Authority on a podcast brought to you by Device Authority.

Speaker B: Hello and welcome to the Authority on the podcast where we explored the trends, technologies and transformations shaping the future of connected security. I'm your host for today, Molly Marks, Senior Director Partner Sales at Device Authority. Today we're diving into one of the most talked about topics in cybersecurity, the intersection of AI and non human identity. Joining me is Jim Walker, General Manager of service delivery at Olympus Solutions, a managed security services provider that helps organizations strengthen trust and resilience across digital ecosystems. Olympus is one of our valued partners at Device Authority and Jim brings a wealth of real world experience in operationalizing identity and access management at scale. Jim, it is great to have you on the Authority on.

Speaker C: Hey, thanks Molly. I'm excited to be here. This is one of those topics that used to be a conference panel conversation and now we're seeing it show up in real RFPs architectures and incident reports. At Olympus, we're starting to see AI and non human identities move from interesting edge cases to the core of how organizations operate day to day. So I'm really looking forward to unpacking what's real, what's hype and what people should do about it.

Speaker B: Yeah, thank you for that. So AI is transforming how we think about digital systems, automation and trust. So from your perspective Jim, what's changed most in how AI interacts with identity and security?

Speaker C: You know, the biggest shift is that uh, AI systems aren't just tools anymore, they're more and more becoming actors in our networks. We used to think in very human centric terms. Users log in, apps respond, and security wraps around all of that. Now we've got models that are making decisions, triggering workflows, talking to other services, and honestly in some cases other AIs, all without a human sitting there clicking a button instead of a user calls an API. You've got AI to AI services, um, and device to cloud interactions happening at machine speed. In a typical modern environment, the majority of authentication and authorization is non human. Humans are now the minority on our own networks. So the problem is most of our traditional identity frameworks were built for humans with usernames, passwords and maybe some other multi factor authentication token like a smart card. They weren't designed for self learning or autonomous systems that can spin up, scale out, make decisions and disappear in seconds. So the big change is this identity is no longer about who's logging in, it's about what's logging in, what's making decisions and what it has the authority to do. So if you don't model that correctly, you end up with powerful AI driven workflows operating with very fuzzy accountability.

Speaker B: It's really fascinating. It feels like we're moving from securing users to securing behaviors and algorithms. So how can organizations begin to wrap governance and accountability around that?

Speaker C: So, you know, you're right, Molly. We are shifting from who you are to what you're allowed to do. And does what you're doing really make sense? So practically, I'd say there are three starting points. One, treat AI as a first class identity. Give AI agents, models and pipelines proper identities just like you would a privileged administrator account or a critical service. That means authentication, authorization, logging, tied to those identities and not just buried in an application log. Treat them like they're core critical human privileged access identities and audit them as such. Define guardrails, not just the capabilities. Don't just ask, what can this AI do? Define it. What should it be allowed to do under. To do under policy and where combining. And that's where combining AI with your identity and access management. Stack your policies and your approvals really start to shine and matter and then make it all auditable. If an AI recommends or executes a high impact action, approving a large transaction, changing a configuration, rotating a certificate, whatever, you need a clear chain back to which identity it was, which data, uh, it was allowed to see, and what policies governed that decision. If you can't answer those questions, then you really don't have governance. You just have a very fast, confident black box.

Speaker B: That's so true. Um, Jim, So regarding that, let's talk about non human identities, such as devices, APIs, bots and workloads. Why has this become such a critical issue in recent years?

Speaker C: Well, you know, because non human identities quietly took over the network. Um, most organizations still think in terms of we have X thousand, uh, employees, but if you look under the hood, they've got hundreds of thousands or maybe millions of non human identities. Service accounts, containers, microservices, IoT devices, API clients, all talking to each other constantly. The explosion of automation means that most of your transactions, authentications and policy enforcement points now involve non human identities entities. So a lot of them are created quickly, often as one offs with credentials that were never rotated and certificates that nobody really frankly is tracking. Uh, manual management of keys, certificates and secrets simply doesn't scale anymore. You can't manage a million certificates with spreadsheets and set and forget configs. That's how you end up with expired search, taking down critical systems or static tokens, sitting in code repositories waiting to be abused. So the pattern we see is step one is visibility. You can't secure what you don't know exists. That means discovering non human identities across cloud on prem, operational technology and edge map what they talk to and what they're allowed to do. Your second step is the lifecycle management, creation, approval, rotation, revocation, all of it automated. No more service account that's been active since 2012 and you know, nobody really knows what happens if we turn it off anymore.

Speaker B: Uh,

Speaker C: step three is policy and automation at scale. That's where partners like Device authority and managed security service providers like Olympus come in. Our job is to give customers control without adding a wall of manual work to make strong identity and crypto hygiene almost boring and invisible because it just works in the background. If you do those things right, you reduce risk while also reducing your operational friction. If you do it wrong, you get shadow keys, shadow certs, shadow services that will absolutely show up in your next incident report.

Speaker B: Right? And without the visibility, zero trust can't really function because you can't apply policy to something you can't identify.

Speaker C: Exactly. Zero trust sounds great on a slide, but in practice it boils down to who or what is this? Should it be doing this right now? And can I prove it? AI and automation should raise the bar for trust, not quietly punch holes in it. Uh, if autonomous systems are allowed to authenticate and act without strong identity governance and telemetry, you don't have zero trust. You have trust by hope, which is really not a great security strategy.

Speaker B: So we've seen a lot of discussion around AI governance, not just about data use, but also about trust and accountability. How does identity management fit into that governance conversation?

Speaker C: So you know, it's, it's even with uh, AI and AI governance identity, just like in zero trust, identity is that anchor. So if you strip it down, governance is really about being able to say who or what tools took this action. Again, you know, what were they allowed to do and can we prove it? Can we reproduce the decision trail if we need to? Without strong identity, all of that above falls apart. So uh, for AI systems that means a few things. Identity. For the AI itself, the model, the agent, the pipeline, they need authenticated unique identity so that you can distinguish this is our production model from this is a test instance someone spun up on Friday 2. You need authenticated auditable data sources. If an AI model is making decisions based on data, you want cryptographic assurance that that data hasn't been tampered with and that it came trust from a trusted source. That's where digital certificates, signed data and robust PKI come into play. And from a cryptographic proof of lineage perspective, as models are trained, fine tuned and deployed, you want a clear lineage between which data, which version, which policies. Cryptographic identity such as key certificates, signatures lets you prove that lineage instead of just trub crude trusting a label in a user interface. When you combine all of that with good logging and policy, you get AI that is traceable and accountable. That's the difference between the AI did something weird and we're really not sure why to here's exactly what happened, when and under which identity and policy.

Speaker B: Looking ahead, where do you think we're heading in terms of securing intelligent interconnected systems?

Speaker C: You know Molly, we already know how to build trust frameworks for humans, services and devices. The next step is to extend those same principles, identity, strong authentication, cryptographic assurance and auditability to AI systems. If we treat AI as just another black box feature instead of a governed identity in the ecosystem, we'll repeat all the same mistakes we made with managed service accounts and shadow it. We'll just do it at a much faster machines level speed, right?

Speaker B: Yeah, that's exactly right. I want to thank you. This has been an incredibly insightful conversation and it's clear that AI becomes more embedded in how we live at work. Managing non human identity will be the backbone of digital trust. And to our listeners, thank you for joining us on the Authority on if you'd like to learn more about how Device Authority and Olympus Solutions are helping organizations secure the next generation of connected systems, please visit our website. They're both listed in the notes of this conversation. Thanks Jim.

Speaker C: Hey, thanks Molly.

Speaker A: Thank you for listening to this episode of the Authority on a podcast brought to you by Device Authority. If you have any questions about the subject matter in this podcast, please head to the Device Authority website. Device Authority. Com See you next time.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • How to Implement AI in Your Business: From AI Use Cases to Real ROI | Dr. Markus SchmidbergerUsing AI at Work · on AI governance92 / 100
  • #291 Why Most AI Projects Fail to Deliver ROI Sinohe Terrero CFO and COO, EnvoyGrowCFO Show · on AI governance91 / 100
  • Who Owns What Your AI Does?The Pre-Read · on AI governance85 / 100
  • Navigating AI Risks with Trevor Horwitz from TrustNetB2B Automation Spotlight · on AI governance79 / 100
  • SailPoint presents: How healthcare can secure AI tools and non-human identitiesHIMSSCast · on Non-human identities77 / 100
  • How AI is Changing Security Awareness TrainingThe SaaS CFO · on AI governance63 / 100

More from The Authority On...

All episodes →
  • Post-Quantum Cryptography56 / 100
  • Strategic Security in a Connected World: A Conversation with Grace Cassy
  • Guide to IoT/OT Visibility and Control
  • Introducing DA Academy
  • What's the Emergency? Public Safety in a World of IOT and Cybersecurity with David Ihrie, CTO at VIPC
Explore the best B2B Engineering & DevTools podcasts →
All The Authority On... episodes →