General session image of Congress@it-sa

IAM as a matter of survival: when AI agents get your access rights

AI agents act with your access rights. Who’s behind them - and how do you document this for the EU AI Act, NIS2 & DORA?

Topic

Education and trainingData security / DLP / Know-how protectionIdentity and access managementAI & Quantum Security

When & Where

calendar_month

Tue, 10/27/2026 04:20 PM - 05:20 PM

location_on

Room Istanbul, NCC Ost

Download session as iCaldownload_for_offline

Details

  • Format:

    Lecture

  • Language:

    German

Session description

AI agents have long been working productively: They triage support tickets, answer employee questions using internal knowledge sources, process invoices, review transactions for fraud detection, and open pull requests in their own repository. In doing so, they access core systems - with the permissions of their users or, worse, with far greater permissions. This is precisely where a blind spot arises: Who is the identity behind the agent? What permissions apply when it acts on behalf of a human? And how do you demonstrate this to auditors, the EU AI Act, NIS2, and DORA? This presentation highlights the practical pitfalls of IAM - overprivileged service accounts, prompt injection, and a lack of traceability - and the resulting regulatory obligations. The focus is on “on-behalf-of” flows, ...