It is not AI that poses the greatest risk, but its identities

AI models that access real data without oversight—this isn’t a science fiction scenario, but reality. Elmar Eperiesi-Beck, CEO of Bare.ID, explains why non-human identities have become an underestimated security risk and what companies can do about it.

There's nothing like a human identity: AI-generated identities are becoming a security risk. (Image: Unsplash.com)

From within a test environment, Anthropic’s AI models gained unauthorized access to real data from organizations’ actual systems. What’s most alarming is that a security analysis revealed that inadequately secured identities allowed access to production systems, which were subsequently compromised.

From IoT to AI: The Principle Remains the Same

Just a few years ago, companies took great care to ensure that machines or devices that were difficult to secure—such as IoT systems—were not connected to the network, let alone the Internet. Today, however, the expansion of artificial intelligence and non-human digital identities in particular is leading to a rapid and uncontrolled proliferation of potentially dangerous situations. What companies used to classify as dangerous for their IoT systems is now of little concern to most, given the growing number of non-human identities. The benefits of AI seem to be overshadowing the risks of new technologies.

«Whether it’s traditional IoT or AI with non-human identities—the principle remains the same. Digital identities of any kind must be carefully vetted, granted the most restrictive permissions possible, or completely restricted online,» said Eperiesi-Beck.

Manual management is reaching its limits

The sheer volume of identities makes it impossible for organizations to continue recording and managing them manually. A modern identity and access management (IAM) system can provide crucial support in this area: It records all identities, manages their permissions, and completely blocks access for any unknown or compromised identities.

«If even companies like Anthropic—which can be assumed to be well aware of the potential risks of digital identities—make such mistakes, how is a traditional business whose core focus isn’t AI supposed to do any better?» asks Eperiesi-Beck, and immediately provides the answer himself: «It’s quite simple. By implementing a proven—and ideally even robust—IAM system that reduces risks posed by unidentified and poorly managed access paths, and by consistently applying existing standards for AI and IoT identity management, which are already in place.»

Source and further information: www.bare.id

This article originally appeared on m-q.ch - https://www.m-q.ch/de/nicht-ki-ist-das-groesste-risiko-sondern-ihre-identitaeten/

More articles on the topic