
Download Transcript (pdf)
AI Agents Have an Ownership Problem with Benny Czarny
AI agents are quickly becoming part of the enterprise environment. They have credentials, access company data, interact with systems and, in some cases, create or direct other agents.
That creates a security question organizations need to answer now:
Who is responsible for what those agents can access and do?
In this episode of ClearTech Loop, Jo Peterson speaks with Benny Czarny, CEO, Founder and Chairman of the Board at OPSWAT, about AI agent governance, identity, permissions, data protection and what CISOs should prioritize as autonomous AI becomes more common.
Benny has spent more than 20 years focused on cybersecurity and critical infrastructure protection. His view is straightforward: while AI may introduce new challenges, many of the security principles required to manage it are already familiar.
Every AI Agent Needs an Identity and an Owner
Benny argues that every AI agent should have its own identity and clearly defined permissions.
Sub-agents should not automatically inherit greater authority than the agent that created them, and permissions should remain limited to what each agent actually needs.
But technical identity is only part of the equation.
Every AI agent also needs a human owner who is responsible for understanding what it can access, what actions it can take and what happens when something goes wrong.
For CISOs, that means AI governance cannot exist separately from accountability.
AI Security Starts With Understanding Data Access
A major theme of the conversation is data.
Instead of focusing only on whether an AI model itself is secure, Benny encourages leaders to ask a more practical question:
What can the agent reach?
Organizations need visibility into the systems, data lakes and sensitive information available to each agent. That includes understanding how multiple agents interact and whether access should be segmented between different environments.
An AI agent with excessive permissions or access to the wrong information can create security and privacy risk regardless of how sophisticated the underlying model may be.
AI Governance Needs Real Authority
Many enterprises are creating AI governance committees, but governance only works when those groups have visibility and authority.
Benny recommends maintaining an inventory of AI agents, assigning ownership, classifying risk and putting appropriate controls around deployments.
Most importantly, organizations need someone with the authority to stop an unsafe AI deployment.
Without that, governance becomes little more than oversight without enforcement.
Starting With AI Governance? Begin With Inventory
For CISOs who are still early in their AI governance programs, Benny recommends starting with the basics.
Identify every AI agent operating within the organization.
Then determine:
- Who owns it?
- What credentials does it have?
- What actions can it take?
- What systems can it access?
- What data can it reach?
- How does it interact with other agents?
Before organizations create complex governance frameworks, they need an accurate picture of what already exists.
AI Agent Governance Starts With Control
A practical AI governance model starts with four areas:
Identity: Every agent should have its own identity and defined credentials.
Ownership: Every agent needs a human owner accountable for its activity.
Access: Permissions should be limited, documented and appropriate to the agent’s purpose.
Data: Organizations need to understand exactly what information each agent can reach and segment sensitive data accordingly.
Before you can govern AI, you need to know what is running, who owns it and what it can touch.
What CISOs Should Take Away
AI security does not require enterprises to abandon everything they already know about cybersecurity.
Identity still matters. Least privilege still matters. Segmentation still matters. Data protection still matters. And ownership matters more than ever.
What has changed is the speed and autonomy involved.
As AI agents become more capable, enterprises will need to apply familiar security disciplines to a new class of user — one that can operate much faster and more independently than the humans traditionally governed by those controls.
Watch the Full ClearTech Loop Episode
Jo Peterson and Benny Czarny discuss AI agent security, governance, data protection and what CISOs should prioritize as autonomous AI adoption grows.
WATCH / LISTEN TO THE FULL EPISODE:
- https://youtu.be/2wqd6EJ8AJE
- https://www.buzzsprout.com/2248577/episodes/19733697
About Benny Czarny
Benny Czarny is the CEO, Founder and Chairman of the Board at OPSWAT. He founded the company in 2004 with a focus on protecting critical infrastructure through technologies designed for high-security environments.
OPSWAT protects organizations across industries including energy, defense, financial services, manufacturing and government.
Additional Resources
- Cybersecurity Upside Down — Benny Czarny Benny’s book expands on his prevention-first approach to cybersecurity and critical infrastructure protection. https://www.amazon.com/dp/B0GH8SZXJ9
- OPSWAT Academy Training and certifications focused on critical infrastructure protection, IT/OT security and real-world cyber operations. https://opswatacademy.com/
- CISA Roadmap for Artificial Intelligence CISA’s framework for approaching AI security, governance and critical infrastructure risk. https://www.govinfo.gov/app/details/GOVPUB-HS2-PURL-gpo221034
- ClearTech Loop: AI Agent Governance Starts With Visibility — Alvaro Gonzalez A companion discussion on AI-agent inventory, observability and why visibility has to come before control. https://cleartechresearch.com/ai-agent-governance-alvaro-gonzalez/
Stay in the Loop
Subscribe to the ClearTech Loop newsletter for new conversations on AI security, governance, cloud strategy and cyber risk.
https://www.linkedin.com/newsletters/7346174860760416256
Watch full episodes and subscribe to ClearTech Research on YouTube.