Wednesday, 5 Aug 2026
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA
logo logo
  • World
  • Politics
  • Crime
  • Economy
  • Tech & Science
  • Sports
  • Entertainment
  • More
    • Education
    • Celebrities
    • Culture and Arts
    • Environment
    • Health and Wellness
    • Lifestyle
  • 🔥
  • Trump
  • House
  • White
  • ScienceAlert
  • VIDEO
  • man
  • Trumps
  • Season
  • star
  • Years
Font ResizerAa
American FocusAmerican Focus
Search
  • World
  • Politics
  • Crime
  • Economy
  • Tech & Science
  • Sports
  • Entertainment
  • More
    • Education
    • Celebrities
    • Culture and Arts
    • Environment
    • Health and Wellness
    • Lifestyle
Follow US
© 2024 americanfocus.online – All Rights Reserved.
American Focus > Blog > Tech and Science > NTT DATA AIVista and Snowflake: Identity alone won’t secure enterprise AI agents
Tech and Science

NTT DATA AIVista and Snowflake: Identity alone won’t secure enterprise AI agents

Last updated: August 4, 2026 11:50 pm
Share
NTT DATA AIVista and Snowflake: Identity alone won’t secure enterprise AI agents
SHARE

Contents
Why Shared Credentials Lead to AI Security IncidentsScoped Credentials Are Just the Beginning for Regulated IndustriesLimitations of the Employee Analogy for AI AgentsA Three-Layer Approach to AI Agent GovernanceInitial Steps for Enterprise Audits

Presented by NTT DATA AIVista


VentureBeat’s June research revealed that 69% of enterprises continue to operate AI agents that share credentials, a practice linked to increased security incidents and near-incidents.

At the VB Transform 2026 event, Mukesh Karki, CTO of NTT DATA AIVista, and Mayank Upadhyay, chief security and trust officer at Snowflake, emphasized that addressing identity issues is merely the initial step. For the safe deployment of autonomous systems at scale, enterprises must incorporate action-level authorization and tamper-resistant audit trails into every agent interaction.

“Organizations need to demonstrate to their auditors in a highly tamper-resistant manner that the records they present truly reflect their activities,” Karki stated. “Provability is essentially your license to operate within a regulated environment.”

Why Shared Credentials Lead to AI Security Incidents

According to Upadhyay, many assumptions from an older generation of software persist.

“In traditional software, a human clicks and the software performs a predictable action, and you know which API it will call,” he explained. “However, in the agentic world, software has a mind of its own and continuously rewires itself. If you grant this software more permissions than necessary, agents—being naturally exploratory—will attempt various actions, leading to unintended side effects.”

Embedding a single static API key increases vulnerability, he further noted.

“It’s problematic if you have one API key embedded in the agent, allowing it to interact with a SaaS service on behalf of anyone, as this effectively grants the agent the combined needs of all users,” he said, highlighting that the second issue is forensic in nature, as “errors may occur, and you won’t be able to attribute them to the correct agent.”

See also  25 years for killing nurse in mistaken identity drive-by while on felony bail - CWB Chicago

Scoped Credentials Are Just the Beginning for Regulated Industries

Karki, who primarily serves clients in insurance, healthcare, and finance, considers scoped credentials as essential.

“In a regulatory context, an agent with broadly scoped credentials cannot operate,” Karki asserted. “Scoped credentials are merely a starting point. There are two layers of constraints: the jurisdiction where the agent operates and the rules of the organization.”

For example, a claims adjustment agent in Washington State operates under different regulations compared to one in California, he explained, with each claim being unique.

“Scoped credentials alone are insufficient, as actions must be governed by specific rules at the time they are taken,” he added.

Limitations of the Employee Analogy for AI Agents

Karki argued that the employee analogy only partially applies. Agents must learn an organization’s unique context, similar to a new employee. However, unlike people, enterprises cannot realistically build trust with thousands of agents over time.

“A star employee in one organization might not excel in another, not because of diminished skills, but due to a lack of context in the new environment, and this is true for agents as well,” Karki explained. “If each employee manages 100 agents, you cannot feasibly onboard and vet all of them.”

Upadhyay suggested that the employee analogy should rank agents lower in the organizational hierarchy.

“Treat them like interns,” he advised. “They mean well but don’t always know what they’re doing, so you need to supervise them while gradually building trust.”

On the Snowflake platform, administrators can enforce platform-wide safeguards like read-only operations, while developers can further restrict an agent’s permissions when initiating each session.

See also  Democrats and the Media Are Trying to Get ICE Agents Killed With Unmasking Demands |

A Three-Layer Approach to AI Agent Governance

According to Karki, governance should be applied to every agent action and positioned outside the agent.

“This is the only way to later prove that the agent took an action it was authorized to take,” he explained.

Upadhyay divided governance into three layers:

The agent layer involves identity, tool permissions, and MCP governance.

The model layer tackles indirect prompt injection and enables models to run within the customer’s VPC, keeping prompts hidden from the model provider.

The data layer involves least-privilege access, zero-copy architecture, and role-based access control.

Effective governance necessitates integration across all three layers.

Initial Steps for Enterprise Audits

For enterprises reviewing the governance of existing AI agents, Upadhyay recommends starting with two areas: auditing permissions for static secrets, which is the most significant fixable attack vector, and addressing shadow AI through an MCP gateway, eliminating the need for developers to operate unauthorized open-source MCP servers under their desks and providing administrators insight into MCP server interactions.

The balance between constraint and capability can be managed at the task level, utilizing confidence scoring to restrict autonomous execution on high-risk actions, with sandboxing as a compromise. However, Karki advises caution for enterprises already scaling their agentic systems.

“Much of this cannot be retrofitted after an agentic system is operational, and it’s even harder to retrofit if you need to justify to auditors why an agent acted as it did,” he pointed out. “Provability must be built from the ground up during system design.”


Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact sales@venturebeat.com.

See also  Trans Democrat Attacked ICE Agents. Now She’s Asking the Public for Bail Donations. | The Gateway Pundit | by Gregory Lyakhov
TAGGED:agentsAIVistaDataEnterpriseIdentityNTTsecuresnowflakeWont
Share This Article
Twitter Email Copy Link Print
Previous Article Ebola kills 1,700 in eastern Congo as outbreak surges Ebola kills 1,700 in eastern Congo as outbreak surges
Next Article By Malene Birger Copenhagen Spring 2027 Collection By Malene Birger Copenhagen Spring 2027 Collection

Popular Posts

Christian Pulisic says he wanted to play USMNT friendlies before Gold Cup, was turned down by coaching staff

U.S. men's national team star Christian Pulisic recently revealed in an interview that he expressed…

June 12, 2025

Sovereignty Wins 2025 Kentucky Derby

Sovereignty Wins 151st Kentucky Derby Sovereignty has claimed victory at the 151st Kentucky Derby, securing…

May 3, 2025

Check Out Our Timeline Of Sean ‘Diddy’ Combs’ Arrest, Trial and Verdict

TMZ.com The high-profile arrest and subsequent trial of Sean "Diddy" Combs has stirred considerable public…

September 29, 2025

Kristin Cavallari Sells Nashville Home for $7.5 Million

Kristin Cavallari Sells Nashville Estate for $7.5 Million!!! Published April 14, 2025 2:25 PM PDT…

April 14, 2025

More than $2b to be spent on new NZDF helicopters

The Defence Minister, Judith Collins, has revealed that $2 billion from the Budget will be…

May 3, 2025

You Might Also Like

Wormholes could be the key to time travel
Tech and Science

Wormholes could be the key to time travel

August 4, 2026
Which Foldable Phone is Better? – Tech Advisor
Tech and Science

Which Foldable Phone is Better? – Tech Advisor

August 4, 2026
Pixel Glow is Actually HiLight and Only Does Two Things – Tech Advisor
Tech and Science

Pixel Glow is Actually HiLight and Only Does Two Things – Tech Advisor

August 4, 2026
New York can’t ban federal agents from wearing face coverings, judge rules
World News

New York can’t ban federal agents from wearing face coverings, judge rules

August 4, 2026
logo logo
Facebook Twitter Youtube

About US


Explore global affairs, political insights, and linguistic origins. Stay informed with our comprehensive coverage of world news, politics, and Lifestyle.

Top Categories
  • Crime
  • Environment
  • Sports
  • Tech and Science
Usefull Links
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA

© 2024 americanfocus.online –  All Rights Reserved.

Welcome Back!

Sign in to your account

Lost your password?