BairesDev

When Seeing Isn’t Believing: Your AI Agents Have Identities, and Your Identity Model Isn’t Ready – Webinar Replay

Security leaders explain what deepfakes and over-permissioned AI agents have in common, and what organizations need to fix before either becomes an incident.

Last Updated: August 31st 2026
Biz & Tech
8 min read
Bob Leibholz
By Bob Leibholz
SVP of Business Development

Bob is SVP of Business Development at BairesDev, leading strategic partnerships and sales strategy. He has over 20 years of experience in technology services, including leadership roles at DataArt and Intermedia.

Illustrative image of agentic identities and security

Most boards are more concerned about an AI agent going off-script than a convincing deepfake, but both risks stem from the same underlying problem: knowing exactly who—or what—you are dealing with. An impersonated employee and an over-permissioned AI agent can both pass authentication while concealing their true identity or level of authority. In a live poll during a BairesDev webinar, only about a fifth of attendees had AI in production. Yet the identity frameworks that will govern these systems are being designed now, before many of the systems themselves have even been deployed.

Our webinar Cybersecurity & Trust: When Seeing Isn’t Believing examined that problem with BairesDev Fellow Jason Conley, Chief Technology Officer at VIP Medical Group, as moderator. Joining him were Amanda Hartle, Managing Director and Chief Architect at Fiddlers; Patrick Doliny, Chief Information Security Officer and Founder at dologiic; and Travis Rosiek, Public Sector CTO at Rubrik and BairesDev Fellow.

The panel covered why deepfakes and rogue agents share the same underlying weakness, and why human verification has fallen behind machine identity. They also worked through a case where a perfectly obedient agent caused an 11-week exposure, and discussed what attribution requires once agents begin acting inside an environment.

Deepfakes and AI Agents Expose the Same Identity Problem

The panel used “deepfake” in the fairly specific sense of impersonating a real person to convince a target to grant access. Travis Rosiek pointed to North Korean operations that placed fake remote workers inside major, Fortune 500 U.S. companies. He described the scale as “quite alarming at how pervasive that was… It just makes you wonder what else is happening that hasn’t been identified.”

He explained that those workers passed hiring processes, they cleared interviews and received credentials. From the company’s perspective, they looked like legitimate employees. Rosiek argued that this puts impersonation and agent risk in the same category. “The agents have identities inside your environment, and they look like valid users,” he said. “To me, they’re kind of in the same bucket.”

Doliny said impersonation is also showing up somewhere new. It has gone beyond the traditional channels covered by security awareness training, he explained, and now “can embed itself into your Slack channels, your other areas, other non-traditional cybersecurity-related areas.” What worries him is that this targets employees in the places they trust most.

During the webinar, attendees were asked which emerging risk worried them most. Conley read the results as showing about half  the room focused on AI agents with excessive permissions and insider threats, and noted that deepfakes and voice cloning received no votes at all. Rosiek found that surprising, given how reliably impersonation already works in ordinary red-team exercises. “They’re using the AI, the graphics, the visualization, the audio, the rendering to get by.”

The split looks organizational. Impersonation tends to sit with security awareness, while agent permissions sit with whoever is shipping the AI feature. That may help explain why the two risks are treated separately even though they expose the same weakness. The controls around machine identity have advanced much faster than the ways organizations verify people.

Machine Identity Got Automated. Human Verification Didn’t.

Hartle traces part of this to where the money went. Organizations have invested heavily in verifying machines while leaving the procedures for verifying people largely untouched, and as voice and video get cheaper to impersonate, that imbalance widens.

“We have this high-speed synthetic reality on 1990s trust models,” she said. “We can clone a voice in seconds, and our idea of verification is still asking somebody for their mother’s maiden name.” Doliny made the same observation from a poll data, noting that the controls and mitigation plans in use are still 1990s thinking applied to conditions that did not exist a year ago.

Hartle described a case involving a CEO she works with who was traveling in Portugal. He received a call claiming that his sibling had been kidnapped. Rather than act on the call, he did what Hartle had trained him to do and checked through a second channel. The sibling was on a plane, proving the call was synthetic.

The attacker got the material from an ordinary social media post. “The reason this whole thing happened was because the sibling had posted on social media that their flight had been delayed in London, Heathrow.” A public post about a delay gave someone enough to build a targeted call within hours, and the only thing standing between that call and a successful extortion was a habit the CEO had built over a decade.

Her larger worry is that the two sides keep drifting further apart. She recognized that synthetic identity has evolved quickly, while the changes people can absorb come slowly, and the distance between those two speeds is where challenges start. She was careful not to blame anyone for that. The verification methods available to people were designed for a slower world.

The Agent That Did Exactly What You Asked For

Hartle’s second case involved no attacker at all. A company pointed an AI assistant at its internal knowledge base to speed up support work. That knowledge base shared a drive with an HR folder holding salaries, severances, and performance reviews.

Permission inheritance behaved differently than the team assumed. “Nobody really understood that Claude doesn’t work that way with Microsoft 365 in terms of permissions and duplication, so nobody set it,” Hartle said. “And it got all the access.”

It ran that way for eleven weeks, until someone asked a routine question about severance figures in general, and the assistant returned real ones. Hartle was brought in for incident response, with legal issues now attached to an exposure nobody had intended.

Rosiek’s warning about timing applies here. The old assumption, he said, was that an attacker could remain inside a network for weeks before something bad happened. “Now it’s seconds. There really is no buffer anymore.” For Hartle, the more important question is how long something can go wrong before anyone notices.

In Hartle’s case, the assistant had access immediately. The company did not discover it for 11 weeks. That visibility problem becomes harder once organizations need to establish not only what happened, but which agent acted and under whose authority.

Everyone Is Skipping the Attribution Layer

Hartle said that years of incident response repeatedly brought her back to two questions nobody could answer immediately. Was it targeted? Who was responsible? The second answer is getting harder.

“When things go off at 2 AM now, we can answer, like, oh, an agent executed this,” she said. “On whose behalf, under what authority, what were they getting access to? Agents are being proliferated everywhere, I just think attribution’s going to start to be an issue.” For someone with a background in forensics, she expects that to make incident investigations much harder.

Rosiek pointed to visibility as the starting point. Attribution depends on knowing who or what acted, when and where it happened, and how. Knowing that an agent executed an action only gets an investigation so far if the organization cannot answer those other questions.

Text blocks with 6 questions every AI agent action should answer

Hartle connected the issue to ownership. The most common mistake she sees is buying a tool without naming who owns it. “A security control that doesn’t have a clear named human owner isn’t any protection. It’s just an expensive line item on a budget. It fails in an audit.” She said she often encounters tools nobody can explain or account for.

Rosiek offered one reason this keeps getting deferred. From his government experience, almost all victims of a major cyber attack were compliant at the time. Too often, organizations treat compliance as the ceiling of a security program rather than the floor, without building the visibility needed to explain what an agent actually did.

It All Comes Back to Verification

The deepfake and the over-permissioned agent are different threats, but they expose the limits of identity models built for a simpler environment. Authentication alone is no longer enough if an organization cannot establish who or what is acting, what authority it has, and what it can access.

When the conversation turned to priorities for the next twelve months, Hartle had a strong point of view: “We are spending millions automating all of the identity for systems, and have left our people running on that honor system.” Her recommendation is to fix human verification before buying another tool.

The machine side needs the same discipline. Every agent should have a named owner, a scope set before it ships, and enough of a trail that someone can answer who authorized an action at 2 AM. None of that arrives with a purchase. It gets built inside the systems organizations are already running.

Watch the full webinar here. The work of bounding scope and building audit trails tends to land on teams that are already at capacity. If that sounds familiar, contact us.

Bob Leibholz
By Bob Leibholz
SVP of Business Development

Bob is SVP of Business Development at BairesDev, leading strategic partnerships and sales strategy. He has over 20 years of experience in technology services, including leadership roles at DataArt and Intermedia.

  1. Blog
  2. Biz & Tech
  3. When Seeing Isn’t Believing: Your AI Agents Have Identities, and Your Identity Model Isn’t Ready – Webinar Replay

Hiring engineers?

We provide nearshore tech talent to companies from startups to enterprises like Google and Rolls-Royce.

Alejandro D.
Alejandro D.Sr. Full-stack Dev.
Gustavo A.
Gustavo A.Sr. QA Engineer
Fiorella G.
Fiorella G.Sr. Data Scientist

BairesDev assembled a dream team for us and in just a few months our digital offering was completely transformed.

VP Product Manager
VP Product ManagerRolls-Royce

Hiring engineers?

We provide nearshore tech talent to companies from startups to enterprises like Google and Rolls-Royce.

Alejandro D.
Alejandro D.Sr. Full-stack Dev.
Gustavo A.
Gustavo A.Sr. QA Engineer
Fiorella G.
Fiorella G.Sr. Data Scientist