Who answers when a machine acts in your name?
At SSS - Cybersecurity Specialists, we spend a lot of time with the leaders who…
Who answers when a machine acts in your name?
At SSS – Cybersecurity Specialists, we spend a lot of time with the leaders who carry this risk. One question keeps coming up: when a machine acts in your organisation’s name, who answers for it?
Most conversations about securing AI assistants start with the model. That’s a mistake. The first control plane for AI isn’t the model. It’s identity.
Consider a routine request: an employee asks an AI assistant to consolidate everything the legal team produced this week. The assistant doesn’t seek authorisation the way a colleague would. It assumes that employee’s identity, inherits every entitlement they’ve accumulated, and retrieves and presents information at machine speed. It acts as that person, but without their judgement, and without ever having been formally onboarded, scoped or reviewed.
That’s a delegation problem. When we delegate authority, we need to know who is acting, on whose behalf, what they are allowed to do, and where that authority ends. Those are fundamentally identity questions. So when an AI assistant acts on someone’s behalf, identity becomes the control point for how that delegated authority is governed.
An invisible workforce, already at work
Inside every organisation New Zealanders rely on, non-human identities, utilised by service accounts, workloads and AI agents that authenticate, decide and act on our behalf, already outnumber human staff many times over.
Yet many institutions can’t say how many they run, who owns them, or how fast they could shut one down.
Over the last decade, boards have backed heavy investment in securing human identities: MFA, conditional access, least privilege, Zero Trust. Machine identities got similar treatment.
Then a new class of non-human identity arrived, one capable of reading everything a person can read and acting on it, and it was granted that access with comparatively little scrutiny.
The risk isn’t hypothetical, and it isn’t just about information leakage.
As assistants become agents, capable of provisioning access, approving workflows and executing transactions, an unaccountable credential stops being a technical exposure and becomes a board-level question.
For government and financial services in particular, this is about public trust. The services people depend on are exactly where misuse of organisational authority can erode confidence that took decades to earn.
So, who answers?
The important question isn’t whether organisations should use AI assistants. They already are.
The question is whether we are applying the same accountability to an AI identity that we would expect from a human an existing automated workload or privileged service account.
And that leads to the next challenge: do the governance models and identity controls we already have actually cover an AI assistant acting on someone behalf?
In Part 2, We’ll explore why existing governance doesn’t always cover this new form of delegated authority – and the practical identity controls organisations can apply.
At SSS - Cybersecurity Specialists, we spend a lot of time with the leaders who…
In pharmaceutical development, there's a well-known principal called "the first-pill problem". Brining a new medicine…
Banking, shopping, learning, connecting with friends, joining communities, building a career. Increasingly, our digital lives…