
Sign up to save your podcasts
Or


Shadow IT was manageable. Shadow AI was concerning. Shadow agents? That's a whole different problem.
300 episodes already? Time flies when you're having fun! In this 300th Episode of the KuppingerCole Analyst Chat, Matthias sits down with Distinguished Analyst Martin Kuppinger to unpack one of the most urgent, and underestimated, security challenges facing organizations right now: employees building and deploying their own AI agents, with no governance, no oversight, and no accountability.
Key topics:
β
What "shadow agents" are and why they're fundamentally different from shadow IT or shadow AI
β
Why vibe coding means anyone, not just developers, can now deploy autonomous agents inside your systems
β
How AI agents massively expand the attack surface through prompt injection, data exfiltration, and uncontrolled access
β
Why discovery and resource-side controls must happen in parallel and why neither alone is enough
β
What organizations can actually do to gain control without just shutting everything down
The bottom line: there's a thin line between agents that help your business and agents that harm it. Right now, most organizations can't tell the difference.
AI is reshaping enterprise architectures, but is security keeping pace? In this episode, Martin Kuppinger, Matthias Reinwarth, and Darran Rolls talk about the urgent question of how organizations should structure their defenses for a world of autonomous, agentic AI. The answer: an AI Security Fabric.
Key Topics:
β
Why agentic AI breaks traditional, deterministic access models
β
The concept of "AIdentity" — what makes AI agent identity fundamentally different
β
Can the Identity Fabric scale to meet AI security demands?
β
Discovery, authorization, and governance as the pillars of an AI Security Fabric
β
The geopolitical divide: US "move fast" vs. EU "govern first"
β
Token delegation as the hardest unsolved problem in AI security today
"We didn't build IAM for a world where the actor, the path, and the destination are all unknown until the moment of access" so what do we build instead? Find out in this episode.
ποΈ Catch Martin, Matthias, and Darran at the European Identity & Cloud Conference (EIC) in Berlin this May and get a head start on the conversation right here.
Security teams have spent decades building deterministic, rule-based defenses. But the threat landscape has changed and AI is no longer just a feature add-on. In this episode of Analyst Chat, Matthias sits down with Matthew Gardiner to unpack his latest advisory note and Leadership Compass on AI SOC, exploring why probabilistic AI is becoming a core pillar of modern cybersecurity.
Key topics:
β
Why deterministic security has run its course — and what comes next
β
The "two-sided coin" model: rules-based vs. probabilistic AI approaches
β
Where AI genuinely outperforms traditional methods (and where it doesn't)
β
Risks, hallucinations, and how to build trust in AI-driven security systems
β
The AI SOC in practice: triage, agents, and phased adoption
β
Market outlook: pricing shifts, platform vs. startup dynamics, and data sovereignty
AI isn't replacing the security rulebook — it's completing the other half of it. Catch Matthew Gardiner live at EIC Berlin in May, and explore his advisory note and AI SOC Leadership Compass.
AI agents don't just use identities. they create, delegate, and impersonate them. In this episode of Analyst Chat, Matthias Reinwarth sits down with KuppingerCole's founder Martin Kuppinger to dig into AIdentity (the concept at the intersection of AI and identity management) and why the IAM tools we've relied on for decades are no longer enough.
Key topics:
β
What AIdentity means and why it's more urgent than ever
β
Why AI agents can't be treated like standard non-human identities
β
The identity relationship challenge — from simple access to complex agent meshes
β
Why "human in the loop" is mostly a misconception
β
The role of verifiable credentials and decentralised identity in securing agents
β
Where security and identity leaders should start today
π‘ Traditional IAM was built for humans. Agentic AI plays by entirely different rules.
AI agents aren't just software, they're a new class of actor that can impersonate users, bypass security policies, and operate across complex identity meshes. In this episode of Analyst Chat, Matthias Reinwarth sits down with Martin Kuppinger and KuppingerCole's newly appointed AI Security Practice Lead Jonathan Care to unpack the emerging concept of AIdentity and why it's the key to securing agentic AI.
Key topics:
β
What "AI Identity" means and why it's more than just a service account
β
The dangers of agent impersonation and the "ClaudeBot dumpster fire"
β
Authorization collapse, what happens when agents bypass security policies
β
The limits of "human in the loop" as a security strategy
β
Two new market categories: AVOP and ATDR
β
Immediate actions CISOs and architects can take today
AI is already in your organization, the question is whether you can see it. Stay tuned for upcoming KuppingerCole research on AVOP and ATDR, and catch Martin, Jonathan, and Matthias live at EIC Berlin in May.
What does an enterprise technology product actually deliver — in hard numbers? In this episode, Matthias Reinwarth sits down with Jonathan Care, KuppingerCole Analysts' newly appointed AI Practice Lead, for a behind-the-scenes look at a brand new research format: the Product Value Navigator (PVN).
Key Topics:
β
Why enterprise tech buying is broken — and what's missing from analyst rankings
β
What the Product Value Navigator is and how it works
β
How KuppingerCole independently validates ROI through real customer interviews and financial modeling
β
Who the PVN is built for: CISOs, IT leaders, procurement teams, and vendors
β
The first published PVN: ManageEngine PAM360 — 219% independently validated ROI
β
What's next on the PVN roadmap: flexible modeling tools and competitive analysis
In a world flooded with vendor-funded research and AI-generated content, truly independent economic validation has never been more valuable, or more necessary.
As OT systems go online, controlling access becomes more critical than enabling it.
In this episode of the Analyst Chat, KuppingerCole analysts Matthias Reinwarth and Warwick Ashford dive into one of cybersecurity’s most overlooked domains: OT (Operational Technology) security. As industrial systems become increasingly connected, the traditional boundaries between IT and OT are dissolving, bringing new risks and new security imperatives.
Key Topics
β
The rise of Secure Remote Access (SRA) in OT environments
β
Why VPN-based access falls short for industrial systems
β
Zero Trust and identity as the new security control plane
β
Regulatory drivers (e.g., NIS2) and auditability requirements
β
Convergence of PAM, SRA, and third-party access governance
β
The growing role of non-human identities in Industry 4.0
Identity is no longer just part of security, it is the control plane for modern cybersecurity.
In today's episode of the Analyst Chat, Matthias Reinwarth welcomes John Tolbert to take a deep dive into the rapidly evolving world of Consumer Identity and Access Management (CIAM). As organizations manage millions, or even billions, of identities, CIAM is shifting from a standalone capability to a core component of broader digital ecosystems.
Key topics:
β
Consumer vs. B2B IAM segmentation
β
Passkeys adoption and UX gaps
β
Identity lifecycle and account recovery
β
CIAM integrations and platform ecosystems
β
AI agents and identity governance
Increasing scale, regulatory pressure, and user expectations are reshaping CIAM requirements. AI agents begin to act on behalf of users, introducing new risks, but also new opportunities for automation and innovation.
In the age of AI-generated content, the real challenge isn’t just detecting falsehood, it’s knowing what to trust at all. As deepfakes and disinformation scale, perception itself becomes a new attack surface.
This week, Matthias Reinwarth and Jonathan Care explore how misinformation and disinformation are reshaping cybersecurity and enterprise risk. They clarify the difference between the two, examine how AI is accelerating the creation of deceptive content, and discuss why traditional trust models are breaking down.
Key Topics
β
Misinformation vs. disinformation: definitions and impact
β
Deepfakes, voice cloning, and synthetic identity risks
β
The “liar’s dividend” and erosion of trust
β
Emotional manipulation vs. factual accuracy
β
Enterprise attack vectors and real-world fraud cases
β
Pre-bunking, awareness training, and process-based defenses
AI has industrialized deception: are your security controls keeping up? In a world of perfect fakes, trust is no longer a given, it’s a security problem.
The future SOC won’t replace humans with AI, it will empower us with AI-driven automation, accelerating detection and response while keeping humans in control of critical decisions.
This week Matthias Reinwarth and Matthew Gardiner discuss the evolution of security automation with the introduction of AI SOC (Security Operations Center). They explore the challenges of alert fatigue, the importance of human oversight, and the cautious optimism surrounding AI's role in cybersecurity. The conversation delves into the balance between automation and human intervention, the trust issues associated with AI systems, and the current landscape of vendors in the AI SOC market. They conclude with insights on the future of AI in security and the potential impact on managed detection and response services.
Key Topics:
β
Evolution from SOAR to AI-powered SOC
β
Using AI agents as junior security analysts
β
Managing alert fatigue and SOC analyst burnout
β
Balancing automation with human oversight
β
Explainability and trust in AI security systems
β
Impact of AI SOC on MDR and security service providers
AI is reshaping SOC operations—but fully autonomous security is still far away. Discover why AI agents may become the “junior analysts” of the modern SOC, handling repetitive tasks while humans focus on complex decisions.
From the publisher's feed