A
Alex Bovee
6
APPEARANCES
4
PODCASTS
012
DEC 30
JAN 6
JAN 13
JAN 20
JAN 27
FEB 3
FEB 10
FEB 17
FEB 24
MAR 3
MAR 10
MAR 17
MAR 24
MAR 31
APR 7
APR 14
APR 21
APR 28
MAY 5
MAY 12
MAY 19
MAY 26
JUN 2
JUN 9
JUN 16
JUN 23
JUN 30
JUL 7
JUL 14
JUL 21
JUL 28
AUG 4
AUG 11
AUG 18
AUG 25
SEP 1
SEP 8
SEP 15
SEP 22
SEP 29
OCT 6
OCT 13
OCT 20
OCT 27
NOV 3
NOV 10
NOV 17
NOV 24
DEC 1
DEC 8
DEC 15
DEC 22
DEC 29
JAN 5
JAN 12
JAN 19
JAN 26
FEB 2
FEB 9
FEB 16
FEB 23
MAR 2
MAR 9
MAR 16
MAR 23
MAR 30
APR 6
APR 13
APR 20
APR 27
MAY 4
MAY 11
MAY 18
MAY 25
JUN 1
JUN 8
JUN 15
JUN 22
JUN 29
JUL 6
JUL 13
JUL 20
JUL 27
AUG 3
AUG 10
AUG 17
AUG 24
AUG 31
SEP 7
SEP 14
SEP 21
SEP 28
Sep 30, 2026
#451 - Sponsor Spotlight - C1.ai
12:22
12:52
13:07
13:18

Jeff SteadmanHOST
I know Jim wants to talk about Hugging Face, but I want to ask you just kind of one question around this idea of AI agents, and maybe for people who haven't gotten, you know, neck deep [chuckles] or deeper into this sort of world, how would you-- If someone says, "Okay, what's the difference between an AI agent and, like, a service account or some other sort of traditional things that have defined permissions versus what an AI might have?" How do you, you know, make that g- I guess, make that case or make that argument or the explanation to people who are struggling to understand what the difference is?

Alex BoveeGUEST
Yeah, I think the, the most simplistic way I sort of think about the difference between humans, applications, agents, and agentic workloads is really, uh, there's two dimensions.

Alex BoveeGUEST
And so, uh, if you look at determinism, uh, you know, there's two dimensions to that, non-deterministic and deterministic.

Alex BoveeGUEST
Humans are non-deterministic, but I would argue generally trustworthy, meaning we all have reputations.
13 MINS LATER
Alex Bovee is Mr NHI's Human Identity In The Hot Seat
4:20
4:31
4:35
4:40
4:56
M
4:12Mr. NHIHOST
Okay, and do you think, um, agentic AI security equals NHI security?

Alex BoveeGUEST
I, I mean, look, NHI is kind of one of these terms that, um, means different things to different people, and you probably get five different, uh, definitions of it depending on who you ask.

Alex BoveeGUEST
You know, some people, when you talk to them about NHI, they think service accounts.

Alex BoveeGUEST
Some people, when you talk to them about NHI, they think keys and tokens and API keys.

Alex BoveeGUEST
Um, but I think, uh, agentic identity really is i- its own, um, set of identity problems from kind of, you know, delegated authorization on behalf of a user for personal productivity agents.

Alex BoveeGUEST
Um, you know, SaaS or infrastructure enterprise agents really have their own kind of service account and, um, like standalone identity th- uh, upon which you need to, like, authorize their activity and authenticate them.
M
5:41Mr. NHIHOST
Now, do you think AI agents behave more like employees or software, to your earlier point?
Ep # 15 - Identity is the 3rd Generation of Security
12:25
12:52
12:56
13:08
13:19
34:55

Lalit ChodaHOST
Okay, so look, uh, we're now gonna be talking about, you know, the, the main focus in this podcast, right, which is identity is the third generation of security, right? So when we talk about that, like, you know, what were the first two generations? What defined them, and why have they now reached their limits, uh, and now s- being surpassed by identity as the third generation of security? Do you wanna share a center?

Alex BoveeGUEST
Yeah, the first gen- yeah, the first generation I think of is very much was network-centric security.

Alex BoveeGUEST
Um, and that was because of the traditional kind of corporate IT infrastructure was very on-prem focused.

Alex BoveeGUEST
There was, um, a network infrastructure that surrounded the digital enterprise and kept the bad guys out and kept the resources in, and we layered a lot of technologies into the network.

Alex BoveeGUEST
Um, DLP, egress firewall, um, uh, you know, um, subnets to be able to restrict access to different applications.
21 MINS LATER

Lalit ChodaHOST
What are you doing at C1? What are some of the capabilities that you're building into your, your platform?
Securing AI Agents at Machine Speed With C1
6:32

Alex BoveeGUEST
We use our own products internally to enable our team to adopt AI MCPs, uh, and tools and automate, um, you know, manual processes.
350: Alex Bovee – Identity in the Age of Agentic AI
6:32
6:43
7:03
7:09
7:13
18:12

Steve DurbinHOST
So how do our underlying access architectures have to evolve to verify trust in a world where, frankly, seeing is just no longer believing, isn't it?

Alex BoveeGUEST
Yeah, I remember a year ago, there was multiple examples of I think it was people deep faking CEOs and board members and trying to get financial transactions made and things like that.

Alex BoveeGUEST
And I think one of the impacts of AI on that is it AI is able to do that at scale and in a very targeted way.

Alex BoveeGUEST
I think we're going to see a lot of asymmetry happening in those types of attacks.

Alex BoveeGUEST
And then the second category is much more of your targeted attack where you're trying to deep fake the CEO calling the CFO asking for a immediate wire transfer to pay for something.
11 MINS LATER

Steve DurbinHOST
I'm just wondering as well, sitting here, do you see a future where AI predicts access needs and then revokes them based on anomalies or when the need for that access is simply gone before the human even notices?
348: Alex Bovee – Identity in the Age of Agentic AI
6:32
6:43
7:03
7:09
7:13
18:12

Steve DurbinHOST
So how do our underlying access architectures have to evolve to verify trust in a world where, frankly, seeing is just no longer believing, isn't it?

Alex BoveeGUEST
Yeah, I remember a year ago, there was multiple examples of I think it was people deep faking CEOs and board members and trying to get financial transactions made and things like that.

Alex BoveeGUEST
And I think one of the impacts of AI on that is it AI is able to do that at scale and in a very targeted way.

Alex BoveeGUEST
I think we're going to see a lot of asymmetry happening in those types of attacks.

Alex BoveeGUEST
And then the second category is much more of your targeted attack where you're trying to deep fake the CEO calling the CFO asking for a immediate wire transfer to pay for something.
11 MINS LATER

Steve DurbinHOST
I'm just wondering as well, sitting here, do you see a future where AI predicts access needs and then revokes them based on anomalies or when the need for that access is simply gone before the human even notices?
