-
Notifications
You must be signed in to change notification settings - Fork 1
Episode 202
Michael Schwartz edited this page Jun 19, 2026
·
7 revisions
- Host: Mike Schwartz, Founder/CEO Gluu
- Guest: Roshan Shaik, Founder & CEO RuntimeAI
AI agents authenticate with valid credentials, pass MFA, and then commit fraud — bulk data exports, cross-tenant queries, unauthorized payments — all with a clean token. The identity layer tells you who the agent is; it doesn't tell you what the agent should be doing. This session covers the emerging runtime enforcement layer for agentic AI: behavioral baselines, real-time fraud scoring, and why the post-2012 identity stack (DPoP, MTLS, device-bound sessions) is necessary but not sufficient when the threat is an authenticated agent acting outside its declared scope.
- FBI IC3 PSA on AI-enabled OAuth token attacks (May 2026)
- Identity ≠ AI Security : RuntimeAI post, 4.5K impressions, strong identity community discussion
- RuntimeAI platform overview: https://www.runtimeai.io/