As AI systems grow in sophistication, particularly with the rise of generative AI and agentic models, the foundational challenge of identity propagation transforms from a mere technical hurdle into a critical security imperative. In a recent presentation, Grant Miller, a Distinguished Engineer at IBM, shed light on the evolving complexities and strategic approaches to securely managing identity across multi-hop, multi-agent AI environments.
Miller highlighted that while traditional identity propagation patterns—such as direct user-to-application connections or trusted assertions via an Identity Provider (IdP)—suffice for simpler architectures, they falter in the intricate, multi-node flows characteristic of modern agentic systems. "Organizations are embracing Gen AI and RAG models and agentic systems. With that, we're starting to see a lot of challenges pop up," he noted, emphasizing the shift from simple user-to-database interactions to complex chains involving chatbots, routers, and multiple agents.
