What is Agentic Security Runtime? Securing AI Agents — Transcript
Full transcript
- 0:00Engineers are being tasked to build AI for their companies, but they're not identity experts, and that's a real problem.
- 0:06Today, we want to talk about agentic runtime security and how you can implement it safely and securely in your organization.
- 0:13What's that look like?
- 0:14It starts with an AI agent.
- 0:17This can be a Python application, a TypeScript application, but it can also be .NET, Java, really doesn't matter.
- 0:25That AI application is going to be running somewhere, generally in a cloud.
- 0:28Maybe it's on AWS Lambda or a virtual machine or running a container.
- 0:32But these by themselves don't provide any value.
- 0:35They have to make external connections to things.
- 0:38And that could be a database.
- 0:41That could be connecting to an LLM provider of your choice.
- 0:46Likely.
- 0:47That could also be a SaaS application.
- 0:51Like a Salesforce or something else.
- 0:54We think about these external connections.
- 0:55How do we govern access to those?
- 0:58Traditionally, we would have our workload would hard code a static credential to a database or an API key to an LLM or an API key to SaaS.
- 1:07We actually recommend against that.
- 1:09And this is what we call non-human identity.
- 1:16What we recommend is you start to build out what these connections are dynamically at runtime per session.
- 1:23What's that look like in practice?
- 1:25So we have an AI agent that's authorized to do read and write to a PostgreSQL database.
- 1:30If I was jailbroken or at prompt injection, they can read or write anything from the database.
- 1:36And so we want to strip that standing privilege.
- 1:38What we really want is for this AI agent, at the time of the session and at the time of evaluating an action,
- 1:44to know what it's gonna request access to and get dynamic credentials into each one of these that is session bound and intent bound.
- 1:54How do you do that?
- 1:55The first is dynamic creds.
- 2:01This is the practice of creating just-in-time credentials for anything you need that are time-bound and automatically revoked at the end of the session.
- 2:07That can be two minutes, two seconds, whatever really matters.
- 2:11But now we need to think about the users on top of this.
- 2:14AI agents are generally used by users.
- 2:16While there are completely autonomous agents that are operating by themselves, today what we normally see is a user in front of it.
- 2:24So this user interacts with your AI agent, usually via HTTP or some other interface.
- 2:29What about using the user identity?
- 2:31How do we understand who that user is and the context?
- 2:35Well, this is where you layer in your IDP.
- 2:38This can be an Okta, this can be an IBM Verify, it really doesn't matter.
- 2:42And AI agents will work with an IDP to understand who you are. That IDP works with you.
- 2:48This is how we do things like single sign-on.
- 2:51This is predicated on a standard called OAuth, typically OAuth 2.0, and it's
- 2:59Authorization code flow.
- 3:02You've likely seen this interaction.
- 3:04When you go to click log on with Google, log on with Microsoft, you'll see a redirect,
- 3:08and that redirect page will ask you: do you authorize this application to access your portfolio, your profile, your email address, or act on your behalf?
- 3:16That is the OAuth standard implemented here.
- 3:19But what about sensitive operations?
- 3:21If you're building an HR application internally, and that HR application, the AI agent, can onboard off-board employees,
- 3:28those are sensitive operations that can have real world impacts to your risk and to your employees and even financial security.
- 3:34When we have those higher-level operations that need to have additional scrutiny, this is when we recommend something called OAuth 2.0 CIBA.
- 3:43And what that means is this is like passkeys for agents.
- 3:46This will actually hit a prompt to the user's phone, completely outside of the browser context.
- 3:53So when a user makes a call to an AI agent, the AI determines that they want to do something sensitive.
- 3:58The AI agent will call the IDP, will initiate this third-party CIBA, Client-Initiated Backchannel Authentication,
- 4:05and prompt the user's phone and say: do you want to off-board this employee with the details?
- 4:10That is a really powerful mechanism around security to make sure that the operations and actions being taken are authorized by the user.
- 4:18It's also another layer of protection against jailbreaking and prompt injection on that AI agent.
- 4:23If there was a prompt injection that said off-bored all employees, I would get a notice for each one of those to my phone.
- 4:30To tie together the dynamic credentials with OAuth 2.0 and now adding in CIBA, Client-Initiated Backchannel Authentication, we put that code into our AI agent.
- 4:40That's where we do the work inside our Python or our TypeScript.
- 4:43We evaluate the JWTs, we create the dynamic credential, we access them, and then we automatically revoke them.
- 4:50And that's how we provide agentic runtime security today.
About this transcript
This page contains the full transcript of What is Agentic Security Runtime? Securing AI Agents by IBM Technology, generated from the public captions YouTube serves with the video. The transcript has 824 words across 62 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.