This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Gouverner les agents IA : identité, accès… et le prochain incident

Download resources

About this session

Stephane Joguet, Field CISO at Cyera, structures his talk around three questions a fellow French bank CISO posed on LinkedIn, building on JPMorgan CISO Pat Opet's doctrine of giving AI agents an identity but no standing entitlements: can you map every agent running in your environment, can you govern their identity lifecycle as rigorously as an employee's, and can you react once an agent has taken an irreversible action. He argues human-paced governance (quarterly reviews, static DLP, manual classification, annual audits) cannot keep up with agents acting continuously, citing data such as two in three companies suspecting undisclosed agent data access, shared API keys used by half of firms for agent-to-agent auth, and only 7 percent believing they could stop a rogue agent. He walks through Cyera's four-module answer, sharpened by its 2026 Oasis Security acquisition (now Cyera Identity): agentless identity discovery as a data-linked graph, automated credential rotation, a real-time kill switch for out-of-intent behaviour, and full action traceability. He cites the OpenAI/Hugging Face sandbox-escape incident and similar Anthropic cases as proof this is operational, notes no regulation yet defines an autonomous agent, and closes recommending an exposure assessment before a governance workshop.

Un Global CISO d'une grande banque française a publié un post LinkedIn qui a fait le tour de la communauté cyber récemment. Il pose trois questions simples auxquelles la plupart des équipes ne savent pas encore répondre : est-ce qu'on est capables de cartographier tous les agents IA qui tournent dans notre environnement, est-ce qu'on gère leur identité et leurs accès avec la même rigueur qu'un employé, et est-ce qu'on peut réagir quand un agent a déjà posé un geste irréversible?
Ce post reprend une idée popularisée par Pat Opet, CISO de JPMorgan Chase : « identity but no entitlements » , devenue une référence pour encadrer la gouvernance des agents. Deux mois plus tard, l'incident OpenAI/Hugging Face, puis des cas similaires reconnus par Anthropic et d'autres, ont montré que ce n'est plus de la théorie : c'est déjà opérationnel.
On part de ces trois questions pour donner aux responsables de cybersécurité un plan concret : comment cartographier la prolifération des agents IA, comment faire évoluer son IAM pour couvrir tout leur cycle de vie, et comment structurer une réponse avant que l'irréversible arrive. On va aussi voir pourquoi l'identité et la sécurité des données doivent converger avec l'exemple du rapprochement entre Cyera et Oasis Security et ce que cela change dans un cadre réglementaire encore incomplet relatif aux agents d'IA.

Key takeaways

  • Build a live inventory (a graph, not a spreadsheet) linking every human and non-human identity to the data it can reach; most organizations discover 30-40% more data and stale accounts than expected once they look.
  • Stop using shared API keys for agent-to-agent authentication; treat a shared key the way you would a shared team password, since it cannot be rotated without breaking every consumer that relies on it.
  • Move from point-in-time, human-paced access reviews (quarterly or annual) toward continuous, policy-based monitoring, since agents create and revoke access at machine speed around the clock.
  • Build the capability to detect and stop an agent that drifts from its original intent in real time; only 7% of surveyed organizations believe they could currently stop a deployed agent, per Forrester.
  • Do not wait for regulation to define 'autonomous agent' before acting: DORA, the EU AI Act, Law 25 and the US NIST framework all still lack a settled definition, but traceability of agent actions is already being asked for in practice.

Speakers

Stephane Joguet
Stephane Joguet
Field CISO-France · Cyera
Stéphane is a global cybersecurity executive with 25+ years of experience driving business-aligned security transformations. As former Global CISO at Sephora (LVMH) and Group Cybersecurity Director at TF1, he has redefined cybersecurity as a… Read moreRead less

Stéphane is a global cybersecurity executive with 25+ years of experience driving business-aligned security transformations.

As former Global CISO at Sephora (LVMH) and Group Cybersecurity Director at TF1, he has redefined cybersecurity as a strategic enabler—embedding Security by Design, leveraging AI-driven operations, and turning compliance (NIST, ISO 27001, NIS2) into a competitive advantage.

His leadership bridges the gap between technical security and business value, enabling organizations to scale securely, innovate confidently, and build trust in an era of digital acceleration. By rationalizing cyber ecosystems and aligning security with board-level priorities, Stéphane ensures that risk mitigation fuels growth—not friction.

« Cybersecurity isn’t just protection; it’s the foundation for resilience, agility, and market leadership. »

Resources

Photos

Tags

More from GoSec 2026

Also from Stephane Joguet

On the same topic