This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Beyond the Login: Securing the AI Enterprise with Runtime Identity

Download resources

About this session

Ron Soper, Field CTO at Ping Identity, argues that identity security must move from a one-time login check to continuous, runtime re-validation as AI agents and deepfakes erode the assumption that a session, once authenticated, can be trusted. He cites steep year-over-year growth in account takeover and fraudulent-agent activity, and traces trust's evolution from implicit (self-asserted identity) through adaptive (risk-based signals) to explicit (identity tied to a verified real-world credential) and finally verified trust: continuously re-checking that explicit identity at sensitive moments, using privacy-preserving biometrics that store no reusable image of a user's face. He walks through account opening, everyday access and account recovery as three vulnerable 'doors' beyond the login screen, citing a bank case study where verified access and recovery patterns cut account takeover by 79 percent and saved $4.1 million a year in support costs. For non-human agents, he argues verified trust is not enough; the target is zero trust with 'just enough, just in time' access, continuously re-evaluating every action against current context rather than a session-level trust decision made once at login.

As autonomous AI agents increasingly execute tasks on behalf of users, the traditional perimeter of identity is shattering. Relying on a one-time login for an unpredictable, autonomous system exposes organizations to unprecedented risk. If a token is compromised, the agent's actions are too.

In this talk, we challenge the conventional IAM playbook. We will dissect the concept of Runtime Identity and its critical necessity in securing AI workflows. We'll explore the technical building blocks required for continuous, real-time trust evaluation, including decentralized identity and dynamic credential verification. Join this session to learn how to move beyond 'authenticate once' and start securing the micro-actions of your autonomous systems.

Key takeaways

  • Stop treating login as the only door to protect; secure account opening, everyday transactions and account recovery as separate, equally vulnerable points of access.
  • Re-verify identity at high-value moments (large payments, adding a payee, sensitive changes) rather than relying on a trust level assigned once at sign-in.
  • Replace knowledge-based recovery questions (mother's maiden name, first pet) with biometric or credential-based recovery; that information is routinely harvested through innocuous-looking social media quizzes.
  • For AI agents, move beyond human-style identity verification toward zero trust: grant just enough access for the task and just in time, then revoke it immediately after.
  • If deploying biometric authentication, prefer a privacy-preserving design that never stores a reusable image of the user's face, to satisfy both privacy teams and customers wary of a biometric honeypot.

Speakers

Ron Soper
Ron Soper
Field CTO · Ping Identity
Ron Soper is a Field CTO at Ping Identity and an identity & security specialist with over 35 years of industry experience. Specializing in identity management, Ron spent 20 years at Ontario Health as Lead Architect for Identity & Access solutions… Read moreRead less

Ron Soper is a Field CTO at Ping Identity and an identity & security specialist with over 35 years of industry experience. Specializing in identity management, Ron spent 20 years at Ontario Health as Lead Architect for Identity & Access solutions, where he designed and implemented large-scale, mission-critical identity platforms. Prior to Ontario Health, he spent nine years at EDS leading a team of specialists responsible for providing Microsoft support to major accounts worldwide. Today, Ron partners with customers to translate complex business and regulatory requirements into scalable, secure, and user-friendly identity strategies that advance Zero Trust, cloud, and AI-driven initiatives.

Resources

Photos

Tags

More from GoSec 2026

Also from Ron Soper

On the same topic