Resources
- -
- Solutions
- RadiantOne
- Why Radiant Logic
- Company
- Support
- Resources
© 2026 Radiant Logic, Inc. All Rights Reserved. | Privacy Policy
In this episode of Radio Logic, host Anders Askasen sits down with Michael from Cyber IAM to dig into the messy reality of governing Agentic AI. They cover why so many AI projects stall at the finish line, why every business now has a “Shadow AI” problem, and why the fix might be a gateway with real guardrails, not blind trust. Michael’s rule is simple: it is called a copilot for a reason. You are still flying the plane. If you own identity, security, or governance, press play.
Anders Askasen:
This is Radio Logic, the show about digital identities, the people behind it, the tech behind it. And in each episode, we’ll cover what works, what doesn’t, and what’s next. Let’s dig into it.
Welcome to Radio Logic, the monthly podcast where identity actually matters. I’m joined today by Michael from Cyber IAM. Michael, welcome.
Michael Ribaudo:
Thank you.
Anders Askasen:
Tell the audience who Cyber IAM is, and what do you do within identity?
Michael Ribaudo:
So Cyber IAM is an identity and access management and governance professional services business. What we do is help vendors like yourselves deploy your software and technology in the identity space to most of the enterprise customers in the UK and Europe.
Anders Askasen:
I’m sure you get this question a lot from your customers. How can AI help us?
Michael Ribaudo:
Oh, wow. That’s a big question.
Anders Askasen:
It is loaded, isn’t it?
Michael Ribaudo:
It is loaded, yeah. So AI is changing very quickly at the moment, and we’ve become an AI-first company ourselves.
I think my employees are sick of hearing me talk about AI, but I think we need to embrace what it’s good at, and then evolve over time as it gets better at other tasks.
So what’s AI good at today in our space? It’s really good at taking large amounts of data and being able to make sense of it. So it’s using AI that’s built inside of the tools, but also some of the external AI to help companies like ourselves help customers make sense of the bigger chunks of what they’re trying to achieve.
Anders Askasen:
At Radiant Logic, we have what we call the three identity problem, and it’s kind of like a flirt to that movie about three stars and three planets.
But essentially, human identity—and you’ve been on the podcast in the past, and we talked about the human identity side, how we potentially have solved that. Although the projects fail, we have an idea. We have a pattern on how to approach it. And then we have the machine identities with SSH, certificates, API keys, all those typical things.
But then we have that third emerging category of agentic AI, agents that operate instantaneously. They make decisions. They do things.
Often, the term is ephemeral.
Is that something that is popping up on the request from your customers that you need to consider this? Are they considering AI? And the reason why I’m asking is because MIT came out with a research saying that ninety percent of these projects have a tendency of failing, but at the same time, every single big enterprise has some kind of initiative.
Michael Ribaudo:
Yes. So the answer is yes. We are seeing our customers looking at AI quite aggressively. I think they went down the initial thought process of how do we do it better, how do we get an ROI, and the security got sort of pushed aside, as it always does. But the CISOs and the heads of identity, etc., are concerned, and they’re looking for ways to bring that under control.
Now on the failed project side, it’s an interesting space to be in, because you get to a stage where the agents are autonomous and you’re ready to go, and then someone goes, “Oh, I don’t know if I trust it.” And so that’s why we’re seeing failed projects, because they’re not ready to let these agents loose yet on their environment because there aren’t the guardrails in place yet.
Anders Askasen:
And I guess in order for these agents to actually do something useful, you kinda have to give up the keys to the kingdom and give them the authority to do things on your behalf or however you account for the accountability process, if you will.
But in the news, a couple weeks ago, Open Claude came out as something that just took the market by storm, this open source project where you give up everything, and you get an agent, a personal assistant that actually does things for you. Now, obviously, it’s kind of a far-fetched stretch from identity, but this kind of indicates where identity is heading towards, and we’ll talk about that in a minute.
But this surfaces a whole bunch of new risks for CISOs. And I know you talk to CISOs daily. What’s on their mind when it comes to agentic AI?
Michael Ribaudo:
I think CISOs and business in general are concerned about when you let something loose, like Claude, how do you put the guardrails in place to say what it can and can’t do? And I think the answer—and there are tools out there and technologies that are starting to emerge—you need a gateway. You need a gateway between agents that has policies in place to be able to say what it can and can’t do.
If you give it the guardrails of “these are the fifty tasks these agents can do with each other, and only these two agents can talk to each other, these four, etc.,” you’re then putting the guardrail and then letting it go and do what it’s supposed to do. When you give it access to everything and let it loose, that’s what’s scaring CISOs right now.
Anders Askasen:
And I think you touched on something that’s quite interesting that we’ve seen with the acquisition spree that has happened by these type of companies. Typically, network companies like the Palo Altos of the world, they have some kind of API gateway. And the reality is that the technology is not a big stretch from looking at what you communicate with an LLM.
So it makes sense to acquire all these different companies and kind of consolidate that. Is that gonna be a bottleneck? Is that gonna be a single point of failure or a risk in itself?
Michael Ribaudo:
I think what’s been really impressive about the traditional SOC network-type organizations is that they’ve finally identified that identity is core to all of this, and that’s why they are now acquiring identity companies: to put the identity-type controls around access that’s out there. That access can be agents, it can be machines, it can be Internet of Things—it really is that they’re bringing it to identity now.
Whereas before, they kind of went in their own direction; it was all about endpoints. If you look at licensing, for example, licensing was always endpoints because that’s what they cared about. Now they’re starting to move towards identity licensing for some of these SOC products, which shows that the market is shifting to putting controls around the identity, not just the endpoint.
Anders Askasen:
There was a recent article that tried to highlight exactly these risks that CISOs see. And one of the things that emerged from that article was shadow IT—how do we actually know what’s in there? And from Radiant Logic’s perspective, we operate under what I call the holy trinity of unify, observe, and act, meaning that we make sure that we have everything under control, one single source of truth, then we can apply some kind of observability on top of it.
And once we have that, we come to the maturity that we know that we have data that is accurate and sound. If there’s an anomaly, we can act on it. And I think, at least this is where we’re going, we’re looking at agents that we need to have an overview, an inventory of all these agents. So think of this as a virtual directory, but for the agentic era where we can have that overview.
And I think once you have that, you’re not fully covered, but you’re in a better spot.
Would that resonate with you?
Michael Ribaudo:
Absolutely. I think it’s spot on.
I think we’ve coined the term—and maybe someone else has—shadow AI. If you think about it, everyone has employees that are using their credit card to get a better version of an AI agent than maybe the organization has access to. And that’s allowing potential leakage of internal data, because it’s not being governed by the way the company’s approved AI solution is.
So we’re seeing a lot of that shadow AI coming in, but the ability to go out and look at your network and find all the agents—and it’s easier said than done, right? Because we spoke earlier about there being custom agents as well as the standard Microsoft, Google, AWS ones. Those are easy; we know how they’re created. But custom agents are a little harder. So how do you go and discover them? The technologies are going to come, and are coming, to give you the oversight of what you have so that you can then get it under control.
Anders Askasen:
But it’s clear that we’re not there yet. There still need to be some guardrails.
There’s still some standardization that needs to happen, and it’s all moving very rapidly. But I have a thesis, and I’m gonna provoke you with that. I think the traditional IGA vendors as we know them either need to adapt to a new type of identity governance that is driven by AI, and if they live in the past, they’re going to disappear from the market space. That’s basically me saying IGA as we know it will die.
Michael Ribaudo:
You know, I’ve heard this before. “Death to IGA, long live IGA,” right? So I think what I’m seeing some of the IGA vendors doing, which I think is the right thing to do, is using traditional IGA methodology to manage agents, because we’ve got nothing now. And that’s a great first step: get it registered, get it governed, get the ownership in place, put some certification campaigns around it—great phase one.
But I do agree with you, the total governance—not just IGA, total identity governance—is going to move into the next era using AI. And we don’t know what that is yet, and it’s an exciting time. What is AI going to tell us is the best way to manage identity? So I agree with you longer term, but I think shorter term, at least they’re doing something.
At least they’re getting the agents under some kind of management, which we want to see. But yes, this world is going to change.
Anders Askasen:
I think it will, and I think in the short term, the problem with agentic AI is the fact that LLMs by nature are nondeterministic, meaning that there’s an eighty-seven percent probability that we should make sure that Michael doesn’t have these entitlements, so we’ll take them away—that’s our threshold.
Michael Ribaudo:
Yep.
Anders Askasen:
But that’s not a binary decision. So I think that’s what we’re currently battling a little bit, plus the fact that what we discussed—that you kind of have to give up all the keys to the kingdom currently to do something useful with agents in a provisioning or joiner-mover-leaver type of scenario.
Michael Ribaudo:
I think before the podcast we spoke about browser access and extensions, etc., and I think what we need to see more of is AI suggesting you do something: “You haven’t used this entitlement in six months. Do you wanna just remove it?” I think there needs to be more continuous AI suggesting right now, until we get it to a level where we go, “It’s not eighty-seven percent; it’s a hundred percent.”
Anders Askasen:
I think what you’re saying, Michael, is that zero trust is really the way forward here—least privilege.
Start with nothing. And if you need something, then you surface that and you request that and you put the context around it. And I think that’s where the vendors, like the one I represent, need to think about that. We need to put forth solutions from a software point of view that help you and Cyber IIM and others like you deploy those at customers.
Michael Ribaudo:
Yeah, I agree. And I think the conversation to have with the CISO—I was asked this the other day: how do we make our CISO, if they’re not concerned, concerned about AI?
The scenario I gave was: imagine if it was a workforce identity, and you were going to give it forty-five times more accounts than it has today, and then we’re going to give those accounts access to a hundred times more data than we have today, and then we’re not going to govern it.
What would the CISO say about that? And that’s what we’re giving agents. Agents are at the moment forty-five times more than the workforce identity—that’s going to grow fast. And the amount of data we’re giving it access to is accelerating as well, so that problem’s only going to get bigger. So to get it under control, I think, is what vendors like yourselves need to be part of.
Anders Askasen:
And like I said, there’s a lot of things that need to happen before we reach a point where it’s matured.
There’s a lot of standardization—how agents communicate with agents—but we’re seeing a lot of development around MCP. Radiant Logic, in fact, supports MCP. We expose our capabilities as MCP tools, if you will, yet there needs to be governance around that, and it needs to be proper authentication. And these tools and these agents have a tendency of being chained up. So one agent calls another agent, and that calls a third agent, and they all use different tools.
How do you put the accountability in that kind of chain? Is it human in the loop, or what’s the accountability thought process from your customers’ perspective—what they require?
Michael Ribaudo:
Customers definitely want human in the loop.
No one’s ready to let the Terminator loose, so they definitely want human in the loop; they want AI to come up and suggest really intelligent things to make things way faster, way better, way more secure, but let the human make the final decision. I was talking about the browser example earlier—definitely want to be in the loop—but we need to let them do more discovery, more suggestions, and then come up with ways of really quickly making changes and let the human give the approval.
Anders Askasen:
I guess that gives back the controls to the enterprise, as opposed to giving it to some off-the-shelf hyperscaler that has an LLM.
Speaking of that topic—and I know you work with big financial institutions here in London and elsewhere—is there thought around local LLM on-prem versus using the hyperscalers’ off-the-shelf type of LLMs?
Michael Ribaudo:
Yeah. I met with a bank this week. Their strategy is to be the best bank at AI, which is quite an interesting statement. And what they said was they can use local, but it’s not going to have the quality of AI that they need. So they’d rather use the off-the-shelf stuff, but in a protected way, so the data remains within their environment, within their tenant, and it doesn’t get exposed to the Internet.
So they’ve identified that they can go, like some of them did with the cloud—internal clouds—and then realized that products don’t really work as well, they don’t update as well. So I think the banks are accepting that the off-the-shelf AI is going to be better, and they’ll have some custom stuff obviously, but it’s going to be a better use than trying to bring it on-prem.
Anders Askasen:
And it’s just how much money gets poured into NVIDIA and the semiconductor industry, right? The more data power, the better it gets. But one thing that is important here—and this is our firm belief from Radiant Logic’s perspective—is that the data layer is crucial. If you serve up all these AI processes with crappy data, you get crappy results. So at some point, you need to make sure that that’s the starting point in all these initiatives.
Michael Ribaudo:
Absolutely.
A scenario was given to me that if you go and point your AI agent that you create for yourself at your OneDrive, your SharePoint site, and you’ve been in that organization for ten years, how old is some of that data? Do you want it making a decision on a meeting you had four years ago that’s no longer relevant? So we’re probably going to have to look at how we can get AI to ignore data beyond a certain point, to allow it to be able to make decisions that are more current and relevant.
So it’s gonna be—I mean, data is what’s changed, I think. Identity didn’t care about data before AI. I mean, how many failed data access governance projects do you know of?
But now data’s become really important because we’re letting this autonomous agent go and do whatever it wants with data. That data has to be good. So that world’s changed.
Anders Askasen:
Michael, we’re getting close to the twenty minutes, but I want to wrap up with asking you one provocative question. Have you tried any of these personal assistant agents and given them the keys to the kingdom?
Michael Ribaudo:
So, yes. We use Microsoft Copilot. And what I tell my team all the time is, everyone’s in consulting worries about their role—“Is AI gonna take over?”
I’m like, the reason it’s called a copilot is because you’re still the pilot. You’re still flying the plane; they’re not allowed to fly the plane, they can only help you fly the plane. So I have a CEO agent that I’ve trained on me, my data, my articles that I’ve written, my documentation, to help me strategize in the business. So, yes, I do have an agent.
Anders Askasen:
So you’re taking the approach that this is something that you should adopt, but be careful. But I’m sure there’s other companies that are more conservative and they say no.
Michael Ribaudo:
We are using the guardrails of the fact that it’s inside of our Azure tenant, where all our documentation is, and it’s locked down. The data doesn’t go out; it only comes in. So we do have that guardrail in place.
And what I tell everyone is: use AI to help you, don’t take it as gospel. Make sure you review everything that it’s given you. Don’t copy and paste.
Anders Askasen:
And I think with those words from Michael, who always brings very clever and wise advice, we’re gonna wrap this up. Make sure that you have the guardrails when you put something in place. But also, AI is here to stay, and it will not necessarily replace you. But if you can use it to augment your work and be more efficient, you should.
With that, over and out.
Listen to Radio Logic using one of many popular podcasting apps or directories: