Table of contents
- Will AI and Self-Healing Security Take Humans Out of the Loop Entirely?
- Why Is Nonhuman Identity the New Front Door for Exploitation Risks?
- Are AI-Driven Identity Attacks Genuinely New?
- Why Does Zero Trust Matter More in the Era of Machine-Speed Attacks?
- Where Should Autonomy Stop When Deploying Agentic Tools?
- Why Is AI Sprawl Being Compared to Shadow IT?
- How Will Agentic AI Change the Role of SOC Analysts?
- Where This Leaves Security Teams
- Agentic AI & Cloud Security LIVE 2026: Frequently Asked Questions
AI security splits into two conversations: stopping attackers who use AI, and using AI to defend faster. At Cloud Security LIVE 2026, Gil Geron, CEO and co-founder of Orca, Jim Reavis, CEO of the Cloud Security Alliance and its new AI Foundation, and Brian Gatta, global vice president for cloud workload security at Zscaler, tackled both. None expect a fully autonomous, self-healing cloud soon. All three agree identity, least privilege, and visibility still decide outcomes, just faster.
Will AI and Self-Healing Security Take Humans Out of the Loop Entirely?
The panel opened on whether AI will eventually take humans out of the loop entirely, detecting, responding to, and remediating threats faster than attackers can move. Geron called full self-healing a “holy grail” worth working toward without expecting to arrive soon.
The reality is that we have to do a lot more with less, and so it’s a must to strive to automate as much as possible and give us the data that we need to take action.
Gil Geron, CEO and Co-Founder, Orca
Reavis added a caution against treating AI as a black box: “we gotta really understand it and not just say we throw things across the wall to AI.” The moderator raised a real risk: agents with too much administrative access taking down a repository or production system by mistake. Geron’s guidance treats the agent like a new hire. Before handing over the keys, confirm it has the knowledge to take the right action, not just the ability to take one.
Why Is Nonhuman Identity the New Front Door for Exploitation Risks?
Reavis was direct about where exploitation risk is concentrating as agentic systems multiply.
Identity, that’s sort of the front door to how we are going to see exploitation risks within the agentic AI, and it’s just a key area we need to be thinking about.
Jim Reavis, CEO, Cloud Security Alliance
He introduced a distinction worth remembering: pairing least privilege with least autonomy. An agent can hold minimal permissions and still cause damage if it has too much freedom to act unsupervised. Reavis connected this to the confused deputy problem, where one agent lacking a permission simply asks a second, more permissive agent for the same information and gets it, since that agent is aligned to be helpful rather than to enforce a boundary. The Cloud Security Alliance’s 2026 focus, called securing the agentic control plane, centers heavily on nonhuman identity for this reason.
Are AI-Driven Identity Attacks Genuinely New?
Asked whether AI-driven identity attacks are genuinely new, Reavis kept it plain: mostly, no. “There’s an acceleration of those. We’re thinking about risk, and I think that’s really important,” he said, noting the principles behind exploitation haven’t changed. Geron backed this from the fundamentals side, arguing prompt injection and other emerging risks don’t erase the basic requirement to secure data, networking, and access.
The essence of the fact we need to secure our data, we need to secure our networking, we need to secure access…still exists. It just scales faster in this era.
Gil Geron, CEO and Co-Founder, Orca
Why Does Zero Trust Matter More in the Era of Machine-Speed Attacks?
Gatta took the discussion into dwell time and lateral movement, arguing that chasing faster detection will always lose to attackers operating at machine speed. The fix is removing the pathway, not shortening the response window.
A workload shouldn’t be able to access anything unless it follows multifactor authentication, identity, business context, and business policy, then and only then I make the connection.
Brian Gatta, Global VP, Cloud Workload Security, Zscaler
He pointed to routable networks left open for convenience as the exact pathway that lets attackers move laterally once inside. Reavis agreed, adding the goal now is reducing blast radius before an attack starts, though enterprise networks change minute by minute, which makes that harder than it sounds.
Where Should Autonomy Stop When Deploying Agentic Tools?
This is the question every security leader piloting agentic tools is actually asking. Reavis framed autonomy as a ladder rather than a switch: an agent might start by explaining a problem, move up to recommending an action, then open a ticket, and only much later apply a fix on its own. “You’re not gonna get to the top rung of the ladder in one leap,” he said.
The moderator added that context changes the correct call. An agent that only sees a critical vulnerability will fix it immediately. One that also knows whether the system is externally facing or in production might decide differently. Recent incidents involving deleted repositories trace back to exactly this gap.
Why Is AI Sprawl Being Compared to Shadow IT?
Gatta described current infrastructure growth around AI adoption bluntly: “it’s pure chaos. It’s an explosion of growth.” Every CISO conversation now starts with AI and ends with cutting cloud cost, two topics he argues aren’t separate anymore.
Reavis tied this to visibility, noting most organizations don’t know how many models they run or whether they’re paying for unnecessarily expensive inference, a pattern he compared directly to early shadow IT. Geron added a development-specific wrinkle: coding assistants tend to recommend broader permissions, since that’s what makes the code work.
In order to make it work, your default is to actually deliver a much less secure software. And so if you’re doing a much less secure software at scale, it’s definitely a challenge.
Gil Geron, CEO and Co-Founder, Orca
How Will Agentic AI Change the Role of SOC Analysts?
Reavis predicts junior analysts will operate with level-two context almost immediately, while senior analysts get more productive as incident volume and complexity increase, often by steering an investigating agent in real time rather than reviewing its output afterward. Geron framed this as a hiring story more than a threat story, pointing to a persistent security talent shortage as the real opportunity AI addresses.
It’s all dependent on us. It depends on us as managers, depends on us as security practitioners. We have to adopt AI too.
Gil Geron, CEO and Co-Founder, Orca
Where This Leaves Security Teams
The panel’s closing round converged on similar advice: choose tools that make your team faster, stay proactive about educating leadership, and stop trying to be the department that says no. If your organization is working through agent identity governance or visibility into AI sprawl, get a demo to see how Orca approaches AI risk across your cloud environment. Watch the full session here.
Agentic AI & Cloud Security LIVE 2026: Frequently Asked Questions
One agent lacking a permission asks a second, more permissive agent to perform the action instead. Because that second agent is aligned to be helpful, it often complies, bypassing the access boundary entirely.
Least privilege limits what an agent can access. Least autonomy limits how freely it can act within that access. Reavis argued teams need both, since minimal permissions don’t prevent harm from unsupervised action.
A framework for rolling out agentic AI in stages: an agent first explains a problem, then recommends an action, then opens a ticket, and only later applies fixes independently. Autonomy is earned incrementally, not granted all at once.
The Cloud Security Alliance’s named focus area for 2026, centered on nonhuman identity across the technologies powering agentic AI systems, according to Reavis.
An agent evaluating a vulnerability in isolation will fix it immediately. One with added context, whether the asset is production or development, may decide differently. Panelists linked this gap to recent incidents involving deleted repositories and outages.
Table of contents
- Will AI and Self-Healing Security Take Humans Out of the Loop Entirely?
- Why Is Nonhuman Identity the New Front Door for Exploitation Risks?
- Are AI-Driven Identity Attacks Genuinely New?
- Why Does Zero Trust Matter More in the Era of Machine-Speed Attacks?
- Where Should Autonomy Stop When Deploying Agentic Tools?
- Why Is AI Sprawl Being Compared to Shadow IT?
- How Will Agentic AI Change the Role of SOC Analysts?
- Where This Leaves Security Teams
- Agentic AI & Cloud Security LIVE 2026: Frequently Asked Questions
