Who Are the Robots? Uncovering AI Agents Identities

Ron Popov, Clément Notin

fwd:cloudsec North America 2026 · Day 1

In an era where Artificial Intelligence (AI) agents are rapidly integrating into enterprise operations, the critical challenge of securing these autonomous entities remains largely unaddressed. Ron Popov and Clément Notin, security researchers at Tennable, delivered a compelling talk at fwd:cloudsec, shedding light on the nascent but vital field of AI agent identity management. Their presentation, "Who Are the Robots? Uncovering AI Agents Identities," delved into the distinct approaches taken by Microsoft and Google to establish identity solutions for AI agents, a fundamental component of their secure operation.

AI review

Competent comparative analysis of Microsoft Entra Agent ID and Google Agent Identities — two genuinely new things worth understanding. The researchers clearly did real work mapping these architectures, and the Spiffy/certificant-bound token detail shows they went past the marketing docs. But this is fundamentally documentation and taxonomy work, not original security research — no novel attack paths, no exploits, no proof-of-concept showing what breaks when the model fails.

Watch on YouTube