I made AI agents apply for my Security Team. Then I gave the agents access to AWS.
Cole Horsman
fwd:cloudsec North America 2026 · Day 1
In a compelling presentation at fwd:cloudsec, Cole Horsman, an AI security specialist at KKR, unveiled an innovative approach to tackling the pervasive challenge of **cloud identity and access management (IAM)**. The talk, provocatively titled "I made AI agents apply for my Security Team. Then I gave the agents access to AWS," details Horsman's journey in developing and deploying an autonomous, multi-agent system designed to manage and secure AWS IAM at scale. This initiative addresses a critical industry gap: the chronic lack of dedicated resources for IAM security amidst an explosion of machine identities, which often outnumber human identities by a staggering 50-to-1.
AI review
Horsman is solving a real problem — IAM debt at scale is genuinely painful and the multi-agent framing is a practical angle most teams haven't tried. The talk lands as a solid practitioner case study: honest about the constraints, grounded in actual tooling, and delivers a measurable result. It's not research; it's an operational experiment, and it should be judged as one.