← Browse

World's Fair 2025

Securing Agents with Open Standards — Bobby Tiernay and Kam Sween, Auth0

Bobby Tiernay , Kam Sween

Overview

This talk addresses the critical security challenges arising from increasingly capable AI agents that perform actions in the real world. It emphasizes the need for robust identity and access control mechanisms to prevent issues like secrets in prompts, overly broad scopes, and difficult troubleshooting. The core thesis is that by adopting open standards and implementing proper identity management, developers can build more secure and trustworthy AI agent systems.

Who should watch

Key takeaways

Notable quotes

*As agents start to do more things in the real world... cracks are starting to appear and it's pretty clear secrets end up in prompts, scopes get too broad and troubleshooting gets really really hard.*
*If that access isn't scoped, monitored, and tied to a real user, you're wide open to abuse and unintended behavior.*
*If your agent doesn't have identity, it doesn't matter how well you scope your tokens or rotate tokens, you still have don't have real control here.*

Watch on YouTube →

Unofficial community note. Prefer the recording for nuance.