
Autonomous Agents Need a Verified Identity with Rosalyn Curato
Show notes
The identity and access model built for human users starts to break the moment an autonomous agent acts on someone's behalf, because an agent cannot be authenticated the way a person is. Rosalyn Curato, Chief Innovation Officer and General Manager of Agentic Security at Vouched, makes the case that an autonomous agent should never be an anonymous one, and that trust starts with verifying the agent and tying it to a known human. Her framing reduces to three questions every organization should be able to answer about an agent: who it is, which human it belongs to and what it has been given permission to do. From there the conversation turns to what breaks without that binding. Curato covers rogue agents, the risk of handing an agent too much access and the fraud and liability costs that organizations are already forecasting. She and hosts Rachael Lyon and Jonathan Knepher work through the controls that answer it, including delegated permissions, immutable audit trails, kill switches and the KYA-OS open standard that Vouched donated to the Decentralized Identity Foundation. For links and resources discussed in this episode, please visit our show notes at https://www.forcepoint.com/resources/podcast/verified-identity-for-ai-agents