Every enterprise is already running a population of identities that vastly outnumbers its employees: service accounts, API keys, OAuth tokens, certificates, and a growing number of autonomous AI agents. Ratios vary across studies, from 45-to-1 to over 100-to-1, and this trend is accelerating with the adoption of agentic AI. This is no longer a technical blind spot; it has become the primary playground for attackers, as documented in the new OWASP Non-Human Identity Top 10 and its 2026 extension dedicated to agentic applications.
This keynote does not stop at definitions. It explains why standards like SPIFFE, designed to prove what a machine is, fail to answer the question that truly matters in 2026: on whose behalf is this machine acting, and for how long? You will leave with the T.R.U.S.T. framework, a five-step method to map, secure, and, if necessary, revoke the access of a compromised machine identity before it compromises everything else.
Designed for architects and security leaders who want the mechanics, not the metaphors.