KuppingerCole Analysts

KuppingerCole Analysts

KuppingerCole Analysts AG is an international, independent analyst organization offering technology research, neutral advice and events in Identity Management, Cybersecurity and Artificial Intelligence.

  1. vor 3 Tagen

    Analyst Chat #314: Can You Trust AI to Verify AI Code?

    AI writes the code. But who checks it, and who is accountable when it goes wrong? In this episode, Matthias is joined by two colleagues: Guillaume Teixeron, bringing 20 years of experience on the product side of identity and authentication, and Jonathan Care, KuppingerCole Analysts' Director of Practice AI. Together they tackle the security gap opening up between how fast AI generates code and how slowly organizations are catching up on assurance, provenance, and accountability. Key Topics: ✅ AI in software development: from hype to structural baseline — but governance is still improvised ✅ Three tectonic shifts in AppSec: provenance, scale, and non-human identity ✅ Why organizations have industrialized code production but not code assurance ✅ The core question: can you trust AI to verify AI-generated code? ✅ Agent autonomy in production pipelines — the next flashpoint nobody has resolved yet ✅ How regulation (CRA, NIS2, DORA) will settle the provenance argument before the market does ⚡ "We have industrialized code production. We have not industrialized code assurance." Jonathan Care on why the security control set was built for human-authored code moving at human speed — and neither assumption is true anymore. 📅 Join KuppingerCole Analysts at the AIdentity & NHI Impact Day in Munich this October — where the accountability and provenance questions raised in this episode will be front and center.

  2. 24. Aug.

    Analyst Chat #313: When AI Agents Don't Play Nice - Multi-Agent Security Risks

    What happens when you put three AI agents in a room and tell them to solve the same problem? Anthropic ran the experiment — and the results are more unsettling than you'd expect. In this episode, Matthias Reinwarth sits down with Jonathan Care, KuppingerCole Analysts' newly appointed Director of Practice AI, to unpack the findings and ask what they mean for enterprise security, identity management, and the CISOs trying to govern it all. Key Topics: ✅ Anthropic's multi-agent experiment: three Claude instances, one codebase, unexpected outcomes ✅ Why coordination does not emerge naturally from intelligence — in agents or in humans ✅ The anthropomorphism trap: why comparing agents to dogs, kids, and wizards is useful but dangerous ✅ Social pressure, mechanisms, and the open research problem of agent cooperation ✅ Risk tolerance as a prerequisite for any agentic architecture — and how to define it ✅ Why correlated agents without coordination break your redundancy and business continuity assumptions 🤖 "If agents are highly correlated but lack coordination, redundancy does not provide the risk diversification we would expect." Jonathan Care on why multi-agent systems are a different beast and why CISOs need to treat them that way. 📅 Join KuppingerCole Analysts at the AIdentity & NHI Impact Day on October 6th in Munich where many of the open questions raised in this episode will be on the agenda

  3. 28. Juli

    Analyst Chat #310: AI Escaped the Sandbox - The OpenAI Hugging Face Hack (special episode)

    When an OpenAI test model escaped its sandbox and attacked Hugging Face's production infrastructure, headlines called it a Skynet moment. But was it? In this special flash news episode, Matthias Reinwarth brings together four KuppingerCole Analysts experts — Alexei Balaganski, Jonathan Care, John Tolbert, and Martin Kuppinger — to cut through the noise and ask the real question: what actually went wrong, and what should organizations do about it? Key Topics: ✅ What actually happened: two separate incidents dressed up as one dramatic story ✅ Why the sandbox failure was a containment and design problem — not an AI apocalypse ✅ Jonathan Care's core argument: the breach was credentials, not packets — you can't firewall your way out ✅ Non-human identity and agent identity as the real unsolved problem at the heart of the incident ✅ Secrets sprawl, overprivileged service accounts, and the absence of least privilege for AI agents ✅ Was it a containment failure, an identity failure, an observability failure, or a governance failure? 🐯 "OpenAI had a pet tiger and the tiger escaped, Hugging Face was just walking down the street." Alexei Balaganski on why the most dramatic AI security story of the year was actually two separate failures. 🔐 Four KuppingerCole Analysts experts, one incident, and the identity governance lessons every organization needs to hear.

  4. 27. Juli

    Analyst Chat #309: Fabrics Deep Dive II - the Identity Fabric as the Blueprint

    The Identity Fabric isn't just a concept, it's a working tool that KuppingerCole Analysts advisors use every day with clients. In this second episode of the fabric mini-series, Matthias sits down with Martin Kuppinger and Phillip Messerschmidt to explore how the Identity Fabric and Reference Architecture are applied in real client engagements, why capability-based thinking beats tool-centric thinking every time, and how the fabric evolves to stay relevant in a world of constant buzzwords. Key Topics: ✅ How the Identity Fabric is used in practice: maturity assessments, gap analyses, roadmaps, and tool selection ✅ Why the right order always goes capabilities → services → tools — never the other way around ✅ What happens when tools are used for things they were never meant to do ✅ Why organizing teams around capabilities — not tools — is the future of IT operations ✅ The Identity Fabric built for 2040: long-term thinking in a fast-moving market ✅ How the fabric absorbs buzzwords like IVIP, ISPM, and ITDR — and why that proves the concept 🧵 "Every second day someone comes up with a new buzzword, the Identity Fabric helps you strip it down to capabilities and ask: is there really something new here?" Martin Kuppinger on why structured thinking beats buzzword bingo. 📅 This is episode two of KuppingerCole Analysts' fabric mini-series, the Cybersecurity Fabric and AI Security Fabric episodes are coming next. Subscribe so you don't miss them.

Bewertungen und Rezensionen

5
von 5
3 Bewertungen

Info

KuppingerCole Analysts AG is an international, independent analyst organization offering technology research, neutral advice and events in Identity Management, Cybersecurity and Artificial Intelligence.